typeanalysisfamilyvidarconfidencelowcreated2026-08-13updated2026-08-13pepe32plusgolanginfostealersigningobfuscationc2mitre-attck
SHA-256: 94cf86f6aab01670ea57aa08b8c531d8dbdda8cbcebbe684b08c64b5738cc819

vidar: 94cf86f6 — Go 1.25.4 x64 with quiverquant.com self-signed cert, ACR-cluster build fingerprint

Executive Summary: Go 1.25.4 PE32+ x64 infostealer with self-signed Authenticode (quiverquant.com/WE1). Build fingerprint — Go 1.25.4, quiverquant.com cert, no .rsrc, 11 randomized main.* functions — is an exact match for the acrstealer cluster. OpenCTI label vidar is contested; this is likely an ACR Stealer mislabel or shared builder pipeline.

What It Is

Field Value
SHA-256 94cf86f6aab01670ea57aa08b8c531d8dbdda8cbcebbe684b08c64b5738cc819
Filename Spectra_Menu.exe
Type PE32+ executable (GUI) x86-64, 8 sections^[file.txt]
Size 2,558,592 bytes (2.44 MB)
Compiler Go 1.25.4, CGO_ENABLED=0, -trimpath=true^[strings.txt:build-info]
Subsystem Windows GUI (no console)
Timestamp Zero (1970-01-01 00:00:00) — Go default^[pefile.txt:34]
Signing Self-signed Authenticode CN=quiverquant.com, issuer WE1, RSA-4096, SHA-256, valid May 9 – Aug 7 2026^[binwalk.txt:cert+openssl]
Family vidar (OpenCTI label; contested — see below)

Build / RE

Toolchain: Go 1.25.4 (GOOS=windows, GOARCH=amd64), CGO_ENABLED=0, -trimpath=true^[strings.txt:build-info]. Standard Go linker version 3.0^[exiftool.json]. Windows GUI subsystem with no console window.

Signing: Authenticode certificate embedded at IMAGE_DIRECTORY_ENTRY_SECURITY offset 0x270208, size 0x880^[pefile.txt]. OpenSSL parse reveals a self-signed X.509v3 certificate with Subject CN=quiverquant.com, Issuer CN=WE1, 4096-bit RSA public key, SHA-256 signature algorithm, validity window 2026-05-09 to 2026-08-07^[binwalk.txt+openssl]. This is the eighth confirmed sample in the corpus on the quiverquant.com/WE1 cert chain, all belonging to the acrstealer cluster.

Obfuscation: Eleven randomized main.* function names in the Go symbol table: Tysobt, qzgezu, Cgbcmfei, Diyhlupo, grzxpixl, Xelkvxcxucxv, Hokgtubwaqwjc, Lbbkzwnqasgzk, Zothwumtfcwfu, uospwsygwsyci, Ulowzcjdcdaemrm^[strings.txt]. No external packer; .text entropy 6.25, .rdata 7.04^[pefile.txt].

Sections: .text, .rdata, .data, .pdata, .xdata, .idata, .reloc, .symtab. Notable: .symtab is present (Go symbol table, not stripped), and there is no .rsrc section (builder stripped icon resources)^[pefile.txt].

Imports: Only kernel32.dll imported directly via IAT — 40+ APIs including VirtualAlloc, CreateThread, LoadLibraryW, GetProcAddress, SetThreadContext^[pefile.txt]. The Go runtime resolves all other APIs dynamically.

Anti-analysis: No VM detection strings, no debugger checks, no sandbox gates observed statically. Go runtime string bloat dominates strings.txt and would poison naive signature matching.

Deploy / ATT&CK

No dynamic analysis was performed (CAPE skipped — no Windows guest available)^[dynamic-analysis.md]. TTPs below are inferred from static artifacts and family behavior.

Technique ID Evidence
Data from Local System T1005 Inferred from infostealer family pattern
Input Capture: Clipboard T1115 Inferred from family behavior (crypto clipper)
Input Capture: Keylogging T1056.001 Inferred from family behavior
Screen Capture T1113 Inferred from family behavior
Credentials from Web Browsers T1555.003 Inferred from family behavior
Exfiltration Over C2 T1041 net/http + crypto/tls linkage implies HTTPS C2
Application Layer Protocol: Web T1071.001 net/http, crypto/tls standard library linkage^[strings.txt]
Native API T1106 VirtualAlloc, CreateThread, LoadLibraryW imported^[pefile.txt]

C2: No hardcoded C2 URL, IP, or domain found in static strings. The ACR/Lumma cluster uses PRNG-seeded runtime C2 decoding — this sample follows the same pattern. net/http, crypto/tls, ws2_32.dll, dnsapi.dll present in strings^[strings.txt].

Persistence: No static evidence. No registry key strings, no scheduled-task references.

Interesting Tidbits

  • Contested attribution: The quiverquant.com/WE1 certificate chain is exclusive to the ACR Stealer cluster in this corpus. Seven prior samples (c69b14a0, f668de57, 1cf857a9, 725dc07c, f258a5d7, 55c7b564, bd783215) share this exact chain. None of the prior confirmed vidar samples (3799d1f74d95, d4b6905ef14c) use this certificate. This suggests either an OpenCTI label collision or a shared crypter/builder service.
  • No .rsrc: The builder optionally strips the .rsrc icon section. Prior ACR siblings c69b14a0 and cdd16fc0 also lack .rsrc, confirming builder toggle behavior.
  • Go 1.25.4 timestamp zero: Go compiler defaults to epoch timestamp, which anti-forensics tools sometimes mistake for "packed."
  • GUI subsystem: Masquerades as a legitimate Windows application (Spectra_Menu.exe).

Deployable Signatures

YARA rule:

rule Go_ACR_Cluster_Quiverquant_WE1 {
    meta:
        description = "Go infostealer with quiverquant.com self-signed cert"
        author = "PacketPursuit"
        date = "2026-08-13"
    strings:
        $go_build = "go1.25.4" ascii
        $cert_cn = "quiverquant.com" ascii wide
        $cert_issuer = "WE1" ascii wide
        $trimpath = "-trimpath=true" ascii
    condition:
        uint16(0) == 0x5A4D and
        $go_build and
        ($cert_cn or $cert_issuer) and
        $trimpath
}

Behavioral fingerprint: PE32+ x64 Go 1.25.4 binary with zero PE timestamp, self-signed Authenticode CN=quiverquant.com/issuer=WE1, no .rsrc section or stripped .rsrc, 10-15 randomized main.* function names in Go symtab, and no static C2 strings. Network-capable via Go net/http + crypto/tls but all C2 resolved at runtime via PRNG seed.

IOCs:

  • Certificate: CN=quiverquant.com, Issuer=WE1, RSA-4096, SHA-256, validity ~3 months
  • Hash: 94cf86f6aab01670ea57aa08b8c531d8dbdda8cbcebbe684b08c64b5738cc819

References

Provenance

Artifacts from wiki/wiki/raw/analyses/94cf86f6aab01670ea57aa08b8c531d8dbdda8cbcebbe684b08c64b5738cc819/: file.txt, pefile.txt, strings.txt, exiftool.json, binwalk.txt, rabin2-info.txt, triage.json. Certificate parsed with OpenSSL from raw PE. Static-only; no CAPE detonation.