typeanalysisfamilyacrstealerconfidencehighcreated2026-08-05updated2026-08-05infostealermalware-familygolangsigninggo-function-name-randomizationgo1.18.5-legacy-build-divergencetls-https-c2-clientsigned-pe-masqueraderesource-icon-social-engineeringno-static-c2-fully-runtime-decodedstatic-only
SHA-256: 7945e84f90503d5b839ec6bda0d7ea7b8287abf8e692f0d40ab75d0df59b61b3

acrstealer: 7945e84f — Go 1.18.5 PE32+ x64, 54 randomized main.* functions, same atom.hutsell.com cert

Executive Summary

Twenty-first confirmed sibling in the ACR Stealer cluster. Go 1.18.5 PE32+ x64, module UyiuGZEejgKpFWS, 54 randomized main.* function names, self-signed Authenticode CN=atom.hutsell.com / issuer WR3. .rsrc section carries a four-icon suite (256×256 PNG intact). No static C2 strings, no custom PE parser, no multi-pass decoder — a light Go 1.18.5 build matching the baseline ef262340 template. Static-only; CAPE skipped.

What It Is

Field Value
SHA-256 7945e84f90503d5b839ec6bda0d7ea7b8287abf8e692f0d40ab75d0df59b61b3
Size 1,976,576 bytes (1.98 MB) ^[raw/analyses/7945e84f9050/metadata.json]
File type PE32+ executable (GUI) x86-64, 7 sections ^[raw/analyses/7945e84f9050/file.txt]
Go version go1.18.5 (amd64, CGO_ENABLED=0, -trimpath=true) ^[raw/analyses/7945e84f9050/strings.txt]
PE timestamp 0x0 (null / stripped) ^[raw/analyses/7945e84f9050/pefile.txt]
Linker Go internal linker 3.0 ^[raw/analyses/7945e84f9050/pefile.txt]
Subsystem Windows GUI ^[raw/analyses/7945e84f9050/pefile.txt]
Stripped Yes (external PDB reference, .symtab retained for Go runtime) ^[raw/analyses/7945e84f9050/rabin2-info.txt]
Overlay None (file size matches last section EOF) ^[raw/analyses/7945e84f9050/binwalk.txt]

Module path: UyiuGZEejgKpFWS ^[raw/analyses/7945e84f9050/strings.txt]. Build ID: Fim3VzUYuPzpDWnfAmB3/llcUnMtux0Te1JblJs54/QCL75ac4I536Q5tdF3tv/ivU7CMFCr5OpJNL_3rMa ^[raw/analyses/7945e84f9050/strings.txt].

How It Works

Build / RE

Compiler / toolchain: Go 1.18.5, GOARCH=amd64, GOOS=windows, CGO_ENABLED=0, -trimpath=true ^[raw/analyses/7945e84f9050/strings.txt]. This places the sample in the legacy Go 1.18.5 divergence branch of the ACR cluster alongside siblings ef262340, 44f594e2, 828405d6, 350a2b69, beff95d5, 119b387e, b0bc17dd, 38cf89b0, and 76a51fb7 — all sharing the same self-signed certificate chain and null PE timestamp.

Signing: Self-signed Authenticode certificate embedded at file offset 0x1EE200, size 2,176 bytes ^[raw/analyses/7945e84f9050/pefile.txt]:

  • Subject: CN=atom.hutsell.com
  • Issuer: CN=WR3
  • Serial: 4C3A4A8198F1CBEF1010F5FB3157D6FE
  • Validity: 2026-04-21 → 2026-07-20 This is the identical certificate chain used by the ten-sibling ef262340 cluster and represents the oldest cert template in the ACR family.

Function-name randomization: 54 randomized main.* function names in the Go symbol table, tying with 119b387e for heaviest PE32 count in the cluster (the x64 sibling beff95d5 has 22; 76a51fb7 has 11; b0bc17dd holds the overall record at 90) ^[raw/analyses/7945e84f9050/strings.txt]. Examples: main.qrhcwphie, main.qezljh, main.Uuktaguvt, main.Vroczbqxcpaqf, main.yktsnw, main.ovghzbnzowtaj.

Anti-analysis: Standard Go runtime cpuid vendor-id check at entry (Genu/ntel string compare) ^[r2:entry0]. No VM-specific anti-analysis observed; no GetTickCount gates, no registry disk-enum checks, no TLS callbacks.

Resources: .rsrc section present (0x1F990 bytes) with four RT_ICON entries and one RT_GROUP_ICON ^[raw/analyses/7945e84f9050/pefile.txt]. A 256×256 PNG icon is embedded, used for social-engineering masquerade. Binwalk confirms the PNG at offset 0x1E37E8 ^[raw/analyses/7945e84f9050/binwalk.txt].

No packing / no crypter: .text entropy 6.20, no UPX/Themida/ConfuserEx signatures ^[raw/analyses/7945e84f9050/pefile.txt].

Absent capabilities (delta from d5655568 / 7620884e branches):

  • No custom in-memory PE parser
  • No multi-pass byte-transform string decoder
  • No .rsrc stripping (unlike 6cbac6bc and beff95d5)

Deploy / ATT&CK

Execution: Go runtime bootstrap → randomized main.main via scheduler. No persistence mechanism visible statically.

Network: No hardcoded C2 IP, domain, or URL strings recovered. Family pattern is PRNG-seeded runtime C2 decoding ^[/intel/analyses/6871848bb724a184e393a734c9de9c17c41da1f26359755696f0df40685c42f2.html] ^[/intel/analyses/c577c6c87bd8a143598000e63d53c8e09b4f7d7a8b8c5de36f7479b5f4411274.html]. crypto/tls, net/http, and syscall packages are linked, confirming TLS-wrapped HTTPS C2 capability ^[raw/analyses/7945e84f9050/strings.txt].

Collection: Infostealer family targeting browser credential stores, cryptocurrency wallets, and FTP/SSH credentials (family naming convention; no static confirmation in this sample).

Exfiltration: POST to C2 over TLS (inferred from standard library linkage and family behaviour).

ATT&CK mapping (static inference):

  • T1055 — Process Injection (Go runtime goroutine scheduler)
  • T1071.001 — Application Layer Protocol: Web Protocols (net/http + crypto/tls)
  • T1071 — Application Layer Protocol (HTTPS C2)
  • T1083 — File and Directory Discovery (infostealer collection scope)
  • T1113 — Screen Capture (family capability, not confirmed in this sample)
  • T1218 — Signed Binary Proxy Execution (self-signed Authenticode)
  • T1567 — Exfiltration Over Web Service (HTTPS POST)

Confidence: Static-only. No CAPE detonation available. ATT&CK mappings are family-inferred where not directly observable.

Decompiled Behavior

Entry point 0x45ab40 (entry0) is the Go runtime _rt0_amd64_windows bootstrap ^[r2:entry0]. Sequence:

  1. cpuid leaf 0 reads vendor string; stores Genu/ntel result in global 0x60a9cc
  2. Runtime allocator init via fcn.004563c0
  3. Thread-local storage setup (gs:[0x28] canary)
  4. Scheduler init (fcn.0045b140, fcn.0045b840)
  5. runtime.main dispatch → randomized main.main

No user-mode encryption, no process hollowing, no registry writes visible in the entry-point decompilation. All threat logic lives inside the randomized main.* goroutines.

C2 Infrastructure

No static C2 recovered. The family employs PRNG-seeded runtime C2 decoding — see prng-seeded-c2-url-decoding for the technique. Sibling ef262340 (same cert, same toolchain) had no static C2; sibling 1bfebf79 (same cert, different module) rotated to hertzfigblob.icu. This sample likely decodes C2 at runtime using the same seeded-PRNG pattern.

Interesting Tidbits

  • Certificate recycling: The atom.hutsell.com / WR3 self-signed chain has now been reused across eleven confirmed siblings spanning four months (Apr–Jul 2026). Builder does not rotate certificates per build — the cert is a cluster fingerprint.
  • Build ID uniqueness: Each sibling carries a unique Go build ID despite identical toolchain, indicating fresh compiles from the same source tree on each build.
  • x64 divergence within legacy branch: While 6cbac6bc and beff95d5 are also x64, they stripped .rsrc; this sample restores the icon suite, showing the builder has a per-build icon-toggle.
  • Function count as builder fingerprint: The 54 randomized main.* names are a reproducible count for this specific build; lighter variants (11, 22) and heavier variants (90) confirm the builder randomizes function names per compile.
  • capa failure: Mandiant capa failed due to missing signature path ^[raw/analyses/7945e84f9050/capa.txt]; no capability data available. floss also errored on argument parsing ^[raw/analyses/7945e84f9050/floss.txt]. Both failures are tooling/environment issues, not sample obfuscation.

How To Mess With It (Homelab Replication)

Toolchain: Go 1.18.5 for Windows amd64. Flags: GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" Randomization: Use a build script to rename all main package functions to random alphanumeric strings before compile. Signing: Generate a self-signed cert with openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 90 -subj "/CN=atom.hutsell.com"; embed via osslsigncode or Go linker -H windowsgui with Authenticode post-processing. Icon: Append a 256×256 PNG icon resource using rsrc or goversioninfo. Verification: The resulting binary should show:

  • go1.18.5 in strings
  • CGO_ENABLED=0 / -trimpath=true in buildinfo
  • Null PE timestamp (0x0)
  • High .rdata entropy (~7.0) from Go runtime tables
  • No static C2 strings

Deployable Signatures

YARA rule

rule acrstealer_go1185_atom_hutsell_selfsigned {
    meta:
        description = "ACR Stealer Go 1.18.5 cluster with atom.hutsell.com self-signed cert"
        author = "PacketPursuit"
        reference = "raw/analyses/7945e84f90503d5b839ec6bda0d7ea7b8287abf8e692f0d40ab75d0df59b61b3"
        date = "2026-08-05"
    strings:
        $go_ver = "go1.18.5" ascii
        $mod_prefix = "main." ascii
        $cert_cn = "atom.hutsell.com" ascii
        $build_cgo = "CGO_ENABLED=0" ascii
        $build_trim = "-trimpath=true" ascii
        $issuer_wr3 = "WR3" ascii
    condition:
        uint16(0) == 0x5a4d and
        $go_ver and
        $build_cgo and
        $cert_cn and
        #mod_prefix > 40
}

Behavioral fingerprint

This binary is a Go 1.18.5 PE32+ x64 with null PE timestamp, ~54 randomized main.* function names, self-signed Authenticode CN=atom.hutsell.com / issuer WR3, .rsrc section containing a 256×256 PNG icon, and no hardcoded C2 strings. On execution it initializes the Go runtime (cpuid vendor check → allocator → scheduler) and dispatches to a randomized main.main goroutine that likely contacts a TLS C2 endpoint decoded at runtime via a PRNG-seeded transform. Network traffic is HTTPS (crypto/tls + net/http linkage confirmed). No custom PE parser or multi-pass decoder — a light build variant within the ACR Stealer family.

IOC list

Indicator Value
SHA-256 7945e84f90503d5b839ec6bda0d7ea7b8287abf8e692f0d40ab75d0df59b61b3
Go build ID Fim3VzUYuPzpDWnfAmB3/llcUnMtux0Te1JblJs54/QCL75ac4I536Q5tdF3tv/ivU7CMFCr5OpJNL_3rMa
Module path UyiuGZEejgKpFWS
Certificate CN atom.hutsell.com
Certificate issuer WR3
Certificate serial 4C3A4A8198F1CBEF1010F5FB3157D6FE
Certificate validity 2026-04-21 → 2026-07-20

Detection Signatures

ATT&CK ID Technique Evidence
T1055 Process Injection Go runtime goroutine scheduler dispatch
T1071.001 Application Layer Protocol: Web Protocols net/http + crypto/tls linkage
T1071 Application Layer Protocol HTTPS C2 (family pattern)
T1083 File and Directory Discovery Infostealer collection scope (family)
T1218 Signed Binary Proxy Execution Self-signed Authenticode
T1567 Exfiltration Over Web Service HTTPS POST (family pattern)

References

  • acrstealer — family entity page
  • golang-stealer-build-pattern — shared build artefacts across Go infostealer families
  • prng-seeded-c2-url-decoding — runtime C2 decoding technique observed in ACR cluster
  • /intel/analyses/ef262340421fcb93d5f0c0d0bf418bc9fc6224398dda3093028ed8c97cc5bba7.html — Tenth sibling (same cert, oldest toolchain baseline)
  • /intel/analyses/b0bc17dda19e36d395e354f6a861e93a70780029bb35116ea3616e316c588710.html — Seventeenth sibling (90 randomized functions, heaviest build)
  • /intel/analyses/76a51fb7d82bcdb120f3128172ec5682f630789b8b4aa9450dc65184ea3a15e6.html — Nineteenth sibling (11 randomized functions, lightest x64 build)

Provenance

Static analysis of <sample 7945e84f9050.bin> (2,026,112 bytes). Tools: file, exiftool, pefile, strings, rabin2, binwalk, radare2 (analysis level 2, 1,501 functions recovered), Python pefile library for certificate extraction. Capa and floss failed due to environment/configuration errors, not sample obfuscation. No CAPE detonation available (no Windows guest). All C2 claims are family-inferred; no static C2 strings recovered in this sample.