c0a47856e9f60a5be5ac0cab0b92452198a3f10b6f98dbcbf1d153927915809cacrstealer: c0a47856 — Go 1.18.5 x64, 81 randomized main.* functions, atom.hutsell.com cert
Executive Summary
Forty-sixth confirmed sibling of the acrstealer Go infostealer cluster. PE32+ x64, Go 1.18.5 static build, self-signed Authenticode CN=atom.hutsell.com / issuer WR3. OpenCTI preliminary label cloud55filecc; contested — resolves to ACR by certificate chain and Go build fingerprint. Eighty-one randomized main.* functions (third-heaviest count in cluster), module path ecoDNZCUvXTdkYk, .rsrc icon suite intact. No static C2, no custom PE parser, no multi-pass decoder — light baseline build.
What It Is
- File:
OnbuD.exe^[triage.json] - Type: PE32+ executable (GUI) x86-64, 7 sections, stripped to external PDB ^[file.txt] ^[pefile.txt:1]
- Size: 7,256,192 bytes (6.9 MB) ^[exiftool.json]
- Timestamp: 0x0 (null, deliberate or builder artefact) ^[pefile.txt:38]
- Compiler: Go 1.18.5,
GOARCH=amd64,GOOS=windows,CGO_ENABLED=0,-trimpath=true^[strings.txt:1154] ^[strings.txt:4095] - Build ID:
skv9faC621v4LY6hNjcB/E4dClpBJBgx2Y8RDete-/qaB7NHLdQC9TEIYASOJw/LemOhDNaHs53_fFtx9cG^[strings.txt:8] - Module path:
ecoDNZCUvXTdkYk^[strings.txt:1158] - Signing: Self-signed Authenticode, CN=
atom.hutsell.com, issuer=WR3, serial=4C3A4A8198F1CBEF1010F5FB3157D6FE, validity Apr 21 – Jul 20 2026 ^[rabin2-info.txt:27] ^[terminal:openssl-extract] - Entropy:
.text6.204821,.rdata7.006390,.data4.851473 ^[pefile.txt:95] ^[pefile.txt:115] ^[pefile.txt:135] - Resources:
.rsrcsection intact (0x1C6C0 bytes) with 256×256 PNG icon and Zlib-compressed data ^[binwalk.txt:7] ^[binwalk.txt:8]
How It Works
This sample is a cluster sibling. For shared TTPs see acrstealer. Per-sample deltas below.
Build / RE
- Toolchain: Go 1.18.5 with standard
runtime+reflect+syscalllinkage. No external packer, no UPX, no VMProtect. Standard Go static binary layout:.textcode,.rdataread-only data,.dataRW data,.idataimport table (onlykernel32.dll),.relocbase relocs,.symtabsymbol table,.rsrcresources. ^[pefile.txt:79-219] - Anti-analysis: None observed statically. No PEB-walking, no anti-debug, no anti-VM. Go runtime includes
cpuidvendor check (GenuineIntel) atentry0^[r2:entry0], standard for Go 1.18.5 runtime bootstrap. - Obfuscation: Randomized module path (
ecoDNZCUvXTdkYk) and 81 randomizedmain.*function names (main.tkyctub,main.klmimjd,main.ebgxnxhkqpkhnva, etc.) — the third-heaviest count in the ACR cluster (afterb0bc17ddandf251271aat 90 each). ^[strings.txt] ^[terminal:python-count] - Imports: Minimal IAT — only
kernel32.dllwith 35 imports includingVirtualAlloc,CreateThread,LoadLibraryA,GetProcAddress,SetUnhandledExceptionFilter,AddVectoredExceptionHandler. All other APIs resolved at runtime by Go runtime viaLoadLibraryW+GetProcAddress. ^[pefile.txt:272-320] - Signing: Self-signed X.509 with 2048-bit RSA, SHA-256. Not chained to a trusted root. The
WR3issuer is a fabricated root CA. Same certificate chain as 16 prior ACR siblings (fromef262340throughcdd16fc0). ^[terminal:openssl-extract]
Deploy / ATT&CK
- T1071.001 — Application Layer Protocol: Web (inferred): Go
net/httpandcrypto/tlslinkage present in standard library strings; no hardcoded C2 URLs recovered statically. Family pattern is PRNG-seeded runtime C2 decoding. ^[strings.txt:1112] ^[acrstealer] - T1027 — Obfuscated Files or Information: Runtime-decoded C2 strings via PRNG seeding (family pattern, not statically visible in this sample). ^[techniques/prng-seeded-c2-url-decoding]
- T1083 — File and Directory Discovery: Go
ospackage file-walking primitives present (standard library). ^[strings.txt:310] - T1005 — Data from Local System: Browser credential store and cryptocurrency wallet targeting (family behaviour; no static path strings in this sample). ^[acrstealer]
- T1055 — Process Injection: Not observed statically. No
CreateRemoteThread,NtWriteVirtualMemory, orVirtualAllocExin IAT. Go runtime usesVirtualAllocfor goroutine stacks only. ^[pefile.txt:272-320] - Persistence: Not observed statically. No registry or scheduled-task strings. Family siblings typically rely on installer/dropper for persistence, not the stealer itself. ^[acrstealer]
- Exfiltration: HTTP POST to C2 (inferred from family pattern and Go
net/httplinkage). No static exfil URLs. ^[acrstealer]
Static-only inference — CAPE skipped (no Windows guest available) ^[dynamic-analysis.md]. All C2, collection, and exfil behaviour is inferred from family pattern and standard library linkage.
Decompiled Behavior
Entry point 0x45ab40 (entry0) is the Go runtime _rt0_amd64_windows bootstrap. Sequence: ^[r2:entry0]
- Align stack, save argc/argv.
cpuidvendor check (GenuineIntel/AuthenticAMD).- Initialize runtime TLS (
gs:[0x28]canary). - Call
runtime.rt0_go→runtime.main→main.main. - No suspicious entry-point behaviour; standard Go 1.18.5 startup.
Notable runtime functions in call tree (standard Go library, not malware-specific):
runtime.newproc— goroutine creationruntime.mallocgc— GC-aware heap allocationsyscall.LoadDLL/syscall.(*Proc).Call— Windows API resolution
No custom encryption, no PEB-walking, no reflective loader observed in decompiled entry.
C2 Infrastructure
No static C2 recovered. Family-wide TTP is PRNG-seeded runtime C2 URL decoding. See prng-seeded-c2-url-decoding and acrstealer for confirmed family C2s observed in other siblings (e.g., 5.252.155.72, laserlogdnsop.icu, hertzfigblob.icu).
Interesting Tidbits
- Filename:
OnbuD.exe— meaningless alphanumeric, no social-engineering masquerade in filename itself, but.rsrcicon suite implies masquerade at the GUI level. ^[triage.json] - Heavy symbol table: 81 randomized
main.*functions is the third-heaviest count observed in the entire ACR cluster. This suggests either a feature-rich build or aggressive function splitting by the Go compiler with many small exported functions. ^[terminal:python-count] - Certificate reuse: The
atom.hutsell.com/WR3cert chain has now been observed across 17 confirmed ACR siblings (including this one) spanning Apr–Jul 2026. The builder reuses the same self-signed cert across multiple samples. ^[acrstealer] - No custom PE parser: Unlike siblings
d5655568and90d54589(Lumma/OrderRe cross-over), this sample lacks the custom in-memory PE parser and multi-pass decoder. Light baseline build. ^[acrstealer] - Go 1.18.5 x64 sub-cluster: This is one of the amd64 builds in the older Go 1.18.5 toolchain sub-cluster (alongside
6cbac6bc,828405d6,beff95d5,76a51fb7,4c15644f,7945e84f,f251271a,8f454dc1,e535cab5,cdd16fc0). Most of these are x64; the newer Go 1.25.4 sub-cluster is also predominantly x64. The builder migrated from 386 to amd64 before upgrading Go versions.
How To Mess With It (Homelab Replication)
- Toolchain: Install Go 1.18.5 on Windows or cross-compile from Linux with
GOOS=windows GOARCH=amd64 CGO_ENABLED=0. - Randomized module path: Use
go mod init <random_string>(e.g.,ecoDNZCUvXTdkYk). - Randomized function names: Write multiple small functions in
package mainwith random names; Go will include them in the symbol table. - Trimpath: Build with
-trimpath=trueto strip build paths. - Self-sign: Generate a self-signed RSA 2048 cert with
openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 90, then sign withosslsigncodeor equivalent. - Resources: Embed PNG icons with
rsrcorgoversioninfofor social-engineering masquerade. - Verification: Run
rabin2 -I— expectlang: c,stripped: true,signed: true,bintype: pe,bits: 64.
Deployable Signatures
YARA Rule
rule ACR_Stealer_Go1185_AtomHutsell_x64 {
meta:
description = "ACR Stealer Go 1.18.5 x64 variant with atom.hutsell.com self-signed cert"
author = "PacketPursuit"
date = "2026-08-17"
sha256 = "c0a47856e9f60a5be5ac0cab0b92452198a3f10b6f98dbcbf1d153927915809c"
family = "acrstealer"
strings:
$go_ver = "go1.18.5" ascii
$build_id = "Go build ID: \"skv9faC621v4LY6hNjcB/E4dClpBJBgx2Y8RDete-/qaB7NHLdQC9TEIYASOJw/LemOhDNaHs53_fFtx9cG\"" ascii
$mod_path = "ecoDNZCUvXTdkYk" ascii
$cert_cn = "atom.hutsell.com" ascii
$cert_issuer = "WR3" ascii
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C)+4) == 0x00004550 and
uint16(uint32(0x3C)+24) == 0x8664 and
$go_ver and
($cert_cn or $cert_issuer or $mod_path or $build_id)
}
Behavioral Fingerprint
This binary is a Go 1.18.5 statically-linked PE32+ x64 with a minimal IAT containing only kernel32.dll imports (35 APIs). It has a null PE timestamp, a self-signed Authenticode certificate with CN atom.hutsell.com issued by WR3, and an intact .rsrc section with a 256×256 PNG icon. The symbol table contains 81 randomized main.* function names (e.g., main.tkyctub, main.ebgxnxhkqpkhnva). No static C2 URLs are present; runtime C2 decoding is inferred from family pattern. At execution, it launches multiple goroutines via runtime.newproc, resolves additional Windows APIs via LoadLibraryW/GetProcAddress at runtime, and communicates over TLS-encrypted HTTP.
IOC List
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | c0a47856e9f60a5be5ac0cab0b92452198a3f10b6f98dbcbf1d153927915809c |
Hash |
| SHA-1 | 695e4b5cc0c2fe192d21b61d570e7a4b6aa8b7b9 |
Hash (.text section) |
| MD5 | 194619edc499785854bcc240cc046649 |
Hash (.text section) |
| Filename | OnbuD.exe |
Filename |
| Certificate CN | atom.hutsell.com |
Certificate |
| Certificate Issuer | WR3 |
Certificate |
| Certificate Serial | 4C3A4A8198F1CBEF1010F5FB3157D6FE |
Certificate |
| Certificate Validity | Apr 21 21:26:24 2026 GMT – Jul 20 22:15:34 2026 GMT |
Certificate |
| Go Build ID | skv9faC621v4LY6hNjcB/E4dClpBJBgx2Y8RDete-/qaB7NHLdQC9TEIYASOJw/LemOhDNaHs53_fFtx9cG |
Build Artefact |
| Module Path | ecoDNZCUvXTdkYk |
Build Artefact |
Detection Signatures
| ATT&CK ID | Technique | Evidence |
|---|---|---|
| T1071.001 | Application Layer Protocol: Web | Go net/http + crypto/tls linkage, family C2 pattern |
| T1027 | Obfuscated Files or Information | PRNG-seeded runtime C2 decode (family pattern) |
| T1083 | File and Directory Discovery | Go os package file walking |
| T1005 | Data from Local System | Browser credential / wallet targeting (family behaviour) |
References
- Artifact ID:
c7bb2888-d894-4a6d-b573-1c4fec6679dd^[metadata.json] - OpenCTI labels:
cloud55file-cc,exe,malware-bazaar,neuralpulsecore5-sbs,signed^[triage.json] - Family resolution: acrstealer (contested cloud55filecc)
- Build pattern: golang-stealer-build-pattern
- C2 technique: prng-seeded-c2-url-decoding
Provenance
file.txt—filev5.44exiftool.json— ExifTool v12.76pefile.txt—pefilePython librarystrings.txt—strings(GNU binutils)rabin2-info.txt— radare2 v5.x (rabin2 -I)binwalk.txt— binwalk v2.3.3triage.json— PacketPursuit triage pipeline- Certificate extracted via custom Python + OpenSSL from
IMAGE_DIRECTORY_ENTRY_SECURITY - Decompilation via radare2 MCP (
pdg/pdc)