unclassified-go-pe32
Umbrella entity for Go-compiled PE32 (x86, not amd64) malware that shares garbled main.* function names and a stripped 32-bit build pattern. This is the first 32-bit Go sample in the corpus; all prior Go malware was PE32+ x64.
Overview
| Attribute | Value |
|---|---|
| First observed | 2026-05-29 (sample 9f7ee895) |
| Platform | Windows PE32 x86 |
| Compiler | Go toolchain (build ID present, version unrecoverable due to stripped buildinfo) |
| Build flags | -trimpath inferred; CGO_ENABLED=0 inferred |
| Architecture | GOARCH=386, GOOS=windows |
| Signing | Unsigned |
| Packing | None observed |
Build / RE
- 32-bit Go build — First
GOARCH=386malware in the corpus. Prior Go families (acrstealer,lummastealer,goloader,9d2ca3,54e64e,valetgate,afk-stealer) were allamd64. - Garbled
main.*names — 16 randomized mixed-case alphanumeric function names (8–20 chars) replacing human-readable symbols ^[raw/analyses/9f7ee895/strings.txt:652-900]. Same anti-static pattern as go-function-name-randomization, but on 32-bit. - Null PE timestamp —
TimeDateStamp: 0x0^[raw/analyses/9f7ee895/pefile.txt:66]. - Standard Go section layout —
.text,.rdata,.data,.idata,.reloc,.symtab,.rsrc(7 sections) ^[raw/analyses/9f7ee895/pefile.txt]. - Runtime API resolution — No static imports;
syscallpackage loads DLLs viaLoadLibraryA+GetProcAddressat runtime ^[raw/analyses/9f7ee895/strings.txt:29-43]. - No VM/debug checks in static strings.
Deploy / ATT&CK
Static-only analysis (CAPE skipped — no Windows guest). Inferred TTPs:
| ID | Technique | Evidence |
|---|---|---|
| T1027.002 | Obfuscated Files or Information | Go -trimpath + garbled main.* names |
| T1620 | Reflective Code Loading (potential) | Runtime-loaded imports suggest embedded payload possible |
| T1071 | Application Layer Protocol (potential) | ws2_32.dll referenced in syscall fragments; no C2 recovered |
Capabilities
go-386-windows-buildgo-garbled-main-function-namesnull-pe-timestampruntime-api-resolution-via-syscallstatic-only-analysis-no-c2-recovered
Notable Analyses
- /intel/analyses/9f7ee895f02870f62073c267bcb21bd85b063dc51c4c8ae1916d8f49670a7402.html — First observed sibling; 32-bit x86, 16 garbled names, zero static C2.
Related
- unclassified-go-pe64 — Sister cluster for Go PE64+ x64 samples with similar obfuscation.
- golang-stealer-build-pattern — Cross-family Go build artefacts (note: this cluster diverges by being 32-bit).
- go-function-name-randomization — Technique page for garbled
main.*names. - unattributed — Umbrella entity for low-confidence samples.