cdd16fc0a2bf1499ba815bc95288456e46c7245b64c9d06033f2c61eb06900f5acrstealer: cdd16fc0 — 65-symbol Go 1.18.5 x64, no .rsrc, atom.hutsell.com cert
Executive Summary
PE32+ x64 infostealer compiled with Go 1.18.5, carrying 65 randomized main.* symbols and a self-signed atom.hutsell.com / WR3 Authenticode certificate. No .rsrc section (icon-masquerade stripped). Static C2 absent — runtime PRNG-seeded decode per family pattern. OpenCTI co-labels this sample remusstealer; static evidence confirms it is the twenty-fifth confirmed sibling in the acrstealer cluster, not Protector Lab. Static-only — CAPE skipped (no Windows guest).
What It Is
| Field | Value |
|---|---|
| SHA-256 | cdd16fc0a2bf1499ba815bc95288456e46c7245b64c9d06033f2c61eb06900f5 |
| Filename | Bootsrappper.exe (typo of "Bootstrapper") ^[metadata.json] |
| Size | 1,559,680 bytes ^[metadata.json] |
| Format | PE32+ executable (GUI) x86-64, 6 sections ^[file.txt] |
| Compiler | Go 1.18.5 (go1.18.5 in .rdata) ^[strings.txt:1155] |
| Build ID | r5ZtVmGqy1LyuEEG5H5p/xMIeSr5qAVH3HAOaGX59/M0b6WZP_S023O48_SUpo/OcJrsCf2pWWsp2kCbCSz ^[strings.txt:7] |
| Timestamp | 1970-01-01 00:00:00 UTC (null, stripped) ^[pefile.txt:34] |
| Signed | Yes — self-signed cert CN=atom.hutsell.com, issuer WR3 ^[rabin2-info.txt], ^[binwalk.txt] |
| .rsrc | Absent — no icon masquerade ^[pefile.txt] |
Build / RE
Toolchain
Go 1.18.5 windows/amd64, CGO_ENABLED=0, -trimpath=true. Standard Go runtime strings dominate .rdata: runtime.main.func1, runtime.netpoll*, syscall.compileCallback, strconv.computeBounds, internal/poll.execIO. ^[strings.txt:1093-5611] The module path is not recovered in static strings (trimpath strips it), but the source file path fragment rYgjRHEwWbFSudb/main.go appears in .rdata. ^[strings.txt:3774]
Function-name randomization
65 unique randomized main.* symbols recovered, of which ~37 are functions/closures (remainder are struct types). Examples: main.rpcubnjtqxzxhce, main.jchczjkekuemaj, main.Acmygyoygmlem. ^[strings.txt:3521-3563] This is mid-range for the cluster (record: 90, minimum: 11).
Signing
Authenticode signature block present at offset 0x17C408 (size 0x880). ^[binwalk.txt] ^[pefile.txt:212-213] Subject CN atom.hutsell.com / issuer WR3 — identical certificate chain to siblings ef262340, 6cbac6bc, beff95d53267, and nineteen others. ^[entities/acrstealer.md] This is a self-signed certificate, not a stolen legitimate one.
Packing / Obfuscation
No external packer. Entropy: .text 6.199, .rdata 6.388 — within normal range for Go binaries. ^[pefile.txt:91,111] No anti-debug or VM-detection strings in static output. No custom PE parser or multi-pass decoder (lightest build variant in cluster).
Deploy / ATT&CK
TTPs
| ATT&CK ID | Technique | Evidence |
|---|---|---|
| T1027.002 | Obfuscated Files or Information: Software Packing | Go binary with randomized function names hindering static clustering ^[strings.txt:3521] |
| T1071.001 | Application Layer Protocol: Web Protocols | net/http and crypto/tls runtime linkage inferred from Go standard-library strings ^[strings.txt:1093] |
| T1497.001 | Virtualization/Sandbox Evasion: System Checks | Null PE timestamp + no static C2 — runtime-only decode evades single-PE sandbox detonation |
C2
No hardcoded IPs, domains, or URLs recovered statically. The family pattern is PRNG-seeded runtime C2 string decoding. ^[entities/acrstealer.md] Without dynamic execution, the C2 endpoint is unrecoverable.
Persistence / Exfil
No static evidence. Family behaviour (per siblings with dynamic data) suggests HTTPS POST exfil of browser credentials and wallet data. ^[entities/acrstealer.md]
Interesting Tidbits
- False-positive co-label: OpenCTI tags this
remusstealer, but every static artefact — Go build ID,atom.hutsell.comcert, randomizedmain.*names — aligns with the ACR cluster. This is the third confirmedremusstealerfalse-positive on theatom.hutsell.comcert sub-cluster, after6cbac6bcandbeff95d53267. ^[entities/remusstealer.md] .rsrcstripped: Unlike most ACR siblings that carry a four-icon suite in.rsrc, this build has none. Builder has an icon-toggle option.- Typo filename:
Bootsrappper.exe(double-p, double-r) — suggests English-speaking operator or copy-paste error in builder configuration. - Mid-range symbol count: 65
main.*symbols sits between the 11-minimum (38cf89b0) and 90-record (b0bc17dd,f251271a,8f454dc1) siblings, indicating the builder randomizes function counts per build.
How To Mess With It (Homelab Replication)
Toolchain: Go 1.18.5 windows/amd64, CGO_ENABLED=0, -trimpath=true, -ldflags="-s -w".
- Write a minimal Go program that seeds
math/randwithtime.Now().Unix(), decodes a C2 string slice at runtime, and POSTs a JSON payload vianet/http+crypto/tls. - Compile with randomized
mainpackage function names (usegolang.org/x/tools/go/ast/astutilor simple source rewriting). - Self-sign with
openssl req -x509 -newkey rsa:2048 -keyout wr3.key -out atom.crt -subj "/CN=atom.hutsell.com/O=WR3" -days 90. - Attach cert with
osslsigncodeorsigntool. - Verify:
rabin2 -I reproducer.exeshould showlang: c,signed: true,stripped: true, and strings should containgo1.18.5plus your randomizedmain.*names.
Deployable Signatures
YARA
rule ACR_Stealer_AtomHutsell_Go1185 {
meta:
description = "ACR Stealer cluster — Go 1.18.5, atom.hutsell.com self-signed cert, randomized main functions"
author = "PacketPursuit"
family = "acrstealer"
strings:
$go_ver = "go1.18.5" ascii wide
$cert_cn = "atom.hutsell.com" ascii wide
$buildid = "Go build ID:" ascii
$main1 = /main\.[a-zA-Z0-9]{8,20}/
condition:
uint16(0) == 0x5A4D and
$go_ver and
$cert_cn and
#main1 >= 10
}
IOC List
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | cdd16fc0a2bf1499ba815bc95288456e46c7245b64c9d06033f2c61eb06900f5 |
Hash |
| Certificate CN | atom.hutsell.com |
Signing indicator |
| Certificate Issuer | WR3 |
Signing indicator |
| Go build version | go1.18.5 |
Build artefact |
| Build ID prefix | r5ZtVmGqy1LyuEEG5H5p |
Build artefact |
| Filename | Bootsrappper.exe |
Social-engineering lure |
Behavioral Fingerprint
This binary is a Go 1.18.5 windows/amd64 static executable with null PE timestamp, stripped symbols, and a self-signed atom.hutsell.com certificate. It contains 10+ randomized main.* function names and links net/http + crypto/tls, but carries no hardcoded C2 strings. Expected runtime behaviour: seeds PRNG with current time, decodes C2 endpoint(s), then POSTs collected system/browser/wallet data over HTTPS. Absence of .rsrc icons is a builder-toggle variant within the cluster.
Detection Signatures
- YARA:
PE_File_Genericmatched (generic PE rule, low value). ^[yara.txt] - CAPE: Skipped — no Windows guest available. ^[dynamic-analysis.md]
- Capa: Failed (signatures path missing). ^[capa.txt]
- FLOSS: Failed (CLI mis-invoked). ^[floss.txt]
References
- OpenCTI artifact:
53487d14-532d-498d-9bb5-ea0092a44f0f^[metadata.json] - Family entity: acrstealer
- Contested co-label: remusstealer
- Build-pattern concept: golang-stealer-build-pattern
- Sibling reports:
ef262340,6cbac6bc,beff95d53267,44f594e2,828405d6,350a2b69,119b387e,b0bc17dd,38cf89b0,76a51fb7,4c15644f,7945e84f,f251271a,8f454dc1,e535cab5^[entities/acrstealer.md]
Provenance
file.txt— file(1) outputexiftool.json— ExifTool PE metadatapefile.txt— pefile.py DOS/NT headers, sections, importsrabin2-info.txt— radare2 binary info (signed: true,stripped: true)strings.txt— GNU strings (Go runtime, randomized main symbols, build ID)binwalk.txt— embedded artefact scan (signature block at 0x17C408)metadata.json/triage.json— OpenCTI labels and triage classificationdynamic-analysis.md— CAPE skipped (no Windows guest)- Ghidra import queued; radare2 entry-point decompilation confirms standard Go runtime init sequence with CPUID detection and stack canary setup.