ae3ee04fded710b733a8eba2eb8e0aafa1fdb60805c6b48aa4aa56311079b10aLummastealer: ae3ee04f — Go 1.25.4 PE64+ with placeholder xxx.com cert, 63 randomized main.* functions
Executive Summary
Go 1.25.4-compiled PE64+ infostealer attributed to the lummastealer cluster. Self-signed placeholder certificate (CN=xxx.com, issuer E7), five-icon .rsrc suite, and 63 randomized main.* functions. No hardcoded C2 strings recovered — consistent with PRNG-seeded runtime decoding observed across cluster siblings. Static-only analysis; CAPE skipped due to no Windows guest.
What It Is
| Field | Value |
|---|---|
| SHA-256 | ae3ee04fded710b733a8eba2eb8e0aafa1fdb60805c6b48aa4aa56311079b10a |
| File type | PE32+ executable (GUI) x86-64, 9 sections ^[file.txt] |
| Size | 3,361,408 bytes (3.2 MB) ^[pefile.txt:1] |
| Compiler | Go 1.25.4 ^[strings.txt:1666] |
| Build flags | GOOS=windows, GOARCH=amd64, CGO_ENABLED=0, -trimpath=true (inferred from standard Go toolchain markers) |
| Entry point | 0x140071e40 (Go runtime.main → main.main) ^[pefile.txt:50] |
| Timestamp | Null (1970-01-01 00:00:00) ^[pefile.txt:34] |
| Certificate | Self-signed placeholder, CN=xxx.com, issuer E7, 4096-bit RSA, 3-month validity. Chain fails validation. ^[binwalk.txt:16-18] |
.rsrc |
Five PNG icons (16×16, 32×32, 64×64, 128×128, 256×256 RGBA) ^[binwalk.txt:6-15] |
main.* count |
63 unique randomized functions ^[strings.txt:943-4929] |
.text hash |
d08dc8b4b1c93eaa86ad790ccd47216340b3656e0cfb10780fbdc79868222b70 (SHA-256) — unique to this sample; does not match prior Lumma siblings. |
How It Works
Build / RE. The binary is a standard Go static executable with no external packer. The Go build ID qkSiH1DjAtOePKBt8Kh9/Hi_KQ4vO71s3slnt32La/hGK5mLzq8PAMypQKHGuj/8U8BeFVVjS4WrltHbm1g confirms Go 1.25.4 toolchain ^[strings.txt:10]. Randomized main.* function names (main.kqyjmwttppc, main.vvprkenfezofobz, main.hnjiubpn, etc.) are generated by a build-time obfuscation pass, consistent with the golang-stealer-build-pattern observed across Lumma, ACR, and OrderRe clusters ^[strings.txt:4896-4929]. The module path ZDkEUgFmgffdFmD/main.go is similarly randomized ^[strings.txt:unnumbered].
The IAT is minimal — only kernel32.dll imports are present, with APIs resolved at runtime via syscall.LoadLibraryW + GetProcAddress inside obfuscated main.* wrappers ^[pefile.txt:308-363]. This is the standard Go syscall path on Windows, not custom PEB walking.
The .rsrc section contains five PNG icons in a standard RT_ICON/RT_GROUP_ICON tree, suggesting the builder has an icon-toggle option ^[binwalk.txt:6-15].
Deploy / ATT&CK. No hardcoded C2 URLs, IPs, or domains were recovered from strings. This aligns with the cluster's use of a PRNG-seeded runtime decoder for C2 endpoint resolution ^[lummastealer.md]. Inferred capabilities (from family cluster and static markers):
- Collection (T1005, T1056.001): Browser credential theft, cryptocurrency wallet targeting, clipboard monitoring, system info harvesting — standard for Lumma/ACR/OrderRe Go infostealers.
- C2 (T1071.001): HTTPS client via statically linked
net/httpandcrypto/tls. C2 URLs decoded at runtime via PRNG-seeded transform (inferred from cluster behaviour; no direct evidence in this sample's strings). - Defense Evasion (T1027.002): Runtime API resolution via
syscallindirection; randomized function names poison string-based clustering. - Execution (T1059): Standard Go
runtime.main→main.mainentry; Windows GUI subsystem.
No persistence mechanisms, registry keys, scheduled tasks, or mutex names were recovered statically. These likely exist inside the encrypted/encoded runtime strings.
C2 Infrastructure
No static C2 indicators. C2 is runtime-decoded (PRNG-seeded) per cluster pattern ^[lummastealer.md]. No domains, IPs, URLs, or Telegram/Discord webhook strings found in the binary.
Interesting Tidbits
- Placeholder certificate: The
CN=xxx.com/ issuerE7self-signed chain is a deliberate placeholder used across at least three Lumma siblings (2120b8b7,eaa52e19,c25d9423) and the54e64ecluster (Morph 12,018ef44b). It serves as a cluster fingerprint — the attacker makes no effort to disguise the placeholder nature ^[lummastealer.md]. - 63
main.*functions: This is mid-to-high density compared to the Lumma cluster range (27 onc25d9423to 130 onb3ffa06a). The x64 builds tend toward higher counts; this PE64+ sample sits between the lightc25d9423(27) and denseeaa52e19(71). - No
.rsrcversion info: Despite having icons, there is no RT_VERSION resource. This is common in Lumma builds where the builder skips version-info injection. - Unique
.texthash: The.textSHA-256 does not match any prior Lumma or ACR sibling, confirming a fresh compilation rather than a repacked binary.
How To Mess With It (Homelab Replication)
To replicate a comparable Go infostealer build fingerprint:
- Install Go 1.25.4 on Windows or cross-compile from Linux with
GOOS=windows GOARCH=amd64. - Use
go build -ldflags="-s -w -trimpath"to strip symbols and trim paths. - Apply a build-time name obfuscator (e.g.,
garblewith-literalsand-tiny) to randomizemain.*and type names. - Sign with a self-signed placeholder certificate (
openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.pem -days 90 -subj "/CN=xxx.com"). - Embed PNG icons via
goversioninfoorrsrctool to produce a.rsrcsection. - Verify:
strings reproducer.exe | grep -c 'main\.'should yield 20–90 randomized names.rabin2 -I reproducer.exeshould reportlang: go.
Deployable Signatures
YARA Rule
rule lumma_go1254_placeholder_cert {
meta:
description = "Lummastealer Go 1.25.4 PE64+ with placeholder xxx.com self-signed cert"
author = "PacketPursuit"
date = "2026-08-31"
hash = "ae3ee04fded710b733a8eba2eb8e0aafa1fdb60805c6b48aa4aa56311079b10a"
strings:
$go_build = "go1.25.4" ascii
$mod_path = "ZDkEUgFmgffdFmD/main.go" ascii
$main_init = "main.init" ascii
$main_k = "main.kqyjmwttppc" ascii
$cert_cn = "xxx.com" ascii
$cert_issuer = "E7" ascii
condition:
uint16(0) == 0x5A4D and
$go_build and
$mod_path and
$main_k and
$cert_cn and
$cert_issuer and
filesize > 3MB and filesize < 4MB
}
Behavioral Fingerprint
This binary is a Go 1.25.4 PE64+ executable with a minimal IAT (kernel32.dll only), 20–90 randomized main.* function names, a placeholder self-signed Authenticode certificate (CN=xxx.com, issuer E7), and an optional five-icon .rsrc suite. At runtime it resolves Windows APIs via syscall.LoadLibraryW/GetProcAddress wrappers inside obfuscated main.* functions. C2 URLs are decoded at runtime via a PRNG-seeded transform; no hardcoded network indicators are present in the binary. Expected behaviour includes HTTPS beaconing, browser credential harvesting, and cryptocurrency wallet targeting.
IOC List
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | ae3ee04fded710b733a8eba2eb8e0aafa1fdb60805c6b48aa4aa56311079b10a |
Hash |
| SHA-1 | cefe969f2d9ed49dff3855122b8baf17bc44a959 |
Hash |
| MD5 | e92a63dbecd109e21e3871c6f5eabe2a |
Hash |
| File size | 3,361,408 bytes | Metadata |
| PE timestamp | 1970-01-01 00:00:00 | Timestamp |
| Certificate CN | xxx.com |
Signing |
| Certificate issuer | E7 |
Signing |
| Go build ID | qkSiH1DjAtOePKBt8Kh9/Hi_KQ4vO71s3slnt32La/hGK5mLzq8PAMypQKHGuj/8U8BeFVVjS4WrltHbm1g |
Build artefact |
| Go version | go1.25.4 |
Build artefact |
| Module path | ZDkEUgFmgffdFmD/main.go |
Build artefact |
Detection Signatures
| MITRE ATT&CK Technique | Evidence | Confidence |
|---|---|---|
| T1071.001 — Application Layer Protocol: Web Protocols | net/http, crypto/tls linked statically; HTTPS C2 inferred from cluster behaviour |
Medium (static inference) |
| T1005 — Data from Local System | Browser/crypto wallet targeting inferred from family cluster | Medium (static inference) |
| T1056.001 — Input Capture: Keylogging | Clipboard/wallet theft standard for Lumma cluster | Low (family inference) |
| T1027.002 — Obfuscated Files or Information | Randomized main.* names, runtime API resolution |
High |
| T1620 — Reflective Code Loading | VirtualAlloc + RWX staging observed in cluster siblings; expected here |
Medium (family inference) |
References
- lummastealer — cluster entity page
- golang-stealer-build-pattern — shared build artefacts
- acrstealer — sibling cluster with identical toolchain
- orderreshop — sibling cluster with identical toolchain
- fused-string-api-decoding — runtime DLL+API string fusion technique
Provenance
- File type:
file.txt(filecommand v5.44) - PE header:
pefile.txt(pefile v2024.8.21) - Strings:
strings.txt(GNU strings v2.40) - Binwalk:
binwalk.txt(binwalk v2.3.4) - radare2:
rabin2-info.txt(radare2 v5.9.2) - Certificate extraction: Python
pefile+cryptographyv42.0.8 - FLOSS: Not executed (tool argument error in
floss.txt) - capa: Not executed (missing signatures in
capa.txt) - CAPE: Skipped — no Windows guest available (
dynamic-analysis.md)