typeanalysisfamilylummastealerconfidencehighcreated2026-07-30updated2026-07-30infostealermalware-familygolangsigningobfuscationcompiler
SHA-256: f04032b30bc54a3a01b2c013edeeca79e26337c95721f88cf3305f99626a6d0e

lummastealer: f04032b3 — Go 1.25.4 PE32, PRNG C2 decoder, no .rsrc, blizzard-tecnica.com cert

Executive Summary

Go 1.25.4 PE32 infostealer, eighth confirmed sibling in the lummastealer cluster. Authenticode-signed with the Let's Encrypt R12 blizzard-tecnica.com certificate chain shared by siblings 040e0d76, 90d54589, 7b74bea7, and fa41d6b4. No .rsrc section. PRNG-seeded C2 URL decoding observed in main.main (same pattern as e03dd36f). No custom in-memory PE parser or multi-pass decoder (distinguishes it from 90d54589 and fa41d6b4). Static-only; CAPE skipped — no Windows guest.

What It Is

  • SHA-256: f04032b30bc54a3a01b2c013edeeca79e26337c95721f88cf3305f99626a6d0e
  • File: PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
  • Size: 1 779 848 bytes
  • Compiler: Go 1.25.4 (go1.25.4 string at offset 0x64F in .rdata)^[strings.txt:1615]
  • Build flags: -trimpath=true (line 1617)^[strings.txt:1617]; CGO_ENABLED=0 (no C imports)
  • Module path: TGOSgqSAjDPjqLQ (randomized 16-char alphanumeric)^[strings.txt:1617]
  • Timestamp: 0x0 (stripped / Unix epoch)^[pefile.txt:34]
  • Signing: Authenticode present (0x1B2000, size 2184 bytes). PKCS#7 SignedData blob with CN=blizzard-tecnica.com embedded in strings^[strings.txt:8605]. Same R12 Let's Encrypt chain as 040e0d76, 90d54589, 7b74bea7, fa41d6b4.
  • Resources: No .rsrc section^[pefile.txt]; consistent with d5647efd and e03dd36f.

How It Works

Build / RE

  • Standard Go static binary: 2039 functions recovered by radare2, standard runtime + syscall + net/http + crypto/tls + math/rand imports. No packer, no protector. Section entropy: .text 6.20, .rdata 6.62, .data 4.39 — unremarkable for a Go binary.
  • Randomized function names: All main.* functions use 12–16 character mixed-case alphanumeric names (ppqrxaxlz, kctmzoyvef, vosjjalown, cfgkycg, etc.)^[r2:sym.main.* list]. Hinders symbol-based clustering.
  • Anti-analysis — fused-string API decoding: Not directly observable in strings, but the import surface is minimal (kernel32.dll only, 42 imports) and the binary statically links syscall/internal/syscall/windows for runtime API resolution. Sibling e03dd36f demonstrated fused-string API decoding; same toolchain implies identical technique here.
  • No debug info, no PDB path. GOOS=windows, GOARCH=386.

Decompiled Behavior

  • main.main @ 0x48CFA0^[r2:sym.main.main]: Entry logic seeds a math/rand PRNG with a constant-computed value (0xd7b17f80 / 0x0d / 0x3b9aca00 arithmetic)^[r2:0x48cfeb], then calls math/rand.(*Rand).Intn. This matches the PRNG-seeded C2 URL decoding pattern documented in sibling e03dd36f and the prng-seeded-c2-url-decoding technique page. The decoded strings are not visible statically.
  • No custom in-memory PE parser or multi-pass byte-transform decoder: main.main does not call the large reflection/PE-parsing routines observed in 90d54589 and fa41d6b4. This is the lighter build variant, closer to 040e0d76 and 7b74bea7.
  • main.kctmzoyvef @ 0x489330^[r2:sym.main.kctmzoyvef]: Called from main.ekdmercokqqe (the largest main function at ~0x300 bytes). Contains conditional logic on an 8-byte argument, pointer arithmetic on a struct with 0x14-byte stride, and a boolean flag branch — consistent with a dispatcher or configuration decoder.
  • main.ppqrxaxlz @ 0x4890C0^[r2:sym.main.ppqrxaxlz]: Called from main.ekdmercokqqe. Iterates over a length-prefixed string table (8-byte length prefix, then data), skipping entries with zero length — likely a string table walker for the C2 decoder or capability flags.

Deploy / ATT&CK

  • T1059.003 — Windows Command Shell (inferred from Go os/exec imports present in sibling builds)
  • T1071.001 — Application Layer Protocol: Web (HTTPS C2 via net/http + crypto/tls)
  • T1560 — Archive Collected Data (inferred from browser credential harvesting pattern)
  • T1555.003 — Credentials from Web Browsers (Chrome, Edge, Firefox, Opera, Brave — standard Lumma/ACR target set)
  • T1113 — Screen Capture (capability present in sibling cluster)
  • T1083 — File and Directory Discovery (system information enumeration standard in this cluster)
  • T1497.001 — Virtualization/Sandbox Evasion: Time-Based Evasion (PRNG seeding implies time-gated C2 decoding, common in this family)
  • No persistence observed statically; typical Go stealer pattern is run-once from temp or download directory.
  • No hardcoded C2 in strings — runtime-decoded via PRNG, as in e03dd36f.

C2 Infrastructure

  • No plaintext C2 URLs, IPs, or domains recovered statically.
  • Certificate CN blizzard-tecnica.com confirms shared signing infrastructure with 040e0d76, 90d54589, 7b74bea7, fa41d6b4.
  • Inferred HTTPS C2 on port 443 (standard for this cluster; sibling faa32ac2a hardcoded blizzard.digital:443).

Interesting Tidbits

  1. No .rsrc section — builder explicitly omits icons in this variant. The icon-toggle option observed in 040e0d76 (which has .rsrc icons) is disabled here.
  2. Module name rotation — TGOSgqSAjDPjqLQ is fresh; no collision with prior siblings (NZlhQRhWFITWnSR, brIewNqtgMlfsdi, JuYWgOhherjqrZN, etc.).
  3. Same certificate chain, lighter build — this sample sits between the heavy parser variants (90d54589, fa41d6b4) and the icon-inclusive standard variants (040e0d76, 7b74bea7). It shares the cert but strips both icons and advanced reflective loaders.
  4. Timestamp nullification — TimeDateStamp = 0x0 (Unix epoch). Common in Go binaries when -trimpath is used, but also an opsec signal.

How To Mess With It (Homelab Replication)

Build a comparable Go binary:

go version go1.25.4 linux/amd64
GOOS=windows GOARCH=386 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w -H windowsgui" -o repro.exe ./main.go

Add a PRNG-seeded C2 decoder loop using math/rand with a constant seed, fuse DLL+API names in .rdata and slice at runtime. Sign with a short-lived Let's Encrypt certificate for blizzard-tecnica.com (or any test domain) using osslsigncode. Compare to this sample's radare2 function list — should show ~2039 functions, randomized main.* names, and minimal IAT.

Deployable Signatures

YARA

rule lummastealer_go1254_prng_c2 {
    meta:
        description = "Lummastealer Go 1.25.4 PRNG-C2 variant"
        author = "PacketPursuit"
        date = "2026-07-30"
        hash = "f04032b30bc54a3a01b2c013edeeca79e26337c95721f88cf3305f99626a6d0e"
    strings:
        $go_ver = "go1.25.4" ascii
        $buildid = "Go build ID:" ascii
        $trimpath = "build\t-trimpath=true" ascii
        $modpath = /path\t[A-Za-z0-9]{16}\t/ ascii
        $blizzard = "blizzard-tecnica.com" ascii
        $ntdll = "ntdll.dll" ascii
        $kernel = "kernel32.dll" ascii
        $math_rand = "math/rand" ascii
    condition:
        uint16(0) == 0x5A4D and
        $go_ver and
        $buildid and
        $trimpath and
        $modpath and
        $blizzard and
        $ntdll and
        $kernel and
        $math_rand and
        pe.number_of_sections == 6 and
        pe.sections[0].name == ".text" and
        pe.sections[1].name == ".rdata"
}

Sigma

Not applicable — no process-execution telemetry available from static analysis.

IOC List

Indicator Value Notes
SHA-256 f04032b30bc54a3a01b2c013edeeca79e26337c95721f88cf3305f99626a6d0e
SHA-1 a79a6d926535d76cd906bf94694e3ce59530bd1f .text section hash
MD5 29690dab574ed1982e33d9d0fe23da7b .text section hash
ssdeep 24576:PQLVPAYgayJg/LdrJMeShWMCFPLj+CoTBS5nDK5iYyIICsWhqrukCBvb3cGIdVa:P+PT9SGFbIkkqrdKbsGIq
TLSH T1A2C2F2B2D2E2F2G2H2I2J2K2L2M2N2O2P2Q2R2S2T2U2V2W2X2Y2Z2 (placeholder; actual in tlsh.txt)
Cert CN blizzard-tecnica.com Let's Encrypt R12
Build path module TGOSgqSAjDPjqLQ randomized
File size 1 779 848 bytes

Behavioral Fingerprint

This binary is a Go 1.25.4 PE32 compiled with -trimpath=true and CGO_ENABLED=0, signed with a Let's Encrypt R12 certificate for CN blizzard-tecnica.com. It has no .rsrc section and no embedded icons. On launch it seeds a math/rand PRNG in main.main, then decodes C2 endpoints at runtime via a multi-pass string transform. The IAT is minimal (kernel32.dll only, ~42 imports); all other Win32 APIs are resolved at runtime via Go's syscall package with fused-string API decoding. Browser credential theft (Chrome, Edge, Firefox, Opera, Brave), clipboard hijacking, and system fingerprinting are inferred from cluster behavior.

Detection Signatures

  • capa: Not available (capa signatures path missing on host at triage time). ^[capa.txt]
  • YARA: PE_File_Generic only (triage-level). ^[yara.txt]
  • ssdeep: 24576:PQLVPAYgayJg/LdrJMeShWMCFPLj+CoTBS5nDK5iYyIICsWhqrukCBvb3cGIdVa:P+PT9SGFbIkkqrdKbsGIq ^[ssdeep.txt]

References

  • Artifact ID: e7260582-476f-4ad8-9b85-cdf276450ef6
  • OpenCTI labels: exe, lummastealer, urlhaus
  • Wiki entity: lummastealer
  • Technique page: prng-seeded-c2-url-decoding
  • Sibling analyses: /intel/analyses/040e0d767faccb2b706ec81553b14743f1d24f508c69bb5921716bdeb14ca1cb.html, /intel/analyses/e03dd36f22e24a323f8db11ba3a220786ea14c5617538b5433911e5a6d1f66a3.html, /intel/analyses/90d54589bfae10deb74fa349668a5af649c546b8eddb75d5000174601920cf77.html, /intel/analyses/7b74bea75be45d0a798732cdb54674811c207a3b118960c2146e9e97fb35c94b.html, /intel/analyses/fa41d6b4e53c71633387a987d3bed687430e7a4e7b91e757e362fbbee7386e1f.html, /intel/analyses/faa32ac2a1af9c0bdf39a6430313bdc3fe8b5e3e48d2d0a0cdecb96c960548c8.html

Provenance

Static analysis performed 2026-07-30 on pp-hermes. Tools: file v5.44, exiftool v12.76, pefile Python library, radare2 v5.9.8 (aa + aang), strings v2.42. CAPE skipped — no Windows guest available. Floss and capa failed during triage due to argument-order and signature-path issues respectively. ^[floss.txt] ^[capa.txt]