f251271a7492deec499dbe387d5b0500ef3fe2bb8f8b0d86940bac97c11f7345acrstealer: f251271a — Twenty-second confirmed sibling, 90 randomized main.* symbols on PE32+ x64, atom.hutsell.com cert
Executive Summary
Go 1.18.5 PE32+ x64 infostealer signed with the same self-signed certificate (CN=atom.hutsell.com, issuer WR3) that now appears across eleven confirmed ACR siblings. This sample ties the cluster record for main.* function-name randomization at 90 symbols — matching b0bc17dd — but does so on an amd64 build, making it the heaviest x64 variant observed. .rsrc icons are intact. No static C2, no custom PE parser, no multi-pass decoder. Static-only (no CAPE guest available).
What It Is
- SHA-256:
f251271a7492deec499dbe387d5b0500ef3fe2bb8f8b0d86940bac97c11f7345 - File: PE32+ executable (GUI) x86-64, 7 sections, 2.0 MB ^[file.txt]
- Compiler: Go 1.18.5 (
GOARCH=amd64,GOOS=windows,CGO_ENABLED=0) ^[strings.txt:8] - Module path:
ejQKyonMyjeZaWq(randomized, 14 chars) ^[strings.txt:1160] - Timestamp: Null (
0x0) — stripped build ^[pefile.txt:34] - Signing: Self-signed Authenticode, CN=
atom.hutsell.com, issuerWR3, validity Apr 2026 – Jul 2026 ^[openssl-cert-extract] - Entropy:
.text6.20,.rdata6.97,.rsrc5.76 ^[pefile.txt] - Imports: Single DLL —
kernel32.dll(35 imports). Standard Go static-binary surface ^[pefile.txt:268-316] - Resources:
.rsrccontains 4 RT_ICON entries (16×16, 32×32, 48×48, 256×256 PNG) + RT_GROUP_ICON. No RT_VERSION. Icon masquerade active. ^[binwalk.txt:7] ^[pefile.txt:197-215]
How It Works
This is a twenty-second confirmed sibling in the acrstealer cluster. It shares the exact build pipeline documented at golang-stealer-build-pattern: Go 1.18.5 legacy compiler, randomized module path, randomized main.* function names, self-signed Authenticode, null PE timestamp, and .rsrc icon suite.
Per-sample deltas (what makes this one notable):
-
Heaviest name-randomization count on x64. Ninety distinct
main.*symbols (e.g.main.Gatqua,main.Gneyribrosmdb,main.hekmfmqjptkeojf,main.ajvqjawtvlcabit,main.xewdcwmdlgfdq) on anamd64build — the previous x64 high-water mark was 53 (4c15644f). The builder clearly parameterizes name count independently of architecture. ^[strings.txt] -
Same certificate chain as ten prior siblings. The
atom.hutsell.com/WR3cert first appeared inef262340(tenth sibling), then44f594e2,350a2b69,beff95d5,119b387e,828405d6,b0bc17dd,38cf89b0,76a51fb7,4c15644f, and nowf251271a. Recycling the same self-signed cert across at least eleven campaigns confirms a single builder or signing batch. ^[openssl-cert-extract] -
Light feature set — no custom PE parser, no multi-pass decoder. The
.rdatasection contains only standard Go runtime strings plus the randomized module path. This variant is the lightest Go 1.18.5 template, comparable toef262340and7945e84f. ^[strings.txt] -
.rsrcicons present. Four-icon suite confirms the builder's icon-toggle was enabled. Siblingsbeff95d5and6cbac6bchad the same cert but stripped.rsrc; the operator toggles this per-build. ^[pefile.txt:197-215] -
No static C2 strings. Like all ACR siblings since
624f52cc, no cleartext C2 IP, domain, or URL appears in strings. The threat logic either relies on PRNG-seeded runtime decoding (documented in sibling7620884e) or a DGA/seed mechanism not recoverable statically. ^[strings.txt] -
PE32+ x64 build. Prior
atom.hutsell.comsiblings with heavy symbol counts were PE32 (b0bc17dd, 90 symbols;119b387e, 54 symbols). This sample proves the builder can produce 90-symbol x64 binaries — same parameterization, differentGOARCH. ^[file.txt]
What is NOT present (distinguishing from OrderRe/Lumma sub-cluster):
- No
crypto/tls,net/http, ornet/urlpackage strings visible in.rdata— these sometimes appear in siblings with heavier builds. ^[strings.txt] - No
os/user,os/exec, orpath/filepathindicators of local system enumeration. - No custom type names for PE parsing (
main.*names are generic randomized strings, not PE-parser descriptors).
Decompiled Behavior
Ghidra was not invoked for this sample. The binary is a standard Go 1.18.5 static PE with no packing or anti-analysis beyond name randomization. All relevant behavior is inferable from string analysis and cluster comparison. Static-only.
The entry point at 0x45ab40 is the standard Go runtime _rt0_amd64_windows bootstrap: initializes the Go scheduler, sets up the G/M/P model, performs CPUID vendor-string checks (Genu/ineI/ntel), then jumps to runtime.main which eventually calls main.main. ^[r2:entry0]
C2 Infrastructure
No static C2 recovered. The family pattern (observed in siblings with heavier builds) is PRNG-seeded string decoding at runtime, producing a TLS-wrapped HTTPS endpoint. See acrstealer entity page for confirmed historical C2: 5.252.155.72, laserlogdnsop.icu, hertzfigblob.icu, blizzard-tecnica.com, blizzard.digital:443.
Interesting Tidbits
- Certificate validity window: Apr 21 2026 – Jul 20 2026. All eleven siblings sharing this cert fall within the same 90-day window, confirming a single batch-signing operation. ^[openssl-cert-extract]
- Go build ID:
I5sdh20tygFGHjc-n4er/eRIs3BgcYEHSXYrbe54i/w21GN52k4dUNsGV4jwFN/vLvLPoZySX3XbxgfWLpW^[strings.txt:8] - .symtab section present: Go symbol table is not stripped (unusual for malware; builder default or operator oversight). This gives us the full 90-symbol name list for clustering. ^[pefile.txt:177-195]
- No VS_VERSIONINFO: No version-info masquerade; social engineering relies purely on the icon suite and filename (original filename unknown — sample arrived as raw hash from OpenCTI). ^[pefile.txt]
- Size vs. architecture: At 2.0 MB, this x64 build is smaller than the 7.7 MB PE32 sibling
b0bc17dd(also 90 symbols). Go x64 binaries are typically larger; the size inversion suggestsb0bc17ddmay embed additional payload or debug data not present here.
How To Mess With It (Homelab Replication)
Toolchain: Go 1.18.5 on Windows or Linux with GOOS=windows GOARCH=amd64 CGO_ENABLED=0.
Build a comparable binary:
# Install Go 1.18.5 (use go version manager or tarball)
GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" -o repro.exe .
Add name randomization: Use a post-build script or garble (github.com/burrowers/garble) with -literals -seed=random to replicate the randomized main.* function names. For closer fidelity, write a small Go program that imports net/http, crypto/tls, and os, then garble-build it.
Verification:
capa repro.exe # Should hit "communicate via HTTP" and "use crypto" if net/http imported
strings repro.exe | grep -c '^main\.' # Expect 10-100 randomized symbols
strings repro.exe | grep 'Go build ID' # Should appear
Certificate: Generate a self-signed cert with OpenSSL:
openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 90 -subj "/CN=atom.hutsell.com" -nodes
openssl pkcs12 -export -in cert.pem -inkey key.pem -out atom.pfx
Sign the PE with signtool sign /f atom.pfx repro.exe (Windows SDK) or osslsigncode.
Deployable Signatures
YARA Rule
rule ACRStealer_Go1185_AtomHutsellCert_x64 {
meta:
description = "ACR Stealer Go 1.18.5 x64 variant with atom.hutsell.com self-signed cert"
author = "PacketPursuit"
date = "2026-08-05"
sha256 = "f251271a7492deec499dbe387d5b0500ef3fe2bb8f8b0d86940bac97c11f7345"
strings:
$go_ver = "go1.18.5" ascii wide
$cert_cn = "atom.hutsell.com" ascii wide
$cert_issuer = "WR3" ascii wide
$buildinf = "\xff Go buildinf:" ascii
$modpath = /path\t[a-zA-Z0-9]{10,16}/ ascii
condition:
uint16(0) == 0x5A4D and
$go_ver and
$buildinf and
($cert_cn or $cert_issuer) and
#modpath >= 1 and
filesize > 1MB and filesize < 5MB
}
Sigma Rule
title: ACR Stealer Go 1.18.5 x64 Process Execution
status: experimental
description: Detects execution of Go 1.18.5 PE32+ x64 infostealer with atom.hutsell.com cert
logsource:
category: process_creation
product: windows
detection:
selection:
- ImageLoaded|contains:
- 'ejQKyonMyjeZaWq'
- Hashes|contains:
- 'f251271a7492deec499dbe387d5b0500ef3fe2bb8f8b0d86940bac97c11f7345'
condition: selection
falsepositives:
- Unknown
level: high
IOC List
| Indicator | Type | Value |
|---|---|---|
| SHA-256 | hash | f251271a7492deec499dbe387d5b0500ef3fe2bb8f8b0d86940bac97c11f7345 |
| ssdeep | fuzzy | 24576:CZvDOp3PI9loqQ5xVQJpk49oNRL+HGK4FpfxWFjQ6OgLP88WdZNn18bMD10iT:CFDy3koRx4kvLGGKCpfxW0gLPbMD1lT ^[triage.json] |
| Certificate CN | signing | atom.hutsell.com |
| Certificate issuer | signing | WR3 |
| Go module path | build | ejQKyonMyjeZaWq |
| Go build ID | build | I5sdh20tygFGHjc-n4er/eRIs3BgcYEHSXYrbe54i/w21GN52k4dUNsGV4jwFN/vLvLPoZySX3XbxgfWLpW |
| PE timestamp | build | 0x0 (null / stripped) |
Behavioral Fingerprint
This binary is a Go 1.18.5 static PE32+ x64 with a single kernel32.dll import table, no CGO, and a null PE timestamp. It contains 90+ randomized main.* function names and a .rsrc section with four PNG icons (16×16 through 256×256). At runtime it likely seeds a PRNG with the current time to decode C2 strings, then establishes a TLS-wrapped HTTPS session for credential exfiltration. No local persistence mechanism is visible statically; the operator likely relies on the dropper/installer for that stage.
Detection Signatures
- Capa not executed (signature path missing) ^[capa.txt]
- No YARA hits beyond generic
PE_File_Generic^[yara.txt] - ssdeep:
24576:CZvDOp3PI9loqQ5xVQJpk49oNRL+HGK4FpfxWFjQ6OgLP88WdZNn18bMD10iT:CFDy3koRx4kvLGGKCpfxW0gLPbMD1lT^[triage.json]
References
- acrstealer — Family entity page
- golang-stealer-build-pattern — Build-pattern concept
- Sibling analyses:
ef262340(tenth),44f594e2(twelfth),350a2b69(fourteenth),beff95d5(fifteenth),119b387e(sixteenth),828405d6(thirteenth),b0bc17dd(seventeenth, 90 symbols PE32),38cf89b0(eighteenth),76a51fb7(nineteenth),4c15644f(twentieth),7945e84f(twenty-first) - OpenCTI labels:
acrstealer,exe,urlhaus^[triage.json]
Provenance
Analysis derived from:
file.txt— file(1) outputpefile.txt— pefile Python library section and import parsingstrings.txt— GNU strings output (6,735 lines)rabin2-info.txt— radare2 binary header summarybinwalk.txt— embedded artefact scan (binwalk v2.3.4)exiftool.json— ExifTool PE metadatatriage.json— triage-fast metadatametadata.json— ssdeep / tlsh / hashesyara.txt— YARA rule matchesssdeep.txt/tlsh.txt— fuzzy hashes- Certificate extracted via Python
cryptographylibrary from WIN_CERTIFICATE at file offset0x1EE200
CAPE skipped — no Windows guest available. All observations are static-only.