typeanalysisfamilyacrstealerconfidencehighcreated2026-08-19updated2026-08-19infostealergolangsigningpemalware-family
SHA-256: ea41d4b15a8e270f2113b16f050cb3e15cb5a5c85711fb6ec31dc6bb7279ba42

acrstealer: ea41d4b1 — Go 1.20.6 x64, seekingalpha.com cert, 81 main.* functions

Executive Summary

Go 1.20.6 PE32+ x64 infostealer mislabeled remusstealer by OpenCTI. It carries the exact same GlobalSign DV TLS certificate chain (GlobalSign Atlas R3 DV TLS CA 2025 Q4 → CN=seekingalpha.com) as confirmed acrstealer siblings f0105851, 2f23087f, and 58eda486. Module path LEMEXLlSisSswHg, 81 randomized main.* function names, four-icon .rsrc suite, no static C2, no custom PE parser, no multi-pass decoder. Static-only analysis (CAPE skipped — no Windows guest).

What It Is

Field Value Source
SHA-256 ea41d4b15a8e270f2113b16f050cb3e15cb5a5c85711fb6ec31dc6bb7279ba42 triage.json
File type PE32+ executable (GUI) x86-64, stripped file.txt
Size 1,761,992 bytes triage.json
Compiler Go 1.20.6, GOARCH=amd64, GOOS=windows, CGO_ENABLED=0, -trimpath=true strings.txt:1247–1259
Module path LEMEXLlSisSswHg strings.txt:1251
Randomized main.* 81 strings.txt count
Certificate GlobalSign Atlas R3 DV TLS CA 2025 Q4 → CN=seekingalpha.com (PKCS#7, 2240 bytes) binwalk.txt:9, pefile.txt
.rsrc 4 icons (16×16, 32×32, 48×48, 256×256 PNG) pefile.txt:329–418
Overlay None — security directory is the only trailing data terminal
Family acrstealer (contested remusstealer label) cert chain + build fingerprint

The remusstealer OpenCTI label is a false-positive umbrella, identical to the 54e64e, depumped, cloud55filecc, vidar, and lummastealer mislabels previously contested and resolved to the ACR cluster. ^[entities/acrstealer.md]

How It Works

Standard ACR cluster execution pattern (see acrstealer for shared behaviour):

  1. Go runtime bootstrap via runtime.rt0_go → main.main ^[r2:entry0]
  2. PRNG-seeded runtime string decoding for C2 URLs (inferred from math/rand heavy linkage and family pattern; no static C2 recovered in this sample) ^[strings.txt:506]
  3. Browser credential store enumeration, cryptocurrency wallet targeting, system info harvesting (family behaviour; no static API call list due to Go syscall abstraction)
  4. Exfiltration via HTTPS POST to runtime-decoded C2 (inferred from net/http + crypto/tls Go runtime strings)

Per-sample deltas from cluster baseline:

  • Go 1.20.6 (not 1.18.5 or 1.25.4) — fourth confirmed sibling on this toolchain
  • PE32+ x64 (same as 58eda486, f251271a, 8f454dc1)
  • Module path LEMEXLlSisSswHg — unique, not seen in prior siblings
  • 81 randomized main.* symbols — heavy count, near-record
  • Four-icon .rsrc suite (not five-icon) — builder icon-toggle at reduced setting
  • No custom in-memory PE parser, no multi-pass byte-transform decoder — light build

Decompiled Behavior

Ghidra/r2 entry point (0x45e380) shows standard Go rt0_go bootstrap: CPUID vendor check (GenuineIntel), TLS slot allocation via gs:, runtime·args parse, and runtime·main dispatch. No anti-debug or VM checks in the entry path. ^[r2:entry0]

Notable functions (from strings, not decompiled individually):

  • main.main — user entry
  • main.dslpqshjkre and main.jobecxfjdpodwkj — likely goroutine workers (naming pattern consistent with ACR randomized functions)
  • Heavy runtime.* and syscall.* surface — standard Go static binary

C2 Infrastructure

No static C2 recovered. The binary links crypto/tls, net/http, and math/rand, consistent with the family-wide PRNG-seeded runtime C2 decode pattern documented at prng-seeded-c2-url-decoding. No hardcoded IP, domain, URL, mutex, or named pipe in strings.

Interesting Tidbits

  • Certificate abuse: The embedded PKCS#7 block carries a Domain Validated TLS certificate for seekingalpha.com (a legitimate financial media website), not a code-signing certificate. GlobalSign Atlas R3 DV TLS CA 2025 Q4 is a web-SSL intermediate, not an Authenticode issuer. Windows may still display a green check in some trust-store configurations. This is certificate-type abuse, not stolen-cert abuse. ^[binwalk.txt:9]
  • No overlay: Unlike some packed families, this binary ends cleanly at the security directory — no encrypted payload trailing the PE. ^[terminal]
  • rabin2 flags: signed: true, stripped: true, canary: true, pic: true, overlay: false (r2 interprets security dir as overlay but there is no real overlay). ^[rabin2-info.txt]
  • FLOSS failure: floss.txt shows only argument-parsing errors — the Go runtime string table defeats FLOSS's stack-string heuristics. ^[floss.txt]
  • capa failure: Capa signatures are missing on this host; no capability report generated. ^[capa.txt]

How To Mess With It (Homelab Replication)

Toolchain to reproduce a comparable binary:

# Go 1.20.6 on Windows or cross-compile from Linux
go1.20.6 version
GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" .

Obfuscation layer:

  • Use garble (or custom AST transform) to randomize package and function names
  • Strip .rsrc or embed a PNG icon suite for masquerade
  • Add math/rand seeded decoder for C2 strings at runtime

Verification:

  • rabin2 -I reproducer.exe should show lang: go, compiled: 1970-01-01 (Go null timestamp), stripped: true
  • String count for main.* symbols should be >50 and randomized

Deployable Signatures

YARA

{
    meta:
        description = "Go 1.20.6 x64 infostealer with seekingalpha.com DV TLS cert (ACR cluster, contested remusstealer label)"
        author = "PacketPursuit"
        date = "2026-08-19"
        sha256 = "ea41d4b15a8e270f2113b16f050cb3e15cb5a5c85711fb6ec31dc6bb7279ba42"
    strings:
        $go_build = "go1.20.6" ascii
        $mod_path = "LEMEXLlSisSswHg" ascii
        $cert_subj = "seekingalpha.com" ascii wide
        $build_trim = "build\t-trimpath=true" ascii
        $build_cgo  = "build\tCGO_ENABLED=0" ascii
        $build_arch = "build\tGOARCH=amd64" ascii
    condition:
        uint16(0) == 0x5A4D and
        filesize < 3MB and
        $go_build and
        $cert_subj and
        3 of ($build_*) and
        (pe.number_of_sections == 7 or pe.number_of_sections == 6)
}

Sigma (process creation)

title: ACR Stealer Go 1.20.6 x64 execution
description: Detects execution of Go 1.20.6 signed PE with seekingalpha.com cert chain
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        - Imphash: '00000000000000000000000000000000'
        - CommandLine|contains:
            - '.exe'
    condition: selection
falsepositives:
    - Legitimate Go binaries signed with the same certificate (unlikely)
level: high

IOC list

Type Value Notes
SHA-256 ea41d4b15a8e270f2113b16f050cb3e15cb5a5c85711fb6ec31dc6bb7279ba42 Sample
SHA-1 65ed6355cd6182f9bc8de624a7e3e983bf291f2f .text section
ssdeep 24576:bBQ5ZEqSm3Q7ez7osUY/yVsiGhGDAkKlDJheSgk0H0s2+D1c7is:bBEZbSm3K2X/yVxGAdCDOSgk0g+D1fs triage.json
Certificate Subject CN=seekingalpha.com DV TLS cert, not code-signing
Certificate Issuer CN=GlobalSign Atlas R3 DV TLS CA 2025 Q4 Web-SSL intermediate
Go module path LEMEXLlSisSswHg Unique to this sample
Build ID _oMqNP3wSJk2Uh2mjhqz/rRdLgpk0WxaOulDBpGig/5ffqjBI3md2aOHA0NkeJ/Z0Su0opNm3O1yCa7GJvk Go build ID

Behavioral fingerprint

This binary is a Go 1.20.6 statically-linked PE32+ x64 executable with no CGO, no meaningful IAT, and a null PE timestamp. It carries a GlobalSign DV TLS certificate for seekingalpha.com in its security directory. At runtime it spawns multiple goroutines with randomized names, contacts a C2 server over HTTPS after decoding the URL via a PRNG-seeded transform, and exfiltrates browser credentials and wallet data. The .rsrc section contains 1–5 PNG icons used for social-engineering masquerade.

Detection Signatures

capa / ATT&CK Status
T1041 — Exfiltration Over C2 Channel Inferred (HTTPS client present)
T1055 — Process Injection Not observed
T1071 — Application Layer Protocol Inferred (HTTP/HTTPS)
T1083 — File and Directory Discovery Inferred (browser path walks)
T1552 — Unsecured Credentials Inferred (browser store targeting)
T1567 — Exfiltration Over Web Service Inferred (HTTPS POST)

References

Provenance

  • file.txt — file(1) output
  • pefile.txt — pefile.py structural dump (section table, imports, resources, security dir)
  • strings.txt — strings -n 6 raw output (Go runtime + user symbols)
  • floss.txt — FireEye flare-floss (failed — Go static binary)
  • capa.txt — Mandiant capa (failed — signatures missing on host)
  • binwalk.txt — binwalk embedded-artifact scan
  • rabin2-info.txt — radare2 binary header summary
  • exiftool.json — ExifTool PE metadata
  • triage.json — internal triage pipeline metadata
  • dynamic-analysis.md — CAPE sandbox (skipped — no Windows guest)
  • Decompilation: radare2 MCP (analyze level 2, 1627 functions, entry at 0x45e380)
  • Certificate extraction: Python pefile + openssl pkcs7 parser (terminal)

Analysis completed 2026-08-19.