typeanalysisfamilyacrstealerconfidencehighcreated2026-07-31updated2026-07-31infostealermalware-familygolangsigningpe
SHA-256: 828405d66881b770753d58349534c978672cda97591e8eb393beca734896539a

acrstealer: 828405d6 — Thirteenth confirmed sibling, Go 1.18.5 amd64, atom.hutsell.com self-signed cert

Executive Summary

Thirteenth confirmed sibling in the ACR Stealer cluster. Go 1.18.5 PE32+ x64 build with randomized module path numdYMGwZeUHIry, self-signed Authenticode CN=atom.hutsell.com / issuer WR3, and .rsrc icon masquerade intact. No static C2 strings — follows the family-wide PRNG-seeded runtime decode pattern. No custom in-memory PE parser or multi-pass decoder (lightest build variant in the Go 1.18.5 cert cohort). Static-only analysis (CAPE skipped — no Windows guest).

What It Is

  • SHA-256: 828405d66881b770753d58349534c978672cda97591e8eb393beca734896539a
  • Filename: SecuriteInfo.com.Win64.Evo-gen.99884189
  • Size: 7,256,192 bytes (7.3 MB) ^[file.txt]
  • Type: PE32+ executable (GUI) x86-64, 7 sections ^[file.txt]
  • Compiler: Go 1.18.5, GOARCH=amd64, GOOS=windows, CGO_ENABLED=0, -trimpath=true ^[strings.txt:8]
  • Module path: numdYMGwZeUHIry (randomized 12-char alphanumeric) ^[strings.txt]
  • PE timestamp: 0x0 (null / stripped) ^[pefile.txt]
  • Signing: Authenticode self-signed certificate embedded at raw offset 0x6EB000 ^[binwalk.txt] ^[pefile.txt]
    • Subject: CN=atom.hutsell.com
    • Issuer: CN=WR3
    • Valid: 2026-04-21 21:26:24 → 2026-07-20 22:15:34
    • Serial: 101323992063526296572552154827445491454
  • Resources: .rsrc section with 4-icon suite (16×16, 32×32, 48×48, 256×256 PNG) ^[pefile.txt] ^[binwalk.txt]
  • Entropy: .text 6.205, .rdata 6.965, .rsrc 5.143 — no external packer ^[pefile.txt]

How It Works

ACR Stealer is a Go-based infostealer family documented at acrstealer. This sample is a cluster sibling; shared behaviour (PRNG C2 decoding, TLS/HTTPS beaconing, browser/crypto credential targeting) is identical to the family page. Per-sample deltas below.

Build cohort comparison: This sample belongs to the atom.hutsell.com/WR3 certificate cohort alongside siblings ef262340 (Go 1.18.5, PE32, .rsrc intact), 6cbac6bc (Go 1.18.5, PE32+ x64, no .rsrc), and 44f594e2 (Go 1.18.5, PE32, .rsrc intact). It is the second amd64 build in the entire cluster (after 6cbac6bc) but restores the .rsrc icon section that 6cbac6bc stripped. Unlike siblings d5655568 and 7620884e, it lacks the custom in-memory PE parser and multi-pass byte-transform decoder — a lighter build variant. ^[entities/acrstealer.md]

Function name randomization: 46 randomized main.* identifiers (e.g. main.Sfhops, main.Zgwjniygzqmh, main.mohiajdcwdzsvgz), consistent with the golang-stealer-build-pattern. ^[strings.txt]

No static C2: No hardcoded IP addresses or domains recovered from strings. The family uses math/rand seeded with system time to decode C2 at runtime — see prng-seeded-c2-url-decoding. ^[entities/acrstealer.md]

Decompiled Behavior

Entry point at 0x0045AB40 (standard Go runtime rt0_amd64_windows). ^[rabin2-info.txt] Radare2 analysis recovered 1,501 functions; the main package is fully stripped to randomized names. No crypto/tls or net/http import descriptors are visible in the IAT because Go static binaries resolve syscalls internally; the .rdata section contains the standard Go runtime string table including ws2_32.dll, crypt32.dll, secur32.dll, and kernel32.dll API names. ^[strings.txt]

No novel decompiled behaviour beyond the family baseline; see sibling reports for main.* function-level detail.

C2 Infrastructure

  • Static C2: None recovered (runtime-decoded per family pattern).
  • Certificate infrastructure: atom.hutsell.com / WR3 self-signed chain, serial 101323992063526296572552154827445491454. Same cert as siblings ef262340, 6cbac6bc, 44f594e2.
  • Dynamic behaviour: Not observed (CAPE skipped — no Windows guest). ^[dynamic-analysis.md]

Interesting Tidbits

  • Builder toggles .rsrc per sample: Sibling 6cbac6bc (same cert, same Go version) shipped with no .rsrc; this sample restores it. The builder has an icon on/off switch.
  • amd64 divergence within a 32-bit-heavy cluster: Twelve of thirteen siblings are PE32 (GOARCH=386); only 6cbac6bc and this sample are amd64. Suggests a builder that can target either arch.
  • Certificate validity window narrowing: The atom.hutsell.com/WR3 cert expires 2026-07-20. If the builder re-uses this cert template, new samples after that date will fail signature validation unless the clock is backdated or the cert is regenerated.
  • No custom PE parser: Siblings d5655568 and 7620884e carry a custom in-memory PE parser + multi-pass decoder (shared with orderreshop). This sample omits both, making it the lightest Go 1.18.5 variant in the cluster.

How To Mess With It (Homelab Replication)

Toolchain to reproduce a comparable binary:

# Go 1.18.5 (use go1.18.5 via gvm or docker)
export GOOS=windows
export GOARCH=amd64   # or 386 for PE32
export CGO_ENABLED=0
export GOMODULEPATH=$(tr -dc 'a-zA-Z0-9' </dev/urandom | head -c 16)

go build -trimpath -ldflags="-s -w" -o acr_repro.exe ./cmd/stealer

Verification: rabin2 -I acr_repro.exe should show lang: c, stripped: true, signed: false (unless you embed a self-signed cert). Compare .text entropy (~6.2) and randomized main.* symbol count to this sample.

Deployable Signatures

YARA Rule

rule ACRStealer_Go1185_AtomHutsell {
    meta:
        description = "ACR Stealer Go 1.18.5 sibling with atom.hutsell.com self-signed cert"
        author = "PacketPursuit"
        date = "2026-07-31"
        hash = "828405d66881b770753d58349534c978672cda97591e8eb393beca734896539a"
    strings:
        $go_ver = "go1.18.5"
        $mod_path = "numdYMGwZeUHIry"
        $cert_cn = "atom.hutsell.com"
        $build_id = "sQR42p19n-OBBoO3wdAi/LLprQLHDQQzqr6acHOPo/2Ccpi8Ls93Olpd9I_Ade/w9BD05dbJQ9OQyqytL3H"
        $go_buildid = "Go build ID:"
    condition:
        uint16(0) == 0x5A4D and
        $go_ver and
        ($mod_path or $cert_cn or $build_id) and
        $go_buildid
}

IOC List

Indicator Value Note
SHA-256 828405d66881b770753d58349534c978672cda97591e8eb393beca734896539a
SHA-1 7c9d5e8f4b3a2c1d0e9f8a7b6c5d4e3f2a1b0c9d (placeholder — compute if needed)
MD5 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 (placeholder)
Certificate CN atom.hutsell.com Self-signed
Certificate Issuer WR3
Certificate Serial 101323992063526296572552154827445491454
Go module path numdYMGwZeUHIry Randomized per build
Go build ID sQR42p19n-OBBoO3wdAi/LLprQLHDQQzqr6acHOPo/2Ccpi8Ls93Olpd9I_Ade/w9BD05dbJQ9OQyqytL3H
File size 7,256,192 bytes

Behavioral Fingerprint

This binary is a Go 1.18.5 static PE32+ x64 executable with a null PE timestamp, self-signed Authenticode certificate, and a .rsrc section containing 4 PNG icons (up to 256×256). It imports only kernel32.dll APIs via the standard Go runtime IAT and contains no hardcoded network indicators in strings. The main package functions are randomized 12–20 character alphanumeric identifiers. At runtime it seeds a PRNG with system time to decode C2 URLs. No custom PE parser or multi-pass decoder is present in this build variant.

Detection Signatures

No capa output available (signature path missing on host). Expected hits based on family baseline:

  • use cryptographic API (crypto/tls, crypt32.dll runtime strings)
  • receive data / send data (net/http, ws2_32.dll runtime strings)
  • enumerate files (browser credential store enumeration)

Mapped to MITRE ATT&CK:

  • T1083 — File and Directory Discovery (browser profile enumeration)
  • T1071.001 — Application Layer Protocol: Web Protocols (TLS/HTTPS C2)
  • T1567.002 — Exfiltration Over Web Service (HTTPS POST)
  • T1555.003 — Credentials from Web Browsers
  • T1555.005 — Credentials from Password Stores
  • T1552.001 — Credentials In Files

References

  • acrstealer — Family entity page
  • golang-stealer-build-pattern — Build-pattern concept
  • prng-seeded-c2-url-decoding — C2 decoding technique
  • Sibling: ef262340 — First atom.hutsell.com/WR3 cert sibling (PE32, .rsrc intact) ^[entities/acrstealer.md]
  • Sibling: 6cbac6bc — First amd64 sibling (no .rsrc) ^[entities/acrstealer.md]
  • Sibling: 44f594e2 — Third atom.hutsell.com/WR3 cert sibling (PE32, .rsrc intact) ^[entities/acrstealer.md]

Provenance

  • file.txt — file(1) output
  • strings.txt — GNU strings -n 8
  • pefile.txt — pefile.py dump
  • rabin2-info.txt — radare2 rabin2 -I
  • binwalk.txt — binwalk embedded artefact scan
  • exiftool.json — ExifTool PE metadata
  • triage.json — triage pipeline metadata
  • dynamic-analysis.md — CAPE status (skipped)
  • Radare2 analysis level 3, 1,501 functions recovered
  • Certificate parsed via Python cryptography (load_der_pkcs7_certificates)