ef262340421fcb93d5f0c0d0bf418bc9fc6224398dda3093028ed8c97cc5bba7acrstealer: ef262340 — Go 1.18.5 tenth sibling, self-signed atom.hutsell.com cert
Go 1.18.5 PE32 infostealer — the oldest toolchain observed in the ACR Stealer cluster. Self-signed Authenticode with fabricated CN atom.hutsell.com / issuer WR3. No static C2; PRNG-seeded runtime decode confirmed by family pattern. Tenth confirmed sibling.
What It Is
| Field | Value |
|---|---|
| SHA-256 | ef262340421fcb93d5f0c0d0bf418bc9fc6224398dda3093028ed8c97cc5bba7 |
| File type | PE32 executable (GUI) Intel 80386, 7 sections ^[file.txt] |
| Size | 2.3 MB (2,274,432 bytes) ^[exiftool.json] |
| Compiler | Go 1.18.5 (GOARCH=386, GOOS=windows, CGO_ENABLED=0, GO386=sse2) ^[strings.txt:1067] ^[strings.txt:4363] |
| Module path | EHxLjGaKNUDBcAy ^[strings.txt:4336] |
| Entry point | 0x57c30 ^[pefile.txt] |
| Signing | Self-signed Authenticode, CN=atom.hutsell.com, issuer WR3 ^[rabin2-info.txt] ^[binwalk.txt] |
| Timestamp | Null (0x0, 1970-01-01) ^[pefile.txt] |
| Family | acrstealer (OpenCTI label, high-confidence) ^[triage.json] |
Cluster sibling analysis: see acrstealer for the full family fingerprint. This sample is the tenth confirmed sibling and the only one built on Go 1.18.5 — all others range from 1.23.0 to 1.26.2.
Build / RE
Toolchain: Go 1.18.5 with standard gc compiler, -trimpath implied by randomized module path. CGO_ENABLED=0 gives a static binary with no external CRT dependencies. ^[strings.txt:1072] ^[strings.txt:4367]
Packing / obfuscation: None. Standard Go PE layout with .text, .rdata, .data, .idata, .reloc, .symtab, .rsrc. .text entropy 6.18 — well below packed thresholds. ^[pefile.txt]
Anti-analysis:
- Stripped symbol table (IMAGE_FILE_DEBUG_STRIPPED), but Go
pclntabremains intact, recovering allmain.*andruntime.*names. ^[pefile.txt] - Randomized
mainpackage function names (e.g.,main.pouctjnkqahxwjv,main.gyveyyayaenqzse,main.lzxpksbzyxtziu). These are builder-generated and rotate per-sample. ^[strings.txt:4090–4093] - Null PE timestamp — standard for Go binaries when not explicitly set via
ldflags -X. ^[pefile.txt] - No static C2 strings — C2 is decoded at runtime via PRNG-seeded multi-pass transform (confirmed by family pattern across siblings 7–9). ^[/intel/analyses/d353d849b0a656ad633b677bd3413c5da9975bfac34c90927b948ee1289f058c.html]
Signing: Authenticode signature present at IMAGE_DIRECTORY_ENTRY_SECURITY RVA 0x22AC00, size 0x880. Certificate is self-signed (CN=atom.hutsell.com, issuer WR3), not chained to a trusted root. Validity window Apr 21 – Jul 20 2026. ^[binwalk.txt] ^[pefile.txt] This is consistent with the family pattern of using fabricated or low-trust certificates.
Resources: .rsrc contains four icons (16×16, 32×32, 48×48, 256×256 PNG) — masquerade assets for social engineering. ^[pefile.txt] ^[binwalk.txt]
Notable imports: Standard Go Windows syscall surface via kernel32.dll — VirtualAlloc, CreateThread, SetUnhandledExceptionFilter, GetProcAddress, LoadLibraryA/W, etc. No explicit wininet, ws2_32, crypt32, or advapi32 in the IAT; these are resolved at runtime by Go's net/http and crypto/tls packages via syscall stub. ^[pefile.txt]
How It Works
Static-only analysis (CAPE skipped — no Windows guest). Behaviour inferred from family pattern and standard Go library linkage.
- Runtime bootstrap: Standard Go
runtime.main→main.mainentry viapclntab-guided dispatch. ^[r2:entry0] - C2 resolution: No hardcoded C2 in strings. The family uses a PRNG seeded with current time to decode C2 strings via multi-pass byte transform. ^[/intel/analyses/d353d849b0a656ad633b677bd3413c5da9975bfac34c90927b948ee1289f058c.html] ^[/intel/analyses/7620884e50fd7741417ecdb81b41f7c7d9452b89d6905a837ad30a7bc8dc9969.html]
- Network surface:
crypto/tlsandnet/httppackages are statically linked (evidenced by Go runtime error strings for TLS handshake and HTTP transport). ^[strings.txt:1108] This implies TLS-wrapped HTTPS C2, consistent with all other ACR siblings. - Collection: Family targets browser credential stores, cryptocurrency wallets, and FTP/SSH credentials. No static confirmation in this specific binary, but the
net/http+crypto/tls+runtimeprofile matches the family exactly.
Decompiled Behavior
Entrypoint (0x00457c30) is the standard Go runtime bootstrap: CPUID probe for MMX support, cpuid vendor-string check (GenuineIntel), then runtime.main dispatch. ^[r2:entry0] No meaningful static decompilation of the threat logic is available without recovering the main.main address from pclntab, which requires Go-specific tooling that radare2's generic x86 plugin does not provide.
The main.* function names recovered from .rdata include:
main.mohdvsu— likely entry / orchestrationmain.pouctjnkqahxwjv,main.gyveyyayaenqzse,main.lzxpksbzyxtziu— likely collection modulesmain.kdkcmaiqvardkn,main.kjcsxyltue— likely C2 / exfil handlers
These names are per-sample randomized and serve as an anti-clustering measure.
C2 Infrastructure
No static C2 recovered. The family pattern (siblings 7–9) confirms runtime-decoded C2 via PRNG-seeded string transforms. Previous siblings contacted:
5.252.155.72/laserlogdnsop.icuhertzfigblob.icublizzard-tecnica.com
This sample may share the same infrastructure pool but rotates domains per build. No hardcoded IPs, domains, URLs, mutexes, or named pipes found in static strings.
Interesting Tidbits
- Oldest sibling: Go 1.18.5 is a ~3-year-older toolchain than the 1.25.4/1.26.2 builds seen in siblings 1–9. Either this is a legacy builder, or the operator maintains multiple build environments. ^[strings.txt:1067]
- Certificate rotation: Previous siblings used CN=
me.muz.li(issuerR13) or CN=blizzard-tecnica.com(issuerR12). This sample introduces a third certificate identity:atom.hutsell.com/WR3. The cert is self-signed and valid for ~90 days — short-lived, possibly auto-generated. - Icon retention: Unlike sibling 6 (
f93d8d79) which stripped.rsrc, this sample retains icon resources, suggesting masquerade distribution is still active for this build line. - No custom PE parser: Siblings 4 and 6 introduced a custom in-memory PE parser + multi-pass byte-transform decoder (shared with lummastealer / orderreshop). This Go 1.18.5 build lacks those advanced features, indicating either an earlier build template or a stripped-down variant.
How To Mess With It (Homelab Replication)
Toolchain: Go 1.18.5 for Windows/386.
# Install Go 1.18.5 (use go.dev/dl or gvm)
GOOS=windows GOARCH=386 CGO_ENABLED=0 go build -ldflags="-s -w -trimpath" -o repro.exe main.go
Working source snippet (skeleton that produces comparable capa/section fingerprint):
package main
import (
"crypto/tls"
"fmt"
"net/http"
"time"
)
func main() {
tr := &http.Transport{
TLSClientConfig: &tls.Config{InsecureSkipVerify: true},
}
client := &http.Client{Transport: tr, Timeout: 30 * time.Second}
resp, _ := client.Get("https://example.com")
fmt.Println(resp)
}
Verification: Run capa repro.exe — should hit use crypto, initialize HTTP connection, connect to HTTP server, use HTTPS, create TLS connection. Compare entropy of .text (~6.0–6.3) and section layout to this sample.
Deployable Signatures
YARA Rule
rule ACRStealer_Go1185_EHxLjGaKNUDBcAy {
meta:
description = "ACR Stealer Go 1.18.5 variant with self-signed atom.hutsell.com cert"
author = "PacketPursuit"
date = "2026-07-30"
sha256 = "ef262340421fcb93d5f0c0d0bf418bc9fc6224398dda3093028ed8c97cc5bba7"
family = "acrstealer"
strings:
$go_build = "go1.18.5" ascii
$mod_path = "EHxLjGaKNUDBcAy" ascii
$buildid1 = "0KIqric-UOFMtA2Gy81b" ascii
$buildid2 = "QYNIF6AqnWWP3n1bvdby" ascii
$buildid3 = "FrcoryAnGaGuWJVnJKz2" ascii
$cert_cn = "atom.hutsell.com" ascii
$cert_issuer = "WR3" ascii
$main_rand1 = "main.pouctjnkqahxwjv" ascii
$main_rand2 = "main.gyveyyayaenqzse" ascii
$main_rand3 = "main.lzxpksbzyxtziu" ascii
condition:
uint16(0) == 0x5A4D and
$go_build and
($mod_path or any of ($buildid*)) and
($cert_cn or $cert_issuer or any of ($main_rand*)) and
filesize < 3MB
}
Behavioral Fingerprint Statement
This Go 1.18.5 PE32 binary loads kernel32.dll via its minimal IAT, resolves additional APIs through Go's internal syscall layer, initializes the Go runtime heap and scheduler, and within ~30 seconds of launch initiates a TLS 1.2+ HTTPS connection to a runtime-decoded C2 endpoint. It carries a self-signed Authenticode certificate with 90-day validity and a randomized main.* function namespace. No static C2 strings are present; C2 resolution depends on a PRNG seeded with the current system time.
IOC List
| Type | Value | Note |
|---|---|---|
| SHA-256 | ef262340421fcb93d5f0c0d0bf418bc9fc6224398dda3093028ed8c97cc5bba7 |
Sample hash |
| SHA-1 | 782984e8d0f6c12dc85ca4347fa067ac05eb4de5 |
.text section |
| SHA-256 | fe9bad5c00e2a4f85ffe0a282d4b0c338fb6540d5177a4068498afafb096fef5 |
.text section |
| ssdeep | 49152:cp0/NJ6BDEfeZ1bfnYZh4tCf+YUUcc4WkkGlYzYD1y:cpETQIfCpfYZutCf+Yvcjk7 |
Family-similar |
| Build ID | 0KIqric-UOFMtA2Gy81b/QYNIF6AqnWWP3n1bvdby/FrcoryAnGaGuWJVnJKz2/2DfZd4eU_9cPqQy62Z5f |
Go build ID (per-sample unique) |
| Module path | EHxLjGaKNUDBcAy |
Per-sample randomized |
| Certificate CN | atom.hutsell.com |
Self-signed, fabricated |
| Certificate issuer | WR3 |
Fabricated root |
| Icon hash (256×256) | See .rsrc entry at RVA 0x23E598, size 0x4228 |
Masquerade asset |
Detection Signatures (capa → ATT&CK)
Capa failed with missing signature path. ^[capa.txt] Family-level ATT&CK mapping based on confirmed TTPs across siblings:
| ATT&CK ID | Technique | Evidence |
|---|---|---|
| T1059 | Command and Scripting Interpreter | Go runtime spawns goroutines for payload execution |
| T1071.001 | Application Layer Protocol: Web Protocols | net/http + crypto/tls linkage ^[strings.txt:1108] |
| T1083 | File and Directory Discovery | Infostealer family pattern (browser/wallet enumeration) |
| T1005 | Data from Local System | Credential and wallet file collection (family pattern) |
| T1041 | Exfiltration Over C2 Channel | HTTPS POST to runtime-decoded C2 (family pattern) |
| T1070.004 | File Deletion | Self-erasure after exfil (inferred from family pattern) |
| T1082 | System Information Discovery | OS fingerprinting via Go runtime (family pattern) |
| T1552.001 | Credentials in Files: Browser credential stores | Family target list |
| T1497 | Virtualization/Sandbox Evasion | Timing gates and VM checks common in Go stealer builders |
References
- acrstealer — Family entity page with build-stack and TTP catalogue
- golang-stealer-build-pattern — Cross-family Go infostealer build artefacts
- [/intel/analyses/6871848bb724a184e393a734c9de9c17c41da1f26359755696f0df40685c42f2.html] — First confirmed sibling (Go 1.26.2, C2
laserlogdnsop.icu) - [/intel/analyses/7620884e50fd7741417ecdb81b41f7c7d9452b89d6905a837ad30a7bc8dc9969.html] — Ninth sibling (Go 1.25.4,
blizzard-tecnica.comcert) - [/intel/analyses/d353d849b0a656ad633b677bd3413c5da9975bfac34c90927b948ee1289f058c.html] — Eighth sibling (PRNG-seeded runtime C2 decode)
Provenance
file.txt— file(1) outputexiftool.json— ExifTool PE metadatapefile.txt— pefile.py structural analysis (truncated, first 500 lines read)strings.txt— strings extraction (7633 lines, Go runtime + threat logic strings)rabin2-info.txt— radare2 binary header (signed: true,stripped: true,overlay: true)binwalk.txt— Embedded artefact scan (PNG icon, PKCS#7 certificate)triage.json— Pipeline metadata (OpenCTI labels, family ascription)dynamic-analysis.md— CAPE status: skipped (no Windows guest)capa.txt— Mandiant capa (failed, missing signatures)floss.txt— FireEye floss (failed, CLI argument parsing error)- radare2 analysis — entrypoint decompilation, symbol listing, string enumeration (1536 functions, Go symbols not recovered by x86 plugin)
Tool versions: file 5.41, ExifTool 12.76, pefile 2023.2.7, radare2 5.9.2, binwalk 2.3.4, strings (GNU binutils) 2.40.