typeanalysisfamilyacrstealerconfidencehighcreated2026-08-13updated2026-08-13pepe32plusgolanginfostealersigningobfuscationc2mitre-attck
SHA-256: c64eb93f00c92ad6367df8de17e7360ba57a34a4e2a85fe7322952513daa50d4

acrstealer: c64eb93f — Go 1.25.4 x64 with quiverquant.com self-signed cert, 64 randomized main.* functions

Executive Summary: Go 1.25.4 PE32+ x64 infostealer with self-signed Authenticode (quiverquant.com/WE1). Build fingerprint — Go 1.25.4, quiverquant.com cert, no .rsrc, 64 randomized main.* symbols — is an exact match for the acrstealer cluster. OpenCTI label vidar is a known false positive on this cert chain; this is the thirty-sixth confirmed sibling and the tenth confirmed sample on the quiverquant.com/WE1 certificate chain.

What It Is

Field Value
SHA-256 c64eb93f00c92ad6367df8de17e7360ba57a34a4e2a85fe7322952513daa50d4
Filename SoftWare.exe
Type PE32+ executable (GUI) x86-64, 8 sections^[file.txt]
Size 2,558,592 bytes (2.44 MB)
Compiler Go 1.25.4, CGO_ENABLED=0, -trimpath=true, -buildmode=exe^[strings.txt:1717-1725]
Module path fPkQKdkjTpkkdga^[strings.txt:1721]
Build ID kDEXpXTj-S0VRMBRP5Ul/df6UcLEmckfOEf1z7YOJ/FZBk6taCIZMeY5nS__66/uoqw0MwHucmSAy9N13Zh^[strings.txt:9]
Subsystem Windows GUI (no console)^[exiftool.json]
Timestamp Zero (1970-01-01 00:00:00) — Go default^[pefile.txt:34]
Signing Self-signed Authenticode CN=quiverquant.com, issuer WE1, RSA-4096, SHA-256, valid May 9 – Aug 7 2026^[binwalk.txt:4-7]
Family acrstealer (high confidence; OpenCTI vidar is contested)

Build / RE

Toolchain: Go 1.25.4 (GOOS=windows, GOARCH=amd64), CGO_ENABLED=0, -trimpath=true, -buildmode=exe^[strings.txt:1717-1725]. Standard Go linker version 3.0^[exiftool.json]. Windows GUI subsystem with no console window.

Signing: Authenticode certificate embedded in overlay at offset 0x270208, size 0x880^[pefile.txt:251-253]. OpenSSL parse reveals a self-signed X.509v3 certificate with Subject CN=quiverquant.com, Issuer CN=WE1, 4096-bit RSA public key, SHA-256 signature algorithm, validity window 2026-05-09 to 2026-08-07^[binwalk.txt:4-7]. This is the tenth confirmed sample in the corpus on the quiverquant.com/WE1 cert chain, all belonging to the acrstealer cluster.

Obfuscation: Sixty-four randomized main.* symbols in the Go symbol table (37 direct functions plus type and closure references): main.enlqjd, main.geowxxuesvvhjh, main.qeenqabaflul, main.jwxmkihsrqz, main.dunvhcb, main.nfslty, main.komccvhqqw, main.ngpiwcfdguq, main.onwddld, main.rdeizssyoub, main.rrrdhfjce, main.ybdmirqqfhq, main.azwfxf, main.djsniih, main.kysfjrch, main.ddwqidtqs, main.xpppcfszypyzyi, main.llkgnxccqklqc, main.wcqwgwqflvaqvp, main.kvnvldktcpsvso, main.nkrsupoo, main.lnstdlwqpdkhxjd, main.lnbpcdmdcq, main.czffrg, main.bsjgscsyrimihw, main.spshhevh, main.tauzjoozmrvvjwa, main.Akoivunidczy, main.Tssmmtygzg, main.Yevdalbc, main.Pitheyfh, main.Lajypwexbblvz, main.Qdkluefiimqx, main.Bohjcfdesuh, main.Rbeqwyxjkfztwei, main.Bawriwvjn, main.gfwagqca^[strings.txt:5748-5783]. No external packer; .text entropy 6.25, .rdata 7.08^[pefile.txt:91,111].

Sections: .text, .rdata, .data, .pdata, .xdata, .idata, .reloc, .symtab. Notable: .symtab is present (Go symbol table, not stripped), and there is no .rsrc section (builder stripped icon resources)^[pefile.txt:75-236].

Imports: Only kernel32.dll imported directly via IAT — 46 APIs including VirtualAlloc, CreateThread, LoadLibraryW, GetProcAddress, SetThreadContext^[pefile.txt:288-344]. The Go runtime resolves all other APIs dynamically.

Exports: 1900 symbols (heavy Go runtime symbol table)^[rabin2-info.txt:30].

Anti-analysis: No VM detection strings, no debugger checks, no sandbox gates observed statically. Go runtime string bloat dominates strings.txt and would poison naive signature matching.

Deploy / ATT&CK

No dynamic analysis was performed (CAPE skipped — no Windows guest available)^[dynamic-analysis.md]. TTPs below are inferred from static artifacts and family behavior.

Technique ID Evidence
Data from Local System T1005 Inferred from infostealer family pattern
Input Capture: Clipboard T1115 Inferred from family behavior (crypto clipper)
Input Capture: Keylogging T1056.001 Inferred from family behavior
Screen Capture T1113 Inferred from family behavior
Credentials from Web Browsers T1555.003 Inferred from family behavior
Exfiltration Over C2 T1041 net/http + crypto/tls linkage implies HTTPS C2
Application Layer Protocol: Web T1071.001 net/http, crypto/tls standard library linkage^[strings.txt]
Native API T1106 VirtualAlloc, CreateThread, LoadLibraryW imported^[pefile.txt]

C2: No hardcoded C2 URL, IP, or domain found in static strings. The ACR/Lumma cluster uses PRNG-seeded runtime C2 decoding — this sample follows the same pattern. net/http, crypto/tls, crypto/x509 present in strings^[strings.txt:1717,1718,1719].

Persistence: No static evidence. No registry key strings, no scheduled-task references.

Interesting Tidbits

  • Contested attribution: The quiverquant.com/WE1 certificate chain is exclusive to the ACR Stealer cluster in this corpus. Nine prior samples (c69b14a0, f668de57, 1cf857a9, 725dc07c, f258a5d7, 55c7b564, bd783215, 94cf86f6, 0bc8490a) share this exact chain. None of the prior confirmed vidar samples (3799d1f74d95, d4b6905ef14c) use this certificate. OpenCTI's vidar label on this sample is a known false positive.
  • No .rsrc: The builder optionally strips the .rsrc icon section. Prior ACR siblings c69b14a0, cdd16fc0, and 94cf86f6 also lack .rsrc, confirming builder toggle behavior.
  • 64 randomized main. symbols:* The highest symbol count observed on the quiverquant.com/WE1 chain (prior range: 11–92). This does not correlate with binary size or section entropy, suggesting the builder randomizes symbol count independently.
  • Go 1.25.4 timestamp zero: Go compiler defaults to epoch timestamp, which anti-forensics tools sometimes mistake for "packed."
  • GUI subsystem: Masquerades as a legitimate Windows application (SoftWare.exe).

How To Mess With It (Homelab Replication)

Toolchain: Go 1.25.4 for Windows amd64.

Compiler/linker flags:

GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build -trimpath -buildmode=exe -o repro.exe .

Working source snippet:

package main

import (
    "crypto/tls"
    "fmt"
    "net/http"
)

func main() {
    tr := &http.Transport{TLSClientConfig: &tls.Config{InsecureSkipVerify: true}}
    client := &http.Client{Transport: tr}
    _, _ = client.Get("https://example.com")
    fmt.Println("done")
}

Verification step: Run capa repro.exe (once signatures are installed) and compare to expected family fingerprint — should hit use network socket, initialize Winsock, and send data capabilities. The actual sample failed capa due to missing signatures, but the family baseline should match.

What you'll learn: How Go's -trimpath and CGO_ENABLED=0 produce a static PE with no build-path leakage and a minimal IAT surface, and how self-signed Authenticode overlays behave versus PE directory entries.

Deployable Signatures

YARA rule:

rule Go_ACR_Cluster_Quiverquant_WE1_v2 {
    meta:
        description = "Go infostealer with quiverquant.com self-signed cert"
        author = "PacketPursuit"
        date = "2026-08-13"
    strings:
        $go_build = "go1.25.4" ascii
        $cert_cn = "quiverquant.com" ascii wide
        $cert_issuer = "WE1" ascii wide
        $trimpath = "-trimpath=true" ascii
    condition:
        uint16(0) == 0x5A4D and
        $go_build and
        ($cert_cn or $cert_issuer) and
        $trimpath
}

Behavioral fingerprint: PE32+ x64 Go 1.25.4 binary with zero PE timestamp, self-signed Authenticode CN=quiverquant.com/issuer=WE1, no .rsrc section or stripped .rsrc, 35–90 randomized main.* function names in Go symtab, and no static C2 strings. Network-capable via Go net/http + crypto/tls but all C2 resolved at runtime via PRNG seed.

IOCs:

  • Certificate: CN=quiverquant.com, Issuer=WE1, RSA-4096, SHA-256, validity ~3 months
  • Hash: c64eb93f00c92ad6367df8de17e7360ba57a34a4e2a85fe7322952513daa50d4
  • Filename: SoftWare.exe

References

Provenance

Artifacts from wiki/wiki/raw/analyses/c64eb93f00c92ad6367df8de17e7360ba57a34a4e2a85fe7322952513daa50d4/: file.txt, pefile.txt, strings.txt, exiftool.json, binwalk.txt, rabin2-info.txt, triage.json. Certificate parsed with OpenSSL from raw PE overlay. Static-only; no CAPE detonation.