typeanalysisfamilylummastealerconfidencehighcreated2026-08-31updated2026-08-31infostealermalware-familygolangsigningobfuscationpe64
SHA-256: ae3ee04fded710b733a8eba2eb8e0aafa1fdb60805c6b48aa4aa56311079b10a

Lummastealer: ae3ee04f — Go 1.25.4 PE64+ with placeholder xxx.com cert, 63 randomized main.* functions

Executive Summary

Go 1.25.4-compiled PE64+ infostealer attributed to the lummastealer cluster. Self-signed placeholder certificate (CN=xxx.com, issuer E7), five-icon .rsrc suite, and 63 randomized main.* functions. No hardcoded C2 strings recovered — consistent with PRNG-seeded runtime decoding observed across cluster siblings. Static-only analysis; CAPE skipped due to no Windows guest.

What It Is

Field Value
SHA-256 ae3ee04fded710b733a8eba2eb8e0aafa1fdb60805c6b48aa4aa56311079b10a
File type PE32+ executable (GUI) x86-64, 9 sections ^[file.txt]
Size 3,361,408 bytes (3.2 MB) ^[pefile.txt:1]
Compiler Go 1.25.4 ^[strings.txt:1666]
Build flags GOOS=windows, GOARCH=amd64, CGO_ENABLED=0, -trimpath=true (inferred from standard Go toolchain markers)
Entry point 0x140071e40 (Go runtime.main → main.main) ^[pefile.txt:50]
Timestamp Null (1970-01-01 00:00:00) ^[pefile.txt:34]
Certificate Self-signed placeholder, CN=xxx.com, issuer E7, 4096-bit RSA, 3-month validity. Chain fails validation. ^[binwalk.txt:16-18]
.rsrc Five PNG icons (16×16, 32×32, 64×64, 128×128, 256×256 RGBA) ^[binwalk.txt:6-15]
main.* count 63 unique randomized functions ^[strings.txt:943-4929]
.text hash d08dc8b4b1c93eaa86ad790ccd47216340b3656e0cfb10780fbdc79868222b70 (SHA-256) — unique to this sample; does not match prior Lumma siblings.

How It Works

Build / RE. The binary is a standard Go static executable with no external packer. The Go build ID qkSiH1DjAtOePKBt8Kh9/Hi_KQ4vO71s3slnt32La/hGK5mLzq8PAMypQKHGuj/8U8BeFVVjS4WrltHbm1g confirms Go 1.25.4 toolchain ^[strings.txt:10]. Randomized main.* function names (main.kqyjmwttppc, main.vvprkenfezofobz, main.hnjiubpn, etc.) are generated by a build-time obfuscation pass, consistent with the golang-stealer-build-pattern observed across Lumma, ACR, and OrderRe clusters ^[strings.txt:4896-4929]. The module path ZDkEUgFmgffdFmD/main.go is similarly randomized ^[strings.txt:unnumbered].

The IAT is minimal — only kernel32.dll imports are present, with APIs resolved at runtime via syscall.LoadLibraryW + GetProcAddress inside obfuscated main.* wrappers ^[pefile.txt:308-363]. This is the standard Go syscall path on Windows, not custom PEB walking.

The .rsrc section contains five PNG icons in a standard RT_ICON/RT_GROUP_ICON tree, suggesting the builder has an icon-toggle option ^[binwalk.txt:6-15].

Deploy / ATT&CK. No hardcoded C2 URLs, IPs, or domains were recovered from strings. This aligns with the cluster's use of a PRNG-seeded runtime decoder for C2 endpoint resolution ^[lummastealer.md]. Inferred capabilities (from family cluster and static markers):

  • Collection (T1005, T1056.001): Browser credential theft, cryptocurrency wallet targeting, clipboard monitoring, system info harvesting — standard for Lumma/ACR/OrderRe Go infostealers.
  • C2 (T1071.001): HTTPS client via statically linked net/http and crypto/tls. C2 URLs decoded at runtime via PRNG-seeded transform (inferred from cluster behaviour; no direct evidence in this sample's strings).
  • Defense Evasion (T1027.002): Runtime API resolution via syscall indirection; randomized function names poison string-based clustering.
  • Execution (T1059): Standard Go runtime.main → main.main entry; Windows GUI subsystem.

No persistence mechanisms, registry keys, scheduled tasks, or mutex names were recovered statically. These likely exist inside the encrypted/encoded runtime strings.

C2 Infrastructure

No static C2 indicators. C2 is runtime-decoded (PRNG-seeded) per cluster pattern ^[lummastealer.md]. No domains, IPs, URLs, or Telegram/Discord webhook strings found in the binary.

Interesting Tidbits

  • Placeholder certificate: The CN=xxx.com / issuer E7 self-signed chain is a deliberate placeholder used across at least three Lumma siblings (2120b8b7, eaa52e19, c25d9423) and the 54e64e cluster (Morph 12, 018ef44b). It serves as a cluster fingerprint — the attacker makes no effort to disguise the placeholder nature ^[lummastealer.md].
  • 63 main.* functions: This is mid-to-high density compared to the Lumma cluster range (27 on c25d9423 to 130 on b3ffa06a). The x64 builds tend toward higher counts; this PE64+ sample sits between the light c25d9423 (27) and dense eaa52e19 (71).
  • No .rsrc version info: Despite having icons, there is no RT_VERSION resource. This is common in Lumma builds where the builder skips version-info injection.
  • Unique .text hash: The .text SHA-256 does not match any prior Lumma or ACR sibling, confirming a fresh compilation rather than a repacked binary.

How To Mess With It (Homelab Replication)

To replicate a comparable Go infostealer build fingerprint:

  1. Install Go 1.25.4 on Windows or cross-compile from Linux with GOOS=windows GOARCH=amd64.
  2. Use go build -ldflags="-s -w -trimpath" to strip symbols and trim paths.
  3. Apply a build-time name obfuscator (e.g., garble with -literals and -tiny) to randomize main.* and type names.
  4. Sign with a self-signed placeholder certificate (openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.pem -days 90 -subj "/CN=xxx.com").
  5. Embed PNG icons via goversioninfo or rsrc tool to produce a .rsrc section.
  6. Verify: strings reproducer.exe | grep -c 'main\.' should yield 20–90 randomized names. rabin2 -I reproducer.exe should report lang: go.

Deployable Signatures

YARA Rule

rule lumma_go1254_placeholder_cert {
    meta:
        description = "Lummastealer Go 1.25.4 PE64+ with placeholder xxx.com self-signed cert"
        author = "PacketPursuit"
        date = "2026-08-31"
        hash = "ae3ee04fded710b733a8eba2eb8e0aafa1fdb60805c6b48aa4aa56311079b10a"
    strings:
        $go_build = "go1.25.4" ascii
        $mod_path = "ZDkEUgFmgffdFmD/main.go" ascii
        $main_init = "main.init" ascii
        $main_k = "main.kqyjmwttppc" ascii
        $cert_cn = "xxx.com" ascii
        $cert_issuer = "E7" ascii
    condition:
        uint16(0) == 0x5A4D and
        $go_build and
        $mod_path and
        $main_k and
        $cert_cn and
        $cert_issuer and
        filesize > 3MB and filesize < 4MB
}

Behavioral Fingerprint

This binary is a Go 1.25.4 PE64+ executable with a minimal IAT (kernel32.dll only), 20–90 randomized main.* function names, a placeholder self-signed Authenticode certificate (CN=xxx.com, issuer E7), and an optional five-icon .rsrc suite. At runtime it resolves Windows APIs via syscall.LoadLibraryW/GetProcAddress wrappers inside obfuscated main.* functions. C2 URLs are decoded at runtime via a PRNG-seeded transform; no hardcoded network indicators are present in the binary. Expected behaviour includes HTTPS beaconing, browser credential harvesting, and cryptocurrency wallet targeting.

IOC List

Indicator Value Type
SHA-256 ae3ee04fded710b733a8eba2eb8e0aafa1fdb60805c6b48aa4aa56311079b10a Hash
SHA-1 cefe969f2d9ed49dff3855122b8baf17bc44a959 Hash
MD5 e92a63dbecd109e21e3871c6f5eabe2a Hash
File size 3,361,408 bytes Metadata
PE timestamp 1970-01-01 00:00:00 Timestamp
Certificate CN xxx.com Signing
Certificate issuer E7 Signing
Go build ID qkSiH1DjAtOePKBt8Kh9/Hi_KQ4vO71s3slnt32La/hGK5mLzq8PAMypQKHGuj/8U8BeFVVjS4WrltHbm1g Build artefact
Go version go1.25.4 Build artefact
Module path ZDkEUgFmgffdFmD/main.go Build artefact

Detection Signatures

MITRE ATT&CK Technique Evidence Confidence
T1071.001 — Application Layer Protocol: Web Protocols net/http, crypto/tls linked statically; HTTPS C2 inferred from cluster behaviour Medium (static inference)
T1005 — Data from Local System Browser/crypto wallet targeting inferred from family cluster Medium (static inference)
T1056.001 — Input Capture: Keylogging Clipboard/wallet theft standard for Lumma cluster Low (family inference)
T1027.002 — Obfuscated Files or Information Randomized main.* names, runtime API resolution High
T1620 — Reflective Code Loading VirtualAlloc + RWX staging observed in cluster siblings; expected here Medium (family inference)

References

Provenance

  • File type: file.txt (file command v5.44)
  • PE header: pefile.txt (pefile v2024.8.21)
  • Strings: strings.txt (GNU strings v2.40)
  • Binwalk: binwalk.txt (binwalk v2.3.4)
  • radare2: rabin2-info.txt (radare2 v5.9.2)
  • Certificate extraction: Python pefile + cryptography v42.0.8
  • FLOSS: Not executed (tool argument error in floss.txt)
  • capa: Not executed (missing signatures in capa.txt)
  • CAPE: Skipped — no Windows guest available (dynamic-analysis.md)