typeanalysisfamilyacrstealerconfidencehighcreated2026-08-14updated2026-08-14infostealergolangsigninganti-vmc2
SHA-256: c5b8d1b89af16d100021edb32f085de5704eee08bc51bd3edc82f0a997981c36

vidar (contested → acrstealer): c5b8d1b89af1 — Go 1.25.4 x64, quiverquant.com/WE1 cert, no .rsrc, PRNG sleep gate

Executive Summary: A PE32+ x64 Go binary tagged vidar by OpenCTI that resolves cleanly to the acrstealer cluster via certificate chain, Go build fingerprint, and PRNG sleep-gate behaviour. The 38th confirmed ACR sibling and the 12th sample on the quiverquant.com/WE1 self-signed chain. No .rsrc section (builder icon-toggle off). Static-only analysis (CAPE skipped — no Windows guest).

What It Is

  • SHA-256: c5b8d1b89af16d100021edb32f085de5704eee08bc51bd3edc82f0a997981c36
  • Filename: Setup.exe ^[triage.json]
  • File type: PE32+ executable (GUI) x86-64, 8 sections ^[file.txt]
  • Size: 2,556,032 bytes (2.55 MB) ^[metadata.json]
  • Compiler: Go 1.25.4, GOARCH=amd64, GOOS=windows, CGO_ENABLED=0, -trimpath=true ^[strings.txt:1715] ^[strings.txt:1723]
  • Module path: xTDyRMuufAbmowN (randomized) ^[strings.txt:6716]
  • Timestamp: null (Unix epoch 1970-01-01 00:00:00) ^[pefile.txt:34]
  • Entropy: .text 6.255, .rdata 7.107 — normal for unstripped Go ^[pefile.txt:91] ^[pefile.txt:111]
  • Signing: Self-signed Authenticode certificate, CN=quiverquant.com, issuer WE1, validity May 2026–Aug 2026 ^[strings.txt:9386] ^[binwalk.txt:6] ^[rabin2-info.txt:27]
  • Resources: No .rsrc section (icon-toggle off in builder) ^[pefile.txt:75-235]
  • YARA: Generic PE hit only ^[yara.txt]

How It Works

Entry point main.main (0x14009ad60) seeds math/rand with a value derived from current time, then enters a PRNG-based delay loop before calling worker functions. This is the standard ACR anti-emulation gate: a Sleep duration between ~800 ms and ~1600 ms (observed constants 0x320 + Intn(0x320) = 800 + rand(800) ms) ^[r2:sym.main.main]. The loop iterates until the PRNG draw exceeds a threshold, after which it dispatches to main.vfspvivg, main.onmpoigavn, main.fvivljlqjvrlsat, main.qchgnlggikbb, and main.agshte.

No static C2 strings are present. The binary links crypto/tls, net/http, and math/rand — the ACR family pattern is to decode C2 URLs at runtime via a PRNG-seeded multi-pass transform (see prng-seeded-c2-url-decoding). No hardcoded domains, IPs, or Telegram bot tokens were recovered.

Decompiled Behaviour

Radare2 decompile of sym.main.main (0x14009ad60) reveals:

  1. Time-seeded PRNG: math/rand seeded with a 64-bit value built from time.Now() equivalent plus a fixed delta (0xa1b203eb3d1a0000). ^[r2:sym.main.main]
  2. Anti-emulation sleep gate: Loop spins, drawing Intn(0x320) (800) and adding 0x320 (800) to produce a sleep between 800–1600 ms. The loop breaks when the draw exceeds a second threshold, at which point worker goroutines are spawned. ^[r2:sym.main.main]
  3. Worker dispatch: After the gate, the binary calls main.vfspvivg, main.onmpoigavn, main.fvivljlqjvrlsat, main.qchgnlggikbb, and main.agshte in sequence. Function names are randomized but counts and dispatch pattern match ACR siblings. ^[r2:sym.main.main]

C2 Infrastructure

  • Static: None recovered. No domains, IPs, URLs, or Telegram tokens in strings.
  • Inferred: TLS/HTTPS C2 over net/http + crypto/tls, decoded at runtime via PRNG. Family pattern per acrstealer and prng-seeded-c2-url-decoding.

Interesting Tidbits

  • 92 randomized main.* functions — mid-to-heavy count, consistent with ACR builder variants that toggle obfuscation depth. ^[strings.txt]
  • No .rsrc section — builder has an icon-toggle switch; this sample has it off. Contrast with siblings f258a5d7 and 55c7b564 which carry 5-icon suites.
  • Self-signed quiverquant.com/WE1 chain — 12th confirmed sample on this exact chain. The builder reuses the same RSA key pair across multiple compiles, rotating only module paths and function names.
  • OpenCTI mislabel vidar — same false-positive as siblings 94cf86f6, c64eb93f, and 43998b11d. Build fingerprint (Go 1.25.4 + quiverquant.com cert + randomized module path + PRNG gate) is an exact match for ACR, not Vidar.
  • Standard Go syscall surface: advapi32.dll, crypt32.dll, dnsapi.dll, iphlpapi.dll, netapi32.dll, ntdll.dll, secur32.dll, shell32.dll, userenv.dll, ws2_32.dll — the full Windows syscall complement typical of Go infostealers. ^[strings.txt:1646] ^[strings.txt:1648]

How To Mess With It (Homelab Replication)

Toolchain: Go 1.25.4, Windows amd64 target, CGO_ENABLED=0, -trimpath=true, -ldflags="-s -w" (optional — strip debug info to match entropy). Randomize main package function names via a small code generator.

Verification: compile a trivial Go binary with math/rand.Seed(time.Now().UnixNano()) and time.Sleep(time.Duration(rand.Intn(800)+800) * time.Millisecond). Run rabin2 -I reproducer.exe — lang should report go, signed should be false unless you add a self-signed cert.

Deployable Signatures

YARA rule

rule ACR_Stealer_Go1254_Quiverquant_WE1 : infostealer {
    meta:
        author = "PacketPursuit"
        description = "ACR Stealer Go 1.25.4 x64 with quiverquant.com self-signed cert"
        date = "2026-08-14"
        hash = "c5b8d1b89af16d100021edb32f085de5704eee08bc51bd3edc82f0a997981c36"
    strings:
        $go_ver = "go1.25.4" ascii
        $mod_path = "xTDyRMuufAbmowN" ascii
        $cert_cn = "quiverquant.com" ascii
        $cert_issuer = "WE1" ascii
        $build_trim = "build\t-trimpath=true" ascii
        $sleep_gate1 = { 48 8B 0D ?? ?? ?? ?? 48 8B 09 48 8B 41 18 FF D0 }
        $kernel32_va = "kernel32.dll.VirtualAlloc" ascii
    condition:
        uint16(0) == 0x5A4D and
        $go_ver and
        $cert_cn and
        $cert_issuer and
        ($mod_path or $build_trim) and
        filesize < 3MB
}

Behavioral fingerprint

This binary is a Go 1.25.4 PE32+ x64 with a null PE timestamp and no .rsrc section. On launch it seeds math/rand from system time, enters a tight loop drawing PRNG values to compute a sleep duration of 800–1600 ms, then dispatches to five randomized main.* worker functions. It imports the full Windows syscall surface (advapi32, crypt32, dnsapi, iphlpapi, netapi32, ntdll, secur32, shell32, userenv, ws2_32) via Go runtime dynamic resolution. No static C2 strings are present; C2 is decoded at runtime.

IOCs

Indicator Value Type
SHA-256 c5b8d1b89af16d100021edb32f085de5704eee08bc51bd3edc82f0a997981c36 hash
File name Setup.exe filename
Certificate CN quiverquant.com signing cert
Certificate issuer WE1 signing cert
Go module path xTDyRMuufAbmowN build artefact
Go version go1.25.4 build artefact
.rsrc absent section absence

Detection Signatures

  • MITRE ATT&CK: T1005 (Data from Local System), T1083 (File and Directory Discovery), T1497.001 (Virtualization/Sandbox Evasion: System Checks — PRNG sleep gate), T1071.001 (Application Layer Protocol: Web Protocols — inferred TLS/HTTPS C2), T1555 (Credentials from Password Stores — inferred from family behaviour), T1041 (Exfiltration Over C2 Channel — inferred).

References

Provenance

  • file.txt — file(1) output
  • pefile.txt — pefile.py parsed headers
  • strings.txt — GNU strings + Go type recovery
  • rabin2-info.txt — radare2 rabin2 -I summary
  • binwalk.txt — embedded artefact scan (certificate extraction)
  • r2:sym.main.main — radare2 decompile of entry point
  • dynamic-analysis.md — CAPE skipped (no Windows guest available)