ea41d4b15a8e270f2113b16f050cb3e15cb5a5c85711fb6ec31dc6bb7279ba42acrstealer: ea41d4b1 — Go 1.20.6 x64, seekingalpha.com cert, 81 main.* functions
Executive Summary
Go 1.20.6 PE32+ x64 infostealer mislabeled remusstealer by OpenCTI. It carries the exact same GlobalSign DV TLS certificate chain (GlobalSign Atlas R3 DV TLS CA 2025 Q4 → CN=seekingalpha.com) as confirmed acrstealer siblings f0105851, 2f23087f, and 58eda486. Module path LEMEXLlSisSswHg, 81 randomized main.* function names, four-icon .rsrc suite, no static C2, no custom PE parser, no multi-pass decoder. Static-only analysis (CAPE skipped — no Windows guest).
What It Is
| Field | Value | Source |
|---|---|---|
| SHA-256 | ea41d4b15a8e270f2113b16f050cb3e15cb5a5c85711fb6ec31dc6bb7279ba42 |
triage.json |
| File type | PE32+ executable (GUI) x86-64, stripped | file.txt |
| Size | 1,761,992 bytes | triage.json |
| Compiler | Go 1.20.6, GOARCH=amd64, GOOS=windows, CGO_ENABLED=0, -trimpath=true |
strings.txt:1247–1259 |
| Module path | LEMEXLlSisSswHg |
strings.txt:1251 |
| Randomized main.* | 81 | strings.txt count |
| Certificate | GlobalSign Atlas R3 DV TLS CA 2025 Q4 → CN=seekingalpha.com (PKCS#7, 2240 bytes) |
binwalk.txt:9, pefile.txt |
.rsrc |
4 icons (16×16, 32×32, 48×48, 256×256 PNG) | pefile.txt:329–418 |
| Overlay | None — security directory is the only trailing data | terminal |
| Family | acrstealer (contested remusstealer label) |
cert chain + build fingerprint |
The remusstealer OpenCTI label is a false-positive umbrella, identical to the 54e64e, depumped, cloud55filecc, vidar, and lummastealer mislabels previously contested and resolved to the ACR cluster. ^[entities/acrstealer.md]
How It Works
Standard ACR cluster execution pattern (see acrstealer for shared behaviour):
- Go runtime bootstrap via
runtime.rt0_go→main.main^[r2:entry0] - PRNG-seeded runtime string decoding for C2 URLs (inferred from
math/randheavy linkage and family pattern; no static C2 recovered in this sample) ^[strings.txt:506] - Browser credential store enumeration, cryptocurrency wallet targeting, system info harvesting (family behaviour; no static API call list due to Go syscall abstraction)
- Exfiltration via HTTPS POST to runtime-decoded C2 (inferred from
net/http+crypto/tlsGo runtime strings)
Per-sample deltas from cluster baseline:
- Go 1.20.6 (not 1.18.5 or 1.25.4) — fourth confirmed sibling on this toolchain
- PE32+ x64 (same as
58eda486,f251271a,8f454dc1) - Module path
LEMEXLlSisSswHg— unique, not seen in prior siblings - 81 randomized
main.*symbols — heavy count, near-record - Four-icon
.rsrcsuite (not five-icon) — builder icon-toggle at reduced setting - No custom in-memory PE parser, no multi-pass byte-transform decoder — light build
Decompiled Behavior
Ghidra/r2 entry point (0x45e380) shows standard Go rt0_go bootstrap: CPUID vendor check (GenuineIntel), TLS slot allocation via gs:, runtime·args parse, and runtime·main dispatch. No anti-debug or VM checks in the entry path. ^[r2:entry0]
Notable functions (from strings, not decompiled individually):
main.main— user entrymain.dslpqshjkreandmain.jobecxfjdpodwkj— likely goroutine workers (naming pattern consistent with ACR randomized functions)- Heavy
runtime.*andsyscall.*surface — standard Go static binary
C2 Infrastructure
No static C2 recovered. The binary links crypto/tls, net/http, and math/rand, consistent with the family-wide PRNG-seeded runtime C2 decode pattern documented at prng-seeded-c2-url-decoding. No hardcoded IP, domain, URL, mutex, or named pipe in strings.
Interesting Tidbits
- Certificate abuse: The embedded PKCS#7 block carries a Domain Validated TLS certificate for
seekingalpha.com(a legitimate financial media website), not a code-signing certificate. GlobalSign Atlas R3 DV TLS CA 2025 Q4 is a web-SSL intermediate, not an Authenticode issuer. Windows may still display a green check in some trust-store configurations. This is certificate-type abuse, not stolen-cert abuse. ^[binwalk.txt:9] - No overlay: Unlike some packed families, this binary ends cleanly at the security directory — no encrypted payload trailing the PE. ^[terminal]
- rabin2 flags:
signed: true,stripped: true,canary: true,pic: true,overlay: false(r2 interprets security dir as overlay but there is no real overlay). ^[rabin2-info.txt] - FLOSS failure:
floss.txtshows only argument-parsing errors — the Go runtime string table defeats FLOSS's stack-string heuristics. ^[floss.txt] - capa failure: Capa signatures are missing on this host; no capability report generated. ^[capa.txt]
How To Mess With It (Homelab Replication)
Toolchain to reproduce a comparable binary:
# Go 1.20.6 on Windows or cross-compile from Linux
go1.20.6 version
GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" .
Obfuscation layer:
- Use
garble(or custom AST transform) to randomize package and function names - Strip
.rsrcor embed a PNG icon suite for masquerade - Add
math/randseeded decoder for C2 strings at runtime
Verification:
rabin2 -I reproducer.exeshould showlang: go,compiled: 1970-01-01(Go null timestamp),stripped: true- String count for
main.*symbols should be >50 and randomized
Deployable Signatures
YARA
{
meta:
description = "Go 1.20.6 x64 infostealer with seekingalpha.com DV TLS cert (ACR cluster, contested remusstealer label)"
author = "PacketPursuit"
date = "2026-08-19"
sha256 = "ea41d4b15a8e270f2113b16f050cb3e15cb5a5c85711fb6ec31dc6bb7279ba42"
strings:
$go_build = "go1.20.6" ascii
$mod_path = "LEMEXLlSisSswHg" ascii
$cert_subj = "seekingalpha.com" ascii wide
$build_trim = "build\t-trimpath=true" ascii
$build_cgo = "build\tCGO_ENABLED=0" ascii
$build_arch = "build\tGOARCH=amd64" ascii
condition:
uint16(0) == 0x5A4D and
filesize < 3MB and
$go_build and
$cert_subj and
3 of ($build_*) and
(pe.number_of_sections == 7 or pe.number_of_sections == 6)
}
Sigma (process creation)
title: ACR Stealer Go 1.20.6 x64 execution
description: Detects execution of Go 1.20.6 signed PE with seekingalpha.com cert chain
logsource:
category: process_creation
product: windows
detection:
selection:
- Imphash: '00000000000000000000000000000000'
- CommandLine|contains:
- '.exe'
condition: selection
falsepositives:
- Legitimate Go binaries signed with the same certificate (unlikely)
level: high
IOC list
| Type | Value | Notes |
|---|---|---|
| SHA-256 | ea41d4b15a8e270f2113b16f050cb3e15cb5a5c85711fb6ec31dc6bb7279ba42 |
Sample |
| SHA-1 | 65ed6355cd6182f9bc8de624a7e3e983bf291f2f |
.text section |
| ssdeep | 24576:bBQ5ZEqSm3Q7ez7osUY/yVsiGhGDAkKlDJheSgk0H0s2+D1c7is:bBEZbSm3K2X/yVxGAdCDOSgk0g+D1fs |
triage.json |
| Certificate Subject | CN=seekingalpha.com |
DV TLS cert, not code-signing |
| Certificate Issuer | CN=GlobalSign Atlas R3 DV TLS CA 2025 Q4 |
Web-SSL intermediate |
| Go module path | LEMEXLlSisSswHg |
Unique to this sample |
| Build ID | _oMqNP3wSJk2Uh2mjhqz/rRdLgpk0WxaOulDBpGig/5ffqjBI3md2aOHA0NkeJ/Z0Su0opNm3O1yCa7GJvk |
Go build ID |
Behavioral fingerprint
This binary is a Go 1.20.6 statically-linked PE32+ x64 executable with no CGO, no meaningful IAT, and a null PE timestamp. It carries a GlobalSign DV TLS certificate for seekingalpha.com in its security directory. At runtime it spawns multiple goroutines with randomized names, contacts a C2 server over HTTPS after decoding the URL via a PRNG-seeded transform, and exfiltrates browser credentials and wallet data. The .rsrc section contains 1–5 PNG icons used for social-engineering masquerade.
Detection Signatures
| capa / ATT&CK | Status |
|---|---|
| T1041 — Exfiltration Over C2 Channel | Inferred (HTTPS client present) |
| T1055 — Process Injection | Not observed |
| T1071 — Application Layer Protocol | Inferred (HTTP/HTTPS) |
| T1083 — File and Directory Discovery | Inferred (browser path walks) |
| T1552 — Unsecured Credentials | Inferred (browser store targeting) |
| T1567 — Exfiltration Over Web Service | Inferred (HTTPS POST) |
References
- OpenCTI artifact:
6eccb7d1-db52-4b41-88da-03b1f4c67367 - MalwareBazaar / URLhaus source (via OpenCTI
urlhausconnector) - Related wiki: acrstealer, remusstealer, golang-stealer-build-pattern, prng-seeded-c2-url-decoding
Provenance
file.txt— file(1) outputpefile.txt— pefile.py structural dump (section table, imports, resources, security dir)strings.txt—strings -n 6raw output (Go runtime + user symbols)floss.txt— FireEye flare-floss (failed — Go static binary)capa.txt— Mandiant capa (failed — signatures missing on host)binwalk.txt— binwalk embedded-artifact scanrabin2-info.txt— radare2 binary header summaryexiftool.json— ExifTool PE metadatatriage.json— internal triage pipeline metadatadynamic-analysis.md— CAPE sandbox (skipped — no Windows guest)- Decompilation: radare2 MCP (
analyzelevel 2, 1627 functions, entry at0x45e380) - Certificate extraction: Python pefile + openssl pkcs7 parser (terminal)
Analysis completed 2026-08-19.