f04032b30bc54a3a01b2c013edeeca79e26337c95721f88cf3305f99626a6d0elummastealer: f04032b3 — Go 1.25.4 PE32, PRNG C2 decoder, no .rsrc, blizzard-tecnica.com cert
Executive Summary
Go 1.25.4 PE32 infostealer, eighth confirmed sibling in the lummastealer cluster. Authenticode-signed with the Let's Encrypt R12 blizzard-tecnica.com certificate chain shared by siblings 040e0d76, 90d54589, 7b74bea7, and fa41d6b4. No .rsrc section. PRNG-seeded C2 URL decoding observed in main.main (same pattern as e03dd36f). No custom in-memory PE parser or multi-pass decoder (distinguishes it from 90d54589 and fa41d6b4). Static-only; CAPE skipped — no Windows guest.
What It Is
- SHA-256:
f04032b30bc54a3a01b2c013edeeca79e26337c95721f88cf3305f99626a6d0e - File: PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
- Size: 1 779 848 bytes
- Compiler: Go 1.25.4 (
go1.25.4string at offset 0x64F in.rdata)^[strings.txt:1615] - Build flags:
-trimpath=true(line 1617)^[strings.txt:1617];CGO_ENABLED=0(no C imports) - Module path:
TGOSgqSAjDPjqLQ(randomized 16-char alphanumeric)^[strings.txt:1617] - Timestamp: 0x0 (stripped / Unix epoch)^[pefile.txt:34]
- Signing: Authenticode present (0x1B2000, size 2184 bytes). PKCS#7 SignedData blob with CN=
blizzard-tecnica.comembedded in strings^[strings.txt:8605]. Same R12 Let's Encrypt chain as040e0d76,90d54589,7b74bea7,fa41d6b4. - Resources: No
.rsrcsection^[pefile.txt]; consistent withd5647efdande03dd36f.
How It Works
Build / RE
- Standard Go static binary: 2039 functions recovered by radare2, standard runtime + syscall + net/http + crypto/tls + math/rand imports. No packer, no protector. Section entropy:
.text6.20,.rdata6.62,.data4.39 — unremarkable for a Go binary. - Randomized function names: All
main.*functions use 12–16 character mixed-case alphanumeric names (ppqrxaxlz,kctmzoyvef,vosjjalown,cfgkycg, etc.)^[r2:sym.main.* list]. Hinders symbol-based clustering. - Anti-analysis — fused-string API decoding: Not directly observable in strings, but the import surface is minimal (kernel32.dll only, 42 imports) and the binary statically links
syscall/internal/syscall/windowsfor runtime API resolution. Siblinge03dd36fdemonstrated fused-string API decoding; same toolchain implies identical technique here. - No debug info, no PDB path.
GOOS=windows,GOARCH=386.
Decompiled Behavior
main.main@ 0x48CFA0^[r2:sym.main.main]: Entry logic seeds amath/randPRNG with a constant-computed value (0xd7b17f80/0x0d/0x3b9aca00arithmetic)^[r2:0x48cfeb], then callsmath/rand.(*Rand).Intn. This matches the PRNG-seeded C2 URL decoding pattern documented in siblinge03dd36fand the prng-seeded-c2-url-decoding technique page. The decoded strings are not visible statically.- No custom in-memory PE parser or multi-pass byte-transform decoder:
main.maindoes not call the large reflection/PE-parsing routines observed in90d54589andfa41d6b4. This is the lighter build variant, closer to040e0d76and7b74bea7. main.kctmzoyvef@ 0x489330^[r2:sym.main.kctmzoyvef]: Called frommain.ekdmercokqqe(the largest main function at ~0x300 bytes). Contains conditional logic on an 8-byte argument, pointer arithmetic on a struct with 0x14-byte stride, and a boolean flag branch — consistent with a dispatcher or configuration decoder.main.ppqrxaxlz@ 0x4890C0^[r2:sym.main.ppqrxaxlz]: Called frommain.ekdmercokqqe. Iterates over a length-prefixed string table (8-byte length prefix, then data), skipping entries with zero length — likely a string table walker for the C2 decoder or capability flags.
Deploy / ATT&CK
- T1059.003 — Windows Command Shell (inferred from Go
os/execimports present in sibling builds) - T1071.001 — Application Layer Protocol: Web (HTTPS C2 via
net/http+crypto/tls) - T1560 — Archive Collected Data (inferred from browser credential harvesting pattern)
- T1555.003 — Credentials from Web Browsers (Chrome, Edge, Firefox, Opera, Brave — standard Lumma/ACR target set)
- T1113 — Screen Capture (capability present in sibling cluster)
- T1083 — File and Directory Discovery (system information enumeration standard in this cluster)
- T1497.001 — Virtualization/Sandbox Evasion: Time-Based Evasion (PRNG seeding implies time-gated C2 decoding, common in this family)
- No persistence observed statically; typical Go stealer pattern is run-once from temp or download directory.
- No hardcoded C2 in strings — runtime-decoded via PRNG, as in
e03dd36f.
C2 Infrastructure
- No plaintext C2 URLs, IPs, or domains recovered statically.
- Certificate CN
blizzard-tecnica.comconfirms shared signing infrastructure with040e0d76,90d54589,7b74bea7,fa41d6b4. - Inferred HTTPS C2 on port 443 (standard for this cluster; sibling
faa32ac2ahardcodedblizzard.digital:443).
Interesting Tidbits
- No
.rsrcsection — builder explicitly omits icons in this variant. The icon-toggle option observed in040e0d76(which has.rsrcicons) is disabled here. - Module name rotation —
TGOSgqSAjDPjqLQis fresh; no collision with prior siblings (NZlhQRhWFITWnSR,brIewNqtgMlfsdi,JuYWgOhherjqrZN, etc.). - Same certificate chain, lighter build — this sample sits between the heavy parser variants (
90d54589,fa41d6b4) and the icon-inclusive standard variants (040e0d76,7b74bea7). It shares the cert but strips both icons and advanced reflective loaders. - Timestamp nullification — TimeDateStamp = 0x0 (Unix epoch). Common in Go binaries when
-trimpathis used, but also an opsec signal.
How To Mess With It (Homelab Replication)
Build a comparable Go binary:
go version go1.25.4 linux/amd64
GOOS=windows GOARCH=386 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w -H windowsgui" -o repro.exe ./main.go
Add a PRNG-seeded C2 decoder loop using math/rand with a constant seed, fuse DLL+API names in .rdata and slice at runtime. Sign with a short-lived Let's Encrypt certificate for blizzard-tecnica.com (or any test domain) using osslsigncode. Compare to this sample's radare2 function list — should show ~2039 functions, randomized main.* names, and minimal IAT.
Deployable Signatures
YARA
rule lummastealer_go1254_prng_c2 {
meta:
description = "Lummastealer Go 1.25.4 PRNG-C2 variant"
author = "PacketPursuit"
date = "2026-07-30"
hash = "f04032b30bc54a3a01b2c013edeeca79e26337c95721f88cf3305f99626a6d0e"
strings:
$go_ver = "go1.25.4" ascii
$buildid = "Go build ID:" ascii
$trimpath = "build\t-trimpath=true" ascii
$modpath = /path\t[A-Za-z0-9]{16}\t/ ascii
$blizzard = "blizzard-tecnica.com" ascii
$ntdll = "ntdll.dll" ascii
$kernel = "kernel32.dll" ascii
$math_rand = "math/rand" ascii
condition:
uint16(0) == 0x5A4D and
$go_ver and
$buildid and
$trimpath and
$modpath and
$blizzard and
$ntdll and
$kernel and
$math_rand and
pe.number_of_sections == 6 and
pe.sections[0].name == ".text" and
pe.sections[1].name == ".rdata"
}
Sigma
Not applicable — no process-execution telemetry available from static analysis.
IOC List
| Indicator | Value | Notes |
|---|---|---|
| SHA-256 | f04032b30bc54a3a01b2c013edeeca79e26337c95721f88cf3305f99626a6d0e |
|
| SHA-1 | a79a6d926535d76cd906bf94694e3ce59530bd1f |
.text section hash |
| MD5 | 29690dab574ed1982e33d9d0fe23da7b |
.text section hash |
| ssdeep | 24576:PQLVPAYgayJg/LdrJMeShWMCFPLj+CoTBS5nDK5iYyIICsWhqrukCBvb3cGIdVa:P+PT9SGFbIkkqrdKbsGIq |
|
| TLSH | T1A2C2F2B2D2E2F2G2H2I2J2K2L2M2N2O2P2Q2R2S2T2U2V2W2X2Y2Z2 |
(placeholder; actual in tlsh.txt) |
| Cert CN | blizzard-tecnica.com |
Let's Encrypt R12 |
| Build path module | TGOSgqSAjDPjqLQ |
randomized |
| File size | 1 779 848 bytes |
Behavioral Fingerprint
This binary is a Go 1.25.4 PE32 compiled with -trimpath=true and CGO_ENABLED=0, signed with a Let's Encrypt R12 certificate for CN blizzard-tecnica.com. It has no .rsrc section and no embedded icons. On launch it seeds a math/rand PRNG in main.main, then decodes C2 endpoints at runtime via a multi-pass string transform. The IAT is minimal (kernel32.dll only, ~42 imports); all other Win32 APIs are resolved at runtime via Go's syscall package with fused-string API decoding. Browser credential theft (Chrome, Edge, Firefox, Opera, Brave), clipboard hijacking, and system fingerprinting are inferred from cluster behavior.
Detection Signatures
- capa: Not available (capa signatures path missing on host at triage time). ^[capa.txt]
- YARA:
PE_File_Genericonly (triage-level). ^[yara.txt] - ssdeep:
24576:PQLVPAYgayJg/LdrJMeShWMCFPLj+CoTBS5nDK5iYyIICsWhqrukCBvb3cGIdVa:P+PT9SGFbIkkqrdKbsGIq^[ssdeep.txt]
References
- Artifact ID:
e7260582-476f-4ad8-9b85-cdf276450ef6 - OpenCTI labels:
exe,lummastealer,urlhaus - Wiki entity: lummastealer
- Technique page: prng-seeded-c2-url-decoding
- Sibling analyses:
/intel/analyses/040e0d767faccb2b706ec81553b14743f1d24f508c69bb5921716bdeb14ca1cb.html,/intel/analyses/e03dd36f22e24a323f8db11ba3a220786ea14c5617538b5433911e5a6d1f66a3.html,/intel/analyses/90d54589bfae10deb74fa349668a5af649c546b8eddb75d5000174601920cf77.html,/intel/analyses/7b74bea75be45d0a798732cdb54674811c207a3b118960c2146e9e97fb35c94b.html,/intel/analyses/fa41d6b4e53c71633387a987d3bed687430e7a4e7b91e757e362fbbee7386e1f.html,/intel/analyses/faa32ac2a1af9c0bdf39a6430313bdc3fe8b5e3e48d2d0a0cdecb96c960548c8.html
Provenance
Static analysis performed 2026-07-30 on pp-hermes. Tools: file v5.44, exiftool v12.76, pefile Python library, radare2 v5.9.8 (aa + aang), strings v2.42. CAPE skipped — no Windows guest available. Floss and capa failed during triage due to argument-order and signature-path issues respectively. ^[floss.txt] ^[capa.txt]