b39688635bb5b2a90bb9101b372080b61d6ba78f2cd78ee275a983a84e2a047dacrstealer: b3968863 — cloud55filecc mislabel, Go 1.25.4 x64, 65 randomized main.* functions
Executive Summary
Go 1.25.4 PE32+ x64 infostealer, preliminary OpenCTI label cloud55filecc. Certificate chain (quiverquant.com/WE1), Go build fingerprint, and module-path randomization resolve it to the acrstealer cluster as the 41st confirmed sibling (16th on the quiverquant.com/WE1 cert chain). .rsrc five-icon suite is intact. No static C2, no custom PE parser, no multi-pass decoder — a light baseline build. Static-only (CAPE skipped — no Windows guest).
What It Is
| Field | Value |
|---|---|
| SHA-256 | b39688635bb5b2a90bb9101b372080b61d6ba78f2cd78ee275a983a84e2a047d |
| Filename | kythy.exe ^[triage.json] |
| Size | 4,382,848 bytes (4.2 MB) ^[triage.json] |
| Type | PE32+ executable (GUI) x86-64, 9 sections ^[file.txt] |
| Compiler | Go 1.25.4 (GOARCH=amd64, GOOS=windows, CGO_ENABLED=0, -trimpath=true) ^[strings.txt] |
| Build ID | VNlBa05664SdWirgM_Nb/aaZg3rSxjkxXTzsPr5lU/ZIEYYxvROiXbJ7sEHv6I/4X_RMt9S-RlpJOS0Oc_0 ^[strings.txt] |
| Module path | kDIdfdDYIETHOsK ^[strings.txt] |
| Entry point | 0x72640 (ImageBase 0x140000000) ^[pefile.txt] |
| Timestamp | 0x0 (null, stripped) ^[pefile.txt] |
| Subsystem | Windows GUI ^[rabin2-info.txt] |
| ASLR / NX | Enabled (DYNAMIC_BASE, HIGH_ENTROPY_VA, NX_COMPAT) ^[pefile.txt] |
Build / RE
Toolchain. Standard Go 1.25.4 gc compiler for amd64 Windows. No CGO. -trimpath=true strips absolute source paths. Null PE timestamp — a cluster-wide trait. ^[strings.txt] ^[pefile.txt]
Signing. Authenticode self-signed certificate embedded at offset 0x42D808 (DER, PKCS#7). Subject CN=quiverquant.com, issuer CN=WE1, validity 2026-05-09 through 2026-08-07. 4096-bit RSA, SHA-256 signature. ^[openssl cert parse from raw binary]
Obfuscation. 65 randomized main.* function names (e.g. main.moowihnjzjmwuj, main.dlgycujlbuhhn, main.yybouhcfexaqzoi) — mid-range count for the cluster. No external packer; .text entropy ~6.26. ^[strings.txt] ^[pefile.txt]
Resources. .rsrc section contains five PNG icons (16×16, 32×32, 64×64, 128×128, 256×256 RGBA) — social-engineering masquerade intact. ^[binwalk.txt]
Anti-analysis. None observed statically beyond the Go runtime's natural symbol obfuscation and runtime C2 decoding (family pattern, see prng-seeded-c2-url-decoding). No anti-VM, no anti-debug, no sandbox gates. Light build.
Notable functions. main.main at 0x14009ad60 (per radare2 symbol recovery). Standard Go runtime init → main.main → goroutine spawn. No custom PE parser or multi-pass decoder present (unlike heavier ACR siblings such as d5655568 or 90d54589). ^[r2:sym.main.main]
How It Works
This is a cluster sibling of acrstealer; shared behaviour (browser credential theft, crypto wallet targeting, TLS C2 exfil) is documented on the family page. Per-sample deltas:
- Module path
kDIdfdDYIETHOsK— unique to this build. - 65 randomized
main.*symbols — mid-range count (cluster spans 11–92). ^[strings.txt] .rsrcicons intact — builder icon-toggle is ON. Contrast with siblingsc69b14a0,cdd16fc0,94cf86f6which strip.rsrc. ^[binwalk.txt]- No custom PE parser / no multi-pass decoder — lightest-tier ACR build; relies on standard Go library API resolution. ^[strings.txt]
- No static C2 — C2 endpoints are runtime-decoded via PRNG-seeded transform (see prng-seeded-c2-url-decoding). ^[strings.txt (absence of URLs)]
OpenCTI label cloud55filecc is contested. This label appears on 23 samples in the corpus; many (including 642ecaab, 8bb023f2, c88a5bba) share Go infostealer build fingerprints and resolve to the ACR/Lumma/OrderRe cluster. The cloud55filecc label is an opaque umbrella without independent technical fingerprint. This sample should be tracked under acrstealer.
Decompiled Behavior
Ghidra was not run for this sample (static analysis relied on radare2 + strings). Radare2 recovered 2,138 functions including standard Go runtime symbols and 65 main.* user functions. main.main sits at 0x14009ad60 and branches into multiple goroutines. No decompiled pseudo-C available beyond r2's function list. ^[r2:function list]
C2 Infrastructure
No hardcoded IPs, domains, or URLs recovered statically. C2 is runtime-resolved via PRNG-seeded string decoding (family-wide technique). Network capability is inferred from statically-linked net/http, crypto/tls, and crypto/x509 packages. ^[strings.txt]
Interesting Tidbits
- The
quiverquant.com/WE1cert chain is now the most prolific in the ACR cluster with 16 confirmed samples (including this one), surpassing theatom.hutsell.com/WR3chain (15 samples) and theme.muz.li/R13chain (4 samples). ^[entities/acrstealer.md] - This cert's validity window is unusually short (~90 days), consistent with rapid rotation observed across the cluster.
- The sample filename
kythy.exehas no semantic value — likely a random builder output name. - The
.symtabsection is present and non-empty (0x1B0F4 bytes), which is unusual for malware but standard for unstripped Go binaries. It provides free symbol recovery.
How To Mess With It (Homelab Replication)
To reproduce a comparable static fingerprint:
- Install Go 1.25.4 on Windows or cross-compile from Linux:
GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" -o repro.exe . - Use a self-signed Authenticode certificate with CN matching a legitimate-sounding domain.
- Randomize all exported function names in the
mainpackage (10–90 functions, 8–16 character mixed-case names). - Embed 5 PNG icons in
.rsrc(16×16 through 256×256). - Implement PRNG-seeded C2 URL decoding to ensure static extraction yields nothing.
- Verify with
capaandstrings— should match the ACR cluster fingerprint: no static C2, heavyruntime.*strings, randomizedmain.*names, null PE timestamp.
What you'll learn: How trivial it is for a Go builder to evade static string-based detection while retaining full infostealer capability via standard libraries.
Deployable Signatures
YARA Rule
rule ACR_Stealer_QuivQuant_We1_Chain {
meta:
description = "ACR Stealer variant with self-signed quiverquant.com/WE1 certificate"
author = "PacketPursuit"
date = "2026-08-16"
hash = "b39688635bb5b2a90bb9101b372080b61d6ba78f2cd78ee275a983a84e2a047d"
reference = "https://raw.githubusercontent.com/packetpursuit/wiki/main/entities/acrstealer.md"
strings:
$go_build = "go1.25.4" ascii
$go_build_id = "Go build ID:" ascii
$mod_path = "path\tkDIdfdDYIETHOsK" ascii
$cert_cn = "quiverquant.com" ascii
$we1 = "WE1" ascii
$main_prefix = "main." ascii
condition:
uint16(0) == 0x5A4D and
filesize < 6MB and
$go_build and
$go_build_id and
$cert_cn and
$we1 and
#main_prefix > 50
}
Behavioral Hunt Query (KQL)
DeviceFileEvents
| where FileName endswith ".exe"
| where FileSize < 6MB
| where (InitiatingProcessCommandLine contains "kythy" or FileName == "kythy.exe")
| union (
DeviceProcessEvents
| where ProcessCommandLine contains "kythy.exe"
| where AccountName != "SYSTEM"
)
| union (
DeviceNetworkEvents
| where RemoteUrl contains "quiverquant.com"
| where InitiatingProcessFileName endswith ".exe"
)
IOC List
| Indicator | Type | Notes |
|---|---|---|
b39688635bb5b2a90bb9101b372080b61d6ba78f2cd78ee275a983a84e2a047d |
SHA-256 | This sample |
kythy.exe |
Filename | Random builder output |
CN=quiverquant.com, issuer=WE1 |
Certificate | Self-signed, 4096-bit RSA |
kDIdfdDYIETHOsK |
Module path | Unique to this build |
| 2026-05-09 → 2026-08-07 | Cert validity | 90-day rotation window |
Behavioral Fingerprint
This binary is a Go 1.25.4 x64 static executable (no CGO, -trimpath) with a null PE timestamp and a self-signed Authenticode certificate (CN quiverquant.com, issuer WE1). It contains 50–70 randomized main.* functions, a populated .rsrc section with five PNG icons, and no hardcoded C2 strings. Upon execution, it spawns multiple goroutines and contacts a TLS-encrypted C2 endpoint decoded at runtime via a PRNG-seeded transform. Network traffic originates from the Go standard net/http and crypto/tls stacks. Static string extraction yields only runtime error messages and standard library symbols.
Detection Signatures
No capa output available for this sample (capa signatures missing on host). Based on cluster analysis, expected ATT&CK mappings:
- T1071.001 — Application Layer Protocol: Web Protocols (HTTPS C2)
- T1083 — File and Directory Discovery (browser profile enumeration)
- T1005 — Data from Local System (credential stores)
- T1041 — Exfiltration Over C2 Channel
- T1078.003 — Valid Accounts: Local Accounts (masquerade via self-signed cert)
- T1027.002 — Obfuscated Files or Information: Software Packing (Go static binary obfuscation)
- T1059.003 — Command and Scripting Interpreter: Windows Command Shell (indirect, via goroutine spawn)
Static-only inference; runtime TTPs would require CAPE detonation.
References
- acrstealer — family entity page
- golang-stealer-build-pattern — shared build artefacts
- prng-seeded-c2-url-decoding — runtime C2 resolution technique
- lummastealer — contested sibling cluster
- OpenCTI artifact
cc0293ee-6590-4671-8b85-5e4805ec1b47— preliminary labelscloud55file-cc,neuralpulsecore5-sbs,signed
Provenance
file.txt— file(1) outputpefile.txt— pefile Python library header dumprabin2-info.txt— radare2rabin2 -Iheader summarystrings.txt—strings -n 8output (7,977 lines)binwalk.txt— binwalk embedded-artefact scanexiftool.json— ExifTool PE metadatatriage.json— triage pipeline metadata- OpenSSL x509 — manual certificate extraction from
IMAGE_DIRECTORY_ENTRY_SECURITY - radare2 —
aaanalysis,aangGo symbol recovery, 2,138 functions recovered
Report authored: 2026-08-16 by Demetrian Titus (pp-hermes).