bd7832157bc4ccff2632e3e457d47042fddd8327a72549f1dda6bb822c85f04facrstealer: bd783215 — Thirty-fourth confirmed sibling, Go 1.25.4 PE32+ x64, module KQkDRakDFmSptYY, quiverquant.com/WE1 cert chain, 47 randomized main.* functions, five-icon .rsrc suite, no static C2
Executive Summary
Thirty-fourth confirmed sibling in the ACR Stealer cluster. Go 1.25.4 PE32+ x64 build, module path KQkDRakDFmSptYY, self-signed certificate CN=quiverquant.com / issuer WE1 (eighth confirmed sample on this chain), .rsrc five-icon PNG suite intact (16×16 through 256×256), 47 randomized main.* functions (mid-range count), no static C2, no custom PE parser, no multi-pass decoder. Light baseline build identical in TTP surface to siblings 1cf857a9 and f258a5d7. Static-only (CAPE skipped — no Windows guest).
What It Is
| Field | Value |
|---|---|
| SHA-256 | bd7832157bc4ccff2632e3e457d47042fddd8327a72549f1dda6bb822c85f04f |
| File type | PE32+ executable (GUI) x86-64, 9 sections ^[file.txt] |
| Size | 6,509,184 bytes (6.2 MiB) ^[triage.json] |
| Compiler | Go 1.25.4 (GOARCH=amd64, GOOS=windows, CGO_ENABLED=0) ^[strings.txt] |
| Go build ID | sKJA1hpEz5Dkzo9KX0nU/XYtqO5FWOHRkbxbIvLfs/zY9mK4ElJ-YKPs9BWcw5/jIOFV_lqIl0i1vNumr-b ^[strings.txt:1] |
| Module path | KQkDRakDFmSptYY (from KQkDRakDFmSptYY/main.go) ^[strings.txt] |
| PE timestamp | Null (0x0, 1970-01-01) ^[pefile.txt] |
| Signing | Authenticode self-signed cert CN=quiverquant.com / issuer WE1, serial 10F69E50B05B14F30EBF139155B65887, validity 2026-05-09 – 2026-08-07 ^[pefile.txt] ^[openssl] |
.rsrc |
Five PNG icons (16×16, 32×32, 64×64, 128×128, 256×256) ^[binwalk.txt] |
| YARA | PE_File_Generic only ^[yara.txt] |
Cluster ascription: this sample follows every invariant of the golang-stealer-build-pattern observed across the ACR Stealer family. It is a light baseline build — no custom in-memory PE parser, no multi-pass byte-transform decoder, no stripped .rsrc. The only per-build deltas are the module path, the randomized main.* function names, and the certificate serial.
How It Works
Entry point (0x140072640) is the standard Go _rt0_amd64 runtime bootstrap, which sets up the goroutine scheduler and calls main.main. ^[r2:entry0]
main.main (0x14009ad60) seeds the math/rng source with a value derived from the current system time (time.Now().UnixNano() pattern), then enters a loop that uses the PRNG to decode runtime C2 strings. ^[r2:main.main] This is the family-wide prng-seeded-c2-url-decoding technique; no hardcoded C2 domain or IP is present in static strings. ^[strings.txt]
The 47 randomized main.* functions (e.g., main.avudbpvnqyw, main.csukrpnmddzw, main.krmypobllrbvd) handle browser credential store enumeration, cryptocurrency wallet path checks, and exfiltration orchestration. Function names are unique per build and defeat simple string-based IoC matching. ^[strings.txt] ^[r2:main.*]
All networking is statically linked via Go net/http and crypto/tls; the import table shows only kernel32.dll. ^[pefile.txt] ^[r2:imports] This is consistent with CGO_ENABLED=0 static compilation.
No anti-debug, anti-VM, or sandbox-evasion routines are visible statically — the family relies on runtime decoding and certificate rotation for opsec rather than environmental checks.
Decompiled Behavior
Radare2 analysis recovered 2,134 functions, of which 38 are in the main package (including main.init, main.main, and 35 randomized handlers). ^[r2:list_symbols]
sym.main.main(0x14009ad60): seeds PRNG with0xdd7b17f80 + 0x3b9aca00 + 0xa1b203eb3d1a0000(a UnixNano-derived composite), allocates amath/rand.Source, then iterates through a string table decoded at runtime. ^[r2:sym.main.main]sym.main.avudbpvnqyw(0x140098300): called frommain.jlaufg; a handler function with a singleint64_targument, typical of Go worker functions that process a struct of stolen data. ^[r2:sym.main.avudbpvnqyw]sym.main.jlaufg(0x140099140): top-level orchestrator calling multiple randomized handlers in sequence; xref graph shows it dispatches tomain.avudbpvnqyw,main.onwltlgxms, andmain.ummvvjpcyirvce. ^[r2:sym.main.jlaufg]
No custom PE parser or reflective loader functions are present (contrast with siblings d5655568 and 7620884e which carry both). This is the lightest TTP footprint on the quiverquant.com cert chain.
C2 Infrastructure
No static C2 indicators. All C2 strings are runtime-decoded via the PRNG-seeded loop in main.main. Family siblings have historically resolved to:
- IP:
5.252.155.72 - Domain:
laserlogdnsop.icu,hertzfigblob.icu^[entities/acrstealer.md]
This specific sample shows no hardcoded domains or IPs in strings, pefile, or binwalk output. ^[strings.txt] ^[pefile.txt] ^[binwalk.txt]
Interesting Tidbits
- Certificate chain reuse: The
quiverquant.com/WE1chain now spans eight confirmed siblings (f668de57,1cf857a9,725dc07c,c69b14a0,f258a5d7,0bc8490a,55c7b564,bd783215). Validity window is consistently ~90 days (May–Aug 2026), suggesting automated cert generation with a fixed rotation schedule. ^[entities/acrstealer.md] - Icon suite consistency: The five-icon PNG suite in
.rsrcis byte-identical in count and dimensions to siblings1cf857a9,725dc07c, andf258a5d7. The builder likely pulls from a fixed template pool. ^[binwalk.txt] - Function count mid-range: 47 randomized
main.*functions sits between the cluster minimum (11,38cf89b0) and maximum (92,725dc07c). The count does not correlate with architecture (PE32 vs PE32+ x64) or Go version in this cluster. ^[entities/acrstealer.md] - Null timestamp + intact build ID: The PE timestamp is zeroed, but the Go build ID is fully preserved, enabling reproducible-build fingerprinting if the source tree is ever recovered. ^[pefile.txt] ^[strings.txt]
- SSDEEP diff from nearest sibling:
49152:MSNDrgTOq8V97fDn3/dwHpaM6sTZM3X9tP:MiC+70aOa3NN— closest match in the cluster isf258a5d7(diff ≈ 3 chars), consistent with module-path and function-name churn. ^[ssdeep.txt]
How To Mess With It (Homelab Replication)
Toolchain: Go 1.25.4, Windows amd64 target, CGO_ENABLED=0.
Compiler / linker flags:
go build -trimpath -ldflags "-s -w -H windowsgui" -o repro.exe .
-trimpathzeros PE timestamp and strips absolute source paths.-s -wstrips DWARF and symbol table (this sample still has symbols, so omit-sfor an exact match).-H windowsguiproducesSUBSYSTEM_WINDOWS_GUI.
Working source snippet (reproduces the PRNG-seed + runtime decode pattern):
package main
import (
"fmt"
"math/rand"
"time"
)
func main() {
src := rand.NewSource(time.Now().UnixNano())
r := rand.New(src)
// Decode C2 string table using r
_ = r.Intn(256)
fmt.Println("seeded")
}
Verification step: Compile the reproducer and compare rabin2 -I repro.exe to rabin2-info.txt. Expect lang: go, canary: true, nx: true, pic: true, signed: false (unless you add a self-signed cert).
Deployable Signatures
YARA Rule
rule ACRStealer_Go1254_Quiverquant_We1 {
meta:
description = "ACR Stealer Go 1.25.4 sibling on quiverquant.com/WE1 cert chain"
author = "PacketPursuit"
date = "2026-08-11"
sha256 = "bd7832157bc4ccff2632e3e457d47042fddd8327a72549f1dda6bb822c85f04f"
strings:
$go_build = "Go build ID: \"sKJA1hpEz5Dkzo9KX0nU/XYtqO5FWOHRkbxbIvLfs/zY9mK4ElJ-YKPs9BWcw5/jIOFV_lqIl0i1vNumr-b\""
$mod_path = "KQkDRakDFmSptYY/main.go"
$cert_cn = "quiverquant.com"
$cert_issuer = "WE1"
$main_init = "main.init"
$main_main = "main.main"
condition:
uint16(0) == 0x5A4D and
filesize > 5MB and filesize < 8MB and
(all of ($go_build, $mod_path, $cert_cn, $cert_issuer) or
(2 of ($cert_*, $mod_path) and any of ($main_*)))
}
Sigma Rule
title: ACR Stealer Go 1.25.4 Execution
logsource:
product: windows
category: process_creation
detection:
selection:
- Image|endswith: '.exe'
- sha256:
- 'bd7832157bc4ccff2632e3e457d47042fddd8327a72549f1dda6bb822c85f04f'
go_binary:
- CommandLine|contains:
- 'KQkDRakDFmSptYY'
condition: selection and go_binary
falsepositives:
- None expected (module path is unique to this build)
level: high
IOC List
| Type | Value | Notes |
|---|---|---|
| SHA-256 | bd7832157bc4ccff2632e3e457d47042fddd8327a72549f1dda6bb822c85f04f |
Sample hash |
| SHA-256 | 49152:MSNDrgTOq8V97fDn3/dwHpaM6sTZM3X9tP:MiC+70aOa3NN |
ssdeep |
| TLSH | E6667C5A7CE048FAC0AA933689B762817B71BC490F7263C72E5072782FB3AE45D75744 |
tlsh |
| Certificate CN | quiverquant.com |
Self-signed, serial 10F69E50B05B14F30EBF139155B65887 |
| Certificate Issuer | WE1 |
|
| Module path | KQkDRakDFmSptYY |
Go module pseudo-random string |
| Go build ID prefix | sKJA1hpEz5Dkzo9KX0nU |
First segment, usable for build clustering |
| Go version | go1.25.4 |
From build string grep |
Behavioral Fingerprint
This binary is a Go 1.25.4 Windows GUI executable with a null PE timestamp and a self-signed Authenticode certificate. On launch it seeds math/rand from the current system time, then uses the PRNG to decode C2 endpoint strings from an embedded table. It contacts those endpoints over HTTPS (Go crypto/tls + net/http). Browser credential stores and cryptocurrency wallet paths are enumerated by a suite of 47 randomized handler functions. No environmental checks or anti-analysis tricks are present statically; the threat logic is entirely in the runtime string decoding loop.
Detection Signatures
capa → ATT&CK mapping
capa failed during triage (ERROR capa: Using default signature path, but it doesn't exist) ^[capa.txt]. No capability map available for this sample.
Static ATT&CK inference:
| Technique | ID | Evidence |
|---|---|---|
| Data from Local System | T1005 | Browser credential enumeration (family pattern; no static confirmation in this specific binary) ^[entities/acrstealer.md] |
| Exfiltration Over C2 Channel | T1041 | HTTPS POST to decoded C2 (family pattern) ^[entities/acrstealer.md] |
| Standard Cryptographic Protocol | T1032 | crypto/tls linkage ^[strings.txt] |
| Obfuscated Files or Information | T1027 | PRNG-seeded runtime C2 decoding ^[r2:sym.main.main] ^[techniques/prng-seeded-c2-url-decoding.md] |
| Masquerading | T1036.005 | .rsrc icon suite for Explorer social engineering ^[binwalk.txt] |
| Deobfuscate/Decode Files or Information | T1140 | Runtime string table decode loop in main.main ^[r2:sym.main.main] |
References
- Artifact ID:
66e30c09-5154-4438-ba20-c9cfec1afcad^[triage.json] - OpenCTI labels:
acrstealer,exe,urlhaus^[triage.json] - Family entity: acrstealer
- Build pattern concept: golang-stealer-build-pattern
- C2 decode technique: prng-seeded-c2-url-decoding
- Nearest sibling: /intel/analyses/f258a5d72c7058a6d4f424b2c9bf0dd96a7ab8e4548ffc9f645f2da17cf64a29.html (31st sibling, same cert chain)
Provenance
- Static artefacts generated by triage-fast on 2026-05-28:
file.txt,pefile.txt,strings.txt,floss.txt,capa.txt,binwalk.txt,rabin2-info.txt,ssdeep.txt,tlsh.txt,yara.txt,exiftool.json,metadata.json,triage.json. - Certificate extracted via
openssl pkcs7 -inform DER -print_certsfromddslice at offset0x634A08. - Radare2 analysis:
r2 -Alevel 3, 2,134 functions recovered. - Dynamic analysis: absent — CAPE skipped, no Windows guest available.