9ca2ebb826a8d0de58eea5a1afb5f6f76adb3938feef9604725508452b0a2e08lummastealer: 9ca2ebb8 — x64 morph, 71-function namespace, placeholder xxx.com cert, 726 KB null-padded overlay
Executive Summary: Go 1.25.4 PE32+ x64 infostealer, sixteenth confirmed sibling in the Lumma cluster. Shares the xxx.com/E7 placeholder-cert sub-cluster with 2120b8b7 (PE32), eaa52e19 (PE32+ x64), and c25d9423 (PE32+ x64). Features 71 randomized main.* functions (matching eaa52e19 density), a main.tehakink.func1 goroutine closure, five-icon .rsrc suite, and a 726 KB null-padded overlay (99.7% zeros). Static-only (CAPE skipped — no Windows guest).
What It Is
- File: PE32+ executable (GUI) x86-64, 9 sections, 3.2 MB ^[file.txt]
- Compiler: Go 1.25.4 (
go1.25.4string at lines 1510, 5278) ^[strings.txt:1510] ^[strings.txt:5278]; null PE timestamp (Thu Jan 1 00:00:00 1970) ^[pefile.txt:34];Go build ID: "_OPp4nbvTYZzssJQSw2w/VnfQkw0t_EbVTgQRBwGx/KZ0dGe_SwpOKt5AOlv4a/RR_sZRz3sa05NG9SJtH6"^[strings.txt:10] - Signing: Authenticode WIN_CERT type 2 (PKCS_SIGNED_DATA) at RVA
0x311C00, size0x880^[pefile.txt:272]. Self-signed placeholder certificate CN=xxx.com, issuerCN=E7, validity 22 May 2026 → 20 Aug 2026 (3 months) ^[terminal:openssl-x509]. Same cert as sub-cluster siblings2120b8b7,eaa52e19, andc25d9423. - Obfuscation: 71 randomized
main.*function names (e.g.,main.ypoybojmgxjho,main.nwgmnowwjyzqsd,main.jctsywriw,main.opmuigpgwmps,main.Xtohcuvbd,main.ocgqunngrflss,main.whqkjlhlklkemvf,main.zqpnmjwvgjkq,main.vadetuewj,main.pamittcul,main.reysjokco,main.tehakink,main.tehakink.func1,main.xkzwhdzixuox,main.gtgqyeoyzlupqkf,main.rlnnldjboxzdwlt) ^[strings.txt:4567-4601] - Resources: Five PNG icons in
.rsrc(16×16, 32×32, 64×64, 128×128, 256×256 RGBA) ^[binwalk.txt] - Overlay: 726,144 bytes after last section (
.rsrc), entropy 0.0516, 99.7% zero bytes. Builder padding artefact, not encrypted payload. ^[terminal:python-overlay] - Build ID: Unique; does not match any prior sibling in the cluster.
How It Works
Standard Go runtime.main bootstrap → main.main entry. The binary is statically linked (no CGO) with the full Go runtime (net/http, crypto/tls, syscall, os, sync/atomic, internal/chacha8rand, math/rand, time, bytes, bufio) ^[strings.txt].
Goroutine concurrency (main.tehakink.func1)
main.tehakink has a child symbol main.tehakink.func1 — an anonymous Go closure emitted by the compiler when a goroutine is spawned inside a parent function. This matches the pattern first observed in sibling c25d9423 (main.xregypl.func1) and confirms the builder now routinely emits goroutine-based concurrency primitives in the main payload path ^[r2:xrefs-to sym.main.tehakink.func1]. The goroutine likely handles C2 beaconing or exfiltration in parallel with credential harvesting.
PRNG sleep gate
main.main seeds math/rand with time.Now().Unix() and time.Now().UnixNano(), then enters nested PRNG loops generating randomized float values. Constants observed in decompilation: 0x408f4000 (1000.0), 0x40a77000 (3000.0), 0x4034000000000000, 0x400999999999999a — producing sleep delays consistent with the 800–4000 second gate pattern observed across the cluster ^[r2:sym.main.main @ 0x14008ef40].
Fused-string API decoder
The cluster's characteristic fused-string API decoding is inferred from .rdata content: DLL+API names are concatenated into indivisible blobs and sliced at runtime via strings.SplitN and strconv.ParseFloat, defeating naive string-based signatures ^[fused-string-api-decoding].
Decompiled Behavior
Radare2 analysis (level 3, 1938 functions) identifies lang: go, signed: true, overlay: true ^[rabin2-info.txt]. Entry point 0x1400715a0 falls inside .text at offset 0x715a0, consistent with Go rt0_amd64_windows. main.main at 0x14008ef40 performs PRNG seeding, sleep-gate computation, and dispatches into randomized payload functions sym.main.ocgqunngrflss, sym.main.whqkjlhlklkemvf, sym.main.ezynrcnf, and sym.main.rlnnldjboxzdwlt ^[r2:sym.main.main]. No full decompilation of inner payload functions was obtained due to Go runtime noise; behaviour is inferred from cluster pattern and xref analysis.
C2 Infrastructure
No static C2 recovered. The Lumma cluster uses runtime PRNG-seeded C2 URL decoding (see prng-seeded-c2-url-decoding). No hardcoded IP, domain, URL, Telegram Bot API token, Discord webhook, or SMTP credentials found.
Interesting Tidbits
.texthash unique: SHA-256 prefixd6cc47c000245a5adoes not match any prior Lumma sibling, confirming a distinct x64 build template. ^[terminal:python-text-hash]- 71
main.*functions: Matcheseaa52e19(also 71 functions) as the densest x64 namespace in the cluster. The builder supports variable density (27–130 functions observed). ^[strings.txt:4567-4601] - Placeholder-cert sub-cluster: The
xxx.com/E7cert links this sample to2120b8b7(PE32),eaa52e19(x64), andc25d9423(x64), distinct from theblizzard-tecnica.comandwww.sjabr.orgcert sub-clusters. ^[terminal:openssl-x509] - 726 KB null-padded overlay: Smaller than
eaa52e19's 1 MB overlay but same artefact (99.7% zeros, entropy 0.0516). Likely builder padding to obfuscate true file size or an uninitialized buffer. ^[terminal:python-overlay] - Five-icon
.rsrcsuite: Same dimensions and count as thexxx.comcert sub-cluster siblings. Builder icon-toggle is consistent. ^[binwalk.txt] .symtabpresent: Not stripped; radare2 Go analysis works without issue. Not UPX-packed.
How To Mess With It (Homelab Replication)
- Install Go 1.25.4, set
GOOS=windows,GOARCH=amd64,CGO_ENABLED=0. - Build a minimal Go PE with randomized function names (
go build -trimpath -ldflags "-s -w -H=windowsgui"). - Use
garbleorgo-obfuscatorto renamemain.*functions. - Generate a self-signed Authenticode cert with
openssl req -x509 -newkey rsa:2048 -subj "/CN=xxx.com"and sign withosslsigncode. - Embed PNG icons via
goversioninfoorrsrc. - Append a 726 KB zero buffer to the PE to replicate the overlay artefact.
- Verify with
rabin2 -Ithatlang: go,signed: true, andoverlay: trueare reported. - Inspect
go tool objdumpto see.func1closure emission for goroutines.
Deployable Signatures
YARA Rule
rule LummaStealer_Go_x64_PlaceholderCert_NullOverlay {
meta:
author = "PacketPursuit"
description = "Lumma/ACR Go infostealer x64 morph with xxx.com placeholder cert and null-padded overlay"
family = "lummastealer"
hash = "9ca2ebb826a8d0de58eea5a1afb5f6f76adb3938feef9604725508452b0a2e08"
strings:
$go_buildid = "Go build ID:" ascii
$go125 = "go1.25.4" ascii
$placeholder_cn = "xxx.com" ascii
$main_prefix = "main." ascii
$goroutine = ".func1" ascii
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C)) == 0x00004550 and
uint16(uint32(0x3C)+0x18) == 0x020B and // PE32+ (x64)
$go_buildid and
$go125 and
$placeholder_cn and
$main_prefix and
$goroutine and
filesize > 3MB and
filesize < 4MB
}
Behavioral Hunt Query (KQL/SPL)
// Hunt for Lumma/ACR Go x64 stealer variants
process_name="*.exe" AND
(pe_info.compiler="go" OR pe_info.linker_version="3.0") AND
pe_info.arch="x64" AND
(filesize > 3MB AND filesize < 4MB) AND
pe_info.cert_subject CONTAINS "xxx.com"
IOC List
- SHA-256:
9ca2ebb826a8d0de58eea5a1afb5f6f76adb3938feef9604725508452b0a2e08 - SHA-1:
3e99c87081f1a8091931a670858e8fef8982ecbd(.textsection) - MD5:
4c4308ccb50801f88f198647a58a2135(.textsection) - Certificate Subject:
CN=xxx.com - Certificate Issuer:
CN=E7 - Certificate Validity: 2026-05-22 to 2026-08-20
- PE Checksum:
0x31BC65 - Build ID:
_OPp4nbvTYZzssJQSw2w/VnfQkw0t_EbVTgQRBwGx/KZ0dGe_SwpOKt5AOlv4a/RR_sZRz3sa05NG9SJtH6 - File Size: 3,220,608 bytes
- Overlay Entropy: ~0.05 (indicative of null padding)
.textSection Hash (SHA-256 prefix):d6cc47c000245a5a
Behavioral Fingerprint
This binary is a Go 1.25.4-compiled PE32+ x64 executable with a null PE timestamp, placeholder self-signed Authenticode certificate (CN xxx.com), and a 700+ KB null-padded overlay (entropy <0.1). It contains 60–80 randomized main.* functions with .func1 goroutine closures, seeds math/rand from system time in main.main, and dispatches into payload functions with no static C2 strings. The .rsrc section contains five PNG icons (16×16 through 256×256). No hardcoded network IOCs are present; C2 is decoded at runtime via PRNG-seeded transform.
Detection Signatures
No capa output available (signatures not installed at analysis time). Expected ATT&CK mappings based on cluster pattern:
- T1055 — Process Injection (RWX
VirtualAllocreflective staging, inferred) - T1027 — Obfuscated Files or Information (PRNG C2 decoding, randomized function names)
- T1071.001 — Application Layer Protocol: Web Protocols (HTTPS C2 via
net/http, inferred) - T1005 — Data from Local System (credential harvesting, inferred)
- T1083 — File and Directory Discovery (system info gathering, inferred)
- T1497.001 — Virtualization/Sandbox Evasion: Time-Based Evasion (PRNG sleep gate)
References
- lummastealer — Cluster entity page
- golang-stealer-build-pattern — Shared Go infostealer build artefacts
- acrstealer — Sibling cluster with shared toolchain
- prng-seeded-c2-url-decoding — Technique page for runtime C2 decoding
- fused-string-api-decoding — Technique page for runtime API string fusion
Provenance
Analysis derived from static artefacts: file.txt, pefile.txt, strings.txt, rabin2-info.txt, binwalk.txt, exiftool.json, metadata.json, triage.json. Capa signatures were unavailable at analysis time. FLOSS failed due to incorrect CLI invocation. CAPE skipped — no Windows guest. Radare2 analysis level 3 (1938 functions). OpenSSL used for certificate extraction at offset 0x311C9D. Python used for overlay entropy and tail analysis.