c5b8d1b89af16d100021edb32f085de5704eee08bc51bd3edc82f0a997981c36vidar (contested → acrstealer): c5b8d1b89af1 — Go 1.25.4 x64, quiverquant.com/WE1 cert, no .rsrc, PRNG sleep gate
Executive Summary: A PE32+ x64 Go binary tagged vidar by OpenCTI that resolves cleanly to the acrstealer cluster via certificate chain, Go build fingerprint, and PRNG sleep-gate behaviour. The 38th confirmed ACR sibling and the 12th sample on the quiverquant.com/WE1 self-signed chain. No .rsrc section (builder icon-toggle off). Static-only analysis (CAPE skipped — no Windows guest).
What It Is
- SHA-256:
c5b8d1b89af16d100021edb32f085de5704eee08bc51bd3edc82f0a997981c36 - Filename:
Setup.exe^[triage.json] - File type: PE32+ executable (GUI) x86-64, 8 sections ^[file.txt]
- Size: 2,556,032 bytes (2.55 MB) ^[metadata.json]
- Compiler: Go 1.25.4,
GOARCH=amd64,GOOS=windows,CGO_ENABLED=0,-trimpath=true^[strings.txt:1715] ^[strings.txt:1723] - Module path:
xTDyRMuufAbmowN(randomized) ^[strings.txt:6716] - Timestamp: null (Unix epoch
1970-01-01 00:00:00) ^[pefile.txt:34] - Entropy:
.text6.255,.rdata7.107 — normal for unstripped Go ^[pefile.txt:91] ^[pefile.txt:111] - Signing: Self-signed Authenticode certificate, CN=
quiverquant.com, issuerWE1, validity May 2026–Aug 2026 ^[strings.txt:9386] ^[binwalk.txt:6] ^[rabin2-info.txt:27] - Resources: No
.rsrcsection (icon-toggle off in builder) ^[pefile.txt:75-235] - YARA: Generic PE hit only ^[yara.txt]
How It Works
Entry point main.main (0x14009ad60) seeds math/rand with a value derived from current time, then enters a PRNG-based delay loop before calling worker functions. This is the standard ACR anti-emulation gate: a Sleep duration between ~800 ms and ~1600 ms (observed constants 0x320 + Intn(0x320) = 800 + rand(800) ms) ^[r2:sym.main.main]. The loop iterates until the PRNG draw exceeds a threshold, after which it dispatches to main.vfspvivg, main.onmpoigavn, main.fvivljlqjvrlsat, main.qchgnlggikbb, and main.agshte.
No static C2 strings are present. The binary links crypto/tls, net/http, and math/rand — the ACR family pattern is to decode C2 URLs at runtime via a PRNG-seeded multi-pass transform (see prng-seeded-c2-url-decoding). No hardcoded domains, IPs, or Telegram bot tokens were recovered.
Decompiled Behaviour
Radare2 decompile of sym.main.main (0x14009ad60) reveals:
- Time-seeded PRNG:
math/randseeded with a 64-bit value built fromtime.Now()equivalent plus a fixed delta (0xa1b203eb3d1a0000). ^[r2:sym.main.main] - Anti-emulation sleep gate: Loop spins, drawing
Intn(0x320)(800) and adding 0x320 (800) to produce a sleep between 800–1600 ms. The loop breaks when the draw exceeds a second threshold, at which point worker goroutines are spawned. ^[r2:sym.main.main] - Worker dispatch: After the gate, the binary calls
main.vfspvivg,main.onmpoigavn,main.fvivljlqjvrlsat,main.qchgnlggikbb, andmain.agshtein sequence. Function names are randomized but counts and dispatch pattern match ACR siblings. ^[r2:sym.main.main]
C2 Infrastructure
- Static: None recovered. No domains, IPs, URLs, or Telegram tokens in strings.
- Inferred: TLS/HTTPS C2 over
net/http+crypto/tls, decoded at runtime via PRNG. Family pattern per acrstealer and prng-seeded-c2-url-decoding.
Interesting Tidbits
- 92 randomized
main.*functions — mid-to-heavy count, consistent with ACR builder variants that toggle obfuscation depth. ^[strings.txt] - No
.rsrcsection — builder has an icon-toggle switch; this sample has it off. Contrast with siblingsf258a5d7and55c7b564which carry 5-icon suites. - Self-signed
quiverquant.com/WE1chain — 12th confirmed sample on this exact chain. The builder reuses the same RSA key pair across multiple compiles, rotating only module paths and function names. - OpenCTI mislabel
vidar— same false-positive as siblings94cf86f6,c64eb93f, and43998b11d. Build fingerprint (Go 1.25.4 + quiverquant.com cert + randomized module path + PRNG gate) is an exact match for ACR, not Vidar. - Standard Go syscall surface:
advapi32.dll,crypt32.dll,dnsapi.dll,iphlpapi.dll,netapi32.dll,ntdll.dll,secur32.dll,shell32.dll,userenv.dll,ws2_32.dll— the full Windows syscall complement typical of Go infostealers. ^[strings.txt:1646] ^[strings.txt:1648]
How To Mess With It (Homelab Replication)
Toolchain: Go 1.25.4, Windows amd64 target, CGO_ENABLED=0, -trimpath=true, -ldflags="-s -w" (optional — strip debug info to match entropy). Randomize main package function names via a small code generator.
Verification: compile a trivial Go binary with math/rand.Seed(time.Now().UnixNano()) and time.Sleep(time.Duration(rand.Intn(800)+800) * time.Millisecond). Run rabin2 -I reproducer.exe — lang should report go, signed should be false unless you add a self-signed cert.
Deployable Signatures
YARA rule
rule ACR_Stealer_Go1254_Quiverquant_WE1 : infostealer {
meta:
author = "PacketPursuit"
description = "ACR Stealer Go 1.25.4 x64 with quiverquant.com self-signed cert"
date = "2026-08-14"
hash = "c5b8d1b89af16d100021edb32f085de5704eee08bc51bd3edc82f0a997981c36"
strings:
$go_ver = "go1.25.4" ascii
$mod_path = "xTDyRMuufAbmowN" ascii
$cert_cn = "quiverquant.com" ascii
$cert_issuer = "WE1" ascii
$build_trim = "build\t-trimpath=true" ascii
$sleep_gate1 = { 48 8B 0D ?? ?? ?? ?? 48 8B 09 48 8B 41 18 FF D0 }
$kernel32_va = "kernel32.dll.VirtualAlloc" ascii
condition:
uint16(0) == 0x5A4D and
$go_ver and
$cert_cn and
$cert_issuer and
($mod_path or $build_trim) and
filesize < 3MB
}
Behavioral fingerprint
This binary is a Go 1.25.4 PE32+ x64 with a null PE timestamp and no .rsrc section. On launch it seeds math/rand from system time, enters a tight loop drawing PRNG values to compute a sleep duration of 800–1600 ms, then dispatches to five randomized main.* worker functions. It imports the full Windows syscall surface (advapi32, crypt32, dnsapi, iphlpapi, netapi32, ntdll, secur32, shell32, userenv, ws2_32) via Go runtime dynamic resolution. No static C2 strings are present; C2 is decoded at runtime.
IOCs
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | c5b8d1b89af16d100021edb32f085de5704eee08bc51bd3edc82f0a997981c36 |
hash |
| File name | Setup.exe |
filename |
| Certificate CN | quiverquant.com |
signing cert |
| Certificate issuer | WE1 |
signing cert |
| Go module path | xTDyRMuufAbmowN |
build artefact |
| Go version | go1.25.4 |
build artefact |
.rsrc |
absent | section absence |
Detection Signatures
- MITRE ATT&CK: T1005 (Data from Local System), T1083 (File and Directory Discovery), T1497.001 (Virtualization/Sandbox Evasion: System Checks — PRNG sleep gate), T1071.001 (Application Layer Protocol: Web Protocols — inferred TLS/HTTPS C2), T1555 (Credentials from Password Stores — inferred from family behaviour), T1041 (Exfiltration Over C2 Channel — inferred).
References
- acrstealer — Primary family entity page (38th confirmed sibling)
- vidar — Contested OpenCTI label; this sample resolves to ACR
- prng-seeded-c2-url-decoding — Family-wide runtime C2 decoding technique
- golang-stealer-build-pattern — Common Go infostealer build artefacts
Provenance
file.txt— file(1) outputpefile.txt— pefile.py parsed headersstrings.txt— GNU strings + Go type recoveryrabin2-info.txt— radare2rabin2 -Isummarybinwalk.txt— embedded artefact scan (certificate extraction)r2:sym.main.main— radare2 decompile of entry pointdynamic-analysis.md— CAPE skipped (no Windows guest available)