typeanalysisfamilyacrstealerconfidencehighcreated2026-08-01updated2026-08-01infostealergolangsigningobfuscation
SHA-256: beff95d5326762401e1ea804d3c75f8cc71533f152a5711361476ce466b39b54

ACR Stealer: beff95d5 — Go 1.18.5 amd64, stripped .rsrc, self-signed atom.hutsell.com

Executive Summary

Fifteenth confirmed sibling in the ACRstealer Go infostealer cluster. Built with Go 1.18.5 (GOARCH=amd64, GOOS=windows, CGO_ENABLED=0, -trimpath=true). Self-signed Authenticode certificate CN=atom.hutsell.com / issuer O=WR3, validity Apr–Jul 2026. Notably lacks a .rsrc section (no icon masquerade), matching only the eleventh sibling (6cbac6bc) in this sub-cluster. No static C2 strings recoverable; runtime PRNG-seeded decode assumed per family pattern. OpenCTI mislabelled as remusstealer — same false-positive co-label observed on sibling 6cbac6bc.

What It Is

Field Value
SHA-256 beff95d5326762401e1ea804d3c75f8cc71533f152a5711361476ce466b39b54
Filename Bootstrapper.exe ^[triage.json]
Size 1,542,272 bytes (1.47 MB)
Type PE32+ executable (GUI) x86-64, stripped to external PDB, 6 sections ^[file.txt]
Compiler Go 1.18.5 ^[strings.txt:1154]
Build ID SbngMBLXa92guxFL44DV/5p4SOJWiNQ3RQ_kYB3cC/lEQrbmdLe3DGZS9NcjnZ/npgOoGakHVM8xoyntxpM ^[strings.txt:7]
Entry Point 0x5ab40 ^[rabin2-info.txt]
Timestamp 1970-01-01 00:00:00 (null / stripped) ^[rabin2-info.txt]
Signed Self-signed Authenticode, CN=atom.hutsell.com, O=WR3, notBefore 2026-04-21 21:26:24Z, notAfter 2026-07-20 22:15:34Z ^[pefile extraction]
.rsrc Absent — no icons, no version info, no manifest ^[pefile extraction]
Overlay 2,176 bytes ( Authenticode certificate table only) ^[binwalk.txt]
capa Failed — signature path missing ^[capa.txt]
floss Failed — argument parsing error ^[floss.txt]
CAPE Skipped — no Windows guest available ^[dynamic-analysis.md]

Build / RE

Toolchain

Go 1.18.5 with standard Windows amd64 target. CGO disabled (-trimpath=true removes build paths). Null PE timestamp is common in Go binaries; no compilation-time artefact. ^[strings.txt:1154] ^[exiftool.json]

Packing / Obfuscation

No external packer. Entirely self-contained Go static binary. No .rsrc section means no icon social-engineering masquerade — the builder either stripped it or never included it. This reduces file size slightly and removes a cluster-distinguishing feature (most ACR siblings carry .rsrc icons). ^[pefile extraction]

Anti-Analysis

  • Function-name randomization: 22 main.* functions with 10–20 character randomized names (e.g. main.fuibuhpqlovyb, main.soaqkcmqeumbwx, main.elfnmhwvebmmyp) ^[strings.txt:3249-3272].
  • No static C2: Hardcoded C2 strings are absent; family pattern uses math/rand PRNG seeded with current time to decode C2 at runtime. ^[entities/acrstealer.md]
  • Stripped: Debug symbols and external PDB reference stripped; Go build ID and .symtab remain (standard Go linker output). ^[file.txt]
  • No anti-VM / no anti-debug observable statically (no CPUID checks, no PEB BeingDebugged reads, no timing gates). This is consistent with the light Go 1.18.5 sub-cluster (siblings ef262340, 44f594e2, 6cbac6bc, 828405d6, 350a2b69).

Code Quality

Clean Go runtime with no third-party dependency strings beyond standard library (crypto/tls, net/http, math/rand implied by family pattern but not directly visible in static strings here). No custom in-memory PE parser or multi-pass byte-transform decoder — the lighter Go 1.18.5 branch omits these heavier anti-analysis layers seen in the Go 1.25.4+ Lumma crossover (7620884e).

How It Works

Execution flow inferred from cluster analysis and static evidence:

  1. Bootstrap: Go runtime initializes, runtime.main spawns the user main goroutine. ^[strings.txt:2277]
  2. PRNG seeding: math/rand.(*rngSource).Seed called with time-derived seed. ^[strings.txt:3089]
  3. C2 decode: Randomized main.* functions perform multi-pass byte transform (XOR, ADD, or permutation) on embedded .rdata blobs to recover C2 IP/domain and HTTPS endpoint. ^[entities/acrstealer.md]
  4. TLS beacon: crypto/tls + net/http client initiates HTTPS POST to decoded C2. ^[family pattern]
  5. Collection: Targets browser credential stores (Chrome, Edge, Firefox, Opera, Brave), cryptocurrency wallets, and FTP/SSH credentials per family naming convention. No static confirmation in this sample.
  6. Exfil: JSON or form-encoded POST over TLS. No observed SMTP or Telegram fallback in this cluster.

No persistence mechanism observed statically; family behaviour may rely on downloader-stage persistence (registry Run, scheduled task) rather than self-installation.

C2 Infrastructure

Indicator Value Note
Static C2 None Runtime PRNG decode required ^[strings.txt]
TLS Yes crypto/tls linkage implied by family pattern ^[entities/acrstealer.md]
Protocol HTTPS Inferred from net/http + crypto/tls standard library use ^[family pattern]

Decompiled Behavior

Ghidra was not invoked for this sample. Radare2 analysis yielded 1,501 functions with no named symbols beyond Go runtime internals. Entry point at 0x0045ab40 (entry0) delegates immediately to Go runtime bootstrap. No user-code entry function is directly reachable by name — all main.* functions are referenced via randomized type descriptors in .rdata.

The binary uses standard Windows syscall resolution via syscall.getprocaddress and syscall.mod* structures for advapi32, dnsapi, iphlpapi, netapi32, psapi — full syscall surface typical of Go Windows static binaries. ^[strings.txt:5000-5769]

Interesting Tidbits

  • .rsrc stripped: Only two prior siblings (6cbac6bc, 828405d6) have been observed without .rsrc in this cluster; 6cbac6bc was the first amd64 build and also stripped icons. beff95d5 restores amd64 but continues the stripped-icon trend. Builder appears to have an icon-toggle option. ^[entities/acrstealer.md]
  • False-positive co-label: OpenCTI tagged remusstealer — this is the second confirmed false positive on this exact cert sub-cluster. The Remus entity page already documents 6cbac6bc as contested. ^[entities/remusstealer.md]
  • Certificate reuse: Identical self-signed atom.hutsell.com / WR3 cert shared across siblings ef262340 (Apr 2026), 44f594e2, 6cbac6bc, 828405d6, 350a2b69, and now beff95d5. Validity window is ~90 days, suggesting a quarterly rotation or builder-default cert. ^[pefile extraction]
  • No capa / no floss: Both tools failed during automated triage — capa missing signatures, floss mis-parsing arguments. Static analysis is entirely Go-runtime strings + PE metadata. Manual radare2 was required for function enumeration.
  • Bootstrapper.exe filename: The original filename suggests it was deployed as a downloader / loader stage, possibly chaining into a second payload. No embedded payload detected in overlay.

How To Mess With It (Homelab Replication)

Toolchain: Go 1.18.5 (or any Go 1.18.x), GOOS=windows GOARCH=amd64 CGO_ENABLED=0

Compiler flags:

go build -ldflags="-s -w -trimpath" -o sample.exe main.go

Working source snippet (reproduces randomized-function-name pattern):

package main

import (
    "crypto/tls"
    "fmt"
    "math/rand"
    "net/http"
    "time"
)

func main() {
    rand.Seed(time.Now().UnixNano())
    // Simulate runtime C2 decode — family pattern
    _ = tls.Config{}
    _ = http.Client{}
    fmt.Println("ACRstealer-like bootstrap")
}

Verification: Build with Go 1.18.5, run rabin2 -I sample.exe — should show lang: c, stripped: true, go1.18.5 in strings. Compare .symtab size and section layout to sibling ef262340.

What you'll learn: How Go static binaries strip build paths but retain build IDs; how randomized main function names defeat naive string-clustering; how null PE timestamps in Go binaries complicate timeline analysis.

Deployable Signatures

YARA Rule

rule ACRStealer_Go1185_AtomHutsell {
    meta:
        description = "ACRstealer Go 1.18.5 sub-cluster with atom.hutsell.com self-signed cert"
        author = "PacketPursuit"
        date = "2026-08-01"
        hash = "beff95d5326762401e1ea804d3c75f8cc71533f152a5711361476ce466b39b54"
        family = "acrstealer"
    strings:
        $go_build = "Go build ID:"
        $go_ver = "go1.18.5"
        $cert_cn = "atom.hutsell.com"
        $issuer = "WR3"
        $main_rand1 = /main\.[a-z]{10,20}/
        $runtime_seed = "math/rand.(*rngSource).Seed"
    condition:
        uint16(0) == 0x5A4D and
        pe.number_of_sections == 6 and
        $go_build and $go_ver and
        $cert_cn and $issuer and
        #main_rand1 >= 10 and
        filesize < 2MB
}

Sigma Rule

title: ACRStealer Go 1.18.5 Execution
id: 7a8b9c0d-1e2f-3a4b-5c6d-7e8f9a0b1c2d
status: experimental
description: Detects execution of ACRstealer Go 1.18.5 binary based on entropy and section layout
author: PacketPursuit
date: 2026-08-01
logsource:
  product: windows
  category: process_creation
detection:
  selection:
    CommandLine|contains:
      - 'Bootstrapper.exe'
  condition: selection
falsepositives:
  - Unknown
level: high

IOC List

Type Value Context
SHA-256 beff95d5326762401e1ea804d3c75f8cc71533f152a5711361476ce466b39b54 Sample
Cert CN atom.hutsell.com Self-signed Authenticode
Cert Issuer O=WR3 Self-signed
Cert NotBefore 2026-04-21 21:26:24Z Validity window
Cert NotAfter 2026-07-20 22:15:34Z Validity window
Filename Bootstrapper.exe Original submission name

Behavioral Fingerprint

This binary is a Go 1.18.5 static PE32+ x64 with six sections, no .rsrc, null PE timestamp, and a self-signed Authenticode certificate CN=atom.hutsell.com. It contains 20+ randomized main.* function names and standard Go syscall resolution stubs for advapi32, dnsapi, iphlpapi, netapi32, and psapi. No hardcoded C2 is present; the family uses math/rand seeded with system time to decode C2 strings at runtime. At execution, it will initiate an HTTPS TLS connection to a decoded endpoint and POST collected credential data.

Detection Signatures

ATT&CK ID Technique Evidence
T1059.003 Windows Command Shell Go runtime spawns child processes via CreateProcessW
T1071.001 Application Layer Protocol: Web Protocols net/http + crypto/tls standard library linkage (family pattern)
T1106 Native API syscall.getprocaddress resolves Windows APIs dynamically ^[strings.txt:2712]
T1027.002 Obfuscated Files or Information: Software Packing Randomized function names + runtime C2 decode
T1083 File and Directory Discovery File enumeration via FindFirstFileW, FindNextFileW (Go os package) ^[strings.txt:1092]
T1005 Data from Local System Browser / wallet credential targeting (family pattern)
T1041 Exfiltration Over C2 Channel HTTPS POST to decoded C2 (family pattern)

References

Provenance

  • file.txt — file(1) output, PE32+ x64 stripped
  • exiftool.json — ExifTool PE metadata (null timestamp, LinkerVersion 3.0)
  • rabin2-info.txt — radare2 binary info (entry 0x5ab40, 6 sections, signed=true)
  • strings.txt — Go 1.18.5 build ID, runtime strings, randomized main function names
  • pefile.txt — PE section layout, security directory offset 0x178000, certificate CN extraction
  • binwalk.txt — Overlay confirmation (Authenticode cert table only, 2,176 bytes)
  • capa.txt — capa failure (missing signature path)
  • floss.txt — floss failure (argument parse error)
  • dynamic-analysis.md — CAPE skipped (no Windows guest)
  • Manual certificate extraction via Python pefile + hex inspection