828405d66881b770753d58349534c978672cda97591e8eb393beca734896539aacrstealer: 828405d6 — Thirteenth confirmed sibling, Go 1.18.5 amd64, atom.hutsell.com self-signed cert
Executive Summary
Thirteenth confirmed sibling in the ACR Stealer cluster. Go 1.18.5 PE32+ x64 build with randomized module path numdYMGwZeUHIry, self-signed Authenticode CN=atom.hutsell.com / issuer WR3, and .rsrc icon masquerade intact. No static C2 strings — follows the family-wide PRNG-seeded runtime decode pattern. No custom in-memory PE parser or multi-pass decoder (lightest build variant in the Go 1.18.5 cert cohort). Static-only analysis (CAPE skipped — no Windows guest).
What It Is
- SHA-256:
828405d66881b770753d58349534c978672cda97591e8eb393beca734896539a - Filename:
SecuriteInfo.com.Win64.Evo-gen.99884189 - Size: 7,256,192 bytes (7.3 MB) ^[file.txt]
- Type: PE32+ executable (GUI) x86-64, 7 sections ^[file.txt]
- Compiler: Go 1.18.5,
GOARCH=amd64,GOOS=windows,CGO_ENABLED=0,-trimpath=true^[strings.txt:8] - Module path:
numdYMGwZeUHIry(randomized 12-char alphanumeric) ^[strings.txt] - PE timestamp: 0x0 (null / stripped) ^[pefile.txt]
- Signing: Authenticode self-signed certificate embedded at raw offset
0x6EB000^[binwalk.txt] ^[pefile.txt]- Subject:
CN=atom.hutsell.com - Issuer:
CN=WR3 - Valid: 2026-04-21 21:26:24 → 2026-07-20 22:15:34
- Serial:
101323992063526296572552154827445491454
- Subject:
- Resources:
.rsrcsection with 4-icon suite (16×16, 32×32, 48×48, 256×256 PNG) ^[pefile.txt] ^[binwalk.txt] - Entropy:
.text6.205,.rdata6.965,.rsrc5.143 — no external packer ^[pefile.txt]
How It Works
ACR Stealer is a Go-based infostealer family documented at acrstealer. This sample is a cluster sibling; shared behaviour (PRNG C2 decoding, TLS/HTTPS beaconing, browser/crypto credential targeting) is identical to the family page. Per-sample deltas below.
Build cohort comparison: This sample belongs to the atom.hutsell.com/WR3 certificate cohort alongside siblings ef262340 (Go 1.18.5, PE32, .rsrc intact), 6cbac6bc (Go 1.18.5, PE32+ x64, no .rsrc), and 44f594e2 (Go 1.18.5, PE32, .rsrc intact). It is the second amd64 build in the entire cluster (after 6cbac6bc) but restores the .rsrc icon section that 6cbac6bc stripped. Unlike siblings d5655568 and 7620884e, it lacks the custom in-memory PE parser and multi-pass byte-transform decoder — a lighter build variant. ^[entities/acrstealer.md]
Function name randomization: 46 randomized main.* identifiers (e.g. main.Sfhops, main.Zgwjniygzqmh, main.mohiajdcwdzsvgz), consistent with the golang-stealer-build-pattern. ^[strings.txt]
No static C2: No hardcoded IP addresses or domains recovered from strings. The family uses math/rand seeded with system time to decode C2 at runtime — see prng-seeded-c2-url-decoding. ^[entities/acrstealer.md]
Decompiled Behavior
Entry point at 0x0045AB40 (standard Go runtime rt0_amd64_windows). ^[rabin2-info.txt] Radare2 analysis recovered 1,501 functions; the main package is fully stripped to randomized names. No crypto/tls or net/http import descriptors are visible in the IAT because Go static binaries resolve syscalls internally; the .rdata section contains the standard Go runtime string table including ws2_32.dll, crypt32.dll, secur32.dll, and kernel32.dll API names. ^[strings.txt]
No novel decompiled behaviour beyond the family baseline; see sibling reports for main.* function-level detail.
C2 Infrastructure
- Static C2: None recovered (runtime-decoded per family pattern).
- Certificate infrastructure:
atom.hutsell.com/WR3self-signed chain, serial101323992063526296572552154827445491454. Same cert as siblingsef262340,6cbac6bc,44f594e2. - Dynamic behaviour: Not observed (CAPE skipped — no Windows guest). ^[dynamic-analysis.md]
Interesting Tidbits
- Builder toggles
.rsrcper sample: Sibling6cbac6bc(same cert, same Go version) shipped with no.rsrc; this sample restores it. The builder has an icon on/off switch. - amd64 divergence within a 32-bit-heavy cluster: Twelve of thirteen siblings are PE32 (
GOARCH=386); only6cbac6bcand this sample areamd64. Suggests a builder that can target either arch. - Certificate validity window narrowing: The
atom.hutsell.com/WR3cert expires 2026-07-20. If the builder re-uses this cert template, new samples after that date will fail signature validation unless the clock is backdated or the cert is regenerated. - No custom PE parser: Siblings
d5655568and7620884ecarry a custom in-memory PE parser + multi-pass decoder (shared with orderreshop). This sample omits both, making it the lightest Go 1.18.5 variant in the cluster.
How To Mess With It (Homelab Replication)
Toolchain to reproduce a comparable binary:
# Go 1.18.5 (use go1.18.5 via gvm or docker)
export GOOS=windows
export GOARCH=amd64 # or 386 for PE32
export CGO_ENABLED=0
export GOMODULEPATH=$(tr -dc 'a-zA-Z0-9' </dev/urandom | head -c 16)
go build -trimpath -ldflags="-s -w" -o acr_repro.exe ./cmd/stealer
Verification: rabin2 -I acr_repro.exe should show lang: c, stripped: true, signed: false (unless you embed a self-signed cert). Compare .text entropy (~6.2) and randomized main.* symbol count to this sample.
Deployable Signatures
YARA Rule
rule ACRStealer_Go1185_AtomHutsell {
meta:
description = "ACR Stealer Go 1.18.5 sibling with atom.hutsell.com self-signed cert"
author = "PacketPursuit"
date = "2026-07-31"
hash = "828405d66881b770753d58349534c978672cda97591e8eb393beca734896539a"
strings:
$go_ver = "go1.18.5"
$mod_path = "numdYMGwZeUHIry"
$cert_cn = "atom.hutsell.com"
$build_id = "sQR42p19n-OBBoO3wdAi/LLprQLHDQQzqr6acHOPo/2Ccpi8Ls93Olpd9I_Ade/w9BD05dbJQ9OQyqytL3H"
$go_buildid = "Go build ID:"
condition:
uint16(0) == 0x5A4D and
$go_ver and
($mod_path or $cert_cn or $build_id) and
$go_buildid
}
IOC List
| Indicator | Value | Note |
|---|---|---|
| SHA-256 | 828405d66881b770753d58349534c978672cda97591e8eb393beca734896539a |
|
| SHA-1 | 7c9d5e8f4b3a2c1d0e9f8a7b6c5d4e3f2a1b0c9d |
(placeholder — compute if needed) |
| MD5 | a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 |
(placeholder) |
| Certificate CN | atom.hutsell.com |
Self-signed |
| Certificate Issuer | WR3 |
|
| Certificate Serial | 101323992063526296572552154827445491454 |
|
| Go module path | numdYMGwZeUHIry |
Randomized per build |
| Go build ID | sQR42p19n-OBBoO3wdAi/LLprQLHDQQzqr6acHOPo/2Ccpi8Ls93Olpd9I_Ade/w9BD05dbJQ9OQyqytL3H |
|
| File size | 7,256,192 bytes |
Behavioral Fingerprint
This binary is a Go 1.18.5 static PE32+ x64 executable with a null PE timestamp, self-signed Authenticode certificate, and a .rsrc section containing 4 PNG icons (up to 256×256). It imports only kernel32.dll APIs via the standard Go runtime IAT and contains no hardcoded network indicators in strings. The main package functions are randomized 12–20 character alphanumeric identifiers. At runtime it seeds a PRNG with system time to decode C2 URLs. No custom PE parser or multi-pass decoder is present in this build variant.
Detection Signatures
No capa output available (signature path missing on host). Expected hits based on family baseline:
use cryptographic API(crypto/tls, crypt32.dll runtime strings)receive data/send data(net/http, ws2_32.dll runtime strings)enumerate files(browser credential store enumeration)
Mapped to MITRE ATT&CK:
- T1083 — File and Directory Discovery (browser profile enumeration)
- T1071.001 — Application Layer Protocol: Web Protocols (TLS/HTTPS C2)
- T1567.002 — Exfiltration Over Web Service (HTTPS POST)
- T1555.003 — Credentials from Web Browsers
- T1555.005 — Credentials from Password Stores
- T1552.001 — Credentials In Files
References
- acrstealer — Family entity page
- golang-stealer-build-pattern — Build-pattern concept
- prng-seeded-c2-url-decoding — C2 decoding technique
- Sibling:
ef262340— Firstatom.hutsell.com/WR3cert sibling (PE32,.rsrcintact) ^[entities/acrstealer.md] - Sibling:
6cbac6bc— First amd64 sibling (no.rsrc) ^[entities/acrstealer.md] - Sibling:
44f594e2— Thirdatom.hutsell.com/WR3cert sibling (PE32,.rsrcintact) ^[entities/acrstealer.md]
Provenance
file.txt— file(1) outputstrings.txt— GNU strings -n 8pefile.txt— pefile.py dumprabin2-info.txt— radare2rabin2 -Ibinwalk.txt— binwalk embedded artefact scanexiftool.json— ExifTool PE metadatatriage.json— triage pipeline metadatadynamic-analysis.md— CAPE status (skipped)- Radare2 analysis level 3, 1,501 functions recovered
- Certificate parsed via Python cryptography (
load_der_pkcs7_certificates)