typeanalysisfamilylummastealerconfidencehighinfostealermalware-familygolangsigningobfuscation
SHA-256: 9ca2ebb826a8d0de58eea5a1afb5f6f76adb3938feef9604725508452b0a2e08

lummastealer: 9ca2ebb8 — x64 morph, 71-function namespace, placeholder xxx.com cert, 726 KB null-padded overlay

Executive Summary: Go 1.25.4 PE32+ x64 infostealer, sixteenth confirmed sibling in the Lumma cluster. Shares the xxx.com/E7 placeholder-cert sub-cluster with 2120b8b7 (PE32), eaa52e19 (PE32+ x64), and c25d9423 (PE32+ x64). Features 71 randomized main.* functions (matching eaa52e19 density), a main.tehakink.func1 goroutine closure, five-icon .rsrc suite, and a 726 KB null-padded overlay (99.7% zeros). Static-only (CAPE skipped — no Windows guest).

What It Is

  • File: PE32+ executable (GUI) x86-64, 9 sections, 3.2 MB ^[file.txt]
  • Compiler: Go 1.25.4 (go1.25.4 string at lines 1510, 5278) ^[strings.txt:1510] ^[strings.txt:5278]; null PE timestamp (Thu Jan 1 00:00:00 1970) ^[pefile.txt:34]; Go build ID: "_OPp4nbvTYZzssJQSw2w/VnfQkw0t_EbVTgQRBwGx/KZ0dGe_SwpOKt5AOlv4a/RR_sZRz3sa05NG9SJtH6" ^[strings.txt:10]
  • Signing: Authenticode WIN_CERT type 2 (PKCS_SIGNED_DATA) at RVA 0x311C00, size 0x880 ^[pefile.txt:272]. Self-signed placeholder certificate CN=xxx.com, issuer CN=E7, validity 22 May 2026 → 20 Aug 2026 (3 months) ^[terminal:openssl-x509]. Same cert as sub-cluster siblings 2120b8b7, eaa52e19, and c25d9423.
  • Obfuscation: 71 randomized main.* function names (e.g., main.ypoybojmgxjho, main.nwgmnowwjyzqsd, main.jctsywriw, main.opmuigpgwmps, main.Xtohcuvbd, main.ocgqunngrflss, main.whqkjlhlklkemvf, main.zqpnmjwvgjkq, main.vadetuewj, main.pamittcul, main.reysjokco, main.tehakink, main.tehakink.func1, main.xkzwhdzixuox, main.gtgqyeoyzlupqkf, main.rlnnldjboxzdwlt) ^[strings.txt:4567-4601]
  • Resources: Five PNG icons in .rsrc (16×16, 32×32, 64×64, 128×128, 256×256 RGBA) ^[binwalk.txt]
  • Overlay: 726,144 bytes after last section (.rsrc), entropy 0.0516, 99.7% zero bytes. Builder padding artefact, not encrypted payload. ^[terminal:python-overlay]
  • Build ID: Unique; does not match any prior sibling in the cluster.

How It Works

Standard Go runtime.main bootstrap → main.main entry. The binary is statically linked (no CGO) with the full Go runtime (net/http, crypto/tls, syscall, os, sync/atomic, internal/chacha8rand, math/rand, time, bytes, bufio) ^[strings.txt].

Goroutine concurrency (main.tehakink.func1)

main.tehakink has a child symbol main.tehakink.func1 — an anonymous Go closure emitted by the compiler when a goroutine is spawned inside a parent function. This matches the pattern first observed in sibling c25d9423 (main.xregypl.func1) and confirms the builder now routinely emits goroutine-based concurrency primitives in the main payload path ^[r2:xrefs-to sym.main.tehakink.func1]. The goroutine likely handles C2 beaconing or exfiltration in parallel with credential harvesting.

PRNG sleep gate

main.main seeds math/rand with time.Now().Unix() and time.Now().UnixNano(), then enters nested PRNG loops generating randomized float values. Constants observed in decompilation: 0x408f4000 (1000.0), 0x40a77000 (3000.0), 0x4034000000000000, 0x400999999999999a — producing sleep delays consistent with the 800–4000 second gate pattern observed across the cluster ^[r2:sym.main.main @ 0x14008ef40].

Fused-string API decoder

The cluster's characteristic fused-string API decoding is inferred from .rdata content: DLL+API names are concatenated into indivisible blobs and sliced at runtime via strings.SplitN and strconv.ParseFloat, defeating naive string-based signatures ^[fused-string-api-decoding].

Decompiled Behavior

Radare2 analysis (level 3, 1938 functions) identifies lang: go, signed: true, overlay: true ^[rabin2-info.txt]. Entry point 0x1400715a0 falls inside .text at offset 0x715a0, consistent with Go rt0_amd64_windows. main.main at 0x14008ef40 performs PRNG seeding, sleep-gate computation, and dispatches into randomized payload functions sym.main.ocgqunngrflss, sym.main.whqkjlhlklkemvf, sym.main.ezynrcnf, and sym.main.rlnnldjboxzdwlt ^[r2:sym.main.main]. No full decompilation of inner payload functions was obtained due to Go runtime noise; behaviour is inferred from cluster pattern and xref analysis.

C2 Infrastructure

No static C2 recovered. The Lumma cluster uses runtime PRNG-seeded C2 URL decoding (see prng-seeded-c2-url-decoding). No hardcoded IP, domain, URL, Telegram Bot API token, Discord webhook, or SMTP credentials found.

Interesting Tidbits

  • .text hash unique: SHA-256 prefix d6cc47c000245a5a does not match any prior Lumma sibling, confirming a distinct x64 build template. ^[terminal:python-text-hash]
  • 71 main.* functions: Matches eaa52e19 (also 71 functions) as the densest x64 namespace in the cluster. The builder supports variable density (27–130 functions observed). ^[strings.txt:4567-4601]
  • Placeholder-cert sub-cluster: The xxx.com/E7 cert links this sample to 2120b8b7 (PE32), eaa52e19 (x64), and c25d9423 (x64), distinct from the blizzard-tecnica.com and www.sjabr.org cert sub-clusters. ^[terminal:openssl-x509]
  • 726 KB null-padded overlay: Smaller than eaa52e19's 1 MB overlay but same artefact (99.7% zeros, entropy 0.0516). Likely builder padding to obfuscate true file size or an uninitialized buffer. ^[terminal:python-overlay]
  • Five-icon .rsrc suite: Same dimensions and count as the xxx.com cert sub-cluster siblings. Builder icon-toggle is consistent. ^[binwalk.txt]
  • .symtab present: Not stripped; radare2 Go analysis works without issue. Not UPX-packed.

How To Mess With It (Homelab Replication)

  1. Install Go 1.25.4, set GOOS=windows, GOARCH=amd64, CGO_ENABLED=0.
  2. Build a minimal Go PE with randomized function names (go build -trimpath -ldflags "-s -w -H=windowsgui").
  3. Use garble or go-obfuscator to rename main.* functions.
  4. Generate a self-signed Authenticode cert with openssl req -x509 -newkey rsa:2048 -subj "/CN=xxx.com" and sign with osslsigncode.
  5. Embed PNG icons via goversioninfo or rsrc.
  6. Append a 726 KB zero buffer to the PE to replicate the overlay artefact.
  7. Verify with rabin2 -I that lang: go, signed: true, and overlay: true are reported.
  8. Inspect go tool objdump to see .func1 closure emission for goroutines.

Deployable Signatures

YARA Rule

rule LummaStealer_Go_x64_PlaceholderCert_NullOverlay {
    meta:
        author = "PacketPursuit"
        description = "Lumma/ACR Go infostealer x64 morph with xxx.com placeholder cert and null-padded overlay"
        family = "lummastealer"
        hash = "9ca2ebb826a8d0de58eea5a1afb5f6f76adb3938feef9604725508452b0a2e08"
    strings:
        $go_buildid = "Go build ID:" ascii
        $go125 = "go1.25.4" ascii
        $placeholder_cn = "xxx.com" ascii
        $main_prefix = "main." ascii
        $goroutine = ".func1" ascii
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)) == 0x00004550 and
        uint16(uint32(0x3C)+0x18) == 0x020B and  // PE32+ (x64)
        $go_buildid and
        $go125 and
        $placeholder_cn and
        $main_prefix and
        $goroutine and
        filesize > 3MB and
        filesize < 4MB
}

Behavioral Hunt Query (KQL/SPL)

// Hunt for Lumma/ACR Go x64 stealer variants
process_name="*.exe" AND 
(pe_info.compiler="go" OR pe_info.linker_version="3.0") AND
pe_info.arch="x64" AND
(filesize > 3MB AND filesize < 4MB) AND
pe_info.cert_subject CONTAINS "xxx.com"

IOC List

  • SHA-256: 9ca2ebb826a8d0de58eea5a1afb5f6f76adb3938feef9604725508452b0a2e08
  • SHA-1: 3e99c87081f1a8091931a670858e8fef8982ecbd (.text section)
  • MD5: 4c4308ccb50801f88f198647a58a2135 (.text section)
  • Certificate Subject: CN=xxx.com
  • Certificate Issuer: CN=E7
  • Certificate Validity: 2026-05-22 to 2026-08-20
  • PE Checksum: 0x31BC65
  • Build ID: _OPp4nbvTYZzssJQSw2w/VnfQkw0t_EbVTgQRBwGx/KZ0dGe_SwpOKt5AOlv4a/RR_sZRz3sa05NG9SJtH6
  • File Size: 3,220,608 bytes
  • Overlay Entropy: ~0.05 (indicative of null padding)
  • .text Section Hash (SHA-256 prefix): d6cc47c000245a5a

Behavioral Fingerprint

This binary is a Go 1.25.4-compiled PE32+ x64 executable with a null PE timestamp, placeholder self-signed Authenticode certificate (CN xxx.com), and a 700+ KB null-padded overlay (entropy <0.1). It contains 60–80 randomized main.* functions with .func1 goroutine closures, seeds math/rand from system time in main.main, and dispatches into payload functions with no static C2 strings. The .rsrc section contains five PNG icons (16×16 through 256×256). No hardcoded network IOCs are present; C2 is decoded at runtime via PRNG-seeded transform.

Detection Signatures

No capa output available (signatures not installed at analysis time). Expected ATT&CK mappings based on cluster pattern:

  • T1055 — Process Injection (RWX VirtualAlloc reflective staging, inferred)
  • T1027 — Obfuscated Files or Information (PRNG C2 decoding, randomized function names)
  • T1071.001 — Application Layer Protocol: Web Protocols (HTTPS C2 via net/http, inferred)
  • T1005 — Data from Local System (credential harvesting, inferred)
  • T1083 — File and Directory Discovery (system info gathering, inferred)
  • T1497.001 — Virtualization/Sandbox Evasion: Time-Based Evasion (PRNG sleep gate)

References

Provenance

Analysis derived from static artefacts: file.txt, pefile.txt, strings.txt, rabin2-info.txt, binwalk.txt, exiftool.json, metadata.json, triage.json. Capa signatures were unavailable at analysis time. FLOSS failed due to incorrect CLI invocation. CAPE skipped — no Windows guest. Radare2 analysis level 3 (1938 functions). OpenSSL used for certificate extraction at offset 0x311C9D. Python used for overlay entropy and tail analysis.