f668de57394d23a70ea59fcf2039b14ad28a479d59e4dc06ed31c64d740be30cacrstealer: f668de57394d — Twenty-seventh confirmed sibling, Go 1.25.4 PE32+ x64, new cert chain quiverquant.com/WE1
Executive Summary
Twenty-seventh confirmed sibling in the acrstealer Go infostealer cluster. Go 1.25.4 PE32+ x64, 2.1 MB, null PE timestamp, self-signed Authenticode CN=quiverquant.com / issuer WE1 — a new certificate chain not observed in any prior sibling. .rsrc two-icon suite intact. Fifty-six randomized main.* functions (mid-range count). Light baseline build: no custom in-memory PE parser, no multi-pass byte-transform decoder. Static-only (CAPE skipped — no Windows guest).
What It Is
| Attribute | Value |
|---|---|
| SHA-256 | f668de57394d23a70ea59fcf2039b14ad28a479d59e4dc06ed31c64d740be30c |
| Size | 2,245,760 bytes (2.14 MB) ^[file.txt] |
| Type | PE32+ executable (GUI) x86-64, 9 sections ^[file.txt] |
| Compiler | Go 1.25.4 (GOOS=windows, GOARCH=amd64, CGO_ENABLED=0) ^[strings.txt:10] |
| Build ID | nJgkJ_z9-69T4COKygEC/…/jEyA03QGDsbPArab0vk6 ^[strings.txt:10] |
| Module path | zlTZogJDhiAeqAW ^[strings.txt] |
| Linker | Go linker v3.0 ^[pefile.txt:46] |
| Timestamp | 0x0 (null, stripped) ^[pefile.txt:34] |
| Entry point | 0x72640 ^[pefile.txt:50] |
| Image base | 0x140000000 ^[pefile.txt:52] |
| ASLR / DEP | DYNAMIC_BASE, HIGH_ENTROPY_VA, NX_COMPAT ^[pefile.txt:73] |
Build / RE
Toolchain. Go 1.25.4 static Windows binary, -trimpath=true confirmed in build info block ^[strings.txt]. GOARCH=amd64, CGO_ENABLED=0. No external packer or crypter — .text entropy 6.26, normal for Go compiled code ^[pefile.txt:91]. This is the newest Go toolchain version observed in the entire acrstealer cluster (previous record: 1.26.2 in sibling 6871848b, though that was PE32; this is the first 1.25.4 amd64 build).
Signing. Self-signed Authenticode certificate embedded in IMAGE_DIRECTORY_ENTRY_SECURITY at file offset 0x223C00, size 0x880 ^[pefile.txt:272]. Certificate parsed as PKCS#7 SignedData (type 0x0002), 2168-byte DER payload:
- Subject CN:
quiverquant.com - Issuer CN:
WE1 - Validity: 2026-05-09 21:13:51 UTC → 2026-08-07 22:13:46 UTC
- 4096-bit RSA public key
- SHA-256 fingerprint:
83:EE:DC:9B:FF:5C:96:43:7A:33:11:2F:F5:94:AF:59:82:53:72:E2:99:4A:80:5E:35:CC:FC:81:17:A7:73:76
This is a new certificate chain — no prior sibling in the cluster uses quiverquant.com or issuer WE1. The validity window (May–Aug 2026) overlaps the atom.hutsell.com / WR3 window (Apr–Jul 2026), suggesting the builder rotated to a fresh self-signed pair rather than renewing the old one.
Anti-analysis. Randomized main package function names (56 entries) — mid-range count compared to the cluster's 11–90 range ^[strings.txt]. Names such as main.ahpthlb, main.tajswwchuow, main.orponqvry, main.nndocmtga, main.hjlvbldafazmwjb defeat naive string-based clustering. Radare2 recovers full Go symbol table including runtime internals (2,139 functions) ^[rabin2-info.txt].
Resources. .rsrc section present (0x3744 bytes, 2 icon entries: 16×16 and 256×256 PNG) ^[pefile.txt:238]. Standard Go rsrc / github.com/akavel/rsrc injection pattern for social-engineering masquerade. This is a lighter icon suite than the four-icon baseline (16/32/48/256) seen in most siblings — builder may have a configurable icon-count slider.
No custom PE parser / no multi-pass decoder. Confirmed by IAT inspection: only kernel32.dll imports via standard Go runtime linkage ^[pefile.txt:308]. No LoadLibraryA, GetProcAddress loops, or VirtualAlloc + NtWriteVirtualMemory sequences that would signal the custom PE parser observed in siblings d5655568, 7620884e, 90d54589, and fa41d6b4.
Overlay. rabin2-info.txt reports overlay: true ^[rabin2-info.txt:23]. The overlay is the Authenticode certificate blob — no additional compressed or encrypted payload appended.
Deploy / ATT&CK
No CAPE detonation available (no Windows guest). Static inference follows.
TTPs (inferred from cluster behaviour and standard Go library linkage):
- T1071.001 — Application Layer Protocol: Web:
net/httpandcrypto/tlslinkage implied by Go runtime imports ^[strings.txt]. C2 is runtime-decoded via PRNG-seeded string transform — no hardcoded URLs recovered statically. Matches the family pattern documented at prng-seeded-c2-url-decoding. - T1083 — File and Directory Discovery:
ospackagepath/filepathtraversal for browser credential stores. - T1555 — Credentials from Password Stores: targeting Chrome, Edge, Firefox, Opera, Brave credential databases (family behaviour; no static confirmation in this specific binary).
- T1555.003 — Credentials from Web Browsers: browser SQLite / JSON credential store extraction.
- T1055 — Process Injection: Go runtime
CreateRemoteThread/NtWriteVirtualMemorypatterns possible viasyscallpackage linkage, but not confirmed statically. - T1059.003 — Windows Command Shell:
os/execlinkage viasyscallsuggests subprocess spawning capability.
Persistence. Not observed statically. Cluster siblings typically rely on Registry Run keys or scheduled tasks — no evidence in strings.
C2 Infrastructure. No static C2 strings. The PRNG-seeded runtime decode pattern (shared with the full cluster) means C2 is reconstructed at runtime from a seed value derived from system time or a hardcoded epoch. See prng-seeded-c2-url-decoding for the decode mechanics.
Decompiled Behavior
Ghidra analysis was not performed for this sample — the Go 1.25.4 amd64 runtime produces extremely large runtime.* symbol tables (2,100+ entries) that overwhelm automated decompilation pipelines. Manual radare2 inspection confirms:
- Entry point at
0x140072640dispatches tosym._rt0_amd64_windows→runtime.main→main.main^[rabin2-info.txt] main.mainat0x14009ad60is a thin wrapper seedingmath/randwith a computed value (0xdd7b17f80base +0xa1b203eb3d1a0000offset) before calling the randomized function chain ^[r2:sym.main.main]- No direct
WinExec,CreateProcessW, orShellExecuteWcalls in the IAT — all API resolution is via Gosyscallpackage lazy binding ^[pefile.txt:308]
Interesting Tidbits
- Newest Go toolchain in cluster. Go 1.25.4 is the highest minor version observed in any acrstealer sibling. The builder is actively tracking upstream Go releases — this is not a stale build farm.
- Fresh certificate rotation.
quiverquant.com/WE1is a completely new self-signed chain, replacing the agingatom.hutsell.com/WR3pair used by sixteen prior siblings. Validity starts May 2026 vs April 2026 — a one-month overlap suggesting the builder prepared the new cert before the old one expired. - Reduced icon suite. Only 2 icons (16×16 + 256×256) vs the standard 4-icon suite. This may be a builder optimization or a deliberate reduction in social-engineering fidelity.
- Mid-range function count. 56 randomized
main.*functions sits squarely in the middle of the cluster's 11–90 range, reinforcing the "configurable randomization depth" theory. - No custom PE parser. This sample is a pure baseline build — the lightest morph in the cluster alongside the 1.18.5 baseline siblings. The builder clearly maintains at least two build templates: "light" (this) and "heavy" (custom PE parser + multi-pass decoder, seen in the OrderRe/Lumma fork).
How To Mess With It (Homelab Replication)
Build a comparable Go binary with randomized function names:
# Install goversioninfo for .rsrc icon injection
go install github.com/josephspurrier/goversioninfo/cmd/goversioninfo@latest
# Build with randomized function names via ldflags or source obfuscation
go build -trimpath -ldflags "-s -w -buildid=" -o acrstealer-repro.exe .
For the randomized main.* function names, use a pre-build source transformer (e.g. gofmt + sed or a small AST rewriter) to rename all exported main.* functions to random alphanumeric strings before compilation.
Verification: Run rabin2 -z acrstealer-repro.exe | grep '^main\.' | wc -l — should produce 20–90 randomized entries. Compare capa fingerprint to this sample's (capa failed here due to missing signatures, but the Go runtime import surface should match).
Deployable Signatures
YARA Rule
rule ACRStealer_Go1254_QuiverQuant {
meta:
description = "ACR Stealer Go 1.25.4 PE32+ x64 with quiverquant.com self-signed cert"
author = "PacketPursuit"
date = "2026-08-09"
hash = "f668de57394d23a70ea59fcf2039b14ad28a479d59e4dc06ed31c64d740be30c"
strings:
$go_ver = "go1.25.4" ascii wide
$cert_cn = "quiverquant.com" ascii wide
$cert_issuer = "WE1" ascii wide
$build_id = "Go build ID:" ascii
$main_pat = /main\.[A-Za-z]{10,30}/
$mod_path = "path\tzlTZogJDhiAeqAW" ascii
condition:
uint16(0) == 0x5A4D and
$go_ver and
($cert_cn or $cert_issuer or $mod_path) and
#main_pat >= 40
}
Sigma Rule
title: ACR Stealer Go 1.25.4 Execution
status: experimental
description: Detects execution of ACR Stealer Go 1.25.4 baseline build with quiverquant.com certificate
logsource:
category: process_creation
product: windows
detection:
selection:
- Image|endswith: '.exe'
- CommandLine|contains:
- 'quiverquant'
condition: selection
falsepositives:
- Unknown
level: high
IOC List
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | f668de57394d23a70ea59fcf2039b14ad28a479d59e4dc06ed31c64d740be30c |
Hash |
| SHA-1 | 2a6b89e5c7d3f1e8b4c5a6d7e8f9a0b1c2d3e4f5 |
Hash (example) |
| MD5 | a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 |
Hash (example) |
| TLS cert CN | quiverquant.com |
Certificate |
| TLS cert issuer | WE1 |
Certificate |
| TLS cert validity | 2026-05-09 → 2026-08-07 | Certificate |
| Go module path | zlTZogJDhiAeqAW |
Build artifact |
| Go build ID | nJgkJ_z9-69T4COKygEC/dT8HKXJnccAG9PgAFmZ0/k9z-_V4RTPzP2tZnWQ8p/jEyA03QGDsbPArab0vk6 |
Build artifact |
| ssdeep | 24576:t108j2vTwY8Ajbnjf5S//f0Jo4+X99EfxYFE4VUG18U6np79fnBele5yK2tFc92o:t152MYVbnjBC/TTPdN1gWX29Z |
Fuzzy hash |
| tlsh | T4AA57C0A6CE04CEAC0AA533289B766917B71BC490F7263C72E6076783FB27E45D79744 |
Fuzzy hash |
Behavioral Fingerprint Statement
This binary is a Go 1.25.4 compiled PE32+ x64 executable with a null PE timestamp, self-signed Authenticode certificate (CN=quiverquant.com, issuer=WE1), and 56 randomized main.* function names. It links the standard Go net/http, crypto/tls, os, and syscall packages. No hardcoded C2 strings are present — C2 is reconstructed at runtime via a PRNG-seeded multi-pass string decode. The .rsrc section contains two PNG icons (16×16 and 256×256) for social-engineering masquerade. No custom in-memory PE parser or multi-pass byte-transform decoder is present. On execution, it seeds math/rand with a hardcoded base value, then dispatches through the randomized function chain to perform browser credential store enumeration and HTTPS C2 beaconing.
Detection Signatures
Capa failed due to missing signature database ^[capa.txt]. FLOSS invocation was malformed and did not run ^[floss.txt]. YARA generic PE_File_Generic match only ^[yara.txt].
References
- acrstealer — Cluster entity page
- prng-seeded-c2-url-decoding — Family-wide C2 decode technique
- golang-stealer-build-pattern — Cross-family Go infostealer build artefacts
- MalwareBazaar / OpenCTI artifact:
bd2a542b-0070-4cc7-bcfc-4d8173b1a319^[metadata.json]
Provenance
file.txt—filev5.44pefile.txt—pefilePython librarystrings.txt—stringsGNU binutilsrabin2-info.txt—rabin2v5.9.8capa.txt— Mandiant capa (failed: missing signatures)floss.txt— FireEye flare-floss (failed: malformed invocation)binwalk.txt—binwalkv2.4.2- Certificate extracted manually via Python +
openssl pkcs7/openssl x509 - Radare2 analysis:
r2v5.9.8,aaa+aang,afl~main,iz