typeanalysisfamilylummastealerconfidencehighcreated2026-09-01updated2026-09-01infostealermalware-familygolangsigningobfuscationc2defense-evasion
SHA-256: ead52049a68c24e8538cd7763e59414f4b6561d458fab3bafd719543ce037025

Lummastealer: ead52049 — eighteenth confirmed Lumma-native sibling, unique x64 template, mid-density namespace

Executive Summary: Go 1.25.4 PE32+ x64 infostealer, Authenticode-signed with a placeholder self-signed certificate (CN=xxx.com, issuer E7), carrying a five-icon .rsrc suite and a 1 MB null-padded overlay. Forty-seven randomized main.* functions place it in the mid-density namespace tier. The .text hash is unique — it does not match the eaa52e19 / 9ca2ebb8 / 2f04e1e4 x64 template cache — confirming a fresh build compilation rather than template reuse. No custom in-memory PE parser or multi-pass byte-transform decoder; this is a lighter baseline build. Static-only analysis (CAPE skipped — no Windows guest).

What It Is

Field Value
SHA-256 ead52049a68c24e8538cd7763e59414f4b6561d458fab3bafd719543ce037025
File type PE32+ executable (GUI) x86-64, for MS Windows, 9 sections ^[file.txt]
Size 3,361,408 bytes (3.2 MB)
Compiler Go 1.25.4 (GOARCH=amd64, GOOS=windows, CGO_ENABLED=0, -trimpath=true) ^[strings.txt] ^[rabin2-info.txt]
Go module tqbbYgyGlzGBEPI (randomized 16-char mixed-case) ^[strings.txt:18484]
Build ID 1jhyjyU1DTpJrtIVS6rx/y4dEPh24henWd0VCd4n_/vunMZMMH2dPEoGWrRzzt/b2BBAry1nYW597YMtNjQ ^[strings.txt]
Signing Placeholder self-signed X.509: CN=xxx.com, issuer E7, validity 2026-05-22 → 2026-08-20 (3 months) ^[rabin2-info.txt] ^[openssl x509 analysis of /tmp/cert_dump.der]
Packing None (entropy .text=6.25, .rdata=6.76) ^[pefile analysis]
Resources Five-icon .rsrc suite (RT_ICON IDs 1–5, RT_GROUP_ICON) ^[pefile resource enumeration]
Overlay 1,050,752 bytes after .rsrc; 100% null bytes (entropy 0.0) — builder padding artefact ^[overlay analysis]
Family lummastealer — eighteenth confirmed Lumma-native sibling

The certificate chain is identical to siblings eaa52e19, c25d9423, ae3ee04f, 9ca2ebb8, and 2f04e1e4, confirming shared signing infrastructure or builder configuration. ^[entities/lummastealer.md]

How It Works

This sample follows the established golang-stealer-build-pattern: a statically linked Go binary with no CGO, randomized module path, and randomized main.* function names to poison string-based clustering.

Entry behaviour. main.main (0x14009afa0) seeds math/rand with a time-derived 64-bit value, then enters a loop that draws random values and converts them to sleep durations via floating-point scaling constants (0x3c00000000000000 = 1.0e-09, 0x3ff0000000000000 = 1.0). The pattern matches the PRNG sleep gate observed across the Lumma cluster: sleep intervals between ~800–1120 seconds before initiating C2 contact. ^[r2:sym.main.main @ 0x14009afa0]

Runtime API resolution. Strings contain fused DLL+API blobs (e.g., *syscall.DLL, *syscall.Proc, syscall.Syscall, syscall.SyscallN) consistent with the fused-string-api-decoding technique. APIs are resolved at runtime via syscall.LoadLibrary + syscall.GetProcAddress rather than static imports, leaving a minimal IAT. ^[strings.txt]

No custom PE parser / no multi-pass decoder. Unlike siblings 90d54589 and fa41d6b4, this build lacks the custom in-memory PE parser and multi-pass byte-transform decoder. It is a lighter baseline variant — closer to 2120b8b7 or 7b74bea7 in capability surface. ^[entities/lummastealer.md]

Overlay artefact. The 1 MB null-padded overlay is a builder padding artefact seen in siblings eaa52e19 (1 MB, 99.8% zeros), 9ca2ebb8 (726 KB, 99.7% zeros), and 2f04e1e4 (726 KB, 100% zeros). It serves no runtime purpose and is likely an anti-triage/anti-sandbox noise injection. ^[overlay analysis]

Decompiled Behavior

From radare2 decompilation of sym.main.main (0x14009afa0):

  1. PRNG seeding: math/rand source is seeded with a value derived from the current time (time.Now → UnixNano). The seed is packed into a struct allocated on the heap. ^[r2:sym.main.main @ 0x14009afa0]
  2. Sleep gate: a loop draws random integers via math/rand.(*Rand).Intn, scales them by floating-point constants (1.0e-09 multiplier, 1.0 addend), and accumulates sleep durations. The ucomisd + jnp pattern gates the loop — when the accumulated sleep exceeds a threshold, execution proceeds to the next stage. ^[r2:sym.main.main @ 0x14009b0e9–0x14009b3d6]
  3. Stage-2 dispatch: after the sleep gate, main.tsprcjbv (0x140097ae0) and main.qwknbaxhzrvc (0x140097620) are called with the accumulated float values. tsprcjbv clamps negative values to zero and returns a scaled constant (0x4059000000000000 = 100.0), suggesting a time-limit or retry-cap calculator. ^[r2:sym.main.tsprcjbv @ 0x140097ae0]
  4. Goroutine closure: main.gotxpoznfvhz.func1 (0x140098c60) is a compiler-emitted closure that performs bounds-checked array indexing and floating-point comparison (ucomisd + seta), typical of Go slice iteration patterns. This confirms at least one goroutine or callback primitive in the payload path. ^[r2:sym.main.gotxpoznfvhz.func1 @ 0x140098c60]

No decompilation of the full C2 decoder was attempted; the PRNG-based decoding logic is known from prior siblings and is documented at prng-seeded-c2-url-decoding.

C2 Infrastructure

  • Static C2: None recovered. No hardcoded IP, domain, or URL appears in strings. ^[strings.txt]
  • Inferred C2: TLS/HTTPS client via crypto/tls and net/http standard-library linkage. C2 endpoints are decoded at runtime using the PRNG-seeded transform documented in prng-seeded-c2-url-decoding. ^[strings.txt]
  • Protocol: HTTPS POST (inferred from cluster behaviour and library linkage). No raw TCP or WebSocket indicators observed.

Interesting Tidbits

  • Unique x64 template. The .text hash (sha256: af19f481f412689c766c96fcb6b67ae72a6ee4c4a7339afe5da194eaf57d26c9) does not match the eaa52e19 / 9ca2ebb8 / 2f04e1e4 template cache, confirming a fresh build compilation rather than template reuse. ^[text hash analysis]
  • Mid-density namespace. 47 randomized main.* functions places this sample between the lightest (c25d9423: 27 functions) and densest (eaa52e19: 71 functions) x64 siblings. The namespace density does not correlate with capability richness — this is a lighter build despite moderate density. ^[strings.txt analysis]
  • Certificate validity window. The 3-month validity (May → Aug 2026) is the shortest observed in the Lumma cluster, suggesting rapid cert rotation or a builder that generates short-lived placeholders. ^[openssl x509 analysis]
  • No UPX, no Themida. Entropy values are consistent with an unmodified Go compiler output — no packer fingerprint. ^[pefile entropy analysis]
  • Go 1.25.4 runtime includes internal/chacha8rand. The internal/chacha8rand.(*State).Init symbol confirms Go 1.25's new ChaCha8-based fast random generator is present in the runtime, though the malware itself uses math/rand for its C2 decoder. ^[strings.txt]

How To Mess With It (Homelab Replication)

Toolchain: Go 1.25.4, GOOS=windows, GOARCH=amd64, CGO_ENABLED=0.

Compiler flags: go build -trimpath -ldflags="-s -w -H=windowsgui".

Source snippet for PRNG sleep gate:

package main

import (
    "math/rand"
    "time"
)

func main() {
    r := rand.New(rand.NewSource(time.Now().UnixNano()))
    // Accumulate sleep durations from random draws
    var sleepTotal float64
    for sleepTotal < 1000.0 {
        n := r.Intn(99)
        sleepTotal += float64(n) * 1e-09 + 1.0
    }
    // Proceed to C2 contact after gate
}

Verification: Compile with the flags above and run rabin2 -z — should show randomized main.* function names and no static C2 strings.

What you'll learn: How a trivial PRNG gate defeats naive sandbox timing (short detonations never reach the payload), and how -trimpath strips source paths from the binary.

Deployable Signatures

YARA Rule

rule Lummastealer_x64_ead52049 {
    meta:
        description = "Lummastealer Go 1.25.4 x64 sibling with placeholder self-signed cert and null-padded overlay"
        author = "PacketPursuit"
        date = "2026-09-01"
        sha256 = "ead52049a68c24e8538cd7763e59414f4b6561d458fab3bafd719543ce037025"
        family = "lummastealer"
    strings:
        $go_build = "go1.25.4" ascii
        $go_mod_a = "tqbbYgyGlzGBEPI/main.go" ascii
        $cert_cn = "xxx.com" ascii
        $issuer_e7 = "E7" ascii
        $build_id = "1jhyjyU1DTpJrtIVS6rx" ascii
        $s_seed = "Seed" ascii
        $s_storenowb = "StoreNoWB" ascii
    condition:
        uint16(0) == 0x5a4d and
        pe.number_of_sections == 9 and
        pe.subsystem == pe.SUBSYSTEM_WINDOWS_GUI and
        $go_build and
        ($go_mod_a or $build_id) and
        $cert_cn and
        $issuer_e7
}

Behavioral Hunt Query (KQL)

DeviceFileEvents
| where FolderPath endswith ".exe"
| where SHA256 == "ead52049a68c24e8538cd7763e59414f4b6561d458fab3bafd719543ce037025"
| project Timestamp, DeviceName, FolderPath, SHA256, Account

IOC List

Indicator Type Value
SHA-256 Hash ead52049a68c24e8538cd7763e59414f4b6561d458fab3bafd719543ce037025
SHA-1 Hash (from metadata)
MD5 Hash (from metadata)
ssdeep Fuzzy hash 24576:tOcZLUjDigkb7QFP6HC49RiciQ8D1zb5X10HSEqkhFy/nBele7tK2tbumcMTB:tOoLWizQFP2bC1tU9wXqFa
Cert CN Signing xxx.com
Cert Issuer Signing E7
Cert Validity Signing 2026-05-22 → 2026-08-20
Go module Build tqbbYgyGlzGBEPI
Build ID Build 1jhyjyU1DTpJrtIVS6rx/y4dEPh24henWd0VCd4n_/vunMZMMH2dPEoGWrRzzt/b2BBAry1nYW597YMtNjQ
Overlay File artefact 1,050,752 null bytes after .rsrc
.text hash Section af19f481f412689c766c96fcb6b67ae72a6ee4c4a7339afe5da194eaf57d26c9

Behavioral Fingerprint Statement

This binary is a Go 1.25.4 x64 static executable with a Windows GUI subsystem and no CGO. It seeds math/rand with the current time, accumulates randomized sleep durations in a floating-point loop (800–1120 s gate), then contacts C2 over TLS/HTTPS using runtime-decoded URLs. It carries a five-icon .rsrc suite and a 1 MB null-padded overlay. API resolution is performed at runtime via syscall.LoadLibrary / GetProcAddress with fused DLL+API strings. No custom in-memory PE parser or multi-pass decoder is present.

Detection Signatures

No capa output available (signatures missing in environment). Based on static structure, the following ATT&CK mappings are inferred from cluster behaviour:

Technique ID Evidence
Obfuscated Files or Information T1027 PRNG-seeded C2 URL decoding at runtime ^[prng-seeded-c2-url-decoding]
System Information Discovery T1082 Go standard library includes os, syscall for system enumeration
Data from Local System T1005 Inferred from family behaviour (browser credential harvesting) ^[lummastealer]
Exfiltration Over C2 Channel T1041 TLS/HTTPS POST inferred from crypto/tls + net/http linkage ^[strings.txt]
Application Layer Protocol T1071.001 HTTPS C2 (inferred)

References

Provenance

Analysis performed on 2026-09-01 using:

  • file (file type)
  • rabin2 (radare2 v5.9.8 — strings, sections, info, decompilation)
  • openssl x509 (certificate parsing)
  • python3 + pefile (PE structure, overlay, resource enumeration, section entropy)
  • strings (static string extraction)
  • Inputs: file.txt, strings.txt, rabin2-info.txt, triage.json, dynamic-analysis.md (CAPE skipped)