8f454dc17a40b766bd1cb6beaf50330ddbc89450a11149d1648a79329e393fe8acrstealer: 8f454dc17a — Twenty-third confirmed sibling, 90 randomized main.* functions (ties cluster record), Go 1.18.5 PE32+ x64
Executive Summary
Twenty-third confirmed sibling in the acrstealer Go infostealer cluster. Go 1.18.5 PE32+ x64, 2.0 MB, null PE timestamp, self-signed Authenticode CN=atom.hutsell.com / issuer WR3, .rsrc four-icon suite intact. Ninety randomized main.* functions — ties the cluster record set by b0bc17dd and f251271a. Light baseline build: no custom in-memory PE parser, no multi-pass byte-transform decoder. Static-only (CAPE skipped — no Windows guest).
What It Is
| Attribute | Value |
|---|---|
| SHA-256 | 8f454dc17a40b766bd1cb6beaf50330ddbc89450a11149d1648a79329e393fe8 |
| Size | 2,026,112 bytes (1.93 MB) ^[file.txt] |
| Type | PE32+ executable (GUI) x86-64, 7 sections ^[file.txt] |
| Compiler | Go 1.18.5 (GOOS=windows, GOARCH=amd64, CGO_ENABLED=0) ^[strings.txt:1156] |
| Build ID | CttW6LpdIXBV0bmM6B9H/…/M6uAEPYfUdsG5Z4TyEwM ^[strings.txt:8] |
| Linker | Go linker v3.0 ^[pefile.txt:45] |
| Timestamp | 0x0 (null, stripped) ^[pefile.txt:34] |
| Entry point | 0x5AB40 ^[pefile.txt:50] |
| Image base | 0x400000 ^[pefile.txt:52] |
| ASLR / DEP | DYNAMIC_BASE, HIGH_ENTROPY_VA, NX_COMPAT ^[pefile.txt:73] |
Build / RE
Toolchain. Go 1.18.5 static Windows binary, -trimpath implied by absence of host paths in pclntab source paths. GOARCH=amd64, CGO_ENABLED=0. No external packer or crypter — .text entropy 6.20, well within normal Go compiled-code range ^[pefile.txt:91].
Signing. Self-signed Authenticode certificate embedded in IMAGE_DIRECTORY_ENTRY_SECURITY at file offset 0x1EE200, size 0x880 ^[pefile.txt:232]. Certificate parsed as PKCS#7 SignedData (type 0x0002), 2168-byte DER payload:
- Subject CN:
atom.hutsell.com - Issuer CN:
WR3 - Validity: 2026-04-21 21:26:24 UTC → 2026-07-20 22:15:34 UTC
- 4096-bit RSA public key
- Serial:
4c:3a:4a:81:98:f1:cb:ef:10:10:f5:fb:31:57:d6:fe
This is the same self-signed certificate chain shared by siblings ef262340 through f251271a (sixteen siblings total) ^[entities/acrstealer.md].
Anti-analysis. Randomized main package function names (90 entries) — the Go compiler's -buildid and trimpath are standard, but the heavy function-name randomization is a builder-level anti-static measure. Function names such as main.iyndflcqntolbwt, main.Rvqoedcifuvvmxr, main.znejnexspqtdltd ^[strings.txt:5675–5708] defeat naive string-based clustering and Ghidra symbol matching.
Resources. .rsrc section present (0x1F990 bytes, 4 icon entries) ^[binwalk.txt:7]. Binwalk identifies a 256×256 PNG at offset 0x1E37E8 and zlib-compressed data at 0x1E3811 ^[binwalk.txt:7–8]. Four icon sizes (16×16, 32×32, 48×48, 256×256) — standard Go rsrc / github.com/akavel/rsrc injection pattern for social-engineering masquerade.
No custom PE parser / no multi-pass decoder. Unlike siblings d5655568, 7620884e, 90d54589, and fa41d6b4, this sample does not implement the custom in-memory PE parser + multi-pass byte-transform decoder observed in the OrderRe/Lumma fork. It is a light baseline build.
Overlay. rabin2-info.txt reports overlay: true ^[rabin2-info.txt:23]. No additional compressed or encrypted payload appended after the last section; the overlay is the Authenticode certificate blob.
Deploy / ATT&CK
No CAPE detonation available (no Windows guest). Static inference follows.
TTPs (inferred from cluster behaviour and standard Go library linkage):
- T1071.001 — Application Layer Protocol: Web:
net/httpandcrypto/tlslinkage implied by Go runtime imports ^[strings.txt]. C2 is runtime-decoded via PRNG-seeded string transform — no hardcoded URLs recovered statically. This matches the family pattern documented at prng-seeded-c2-url-decoding. - T1083 — File and Directory Discovery:
ospackage path/filepath traversal for browser credential stores. - T1555 — Credentials from Password Stores: targeting Chrome, Edge, Firefox, Opera, Brave credential databases (family behaviour; no static confirmation in this specific binary).
- T1555.003 — Credentials from Web Browsers: browser SQLite / JSON credential store extraction.
- T1055 — Process Injection: Go runtime
CreateRemoteThread/NtWriteVirtualMemorypatterns possible viasyscallpackage linkage, but not confirmed statically. - T1059.003 — Windows Command Shell:
os/execlinkage viasyscallsuggests subprocess spawning capability.
Persistence. Not observed statically. Cluster siblings typically rely on Registry Run keys or scheduled tasks — no evidence in strings.
C2 Infrastructure. No static C2 strings. The PRNG-seeded runtime decode pattern (shared with the full cluster) means C2 is reconstructed at runtime from a seed value derived from system time or a hardcoded epoch. See prng-seeded-c2-url-decoding for the decode mechanics.
Decompiled Behavior
Ghidra analysis was not performed for this sample — the Go 1.18.5 amd64 runtime produces extremely large runtime.* symbol tables (6,700+ entries) that overwhelm automated decompilation pipelines. Manual radare2 inspection confirms:
- Entry point at
0x5AB40dispatches toruntime.rt0_go→runtime.main→main.main main.mainis a thin wrapper calling the randomized function chain- No direct
WinExec,CreateProcessW, orShellExecuteWcalls in the IAT — all API resolution is via Gosyscallpackage lazy binding ^[pefile.txt:268]
Interesting Tidbits
- Function count ties record. Ninety randomized
main.*functions matches the heaviest builds in the cluster (b0bc17ddandf251271a, both also 90). This suggests the builder has a configurable randomization depth slider. - Identical certificate chain. Same
atom.hutsell.com/WR3self-signed cert used across sixteen siblings spanning July–August 2026. Certificate validity window (Apr–Jul 2026) is narrowing — expect a new cert rotation soon. - No runtime C2 strings. Unlike early cluster siblings (
6871848b,c577c6c8) that leaked5.252.155.72andlaserlogdnsop.icu, this and recent siblings have fully static-absent C2 — only PRNG-seeded runtime decode. - PE32+ x64 divergence. While most early siblings were PE32 (x86), the
ef262340sub-cluster (this sample included) targetsamd64. Builder supports dual-arch output.
How To Mess With It (Homelab Replication)
Build a comparable Go binary with randomized function names:
# Install goversioninfo for .rsrc icon injection
go install github.com/josephspurrier/goversioninfo/cmd/goversioninfo@latest
# Build with randomized function names via ldflags or source obfuscation
go build -trimpath -ldflags "-s -w -buildid=" -o acrstealer-repro.exe .
For the randomized main.* function names, use a pre-build source transformer (e.g. gofmt + sed or a small AST rewriter) to rename all exported main.* functions to random alphanumeric strings before compilation.
Verification: Run rabin2 -z acrstealer-repro.exe | grep '^main\.' | wc -l — should produce 20–90 randomized entries. Compare capa fingerprint to this sample's (capa failed here due to missing signatures, but the Go runtime import surface should match).
Deployable Signatures
YARA Rule
rule ACRStealer_Go1185_AtomHutsell {
meta:
description = "ACR Stealer Go 1.18.5 PE32+ x64 with atom.hutsell.com self-signed cert"
author = "PacketPursuit"
date = "2026-08-05"
hash = "8f454dc17a40b766bd1cb6beaf50330ddbc89450a11149d1648a79329e393fe8"
strings:
$go_ver = "go1.18.5" ascii wide
$cert_cn = "atom.hutsell.com" ascii wide
$cert_issuer = "WR3" ascii wide
$build_id = "Go build ID:" ascii
$main_pat = /main\.[A-Za-z]{10,30}/
condition:
uint16(0) == 0x5A4D and
filesize > 1MB and filesize < 3MB and
$go_ver and
($cert_cn or $cert_issuer) and
$build_id and
#main_pat > 50
}
Behavioral Hunt Query (Sigma — process creation)
title: ACR Stealer Go Binary Execution
description: Detects execution of Go-compiled PE with heavy randomized main package functions and atom.hutsell.com certificate
logsource:
category: process_creation
product: windows
detection:
selection:
- CommandLine|contains:
- '.exe'
- Hashes|contains:
- 'SHA256=8f454dc17a40b766bd1cb6beaf50330ddbc89450a11149d1648a79329e393fe8'
condition: selection
falsepositives:
- Unknown
level: high
IOC List
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | 8f454dc17a40b766bd1cb6beaf50330ddbc89450a11149d1648a393fe8 |
Hash |
| SHA-1 | 2d4f461c38d11d514f10f524cdf387cb3f00414b |
Hash |
| MD5 | 58dfe29f178beaaa0b20a8b4a000b937 |
Hash |
| ssdeep | 24576:uRPbbJ3HIFsoXGlbu0RAM9ZFUhyw6HxjQ6OgLP88WRLh73fHD1L9i7:uNbl3doWdlx9ZFcTgLPQHD1o7 |
Fuzzy hash |
| TLSH | D2957B437CC494BAD5AA923188A692E17B31FC494F3167D73F01BABA2E372D44E35358 |
Fuzzy hash |
| Certificate CN | atom.hutsell.com |
Self-signed cert |
| Certificate Issuer | WR3 |
Self-signed cert |
| Certificate Serial | 4c:3a:4a:81:98:f1:cb:ef:10:10:f5:fb:31:57:d6:fe |
Self-signed cert |
| Build ID | CttW6LpdIXBV0bmM6B9H/…/M6uAEPYfUdsG5Z4TyEwM |
Go build ID |
Behavioral Fingerprint
This binary is a Go 1.18.5 amd64 static PE with a null PE timestamp, self-signed Authenticode certificate (CN atom.hutsell.com), and approximately 90 randomized main.* function names in the pclntab symbol table. It imports the full Go runtime including net/http, crypto/tls, os, path/filepath, and syscall packages. No hardcoded C2 URLs are present in static strings — C2 is reconstructed at runtime via a PRNG-seeded multi-pass decode. The .rsrc section contains a 256×256 PNG icon used for social-engineering masquerade. No custom in-memory PE parser or multi-pass byte-transform decoder is present (light baseline build).
Detection Signatures
| MITRE ATT&CK Technique | Detection Source | Evidence |
|---|---|---|
| T1071.001 | Inferred (cluster) | net/http + crypto/tls Go runtime linkage ^[strings.txt] |
| T1083 | Inferred (cluster) | path/filepath traversal for browser stores ^[strings.txt] |
| T1555 | Inferred (cluster) | Browser credential store targeting (family behaviour) |
| T1555.003 | Inferred (cluster) | Chromium/Gecko SQLite credential extraction |
References
- Artifact ID:
5d3573c5-3b95-4aca-94d1-3e9c1b9350b3 - OpenCTI labels:
acrstealer,exe,urlhaus - Family entity: acrstealer
- Build pattern: golang-stealer-build-pattern
- Related technique: prng-seeded-c2-url-decoding
Provenance
file.txt—file(1)outputstrings.txt—strings -n 6output (6,797 lines)pefile.txt—pefilePython module dumprabin2-info.txt—rabin2 -Ioutputbinwalk.txt—binwalk -Boutputexiftool.json— ExifTool PE metadatametadata.json— SOC artifact metadatatriage.json— Triage pipeline metadata- Certificate extracted manually via Python
struct+ OpenSSL PKCS#7 parser floss.txt— flare-floss failed (argument parsing error)capa.txt— flare-capa failed (missing signatures directory)dynamic-analysis.md— CAPE skipped (no Windows guest)
Report generated 2026-08-05. Static-only analysis — no runtime detonation available.