e535cab50e8134087f804a818c9c96098e56520a27bb0b35c82de020937938b4acrstealer: e535cab5 — Go 1.18.5 PE32+ x64, module BMPHSkKmFnRuuMP, 60 randomized main.* functions
Executive Summary
Twenty-fourth confirmed sibling in the ACR Stealer cluster. Go 1.18.5 PE32+ x64 with a self-signed Authenticode certificate (CN=atom.hutsell.com, issuer WR3) and a .rsrc four-icon suite. Sixty randomized main.* functions — mid-range count, heavier than the 11-function minimum but lighter than the 90-function maximum observed in this cluster. No static C2 strings recovered; PRNG-seeded runtime decoding per family pattern. No custom in-memory PE parser and no multi-pass byte-transform decoder, confirming this is a light baseline build rather than the advanced orderreshop-shared morph. Static-only analysis (CAPE skipped — no Windows guest).
What It Is
| Attribute | Value |
|---|---|
| SHA-256 | e535cab50e8134087f804a818c9c96098e56520a27bb0b35c82de020937938b4 |
| Size | 2,026,112 bytes (1.93 MB) ^[file.txt] |
| Type | PE32+ executable (GUI) x86-64, 7 sections ^[file.txt] |
| Compiler | Go 1.18.5 (GOARCH=amd64, GOOS=windows, CGO_ENABLED=0, -trimpath=true) ^[strings.txt:8] |
| Build ID | zAT3tfRZxi72dFNjesrc/NCpKc1JoODMuU3UkDEBi/8lJGC1qr0ZHy41qB2leE/TS-Hh30vY-zULsyA4mYJ ^[strings.txt:8] |
| Module path | BMPHSkKmFnRuuMP ^[strings.txt:1159] |
| Stripped | Yes (external PDB stripped, IMAGE_FILE_DEBUG_STRIPPED set) ^[pefile.txt:39] |
| Signed | Yes — self-signed Authenticode, CN=atom.hutsell.com, issuer WR3, valid Apr 21 2026 – Jul 20 2026 ^[rabin2-info.txt:27] |
| PE timestamp | 0x0 (null, typical of Go linker) ^[pefile.txt:34] |
| Entry point | 0x5AB40 ^[pefile.txt:50] |
How It Works
Build / RE
The binary is a standard Go 1.18.5 static Windows build with no CGO. The .text section entropy is 6.20 — consistent with unstripped Go runtime rather than packing ^[pefile.txt:91]. Seven sections: .text, .rdata, .data, .idata, .reloc, .symtab, .rsrc ^[pefile.txt]. The .symtab section (0x17688 bytes) holds Go symbol names including 60 randomized main.* functions ^[strings.txt].
Certificate chain sits at raw offset 0x1EE200 (PE directory entry 4, size 0x880) ^[pefile.txt:232]. Subject CN atom.hutsell.com and issuer WR3 match the cert shared by siblings ef262340 through 8f454dc1 ^[entities/acrstealer.md]. Validity window Apr–Jul 2026 is identical to the rest of this sub-cluster.
.rsrc contains four RT_ICON entries: 16×16, 32×32, 48×48, and 256×256 PNG ^[pefile.txt:328-416]. The 256×256 PNG is at raw offset 0x1E37E8 per binwalk ^[binwalk.txt:7]. Group icon (RT_GROUP_ICON, ID 0xE) is present ^[pefile.txt:419]. This is the builder's icon-toggle mode enabled (some siblings strip .rsrc entirely).
No custom in-memory PE parser strings (custom PE parser, multi-pass decoder patterns absent) ^[strings.txt]. This is the light baseline build matching ef262340, 44f594e2, 76a51fb7, and 7945e84f.
Deploy / ATT&CK
Execution — T1204.002 (User Execution: Malicious File). The binary is a GUI-subsystem PE; victim double-click expected.
Defense Evasion — T1027.002 (Obfuscated Files or Information: Software Packing). Go static binary with randomized function names (go-function-name-randomization) hinders static clustering ^[strings.txt].
Discovery — T1082 (System Information Discovery). Go runtime queries OS version via RtlGetNtVersionNumbers and GetSystemInfo ^[strings.txt:64-70].
Collection — T1005 (Data from Local System). Family pattern targets browser credential stores, crypto wallets, and FTP/SSH credentials ^[entities/acrstealer.md].
Command and Control — T1071.001 (Application Layer Protocol: Web Protocols). math/rand PRNG seeded at runtime (likely time.Now) decodes C2 strings in-memory ^[strings.txt:477]. No hardcoded C2 IP or domain recovered statically; this is the runtime-only decode pattern shared by siblings 624f52cc, d353d849, ef262340, 6cbac6bc, 44f594e2, 828405d6, 350a2b69, beff95d5, 119b387e, b0bc17dd, 38cf89b0, 76a51fb7, 4c15644f, 7945e84f, f251271a, and 8f454dc1 ^[entities/acrstealer.md].
Exfiltration — T1041 (Exfiltration Over C2 Channel). Inferred from net/http and crypto/tls runtime linkage in Go standard library ^[strings.txt].
Decompiled Behavior
Entry point at 0x45AB40 (entry0) is the Go runtime _rt0_amd64_windows bootstrap ^[r2:entry0]. It performs standard Go initialization: stack framing, CPUID feature detection (cpuid at 0x456f81), then jumps to runtime.main which spawns the goroutine scheduler and eventually calls main.main ^[r2:entry0].
No unusual anti-debug or anti-VM logic is present in the entry path. The binary relies on the family-level PRNG C2 decoder rather than environmental gating.
C2 Infrastructure
Static C2: None recovered. The binary uses PRNG-seeded runtime string decoding ^[strings.txt:477].
Certificate IoC: CN atom.hutsell.com, issuer WR3, serial not extracted (self-signed, not chained to a public CA). Validity: 2026-04-21 to 2026-07-20.
Mutex / Named Objects: None observed statically.
Registry / Filesystem: No static registry keys or marker-file names.
Interesting Tidbits
- Module path
BMPHSkKmFnRuuMPis 15 characters, consistent with the cluster's randomized module-path pattern ^[strings.txt:1159]. main.gois present in the source-path strings (BMPHSkKmFnRuuMP/main.go) ^[strings.txt:4389], confirming a single-filemainpackage build.- The
.rsrcfour-icon suite includes a 256×256 PNG (0xA966bytes) ^[pefile.txt:414] and a group-icon directory (0x3Ebytes) ^[pefile.txt:446]. - No
github.com,golang.org, or third-party import paths observed — standard library only ^[strings.txt]. - Go build ID is unique; no collision with prior siblings.
How To Mess With It (Homelab Replication)
Toolchain: Go 1.18.5 windows/amd64, CGO_ENABLED=0, -trimpath=true, -ldflags="-s -w".
Recipe:
- Install Go 1.18.5 (or use
go1.18.5toolchain viago install golang.org/dl/go1.18.5@latest). - Create a module with a randomized name:
go mod init BMPHSkKmFnRuuMP. - Write
main.gowith PRNG-seeded C2 decoding (seed withtime.Now().UnixNano(), decode viamath/rand). - Build:
GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" -o acr_baseline.exe. - Sign with a self-signed cert (OpenSSL:
openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 90 -nodes -subj "/CN=atom.hutsell.com"). - Embed cert via
signtool sign /f cert.pem /p "" acr_baseline.exeor append DER manually. - Add
.rsrcicons withgoversioninfoor Resource Hacker for masquerade.
Verification: Run strings acr_baseline.exe | grep -c '^main\.' — should match ~60 randomized functions. Compare file output to PE32+ executable (GUI) x86-64.
Deployable Signatures
YARA
rule ACRStealer_Go1185_Baseline_x64 {
meta:
description = "ACR Stealer Go 1.18.5 baseline x64 sibling"
author = "PacketPursuit"
date = "2026-08-06"
sha256 = "e535cab50e8134087f804a818c9c96098e56520a27bb0b35c82de020937938b4"
strings:
$go_build_id = "Go build ID: \"zAT3tfRZxi72dFNjesrc/NCpKc1JoODMuU3UkDEBi/8lJGC1qr0ZHy41qB2leE/TS-Hh30vY-zULsyA4mYJ\""
$mod_path = "path\tBMPHSkKmFnRuuMP"
$main_pattern = /main\.[a-zA-Z]{6,20}/
$cert_cn = "atom.hutsell.com"
$issuer = "WR3"
condition:
uint16(0) == 0x5A4D and
pe.machine == pe.MACHINE_AMD64 and
$go_build_id and
$mod_path and
#main_pattern >= 50 and
$cert_cn and
$issuer
}
Sigma
title: ACR Stealer Go 1.18.5 Baseline Execution
logsource:
product: windows
category: process_creation
detection:
selection:
CommandLine|contains:
- 'BMPHSkKmFnRuuMP'
# Heuristic: Go static binary with large .rdata and .symtab
Image|endswith: '.exe'
condition: selection
falsepositives:
- Unknown
level: high
IOC List
| Type | Value | Notes |
|---|---|---|
| SHA-256 | e535cab50e8134087f804a818c9c96098e56520a27bb0b35c82de020937938b4 |
This sample |
| SHA-1 | 731cd158ea10f2ac070df7a627e12c3b61591fb6 |
.text section ^[pefile.txt:93] |
| MD5 | d5bc598c9e1fc9134e7d679747f82e5e |
.text section ^[pefile.txt:92] |
| ssdeep | 24576:b+jE3dR+V7B2PES6cITDN37p14A3qfJJrNjQ6OgLP88WvFHXvYsD1PiS:b+o3m7/PcITDN7poJIgLPNsD1aS |
^[triage.json] |
| tlsh | T16CF472CF604E45DBF8C2B4D607E8B2E2A757D472F4458F774D485E3E8B5838E3A5F4 |
^[tlsh.txt] |
| Cert CN | atom.hutsell.com |
Self-signed |
| Cert Issuer | WR3 |
Self-signed |
| Go Build ID | zAT3tfRZxi72dFNjesrc/NCpKc1JoODMuU3UkDEBi/8lJGC1qr0ZHy41qB2leE/TS-Hh30vY-zULsyA4mYJ |
Unique |
| Module path | BMPHSkKmFnRuuMP |
Randomized |
Behavioral Fingerprint
This binary is a Go 1.18.5 windows/amd64 static executable with a null PE timestamp, a .symtab section containing 50-90 randomized main.* function names, a .rsrc section with 1-4 PNG icons (up to 256×256), and a self-signed Authenticode certificate with CN atom.hutsell.com and issuer WR3. It imports only kernel32.dll APIs via the standard Go syscall layer, links math/rand for PRNG operations, and contains no hardcoded C2 strings — C2 is decoded at runtime from a PRNG seed (likely current time). No custom PE parser or multi-pass decoder strings are present in baseline variants. Family behavior includes browser credential theft, cryptocurrency wallet targeting, and HTTPS C2 exfiltration.
Detection Signatures
| ATT&CK Technique | Detection Source |
|---|---|
| T1204.002 | Execution — malicious PE with GUI subsystem and icon masquerade |
| T1027.002 | Defense Evasion — Go static binary with randomized function names |
| T1082 | Discovery — RtlGetNtVersionNumbers, GetSystemInfo |
| T1005 | Collection — browser/crypto/FTP credential harvesting (family pattern) |
| T1071.001 | C2 — PRNG-decoded HTTPS/TLS C2 (inferred from math/rand + Go net/http linkage) |
| T1041 | Exfiltration — data posted to C2 over HTTPS |
References
- acrstealer — Entity page for the ACR Stealer family
- golang-stealer-build-pattern — Common Go infostealer build artefacts
- prng-seeded-c2-url-decoding — Family-wide C2 decoding technique
- OpenCTI labels:
acrstealer,exe,urlhaus^[triage.json]
Provenance
Analysis derived from:
file.txt(file(1) output)strings.txt(6,942 lines,strings -a -n 6)pefile.txt(pefile Python module output)rabin2-info.txt(radare2rabin2 -I)binwalk.txt(binwalk embedded-artifact scan)exiftool.json(ExifTool 12.76)triage.json(triage pipeline metadata)metadata.json(OpenCTI artifact metadata)ssdeep.txt,tlsh.txt(fuzzy hashes)yara.txt(YARA matches — generic PE only)dynamic-analysis.md(CAPE skipped — no Windows guest)- radare2 analysis (level 3, 1,501 functions recovered, entry point
0x45AB40)
Tools: radare2 5.x, pefile, binwalk, ExifTool 12.76, ssdeep, tlsh, YARA.