typeanalysisfamilyacrstealerconfidencehighcreated2026-08-17updated2026-08-17golanginfostealersigningpemalware-familycontested-label
SHA-256: c0a47856e9f60a5be5ac0cab0b92452198a3f10b6f98dbcbf1d153927915809c

acrstealer: c0a47856 — Go 1.18.5 x64, 81 randomized main.* functions, atom.hutsell.com cert

Executive Summary

Forty-sixth confirmed sibling of the acrstealer Go infostealer cluster. PE32+ x64, Go 1.18.5 static build, self-signed Authenticode CN=atom.hutsell.com / issuer WR3. OpenCTI preliminary label cloud55filecc; contested — resolves to ACR by certificate chain and Go build fingerprint. Eighty-one randomized main.* functions (third-heaviest count in cluster), module path ecoDNZCUvXTdkYk, .rsrc icon suite intact. No static C2, no custom PE parser, no multi-pass decoder — light baseline build.

What It Is

  • File: OnbuD.exe ^[triage.json]
  • Type: PE32+ executable (GUI) x86-64, 7 sections, stripped to external PDB ^[file.txt] ^[pefile.txt:1]
  • Size: 7,256,192 bytes (6.9 MB) ^[exiftool.json]
  • Timestamp: 0x0 (null, deliberate or builder artefact) ^[pefile.txt:38]
  • Compiler: Go 1.18.5, GOARCH=amd64, GOOS=windows, CGO_ENABLED=0, -trimpath=true ^[strings.txt:1154] ^[strings.txt:4095]
  • Build ID: skv9faC621v4LY6hNjcB/E4dClpBJBgx2Y8RDete-/qaB7NHLdQC9TEIYASOJw/LemOhDNaHs53_fFtx9cG ^[strings.txt:8]
  • Module path: ecoDNZCUvXTdkYk ^[strings.txt:1158]
  • Signing: Self-signed Authenticode, CN=atom.hutsell.com, issuer=WR3, serial=4C3A4A8198F1CBEF1010F5FB3157D6FE, validity Apr 21 – Jul 20 2026 ^[rabin2-info.txt:27] ^[terminal:openssl-extract]
  • Entropy: .text 6.204821, .rdata 7.006390, .data 4.851473 ^[pefile.txt:95] ^[pefile.txt:115] ^[pefile.txt:135]
  • Resources: .rsrc section intact (0x1C6C0 bytes) with 256×256 PNG icon and Zlib-compressed data ^[binwalk.txt:7] ^[binwalk.txt:8]

How It Works

This sample is a cluster sibling. For shared TTPs see acrstealer. Per-sample deltas below.

Build / RE

  • Toolchain: Go 1.18.5 with standard runtime + reflect + syscall linkage. No external packer, no UPX, no VMProtect. Standard Go static binary layout: .text code, .rdata read-only data, .data RW data, .idata import table (only kernel32.dll), .reloc base relocs, .symtab symbol table, .rsrc resources. ^[pefile.txt:79-219]
  • Anti-analysis: None observed statically. No PEB-walking, no anti-debug, no anti-VM. Go runtime includes cpuid vendor check (GenuineIntel) at entry0 ^[r2:entry0], standard for Go 1.18.5 runtime bootstrap.
  • Obfuscation: Randomized module path (ecoDNZCUvXTdkYk) and 81 randomized main.* function names (main.tkyctub, main.klmimjd, main.ebgxnxhkqpkhnva, etc.) — the third-heaviest count in the ACR cluster (after b0bc17dd and f251271a at 90 each). ^[strings.txt] ^[terminal:python-count]
  • Imports: Minimal IAT — only kernel32.dll with 35 imports including VirtualAlloc, CreateThread, LoadLibraryA, GetProcAddress, SetUnhandledExceptionFilter, AddVectoredExceptionHandler. All other APIs resolved at runtime by Go runtime via LoadLibraryW + GetProcAddress. ^[pefile.txt:272-320]
  • Signing: Self-signed X.509 with 2048-bit RSA, SHA-256. Not chained to a trusted root. The WR3 issuer is a fabricated root CA. Same certificate chain as 16 prior ACR siblings (from ef262340 through cdd16fc0). ^[terminal:openssl-extract]

Deploy / ATT&CK

  • T1071.001 — Application Layer Protocol: Web (inferred): Go net/http and crypto/tls linkage present in standard library strings; no hardcoded C2 URLs recovered statically. Family pattern is PRNG-seeded runtime C2 decoding. ^[strings.txt:1112] ^[acrstealer]
  • T1027 — Obfuscated Files or Information: Runtime-decoded C2 strings via PRNG seeding (family pattern, not statically visible in this sample). ^[techniques/prng-seeded-c2-url-decoding]
  • T1083 — File and Directory Discovery: Go os package file-walking primitives present (standard library). ^[strings.txt:310]
  • T1005 — Data from Local System: Browser credential store and cryptocurrency wallet targeting (family behaviour; no static path strings in this sample). ^[acrstealer]
  • T1055 — Process Injection: Not observed statically. No CreateRemoteThread, NtWriteVirtualMemory, or VirtualAllocEx in IAT. Go runtime uses VirtualAlloc for goroutine stacks only. ^[pefile.txt:272-320]
  • Persistence: Not observed statically. No registry or scheduled-task strings. Family siblings typically rely on installer/dropper for persistence, not the stealer itself. ^[acrstealer]
  • Exfiltration: HTTP POST to C2 (inferred from family pattern and Go net/http linkage). No static exfil URLs. ^[acrstealer]

Static-only inference — CAPE skipped (no Windows guest available) ^[dynamic-analysis.md]. All C2, collection, and exfil behaviour is inferred from family pattern and standard library linkage.

Decompiled Behavior

Entry point 0x45ab40 (entry0) is the Go runtime _rt0_amd64_windows bootstrap. Sequence: ^[r2:entry0]

  1. Align stack, save argc/argv.
  2. cpuid vendor check (GenuineIntel / AuthenticAMD).
  3. Initialize runtime TLS (gs:[0x28] canary).
  4. Call runtime.rt0_go → runtime.main → main.main.
  5. No suspicious entry-point behaviour; standard Go 1.18.5 startup.

Notable runtime functions in call tree (standard Go library, not malware-specific):

  • runtime.newproc — goroutine creation
  • runtime.mallocgc — GC-aware heap allocation
  • syscall.LoadDLL / syscall.(*Proc).Call — Windows API resolution

No custom encryption, no PEB-walking, no reflective loader observed in decompiled entry.

C2 Infrastructure

No static C2 recovered. Family-wide TTP is PRNG-seeded runtime C2 URL decoding. See prng-seeded-c2-url-decoding and acrstealer for confirmed family C2s observed in other siblings (e.g., 5.252.155.72, laserlogdnsop.icu, hertzfigblob.icu).

Interesting Tidbits

  • Filename: OnbuD.exe — meaningless alphanumeric, no social-engineering masquerade in filename itself, but .rsrc icon suite implies masquerade at the GUI level. ^[triage.json]
  • Heavy symbol table: 81 randomized main.* functions is the third-heaviest count observed in the entire ACR cluster. This suggests either a feature-rich build or aggressive function splitting by the Go compiler with many small exported functions. ^[terminal:python-count]
  • Certificate reuse: The atom.hutsell.com / WR3 cert chain has now been observed across 17 confirmed ACR siblings (including this one) spanning Apr–Jul 2026. The builder reuses the same self-signed cert across multiple samples. ^[acrstealer]
  • No custom PE parser: Unlike siblings d5655568 and 90d54589 (Lumma/OrderRe cross-over), this sample lacks the custom in-memory PE parser and multi-pass decoder. Light baseline build. ^[acrstealer]
  • Go 1.18.5 x64 sub-cluster: This is one of the amd64 builds in the older Go 1.18.5 toolchain sub-cluster (alongside 6cbac6bc, 828405d6, beff95d5, 76a51fb7, 4c15644f, 7945e84f, f251271a, 8f454dc1, e535cab5, cdd16fc0). Most of these are x64; the newer Go 1.25.4 sub-cluster is also predominantly x64. The builder migrated from 386 to amd64 before upgrading Go versions.

How To Mess With It (Homelab Replication)

  1. Toolchain: Install Go 1.18.5 on Windows or cross-compile from Linux with GOOS=windows GOARCH=amd64 CGO_ENABLED=0.
  2. Randomized module path: Use go mod init <random_string> (e.g., ecoDNZCUvXTdkYk).
  3. Randomized function names: Write multiple small functions in package main with random names; Go will include them in the symbol table.
  4. Trimpath: Build with -trimpath=true to strip build paths.
  5. Self-sign: Generate a self-signed RSA 2048 cert with openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 90, then sign with osslsigncode or equivalent.
  6. Resources: Embed PNG icons with rsrc or goversioninfo for social-engineering masquerade.
  7. Verification: Run rabin2 -I — expect lang: c, stripped: true, signed: true, bintype: pe, bits: 64.

Deployable Signatures

YARA Rule

rule ACR_Stealer_Go1185_AtomHutsell_x64 {
    meta:
        description = "ACR Stealer Go 1.18.5 x64 variant with atom.hutsell.com self-signed cert"
        author = "PacketPursuit"
        date = "2026-08-17"
        sha256 = "c0a47856e9f60a5be5ac0cab0b92452198a3f10b6f98dbcbf1d153927915809c"
        family = "acrstealer"
    strings:
        $go_ver = "go1.18.5" ascii
        $build_id = "Go build ID: \"skv9faC621v4LY6hNjcB/E4dClpBJBgx2Y8RDete-/qaB7NHLdQC9TEIYASOJw/LemOhDNaHs53_fFtx9cG\"" ascii
        $mod_path = "ecoDNZCUvXTdkYk" ascii
        $cert_cn = "atom.hutsell.com" ascii
        $cert_issuer = "WR3" ascii
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)+4) == 0x00004550 and
        uint16(uint32(0x3C)+24) == 0x8664 and
        $go_ver and
        ($cert_cn or $cert_issuer or $mod_path or $build_id)
}

Behavioral Fingerprint

This binary is a Go 1.18.5 statically-linked PE32+ x64 with a minimal IAT containing only kernel32.dll imports (35 APIs). It has a null PE timestamp, a self-signed Authenticode certificate with CN atom.hutsell.com issued by WR3, and an intact .rsrc section with a 256×256 PNG icon. The symbol table contains 81 randomized main.* function names (e.g., main.tkyctub, main.ebgxnxhkqpkhnva). No static C2 URLs are present; runtime C2 decoding is inferred from family pattern. At execution, it launches multiple goroutines via runtime.newproc, resolves additional Windows APIs via LoadLibraryW/GetProcAddress at runtime, and communicates over TLS-encrypted HTTP.

IOC List

Indicator Value Type
SHA-256 c0a47856e9f60a5be5ac0cab0b92452198a3f10b6f98dbcbf1d153927915809c Hash
SHA-1 695e4b5cc0c2fe192d21b61d570e7a4b6aa8b7b9 Hash (.text section)
MD5 194619edc499785854bcc240cc046649 Hash (.text section)
Filename OnbuD.exe Filename
Certificate CN atom.hutsell.com Certificate
Certificate Issuer WR3 Certificate
Certificate Serial 4C3A4A8198F1CBEF1010F5FB3157D6FE Certificate
Certificate Validity Apr 21 21:26:24 2026 GMT – Jul 20 22:15:34 2026 GMT Certificate
Go Build ID skv9faC621v4LY6hNjcB/E4dClpBJBgx2Y8RDete-/qaB7NHLdQC9TEIYASOJw/LemOhDNaHs53_fFtx9cG Build Artefact
Module Path ecoDNZCUvXTdkYk Build Artefact

Detection Signatures

ATT&CK ID Technique Evidence
T1071.001 Application Layer Protocol: Web Go net/http + crypto/tls linkage, family C2 pattern
T1027 Obfuscated Files or Information PRNG-seeded runtime C2 decode (family pattern)
T1083 File and Directory Discovery Go os package file walking
T1005 Data from Local System Browser credential / wallet targeting (family behaviour)

References

Provenance

  • file.txt — file v5.44
  • exiftool.json — ExifTool v12.76
  • pefile.txt — pefile Python library
  • strings.txt — strings (GNU binutils)
  • rabin2-info.txt — radare2 v5.x (rabin2 -I)
  • binwalk.txt — binwalk v2.3.3
  • triage.json — PacketPursuit triage pipeline
  • Certificate extracted via custom Python + OpenSSL from IMAGE_DIRECTORY_ENTRY_SECURITY
  • Decompilation via radare2 MCP (pdg / pdc)