typeanalysisfamilyacrstealerconfidencehighinfostealermalware-familygolangsigningc2exfiltration
SHA-256: e535cab50e8134087f804a818c9c96098e56520a27bb0b35c82de020937938b4

acrstealer: e535cab5 — Go 1.18.5 PE32+ x64, module BMPHSkKmFnRuuMP, 60 randomized main.* functions

Executive Summary

Twenty-fourth confirmed sibling in the ACR Stealer cluster. Go 1.18.5 PE32+ x64 with a self-signed Authenticode certificate (CN=atom.hutsell.com, issuer WR3) and a .rsrc four-icon suite. Sixty randomized main.* functions — mid-range count, heavier than the 11-function minimum but lighter than the 90-function maximum observed in this cluster. No static C2 strings recovered; PRNG-seeded runtime decoding per family pattern. No custom in-memory PE parser and no multi-pass byte-transform decoder, confirming this is a light baseline build rather than the advanced orderreshop-shared morph. Static-only analysis (CAPE skipped — no Windows guest).

What It Is

Attribute Value
SHA-256 e535cab50e8134087f804a818c9c96098e56520a27bb0b35c82de020937938b4
Size 2,026,112 bytes (1.93 MB) ^[file.txt]
Type PE32+ executable (GUI) x86-64, 7 sections ^[file.txt]
Compiler Go 1.18.5 (GOARCH=amd64, GOOS=windows, CGO_ENABLED=0, -trimpath=true) ^[strings.txt:8]
Build ID zAT3tfRZxi72dFNjesrc/NCpKc1JoODMuU3UkDEBi/8lJGC1qr0ZHy41qB2leE/TS-Hh30vY-zULsyA4mYJ ^[strings.txt:8]
Module path BMPHSkKmFnRuuMP ^[strings.txt:1159]
Stripped Yes (external PDB stripped, IMAGE_FILE_DEBUG_STRIPPED set) ^[pefile.txt:39]
Signed Yes — self-signed Authenticode, CN=atom.hutsell.com, issuer WR3, valid Apr 21 2026 – Jul 20 2026 ^[rabin2-info.txt:27]
PE timestamp 0x0 (null, typical of Go linker) ^[pefile.txt:34]
Entry point 0x5AB40 ^[pefile.txt:50]

How It Works

Build / RE

The binary is a standard Go 1.18.5 static Windows build with no CGO. The .text section entropy is 6.20 — consistent with unstripped Go runtime rather than packing ^[pefile.txt:91]. Seven sections: .text, .rdata, .data, .idata, .reloc, .symtab, .rsrc ^[pefile.txt]. The .symtab section (0x17688 bytes) holds Go symbol names including 60 randomized main.* functions ^[strings.txt].

Certificate chain sits at raw offset 0x1EE200 (PE directory entry 4, size 0x880) ^[pefile.txt:232]. Subject CN atom.hutsell.com and issuer WR3 match the cert shared by siblings ef262340 through 8f454dc1 ^[entities/acrstealer.md]. Validity window Apr–Jul 2026 is identical to the rest of this sub-cluster.

.rsrc contains four RT_ICON entries: 16×16, 32×32, 48×48, and 256×256 PNG ^[pefile.txt:328-416]. The 256×256 PNG is at raw offset 0x1E37E8 per binwalk ^[binwalk.txt:7]. Group icon (RT_GROUP_ICON, ID 0xE) is present ^[pefile.txt:419]. This is the builder's icon-toggle mode enabled (some siblings strip .rsrc entirely).

No custom in-memory PE parser strings (custom PE parser, multi-pass decoder patterns absent) ^[strings.txt]. This is the light baseline build matching ef262340, 44f594e2, 76a51fb7, and 7945e84f.

Deploy / ATT&CK

Execution — T1204.002 (User Execution: Malicious File). The binary is a GUI-subsystem PE; victim double-click expected.

Defense Evasion — T1027.002 (Obfuscated Files or Information: Software Packing). Go static binary with randomized function names (go-function-name-randomization) hinders static clustering ^[strings.txt].

Discovery — T1082 (System Information Discovery). Go runtime queries OS version via RtlGetNtVersionNumbers and GetSystemInfo ^[strings.txt:64-70].

Collection — T1005 (Data from Local System). Family pattern targets browser credential stores, crypto wallets, and FTP/SSH credentials ^[entities/acrstealer.md].

Command and Control — T1071.001 (Application Layer Protocol: Web Protocols). math/rand PRNG seeded at runtime (likely time.Now) decodes C2 strings in-memory ^[strings.txt:477]. No hardcoded C2 IP or domain recovered statically; this is the runtime-only decode pattern shared by siblings 624f52cc, d353d849, ef262340, 6cbac6bc, 44f594e2, 828405d6, 350a2b69, beff95d5, 119b387e, b0bc17dd, 38cf89b0, 76a51fb7, 4c15644f, 7945e84f, f251271a, and 8f454dc1 ^[entities/acrstealer.md].

Exfiltration — T1041 (Exfiltration Over C2 Channel). Inferred from net/http and crypto/tls runtime linkage in Go standard library ^[strings.txt].

Decompiled Behavior

Entry point at 0x45AB40 (entry0) is the Go runtime _rt0_amd64_windows bootstrap ^[r2:entry0]. It performs standard Go initialization: stack framing, CPUID feature detection (cpuid at 0x456f81), then jumps to runtime.main which spawns the goroutine scheduler and eventually calls main.main ^[r2:entry0].

No unusual anti-debug or anti-VM logic is present in the entry path. The binary relies on the family-level PRNG C2 decoder rather than environmental gating.

C2 Infrastructure

Static C2: None recovered. The binary uses PRNG-seeded runtime string decoding ^[strings.txt:477].

Certificate IoC: CN atom.hutsell.com, issuer WR3, serial not extracted (self-signed, not chained to a public CA). Validity: 2026-04-21 to 2026-07-20.

Mutex / Named Objects: None observed statically.

Registry / Filesystem: No static registry keys or marker-file names.

Interesting Tidbits

  • Module path BMPHSkKmFnRuuMP is 15 characters, consistent with the cluster's randomized module-path pattern ^[strings.txt:1159].
  • main.go is present in the source-path strings (BMPHSkKmFnRuuMP/main.go) ^[strings.txt:4389], confirming a single-file main package build.
  • The .rsrc four-icon suite includes a 256×256 PNG (0xA966 bytes) ^[pefile.txt:414] and a group-icon directory (0x3E bytes) ^[pefile.txt:446].
  • No github.com, golang.org, or third-party import paths observed — standard library only ^[strings.txt].
  • Go build ID is unique; no collision with prior siblings.

How To Mess With It (Homelab Replication)

Toolchain: Go 1.18.5 windows/amd64, CGO_ENABLED=0, -trimpath=true, -ldflags="-s -w".

Recipe:

  1. Install Go 1.18.5 (or use go1.18.5 toolchain via go install golang.org/dl/go1.18.5@latest).
  2. Create a module with a randomized name: go mod init BMPHSkKmFnRuuMP.
  3. Write main.go with PRNG-seeded C2 decoding (seed with time.Now().UnixNano(), decode via math/rand).
  4. Build: GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" -o acr_baseline.exe.
  5. Sign with a self-signed cert (OpenSSL: openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 90 -nodes -subj "/CN=atom.hutsell.com").
  6. Embed cert via signtool sign /f cert.pem /p "" acr_baseline.exe or append DER manually.
  7. Add .rsrc icons with goversioninfo or Resource Hacker for masquerade.

Verification: Run strings acr_baseline.exe | grep -c '^main\.' — should match ~60 randomized functions. Compare file output to PE32+ executable (GUI) x86-64.

Deployable Signatures

YARA

rule ACRStealer_Go1185_Baseline_x64 {
    meta:
        description = "ACR Stealer Go 1.18.5 baseline x64 sibling"
        author = "PacketPursuit"
        date = "2026-08-06"
        sha256 = "e535cab50e8134087f804a818c9c96098e56520a27bb0b35c82de020937938b4"
    strings:
        $go_build_id = "Go build ID: \"zAT3tfRZxi72dFNjesrc/NCpKc1JoODMuU3UkDEBi/8lJGC1qr0ZHy41qB2leE/TS-Hh30vY-zULsyA4mYJ\""
        $mod_path = "path\tBMPHSkKmFnRuuMP"
        $main_pattern = /main\.[a-zA-Z]{6,20}/
        $cert_cn = "atom.hutsell.com"
        $issuer = "WR3"
    condition:
        uint16(0) == 0x5A4D and
        pe.machine == pe.MACHINE_AMD64 and
        $go_build_id and
        $mod_path and
        #main_pattern >= 50 and
        $cert_cn and
        $issuer
}

Sigma

title: ACR Stealer Go 1.18.5 Baseline Execution
logsource:
    product: windows
    category: process_creation
detection:
    selection:
        CommandLine|contains:
            - 'BMPHSkKmFnRuuMP'
        # Heuristic: Go static binary with large .rdata and .symtab
        Image|endswith: '.exe'
    condition: selection
falsepositives:
    - Unknown
level: high

IOC List

Type Value Notes
SHA-256 e535cab50e8134087f804a818c9c96098e56520a27bb0b35c82de020937938b4 This sample
SHA-1 731cd158ea10f2ac070df7a627e12c3b61591fb6 .text section ^[pefile.txt:93]
MD5 d5bc598c9e1fc9134e7d679747f82e5e .text section ^[pefile.txt:92]
ssdeep 24576:b+jE3dR+V7B2PES6cITDN37p14A3qfJJrNjQ6OgLP88WvFHXvYsD1PiS:b+o3m7/PcITDN7poJIgLPNsD1aS ^[triage.json]
tlsh T16CF472CF604E45DBF8C2B4D607E8B2E2A757D472F4458F774D485E3E8B5838E3A5F4 ^[tlsh.txt]
Cert CN atom.hutsell.com Self-signed
Cert Issuer WR3 Self-signed
Go Build ID zAT3tfRZxi72dFNjesrc/NCpKc1JoODMuU3UkDEBi/8lJGC1qr0ZHy41qB2leE/TS-Hh30vY-zULsyA4mYJ Unique
Module path BMPHSkKmFnRuuMP Randomized

Behavioral Fingerprint

This binary is a Go 1.18.5 windows/amd64 static executable with a null PE timestamp, a .symtab section containing 50-90 randomized main.* function names, a .rsrc section with 1-4 PNG icons (up to 256×256), and a self-signed Authenticode certificate with CN atom.hutsell.com and issuer WR3. It imports only kernel32.dll APIs via the standard Go syscall layer, links math/rand for PRNG operations, and contains no hardcoded C2 strings — C2 is decoded at runtime from a PRNG seed (likely current time). No custom PE parser or multi-pass decoder strings are present in baseline variants. Family behavior includes browser credential theft, cryptocurrency wallet targeting, and HTTPS C2 exfiltration.

Detection Signatures

ATT&CK Technique Detection Source
T1204.002 Execution — malicious PE with GUI subsystem and icon masquerade
T1027.002 Defense Evasion — Go static binary with randomized function names
T1082 Discovery — RtlGetNtVersionNumbers, GetSystemInfo
T1005 Collection — browser/crypto/FTP credential harvesting (family pattern)
T1071.001 C2 — PRNG-decoded HTTPS/TLS C2 (inferred from math/rand + Go net/http linkage)
T1041 Exfiltration — data posted to C2 over HTTPS

References

Provenance

Analysis derived from:

  • file.txt (file(1) output)
  • strings.txt (6,942 lines, strings -a -n 6)
  • pefile.txt (pefile Python module output)
  • rabin2-info.txt (radare2 rabin2 -I)
  • binwalk.txt (binwalk embedded-artifact scan)
  • exiftool.json (ExifTool 12.76)
  • triage.json (triage pipeline metadata)
  • metadata.json (OpenCTI artifact metadata)
  • ssdeep.txt, tlsh.txt (fuzzy hashes)
  • yara.txt (YARA matches — generic PE only)
  • dynamic-analysis.md (CAPE skipped — no Windows guest)
  • radare2 analysis (level 3, 1,501 functions recovered, entry point 0x45AB40)

Tools: radare2 5.x, pefile, binwalk, ExifTool 12.76, ssdeep, tlsh, YARA.