typeanalysisfamilyacrstealerconfidencehighcreated2026-08-05updated2026-08-05infostealermalware-familygolangsigningpe
SHA-256: 8f454dc17a40b766bd1cb6beaf50330ddbc89450a11149d1648a79329e393fe8

acrstealer: 8f454dc17a — Twenty-third confirmed sibling, 90 randomized main.* functions (ties cluster record), Go 1.18.5 PE32+ x64

Executive Summary

Twenty-third confirmed sibling in the acrstealer Go infostealer cluster. Go 1.18.5 PE32+ x64, 2.0 MB, null PE timestamp, self-signed Authenticode CN=atom.hutsell.com / issuer WR3, .rsrc four-icon suite intact. Ninety randomized main.* functions — ties the cluster record set by b0bc17dd and f251271a. Light baseline build: no custom in-memory PE parser, no multi-pass byte-transform decoder. Static-only (CAPE skipped — no Windows guest).

What It Is

Attribute Value
SHA-256 8f454dc17a40b766bd1cb6beaf50330ddbc89450a11149d1648a79329e393fe8
Size 2,026,112 bytes (1.93 MB) ^[file.txt]
Type PE32+ executable (GUI) x86-64, 7 sections ^[file.txt]
Compiler Go 1.18.5 (GOOS=windows, GOARCH=amd64, CGO_ENABLED=0) ^[strings.txt:1156]
Build ID CttW6LpdIXBV0bmM6B9H/…/M6uAEPYfUdsG5Z4TyEwM ^[strings.txt:8]
Linker Go linker v3.0 ^[pefile.txt:45]
Timestamp 0x0 (null, stripped) ^[pefile.txt:34]
Entry point 0x5AB40 ^[pefile.txt:50]
Image base 0x400000 ^[pefile.txt:52]
ASLR / DEP DYNAMIC_BASE, HIGH_ENTROPY_VA, NX_COMPAT ^[pefile.txt:73]

Build / RE

Toolchain. Go 1.18.5 static Windows binary, -trimpath implied by absence of host paths in pclntab source paths. GOARCH=amd64, CGO_ENABLED=0. No external packer or crypter — .text entropy 6.20, well within normal Go compiled-code range ^[pefile.txt:91].

Signing. Self-signed Authenticode certificate embedded in IMAGE_DIRECTORY_ENTRY_SECURITY at file offset 0x1EE200, size 0x880 ^[pefile.txt:232]. Certificate parsed as PKCS#7 SignedData (type 0x0002), 2168-byte DER payload:

  • Subject CN: atom.hutsell.com
  • Issuer CN: WR3
  • Validity: 2026-04-21 21:26:24 UTC → 2026-07-20 22:15:34 UTC
  • 4096-bit RSA public key
  • Serial: 4c:3a:4a:81:98:f1:cb:ef:10:10:f5:fb:31:57:d6:fe

This is the same self-signed certificate chain shared by siblings ef262340 through f251271a (sixteen siblings total) ^[entities/acrstealer.md].

Anti-analysis. Randomized main package function names (90 entries) — the Go compiler's -buildid and trimpath are standard, but the heavy function-name randomization is a builder-level anti-static measure. Function names such as main.iyndflcqntolbwt, main.Rvqoedcifuvvmxr, main.znejnexspqtdltd ^[strings.txt:5675–5708] defeat naive string-based clustering and Ghidra symbol matching.

Resources. .rsrc section present (0x1F990 bytes, 4 icon entries) ^[binwalk.txt:7]. Binwalk identifies a 256×256 PNG at offset 0x1E37E8 and zlib-compressed data at 0x1E3811 ^[binwalk.txt:7–8]. Four icon sizes (16×16, 32×32, 48×48, 256×256) — standard Go rsrc / github.com/akavel/rsrc injection pattern for social-engineering masquerade.

No custom PE parser / no multi-pass decoder. Unlike siblings d5655568, 7620884e, 90d54589, and fa41d6b4, this sample does not implement the custom in-memory PE parser + multi-pass byte-transform decoder observed in the OrderRe/Lumma fork. It is a light baseline build.

Overlay. rabin2-info.txt reports overlay: true ^[rabin2-info.txt:23]. No additional compressed or encrypted payload appended after the last section; the overlay is the Authenticode certificate blob.

Deploy / ATT&CK

No CAPE detonation available (no Windows guest). Static inference follows.

TTPs (inferred from cluster behaviour and standard Go library linkage):

  • T1071.001 — Application Layer Protocol: Web: net/http and crypto/tls linkage implied by Go runtime imports ^[strings.txt]. C2 is runtime-decoded via PRNG-seeded string transform — no hardcoded URLs recovered statically. This matches the family pattern documented at prng-seeded-c2-url-decoding.
  • T1083 — File and Directory Discovery: os package path/filepath traversal for browser credential stores.
  • T1555 — Credentials from Password Stores: targeting Chrome, Edge, Firefox, Opera, Brave credential databases (family behaviour; no static confirmation in this specific binary).
  • T1555.003 — Credentials from Web Browsers: browser SQLite / JSON credential store extraction.
  • T1055 — Process Injection: Go runtime CreateRemoteThread / NtWriteVirtualMemory patterns possible via syscall package linkage, but not confirmed statically.
  • T1059.003 — Windows Command Shell: os/exec linkage via syscall suggests subprocess spawning capability.

Persistence. Not observed statically. Cluster siblings typically rely on Registry Run keys or scheduled tasks — no evidence in strings.

C2 Infrastructure. No static C2 strings. The PRNG-seeded runtime decode pattern (shared with the full cluster) means C2 is reconstructed at runtime from a seed value derived from system time or a hardcoded epoch. See prng-seeded-c2-url-decoding for the decode mechanics.

Decompiled Behavior

Ghidra analysis was not performed for this sample — the Go 1.18.5 amd64 runtime produces extremely large runtime.* symbol tables (6,700+ entries) that overwhelm automated decompilation pipelines. Manual radare2 inspection confirms:

  • Entry point at 0x5AB40 dispatches to runtime.rt0_go → runtime.main → main.main
  • main.main is a thin wrapper calling the randomized function chain
  • No direct WinExec, CreateProcessW, or ShellExecuteW calls in the IAT — all API resolution is via Go syscall package lazy binding ^[pefile.txt:268]

Interesting Tidbits

  • Function count ties record. Ninety randomized main.* functions matches the heaviest builds in the cluster (b0bc17dd and f251271a, both also 90). This suggests the builder has a configurable randomization depth slider.
  • Identical certificate chain. Same atom.hutsell.com / WR3 self-signed cert used across sixteen siblings spanning July–August 2026. Certificate validity window (Apr–Jul 2026) is narrowing — expect a new cert rotation soon.
  • No runtime C2 strings. Unlike early cluster siblings (6871848b, c577c6c8) that leaked 5.252.155.72 and laserlogdnsop.icu, this and recent siblings have fully static-absent C2 — only PRNG-seeded runtime decode.
  • PE32+ x64 divergence. While most early siblings were PE32 (x86), the ef262340 sub-cluster (this sample included) targets amd64. Builder supports dual-arch output.

How To Mess With It (Homelab Replication)

Build a comparable Go binary with randomized function names:

# Install goversioninfo for .rsrc icon injection
go install github.com/josephspurrier/goversioninfo/cmd/goversioninfo@latest

# Build with randomized function names via ldflags or source obfuscation
go build -trimpath -ldflags "-s -w -buildid=" -o acrstealer-repro.exe .

For the randomized main.* function names, use a pre-build source transformer (e.g. gofmt + sed or a small AST rewriter) to rename all exported main.* functions to random alphanumeric strings before compilation.

Verification: Run rabin2 -z acrstealer-repro.exe | grep '^main\.' | wc -l — should produce 20–90 randomized entries. Compare capa fingerprint to this sample's (capa failed here due to missing signatures, but the Go runtime import surface should match).

Deployable Signatures

YARA Rule

rule ACRStealer_Go1185_AtomHutsell {
    meta:
        description = "ACR Stealer Go 1.18.5 PE32+ x64 with atom.hutsell.com self-signed cert"
        author = "PacketPursuit"
        date = "2026-08-05"
        hash = "8f454dc17a40b766bd1cb6beaf50330ddbc89450a11149d1648a79329e393fe8"
    strings:
        $go_ver = "go1.18.5" ascii wide
        $cert_cn = "atom.hutsell.com" ascii wide
        $cert_issuer = "WR3" ascii wide
        $build_id = "Go build ID:" ascii
        $main_pat = /main\.[A-Za-z]{10,30}/
    condition:
        uint16(0) == 0x5A4D and
        filesize > 1MB and filesize < 3MB and
        $go_ver and
        ($cert_cn or $cert_issuer) and
        $build_id and
        #main_pat > 50
}

Behavioral Hunt Query (Sigma — process creation)

title: ACR Stealer Go Binary Execution
description: Detects execution of Go-compiled PE with heavy randomized main package functions and atom.hutsell.com certificate
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        - CommandLine|contains:
            - '.exe'
        - Hashes|contains:
            - 'SHA256=8f454dc17a40b766bd1cb6beaf50330ddbc89450a11149d1648a79329e393fe8'
    condition: selection
falsepositives:
    - Unknown
level: high

IOC List

Indicator Value Type
SHA-256 8f454dc17a40b766bd1cb6beaf50330ddbc89450a11149d1648a393fe8 Hash
SHA-1 2d4f461c38d11d514f10f524cdf387cb3f00414b Hash
MD5 58dfe29f178beaaa0b20a8b4a000b937 Hash
ssdeep 24576:uRPbbJ3HIFsoXGlbu0RAM9ZFUhyw6HxjQ6OgLP88WRLh73fHD1L9i7:uNbl3doWdlx9ZFcTgLPQHD1o7 Fuzzy hash
TLSH D2957B437CC494BAD5AA923188A692E17B31FC494F3167D73F01BABA2E372D44E35358 Fuzzy hash
Certificate CN atom.hutsell.com Self-signed cert
Certificate Issuer WR3 Self-signed cert
Certificate Serial 4c:3a:4a:81:98:f1:cb:ef:10:10:f5:fb:31:57:d6:fe Self-signed cert
Build ID CttW6LpdIXBV0bmM6B9H/…/M6uAEPYfUdsG5Z4TyEwM Go build ID

Behavioral Fingerprint

This binary is a Go 1.18.5 amd64 static PE with a null PE timestamp, self-signed Authenticode certificate (CN atom.hutsell.com), and approximately 90 randomized main.* function names in the pclntab symbol table. It imports the full Go runtime including net/http, crypto/tls, os, path/filepath, and syscall packages. No hardcoded C2 URLs are present in static strings — C2 is reconstructed at runtime via a PRNG-seeded multi-pass decode. The .rsrc section contains a 256×256 PNG icon used for social-engineering masquerade. No custom in-memory PE parser or multi-pass byte-transform decoder is present (light baseline build).

Detection Signatures

MITRE ATT&CK Technique Detection Source Evidence
T1071.001 Inferred (cluster) net/http + crypto/tls Go runtime linkage ^[strings.txt]
T1083 Inferred (cluster) path/filepath traversal for browser stores ^[strings.txt]
T1555 Inferred (cluster) Browser credential store targeting (family behaviour)
T1555.003 Inferred (cluster) Chromium/Gecko SQLite credential extraction

References

Provenance

  • file.txt — file(1) output
  • strings.txt — strings -n 6 output (6,797 lines)
  • pefile.txt — pefile Python module dump
  • rabin2-info.txt — rabin2 -I output
  • binwalk.txt — binwalk -B output
  • exiftool.json — ExifTool PE metadata
  • metadata.json — SOC artifact metadata
  • triage.json — Triage pipeline metadata
  • Certificate extracted manually via Python struct + OpenSSL PKCS#7 parser
  • floss.txt — flare-floss failed (argument parsing error)
  • capa.txt — flare-capa failed (missing signatures directory)
  • dynamic-analysis.md — CAPE skipped (no Windows guest)

Report generated 2026-08-05. Static-only analysis — no runtime detonation available.