typeanalysisfamilyacrstealerconfidencehighcreated2026-08-11updated2026-08-11infostealermalware-familygolangsigningpe
SHA-256: bd7832157bc4ccff2632e3e457d47042fddd8327a72549f1dda6bb822c85f04f

acrstealer: bd783215 — Thirty-fourth confirmed sibling, Go 1.25.4 PE32+ x64, module KQkDRakDFmSptYY, quiverquant.com/WE1 cert chain, 47 randomized main.* functions, five-icon .rsrc suite, no static C2

Executive Summary Thirty-fourth confirmed sibling in the ACR Stealer cluster. Go 1.25.4 PE32+ x64 build, module path KQkDRakDFmSptYY, self-signed certificate CN=quiverquant.com / issuer WE1 (eighth confirmed sample on this chain), .rsrc five-icon PNG suite intact (16×16 through 256×256), 47 randomized main.* functions (mid-range count), no static C2, no custom PE parser, no multi-pass decoder. Light baseline build identical in TTP surface to siblings 1cf857a9 and f258a5d7. Static-only (CAPE skipped — no Windows guest).

What It Is

Field Value
SHA-256 bd7832157bc4ccff2632e3e457d47042fddd8327a72549f1dda6bb822c85f04f
File type PE32+ executable (GUI) x86-64, 9 sections ^[file.txt]
Size 6,509,184 bytes (6.2 MiB) ^[triage.json]
Compiler Go 1.25.4 (GOARCH=amd64, GOOS=windows, CGO_ENABLED=0) ^[strings.txt]
Go build ID sKJA1hpEz5Dkzo9KX0nU/XYtqO5FWOHRkbxbIvLfs/zY9mK4ElJ-YKPs9BWcw5/jIOFV_lqIl0i1vNumr-b ^[strings.txt:1]
Module path KQkDRakDFmSptYY (from KQkDRakDFmSptYY/main.go) ^[strings.txt]
PE timestamp Null (0x0, 1970-01-01) ^[pefile.txt]
Signing Authenticode self-signed cert CN=quiverquant.com / issuer WE1, serial 10F69E50B05B14F30EBF139155B65887, validity 2026-05-09 – 2026-08-07 ^[pefile.txt] ^[openssl]
.rsrc Five PNG icons (16×16, 32×32, 64×64, 128×128, 256×256) ^[binwalk.txt]
YARA PE_File_Generic only ^[yara.txt]

Cluster ascription: this sample follows every invariant of the golang-stealer-build-pattern observed across the ACR Stealer family. It is a light baseline build — no custom in-memory PE parser, no multi-pass byte-transform decoder, no stripped .rsrc. The only per-build deltas are the module path, the randomized main.* function names, and the certificate serial.

How It Works

Entry point (0x140072640) is the standard Go _rt0_amd64 runtime bootstrap, which sets up the goroutine scheduler and calls main.main. ^[r2:entry0]

main.main (0x14009ad60) seeds the math/rng source with a value derived from the current system time (time.Now().UnixNano() pattern), then enters a loop that uses the PRNG to decode runtime C2 strings. ^[r2:main.main] This is the family-wide prng-seeded-c2-url-decoding technique; no hardcoded C2 domain or IP is present in static strings. ^[strings.txt]

The 47 randomized main.* functions (e.g., main.avudbpvnqyw, main.csukrpnmddzw, main.krmypobllrbvd) handle browser credential store enumeration, cryptocurrency wallet path checks, and exfiltration orchestration. Function names are unique per build and defeat simple string-based IoC matching. ^[strings.txt] ^[r2:main.*]

All networking is statically linked via Go net/http and crypto/tls; the import table shows only kernel32.dll. ^[pefile.txt] ^[r2:imports] This is consistent with CGO_ENABLED=0 static compilation.

No anti-debug, anti-VM, or sandbox-evasion routines are visible statically — the family relies on runtime decoding and certificate rotation for opsec rather than environmental checks.

Decompiled Behavior

Radare2 analysis recovered 2,134 functions, of which 38 are in the main package (including main.init, main.main, and 35 randomized handlers). ^[r2:list_symbols]

  • sym.main.main (0x14009ad60): seeds PRNG with 0xdd7b17f80 + 0x3b9aca00 + 0xa1b203eb3d1a0000 (a UnixNano-derived composite), allocates a math/rand.Source, then iterates through a string table decoded at runtime. ^[r2:sym.main.main]
  • sym.main.avudbpvnqyw (0x140098300): called from main.jlaufg; a handler function with a single int64_t argument, typical of Go worker functions that process a struct of stolen data. ^[r2:sym.main.avudbpvnqyw]
  • sym.main.jlaufg (0x140099140): top-level orchestrator calling multiple randomized handlers in sequence; xref graph shows it dispatches to main.avudbpvnqyw, main.onwltlgxms, and main.ummvvjpcyirvce. ^[r2:sym.main.jlaufg]

No custom PE parser or reflective loader functions are present (contrast with siblings d5655568 and 7620884e which carry both). This is the lightest TTP footprint on the quiverquant.com cert chain.

C2 Infrastructure

No static C2 indicators. All C2 strings are runtime-decoded via the PRNG-seeded loop in main.main. Family siblings have historically resolved to:

  • IP: 5.252.155.72
  • Domain: laserlogdnsop.icu, hertzfigblob.icu ^[entities/acrstealer.md]

This specific sample shows no hardcoded domains or IPs in strings, pefile, or binwalk output. ^[strings.txt] ^[pefile.txt] ^[binwalk.txt]

Interesting Tidbits

  • Certificate chain reuse: The quiverquant.com / WE1 chain now spans eight confirmed siblings (f668de57, 1cf857a9, 725dc07c, c69b14a0, f258a5d7, 0bc8490a, 55c7b564, bd783215). Validity window is consistently ~90 days (May–Aug 2026), suggesting automated cert generation with a fixed rotation schedule. ^[entities/acrstealer.md]
  • Icon suite consistency: The five-icon PNG suite in .rsrc is byte-identical in count and dimensions to siblings 1cf857a9, 725dc07c, and f258a5d7. The builder likely pulls from a fixed template pool. ^[binwalk.txt]
  • Function count mid-range: 47 randomized main.* functions sits between the cluster minimum (11, 38cf89b0) and maximum (92, 725dc07c). The count does not correlate with architecture (PE32 vs PE32+ x64) or Go version in this cluster. ^[entities/acrstealer.md]
  • Null timestamp + intact build ID: The PE timestamp is zeroed, but the Go build ID is fully preserved, enabling reproducible-build fingerprinting if the source tree is ever recovered. ^[pefile.txt] ^[strings.txt]
  • SSDEEP diff from nearest sibling: 49152:MSNDrgTOq8V97fDn3/dwHpaM6sTZM3X9tP:MiC+70aOa3NN — closest match in the cluster is f258a5d7 (diff ≈ 3 chars), consistent with module-path and function-name churn. ^[ssdeep.txt]

How To Mess With It (Homelab Replication)

Toolchain: Go 1.25.4, Windows amd64 target, CGO_ENABLED=0.

Compiler / linker flags:

go build -trimpath -ldflags "-s -w -H windowsgui" -o repro.exe .
  • -trimpath zeros PE timestamp and strips absolute source paths.
  • -s -w strips DWARF and symbol table (this sample still has symbols, so omit -s for an exact match).
  • -H windowsgui produces SUBSYSTEM_WINDOWS_GUI.

Working source snippet (reproduces the PRNG-seed + runtime decode pattern):

package main

import (
    "fmt"
    "math/rand"
    "time"
)

func main() {
    src := rand.NewSource(time.Now().UnixNano())
    r := rand.New(src)
    // Decode C2 string table using r
    _ = r.Intn(256)
    fmt.Println("seeded")
}

Verification step: Compile the reproducer and compare rabin2 -I repro.exe to rabin2-info.txt. Expect lang: go, canary: true, nx: true, pic: true, signed: false (unless you add a self-signed cert).

Deployable Signatures

YARA Rule

rule ACRStealer_Go1254_Quiverquant_We1 {
    meta:
        description = "ACR Stealer Go 1.25.4 sibling on quiverquant.com/WE1 cert chain"
        author = "PacketPursuit"
        date = "2026-08-11"
        sha256 = "bd7832157bc4ccff2632e3e457d47042fddd8327a72549f1dda6bb822c85f04f"
    strings:
        $go_build = "Go build ID: \"sKJA1hpEz5Dkzo9KX0nU/XYtqO5FWOHRkbxbIvLfs/zY9mK4ElJ-YKPs9BWcw5/jIOFV_lqIl0i1vNumr-b\""
        $mod_path = "KQkDRakDFmSptYY/main.go"
        $cert_cn = "quiverquant.com"
        $cert_issuer = "WE1"
        $main_init = "main.init"
        $main_main = "main.main"
    condition:
        uint16(0) == 0x5A4D and
        filesize > 5MB and filesize < 8MB and
        (all of ($go_build, $mod_path, $cert_cn, $cert_issuer) or
         (2 of ($cert_*, $mod_path) and any of ($main_*)))
}

Sigma Rule

title: ACR Stealer Go 1.25.4 Execution
logsource:
    product: windows
    category: process_creation
detection:
    selection:
        - Image|endswith: '.exe'
        - sha256:
            - 'bd7832157bc4ccff2632e3e457d47042fddd8327a72549f1dda6bb822c85f04f'
    go_binary:
        - CommandLine|contains:
            - 'KQkDRakDFmSptYY'
    condition: selection and go_binary
falsepositives:
    - None expected (module path is unique to this build)
level: high

IOC List

Type Value Notes
SHA-256 bd7832157bc4ccff2632e3e457d47042fddd8327a72549f1dda6bb822c85f04f Sample hash
SHA-256 49152:MSNDrgTOq8V97fDn3/dwHpaM6sTZM3X9tP:MiC+70aOa3NN ssdeep
TLSH E6667C5A7CE048FAC0AA933689B762817B71BC490F7263C72E5072782FB3AE45D75744 tlsh
Certificate CN quiverquant.com Self-signed, serial 10F69E50B05B14F30EBF139155B65887
Certificate Issuer WE1
Module path KQkDRakDFmSptYY Go module pseudo-random string
Go build ID prefix sKJA1hpEz5Dkzo9KX0nU First segment, usable for build clustering
Go version go1.25.4 From build string grep

Behavioral Fingerprint

This binary is a Go 1.25.4 Windows GUI executable with a null PE timestamp and a self-signed Authenticode certificate. On launch it seeds math/rand from the current system time, then uses the PRNG to decode C2 endpoint strings from an embedded table. It contacts those endpoints over HTTPS (Go crypto/tls + net/http). Browser credential stores and cryptocurrency wallet paths are enumerated by a suite of 47 randomized handler functions. No environmental checks or anti-analysis tricks are present statically; the threat logic is entirely in the runtime string decoding loop.

Detection Signatures

capa → ATT&CK mapping

capa failed during triage (ERROR capa: Using default signature path, but it doesn't exist) ^[capa.txt]. No capability map available for this sample.

Static ATT&CK inference:

Technique ID Evidence
Data from Local System T1005 Browser credential enumeration (family pattern; no static confirmation in this specific binary) ^[entities/acrstealer.md]
Exfiltration Over C2 Channel T1041 HTTPS POST to decoded C2 (family pattern) ^[entities/acrstealer.md]
Standard Cryptographic Protocol T1032 crypto/tls linkage ^[strings.txt]
Obfuscated Files or Information T1027 PRNG-seeded runtime C2 decoding ^[r2:sym.main.main] ^[techniques/prng-seeded-c2-url-decoding.md]
Masquerading T1036.005 .rsrc icon suite for Explorer social engineering ^[binwalk.txt]
Deobfuscate/Decode Files or Information T1140 Runtime string table decode loop in main.main ^[r2:sym.main.main]

References

  • Artifact ID: 66e30c09-5154-4438-ba20-c9cfec1afcad ^[triage.json]
  • OpenCTI labels: acrstealer, exe, urlhaus ^[triage.json]
  • Family entity: acrstealer
  • Build pattern concept: golang-stealer-build-pattern
  • C2 decode technique: prng-seeded-c2-url-decoding
  • Nearest sibling: /intel/analyses/f258a5d72c7058a6d4f424b2c9bf0dd96a7ab8e4548ffc9f645f2da17cf64a29.html (31st sibling, same cert chain)

Provenance

  • Static artefacts generated by triage-fast on 2026-05-28: file.txt, pefile.txt, strings.txt, floss.txt, capa.txt, binwalk.txt, rabin2-info.txt, ssdeep.txt, tlsh.txt, yara.txt, exiftool.json, metadata.json, triage.json.
  • Certificate extracted via openssl pkcs7 -inform DER -print_certs from dd slice at offset 0x634A08.
  • Radare2 analysis: r2 -A level 3, 2,134 functions recovered.
  • Dynamic analysis: absent — CAPE skipped, no Windows guest available.