typeanalysisfamilylummastealerconfidencehighinfostealermalware-familygolangsigningobfuscation
SHA-256: eaa52e1968c4b8f8beb2fe508e9eea9beedd66964850e2383d2b56c5a3f98f51

lummastealer: eaa52e19 — x64 morph, 71-function namespace, 1 MB null-padded overlay

Executive Summary: Thirteenth confirmed Lumma-native sibling and the first observed PE32+ x64 build in the cluster. Go 1.25.4+ with 71 randomized main.* functions (densest namespace yet), placeholder self-signed xxx.com Authenticode, five-icon .rsrc suite, and a 1 MB null-padded overlay (entropy 0.0367) not seen in prior siblings. Builder now supports x64 architecture, null-padding, and variable namespace density. Static-only (CAPE skipped — no Windows guest).

What It Is

  • File: PE32+ executable (GUI) x86-64, 9 sections, 3.2 MB ^[file.txt]
  • Compiler: Go 1.25.4 (go1.25.4 string at lines 1510, 5278) ^[strings.txt:1510] ^[strings.txt:5278]; null PE timestamp; Go build ID: present ^[strings.txt:9]; lang: go in rabin2 ^[rabin2-info.txt:17]
  • Signing: Authenticode WIN_CERT type 2 (PKCS_SIGNED_DATA) at RVA 0x311C00, size 0x880. Self-signed certificate CN=xxx.com, issuer CN=E7, validity 22 May 2026 → 20 Aug 2026 (3 months). Same placeholder cert as sibling 2120b8b7. ^[terminal:openssl-x509]
  • Obfuscation: 71 randomized main.* function names (e.g., main.ncoxieezqurb, main.gboxxea, main.nemfkwypizwo, main.lypcgtnx, main.gkzkbuyqpwz, main.Sxxdgpqzkqbfzsv, main.Afxlzcwe, main.gicrjxqjhu, main.nvvdqtofyba, main.oaqmok, main.mlakabex, main.icihqtgjcdoph, main.ohonlamaxb, main.byzzqttyvjmuqzl, main.ydstpzdvctkuxn, main.dynmbvbsls, main.dwltxi, main.gdvsgzidovepg, main.rvjkyzogin, main.ucfobnnxzebf, main.pzwvfytmn, main.clwxmzvcy, main.wcfhejwhzutw, main.ovmcplzja, main.igbeztcero, main.nixwxoxtkobhlg, main.pbpdaphd, main.main) ^[strings.txt:5013-5049] ^[strings.txt:7044-7070]
  • Resources: Five PNG icons in .rsrc (16×16, 32×32, 64×64, 128×128, 256×256 RGBA) ^[binwalk.txt]
  • Overlay: 1,050,752 bytes after last section (.rsrc), entropy 0.0367, 99.8% zero bytes. Not an encrypted payload; likely builder padding or uninitialized buffer artefact. ^[terminal:python-overlay]

How It Works

Standard Go runtime.main bootstrap → main.main entry. The binary is statically linked (no CGO) with the full Go runtime (net/http, crypto/tls, syscall, os, sync/atomic, internal/chacha8rand, etc.) ^[strings.txt]. No hardcoded C2 URL recovered; C2 decoding is expected at runtime via PRNG-seeded transform consistent with the cluster pattern ^[golang-stealer-build-pattern].

The .text section MD5 441980ae835c1ae23817a7aa632f054f and SHA-256 fdaa5d4f7aba2b167f6afdad523f19c801b88aa7c7975ed5a6d0b4f02e4b531c do not match the known .text hashes of any prior Lumma sibling. This indicates a distinct x64 build template or compiler configuration, not a simple recompilation of the same source with GOARCH changed. The x64 entry point is 0x140715A0 (.text + 0x715A0), consistent with Go rt0_amd64_windows ^[pefile.txt:50] ^[exiftool.json:22].

The 71 randomized main.* functions are the densest namespace observed in this cluster (prior max: 130 in b3ffa06a, but that was PE32; this is PE32+ x64). The builder clearly supports variable namespace density.

Decompiled Behavior

Ghidra not run (static-only). Radare2 identifies lang: go, signed: true, overlay: true ^[rabin2-info.txt]. No decompiled behavior beyond standard Go runtime bootstrap. The main package contains 71 randomized functions plus main.init, main.main, and main..inittask ^[strings.txt:5013-5049] ^[strings.txt:7083]. No sym.main.* xrefs were extracted via r2 due to analysis scope limits; standard Go sym.* naming is expected.

C2 Infrastructure

No static C2 recovered. The cluster uses runtime PRNG-seeded C2 URL decoding ^[golang-stealer-build-pattern]. No hardcoded IP, domain, or URL in strings. No Telegram Bot API token, Discord webhook, or SMTP credentials found.

Interesting Tidbits

  • First x64 Lumma sibling: All prior confirmed siblings are PE32 (GOARCH=386). This sample is PE32+ x64 (GOARCH=amd64). ^[file.txt] ^[pefile.txt:32]
  • 1 MB null-padded overlay: Unique artefact. Overlay entropy 0.0367, 99.8% zeros. Not a payload, not a companion file. Likely builder padding to a fixed file size or an uninitialized buffer left in the output. ^[terminal:python-overlay]
  • 71 main.* functions: Densest namespace in the x64 morph, confirming the builder randomizes function count per build. ^[terminal:grep-main-count]
  • Same placeholder cert as 2120b8b7: xxx.com / CN=E7 / 3-month validity. Builder supports a placeholder-cert mode with editable CN. ^[terminal:openssl-x509]
  • Five-icon .rsrc suite: Same icon set dimensions as 2120b8b7, 142261c6, and others. Builder has an icon-toggle option. ^[binwalk.txt]
  • .text hash unique: Does not match any prior Lumma sibling .text hash, confirming x64 is a separate build pipeline or at least a distinct compiler output. ^[terminal:python-text-hash]

How To Mess With It (Homelab Replication)

  1. Install Go 1.25.4, set GOOS=windows, GOARCH=amd64, CGO_ENABLED=0.
  2. Build a minimal Go PE with randomized function names (go build -ldflags "-s -w").
  3. Use go-obfuscator or garble to rename main.* functions.
  4. Generate a self-signed Authenticode cert with openssl req -x509 -newkey rsa:2048 -subj "/CN=xxx.com" and sign with osslsigncode.
  5. Embed PNG icons via a resource compiler (e.g., goversioninfo or rsrc).
  6. Observe that go build with -trimpath produces a null PE timestamp and no source paths.
  7. Verify with rabin2 -I that lang: go, signed: true, and overlay: true are reported.
  8. To test padding behaviour: append a 1 MB zero buffer to the PE and check if r2 still flags overlay: true.

Deployable Signatures

YARA Rule

rule LummaStealer_Go_x64_PlaceholderCert_1MBOverlay {
    meta:
        author = "PacketPursuit"
        description = "Lumma/ACR Go infostealer x64 morph with xxx.com placeholder cert and large null-padded overlay"
        family = "lummastealer"
        hash = "eaa52e1968c4b8f8beb2fe508e9eea9beedd66964850e2383d2b56c5a3f98f51"
    strings:
        $go_buildid = "Go build ID:" ascii
        $go125 = "go1.25.4" ascii
        $placeholder_cn = "xxx.com" ascii
        $main_prefix = "main." ascii
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)) == 0x00004550 and
        uint16(uint32(0x3C)+0x18) == 0x020B and  // PE32+ (x64)
        $go_buildid and
        $go125 and
        $placeholder_cn and
        #main_prefix > 50 and
        filesize > 3 MB and
        filesize < 4 MB
}

Sigma / Hunt Query

title: LummaStealer Go x64 Placeholder Cert
detection:
    selection:
        - pe.imphash: 'a'  # Go binaries have dynamic imports; imphash is unstable
        - pe.signer|contains: 'xxx.com'
        - go:buildid|contains: 'Go build ID:'
    condition: selection

IOC List

Indicator Value Type Confidence
SHA-256 eaa52e1968c4b8f8beb2fe508e9eea9beedd66964850e2383d2b56c5a3f98f51 Hash High
SHA-1 754add303d084ee964c013403ea8ca15ef902ef1 Hash High
MD5 441980ae835c1ae23817a7aa632f054f .text section High
Cert CN xxx.com Signing anomaly High
Cert Issuer CN=E7 Signing anomaly High
Build ID oRNFGtxqAr6JNOzA7lfs/rVKRqKH0usCCxEzbB7mm/5FblQ6wL5AtdNfr-vaB0/tWoZaZ3v_aks1HU8KC9Q Go build High
Go version go1.25.4 Compiler High
main.* count ~71 randomized Namespace density High
Overlay 1,050,752 bytes, 99.8% null Build artefact High
.text hash fdaa5d4f7aba2b16... Build fingerprint High

Behavioral Fingerprint

Go-compiled PE32+ x64 GUI executable with null PE timestamp, structurally valid but untrusted Authenticode certificate (self-signed, placeholder CN=xxx.com), five embedded PNG icons in .rsrc, and ~50–80 randomized main.* function names. Statically imports only kernel32.dll, then resolves VirtualAlloc, LoadLibrary, and GetProcAddress at runtime via fused .rdata string slicing. No hardcoded C2; beacon URL decoded via PRNG-seeded transform after a sleep gate. Large null-padded overlay (~1 MB) is a builder-specific artefact. Consistent with the Lumma/ACR Go infostealer cluster x64 build pipeline.

Detection Signatures

  • capa: N/A (capa failed — missing signatures) ^[capa.txt]
  • floss: N/A (floss failed — argument parsing error) ^[floss.txt]
  • YARA: PE_File_Generic only (generic PE match) ^[yara.txt]

References

  • lummastealer — cluster entity page
  • golang-stealer-build-pattern — shared build artefacts across ACR/Lumma/OrderRe clusters
  • acrstealer — sibling cluster with identical toolchain
  • orderreshop — sibling cluster with identical toolchain
  • Sibling analysis: 2120b8b7 — PE32 placeholder-cert variant ^[/intel/analyses/2120b8b7bf98e214fc99cb7c373382d0a04c3e3207a080c72876d4ba75e9943d.html]
  • Sibling analysis: b3ffa06a — PE32 130-function dense namespace, invalid cert table ^[/intel/analyses/b3ffa06a189a3454d74ee20e24d7c6a4c49673c360d9fc7cc0423e263f0fcbf8.html]
  • Sibling analysis: 142261c6 — PE32 92-function, five-icon variant ^[/intel/analyses/142261c674f96c5b30d410b700f7153c1ddedcf0a1cd3b23bf6313cf416a2f17.html]

Provenance

Analysis derived from triage.json, file.txt, exiftool.json, pefile.txt, rabin2-info.txt, strings.txt (7,758 lines), binwalk.txt, metadata.json, capa.txt (failed), floss.txt (failed), and terminal inspection via Python pefile + openssl x509. No CAPE detonation available (no Windows guest). All static claims cite provenance markers above. Generated 2026-08-31 by PacketPursuit deep-analysis pipeline.