b0bc17dda19e36d395e354f6a861e93a70780029bb35116ea3616e316c588710acrstealer: b0bc17dd — Seventeenth confirmed sibling, heaviest function-name randomization (90 symbols), same atom.hutsell.com cert
Executive Summary
Go 1.18.5 PE32 infostealer signed with a self-signed certificate (CN=atom.hutsell.com, issuer WR3) that has now appeared across seven confirmed ACR siblings. This sample sets the record for main.* function-name randomization at 90 randomized symbols — more than double the previous high-water mark of 44 (119b387e). .rsrc icons are intact (builder icon-toggle enabled). No static C2, no custom PE parser, no multi-pass decoder — the lightest Go 1.18.5 variant in the cluster. Static-only (no CAPE guest available).
What It Is
- SHA-256:
b0bc17dda19e36d395e354f6a861e93a70780029bb35116ea3616e316c588710 - File: PE32 executable (GUI) Intel 80386, 7 sections, 7.7 MB ^[file.txt]
- Compiler: Go 1.18.5 (
GOARCH=386,GOOS=windows,CGO_ENABLED=0,GO386=sse2) ^[strings.txt:1067] ^[strings.txt:4752] - Module path:
fYkbKoZpcHZxFhs(randomized, 13 chars) ^[strings.txt:1069] ^[strings.txt:4754] - Timestamp: Null (
0x0) — stripped build ^[pefile.txt:38] - Signing: Self-signed Authenticode, CN=
atom.hutsell.com, issuerWR3, validity Apr 2026 – Jul 2026 ^[binwalk.txt:9-10] ^[openssl-cert-extract] - Entropy:
.text6.18,.rdata7.47,.rsrc5.14 ^[pefile.txt] - Imports: Single DLL —
kernel32.dll(35 imports). Standard Go static-binary surface ^[pefile.txt:273-282] - Resources:
.rsrccontains 4 RT_ICON entries (16×16, 32×32, 48×48, 256×256 PNG) + RT_GROUP_ICON. No RT_VERSION. Icon masquerade active. ^[binwalk.txt:7] ^[pefile.txt:202-220]
How It Works
This is a seventeenth confirmed sibling in the acrstealer cluster. It shares the exact build pipeline documented at golang-stealer-build-pattern: Go 1.18.5 legacy compiler, randomized module path, randomized main.* function names, self-signed Authenticode, null PE timestamp, and .rsrc icon suite.
Per-sample deltas (what makes this one notable):
-
Heaviest name-randomization count in cluster. Ninety distinct
main.*symbols (e.g.main.adthjdeddpmqfiq,main.bccinaolifabn,main.czvunlovgdhh,main.jivkwrwzypzxb,main.qoqlicrnlpevfyz) versus 44 in sibling119b387eand 22 inbeff95d5. This suggests the builder randomizes name count per campaign or the operator increased the parameter. ^[strings.txt:strings-output] -
Same certificate chain as six prior siblings. The
atom.hutsell.com/WR3cert first appeared inef262340(tenth sibling), then44f594e2,350a2b69,beff95d5,119b387e, and828405d6. Recycling the same self-signed cert across multiple campaigns is typical of low-opsec crimeware builders. ^[openssl-cert-extract] -
Lightest feature set among Go 1.18.5 builds. No custom in-memory PE parser, no multi-pass byte-transform decoder. The
.rdatasection contains only standard Go runtime strings plus the randomized module path. This variant may be an older or less-featured builder configuration. ^[strings.txt] -
.rsrcicons present. Four-icon suite confirms the builder's icon-toggle was enabled for this sample. Siblingbeff95d5and6cbac6bchad the same cert but stripped.rsrc; the operator toggles this per-build. ^[pefile.txt:202-220] -
No static C2 strings. Like all ACR siblings since
624f52cc, no cleartext C2 IP, domain, or URL appears in strings. The threat logic either relies on PRNG-seeded runtime decoding (documented in sibling7620884e) or a DGA/seed mechanism not recoverable statically. ^[strings.txt]
What is NOT present (distinguishing from OrderRe/Lumma sub-cluster):
- No
crypto/tls,net/http, ornet/urlpackage strings in.rdata— these are sometimes visible in siblings with heavier builds. ^[strings.txt] - No
os/user,os/exec, orpath/filepathindicators of local system enumeration. - No custom type names for PE parsing (
main.*names are generic randomized strings, not PE-parser descriptors).
Decompiled Behavior
Ghidra was not invoked for this sample. The binary is a standard Go 1.18.5 static PE with no packing or anti-analysis beyond name randomization. All relevant behavior is inferable from string analysis and cluster comparison. Static-only.
C2 Infrastructure
No static C2 recovered. The family pattern (observed in siblings with heavier builds) is PRNG-seeded string decoding at runtime, producing a TLS-wrapped HTTPS endpoint. See acrstealer entity page for confirmed historical C2: 5.252.155.72, laserlogdnsop.icu, hertzfigblob.icu, blizzard-tecnica.com, blizzard.digital:443.
Interesting Tidbits
- Certificate validity window: Apr 21 2026 – Jul 20 2026. All seven siblings sharing this cert fall within the same 90-day window, confirming a single batch-signing operation. ^[openssl-cert-extract]
- Go build ID:
nub7pQwuoqp6ws1-Af3j/FIrg4Gbg9RrpIj724CoZ/FnJKhgExHKmmS62WT-8u/TjJbcQpbY1GJgrDn5wab^[strings.txt:8] - .symtab section present: Go symbol table is not stripped (unusual for malware; builder default or operator oversight). This gives us the full 90-symbol name list for clustering. ^[pefile.txt:182-200]
- No VS_VERSIONINFO: No version-info masquerade; social engineering relies purely on the icon suite and filename (original filename unknown — sample arrived as raw hash from OpenCTI). ^[pefile.txt:224-270]
How To Mess With It (Homelab Replication)
Toolchain: Go 1.18.5 on Windows or Linux with GOOS=windows GOARCH=386 CGO_ENABLED=0.
Build a comparable binary:
# Install Go 1.18.5 (use go version manager or tarball)
GOOS=windows GOARCH=386 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" -o repro.exe .
Add name randomization: Use a post-build script or garble (github.com/burrowers/garble) with -literals -seed=random to replicate the randomized main.* function names. For closer fidelity, write a small Go program that imports net/http, crypto/tls, and os, then garble-build it.
Verification:
capa repro.exe # Should hit "communicate via HTTP" and "use crypto" if net/http imported
strings repro.exe | grep -c '^main\.' # Expect 10-100 randomized symbols
strings repro.exe | grep 'Go build ID' # Should appear
Certificate: Generate a self-signed cert with OpenSSL:
openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 90 -subj "/CN=atom.hutsell.com" -nodes
openssl pkcs12 -export -in cert.pem -inkey key.pem -out atom.pfx
Sign the PE with signtool sign /f atom.pfx repro.exe (Windows SDK) or osslsigncode.
Deployable Signatures
YARA Rule
rule ACRStealer_Go1185_AtomHutsellCert {
meta:
description = "ACR Stealer Go 1.18.5 variant with atom.hutsell.com self-signed cert"
author = "PacketPursuit"
date = "2026-08-02"
sha256 = "b0bc17dda19e36d395e354f6a861e93a70780029bb35116ea3616e316c588710"
strings:
$go_ver = "go1.18.5" ascii wide
$cert_cn = "atom.hutsell.com" ascii wide
$cert_issuer = "WR3" ascii wide
$buildinf = "\xff Go buildinf:" ascii
$modpath = /path\t[a-zA-Z0-9]{10,16}/ ascii
condition:
uint16(0) == 0x5A4D and
$go_ver and
$buildinf and
($cert_cn or $cert_issuer) and
#modpath >= 1 and
filesize > 5MB and filesize < 15MB
}
Sigma Rule
title: ACR Stealer Go 1.18.5 Process Execution
status: experimental
description: Detects execution of Go 1.18.5 PE32 infostealer with atom.hutsell.com cert
logsource:
category: process_creation
product: windows
detection:
selection:
- ImageLoaded|contains:
- 'fYkbKoZpcHZxFhs'
- Hashes|contains:
- 'b0bc17dda19e36d395e354f6a861e93a70780029bb35116ea3616e316c588710'
condition: selection
falsepositives:
- Unknown
level: high
IOC List
| Indicator | Type | Value |
|---|---|---|
| SHA-256 | hash | b0bc17dda19e36d395e354f6a861e93a70780029bb35116ea3616e316c588710 |
| SHA-1 | hash | 7c2a0f3e7d6e8f5a1b9c4d2e8f7a6b5c3d4e2f1a (placeholder — compute from sample) |
| MD5 | hash | e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0 (placeholder) |
| ssdeep | fuzzy | 49152:h/tF00KW1nNX6Mo/f9PABcJJ4DUD2GU4mhYmYD14:h/7TKWBAMon2cb4DUDvUHZ ^[triage.json] |
| Certificate CN | signing | atom.hutsell.com |
| Certificate issuer | signing | WR3 |
| Go module path | build | fYkbKoZpcHZxFhs |
| Go build ID | build | nub7pQwuoqp6ws1-Af3j/FIrg4Gbg9RrpIj724CoZ/FnJKhgExHKmmS62WT-8u/TjJbcQpbY1GJgrDn5wab |
| PE timestamp | build | 0x0 (null / stripped) |
Behavioral Fingerprint
This binary is a Go 1.18.5 static PE32 with a single kernel32.dll import table, no CGO, and a null PE timestamp. It contains 90+ randomized main.* function names and a .rsrc section with four PNG icons (16×16 through 256×256). At runtime it likely seeds a PRNG with the current time to decode C2 strings, then establishes a TLS-wrapped HTTPS session for credential exfiltration. No local persistence mechanism is visible statically; the operator likely relies on the dropper/installer for that stage.
Detection Signatures
- Capa not executed (signature path missing) ^[capa.txt]
- No YARA hits beyond generic
PE_File_Generic^[yara.txt] - ssdeep:
49152:h/tF00KW1nNX6Mo/f9PABcJJ4DUD2GU4mhYmYD14:h/7TKWBAMon2cb4DUDvUHZ^[triage.json]
References
- acrstealer — Family entity page
- golang-stealer-build-pattern — Build-pattern concept
- Sibling analyses:
ef262340(tenth),44f594e2(twelfth),350a2b69(fourteenth),beff95d5(fifteenth),119b387e(sixteenth),828405d6(thirteenth) - OpenCTI labels:
acrstealer,exe,urlhaus^[triage.json]
Provenance
Analysis derived from:
file.txt— file(1) outputpefile.txt— pefile Python library section and import parsingstrings.txt— GNU strings output (8,034 lines)rabin2-info.txt— radare2 binary header summarybinwalk.txt— embedded artefact scan (binwalk v2.3.4)exiftool.json— ExifTool PE metadatatriage.json— triage-fast metadatametadata.json— ssdeep / tlsh / hashesyara.txt— YARA rule matchesssdeep.txt/tlsh.txt— fuzzy hashes- Certificate extracted via
openssl pkcs7 -inform DER -print_certsat file offset0x74C808(binwalk-identified security directory)
CAPE skipped — no Windows guest available. All observations are static-only.