b07d5dcd0cb2b95480328ff64456f811d917763b53f0e3403969093383a90014AFK Stealer 0.28.1 (x86) — b07d5dcd
1. Build / RE
Packing: UPX-compressed outer shell (Likely_Packer_UPX YARA hit; upx -d expands 3.6 MB → 12.6 MB). ^[yara.txt] Post-decompression yields a PE32 executable (GUI) Intel 80386, 6 sections, no .rsrc, no version info, no icon. ^[file.txt]
Toolchain: Go 1.24.0, GOOS=windows, GOARCH=386, module name salat (devel build). ^[strings-unpacked.txt:6957] No build timestamp; PE timestamp is zeroed. ^[exiftool.json]
Signing: Unsigned. No Authenticode or self-signed certificate.
Anti-analysis: None observed. No debug checks, VM detection, or anti-disassembly in static surface. Stripped but retains Go .symtab function names.
Embedded resources: No icon or manifest. Standard Go runtime with CGO disabled (pure Go). The wazero WebAssembly runtime is present, suggesting optional WASM module loading at runtime. ^[strings-unpacked.txt:6973]
Dependencies (Go modules) — identical dep graph to siblings 0b6c65cd and 6d8ecdd1:
| Module | Version | Purpose |
|---|---|---|
github.com/quic-go/quic-go |
v0.38.1 | QUIC/HTTP3 C2 transport |
github.com/gorilla/websocket |
v1.5.3 | WebSocket fallback |
github.com/tetratelabs/wazero |
v1.8.2 | WASM runtime (in-process module loader) |
github.com/capnspacehook/taskmaster |
v0.0.0-20210519235353-1629df7c85e9 | Windows Task Scheduler persistence |
github.com/ncruces/go-sqlite3 |
v0.23.0 | SQLite driver for browser DB parsing |
github.com/xssnick/tonutils-go |
v1.16.0 | TON blockchain wallet operations |
github.com/andygrunwald/vdf |
v1.1.0 | Steam local.vdf parsing |
github.com/StackExchange/wmi |
v1.2.1 | WMI queries (system reconnaissance) |
github.com/yusufpapurcu/wmi |
v1.2.3 | WMI queries (alternate/fallback WMI provider) |
github.com/buger/jsonparser |
v1.1.1 | Fast JSON parsing for exfil |
^[strings-unpacked.txt:6958–6975]
Notable functions:
main.(*wsSess).recvWss,main.(*wsSess).sendTrace,main.(*wsSess).Start— WebSocket session management (C2 channel). ^[strings-unpacked.txt:20088–20118]main.(*wsSess).execCommand,main.(*wsSess).sepDesktop,main.(*wsSess).ffdesktop— remote command execution and desktop separation (likely RDP / screen sharing / multi-desktop isolation for evasion). ^[strings-unpacked.txt:20119–20123]main.base64decode— config/blob decoding. ^[strings-unpacked.txt:20082]main.GetHWID— machine fingerprinting. ^[strings-unpacked.txt:20205]salat/screenshot.Capture,salat/screenshot.CaptureRect— screen capture. ^[strings-unpacked.txt:16202–16213]
2. Deploy / ATT&CK
TTPs (static + sibling inference):
- T1555.003 — Credentials from Web Browsers: Chromium + Gecko cookie/SQLite DB parsing via
ncruces/go-sqlite3; DPAPI/AES key recovery (CANT DECRYPT KEY,AES ERROR). ^[strings-unpacked.txt:4751] - T1082 — System Information Discovery:
GetHWID, WMI queries,PC Name:,OS:,IP:,Resolution:. ^[strings-unpacked.txt:4729] - T1056.001 — Input Capture / Keylogging:
GetKeyboardState,GetLastInputInfo,GetClipboardData,Active window:strings. ^[strings-unpacked.txt:4751] - T1113 — Screen Capture:
salat/screenshot.CaptureRect. ^[strings-unpacked.txt:16203] - T1115 — Clipboard Data:
clipboard-hijackimplied by clipboard API imports and stealer family behaviour. - T1071 — Application Layer Protocol: QUIC/HTTP3 primary (
quic-gov0.38.1), WebSocket fallback (gorilla/websocket), HTTP/2.0 and HTTP/1.1 fallbacks. ^[strings-unpacked.txt:4734] - T1572 — Protocol Tunneling: DNS-over-HTTPS fallback (
https://1.1.1.1/dns-query,https://cloudflare-dns.com/dns-query,https://dns.google/resolve). ^[strings-unpacked.txt:4784] - T1543.005 — Create or Modify System Process (Task Scheduler):
capnspacehook/taskmaster. ^[strings-unpacked.txt:6961] - T1567 — Exfiltration Over Web Service: JSON POST (
application/json),LOG SENT!,steal finished!. ^[strings-unpacked.txt:4729] - T1083 — File and Directory Discovery: browser profile enumeration, wallet path traversal.
Persistence: Windows Task Scheduler via OLE automation (taskmaster). No registry Run key observed in strings (unlike some stealer families).
C2 / Exfil:
- Primary: WebSocket-over-TLS (
wsSessstruct,gorilla/websocket), with QUIC/HTTP3 as the preferred high-performance transport (quic-go). - Fallback: DoH (Cloudflare, Google, Quad9) for name resolution if direct C2 is blocked.
- Exfil format:
application/jsonPOSTs. No hardcoded Telegram bot token or Discord webhook URL found in static strings; config is likely delivered via the C2 WebSocket at runtime. - No static C2 endpoint, IP, or domain recovered from unpacked binary.
dQw4w9WgXcQ(Rickroll YouTube ID) present in strings — likely placeholder or test artifact. ^[strings-unpacked.txt:4748]
Attribution:
- Russian-language builder/distribution context (AFK Stealer sold on Russian-speaking cybercrime forums).
- Version string
[AFK] 0.28.1 (x86)is consistent across all three siblings. - No code-signing or branding beyond the version banner.
3. Sibling Comparison
| Attribute | b07d5dcd (this) | 0b6c65cd | 6d8ecdd1 |
|---|---|---|---|
| Version | 0.28.1 | 0.28.1 | 0.28.1 |
| Go version | 1.24.0 | 1.24.0 | 1.24.0 |
| Module | salat |
salat |
salat |
| Architecture | x86 | x86 | x86 |
| Packing | UPX | UPX | UPX |
| Dep graph | Identical | Identical | Identical |
| Strings (unpacked) | 22,858 | 21,900 (approx) | ~21,900 |
| Unique delta | None — byte-level build variation | — | — |
All three siblings share an identical dependency graph, version banner, module name, and build configuration. No functional deltas detected in static surface. Likely successive builds from the same builder with minor code or config changes between compiles.
4. IOCs
| Type | Value | Note |
|---|---|---|
| Version banner | [AFK] 0.28.1 (x86) |
Present in all siblings |
| Go module | salat (devel) |
Build path: salat |
| Imphash (packed) | N/A (UPX-stripped) | No recoverable import table |
| Rich PE hash | N/A | Zeroed timestamps |
| ssdeep | See ssdeep.txt |
Packed-stage only |
| Network | DoH: 1.1.1.1, cloudflare-dns.com, dns.google |
Static fallback |
Static-only analysis. No CAPE runtime data available (empty dynamic-analysis.md / cape-report.json).