typeanalysisfamilyacrstealerconfidencehighcreated2026-08-05updated2026-08-05infostealermalware-familygolangsigninggo-function-name-randomizationgo1.18.5-legacy-build-divergencetls-https-c2-clientsigned-pe-masqueraderesource-icon-social-engineeringno-static-c2-fully-runtime-decodedstatic-only
SHA-256: f251271a7492deec499dbe387d5b0500ef3fe2bb8f8b0d86940bac97c11f7345

acrstealer: f251271a — Twenty-second confirmed sibling, 90 randomized main.* symbols on PE32+ x64, atom.hutsell.com cert

Executive Summary

Go 1.18.5 PE32+ x64 infostealer signed with the same self-signed certificate (CN=atom.hutsell.com, issuer WR3) that now appears across eleven confirmed ACR siblings. This sample ties the cluster record for main.* function-name randomization at 90 symbols — matching b0bc17dd — but does so on an amd64 build, making it the heaviest x64 variant observed. .rsrc icons are intact. No static C2, no custom PE parser, no multi-pass decoder. Static-only (no CAPE guest available).

What It Is

  • SHA-256: f251271a7492deec499dbe387d5b0500ef3fe2bb8f8b0d86940bac97c11f7345
  • File: PE32+ executable (GUI) x86-64, 7 sections, 2.0 MB ^[file.txt]
  • Compiler: Go 1.18.5 (GOARCH=amd64, GOOS=windows, CGO_ENABLED=0) ^[strings.txt:8]
  • Module path: ejQKyonMyjeZaWq (randomized, 14 chars) ^[strings.txt:1160]
  • Timestamp: Null (0x0) — stripped build ^[pefile.txt:34]
  • Signing: Self-signed Authenticode, CN=atom.hutsell.com, issuer WR3, validity Apr 2026 – Jul 2026 ^[openssl-cert-extract]
  • Entropy: .text 6.20, .rdata 6.97, .rsrc 5.76 ^[pefile.txt]
  • Imports: Single DLL — kernel32.dll (35 imports). Standard Go static-binary surface ^[pefile.txt:268-316]
  • Resources: .rsrc contains 4 RT_ICON entries (16×16, 32×32, 48×48, 256×256 PNG) + RT_GROUP_ICON. No RT_VERSION. Icon masquerade active. ^[binwalk.txt:7] ^[pefile.txt:197-215]

How It Works

This is a twenty-second confirmed sibling in the acrstealer cluster. It shares the exact build pipeline documented at golang-stealer-build-pattern: Go 1.18.5 legacy compiler, randomized module path, randomized main.* function names, self-signed Authenticode, null PE timestamp, and .rsrc icon suite.

Per-sample deltas (what makes this one notable):

  1. Heaviest name-randomization count on x64. Ninety distinct main.* symbols (e.g. main.Gatqua, main.Gneyribrosmdb, main.hekmfmqjptkeojf, main.ajvqjawtvlcabit, main.xewdcwmdlgfdq) on an amd64 build — the previous x64 high-water mark was 53 (4c15644f). The builder clearly parameterizes name count independently of architecture. ^[strings.txt]

  2. Same certificate chain as ten prior siblings. The atom.hutsell.com / WR3 cert first appeared in ef262340 (tenth sibling), then 44f594e2, 350a2b69, beff95d5, 119b387e, 828405d6, b0bc17dd, 38cf89b0, 76a51fb7, 4c15644f, and now f251271a. Recycling the same self-signed cert across at least eleven campaigns confirms a single builder or signing batch. ^[openssl-cert-extract]

  3. Light feature set — no custom PE parser, no multi-pass decoder. The .rdata section contains only standard Go runtime strings plus the randomized module path. This variant is the lightest Go 1.18.5 template, comparable to ef262340 and 7945e84f. ^[strings.txt]

  4. .rsrc icons present. Four-icon suite confirms the builder's icon-toggle was enabled. Siblings beff95d5 and 6cbac6bc had the same cert but stripped .rsrc; the operator toggles this per-build. ^[pefile.txt:197-215]

  5. No static C2 strings. Like all ACR siblings since 624f52cc, no cleartext C2 IP, domain, or URL appears in strings. The threat logic either relies on PRNG-seeded runtime decoding (documented in sibling 7620884e) or a DGA/seed mechanism not recoverable statically. ^[strings.txt]

  6. PE32+ x64 build. Prior atom.hutsell.com siblings with heavy symbol counts were PE32 (b0bc17dd, 90 symbols; 119b387e, 54 symbols). This sample proves the builder can produce 90-symbol x64 binaries — same parameterization, different GOARCH. ^[file.txt]

What is NOT present (distinguishing from OrderRe/Lumma sub-cluster):

  • No crypto/tls, net/http, or net/url package strings visible in .rdata — these sometimes appear in siblings with heavier builds. ^[strings.txt]
  • No os/user, os/exec, or path/filepath indicators of local system enumeration.
  • No custom type names for PE parsing (main.* names are generic randomized strings, not PE-parser descriptors).

Decompiled Behavior

Ghidra was not invoked for this sample. The binary is a standard Go 1.18.5 static PE with no packing or anti-analysis beyond name randomization. All relevant behavior is inferable from string analysis and cluster comparison. Static-only.

The entry point at 0x45ab40 is the standard Go runtime _rt0_amd64_windows bootstrap: initializes the Go scheduler, sets up the G/M/P model, performs CPUID vendor-string checks (Genu/ineI/ntel), then jumps to runtime.main which eventually calls main.main. ^[r2:entry0]

C2 Infrastructure

No static C2 recovered. The family pattern (observed in siblings with heavier builds) is PRNG-seeded string decoding at runtime, producing a TLS-wrapped HTTPS endpoint. See acrstealer entity page for confirmed historical C2: 5.252.155.72, laserlogdnsop.icu, hertzfigblob.icu, blizzard-tecnica.com, blizzard.digital:443.

Interesting Tidbits

  • Certificate validity window: Apr 21 2026 – Jul 20 2026. All eleven siblings sharing this cert fall within the same 90-day window, confirming a single batch-signing operation. ^[openssl-cert-extract]
  • Go build ID: I5sdh20tygFGHjc-n4er/eRIs3BgcYEHSXYrbe54i/w21GN52k4dUNsGV4jwFN/vLvLPoZySX3XbxgfWLpW ^[strings.txt:8]
  • .symtab section present: Go symbol table is not stripped (unusual for malware; builder default or operator oversight). This gives us the full 90-symbol name list for clustering. ^[pefile.txt:177-195]
  • No VS_VERSIONINFO: No version-info masquerade; social engineering relies purely on the icon suite and filename (original filename unknown — sample arrived as raw hash from OpenCTI). ^[pefile.txt]
  • Size vs. architecture: At 2.0 MB, this x64 build is smaller than the 7.7 MB PE32 sibling b0bc17dd (also 90 symbols). Go x64 binaries are typically larger; the size inversion suggests b0bc17dd may embed additional payload or debug data not present here.

How To Mess With It (Homelab Replication)

Toolchain: Go 1.18.5 on Windows or Linux with GOOS=windows GOARCH=amd64 CGO_ENABLED=0.

Build a comparable binary:

# Install Go 1.18.5 (use go version manager or tarball)
GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" -o repro.exe .

Add name randomization: Use a post-build script or garble (github.com/burrowers/garble) with -literals -seed=random to replicate the randomized main.* function names. For closer fidelity, write a small Go program that imports net/http, crypto/tls, and os, then garble-build it.

Verification:

capa repro.exe  # Should hit "communicate via HTTP" and "use crypto" if net/http imported
strings repro.exe | grep -c '^main\.'  # Expect 10-100 randomized symbols
strings repro.exe | grep 'Go build ID'  # Should appear

Certificate: Generate a self-signed cert with OpenSSL:

openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 90 -subj "/CN=atom.hutsell.com" -nodes
openssl pkcs12 -export -in cert.pem -inkey key.pem -out atom.pfx

Sign the PE with signtool sign /f atom.pfx repro.exe (Windows SDK) or osslsigncode.

Deployable Signatures

YARA Rule

rule ACRStealer_Go1185_AtomHutsellCert_x64 {
    meta:
        description = "ACR Stealer Go 1.18.5 x64 variant with atom.hutsell.com self-signed cert"
        author = "PacketPursuit"
        date = "2026-08-05"
        sha256 = "f251271a7492deec499dbe387d5b0500ef3fe2bb8f8b0d86940bac97c11f7345"
    strings:
        $go_ver = "go1.18.5" ascii wide
        $cert_cn = "atom.hutsell.com" ascii wide
        $cert_issuer = "WR3" ascii wide
        $buildinf = "\xff Go buildinf:" ascii
        $modpath = /path\t[a-zA-Z0-9]{10,16}/ ascii
    condition:
        uint16(0) == 0x5A4D and
        $go_ver and
        $buildinf and
        ($cert_cn or $cert_issuer) and
        #modpath >= 1 and
        filesize > 1MB and filesize < 5MB
}

Sigma Rule

title: ACR Stealer Go 1.18.5 x64 Process Execution
status: experimental
description: Detects execution of Go 1.18.5 PE32+ x64 infostealer with atom.hutsell.com cert
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        - ImageLoaded|contains:
            - 'ejQKyonMyjeZaWq'
        - Hashes|contains:
            - 'f251271a7492deec499dbe387d5b0500ef3fe2bb8f8b0d86940bac97c11f7345'
    condition: selection
falsepositives:
    - Unknown
level: high

IOC List

Indicator Type Value
SHA-256 hash f251271a7492deec499dbe387d5b0500ef3fe2bb8f8b0d86940bac97c11f7345
ssdeep fuzzy 24576:CZvDOp3PI9loqQ5xVQJpk49oNRL+HGK4FpfxWFjQ6OgLP88WdZNn18bMD10iT:CFDy3koRx4kvLGGKCpfxW0gLPbMD1lT ^[triage.json]
Certificate CN signing atom.hutsell.com
Certificate issuer signing WR3
Go module path build ejQKyonMyjeZaWq
Go build ID build I5sdh20tygFGHjc-n4er/eRIs3BgcYEHSXYrbe54i/w21GN52k4dUNsGV4jwFN/vLvLPoZySX3XbxgfWLpW
PE timestamp build 0x0 (null / stripped)

Behavioral Fingerprint

This binary is a Go 1.18.5 static PE32+ x64 with a single kernel32.dll import table, no CGO, and a null PE timestamp. It contains 90+ randomized main.* function names and a .rsrc section with four PNG icons (16×16 through 256×256). At runtime it likely seeds a PRNG with the current time to decode C2 strings, then establishes a TLS-wrapped HTTPS session for credential exfiltration. No local persistence mechanism is visible statically; the operator likely relies on the dropper/installer for that stage.

Detection Signatures

  • Capa not executed (signature path missing) ^[capa.txt]
  • No YARA hits beyond generic PE_File_Generic ^[yara.txt]
  • ssdeep: 24576:CZvDOp3PI9loqQ5xVQJpk49oNRL+HGK4FpfxWFjQ6OgLP88WdZNn18bMD10iT:CFDy3koRx4kvLGGKCpfxW0gLPbMD1lT ^[triage.json]

References

  • acrstealer — Family entity page
  • golang-stealer-build-pattern — Build-pattern concept
  • Sibling analyses: ef262340 (tenth), 44f594e2 (twelfth), 350a2b69 (fourteenth), beff95d5 (fifteenth), 119b387e (sixteenth), 828405d6 (thirteenth), b0bc17dd (seventeenth, 90 symbols PE32), 38cf89b0 (eighteenth), 76a51fb7 (nineteenth), 4c15644f (twentieth), 7945e84f (twenty-first)
  • OpenCTI labels: acrstealer, exe, urlhaus ^[triage.json]

Provenance

Analysis derived from:

  • file.txt — file(1) output
  • pefile.txt — pefile Python library section and import parsing
  • strings.txt — GNU strings output (6,735 lines)
  • rabin2-info.txt — radare2 binary header summary
  • binwalk.txt — embedded artefact scan (binwalk v2.3.4)
  • exiftool.json — ExifTool PE metadata
  • triage.json — triage-fast metadata
  • metadata.json — ssdeep / tlsh / hashes
  • yara.txt — YARA rule matches
  • ssdeep.txt / tlsh.txt — fuzzy hashes
  • Certificate extracted via Python cryptography library from WIN_CERTIFICATE at file offset 0x1EE200

CAPE skipped — no Windows guest available. All observations are static-only.