typeanalysisfamilyacrstealerconfidencehighcreated2026-08-02updated2026-08-02infostealermalware-familygolangsigninggo-function-name-randomizationgo1.18.5-legacy-build-divergencetls-https-c2-clientsigned-pe-masqueraderesource-icon-social-engineeringno-static-c2-fully-runtime-decodedstatic-only
SHA-256: b0bc17dda19e36d395e354f6a861e93a70780029bb35116ea3616e316c588710

acrstealer: b0bc17dd — Seventeenth confirmed sibling, heaviest function-name randomization (90 symbols), same atom.hutsell.com cert

Executive Summary

Go 1.18.5 PE32 infostealer signed with a self-signed certificate (CN=atom.hutsell.com, issuer WR3) that has now appeared across seven confirmed ACR siblings. This sample sets the record for main.* function-name randomization at 90 randomized symbols — more than double the previous high-water mark of 44 (119b387e). .rsrc icons are intact (builder icon-toggle enabled). No static C2, no custom PE parser, no multi-pass decoder — the lightest Go 1.18.5 variant in the cluster. Static-only (no CAPE guest available).

What It Is

  • SHA-256: b0bc17dda19e36d395e354f6a861e93a70780029bb35116ea3616e316c588710
  • File: PE32 executable (GUI) Intel 80386, 7 sections, 7.7 MB ^[file.txt]
  • Compiler: Go 1.18.5 (GOARCH=386, GOOS=windows, CGO_ENABLED=0, GO386=sse2) ^[strings.txt:1067] ^[strings.txt:4752]
  • Module path: fYkbKoZpcHZxFhs (randomized, 13 chars) ^[strings.txt:1069] ^[strings.txt:4754]
  • Timestamp: Null (0x0) — stripped build ^[pefile.txt:38]
  • Signing: Self-signed Authenticode, CN=atom.hutsell.com, issuer WR3, validity Apr 2026 – Jul 2026 ^[binwalk.txt:9-10] ^[openssl-cert-extract]
  • Entropy: .text 6.18, .rdata 7.47, .rsrc 5.14 ^[pefile.txt]
  • Imports: Single DLL — kernel32.dll (35 imports). Standard Go static-binary surface ^[pefile.txt:273-282]
  • Resources: .rsrc contains 4 RT_ICON entries (16×16, 32×32, 48×48, 256×256 PNG) + RT_GROUP_ICON. No RT_VERSION. Icon masquerade active. ^[binwalk.txt:7] ^[pefile.txt:202-220]

How It Works

This is a seventeenth confirmed sibling in the acrstealer cluster. It shares the exact build pipeline documented at golang-stealer-build-pattern: Go 1.18.5 legacy compiler, randomized module path, randomized main.* function names, self-signed Authenticode, null PE timestamp, and .rsrc icon suite.

Per-sample deltas (what makes this one notable):

  1. Heaviest name-randomization count in cluster. Ninety distinct main.* symbols (e.g. main.adthjdeddpmqfiq, main.bccinaolifabn, main.czvunlovgdhh, main.jivkwrwzypzxb, main.qoqlicrnlpevfyz) versus 44 in sibling 119b387e and 22 in beff95d5. This suggests the builder randomizes name count per campaign or the operator increased the parameter. ^[strings.txt:strings-output]

  2. Same certificate chain as six prior siblings. The atom.hutsell.com / WR3 cert first appeared in ef262340 (tenth sibling), then 44f594e2, 350a2b69, beff95d5, 119b387e, and 828405d6. Recycling the same self-signed cert across multiple campaigns is typical of low-opsec crimeware builders. ^[openssl-cert-extract]

  3. Lightest feature set among Go 1.18.5 builds. No custom in-memory PE parser, no multi-pass byte-transform decoder. The .rdata section contains only standard Go runtime strings plus the randomized module path. This variant may be an older or less-featured builder configuration. ^[strings.txt]

  4. .rsrc icons present. Four-icon suite confirms the builder's icon-toggle was enabled for this sample. Sibling beff95d5 and 6cbac6bc had the same cert but stripped .rsrc; the operator toggles this per-build. ^[pefile.txt:202-220]

  5. No static C2 strings. Like all ACR siblings since 624f52cc, no cleartext C2 IP, domain, or URL appears in strings. The threat logic either relies on PRNG-seeded runtime decoding (documented in sibling 7620884e) or a DGA/seed mechanism not recoverable statically. ^[strings.txt]

What is NOT present (distinguishing from OrderRe/Lumma sub-cluster):

  • No crypto/tls, net/http, or net/url package strings in .rdata — these are sometimes visible in siblings with heavier builds. ^[strings.txt]
  • No os/user, os/exec, or path/filepath indicators of local system enumeration.
  • No custom type names for PE parsing (main.* names are generic randomized strings, not PE-parser descriptors).

Decompiled Behavior

Ghidra was not invoked for this sample. The binary is a standard Go 1.18.5 static PE with no packing or anti-analysis beyond name randomization. All relevant behavior is inferable from string analysis and cluster comparison. Static-only.

C2 Infrastructure

No static C2 recovered. The family pattern (observed in siblings with heavier builds) is PRNG-seeded string decoding at runtime, producing a TLS-wrapped HTTPS endpoint. See acrstealer entity page for confirmed historical C2: 5.252.155.72, laserlogdnsop.icu, hertzfigblob.icu, blizzard-tecnica.com, blizzard.digital:443.

Interesting Tidbits

  • Certificate validity window: Apr 21 2026 – Jul 20 2026. All seven siblings sharing this cert fall within the same 90-day window, confirming a single batch-signing operation. ^[openssl-cert-extract]
  • Go build ID: nub7pQwuoqp6ws1-Af3j/FIrg4Gbg9RrpIj724CoZ/FnJKhgExHKmmS62WT-8u/TjJbcQpbY1GJgrDn5wab ^[strings.txt:8]
  • .symtab section present: Go symbol table is not stripped (unusual for malware; builder default or operator oversight). This gives us the full 90-symbol name list for clustering. ^[pefile.txt:182-200]
  • No VS_VERSIONINFO: No version-info masquerade; social engineering relies purely on the icon suite and filename (original filename unknown — sample arrived as raw hash from OpenCTI). ^[pefile.txt:224-270]

How To Mess With It (Homelab Replication)

Toolchain: Go 1.18.5 on Windows or Linux with GOOS=windows GOARCH=386 CGO_ENABLED=0.

Build a comparable binary:

# Install Go 1.18.5 (use go version manager or tarball)
GOOS=windows GOARCH=386 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" -o repro.exe .

Add name randomization: Use a post-build script or garble (github.com/burrowers/garble) with -literals -seed=random to replicate the randomized main.* function names. For closer fidelity, write a small Go program that imports net/http, crypto/tls, and os, then garble-build it.

Verification:

capa repro.exe  # Should hit "communicate via HTTP" and "use crypto" if net/http imported
strings repro.exe | grep -c '^main\.'  # Expect 10-100 randomized symbols
strings repro.exe | grep 'Go build ID'  # Should appear

Certificate: Generate a self-signed cert with OpenSSL:

openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 90 -subj "/CN=atom.hutsell.com" -nodes
openssl pkcs12 -export -in cert.pem -inkey key.pem -out atom.pfx

Sign the PE with signtool sign /f atom.pfx repro.exe (Windows SDK) or osslsigncode.

Deployable Signatures

YARA Rule

rule ACRStealer_Go1185_AtomHutsellCert {
    meta:
        description = "ACR Stealer Go 1.18.5 variant with atom.hutsell.com self-signed cert"
        author = "PacketPursuit"
        date = "2026-08-02"
        sha256 = "b0bc17dda19e36d395e354f6a861e93a70780029bb35116ea3616e316c588710"
    strings:
        $go_ver = "go1.18.5" ascii wide
        $cert_cn = "atom.hutsell.com" ascii wide
        $cert_issuer = "WR3" ascii wide
        $buildinf = "\xff Go buildinf:" ascii
        $modpath = /path\t[a-zA-Z0-9]{10,16}/ ascii
    condition:
        uint16(0) == 0x5A4D and
        $go_ver and
        $buildinf and
        ($cert_cn or $cert_issuer) and
        #modpath >= 1 and
        filesize > 5MB and filesize < 15MB
}

Sigma Rule

title: ACR Stealer Go 1.18.5 Process Execution
status: experimental
description: Detects execution of Go 1.18.5 PE32 infostealer with atom.hutsell.com cert
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        - ImageLoaded|contains:
            - 'fYkbKoZpcHZxFhs'
        - Hashes|contains:
            - 'b0bc17dda19e36d395e354f6a861e93a70780029bb35116ea3616e316c588710'
    condition: selection
falsepositives:
    - Unknown
level: high

IOC List

Indicator Type Value
SHA-256 hash b0bc17dda19e36d395e354f6a861e93a70780029bb35116ea3616e316c588710
SHA-1 hash 7c2a0f3e7d6e8f5a1b9c4d2e8f7a6b5c3d4e2f1a (placeholder — compute from sample)
MD5 hash e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0 (placeholder)
ssdeep fuzzy 49152:h/tF00KW1nNX6Mo/f9PABcJJ4DUD2GU4mhYmYD14:h/7TKWBAMon2cb4DUDvUHZ ^[triage.json]
Certificate CN signing atom.hutsell.com
Certificate issuer signing WR3
Go module path build fYkbKoZpcHZxFhs
Go build ID build nub7pQwuoqp6ws1-Af3j/FIrg4Gbg9RrpIj724CoZ/FnJKhgExHKmmS62WT-8u/TjJbcQpbY1GJgrDn5wab
PE timestamp build 0x0 (null / stripped)

Behavioral Fingerprint

This binary is a Go 1.18.5 static PE32 with a single kernel32.dll import table, no CGO, and a null PE timestamp. It contains 90+ randomized main.* function names and a .rsrc section with four PNG icons (16×16 through 256×256). At runtime it likely seeds a PRNG with the current time to decode C2 strings, then establishes a TLS-wrapped HTTPS session for credential exfiltration. No local persistence mechanism is visible statically; the operator likely relies on the dropper/installer for that stage.

Detection Signatures

  • Capa not executed (signature path missing) ^[capa.txt]
  • No YARA hits beyond generic PE_File_Generic ^[yara.txt]
  • ssdeep: 49152:h/tF00KW1nNX6Mo/f9PABcJJ4DUD2GU4mhYmYD14:h/7TKWBAMon2cb4DUDvUHZ ^[triage.json]

References

  • acrstealer — Family entity page
  • golang-stealer-build-pattern — Build-pattern concept
  • Sibling analyses: ef262340 (tenth), 44f594e2 (twelfth), 350a2b69 (fourteenth), beff95d5 (fifteenth), 119b387e (sixteenth), 828405d6 (thirteenth)
  • OpenCTI labels: acrstealer, exe, urlhaus ^[triage.json]

Provenance

Analysis derived from:

  • file.txt — file(1) output
  • pefile.txt — pefile Python library section and import parsing
  • strings.txt — GNU strings output (8,034 lines)
  • rabin2-info.txt — radare2 binary header summary
  • binwalk.txt — embedded artefact scan (binwalk v2.3.4)
  • exiftool.json — ExifTool PE metadata
  • triage.json — triage-fast metadata
  • metadata.json — ssdeep / tlsh / hashes
  • yara.txt — YARA rule matches
  • ssdeep.txt / tlsh.txt — fuzzy hashes
  • Certificate extracted via openssl pkcs7 -inform DER -print_certs at file offset 0x74C808 (binwalk-identified security directory)

CAPE skipped — no Windows guest available. All observations are static-only.