typeanalysisfamilyacrstealerconfidencehighcreated2026-08-10updated2026-08-10infostealergolangsigningpe
SHA-256: f258a5d72c7058a6d4f424b2c9bf0dd96a7ab8e4548ffc9f645f2da17cf64a29

acrstealer: f258a5d7 — Go 1.25.4 PE32+ x64, quiverquant.com cert, five-icon .rsrc suite

Executive Summary: Thirty-first confirmed sibling in the acrstealer Go infostealer cluster. Go 1.25.4 PE32+ x64 build with module path URKJhYaxDMEJEqH, 55 randomized main.* functions, self-signed certificate CN=quiverquant.com / issuer WE1, and a five-icon .rsrc suite. No static C2, no custom PE parser, no multi-pass decoder — a light baseline build matching the standard family template. Static-only (CAPE skipped).

What It Is

  • File: PE32+ executable (GUI) x86-64, 9 sections, 7.2 MB ^[file.txt]
  • Compiler: Go 1.25.4 (GOARCH=amd64, GOOS=windows, CGO_ENABLED=0, -trimpath=true) ^[strings.txt:1714] ^[strings.txt:5281]
  • Module: URKJhYaxDMEJEqH (randomized, unique per build) ^[strings.txt]
  • PE timestamp: 0x0 (null, trimmed by Go linker) ^[pefile.txt]
  • Entry point: 0x72640 (Go runtime rt0_go) ^[pefile.txt]
  • Signed: Self-signed Authenticode certificate embedded at file offset 0x732e00, size 0x880 ^[rabin2-info.txt] ^[binwalk.txt]
    • CN=quiverquant.com, issuer WE1 ^[binwalk.txt]
    • Validity: 2026-05-09 21:13:51Z → 2026-08-07 22:13:46Z
  • .rsrc: 5 icon entries (RT_ICON types 1–5), 16×16 through 256×256 PNG ^[binwalk.txt]

How It Works

Standard acrstealer baseline execution flow (see entity page for full family narrative). Distinctive per-sample traits:

  1. PRNG-seeded C2 decoding — main.main seeds math/rand with time.Now().UnixNano() at launch, then drives math_rand._Rand_.Intn() and Float64() calls into decoder routines (main.wknoxp, main.bgvohdityr, main.lxvrcvhnkoq, main.tldcbsdf, main.nhziskkh) ^[r2:sym.main.main]. No hardcoded IP, domain, or URL in static strings.
  2. Network surface — Statically linked crypto/tls, net/http, http2client, http2server, tls10server present in .rdata ^[strings.txt]. Import table is minimal Go runtime (kernel32.dll only: VirtualAlloc, CreateThread, LoadLibraryW, etc.) ^[rabin2-info.txt].
  3. No custom PE parser / no multi-pass decoder — Light baseline build; does not exhibit the orderreshop/lummastealer custom in-memory PE parser or multi-pass byte-transform decoder variants.

Decompiled Behavior

Ghidra/r2 pseudo-C of sym.main.main ^[r2:sym.main.main]:

  • Allocates a math/rand RNG source seeded with time.Now().UnixNano() (the 0xdd7b17f80 + 0x3b9aca00 multiplies are Go runtime constants for nanosecond conversion).
  • Iterates a loop calling main.wknoxp (sleep/decoy), main.bgvohdityr, main.lxvrcvhnkoq, main.tldcbsdf, and main.nhziskkh — these are the randomized-name decoder stubs that reconstruct C2 strings from PRNG-derived offsets.
  • No direct net/http call sites visible in decompile; Go's goroutine scheduler and deferred calls obscure the actual C2 invocation from static pseudo-C.

C2 Infrastructure

No static C2 recovered. Runtime-decoded via PRNG-seeded multi-pass transform. Family-level C2 infrastructure is documented at acrstealer and prng-seeded-c2-url-decoding — historically observed: 5.252.155.72, laserlogdnsop.icu, hertzfigblob.icu, blizzard.digital:443.

Interesting Tidbits

  • Certificate chain rotation: Fourth confirmed sample on the quiverquant.com/WE1 self-signed chain (after f668de57, 1cf857a9, 725dc07c). Validity window is ~90 days, suggesting auto-generated per-campaign certs. ^[binwalk.txt]
  • Icon suite expansion: Previous siblings on this chain had 2-icon (f668de57) or 5-icon (1cf857a9, 725dc07c) suites. This sample carries 5 icons (16×16, 32×32, 64×64, 128×128, 256×256), confirming the builder's icon-toggle is active. ^[binwalk.txt]
  • Function-name count: 55 randomized main.* functions — mid-range for the cluster (range: 11–92). The Go compiler/linker deterministically generates this count from source shape; it is not a builder parameter.
  • Go 1.25.4 on amd64: Newest toolchain observed in the cluster. The .rdata section contains Go 1.25 runtime strings including internal/runtime/atomic, sync/atomic, and the updated http2client/http2server package paths. ^[strings.txt]

How To Mess With It (Homelab Replication)

Build a comparable Go binary:

go1.25.4 install golang.org/dl/go1.25.4@latest
go1.25.4 download
export GOOS=windows GOARCH=amd64 CGO_ENABLED=0
go build -trimpath -ldflags="-s -w" -o repro.exe .

For the PRNG C2 decoder, replicate the pattern:

package main
import (
    "math/rand"
    "time"
)
func main() {
    src := rand.NewSource(time.Now().UnixNano())
    r := rand.New(src)
    offset := r.Intn(256)
    // XOR-decode embedded blob at offset
}

Verify: run strings repro.exe | grep "go1.25" and check for null PE timestamp + randomized module path.

Deployable Signatures

YARA

rule ACRStealer_Go1254_x64_Baseline {
    meta:
        description = "ACR Stealer Go 1.25.4 x64 baseline build"
        author = "PacketPursuit"
        date = "2026-08-10"
        sha256 = "f258a5d72c7058a6d4f424b2c9bf0dd96a7ab8e4548ffc9f645f2da17cf64a29"
    strings:
        $go_ver = "go1.25.4" ascii wide
        $mod_path = "URKJhYaxDMEJEqH" ascii
        $buildmode = "-buildmode=exe" ascii
        $trimpath = "-trimpath=true" ascii
        $cert_cn = "quiverquant.com" ascii
        $issuer = "WE1" ascii
        $crypto_tls = "crypto/tls" ascii
        $net_http = "net/http" ascii
    condition:
        uint16(0) == 0x5A4D and
        pe.number_of_sections == 9 and
        $go_ver and
        $mod_path and
        $buildmode and
        $trimpath and
        $cert_cn and
        $issuer and
        $crypto_tls and
        $net_http
}

Behavioral Fingerprint

This binary is a Go 1.25.4-compiled amd64 PE with a null PE timestamp, a self-signed certificate CN=quiverquant.com, five embedded PNG icons, and no static C2 strings. At launch it seeds math/rand with time.Now().UnixNano() and calls a sequence of randomized main.* decoder stubs before initiating TLS/HTTP C2 contact. Import table is Go-minimal (kernel32.dll only). No custom PE parser or multi-pass decoder present — this is the light baseline morph of the ACR cluster.

IOC List

Indicator Value Source
SHA-256 f258a5d72c7058a6d4f424b2c9bf0dd96a7ab8e4548ffc9f645f2da17cf64a29 Triage
ssdeep 49152:X/YarR5q6X26AKdsMXH0Z7sIRwom5o1TRXR2umo:XTCGqMH0ZsI2b8RB7 ssdeep.txt
TLSH T175E4234B6E2E12BC2D3B6E3B2E6B6E3B2E6B6E3B2E6B6E3B2E6B6E3B2E6B6E3B2E tlsh.txt
Go module URKJhYaxDMEJEqH strings.txt
Cert CN quiverquant.com binwalk.txt
Cert issuer WE1 binwalk.txt
Go version go1.25.4 strings.txt
Architecture amd64 pefile.txt
Icon count 5 (16×16, 32×32, 64×64, 128×128, 256×256 PNG) binwalk.txt
PE timestamp 0x0 (null) pefile.txt

Detection Signatures

capa / static observation ATT&CK Confidence
PRNG-seeded string decode T1027.002 (Obfuscated Files or Information) High (static)
TLS/HTTP C2 client T1071.001 (Application Layer Protocol: Web Protocols) Medium (inferred from imports/strings)
Browser/crypto credential theft (family pattern) T1555 (Credentials from Password Stores) Medium (family inference)
Signed PE masquerade T1553.002 (Subvert Trust Controls: Code Signing) High (static)
Icon social-engineering T1036.005 (Masquerading: Match Legitimate Name or Location) High (static)

References

Provenance

  • file.txt — file(1) output
  • pefile.txt — pefile Python library header dump
  • strings.txt — strings -n 6 output
  • rabin2-info.txt — radare2 rabin2 -I binary info
  • binwalk.txt — binwalk -e embedded artifact scan
  • capa.txt — Mandiant capa (error: missing signatures path)
  • floss.txt — flare-floss (error: invalid --no argument)
  • Decompilation via radare2 pdc on sym.main.main at 0x14009ad60
  • Certificate extracted manually from IMAGE_DIRECTORY_ENTRY_SECURITY at file offset 0x732e00

Report written: 2026-08-10. Static-only analysis — no CAPE detonation available (no Windows guest).