f258a5d72c7058a6d4f424b2c9bf0dd96a7ab8e4548ffc9f645f2da17cf64a29acrstealer: f258a5d7 — Go 1.25.4 PE32+ x64, quiverquant.com cert, five-icon .rsrc suite
Executive Summary: Thirty-first confirmed sibling in the acrstealer Go infostealer cluster. Go 1.25.4 PE32+ x64 build with module path URKJhYaxDMEJEqH, 55 randomized main.* functions, self-signed certificate CN=quiverquant.com / issuer WE1, and a five-icon .rsrc suite. No static C2, no custom PE parser, no multi-pass decoder — a light baseline build matching the standard family template. Static-only (CAPE skipped).
What It Is
- File: PE32+ executable (GUI) x86-64, 9 sections, 7.2 MB ^[file.txt]
- Compiler: Go 1.25.4 (
GOARCH=amd64,GOOS=windows,CGO_ENABLED=0,-trimpath=true) ^[strings.txt:1714] ^[strings.txt:5281] - Module:
URKJhYaxDMEJEqH(randomized, unique per build) ^[strings.txt] - PE timestamp: 0x0 (null, trimmed by Go linker) ^[pefile.txt]
- Entry point:
0x72640(Go runtimert0_go) ^[pefile.txt] - Signed: Self-signed Authenticode certificate embedded at file offset
0x732e00, size0x880^[rabin2-info.txt] ^[binwalk.txt]- CN=
quiverquant.com, issuerWE1^[binwalk.txt] - Validity: 2026-05-09 21:13:51Z → 2026-08-07 22:13:46Z
- CN=
.rsrc: 5 icon entries (RT_ICON types 1–5), 16×16 through 256×256 PNG ^[binwalk.txt]
How It Works
Standard acrstealer baseline execution flow (see entity page for full family narrative). Distinctive per-sample traits:
- PRNG-seeded C2 decoding —
main.mainseedsmath/randwithtime.Now().UnixNano()at launch, then drivesmath_rand._Rand_.Intn()andFloat64()calls into decoder routines (main.wknoxp,main.bgvohdityr,main.lxvrcvhnkoq,main.tldcbsdf,main.nhziskkh) ^[r2:sym.main.main]. No hardcoded IP, domain, or URL in static strings. - Network surface — Statically linked
crypto/tls,net/http,http2client,http2server,tls10serverpresent in.rdata^[strings.txt]. Import table is minimal Go runtime (kernel32.dllonly:VirtualAlloc,CreateThread,LoadLibraryW, etc.) ^[rabin2-info.txt]. - No custom PE parser / no multi-pass decoder — Light baseline build; does not exhibit the
orderreshop/lummastealercustom in-memory PE parser or multi-pass byte-transform decoder variants.
Decompiled Behavior
Ghidra/r2 pseudo-C of sym.main.main ^[r2:sym.main.main]:
- Allocates a
math/randRNG source seeded withtime.Now().UnixNano()(the0xdd7b17f80+0x3b9aca00multiplies are Go runtime constants for nanosecond conversion). - Iterates a loop calling
main.wknoxp(sleep/decoy),main.bgvohdityr,main.lxvrcvhnkoq,main.tldcbsdf, andmain.nhziskkh— these are the randomized-name decoder stubs that reconstruct C2 strings from PRNG-derived offsets. - No direct
net/httpcall sites visible in decompile; Go's goroutine scheduler and deferred calls obscure the actual C2 invocation from static pseudo-C.
C2 Infrastructure
No static C2 recovered. Runtime-decoded via PRNG-seeded multi-pass transform. Family-level C2 infrastructure is documented at acrstealer and prng-seeded-c2-url-decoding — historically observed: 5.252.155.72, laserlogdnsop.icu, hertzfigblob.icu, blizzard.digital:443.
Interesting Tidbits
- Certificate chain rotation: Fourth confirmed sample on the
quiverquant.com/WE1self-signed chain (afterf668de57,1cf857a9,725dc07c). Validity window is ~90 days, suggesting auto-generated per-campaign certs. ^[binwalk.txt] - Icon suite expansion: Previous siblings on this chain had 2-icon (
f668de57) or 5-icon (1cf857a9,725dc07c) suites. This sample carries 5 icons (16×16, 32×32, 64×64, 128×128, 256×256), confirming the builder's icon-toggle is active. ^[binwalk.txt] - Function-name count: 55 randomized
main.*functions — mid-range for the cluster (range: 11–92). The Go compiler/linker deterministically generates this count from source shape; it is not a builder parameter. - Go 1.25.4 on amd64: Newest toolchain observed in the cluster. The
.rdatasection contains Go 1.25 runtime strings includinginternal/runtime/atomic,sync/atomic, and the updatedhttp2client/http2serverpackage paths. ^[strings.txt]
How To Mess With It (Homelab Replication)
Build a comparable Go binary:
go1.25.4 install golang.org/dl/go1.25.4@latest
go1.25.4 download
export GOOS=windows GOARCH=amd64 CGO_ENABLED=0
go build -trimpath -ldflags="-s -w" -o repro.exe .
For the PRNG C2 decoder, replicate the pattern:
package main
import (
"math/rand"
"time"
)
func main() {
src := rand.NewSource(time.Now().UnixNano())
r := rand.New(src)
offset := r.Intn(256)
// XOR-decode embedded blob at offset
}
Verify: run strings repro.exe | grep "go1.25" and check for null PE timestamp + randomized module path.
Deployable Signatures
YARA
rule ACRStealer_Go1254_x64_Baseline {
meta:
description = "ACR Stealer Go 1.25.4 x64 baseline build"
author = "PacketPursuit"
date = "2026-08-10"
sha256 = "f258a5d72c7058a6d4f424b2c9bf0dd96a7ab8e4548ffc9f645f2da17cf64a29"
strings:
$go_ver = "go1.25.4" ascii wide
$mod_path = "URKJhYaxDMEJEqH" ascii
$buildmode = "-buildmode=exe" ascii
$trimpath = "-trimpath=true" ascii
$cert_cn = "quiverquant.com" ascii
$issuer = "WE1" ascii
$crypto_tls = "crypto/tls" ascii
$net_http = "net/http" ascii
condition:
uint16(0) == 0x5A4D and
pe.number_of_sections == 9 and
$go_ver and
$mod_path and
$buildmode and
$trimpath and
$cert_cn and
$issuer and
$crypto_tls and
$net_http
}
Behavioral Fingerprint
This binary is a Go 1.25.4-compiled amd64 PE with a null PE timestamp, a self-signed certificate CN=quiverquant.com, five embedded PNG icons, and no static C2 strings. At launch it seeds math/rand with time.Now().UnixNano() and calls a sequence of randomized main.* decoder stubs before initiating TLS/HTTP C2 contact. Import table is Go-minimal (kernel32.dll only). No custom PE parser or multi-pass decoder present — this is the light baseline morph of the ACR cluster.
IOC List
| Indicator | Value | Source |
|---|---|---|
| SHA-256 | f258a5d72c7058a6d4f424b2c9bf0dd96a7ab8e4548ffc9f645f2da17cf64a29 |
Triage |
| ssdeep | 49152:X/YarR5q6X26AKdsMXH0Z7sIRwom5o1TRXR2umo:XTCGqMH0ZsI2b8RB7 |
ssdeep.txt |
| TLSH | T175E4234B6E2E12BC2D3B6E3B2E6B6E3B2E6B6E3B2E6B6E3B2E6B6E3B2E6B6E3B2E |
tlsh.txt |
| Go module | URKJhYaxDMEJEqH |
strings.txt |
| Cert CN | quiverquant.com |
binwalk.txt |
| Cert issuer | WE1 |
binwalk.txt |
| Go version | go1.25.4 |
strings.txt |
| Architecture | amd64 |
pefile.txt |
| Icon count | 5 (16×16, 32×32, 64×64, 128×128, 256×256 PNG) | binwalk.txt |
| PE timestamp | 0x0 (null) |
pefile.txt |
Detection Signatures
| capa / static observation | ATT&CK | Confidence |
|---|---|---|
| PRNG-seeded string decode | T1027.002 (Obfuscated Files or Information) | High (static) |
| TLS/HTTP C2 client | T1071.001 (Application Layer Protocol: Web Protocols) | Medium (inferred from imports/strings) |
| Browser/crypto credential theft (family pattern) | T1555 (Credentials from Password Stores) | Medium (family inference) |
| Signed PE masquerade | T1553.002 (Subvert Trust Controls: Code Signing) | High (static) |
| Icon social-engineering | T1036.005 (Masquerading: Match Legitimate Name or Location) | High (static) |
References
- Artifact ID:
f45fcb10-a94e-409e-ab4c-89a7c4dc2e6e^[metadata.json] - OpenCTI labels:
acrstealer,exe,urlhaus^[triage.json] - Family entity: acrstealer
- Build pattern: golang-stealer-build-pattern
- C2 decode technique: prng-seeded-c2-url-decoding
Provenance
file.txt—file(1)outputpefile.txt— pefile Python library header dumpstrings.txt—strings -n 6outputrabin2-info.txt— radare2rabin2 -Ibinary infobinwalk.txt—binwalk -eembedded artifact scancapa.txt— Mandiant capa (error: missing signatures path)floss.txt— flare-floss (error: invalid--noargument)- Decompilation via radare2
pdconsym.main.mainat0x14009ad60 - Certificate extracted manually from
IMAGE_DIRECTORY_ENTRY_SECURITYat file offset0x732e00
Report written: 2026-08-10. Static-only analysis — no CAPE detonation available (no Windows guest).