eaa52e1968c4b8f8beb2fe508e9eea9beedd66964850e2383d2b56c5a3f98f51lummastealer: eaa52e19 — x64 morph, 71-function namespace, 1 MB null-padded overlay
Executive Summary: Thirteenth confirmed Lumma-native sibling and the first observed PE32+ x64 build in the cluster. Go 1.25.4+ with 71 randomized main.* functions (densest namespace yet), placeholder self-signed xxx.com Authenticode, five-icon .rsrc suite, and a 1 MB null-padded overlay (entropy 0.0367) not seen in prior siblings. Builder now supports x64 architecture, null-padding, and variable namespace density. Static-only (CAPE skipped — no Windows guest).
What It Is
- File: PE32+ executable (GUI) x86-64, 9 sections, 3.2 MB ^[file.txt]
- Compiler: Go 1.25.4 (
go1.25.4string at lines 1510, 5278) ^[strings.txt:1510] ^[strings.txt:5278]; null PE timestamp;Go build ID:present ^[strings.txt:9];lang: goin rabin2 ^[rabin2-info.txt:17] - Signing: Authenticode WIN_CERT type 2 (PKCS_SIGNED_DATA) at RVA 0x311C00, size 0x880. Self-signed certificate CN=
xxx.com, issuerCN=E7, validity 22 May 2026 → 20 Aug 2026 (3 months). Same placeholder cert as sibling2120b8b7. ^[terminal:openssl-x509] - Obfuscation: 71 randomized
main.*function names (e.g.,main.ncoxieezqurb,main.gboxxea,main.nemfkwypizwo,main.lypcgtnx,main.gkzkbuyqpwz,main.Sxxdgpqzkqbfzsv,main.Afxlzcwe,main.gicrjxqjhu,main.nvvdqtofyba,main.oaqmok,main.mlakabex,main.icihqtgjcdoph,main.ohonlamaxb,main.byzzqttyvjmuqzl,main.ydstpzdvctkuxn,main.dynmbvbsls,main.dwltxi,main.gdvsgzidovepg,main.rvjkyzogin,main.ucfobnnxzebf,main.pzwvfytmn,main.clwxmzvcy,main.wcfhejwhzutw,main.ovmcplzja,main.igbeztcero,main.nixwxoxtkobhlg,main.pbpdaphd,main.main) ^[strings.txt:5013-5049] ^[strings.txt:7044-7070] - Resources: Five PNG icons in
.rsrc(16×16, 32×32, 64×64, 128×128, 256×256 RGBA) ^[binwalk.txt] - Overlay: 1,050,752 bytes after last section (
.rsrc), entropy 0.0367, 99.8% zero bytes. Not an encrypted payload; likely builder padding or uninitialized buffer artefact. ^[terminal:python-overlay]
How It Works
Standard Go runtime.main bootstrap → main.main entry. The binary is statically linked (no CGO) with the full Go runtime (net/http, crypto/tls, syscall, os, sync/atomic, internal/chacha8rand, etc.) ^[strings.txt]. No hardcoded C2 URL recovered; C2 decoding is expected at runtime via PRNG-seeded transform consistent with the cluster pattern ^[golang-stealer-build-pattern].
The .text section MD5 441980ae835c1ae23817a7aa632f054f and SHA-256 fdaa5d4f7aba2b167f6afdad523f19c801b88aa7c7975ed5a6d0b4f02e4b531c do not match the known .text hashes of any prior Lumma sibling. This indicates a distinct x64 build template or compiler configuration, not a simple recompilation of the same source with GOARCH changed. The x64 entry point is 0x140715A0 (.text + 0x715A0), consistent with Go rt0_amd64_windows ^[pefile.txt:50] ^[exiftool.json:22].
The 71 randomized main.* functions are the densest namespace observed in this cluster (prior max: 130 in b3ffa06a, but that was PE32; this is PE32+ x64). The builder clearly supports variable namespace density.
Decompiled Behavior
Ghidra not run (static-only). Radare2 identifies lang: go, signed: true, overlay: true ^[rabin2-info.txt]. No decompiled behavior beyond standard Go runtime bootstrap. The main package contains 71 randomized functions plus main.init, main.main, and main..inittask ^[strings.txt:5013-5049] ^[strings.txt:7083]. No sym.main.* xrefs were extracted via r2 due to analysis scope limits; standard Go sym.* naming is expected.
C2 Infrastructure
No static C2 recovered. The cluster uses runtime PRNG-seeded C2 URL decoding ^[golang-stealer-build-pattern]. No hardcoded IP, domain, or URL in strings. No Telegram Bot API token, Discord webhook, or SMTP credentials found.
Interesting Tidbits
- First x64 Lumma sibling: All prior confirmed siblings are PE32 (
GOARCH=386). This sample is PE32+ x64 (GOARCH=amd64). ^[file.txt] ^[pefile.txt:32] - 1 MB null-padded overlay: Unique artefact. Overlay entropy 0.0367, 99.8% zeros. Not a payload, not a companion file. Likely builder padding to a fixed file size or an uninitialized buffer left in the output. ^[terminal:python-overlay]
- 71
main.*functions: Densest namespace in the x64 morph, confirming the builder randomizes function count per build. ^[terminal:grep-main-count] - Same placeholder cert as 2120b8b7:
xxx.com/CN=E7/ 3-month validity. Builder supports a placeholder-cert mode with editable CN. ^[terminal:openssl-x509] - Five-icon
.rsrcsuite: Same icon set dimensions as2120b8b7,142261c6, and others. Builder has an icon-toggle option. ^[binwalk.txt] .texthash unique: Does not match any prior Lumma sibling.texthash, confirming x64 is a separate build pipeline or at least a distinct compiler output. ^[terminal:python-text-hash]
How To Mess With It (Homelab Replication)
- Install Go 1.25.4, set
GOOS=windows,GOARCH=amd64,CGO_ENABLED=0. - Build a minimal Go PE with randomized function names (
go build -ldflags "-s -w"). - Use
go-obfuscatororgarbleto renamemain.*functions. - Generate a self-signed Authenticode cert with
openssl req -x509 -newkey rsa:2048 -subj "/CN=xxx.com"and sign withosslsigncode. - Embed PNG icons via a resource compiler (e.g.,
goversioninfoorrsrc). - Observe that
go buildwith-trimpathproduces a null PE timestamp and no source paths. - Verify with
rabin2 -Ithatlang: go,signed: true, andoverlay: trueare reported. - To test padding behaviour: append a 1 MB zero buffer to the PE and check if r2 still flags
overlay: true.
Deployable Signatures
YARA Rule
rule LummaStealer_Go_x64_PlaceholderCert_1MBOverlay {
meta:
author = "PacketPursuit"
description = "Lumma/ACR Go infostealer x64 morph with xxx.com placeholder cert and large null-padded overlay"
family = "lummastealer"
hash = "eaa52e1968c4b8f8beb2fe508e9eea9beedd66964850e2383d2b56c5a3f98f51"
strings:
$go_buildid = "Go build ID:" ascii
$go125 = "go1.25.4" ascii
$placeholder_cn = "xxx.com" ascii
$main_prefix = "main." ascii
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C)) == 0x00004550 and
uint16(uint32(0x3C)+0x18) == 0x020B and // PE32+ (x64)
$go_buildid and
$go125 and
$placeholder_cn and
#main_prefix > 50 and
filesize > 3 MB and
filesize < 4 MB
}
Sigma / Hunt Query
title: LummaStealer Go x64 Placeholder Cert
detection:
selection:
- pe.imphash: 'a' # Go binaries have dynamic imports; imphash is unstable
- pe.signer|contains: 'xxx.com'
- go:buildid|contains: 'Go build ID:'
condition: selection
IOC List
| Indicator | Value | Type | Confidence |
|---|---|---|---|
| SHA-256 | eaa52e1968c4b8f8beb2fe508e9eea9beedd66964850e2383d2b56c5a3f98f51 |
Hash | High |
| SHA-1 | 754add303d084ee964c013403ea8ca15ef902ef1 |
Hash | High |
| MD5 | 441980ae835c1ae23817a7aa632f054f |
.text section | High |
| Cert CN | xxx.com |
Signing anomaly | High |
| Cert Issuer | CN=E7 |
Signing anomaly | High |
| Build ID | oRNFGtxqAr6JNOzA7lfs/rVKRqKH0usCCxEzbB7mm/5FblQ6wL5AtdNfr-vaB0/tWoZaZ3v_aks1HU8KC9Q |
Go build | High |
| Go version | go1.25.4 |
Compiler | High |
main.* count |
~71 randomized | Namespace density | High |
| Overlay | 1,050,752 bytes, 99.8% null | Build artefact | High |
| .text hash | fdaa5d4f7aba2b16... |
Build fingerprint | High |
Behavioral Fingerprint
Go-compiled PE32+ x64 GUI executable with null PE timestamp, structurally valid but untrusted Authenticode certificate (self-signed, placeholder CN=xxx.com), five embedded PNG icons in .rsrc, and ~50–80 randomized main.* function names. Statically imports only kernel32.dll, then resolves VirtualAlloc, LoadLibrary, and GetProcAddress at runtime via fused .rdata string slicing. No hardcoded C2; beacon URL decoded via PRNG-seeded transform after a sleep gate. Large null-padded overlay (~1 MB) is a builder-specific artefact. Consistent with the Lumma/ACR Go infostealer cluster x64 build pipeline.
Detection Signatures
- capa: N/A (capa failed — missing signatures) ^[capa.txt]
- floss: N/A (floss failed — argument parsing error) ^[floss.txt]
- YARA:
PE_File_Genericonly (generic PE match) ^[yara.txt]
References
- lummastealer — cluster entity page
- golang-stealer-build-pattern — shared build artefacts across ACR/Lumma/OrderRe clusters
- acrstealer — sibling cluster with identical toolchain
- orderreshop — sibling cluster with identical toolchain
- Sibling analysis:
2120b8b7— PE32 placeholder-cert variant ^[/intel/analyses/2120b8b7bf98e214fc99cb7c373382d0a04c3e3207a080c72876d4ba75e9943d.html] - Sibling analysis:
b3ffa06a— PE32 130-function dense namespace, invalid cert table ^[/intel/analyses/b3ffa06a189a3454d74ee20e24d7c6a4c49673c360d9fc7cc0423e263f0fcbf8.html] - Sibling analysis:
142261c6— PE32 92-function, five-icon variant ^[/intel/analyses/142261c674f96c5b30d410b700f7153c1ddedcf0a1cd3b23bf6313cf416a2f17.html]
Provenance
Analysis derived from triage.json, file.txt, exiftool.json, pefile.txt, rabin2-info.txt, strings.txt (7,758 lines), binwalk.txt, metadata.json, capa.txt (failed), floss.txt (failed), and terminal inspection via Python pefile + openssl x509. No CAPE detonation available (no Windows guest). All static claims cite provenance markers above. Generated 2026-08-31 by PacketPursuit deep-analysis pipeline.