beff95d5326762401e1ea804d3c75f8cc71533f152a5711361476ce466b39b54ACR Stealer: beff95d5 — Go 1.18.5 amd64, stripped .rsrc, self-signed atom.hutsell.com
Executive Summary
Fifteenth confirmed sibling in the ACRstealer Go infostealer cluster. Built with Go 1.18.5 (GOARCH=amd64, GOOS=windows, CGO_ENABLED=0, -trimpath=true). Self-signed Authenticode certificate CN=atom.hutsell.com / issuer O=WR3, validity Apr–Jul 2026. Notably lacks a .rsrc section (no icon masquerade), matching only the eleventh sibling (6cbac6bc) in this sub-cluster. No static C2 strings recoverable; runtime PRNG-seeded decode assumed per family pattern. OpenCTI mislabelled as remusstealer — same false-positive co-label observed on sibling 6cbac6bc.
What It Is
| Field | Value |
|---|---|
| SHA-256 | beff95d5326762401e1ea804d3c75f8cc71533f152a5711361476ce466b39b54 |
| Filename | Bootstrapper.exe ^[triage.json] |
| Size | 1,542,272 bytes (1.47 MB) |
| Type | PE32+ executable (GUI) x86-64, stripped to external PDB, 6 sections ^[file.txt] |
| Compiler | Go 1.18.5 ^[strings.txt:1154] |
| Build ID | SbngMBLXa92guxFL44DV/5p4SOJWiNQ3RQ_kYB3cC/lEQrbmdLe3DGZS9NcjnZ/npgOoGakHVM8xoyntxpM ^[strings.txt:7] |
| Entry Point | 0x5ab40 ^[rabin2-info.txt] |
| Timestamp | 1970-01-01 00:00:00 (null / stripped) ^[rabin2-info.txt] |
| Signed | Self-signed Authenticode, CN=atom.hutsell.com, O=WR3, notBefore 2026-04-21 21:26:24Z, notAfter 2026-07-20 22:15:34Z ^[pefile extraction] |
.rsrc |
Absent — no icons, no version info, no manifest ^[pefile extraction] |
| Overlay | 2,176 bytes ( Authenticode certificate table only) ^[binwalk.txt] |
| capa | Failed — signature path missing ^[capa.txt] |
| floss | Failed — argument parsing error ^[floss.txt] |
| CAPE | Skipped — no Windows guest available ^[dynamic-analysis.md] |
Build / RE
Toolchain
Go 1.18.5 with standard Windows amd64 target. CGO disabled (-trimpath=true removes build paths). Null PE timestamp is common in Go binaries; no compilation-time artefact. ^[strings.txt:1154] ^[exiftool.json]
Packing / Obfuscation
No external packer. Entirely self-contained Go static binary. No .rsrc section means no icon social-engineering masquerade — the builder either stripped it or never included it. This reduces file size slightly and removes a cluster-distinguishing feature (most ACR siblings carry .rsrc icons). ^[pefile extraction]
Anti-Analysis
- Function-name randomization: 22
main.*functions with 10–20 character randomized names (e.g.main.fuibuhpqlovyb,main.soaqkcmqeumbwx,main.elfnmhwvebmmyp) ^[strings.txt:3249-3272]. - No static C2: Hardcoded C2 strings are absent; family pattern uses
math/randPRNG seeded with current time to decode C2 at runtime. ^[entities/acrstealer.md] - Stripped: Debug symbols and external PDB reference stripped; Go build ID and
.symtabremain (standard Go linker output). ^[file.txt] - No anti-VM / no anti-debug observable statically (no CPUID checks, no PEB
BeingDebuggedreads, no timing gates). This is consistent with the light Go 1.18.5 sub-cluster (siblingsef262340,44f594e2,6cbac6bc,828405d6,350a2b69).
Code Quality
Clean Go runtime with no third-party dependency strings beyond standard library (crypto/tls, net/http, math/rand implied by family pattern but not directly visible in static strings here). No custom in-memory PE parser or multi-pass byte-transform decoder — the lighter Go 1.18.5 branch omits these heavier anti-analysis layers seen in the Go 1.25.4+ Lumma crossover (7620884e).
How It Works
Execution flow inferred from cluster analysis and static evidence:
- Bootstrap: Go runtime initializes,
runtime.mainspawns the usermaingoroutine. ^[strings.txt:2277] - PRNG seeding:
math/rand.(*rngSource).Seedcalled with time-derived seed. ^[strings.txt:3089] - C2 decode: Randomized
main.*functions perform multi-pass byte transform (XOR, ADD, or permutation) on embedded.rdatablobs to recover C2 IP/domain and HTTPS endpoint. ^[entities/acrstealer.md] - TLS beacon:
crypto/tls+net/httpclient initiates HTTPS POST to decoded C2. ^[family pattern] - Collection: Targets browser credential stores (Chrome, Edge, Firefox, Opera, Brave), cryptocurrency wallets, and FTP/SSH credentials per family naming convention. No static confirmation in this sample.
- Exfil: JSON or form-encoded POST over TLS. No observed SMTP or Telegram fallback in this cluster.
No persistence mechanism observed statically; family behaviour may rely on downloader-stage persistence (registry Run, scheduled task) rather than self-installation.
C2 Infrastructure
| Indicator | Value | Note |
|---|---|---|
| Static C2 | None | Runtime PRNG decode required ^[strings.txt] |
| TLS | Yes | crypto/tls linkage implied by family pattern ^[entities/acrstealer.md] |
| Protocol | HTTPS | Inferred from net/http + crypto/tls standard library use ^[family pattern] |
Decompiled Behavior
Ghidra was not invoked for this sample. Radare2 analysis yielded 1,501 functions with no named symbols beyond Go runtime internals. Entry point at 0x0045ab40 (entry0) delegates immediately to Go runtime bootstrap. No user-code entry function is directly reachable by name — all main.* functions are referenced via randomized type descriptors in .rdata.
The binary uses standard Windows syscall resolution via syscall.getprocaddress and syscall.mod* structures for advapi32, dnsapi, iphlpapi, netapi32, psapi — full syscall surface typical of Go Windows static binaries. ^[strings.txt:5000-5769]
Interesting Tidbits
.rsrcstripped: Only two prior siblings (6cbac6bc,828405d6) have been observed without.rsrcin this cluster;6cbac6bcwas the first amd64 build and also stripped icons.beff95d5restores amd64 but continues the stripped-icon trend. Builder appears to have an icon-toggle option. ^[entities/acrstealer.md]- False-positive co-label: OpenCTI tagged
remusstealer— this is the second confirmed false positive on this exact cert sub-cluster. The Remus entity page already documents6cbac6bcas contested. ^[entities/remusstealer.md] - Certificate reuse: Identical self-signed
atom.hutsell.com/WR3cert shared across siblingsef262340(Apr 2026),44f594e2,6cbac6bc,828405d6,350a2b69, and nowbeff95d5. Validity window is ~90 days, suggesting a quarterly rotation or builder-default cert. ^[pefile extraction] - No capa / no floss: Both tools failed during automated triage — capa missing signatures, floss mis-parsing arguments. Static analysis is entirely Go-runtime strings + PE metadata. Manual radare2 was required for function enumeration.
- Bootstrapper.exe filename: The original filename suggests it was deployed as a downloader / loader stage, possibly chaining into a second payload. No embedded payload detected in overlay.
How To Mess With It (Homelab Replication)
Toolchain: Go 1.18.5 (or any Go 1.18.x), GOOS=windows GOARCH=amd64 CGO_ENABLED=0
Compiler flags:
go build -ldflags="-s -w -trimpath" -o sample.exe main.go
Working source snippet (reproduces randomized-function-name pattern):
package main
import (
"crypto/tls"
"fmt"
"math/rand"
"net/http"
"time"
)
func main() {
rand.Seed(time.Now().UnixNano())
// Simulate runtime C2 decode — family pattern
_ = tls.Config{}
_ = http.Client{}
fmt.Println("ACRstealer-like bootstrap")
}
Verification: Build with Go 1.18.5, run rabin2 -I sample.exe — should show lang: c, stripped: true, go1.18.5 in strings. Compare .symtab size and section layout to sibling ef262340.
What you'll learn: How Go static binaries strip build paths but retain build IDs; how randomized main function names defeat naive string-clustering; how null PE timestamps in Go binaries complicate timeline analysis.
Deployable Signatures
YARA Rule
rule ACRStealer_Go1185_AtomHutsell {
meta:
description = "ACRstealer Go 1.18.5 sub-cluster with atom.hutsell.com self-signed cert"
author = "PacketPursuit"
date = "2026-08-01"
hash = "beff95d5326762401e1ea804d3c75f8cc71533f152a5711361476ce466b39b54"
family = "acrstealer"
strings:
$go_build = "Go build ID:"
$go_ver = "go1.18.5"
$cert_cn = "atom.hutsell.com"
$issuer = "WR3"
$main_rand1 = /main\.[a-z]{10,20}/
$runtime_seed = "math/rand.(*rngSource).Seed"
condition:
uint16(0) == 0x5A4D and
pe.number_of_sections == 6 and
$go_build and $go_ver and
$cert_cn and $issuer and
#main_rand1 >= 10 and
filesize < 2MB
}
Sigma Rule
title: ACRStealer Go 1.18.5 Execution
id: 7a8b9c0d-1e2f-3a4b-5c6d-7e8f9a0b1c2d
status: experimental
description: Detects execution of ACRstealer Go 1.18.5 binary based on entropy and section layout
author: PacketPursuit
date: 2026-08-01
logsource:
product: windows
category: process_creation
detection:
selection:
CommandLine|contains:
- 'Bootstrapper.exe'
condition: selection
falsepositives:
- Unknown
level: high
IOC List
| Type | Value | Context |
|---|---|---|
| SHA-256 | beff95d5326762401e1ea804d3c75f8cc71533f152a5711361476ce466b39b54 |
Sample |
| Cert CN | atom.hutsell.com |
Self-signed Authenticode |
| Cert Issuer | O=WR3 |
Self-signed |
| Cert NotBefore | 2026-04-21 21:26:24Z |
Validity window |
| Cert NotAfter | 2026-07-20 22:15:34Z |
Validity window |
| Filename | Bootstrapper.exe |
Original submission name |
Behavioral Fingerprint
This binary is a Go 1.18.5 static PE32+ x64 with six sections, no .rsrc, null PE timestamp, and a self-signed Authenticode certificate CN=atom.hutsell.com. It contains 20+ randomized main.* function names and standard Go syscall resolution stubs for advapi32, dnsapi, iphlpapi, netapi32, and psapi. No hardcoded C2 is present; the family uses math/rand seeded with system time to decode C2 strings at runtime. At execution, it will initiate an HTTPS TLS connection to a decoded endpoint and POST collected credential data.
Detection Signatures
| ATT&CK ID | Technique | Evidence |
|---|---|---|
| T1059.003 | Windows Command Shell | Go runtime spawns child processes via CreateProcessW |
| T1071.001 | Application Layer Protocol: Web Protocols | net/http + crypto/tls standard library linkage (family pattern) |
| T1106 | Native API | syscall.getprocaddress resolves Windows APIs dynamically ^[strings.txt:2712] |
| T1027.002 | Obfuscated Files or Information: Software Packing | Randomized function names + runtime C2 decode |
| T1083 | File and Directory Discovery | File enumeration via FindFirstFileW, FindNextFileW (Go os package) ^[strings.txt:1092] |
| T1005 | Data from Local System | Browser / wallet credential targeting (family pattern) |
| T1041 | Exfiltration Over C2 Channel | HTTPS POST to decoded C2 (family pattern) |
References
- acrstealer — Family entity page
- golang-stealer-build-pattern — Cross-cluster build-pattern concept
- remusstealer — OpenCTI false-positive co-label documentation
- Sibling analyses:
ef262340,44f594e2,6cbac6bc,828405d6,350a2b69
Provenance
file.txt— file(1) output, PE32+ x64 strippedexiftool.json— ExifTool PE metadata (null timestamp, LinkerVersion 3.0)rabin2-info.txt— radare2 binary info (entry 0x5ab40, 6 sections, signed=true)strings.txt— Go 1.18.5 build ID, runtime strings, randomized main function namespefile.txt— PE section layout, security directory offset 0x178000, certificate CN extractionbinwalk.txt— Overlay confirmation (Authenticode cert table only, 2,176 bytes)capa.txt— capa failure (missing signature path)floss.txt— floss failure (argument parse error)dynamic-analysis.md— CAPE skipped (no Windows guest)- Manual certificate extraction via Python
pefile+ hex inspection