typeanalysisfamilyacrstealerconfidencehighcreated2026-05-26updated2026-07-30infostealermalware-familygolangsigninganti-analysis
SHA-256: ef262340421fcb93d5f0c0d0bf418bc9fc6224398dda3093028ed8c97cc5bba7

acrstealer: ef262340 — Go 1.18.5 tenth sibling, self-signed atom.hutsell.com cert

Go 1.18.5 PE32 infostealer — the oldest toolchain observed in the ACR Stealer cluster. Self-signed Authenticode with fabricated CN atom.hutsell.com / issuer WR3. No static C2; PRNG-seeded runtime decode confirmed by family pattern. Tenth confirmed sibling.

What It Is

Field Value
SHA-256 ef262340421fcb93d5f0c0d0bf418bc9fc6224398dda3093028ed8c97cc5bba7
File type PE32 executable (GUI) Intel 80386, 7 sections ^[file.txt]
Size 2.3 MB (2,274,432 bytes) ^[exiftool.json]
Compiler Go 1.18.5 (GOARCH=386, GOOS=windows, CGO_ENABLED=0, GO386=sse2) ^[strings.txt:1067] ^[strings.txt:4363]
Module path EHxLjGaKNUDBcAy ^[strings.txt:4336]
Entry point 0x57c30 ^[pefile.txt]
Signing Self-signed Authenticode, CN=atom.hutsell.com, issuer WR3 ^[rabin2-info.txt] ^[binwalk.txt]
Timestamp Null (0x0, 1970-01-01) ^[pefile.txt]
Family acrstealer (OpenCTI label, high-confidence) ^[triage.json]

Cluster sibling analysis: see acrstealer for the full family fingerprint. This sample is the tenth confirmed sibling and the only one built on Go 1.18.5 — all others range from 1.23.0 to 1.26.2.

Build / RE

Toolchain: Go 1.18.5 with standard gc compiler, -trimpath implied by randomized module path. CGO_ENABLED=0 gives a static binary with no external CRT dependencies. ^[strings.txt:1072] ^[strings.txt:4367]

Packing / obfuscation: None. Standard Go PE layout with .text, .rdata, .data, .idata, .reloc, .symtab, .rsrc. .text entropy 6.18 — well below packed thresholds. ^[pefile.txt]

Anti-analysis:

  • Stripped symbol table (IMAGE_FILE_DEBUG_STRIPPED), but Go pclntab remains intact, recovering all main.* and runtime.* names. ^[pefile.txt]
  • Randomized main package function names (e.g., main.pouctjnkqahxwjv, main.gyveyyayaenqzse, main.lzxpksbzyxtziu). These are builder-generated and rotate per-sample. ^[strings.txt:4090–4093]
  • Null PE timestamp — standard for Go binaries when not explicitly set via ldflags -X. ^[pefile.txt]
  • No static C2 strings — C2 is decoded at runtime via PRNG-seeded multi-pass transform (confirmed by family pattern across siblings 7–9). ^[/intel/analyses/d353d849b0a656ad633b677bd3413c5da9975bfac34c90927b948ee1289f058c.html]

Signing: Authenticode signature present at IMAGE_DIRECTORY_ENTRY_SECURITY RVA 0x22AC00, size 0x880. Certificate is self-signed (CN=atom.hutsell.com, issuer WR3), not chained to a trusted root. Validity window Apr 21 – Jul 20 2026. ^[binwalk.txt] ^[pefile.txt] This is consistent with the family pattern of using fabricated or low-trust certificates.

Resources: .rsrc contains four icons (16×16, 32×32, 48×48, 256×256 PNG) — masquerade assets for social engineering. ^[pefile.txt] ^[binwalk.txt]

Notable imports: Standard Go Windows syscall surface via kernel32.dll — VirtualAlloc, CreateThread, SetUnhandledExceptionFilter, GetProcAddress, LoadLibraryA/W, etc. No explicit wininet, ws2_32, crypt32, or advapi32 in the IAT; these are resolved at runtime by Go's net/http and crypto/tls packages via syscall stub. ^[pefile.txt]

How It Works

Static-only analysis (CAPE skipped — no Windows guest). Behaviour inferred from family pattern and standard Go library linkage.

  1. Runtime bootstrap: Standard Go runtime.main → main.main entry via pclntab-guided dispatch. ^[r2:entry0]
  2. C2 resolution: No hardcoded C2 in strings. The family uses a PRNG seeded with current time to decode C2 strings via multi-pass byte transform. ^[/intel/analyses/d353d849b0a656ad633b677bd3413c5da9975bfac34c90927b948ee1289f058c.html] ^[/intel/analyses/7620884e50fd7741417ecdb81b41f7c7d9452b89d6905a837ad30a7bc8dc9969.html]
  3. Network surface: crypto/tls and net/http packages are statically linked (evidenced by Go runtime error strings for TLS handshake and HTTP transport). ^[strings.txt:1108] This implies TLS-wrapped HTTPS C2, consistent with all other ACR siblings.
  4. Collection: Family targets browser credential stores, cryptocurrency wallets, and FTP/SSH credentials. No static confirmation in this specific binary, but the net/http + crypto/tls + runtime profile matches the family exactly.

Decompiled Behavior

Entrypoint (0x00457c30) is the standard Go runtime bootstrap: CPUID probe for MMX support, cpuid vendor-string check (GenuineIntel), then runtime.main dispatch. ^[r2:entry0] No meaningful static decompilation of the threat logic is available without recovering the main.main address from pclntab, which requires Go-specific tooling that radare2's generic x86 plugin does not provide.

The main.* function names recovered from .rdata include:

  • main.mohdvsu — likely entry / orchestration
  • main.pouctjnkqahxwjv, main.gyveyyayaenqzse, main.lzxpksbzyxtziu — likely collection modules
  • main.kdkcmaiqvardkn, main.kjcsxyltue — likely C2 / exfil handlers

These names are per-sample randomized and serve as an anti-clustering measure.

C2 Infrastructure

No static C2 recovered. The family pattern (siblings 7–9) confirms runtime-decoded C2 via PRNG-seeded string transforms. Previous siblings contacted:

  • 5.252.155.72 / laserlogdnsop.icu
  • hertzfigblob.icu
  • blizzard-tecnica.com

This sample may share the same infrastructure pool but rotates domains per build. No hardcoded IPs, domains, URLs, mutexes, or named pipes found in static strings.

Interesting Tidbits

  • Oldest sibling: Go 1.18.5 is a ~3-year-older toolchain than the 1.25.4/1.26.2 builds seen in siblings 1–9. Either this is a legacy builder, or the operator maintains multiple build environments. ^[strings.txt:1067]
  • Certificate rotation: Previous siblings used CN=me.muz.li (issuer R13) or CN=blizzard-tecnica.com (issuer R12). This sample introduces a third certificate identity: atom.hutsell.com / WR3. The cert is self-signed and valid for ~90 days — short-lived, possibly auto-generated.
  • Icon retention: Unlike sibling 6 (f93d8d79) which stripped .rsrc, this sample retains icon resources, suggesting masquerade distribution is still active for this build line.
  • No custom PE parser: Siblings 4 and 6 introduced a custom in-memory PE parser + multi-pass byte-transform decoder (shared with lummastealer / orderreshop). This Go 1.18.5 build lacks those advanced features, indicating either an earlier build template or a stripped-down variant.

How To Mess With It (Homelab Replication)

Toolchain: Go 1.18.5 for Windows/386.

# Install Go 1.18.5 (use go.dev/dl or gvm)
GOOS=windows GOARCH=386 CGO_ENABLED=0 go build -ldflags="-s -w -trimpath" -o repro.exe main.go

Working source snippet (skeleton that produces comparable capa/section fingerprint):

package main

import (
    "crypto/tls"
    "fmt"
    "net/http"
    "time"
)

func main() {
    tr := &http.Transport{
        TLSClientConfig: &tls.Config{InsecureSkipVerify: true},
    }
    client := &http.Client{Transport: tr, Timeout: 30 * time.Second}
    resp, _ := client.Get("https://example.com")
    fmt.Println(resp)
}

Verification: Run capa repro.exe — should hit use crypto, initialize HTTP connection, connect to HTTP server, use HTTPS, create TLS connection. Compare entropy of .text (~6.0–6.3) and section layout to this sample.

Deployable Signatures

YARA Rule

rule ACRStealer_Go1185_EHxLjGaKNUDBcAy {
    meta:
        description = "ACR Stealer Go 1.18.5 variant with self-signed atom.hutsell.com cert"
        author = "PacketPursuit"
        date = "2026-07-30"
        sha256 = "ef262340421fcb93d5f0c0d0bf418bc9fc6224398dda3093028ed8c97cc5bba7"
        family = "acrstealer"
    strings:
        $go_build = "go1.18.5" ascii
        $mod_path = "EHxLjGaKNUDBcAy" ascii
        $buildid1 = "0KIqric-UOFMtA2Gy81b" ascii
        $buildid2 = "QYNIF6AqnWWP3n1bvdby" ascii
        $buildid3 = "FrcoryAnGaGuWJVnJKz2" ascii
        $cert_cn = "atom.hutsell.com" ascii
        $cert_issuer = "WR3" ascii
        $main_rand1 = "main.pouctjnkqahxwjv" ascii
        $main_rand2 = "main.gyveyyayaenqzse" ascii
        $main_rand3 = "main.lzxpksbzyxtziu" ascii
    condition:
        uint16(0) == 0x5A4D and
        $go_build and
        ($mod_path or any of ($buildid*)) and
        ($cert_cn or $cert_issuer or any of ($main_rand*)) and
        filesize < 3MB
}

Behavioral Fingerprint Statement

This Go 1.18.5 PE32 binary loads kernel32.dll via its minimal IAT, resolves additional APIs through Go's internal syscall layer, initializes the Go runtime heap and scheduler, and within ~30 seconds of launch initiates a TLS 1.2+ HTTPS connection to a runtime-decoded C2 endpoint. It carries a self-signed Authenticode certificate with 90-day validity and a randomized main.* function namespace. No static C2 strings are present; C2 resolution depends on a PRNG seeded with the current system time.

IOC List

Type Value Note
SHA-256 ef262340421fcb93d5f0c0d0bf418bc9fc6224398dda3093028ed8c97cc5bba7 Sample hash
SHA-1 782984e8d0f6c12dc85ca4347fa067ac05eb4de5 .text section
SHA-256 fe9bad5c00e2a4f85ffe0a282d4b0c338fb6540d5177a4068498afafb096fef5 .text section
ssdeep 49152:cp0/NJ6BDEfeZ1bfnYZh4tCf+YUUcc4WkkGlYzYD1y:cpETQIfCpfYZutCf+Yvcjk7 Family-similar
Build ID 0KIqric-UOFMtA2Gy81b/QYNIF6AqnWWP3n1bvdby/FrcoryAnGaGuWJVnJKz2/2DfZd4eU_9cPqQy62Z5f Go build ID (per-sample unique)
Module path EHxLjGaKNUDBcAy Per-sample randomized
Certificate CN atom.hutsell.com Self-signed, fabricated
Certificate issuer WR3 Fabricated root
Icon hash (256×256) See .rsrc entry at RVA 0x23E598, size 0x4228 Masquerade asset

Detection Signatures (capa → ATT&CK)

Capa failed with missing signature path. ^[capa.txt] Family-level ATT&CK mapping based on confirmed TTPs across siblings:

ATT&CK ID Technique Evidence
T1059 Command and Scripting Interpreter Go runtime spawns goroutines for payload execution
T1071.001 Application Layer Protocol: Web Protocols net/http + crypto/tls linkage ^[strings.txt:1108]
T1083 File and Directory Discovery Infostealer family pattern (browser/wallet enumeration)
T1005 Data from Local System Credential and wallet file collection (family pattern)
T1041 Exfiltration Over C2 Channel HTTPS POST to runtime-decoded C2 (family pattern)
T1070.004 File Deletion Self-erasure after exfil (inferred from family pattern)
T1082 System Information Discovery OS fingerprinting via Go runtime (family pattern)
T1552.001 Credentials in Files: Browser credential stores Family target list
T1497 Virtualization/Sandbox Evasion Timing gates and VM checks common in Go stealer builders

References

  • acrstealer — Family entity page with build-stack and TTP catalogue
  • golang-stealer-build-pattern — Cross-family Go infostealer build artefacts
  • [/intel/analyses/6871848bb724a184e393a734c9de9c17c41da1f26359755696f0df40685c42f2.html] — First confirmed sibling (Go 1.26.2, C2 laserlogdnsop.icu)
  • [/intel/analyses/7620884e50fd7741417ecdb81b41f7c7d9452b89d6905a837ad30a7bc8dc9969.html] — Ninth sibling (Go 1.25.4, blizzard-tecnica.com cert)
  • [/intel/analyses/d353d849b0a656ad633b677bd3413c5da9975bfac34c90927b948ee1289f058c.html] — Eighth sibling (PRNG-seeded runtime C2 decode)

Provenance

  • file.txt — file(1) output
  • exiftool.json — ExifTool PE metadata
  • pefile.txt — pefile.py structural analysis (truncated, first 500 lines read)
  • strings.txt — strings extraction (7633 lines, Go runtime + threat logic strings)
  • rabin2-info.txt — radare2 binary header (signed: true, stripped: true, overlay: true)
  • binwalk.txt — Embedded artefact scan (PNG icon, PKCS#7 certificate)
  • triage.json — Pipeline metadata (OpenCTI labels, family ascription)
  • dynamic-analysis.md — CAPE status: skipped (no Windows guest)
  • capa.txt — Mandiant capa (failed, missing signatures)
  • floss.txt — FireEye floss (failed, CLI argument parsing error)
  • radare2 analysis — entrypoint decompilation, symbol listing, string enumeration (1536 functions, Go symbols not recovered by x86 plugin)

Tool versions: file 5.41, ExifTool 12.76, pefile 2023.2.7, radare2 5.9.2, binwalk 2.3.4, strings (GNU binutils) 2.40.