f010585162a905c486b5ddd0cdae3ad5ad232c94a6091ed718692c8f72b0b68aacrstealer: f0105851 — Go 1.20.6 PE32, valid GlobalSign DV cert CN=seekingalpha.com, 90 randomized main.* functions
Executive Summary
Twenty-sixth confirmed sibling of the acrstealer Go infostealer cluster. Notable departure from prior siblings: compiled with Go 1.20.6 (vs 1.18.5/1.25.4/1.26.2), signed with a valid GlobalSign DV TLS certificate for seekingalpha.com (vs self-signed atom.hutsell.com), and maintains the heavy 90-function randomized main.* package. No static C2, no custom PE parser, no multi-pass decoder. Static-only analysis (CAPE skipped — no Windows guest).
What It Is
- SHA-256:
f010585162a905c486b5ddd0cdae3ad5ad232c94a6091ed718692c8f72b0b68a - File type: PE32 executable (GUI) Intel 80386, 7 sections ^[file.txt]
- Size: 2.37 MB
- Linker: Go 1.20.6 (
GOARCH=386,GOOS=windows,CGO_ENABLED=0,-trimpath=true) ^[strings.txt:8] ^[strings.txt:4741] - Module path:
UwKaCILheRgWMLk^[strings.txt] (Go buildinfo parsed via pefile) - PE timestamp:
0x0(null, Go default) ^[pefile.txt:34] - Entropy:
.text6.18,.rdata7.34 ^[pefile.txt]
Build / RE
Toolchain & Obfuscation
- Compiler: Go 1.20.6. This is the first observed sibling on the 1.20.x branch; the cluster previously spanned 1.18.5–1.26.2. ^[strings.txt:1157]
- Anti-static: 90 randomized
main.*function names (matching the cluster record tied byb0bc17ddand8f454dc1). ^[strings.txt:4455–4488] - No external packer: Standard Go PE layout (
.text,.rdata,.data,.idata,.reloc,.symtab,.rsrc). No UPX, Themida, or crypter overlay. - Stripped:
IMAGE_FILE_DEBUG_STRIPPEDset; Go symbol table present in.symtab(standard for Go binaries). ^[pefile.txt:39]
Signing
- Certificate: Valid GlobalSign Atlas R3 DV TLS CA 2025 Q4 → CN=
seekingalpha.com - Validity: 2025-12-09 00:01:00 UTC – 2027-01-10 00:00:30 UTC
- Serial:
01:FD:9F:5B:7B:69:0B:97:FF:B8:33:2C:60:FE:09:0F - Type: Authenticode
IMAGE_DIRECTORY_ENTRY_SECURITYat RVA0x244400, size0x8C8(2,240 bytes). PKCS#7 SignedData with SHA-256 digest. ^[pefile.txt:232] ^[binwalk.txt:9–10] - Significance: First observed ACRStealer sibling with a commercially-trusted DV TLS certificate rather than a self-signed
atom.hutsell.com/WR3orme.muz.li/R13chain. The cert is live and matches the legitimate financial-media domainseekingalpha.com, suggesting either certificate theft, reseller compromise, or registration under a lookalike/typosquat identity.
Resources
.rsrcsection contains 4 RT_ICON entries (1,128; 16,936; 67,624; 43,366 bytes) plus RT_GROUP_ICON. ^[pefile.txt]- The 256×256 PNG icon (67 KB) is the social-engineering masquerade surface, consistent with prior siblings. ^[binwalk.txt:7]
Anti-Analysis
- No debug checks, VM detection, or timing gates observed in static strings. Go binaries of this family rely on runtime C2 decoding and TLS pinning rather than sandbox evasion.
- No static C2 strings; all network indicators are PRNG-seeded or hardcoded as transformed byte arrays decoded at runtime. ^[prng-seeded-c2-url-decoding]
How It Works
The binary follows the established ACRStealer execution template documented on the acrstealer entity page:
- Bootstrap: Standard Go
runtime.mainentry →main.lzitkffq(entry function; name randomized per build). - API resolution: All Win32 APIs resolved via Go
syscallpackage linkage tokernel32.dll,advapi32.dll,crypt32.dll,ws2_32.dll,shell32.dll,ntdll.dll. No PEB-walking or custom hash resolution. ^[strings.txt:7146–7157] ^[strings.txt:7911–7917] - Network:
crypto/tls+net/httpclient used for C2 beaconing and exfiltration. Family-wide TTP: seed PRNG with system time, decode C2 strings via multi-pass transform. ^[prng-seeded-c2-url-decoding] - Collection: Inferred from family behaviour — browser credential stores (Chrome, Firefox, Edge), cryptocurrency wallets, FTP/SSH credentials, and system fingerprinting. No static confirmation in this sample (strings are runtime-decoded).
- Exfiltration: HTTPS POST to C2 endpoints. No static URL recovered.
Decompiled Behavior
Static-only; Ghidra/radare2 decompilation of Go 1.20.6 PE32 yields the standard runtime.main → main.main → randomized worker dispatch. The heavy main.* function count (90) maps to the same anti-clustering strategy seen in siblings b0bc17dd and 8f454dc1: every build gets a unique function-name fingerprint, defeating simple string-based IoC matching.
Notable Go runtime linkages observed:
runtime.netpollGenericInit,runtime.netpollready— async I/O poller for network operations. ^[strings.txt:3258]syscall.procWSASocketW,syscall.procWSAStartup— raw Winsock bootstrap. ^[strings.txt:7284–7291]internal/syscall/windows/registry— registry access for persistence or system fingerprinting. ^[strings.txt:7957]
No reflective loaders, process hollowing, or injection APIs observed statically.
C2 Infrastructure
- Static C2: None recovered.
- Inference: PRNG-seeded runtime decoding (family pattern). Historical siblings contacted
5.252.155.72,laserlogdnsop.icu,hertzfigblob.icu. ^[acrstealer] - Protocol: TLS-wrapped HTTPS (implied by
crypto/tlsandnet/httpimports).
Interesting Tidbits
- Certificate pivot: The
seekingalpha.comcert is a dramatic escalation in opsec — from self-signed certs that flag immediately in triage, to a DV TLS cert issued by a globally-trusted CA. If this is a stolen/resold cert, it explains the short validity window (~13 months) and the Dec 2025 issuance. - Go 1.20.6 divergence: The cluster shows no loyalty to a single Go minor version; builders rotate across 1.18.5, 1.20.6, 1.23.0, 1.25.4, and 1.26.2. This suggests the builder is a generic Go cross-compile script with a rotating toolchain parameter, not a fixed builder VM.
- Module path
UwKaCILheRgWMLk: 15-character randomized string, consistent with the 12–16 char pattern across all siblings. - PE32, not PE32+: While the cluster has trended x64 (
PE32+) in recent months, this build returns to 32-bit. Likely a builder arch toggle.
Deployable Signatures
YARA
rule ACRStealer_Go1206_GlobalSign_DVTLS {
meta:
description = "ACRStealer Go infostealer — Go 1.20.6+ PE32 with GlobalSign DV TLS cert CN=seekingalpha.com"
author = "PacketPursuit"
date = "2026-08-06"
sha256 = "f010585162a905c486b5ddd0cdae3ad5ad232c94a6091ed718692c8f72b0b68a"
strings:
$go_build = "go1.20.6"
$mod1 = "UwKaCILheRgWMLk"
$cert_cn = "seekingalpha.com"
$gs_ca = "GlobalSign Atlas R3 DV TLS CA"
$s1 = "runtime.main"
$s2 = "syscall.procWSAStartup"
$s3 = "crypto/tls"
condition:
uint16(0) == 0x5A4D and
$go_build and
($mod1 or ($cert_cn and $gs_ca)) and
2 of ($s*)
}
Behavioral Fingerprint
PE32 GUI executable compiled with Go 1.20.6 (
go:buildinfostrings), signed with GlobalSign DV TLS certificate CN=seekingalpha.com, containing 4 RT_ICON resources (including a 256×256 PNG). On execution, resolves Win32 APIs via standard Go syscall package, initializes Winsock and TLS client, and beacons to a runtime-decoded C2 over HTTPS. No static C2 strings. Heavy randomizedmain.*function namespace (90+ functions) defeats string-based clustering. No disk-write staging or process injection observed statically.
IOC List
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | f010585162a905c486b5ddd0cdae3ad5ad232c94a6091ed718692c8f72b0b68a |
hash |
| SHA-1 | 9e180e2a48a4170cb863c8446cabf3e7ff77bb3b |
hash (.text section) |
| ssdeep | 49152:oXcy7eA66RbpjEKnTpaIPQy7gHBYD1x3M1h:PieA3RbpDTpaIPb7gHK3qh |
hash |
| Certificate CN | seekingalpha.com |
signing |
| Certificate Issuer | GlobalSign Atlas R3 DV TLS CA 2025 Q4 |
signing |
| Certificate Serial | 01:FD:9F:5B:7B:69:0B:97:FF:B8:33:2C:60:FE:09:0F |
signing |
| Valid From | 2025-12-09 | signing |
| Valid To | 2027-01-10 | signing |
| Go module path | UwKaCILheRgWMLk |
build artefact |
| Entry function | main.lzitkffq |
build artefact |
Detection Signatures
| Technique | ID | Evidence |
|---|---|---|
| Data from Local System | T1005 | Inferred from family behaviour (browser credential store enumeration) |
| Credentials from Password Stores | T1555 | Inferred — Go infostealer family targeting browser SQLite/LevelDB stores |
| Exfiltration Over C2 Channel | T1041 | Inferred — crypto/tls + net/http beaconing |
| Standard Cryptographic Protocol | T1032 | TLS client via Go crypto/tls |
| Application Layer Protocol: Web Protocols | T1071.001 | HTTPS C2 beaconing (inferred from family TTPs) |
| Masquerading: Match Legitimate Name or Location | T1036.005 | GlobalSign-signed binary CN=seekingalpha.com; 4-icon .rsrc masquerade |
References
- acrstealer — ACRStealer family entity page (25 prior siblings, build-pattern analysis)
- golang-stealer-build-pattern — Recurring Go infostealer build artefacts
- prng-seeded-c2-url-decoding — Family-wide runtime C2 decoding technique
- OpenCTI labels:
acrstealer,urlhaus
Provenance
file.txt— file(1) outputstrings.txt— strings(1) extractionpefile.txt— pefile Python library section/import/resource dumprabin2-info.txt— radare2 binary header summarybinwalk.txt— binwalk embedded-artefact scanexiftool.json— ExifTool PE metadatametadata.json— OpenCTI artifact metadata- Certificate details extracted via
openssl x509 -inform DERonIMAGE_DIRECTORY_ENTRY_SECURITYblob at offset0x244408 - Go buildinfo and module path extracted via pefile Python library parsing
.rdata - Capa and floss tools failed (signature path missing / CLI argument error) — no output available ^[capa.txt] ^[floss.txt]
- Dynamic analysis skipped: CAPE has no Windows guest available ^[dynamic-analysis.md]
^[/intel/analyses/f010585162a905c486b5ddd0cdae3ad5ad232c94a6091ed718692c8f72b0b68a.html]