a02296ceeb8f1419fe18a4376ce3b563e5de0fe8d85e7bf1b8461784d3c17992acrstealer: a02296ce — Go 1.20.6 signed sibling, GlobalSign DV TLS cert, 34 randomized main functions
Executive Summary
Go 1.20.6 PE32 infostealer sibling of the acrstealer cluster, masquerading as CuService.exe and signed with a valid GlobalSign DV TLS certificate (CN=seekingalpha.com). Thirty-four randomized main.* functions, randomized module path XXjuhfDdZFXrSHR, two-icon .rsrc suite, and no static C2 — all consistent with the ACR baseline. Static-only analysis (CAPE skipped — no Windows guest). Resolves from contested OpenCTI label cloud55file-cc.
What It Is
- SHA-256:
a02296ceeb8f1419fe18a4376ce3b563e5de0fe8d85e7bf1b8461784d3c17992 - Filename:
CuService.exe^[file.txt] - Type: PE32 executable (GUI) Intel 80386, 7 sections, stripped to external PDB ^[file.txt]
- Size: 1 703 112 bytes
- Timestamp:
0x0(Thu Jan 1 00:00:00 1970 UTC) — null, typical of Go-trimpathbuilds ^[pefile.txt:34] - Family: acrstealer (resolved from OpenCTI
cloud55file-cccontested label) - Dynamic analysis: skipped — no CAPE Windows guest available ^[dynamic-analysis.md]
How It Works
This is a cluster sibling; shared behavior (PRNG-seeded C2 decoding, browser/wallet credential targeting, TLS/HTTPS exfil) is documented on acrstealer. Per-sample deltas below.
Build / RE Lens
Toolchain: Go 1.20.6 (go1.20.6), gc compiler, -buildmode=exe, -trimpath=true, CGO_ENABLED=0, GOARCH=386, GOOS=windows, GO386=sse2 ^[strings.txt:944] ^[strings.txt:948–954]. No external packer or crypter — .text entropy 6.11, within normal range for Go static binaries ^[pefile.txt:92].
Signing: Authenticode-signed with a valid GlobalSign DV TLS certificate embedded in IMAGE_DIRECTORY_ENTRY_SECURITY (offset 0x19F408, size 0x8C8) ^[binwalk.txt] ^[pefile.txt:232–234]. Inner X.509:
- Subject:
CN = seekingalpha.com - Issuer:
CN = GlobalSign Atlas R3 DV TLS CA 2025 Q4 - Validity: Dec 9 2025 — Jan 10 2027
- SHA-256 fingerprint:
0D:15:42:B8:AD:6F:4F:7F:F2:01:66:8D:32:15:59:69:BF:67:F3:A8:2E:18:39:1D:0E:87:1F:9F:1C:BE:6B:92
This is a TLS certificate chain reused for code signing, same chain observed on ACR sibling f0105851 ^[rabin2-info.txt:27]. The cert is commercially trusted at detonation time, which suppresses SmartScreen and reputation-based blocks.
Obfuscation / anti-analysis:
- Randomized Go module path:
XXjuhfDdZFXrSHR^[strings.txt:946–947] - Thirty-four randomized
main.*function names (e.g.main.dfmqjjppyfnrvuj,main.gkjiotaekzcz,main.mnadgmqvxxzfhf,main.ddloigjcgnryswk,main.jsytyw,main.xdtvbsszfax,main.ydyjyjkagev,main.ofyhqmbmlgzx) ^[strings.txt:4366–4375]. This poisons string-based clustering and complicates rule authorship. - No static C2 URLs, IPs, or domains in strings — C2 is runtime-decoded (inferred from family pattern and absence of any network constants)
- No debug symbols, no PDB path, no Rich header
stripped trueper radare2 ^[rabin2-info.txt:30]
Resources: .rsrc section contains a two-icon suite (RT_ICON id 1 and id 2, both LANG_ENGLISH US) ^[pefile.txt:329–378]. This is a reduced icon set compared to the five-icon suite common on the quiverquant.com/WE1 cert chain, suggesting builder configuration variation.
Code quality: Go standard-library binary. All imports routed through kernel32.dll (LoadLibraryA/W, GetProcAddress, VirtualAlloc, CreateThread, etc.) ^[pefile.txt:269–317]. No suspicious API imports directly visible in the IAT — Go runtime loads everything dynamically via syscall.LazyDLL / syscall.LazyProc, which is standard for Go on Windows but also serves as mild obfuscation.
Deploy / ATT&CK Lens
Execution — T1204.002 (Malicious File — User Execution): CuService.exe filename masquerades as a benign system service. ^[triage.json:5]
Persistence — None observed statically; family pattern suggests no persistent installation in baseline builds (run-once infostealer). If the builder enables persistence, it would likely use registry Run keys (T1547.001) or scheduled tasks (T1053.005) — not visible in this sample.
Defense Evasion —
- T1027 (Obfuscated Files or Information): randomized function names and module path. ^[strings.txt:4366–4375]
- T1036.005 (Match Legitimate Name or Location):
CuService.exemasquerade andseekingalpha.comcertificate chain. ^[triage.json:5] - T1553.002 (Subvert Trust Controls — Code Signing): valid GlobalSign DV TLS certificate abused for code-signing trust. ^[binwalk.txt]
- T1497.001 (Virtualization/Sandbox Evasion — System Checks): inferred from family pattern (PRNG-seeded sleep gates and runtime C2 decoding evade time-shifted sandboxes). No explicit anti-VM strings in this sample.
Discovery — T1083 (File and Directory Discovery): inferred from family targeting of browser profiles, wallet files, and credential stores. ^[entities/acrstealer.md]
Collection —
- T1555 (Credentials from Password Stores): browser credential theft (family pattern). ^[entities/acrstealer.md]
- T1555.003 (Credentials from Web Browsers): family-wide capability. ^[entities/acrstealer.md]
- T1113 (Screen Capture): inferred from
.rsrcicon masquerade and family behavior. - T1056.001 (Input Capture — Keylogging): family-wide capability on some siblings; not confirmed for this build.
Command and Control —
- T1071.001 (Application Layer Protocol — Web Protocols): TLS-wrapped HTTP C2 via Go
crypto/tls+net/http(inferred from family pattern and standard library linkage). ^[entities/acrstealer.md] - No static C2 observable — fully runtime-resolved (T1568 — Dynamic Resolution). ^[entities/acrstealer.md]
Exfiltration — T1041 (Exfiltration Over C2 Channel): family pattern POSTs collected data to C2 endpoints. ^[entities/acrstealer.md]
Impact — None observed statically; family behavior is credential theft and cryptocurrency wallet draining, not encryption or destruction.
C2 Infrastructure
No static C2 indicators recovered. The sample contains no hardcoded URLs, IPs, domains, or Telegram/Discord tokens in strings. C2 decoding is runtime-resolved via PRNG-seeded string transforms, consistent with the family pattern documented on acrstealer and prng-seeded-c2-url-decoding.
Interesting Tidbits
- Go 1.20.6 divergence: This sibling uses an older toolchain than the dominant 1.25.4 builds in the cluster, matching only
f0105851(26th sibling). Suggests the builder supports multiple Go versions or the operator is recycling older toolchain VMs. ^[strings.txt:944] - GlobalSign DV TLS cert chain: First observed on
f0105851(26th sibling, Go 1.20.6 PE32, 90 randomized functions). This sample shares the identical cert chain but is a lighter build (34 functions, two icons). ^[entities/acrstealer.md] - Reduced icon suite: Two icons vs. the five-icon suite common on
quiverquant.com/WE1chain. Builder icon-toggle confirmed. ^[pefile.txt:329–378] - Null PE timestamp: Consistent with
-trimpath=trueGo builds; not a deliberate anti-forensic measure but useful for clustering. ^[pefile.txt:34] - No custom PE parser / no multi-pass decoder: Light baseline build. No code-reuse overlap with the orderreshop / lummastealer fork that added those features. ^[entities/acrstealer.md]
How To Mess With It (Homelab Replication)
Toolchain:
- Go 1.20.6 (or any 1.18+ release)
- Target:
GOOS=windows GOARCH=386 CGO_ENABLED=0 - Flags:
-trimpath=true -ldflags="-s -w"
Working source snippet:
package main
import (
"crypto/rand"
"fmt"
"math/big"
"os"
"time"
)
func main() {
// PRNG-seeded C2 decoder simulation
seed := time.Now().Unix()
fmt.Printf("seed=%d\n", seed)
// Randomized function names are compile-time only;
// rename symbols with a post-processing script or Go build tags.
os.Exit(0)
}
Verification: Build the reproducer, run strings and confirm go1.20.6, -trimpath=true, and randomized main.* symbols if you used a renaming script. Compare entropy (~6.0–6.2 in .text) and null PE timestamp to this sample.
What you'll learn: How Go static binaries strip timestamps, how -trimpath removes source paths, and how trivial it is to generate randomized symbol names that poison string-based clustering.
Deployable Signatures
YARA Rule
rule ACRStealer_Go1206_GlobalSign_SeekingAlpha
{
meta:
description = "ACR Stealer Go 1.20.6 sibling with GlobalSign DV TLS cert CN=seekingalpha.com"
author = "PacketPursuit"
date = "2026-08-16"
sha256 = "a02296ceeb8f1419fe18a4376ce3b563e5de0fe8d85e7bf1b8461784d3c17992"
family = "acrstealer"
strings:
$go_build = "go1.20.6"
$trimpath = "build\t-trimpath=true"
$cgo = "build\tCGO_ENABLED=0"
$goarch = "build\tGOARCH=386"
$mod1 = "path\tXXjuhfDdZFXrSHR"
$mod2 = "mod\tXXjuhfDdZFXrSHR\t(devel)"
$main1 = "main.dfmqjjppyfnrvuj"
$main2 = "main.gkjiotaekzcz"
$main3 = "main.mnadgmqvxxzfhf"
$main4 = "main.jsytyw"
$seekingalpha = "seekingalpha.com" ascii wide
$globalsign = "GlobalSign Atlas R3 DV TLS CA 2025 Q4" ascii wide
condition:
uint16(0) == 0x5A4D and
($go_build and $trimpath and $cgo and $goarch) and
(2 of ($main*)) and
any of ($mod*) and
any of ($seekingalpha, $globalsign)
}
IOC List
| Indicator | Type | Value | Notes |
|---|---|---|---|
| SHA-256 | hash | a02296ceeb8f1419fe18a4376ce3b563e5de0fe8d85e7bf1b8461784d3c17992 |
Primary artifact |
| SHA-1 | hash | acb614eccf5d41ad3ac06904b7f2418a602441fb |
.text section |
| SSDeep | hash | 49152:aZ3JTQxZ6fIWrUdDcFIPiWr1HxW5d728DqYK1t:aZ3tQCZ+hga8g |
^[triage.json:14] |
| Filename | string | CuService.exe |
Service masquerade |
| Certificate CN | x509 | seekingalpha.com |
GlobalSign DV TLS |
| Cert SHA-256 | x509 | 0D:15:42:B8:AD:6F:4F:7F:F2:01:66:8D:32:15:59:69:BF:67:F3:A8:2E:18:39:1D:0E:87:1F:9F:1C:BE:6B:92 |
Valid 2025-12-09 → 2027-01-10 |
| Go module | string | XXjuhfDdZFXrSHR |
Randomized module path |
| Go build ID | string | TYvBSq1zXdkPdC2asRVH/jFfxwOLNH58_3uMOU7VR/ng--kXfOyb90XvJK_CXy/a9auVj9wjw2z2Gb4TyOr |
Unique per build |
Behavioral Fingerprint
This binary is a Go 1.20.6 static PE32 with null PE timestamp, 34 randomized main.* function names, and a valid GlobalSign DV TLS certificate. At runtime it decodes C2 strings via PRNG-seeded transforms (no static network indicators), then communicates over TLS/HTTPS to exfiltrate browser credentials and cryptocurrency wallet data. The .rsrc section contains exactly two PNG icons used for social-engineering masquerade. No custom in-memory PE parser or multi-pass byte-transform decoder is present in this light baseline build.
Detection Signatures
No capa output available (signature database missing on this host). Based on static surface:
- Go static binary with
GOARCH=386and null timestamp main.*symbol table flooded with randomized alphanumeric names- Valid but suspicious DV TLS code-signing cert on a binary named
CuService.exe - No static C2, no obvious payload resource, no AMSI bypass imports
References
- Artifact ID:
37f16e6c-748e-4ca7-84fc-c0f718add950 - Source: OpenCTI / MalwareBazaar
- Related family page: acrstealer
- Related build-pattern page: golang-stealer-build-pattern
- Related C2 technique: prng-seeded-c2-url-decoding
- Contested label page: cloud55filecc
- Sibling with same cert chain:
f0105851(Go 1.20.6, 90 randomized functions, five-icon suite)
Provenance
Analysis performed 2026-08-16 on pp-hermes (Lab1BU). Tools: pefile 2023.x, ExifTool 12.76, strings, grep, radare2 (rabin2), openssl, binwalk, Python 3.x. CAPE sandbox skipped — no Windows guest available. Static-only inference is explicitly marked where dynamic evidence is absent. All claims carry ^[file:line] or ^[tool] provenance markers.