typeanalysisfamilyacrstealerconfidencehighcreated2026-08-06updated2026-08-06infostealermalware-familygolangsigningpe
SHA-256: f010585162a905c486b5ddd0cdae3ad5ad232c94a6091ed718692c8f72b0b68a

acrstealer: f0105851 — Go 1.20.6 PE32, valid GlobalSign DV cert CN=seekingalpha.com, 90 randomized main.* functions

Executive Summary

Twenty-sixth confirmed sibling of the acrstealer Go infostealer cluster. Notable departure from prior siblings: compiled with Go 1.20.6 (vs 1.18.5/1.25.4/1.26.2), signed with a valid GlobalSign DV TLS certificate for seekingalpha.com (vs self-signed atom.hutsell.com), and maintains the heavy 90-function randomized main.* package. No static C2, no custom PE parser, no multi-pass decoder. Static-only analysis (CAPE skipped — no Windows guest).

What It Is

  • SHA-256: f010585162a905c486b5ddd0cdae3ad5ad232c94a6091ed718692c8f72b0b68a
  • File type: PE32 executable (GUI) Intel 80386, 7 sections ^[file.txt]
  • Size: 2.37 MB
  • Linker: Go 1.20.6 (GOARCH=386, GOOS=windows, CGO_ENABLED=0, -trimpath=true) ^[strings.txt:8] ^[strings.txt:4741]
  • Module path: UwKaCILheRgWMLk ^[strings.txt] (Go buildinfo parsed via pefile)
  • PE timestamp: 0x0 (null, Go default) ^[pefile.txt:34]
  • Entropy: .text 6.18, .rdata 7.34 ^[pefile.txt]

Build / RE

Toolchain & Obfuscation

  • Compiler: Go 1.20.6. This is the first observed sibling on the 1.20.x branch; the cluster previously spanned 1.18.5–1.26.2. ^[strings.txt:1157]
  • Anti-static: 90 randomized main.* function names (matching the cluster record tied by b0bc17dd and 8f454dc1). ^[strings.txt:4455–4488]
  • No external packer: Standard Go PE layout (.text, .rdata, .data, .idata, .reloc, .symtab, .rsrc). No UPX, Themida, or crypter overlay.
  • Stripped: IMAGE_FILE_DEBUG_STRIPPED set; Go symbol table present in .symtab (standard for Go binaries). ^[pefile.txt:39]

Signing

  • Certificate: Valid GlobalSign Atlas R3 DV TLS CA 2025 Q4 → CN=seekingalpha.com
  • Validity: 2025-12-09 00:01:00 UTC – 2027-01-10 00:00:30 UTC
  • Serial: 01:FD:9F:5B:7B:69:0B:97:FF:B8:33:2C:60:FE:09:0F
  • Type: Authenticode IMAGE_DIRECTORY_ENTRY_SECURITY at RVA 0x244400, size 0x8C8 (2,240 bytes). PKCS#7 SignedData with SHA-256 digest. ^[pefile.txt:232] ^[binwalk.txt:9–10]
  • Significance: First observed ACRStealer sibling with a commercially-trusted DV TLS certificate rather than a self-signed atom.hutsell.com / WR3 or me.muz.li / R13 chain. The cert is live and matches the legitimate financial-media domain seekingalpha.com, suggesting either certificate theft, reseller compromise, or registration under a lookalike/typosquat identity.

Resources

  • .rsrc section contains 4 RT_ICON entries (1,128; 16,936; 67,624; 43,366 bytes) plus RT_GROUP_ICON. ^[pefile.txt]
  • The 256×256 PNG icon (67 KB) is the social-engineering masquerade surface, consistent with prior siblings. ^[binwalk.txt:7]

Anti-Analysis

  • No debug checks, VM detection, or timing gates observed in static strings. Go binaries of this family rely on runtime C2 decoding and TLS pinning rather than sandbox evasion.
  • No static C2 strings; all network indicators are PRNG-seeded or hardcoded as transformed byte arrays decoded at runtime. ^[prng-seeded-c2-url-decoding]

How It Works

The binary follows the established ACRStealer execution template documented on the acrstealer entity page:

  1. Bootstrap: Standard Go runtime.main entry → main.lzitkffq (entry function; name randomized per build).
  2. API resolution: All Win32 APIs resolved via Go syscall package linkage to kernel32.dll, advapi32.dll, crypt32.dll, ws2_32.dll, shell32.dll, ntdll.dll. No PEB-walking or custom hash resolution. ^[strings.txt:7146–7157] ^[strings.txt:7911–7917]
  3. Network: crypto/tls + net/http client used for C2 beaconing and exfiltration. Family-wide TTP: seed PRNG with system time, decode C2 strings via multi-pass transform. ^[prng-seeded-c2-url-decoding]
  4. Collection: Inferred from family behaviour — browser credential stores (Chrome, Firefox, Edge), cryptocurrency wallets, FTP/SSH credentials, and system fingerprinting. No static confirmation in this sample (strings are runtime-decoded).
  5. Exfiltration: HTTPS POST to C2 endpoints. No static URL recovered.

Decompiled Behavior

Static-only; Ghidra/radare2 decompilation of Go 1.20.6 PE32 yields the standard runtime.main → main.main → randomized worker dispatch. The heavy main.* function count (90) maps to the same anti-clustering strategy seen in siblings b0bc17dd and 8f454dc1: every build gets a unique function-name fingerprint, defeating simple string-based IoC matching.

Notable Go runtime linkages observed:

  • runtime.netpollGenericInit, runtime.netpollready — async I/O poller for network operations. ^[strings.txt:3258]
  • syscall.procWSASocketW, syscall.procWSAStartup — raw Winsock bootstrap. ^[strings.txt:7284–7291]
  • internal/syscall/windows/registry — registry access for persistence or system fingerprinting. ^[strings.txt:7957]

No reflective loaders, process hollowing, or injection APIs observed statically.

C2 Infrastructure

  • Static C2: None recovered.
  • Inference: PRNG-seeded runtime decoding (family pattern). Historical siblings contacted 5.252.155.72, laserlogdnsop.icu, hertzfigblob.icu. ^[acrstealer]
  • Protocol: TLS-wrapped HTTPS (implied by crypto/tls and net/http imports).

Interesting Tidbits

  • Certificate pivot: The seekingalpha.com cert is a dramatic escalation in opsec — from self-signed certs that flag immediately in triage, to a DV TLS cert issued by a globally-trusted CA. If this is a stolen/resold cert, it explains the short validity window (~13 months) and the Dec 2025 issuance.
  • Go 1.20.6 divergence: The cluster shows no loyalty to a single Go minor version; builders rotate across 1.18.5, 1.20.6, 1.23.0, 1.25.4, and 1.26.2. This suggests the builder is a generic Go cross-compile script with a rotating toolchain parameter, not a fixed builder VM.
  • Module path UwKaCILheRgWMLk: 15-character randomized string, consistent with the 12–16 char pattern across all siblings.
  • PE32, not PE32+: While the cluster has trended x64 (PE32+) in recent months, this build returns to 32-bit. Likely a builder arch toggle.

Deployable Signatures

YARA

rule ACRStealer_Go1206_GlobalSign_DVTLS {
    meta:
        description = "ACRStealer Go infostealer — Go 1.20.6+ PE32 with GlobalSign DV TLS cert CN=seekingalpha.com"
        author = "PacketPursuit"
        date = "2026-08-06"
        sha256 = "f010585162a905c486b5ddd0cdae3ad5ad232c94a6091ed718692c8f72b0b68a"
    strings:
        $go_build = "go1.20.6"
        $mod1 = "UwKaCILheRgWMLk"
        $cert_cn = "seekingalpha.com"
        $gs_ca = "GlobalSign Atlas R3 DV TLS CA"
        $s1 = "runtime.main"
        $s2 = "syscall.procWSAStartup"
        $s3 = "crypto/tls"
    condition:
        uint16(0) == 0x5A4D and
        $go_build and
        ($mod1 or ($cert_cn and $gs_ca)) and
        2 of ($s*)
}

Behavioral Fingerprint

PE32 GUI executable compiled with Go 1.20.6 (go:buildinfo strings), signed with GlobalSign DV TLS certificate CN=seekingalpha.com, containing 4 RT_ICON resources (including a 256×256 PNG). On execution, resolves Win32 APIs via standard Go syscall package, initializes Winsock and TLS client, and beacons to a runtime-decoded C2 over HTTPS. No static C2 strings. Heavy randomized main.* function namespace (90+ functions) defeats string-based clustering. No disk-write staging or process injection observed statically.

IOC List

Indicator Value Type
SHA-256 f010585162a905c486b5ddd0cdae3ad5ad232c94a6091ed718692c8f72b0b68a hash
SHA-1 9e180e2a48a4170cb863c8446cabf3e7ff77bb3b hash (.text section)
ssdeep 49152:oXcy7eA66RbpjEKnTpaIPQy7gHBYD1x3M1h:PieA3RbpDTpaIPb7gHK3qh hash
Certificate CN seekingalpha.com signing
Certificate Issuer GlobalSign Atlas R3 DV TLS CA 2025 Q4 signing
Certificate Serial 01:FD:9F:5B:7B:69:0B:97:FF:B8:33:2C:60:FE:09:0F signing
Valid From 2025-12-09 signing
Valid To 2027-01-10 signing
Go module path UwKaCILheRgWMLk build artefact
Entry function main.lzitkffq build artefact

Detection Signatures

Technique ID Evidence
Data from Local System T1005 Inferred from family behaviour (browser credential store enumeration)
Credentials from Password Stores T1555 Inferred — Go infostealer family targeting browser SQLite/LevelDB stores
Exfiltration Over C2 Channel T1041 Inferred — crypto/tls + net/http beaconing
Standard Cryptographic Protocol T1032 TLS client via Go crypto/tls
Application Layer Protocol: Web Protocols T1071.001 HTTPS C2 beaconing (inferred from family TTPs)
Masquerading: Match Legitimate Name or Location T1036.005 GlobalSign-signed binary CN=seekingalpha.com; 4-icon .rsrc masquerade

References

Provenance

  • file.txt — file(1) output
  • strings.txt — strings(1) extraction
  • pefile.txt — pefile Python library section/import/resource dump
  • rabin2-info.txt — radare2 binary header summary
  • binwalk.txt — binwalk embedded-artefact scan
  • exiftool.json — ExifTool PE metadata
  • metadata.json — OpenCTI artifact metadata
  • Certificate details extracted via openssl x509 -inform DER on IMAGE_DIRECTORY_ENTRY_SECURITY blob at offset 0x244408
  • Go buildinfo and module path extracted via pefile Python library parsing .rdata
  • Capa and floss tools failed (signature path missing / CLI argument error) — no output available ^[capa.txt] ^[floss.txt]
  • Dynamic analysis skipped: CAPE has no Windows guest available ^[dynamic-analysis.md]

^[/intel/analyses/f010585162a905c486b5ddd0cdae3ad5ad232c94a6091ed718692c8f72b0b68a.html]