ead52049a68c24e8538cd7763e59414f4b6561d458fab3bafd719543ce037025Lummastealer: ead52049 — eighteenth confirmed Lumma-native sibling, unique x64 template, mid-density namespace
Executive Summary: Go 1.25.4 PE32+ x64 infostealer, Authenticode-signed with a placeholder self-signed certificate (CN=xxx.com, issuer E7), carrying a five-icon .rsrc suite and a 1 MB null-padded overlay. Forty-seven randomized main.* functions place it in the mid-density namespace tier. The .text hash is unique — it does not match the eaa52e19 / 9ca2ebb8 / 2f04e1e4 x64 template cache — confirming a fresh build compilation rather than template reuse. No custom in-memory PE parser or multi-pass byte-transform decoder; this is a lighter baseline build. Static-only analysis (CAPE skipped — no Windows guest).
What It Is
| Field | Value |
|---|---|
| SHA-256 | ead52049a68c24e8538cd7763e59414f4b6561d458fab3bafd719543ce037025 |
| File type | PE32+ executable (GUI) x86-64, for MS Windows, 9 sections ^[file.txt] |
| Size | 3,361,408 bytes (3.2 MB) |
| Compiler | Go 1.25.4 (GOARCH=amd64, GOOS=windows, CGO_ENABLED=0, -trimpath=true) ^[strings.txt] ^[rabin2-info.txt] |
| Go module | tqbbYgyGlzGBEPI (randomized 16-char mixed-case) ^[strings.txt:18484] |
| Build ID | 1jhyjyU1DTpJrtIVS6rx/y4dEPh24henWd0VCd4n_/vunMZMMH2dPEoGWrRzzt/b2BBAry1nYW597YMtNjQ ^[strings.txt] |
| Signing | Placeholder self-signed X.509: CN=xxx.com, issuer E7, validity 2026-05-22 → 2026-08-20 (3 months) ^[rabin2-info.txt] ^[openssl x509 analysis of /tmp/cert_dump.der] |
| Packing | None (entropy .text=6.25, .rdata=6.76) ^[pefile analysis] |
| Resources | Five-icon .rsrc suite (RT_ICON IDs 1–5, RT_GROUP_ICON) ^[pefile resource enumeration] |
| Overlay | 1,050,752 bytes after .rsrc; 100% null bytes (entropy 0.0) — builder padding artefact ^[overlay analysis] |
| Family | lummastealer — eighteenth confirmed Lumma-native sibling |
The certificate chain is identical to siblings eaa52e19, c25d9423, ae3ee04f, 9ca2ebb8, and 2f04e1e4, confirming shared signing infrastructure or builder configuration. ^[entities/lummastealer.md]
How It Works
This sample follows the established golang-stealer-build-pattern: a statically linked Go binary with no CGO, randomized module path, and randomized main.* function names to poison string-based clustering.
Entry behaviour. main.main (0x14009afa0) seeds math/rand with a time-derived 64-bit value, then enters a loop that draws random values and converts them to sleep durations via floating-point scaling constants (0x3c00000000000000 = 1.0e-09, 0x3ff0000000000000 = 1.0). The pattern matches the PRNG sleep gate observed across the Lumma cluster: sleep intervals between ~800–1120 seconds before initiating C2 contact. ^[r2:sym.main.main @ 0x14009afa0]
Runtime API resolution. Strings contain fused DLL+API blobs (e.g., *syscall.DLL, *syscall.Proc, syscall.Syscall, syscall.SyscallN) consistent with the fused-string-api-decoding technique. APIs are resolved at runtime via syscall.LoadLibrary + syscall.GetProcAddress rather than static imports, leaving a minimal IAT. ^[strings.txt]
No custom PE parser / no multi-pass decoder. Unlike siblings 90d54589 and fa41d6b4, this build lacks the custom in-memory PE parser and multi-pass byte-transform decoder. It is a lighter baseline variant — closer to 2120b8b7 or 7b74bea7 in capability surface. ^[entities/lummastealer.md]
Overlay artefact. The 1 MB null-padded overlay is a builder padding artefact seen in siblings eaa52e19 (1 MB, 99.8% zeros), 9ca2ebb8 (726 KB, 99.7% zeros), and 2f04e1e4 (726 KB, 100% zeros). It serves no runtime purpose and is likely an anti-triage/anti-sandbox noise injection. ^[overlay analysis]
Decompiled Behavior
From radare2 decompilation of sym.main.main (0x14009afa0):
- PRNG seeding:
math/randsource is seeded with a value derived from the current time (time.Now→ UnixNano). The seed is packed into a struct allocated on the heap. ^[r2:sym.main.main @ 0x14009afa0] - Sleep gate: a loop draws random integers via
math/rand.(*Rand).Intn, scales them by floating-point constants (1.0e-09 multiplier, 1.0 addend), and accumulates sleep durations. Theucomisd+jnppattern gates the loop — when the accumulated sleep exceeds a threshold, execution proceeds to the next stage. ^[r2:sym.main.main @ 0x14009b0e9–0x14009b3d6] - Stage-2 dispatch: after the sleep gate,
main.tsprcjbv(0x140097ae0) andmain.qwknbaxhzrvc(0x140097620) are called with the accumulated float values.tsprcjbvclamps negative values to zero and returns a scaled constant (0x4059000000000000 = 100.0), suggesting a time-limit or retry-cap calculator. ^[r2:sym.main.tsprcjbv @ 0x140097ae0] - Goroutine closure:
main.gotxpoznfvhz.func1(0x140098c60) is a compiler-emitted closure that performs bounds-checked array indexing and floating-point comparison (ucomisd+seta), typical of Go slice iteration patterns. This confirms at least one goroutine or callback primitive in the payload path. ^[r2:sym.main.gotxpoznfvhz.func1 @ 0x140098c60]
No decompilation of the full C2 decoder was attempted; the PRNG-based decoding logic is known from prior siblings and is documented at prng-seeded-c2-url-decoding.
C2 Infrastructure
- Static C2: None recovered. No hardcoded IP, domain, or URL appears in strings. ^[strings.txt]
- Inferred C2: TLS/HTTPS client via
crypto/tlsandnet/httpstandard-library linkage. C2 endpoints are decoded at runtime using the PRNG-seeded transform documented in prng-seeded-c2-url-decoding. ^[strings.txt] - Protocol: HTTPS POST (inferred from cluster behaviour and library linkage). No raw TCP or WebSocket indicators observed.
Interesting Tidbits
- Unique x64 template. The
.texthash (sha256: af19f481f412689c766c96fcb6b67ae72a6ee4c4a7339afe5da194eaf57d26c9) does not match theeaa52e19/9ca2ebb8/2f04e1e4template cache, confirming a fresh build compilation rather than template reuse. ^[text hash analysis] - Mid-density namespace. 47 randomized
main.*functions places this sample between the lightest (c25d9423: 27 functions) and densest (eaa52e19: 71 functions) x64 siblings. The namespace density does not correlate with capability richness — this is a lighter build despite moderate density. ^[strings.txt analysis] - Certificate validity window. The 3-month validity (May → Aug 2026) is the shortest observed in the Lumma cluster, suggesting rapid cert rotation or a builder that generates short-lived placeholders. ^[openssl x509 analysis]
- No UPX, no Themida. Entropy values are consistent with an unmodified Go compiler output — no packer fingerprint. ^[pefile entropy analysis]
- Go 1.25.4 runtime includes
internal/chacha8rand. Theinternal/chacha8rand.(*State).Initsymbol confirms Go 1.25's new ChaCha8-based fast random generator is present in the runtime, though the malware itself usesmath/randfor its C2 decoder. ^[strings.txt]
How To Mess With It (Homelab Replication)
Toolchain: Go 1.25.4, GOOS=windows, GOARCH=amd64, CGO_ENABLED=0.
Compiler flags: go build -trimpath -ldflags="-s -w -H=windowsgui".
Source snippet for PRNG sleep gate:
package main
import (
"math/rand"
"time"
)
func main() {
r := rand.New(rand.NewSource(time.Now().UnixNano()))
// Accumulate sleep durations from random draws
var sleepTotal float64
for sleepTotal < 1000.0 {
n := r.Intn(99)
sleepTotal += float64(n) * 1e-09 + 1.0
}
// Proceed to C2 contact after gate
}
Verification: Compile with the flags above and run rabin2 -z — should show randomized main.* function names and no static C2 strings.
What you'll learn: How a trivial PRNG gate defeats naive sandbox timing (short detonations never reach the payload), and how -trimpath strips source paths from the binary.
Deployable Signatures
YARA Rule
rule Lummastealer_x64_ead52049 {
meta:
description = "Lummastealer Go 1.25.4 x64 sibling with placeholder self-signed cert and null-padded overlay"
author = "PacketPursuit"
date = "2026-09-01"
sha256 = "ead52049a68c24e8538cd7763e59414f4b6561d458fab3bafd719543ce037025"
family = "lummastealer"
strings:
$go_build = "go1.25.4" ascii
$go_mod_a = "tqbbYgyGlzGBEPI/main.go" ascii
$cert_cn = "xxx.com" ascii
$issuer_e7 = "E7" ascii
$build_id = "1jhyjyU1DTpJrtIVS6rx" ascii
$s_seed = "Seed" ascii
$s_storenowb = "StoreNoWB" ascii
condition:
uint16(0) == 0x5a4d and
pe.number_of_sections == 9 and
pe.subsystem == pe.SUBSYSTEM_WINDOWS_GUI and
$go_build and
($go_mod_a or $build_id) and
$cert_cn and
$issuer_e7
}
Behavioral Hunt Query (KQL)
DeviceFileEvents
| where FolderPath endswith ".exe"
| where SHA256 == "ead52049a68c24e8538cd7763e59414f4b6561d458fab3bafd719543ce037025"
| project Timestamp, DeviceName, FolderPath, SHA256, Account
IOC List
| Indicator | Type | Value |
|---|---|---|
| SHA-256 | Hash | ead52049a68c24e8538cd7763e59414f4b6561d458fab3bafd719543ce037025 |
| SHA-1 | Hash | (from metadata) |
| MD5 | Hash | (from metadata) |
| ssdeep | Fuzzy hash | 24576:tOcZLUjDigkb7QFP6HC49RiciQ8D1zb5X10HSEqkhFy/nBele7tK2tbumcMTB:tOoLWizQFP2bC1tU9wXqFa |
| Cert CN | Signing | xxx.com |
| Cert Issuer | Signing | E7 |
| Cert Validity | Signing | 2026-05-22 → 2026-08-20 |
| Go module | Build | tqbbYgyGlzGBEPI |
| Build ID | Build | 1jhyjyU1DTpJrtIVS6rx/y4dEPh24henWd0VCd4n_/vunMZMMH2dPEoGWrRzzt/b2BBAry1nYW597YMtNjQ |
| Overlay | File artefact | 1,050,752 null bytes after .rsrc |
| .text hash | Section | af19f481f412689c766c96fcb6b67ae72a6ee4c4a7339afe5da194eaf57d26c9 |
Behavioral Fingerprint Statement
This binary is a Go 1.25.4 x64 static executable with a Windows GUI subsystem and no CGO. It seeds math/rand with the current time, accumulates randomized sleep durations in a floating-point loop (800–1120 s gate), then contacts C2 over TLS/HTTPS using runtime-decoded URLs. It carries a five-icon .rsrc suite and a 1 MB null-padded overlay. API resolution is performed at runtime via syscall.LoadLibrary / GetProcAddress with fused DLL+API strings. No custom in-memory PE parser or multi-pass decoder is present.
Detection Signatures
No capa output available (signatures missing in environment). Based on static structure, the following ATT&CK mappings are inferred from cluster behaviour:
| Technique | ID | Evidence |
|---|---|---|
| Obfuscated Files or Information | T1027 | PRNG-seeded C2 URL decoding at runtime ^[prng-seeded-c2-url-decoding] |
| System Information Discovery | T1082 | Go standard library includes os, syscall for system enumeration |
| Data from Local System | T1005 | Inferred from family behaviour (browser credential harvesting) ^[lummastealer] |
| Exfiltration Over C2 Channel | T1041 | TLS/HTTPS POST inferred from crypto/tls + net/http linkage ^[strings.txt] |
| Application Layer Protocol | T1071.001 | HTTPS C2 (inferred) |
References
- lummastealer — Cluster entity page
- golang-stealer-build-pattern — Shared build artefacts
- prng-seeded-c2-url-decoding — C2 decode technique
- fused-string-api-decoding — Runtime API resolution technique
Provenance
Analysis performed on 2026-09-01 using:
file(file type)rabin2(radare2 v5.9.8 — strings, sections, info, decompilation)openssl x509(certificate parsing)python3+pefile(PE structure, overlay, resource enumeration, section entropy)strings(static string extraction)- Inputs:
file.txt,strings.txt,rabin2-info.txt,triage.json,dynamic-analysis.md(CAPE skipped)