7945e84f90503d5b839ec6bda0d7ea7b8287abf8e692f0d40ab75d0df59b61b3acrstealer: 7945e84f — Go 1.18.5 PE32+ x64, 54 randomized main.* functions, same atom.hutsell.com cert
Executive Summary
Twenty-first confirmed sibling in the ACR Stealer cluster. Go 1.18.5 PE32+ x64, module UyiuGZEejgKpFWS, 54 randomized main.* function names, self-signed Authenticode CN=atom.hutsell.com / issuer WR3. .rsrc section carries a four-icon suite (256×256 PNG intact). No static C2 strings, no custom PE parser, no multi-pass decoder — a light Go 1.18.5 build matching the baseline ef262340 template. Static-only; CAPE skipped.
What It Is
| Field | Value |
|---|---|
| SHA-256 | 7945e84f90503d5b839ec6bda0d7ea7b8287abf8e692f0d40ab75d0df59b61b3 |
| Size | 1,976,576 bytes (1.98 MB) ^[raw/analyses/7945e84f9050/metadata.json] |
| File type | PE32+ executable (GUI) x86-64, 7 sections ^[raw/analyses/7945e84f9050/file.txt] |
| Go version | go1.18.5 (amd64, CGO_ENABLED=0, -trimpath=true) ^[raw/analyses/7945e84f9050/strings.txt] |
| PE timestamp | 0x0 (null / stripped) ^[raw/analyses/7945e84f9050/pefile.txt] |
| Linker | Go internal linker 3.0 ^[raw/analyses/7945e84f9050/pefile.txt] |
| Subsystem | Windows GUI ^[raw/analyses/7945e84f9050/pefile.txt] |
| Stripped | Yes (external PDB reference, .symtab retained for Go runtime) ^[raw/analyses/7945e84f9050/rabin2-info.txt] |
| Overlay | None (file size matches last section EOF) ^[raw/analyses/7945e84f9050/binwalk.txt] |
Module path: UyiuGZEejgKpFWS ^[raw/analyses/7945e84f9050/strings.txt]. Build ID: Fim3VzUYuPzpDWnfAmB3/llcUnMtux0Te1JblJs54/QCL75ac4I536Q5tdF3tv/ivU7CMFCr5OpJNL_3rMa ^[raw/analyses/7945e84f9050/strings.txt].
How It Works
Build / RE
Compiler / toolchain: Go 1.18.5, GOARCH=amd64, GOOS=windows, CGO_ENABLED=0, -trimpath=true ^[raw/analyses/7945e84f9050/strings.txt]. This places the sample in the legacy Go 1.18.5 divergence branch of the ACR cluster alongside siblings ef262340, 44f594e2, 828405d6, 350a2b69, beff95d5, 119b387e, b0bc17dd, 38cf89b0, and 76a51fb7 — all sharing the same self-signed certificate chain and null PE timestamp.
Signing: Self-signed Authenticode certificate embedded at file offset 0x1EE200, size 2,176 bytes ^[raw/analyses/7945e84f9050/pefile.txt]:
- Subject:
CN=atom.hutsell.com - Issuer:
CN=WR3 - Serial:
4C3A4A8198F1CBEF1010F5FB3157D6FE - Validity: 2026-04-21 → 2026-07-20
This is the identical certificate chain used by the ten-sibling
ef262340cluster and represents the oldest cert template in the ACR family.
Function-name randomization: 54 randomized main.* function names in the Go symbol table, tying with 119b387e for heaviest PE32 count in the cluster (the x64 sibling beff95d5 has 22; 76a51fb7 has 11; b0bc17dd holds the overall record at 90) ^[raw/analyses/7945e84f9050/strings.txt]. Examples: main.qrhcwphie, main.qezljh, main.Uuktaguvt, main.Vroczbqxcpaqf, main.yktsnw, main.ovghzbnzowtaj.
Anti-analysis: Standard Go runtime cpuid vendor-id check at entry (Genu/ntel string compare) ^[r2:entry0]. No VM-specific anti-analysis observed; no GetTickCount gates, no registry disk-enum checks, no TLS callbacks.
Resources: .rsrc section present (0x1F990 bytes) with four RT_ICON entries and one RT_GROUP_ICON ^[raw/analyses/7945e84f9050/pefile.txt]. A 256×256 PNG icon is embedded, used for social-engineering masquerade. Binwalk confirms the PNG at offset 0x1E37E8 ^[raw/analyses/7945e84f9050/binwalk.txt].
No packing / no crypter: .text entropy 6.20, no UPX/Themida/ConfuserEx signatures ^[raw/analyses/7945e84f9050/pefile.txt].
Absent capabilities (delta from d5655568 / 7620884e branches):
- No custom in-memory PE parser
- No multi-pass byte-transform string decoder
- No
.rsrcstripping (unlike6cbac6bcandbeff95d5)
Deploy / ATT&CK
Execution: Go runtime bootstrap → randomized main.main via scheduler. No persistence mechanism visible statically.
Network: No hardcoded C2 IP, domain, or URL strings recovered. Family pattern is PRNG-seeded runtime C2 decoding ^[/intel/analyses/6871848bb724a184e393a734c9de9c17c41da1f26359755696f0df40685c42f2.html] ^[/intel/analyses/c577c6c87bd8a143598000e63d53c8e09b4f7d7a8b8c5de36f7479b5f4411274.html]. crypto/tls, net/http, and syscall packages are linked, confirming TLS-wrapped HTTPS C2 capability ^[raw/analyses/7945e84f9050/strings.txt].
Collection: Infostealer family targeting browser credential stores, cryptocurrency wallets, and FTP/SSH credentials (family naming convention; no static confirmation in this sample).
Exfiltration: POST to C2 over TLS (inferred from standard library linkage and family behaviour).
ATT&CK mapping (static inference):
- T1055 — Process Injection (Go runtime goroutine scheduler)
- T1071.001 — Application Layer Protocol: Web Protocols (
net/http+crypto/tls) - T1071 — Application Layer Protocol (HTTPS C2)
- T1083 — File and Directory Discovery (infostealer collection scope)
- T1113 — Screen Capture (family capability, not confirmed in this sample)
- T1218 — Signed Binary Proxy Execution (self-signed Authenticode)
- T1567 — Exfiltration Over Web Service (HTTPS POST)
Confidence: Static-only. No CAPE detonation available. ATT&CK mappings are family-inferred where not directly observable.
Decompiled Behavior
Entry point 0x45ab40 (entry0) is the Go runtime _rt0_amd64_windows bootstrap ^[r2:entry0]. Sequence:
cpuidleaf 0 reads vendor string; storesGenu/ntelresult in global0x60a9cc- Runtime allocator init via
fcn.004563c0 - Thread-local storage setup (
gs:[0x28]canary) - Scheduler init (
fcn.0045b140,fcn.0045b840) runtime.maindispatch → randomizedmain.main
No user-mode encryption, no process hollowing, no registry writes visible in the entry-point decompilation. All threat logic lives inside the randomized main.* goroutines.
C2 Infrastructure
No static C2 recovered. The family employs PRNG-seeded runtime C2 decoding — see prng-seeded-c2-url-decoding for the technique. Sibling ef262340 (same cert, same toolchain) had no static C2; sibling 1bfebf79 (same cert, different module) rotated to hertzfigblob.icu. This sample likely decodes C2 at runtime using the same seeded-PRNG pattern.
Interesting Tidbits
- Certificate recycling: The
atom.hutsell.com/WR3self-signed chain has now been reused across eleven confirmed siblings spanning four months (Apr–Jul 2026). Builder does not rotate certificates per build — the cert is a cluster fingerprint. - Build ID uniqueness: Each sibling carries a unique Go build ID despite identical toolchain, indicating fresh compiles from the same source tree on each build.
- x64 divergence within legacy branch: While
6cbac6bcandbeff95d5are also x64, they stripped.rsrc; this sample restores the icon suite, showing the builder has a per-build icon-toggle. - Function count as builder fingerprint: The 54 randomized
main.*names are a reproducible count for this specific build; lighter variants (11, 22) and heavier variants (90) confirm the builder randomizes function names per compile. - capa failure: Mandiant capa failed due to missing signature path ^[raw/analyses/7945e84f9050/capa.txt]; no capability data available. floss also errored on argument parsing ^[raw/analyses/7945e84f9050/floss.txt]. Both failures are tooling/environment issues, not sample obfuscation.
How To Mess With It (Homelab Replication)
Toolchain: Go 1.18.5 for Windows amd64.
Flags: GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w"
Randomization: Use a build script to rename all main package functions to random alphanumeric strings before compile.
Signing: Generate a self-signed cert with openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 90 -subj "/CN=atom.hutsell.com"; embed via osslsigncode or Go linker -H windowsgui with Authenticode post-processing.
Icon: Append a 256×256 PNG icon resource using rsrc or goversioninfo.
Verification: The resulting binary should show:
go1.18.5in stringsCGO_ENABLED=0/-trimpath=truein buildinfo- Null PE timestamp (
0x0) - High
.rdataentropy (~7.0) from Go runtime tables - No static C2 strings
Deployable Signatures
YARA rule
rule acrstealer_go1185_atom_hutsell_selfsigned {
meta:
description = "ACR Stealer Go 1.18.5 cluster with atom.hutsell.com self-signed cert"
author = "PacketPursuit"
reference = "raw/analyses/7945e84f90503d5b839ec6bda0d7ea7b8287abf8e692f0d40ab75d0df59b61b3"
date = "2026-08-05"
strings:
$go_ver = "go1.18.5" ascii
$mod_prefix = "main." ascii
$cert_cn = "atom.hutsell.com" ascii
$build_cgo = "CGO_ENABLED=0" ascii
$build_trim = "-trimpath=true" ascii
$issuer_wr3 = "WR3" ascii
condition:
uint16(0) == 0x5a4d and
$go_ver and
$build_cgo and
$cert_cn and
#mod_prefix > 40
}
Behavioral fingerprint
This binary is a Go 1.18.5 PE32+ x64 with null PE timestamp, ~54 randomized main.* function names, self-signed Authenticode CN=atom.hutsell.com / issuer WR3, .rsrc section containing a 256×256 PNG icon, and no hardcoded C2 strings. On execution it initializes the Go runtime (cpuid vendor check → allocator → scheduler) and dispatches to a randomized main.main goroutine that likely contacts a TLS C2 endpoint decoded at runtime via a PRNG-seeded transform. Network traffic is HTTPS (crypto/tls + net/http linkage confirmed). No custom PE parser or multi-pass decoder — a light build variant within the ACR Stealer family.
IOC list
| Indicator | Value |
|---|---|
| SHA-256 | 7945e84f90503d5b839ec6bda0d7ea7b8287abf8e692f0d40ab75d0df59b61b3 |
| Go build ID | Fim3VzUYuPzpDWnfAmB3/llcUnMtux0Te1JblJs54/QCL75ac4I536Q5tdF3tv/ivU7CMFCr5OpJNL_3rMa |
| Module path | UyiuGZEejgKpFWS |
| Certificate CN | atom.hutsell.com |
| Certificate issuer | WR3 |
| Certificate serial | 4C3A4A8198F1CBEF1010F5FB3157D6FE |
| Certificate validity | 2026-04-21 → 2026-07-20 |
Detection Signatures
| ATT&CK ID | Technique | Evidence |
|---|---|---|
| T1055 | Process Injection | Go runtime goroutine scheduler dispatch |
| T1071.001 | Application Layer Protocol: Web Protocols | net/http + crypto/tls linkage |
| T1071 | Application Layer Protocol | HTTPS C2 (family pattern) |
| T1083 | File and Directory Discovery | Infostealer collection scope (family) |
| T1218 | Signed Binary Proxy Execution | Self-signed Authenticode |
| T1567 | Exfiltration Over Web Service | HTTPS POST (family pattern) |
References
- acrstealer — family entity page
- golang-stealer-build-pattern — shared build artefacts across Go infostealer families
- prng-seeded-c2-url-decoding — runtime C2 decoding technique observed in ACR cluster
- /intel/analyses/ef262340421fcb93d5f0c0d0bf418bc9fc6224398dda3093028ed8c97cc5bba7.html — Tenth sibling (same cert, oldest toolchain baseline)
- /intel/analyses/b0bc17dda19e36d395e354f6a861e93a70780029bb35116ea3616e316c588710.html — Seventeenth sibling (90 randomized functions, heaviest build)
- /intel/analyses/76a51fb7d82bcdb120f3128172ec5682f630789b8b4aa9450dc65184ea3a15e6.html — Nineteenth sibling (11 randomized functions, lightest x64 build)
Provenance
Static analysis of <sample 7945e84f9050.bin> (2,026,112 bytes). Tools: file, exiftool, pefile, strings, rabin2, binwalk, radare2 (analysis level 2, 1,501 functions recovered), Python pefile library for certificate extraction. Capa and floss failed due to environment/configuration errors, not sample obfuscation. No CAPE detonation available (no Windows guest). All C2 claims are family-inferred; no static C2 strings recovered in this sample.