94cf86f6aab01670ea57aa08b8c531d8dbdda8cbcebbe684b08c64b5738cc819vidar: 94cf86f6 — Go 1.25.4 x64 with quiverquant.com self-signed cert, ACR-cluster build fingerprint
Executive Summary: Go 1.25.4 PE32+ x64 infostealer with self-signed Authenticode (quiverquant.com/WE1). Build fingerprint — Go 1.25.4, quiverquant.com cert, no .rsrc, 11 randomized main.* functions — is an exact match for the acrstealer cluster. OpenCTI label vidar is contested; this is likely an ACR Stealer mislabel or shared builder pipeline.
What It Is
| Field | Value |
|---|---|
| SHA-256 | 94cf86f6aab01670ea57aa08b8c531d8dbdda8cbcebbe684b08c64b5738cc819 |
| Filename | Spectra_Menu.exe |
| Type | PE32+ executable (GUI) x86-64, 8 sections^[file.txt] |
| Size | 2,558,592 bytes (2.44 MB) |
| Compiler | Go 1.25.4, CGO_ENABLED=0, -trimpath=true^[strings.txt:build-info] |
| Subsystem | Windows GUI (no console) |
| Timestamp | Zero (1970-01-01 00:00:00) — Go default^[pefile.txt:34] |
| Signing | Self-signed Authenticode CN=quiverquant.com, issuer WE1, RSA-4096, SHA-256, valid May 9 – Aug 7 2026^[binwalk.txt:cert+openssl] |
| Family | vidar (OpenCTI label; contested — see below) |
Build / RE
Toolchain: Go 1.25.4 (GOOS=windows, GOARCH=amd64), CGO_ENABLED=0, -trimpath=true^[strings.txt:build-info]. Standard Go linker version 3.0^[exiftool.json]. Windows GUI subsystem with no console window.
Signing: Authenticode certificate embedded at IMAGE_DIRECTORY_ENTRY_SECURITY offset 0x270208, size 0x880^[pefile.txt]. OpenSSL parse reveals a self-signed X.509v3 certificate with Subject CN=quiverquant.com, Issuer CN=WE1, 4096-bit RSA public key, SHA-256 signature algorithm, validity window 2026-05-09 to 2026-08-07^[binwalk.txt+openssl]. This is the eighth confirmed sample in the corpus on the quiverquant.com/WE1 cert chain, all belonging to the acrstealer cluster.
Obfuscation: Eleven randomized main.* function names in the Go symbol table: Tysobt, qzgezu, Cgbcmfei, Diyhlupo, grzxpixl, Xelkvxcxucxv, Hokgtubwaqwjc, Lbbkzwnqasgzk, Zothwumtfcwfu, uospwsygwsyci, Ulowzcjdcdaemrm^[strings.txt]. No external packer; .text entropy 6.25, .rdata 7.04^[pefile.txt].
Sections: .text, .rdata, .data, .pdata, .xdata, .idata, .reloc, .symtab. Notable: .symtab is present (Go symbol table, not stripped), and there is no .rsrc section (builder stripped icon resources)^[pefile.txt].
Imports: Only kernel32.dll imported directly via IAT — 40+ APIs including VirtualAlloc, CreateThread, LoadLibraryW, GetProcAddress, SetThreadContext^[pefile.txt]. The Go runtime resolves all other APIs dynamically.
Anti-analysis: No VM detection strings, no debugger checks, no sandbox gates observed statically. Go runtime string bloat dominates strings.txt and would poison naive signature matching.
Deploy / ATT&CK
No dynamic analysis was performed (CAPE skipped — no Windows guest available)^[dynamic-analysis.md]. TTPs below are inferred from static artifacts and family behavior.
| Technique | ID | Evidence |
|---|---|---|
| Data from Local System | T1005 | Inferred from infostealer family pattern |
| Input Capture: Clipboard | T1115 | Inferred from family behavior (crypto clipper) |
| Input Capture: Keylogging | T1056.001 | Inferred from family behavior |
| Screen Capture | T1113 | Inferred from family behavior |
| Credentials from Web Browsers | T1555.003 | Inferred from family behavior |
| Exfiltration Over C2 | T1041 | net/http + crypto/tls linkage implies HTTPS C2 |
| Application Layer Protocol: Web | T1071.001 | net/http, crypto/tls standard library linkage^[strings.txt] |
| Native API | T1106 | VirtualAlloc, CreateThread, LoadLibraryW imported^[pefile.txt] |
C2: No hardcoded C2 URL, IP, or domain found in static strings. The ACR/Lumma cluster uses PRNG-seeded runtime C2 decoding — this sample follows the same pattern. net/http, crypto/tls, ws2_32.dll, dnsapi.dll present in strings^[strings.txt].
Persistence: No static evidence. No registry key strings, no scheduled-task references.
Interesting Tidbits
- Contested attribution: The
quiverquant.com/WE1certificate chain is exclusive to the ACR Stealer cluster in this corpus. Seven prior samples (c69b14a0,f668de57,1cf857a9,725dc07c,f258a5d7,55c7b564,bd783215) share this exact chain. None of the prior confirmedvidarsamples (3799d1f74d95,d4b6905ef14c) use this certificate. This suggests either an OpenCTI label collision or a shared crypter/builder service. - No
.rsrc: The builder optionally strips the.rsrcicon section. Prior ACR siblingsc69b14a0andcdd16fc0also lack.rsrc, confirming builder toggle behavior. - Go 1.25.4 timestamp zero: Go compiler defaults to epoch timestamp, which anti-forensics tools sometimes mistake for "packed."
- GUI subsystem: Masquerades as a legitimate Windows application (
Spectra_Menu.exe).
Deployable Signatures
YARA rule:
rule Go_ACR_Cluster_Quiverquant_WE1 {
meta:
description = "Go infostealer with quiverquant.com self-signed cert"
author = "PacketPursuit"
date = "2026-08-13"
strings:
$go_build = "go1.25.4" ascii
$cert_cn = "quiverquant.com" ascii wide
$cert_issuer = "WE1" ascii wide
$trimpath = "-trimpath=true" ascii
condition:
uint16(0) == 0x5A4D and
$go_build and
($cert_cn or $cert_issuer) and
$trimpath
}
Behavioral fingerprint: PE32+ x64 Go 1.25.4 binary with zero PE timestamp, self-signed Authenticode CN=quiverquant.com/issuer=WE1, no .rsrc section or stripped .rsrc, 10-15 randomized main.* function names in Go symtab, and no static C2 strings. Network-capable via Go net/http + crypto/tls but all C2 resolved at runtime via PRNG seed.
IOCs:
- Certificate: CN=
quiverquant.com, Issuer=WE1, RSA-4096, SHA-256, validity ~3 months - Hash:
94cf86f6aab01670ea57aa08b8c531d8dbdda8cbcebbe684b08c64b5738cc819
References
- vidar — entity page (contested attribution)
- acrstealer — matching cluster (Go 1.25.4, same cert chain)
- golang-stealer-build-pattern — build-pattern concept
- prng-seeded-c2-url-decoding — C2 decode technique
Provenance
Artifacts from wiki/wiki/raw/analyses/94cf86f6aab01670ea57aa08b8c531d8dbdda8cbcebbe684b08c64b5738cc819/: file.txt, pefile.txt, strings.txt, exiftool.json, binwalk.txt, rabin2-info.txt, triage.json. Certificate parsed with OpenSSL from raw PE. Static-only; no CAPE detonation.