c64eb93f00c92ad6367df8de17e7360ba57a34a4e2a85fe7322952513daa50d4acrstealer: c64eb93f — Go 1.25.4 x64 with quiverquant.com self-signed cert, 64 randomized main.* functions
Executive Summary: Go 1.25.4 PE32+ x64 infostealer with self-signed Authenticode (quiverquant.com/WE1). Build fingerprint — Go 1.25.4, quiverquant.com cert, no .rsrc, 64 randomized main.* symbols — is an exact match for the acrstealer cluster. OpenCTI label vidar is a known false positive on this cert chain; this is the thirty-sixth confirmed sibling and the tenth confirmed sample on the quiverquant.com/WE1 certificate chain.
What It Is
| Field | Value |
|---|---|
| SHA-256 | c64eb93f00c92ad6367df8de17e7360ba57a34a4e2a85fe7322952513daa50d4 |
| Filename | SoftWare.exe |
| Type | PE32+ executable (GUI) x86-64, 8 sections^[file.txt] |
| Size | 2,558,592 bytes (2.44 MB) |
| Compiler | Go 1.25.4, CGO_ENABLED=0, -trimpath=true, -buildmode=exe^[strings.txt:1717-1725] |
| Module path | fPkQKdkjTpkkdga^[strings.txt:1721] |
| Build ID | kDEXpXTj-S0VRMBRP5Ul/df6UcLEmckfOEf1z7YOJ/FZBk6taCIZMeY5nS__66/uoqw0MwHucmSAy9N13Zh^[strings.txt:9] |
| Subsystem | Windows GUI (no console)^[exiftool.json] |
| Timestamp | Zero (1970-01-01 00:00:00) — Go default^[pefile.txt:34] |
| Signing | Self-signed Authenticode CN=quiverquant.com, issuer WE1, RSA-4096, SHA-256, valid May 9 – Aug 7 2026^[binwalk.txt:4-7] |
| Family | acrstealer (high confidence; OpenCTI vidar is contested) |
Build / RE
Toolchain: Go 1.25.4 (GOOS=windows, GOARCH=amd64), CGO_ENABLED=0, -trimpath=true, -buildmode=exe^[strings.txt:1717-1725]. Standard Go linker version 3.0^[exiftool.json]. Windows GUI subsystem with no console window.
Signing: Authenticode certificate embedded in overlay at offset 0x270208, size 0x880^[pefile.txt:251-253]. OpenSSL parse reveals a self-signed X.509v3 certificate with Subject CN=quiverquant.com, Issuer CN=WE1, 4096-bit RSA public key, SHA-256 signature algorithm, validity window 2026-05-09 to 2026-08-07^[binwalk.txt:4-7]. This is the tenth confirmed sample in the corpus on the quiverquant.com/WE1 cert chain, all belonging to the acrstealer cluster.
Obfuscation: Sixty-four randomized main.* symbols in the Go symbol table (37 direct functions plus type and closure references): main.enlqjd, main.geowxxuesvvhjh, main.qeenqabaflul, main.jwxmkihsrqz, main.dunvhcb, main.nfslty, main.komccvhqqw, main.ngpiwcfdguq, main.onwddld, main.rdeizssyoub, main.rrrdhfjce, main.ybdmirqqfhq, main.azwfxf, main.djsniih, main.kysfjrch, main.ddwqidtqs, main.xpppcfszypyzyi, main.llkgnxccqklqc, main.wcqwgwqflvaqvp, main.kvnvldktcpsvso, main.nkrsupoo, main.lnstdlwqpdkhxjd, main.lnbpcdmdcq, main.czffrg, main.bsjgscsyrimihw, main.spshhevh, main.tauzjoozmrvvjwa, main.Akoivunidczy, main.Tssmmtygzg, main.Yevdalbc, main.Pitheyfh, main.Lajypwexbblvz, main.Qdkluefiimqx, main.Bohjcfdesuh, main.Rbeqwyxjkfztwei, main.Bawriwvjn, main.gfwagqca^[strings.txt:5748-5783]. No external packer; .text entropy 6.25, .rdata 7.08^[pefile.txt:91,111].
Sections: .text, .rdata, .data, .pdata, .xdata, .idata, .reloc, .symtab. Notable: .symtab is present (Go symbol table, not stripped), and there is no .rsrc section (builder stripped icon resources)^[pefile.txt:75-236].
Imports: Only kernel32.dll imported directly via IAT — 46 APIs including VirtualAlloc, CreateThread, LoadLibraryW, GetProcAddress, SetThreadContext^[pefile.txt:288-344]. The Go runtime resolves all other APIs dynamically.
Exports: 1900 symbols (heavy Go runtime symbol table)^[rabin2-info.txt:30].
Anti-analysis: No VM detection strings, no debugger checks, no sandbox gates observed statically. Go runtime string bloat dominates strings.txt and would poison naive signature matching.
Deploy / ATT&CK
No dynamic analysis was performed (CAPE skipped — no Windows guest available)^[dynamic-analysis.md]. TTPs below are inferred from static artifacts and family behavior.
| Technique | ID | Evidence |
|---|---|---|
| Data from Local System | T1005 | Inferred from infostealer family pattern |
| Input Capture: Clipboard | T1115 | Inferred from family behavior (crypto clipper) |
| Input Capture: Keylogging | T1056.001 | Inferred from family behavior |
| Screen Capture | T1113 | Inferred from family behavior |
| Credentials from Web Browsers | T1555.003 | Inferred from family behavior |
| Exfiltration Over C2 | T1041 | net/http + crypto/tls linkage implies HTTPS C2 |
| Application Layer Protocol: Web | T1071.001 | net/http, crypto/tls standard library linkage^[strings.txt] |
| Native API | T1106 | VirtualAlloc, CreateThread, LoadLibraryW imported^[pefile.txt] |
C2: No hardcoded C2 URL, IP, or domain found in static strings. The ACR/Lumma cluster uses PRNG-seeded runtime C2 decoding — this sample follows the same pattern. net/http, crypto/tls, crypto/x509 present in strings^[strings.txt:1717,1718,1719].
Persistence: No static evidence. No registry key strings, no scheduled-task references.
Interesting Tidbits
- Contested attribution: The
quiverquant.com/WE1certificate chain is exclusive to the ACR Stealer cluster in this corpus. Nine prior samples (c69b14a0,f668de57,1cf857a9,725dc07c,f258a5d7,55c7b564,bd783215,94cf86f6,0bc8490a) share this exact chain. None of the prior confirmedvidarsamples (3799d1f74d95,d4b6905ef14c) use this certificate. OpenCTI'svidarlabel on this sample is a known false positive. - No
.rsrc: The builder optionally strips the.rsrcicon section. Prior ACR siblingsc69b14a0,cdd16fc0, and94cf86f6also lack.rsrc, confirming builder toggle behavior. - 64 randomized main. symbols:* The highest symbol count observed on the
quiverquant.com/WE1chain (prior range: 11–92). This does not correlate with binary size or section entropy, suggesting the builder randomizes symbol count independently. - Go 1.25.4 timestamp zero: Go compiler defaults to epoch timestamp, which anti-forensics tools sometimes mistake for "packed."
- GUI subsystem: Masquerades as a legitimate Windows application (
SoftWare.exe).
How To Mess With It (Homelab Replication)
Toolchain: Go 1.25.4 for Windows amd64.
Compiler/linker flags:
GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build -trimpath -buildmode=exe -o repro.exe .
Working source snippet:
package main
import (
"crypto/tls"
"fmt"
"net/http"
)
func main() {
tr := &http.Transport{TLSClientConfig: &tls.Config{InsecureSkipVerify: true}}
client := &http.Client{Transport: tr}
_, _ = client.Get("https://example.com")
fmt.Println("done")
}
Verification step: Run capa repro.exe (once signatures are installed) and compare to expected family fingerprint — should hit use network socket, initialize Winsock, and send data capabilities. The actual sample failed capa due to missing signatures, but the family baseline should match.
What you'll learn: How Go's -trimpath and CGO_ENABLED=0 produce a static PE with no build-path leakage and a minimal IAT surface, and how self-signed Authenticode overlays behave versus PE directory entries.
Deployable Signatures
YARA rule:
rule Go_ACR_Cluster_Quiverquant_WE1_v2 {
meta:
description = "Go infostealer with quiverquant.com self-signed cert"
author = "PacketPursuit"
date = "2026-08-13"
strings:
$go_build = "go1.25.4" ascii
$cert_cn = "quiverquant.com" ascii wide
$cert_issuer = "WE1" ascii wide
$trimpath = "-trimpath=true" ascii
condition:
uint16(0) == 0x5A4D and
$go_build and
($cert_cn or $cert_issuer) and
$trimpath
}
Behavioral fingerprint: PE32+ x64 Go 1.25.4 binary with zero PE timestamp, self-signed Authenticode CN=quiverquant.com/issuer=WE1, no .rsrc section or stripped .rsrc, 35–90 randomized main.* function names in Go symtab, and no static C2 strings. Network-capable via Go net/http + crypto/tls but all C2 resolved at runtime via PRNG seed.
IOCs:
- Certificate: CN=
quiverquant.com, Issuer=WE1, RSA-4096, SHA-256, validity ~3 months - Hash:
c64eb93f00c92ad6367df8de17e7360ba57a34a4e2a85fe7322952513daa50d4 - Filename:
SoftWare.exe
References
- acrstealer — matching cluster (Go 1.25.4, same cert chain)
- golang-stealer-build-pattern — build-pattern concept
- prng-seeded-c2-url-decoding — C2 decode technique
- vidar — entity page (contested attribution; OpenCTI false positive)
Provenance
Artifacts from wiki/wiki/raw/analyses/c64eb93f00c92ad6367df8de17e7360ba57a34a4e2a85fe7322952513daa50d4/: file.txt, pefile.txt, strings.txt, exiftool.json, binwalk.txt, rabin2-info.txt, triage.json. Certificate parsed with OpenSSL from raw PE overlay. Static-only; no CAPE detonation.