typeentityconfidencelowcreated2026-08-25updated2026-08-25malware-familygolangpeevasion

unclassified-go-pe32

Umbrella entity for Go-compiled PE32 (x86, not amd64) malware that shares garbled main.* function names and a stripped 32-bit build pattern. This is the first 32-bit Go sample in the corpus; all prior Go malware was PE32+ x64.

Overview

Attribute Value
First observed 2026-05-29 (sample 9f7ee895)
Platform Windows PE32 x86
Compiler Go toolchain (build ID present, version unrecoverable due to stripped buildinfo)
Build flags -trimpath inferred; CGO_ENABLED=0 inferred
Architecture GOARCH=386, GOOS=windows
Signing Unsigned
Packing None observed

Build / RE

  • 32-bit Go build — First GOARCH=386 malware in the corpus. Prior Go families (acrstealer, lummastealer, goloader, 9d2ca3, 54e64e, valetgate, afk-stealer) were all amd64.
  • Garbled main.* names — 16 randomized mixed-case alphanumeric function names (8–20 chars) replacing human-readable symbols ^[raw/analyses/9f7ee895/strings.txt:652-900]. Same anti-static pattern as go-function-name-randomization, but on 32-bit.
  • Null PE timestamp — TimeDateStamp: 0x0 ^[raw/analyses/9f7ee895/pefile.txt:66].
  • Standard Go section layout — .text, .rdata, .data, .idata, .reloc, .symtab, .rsrc (7 sections) ^[raw/analyses/9f7ee895/pefile.txt].
  • Runtime API resolution — No static imports; syscall package loads DLLs via LoadLibraryA + GetProcAddress at runtime ^[raw/analyses/9f7ee895/strings.txt:29-43].
  • No VM/debug checks in static strings.

Deploy / ATT&CK

Static-only analysis (CAPE skipped — no Windows guest). Inferred TTPs:

ID Technique Evidence
T1027.002 Obfuscated Files or Information Go -trimpath + garbled main.* names
T1620 Reflective Code Loading (potential) Runtime-loaded imports suggest embedded payload possible
T1071 Application Layer Protocol (potential) ws2_32.dll referenced in syscall fragments; no C2 recovered

Capabilities

  • go-386-windows-build
  • go-garbled-main-function-names
  • null-pe-timestamp
  • runtime-api-resolution-via-syscall
  • static-only-analysis-no-c2-recovered

Notable Analyses

  • /intel/analyses/9f7ee895f02870f62073c267bcb21bd85b063dc51c4c8ae1916d8f49670a7402.html — First observed sibling; 32-bit x86, 16 garbled names, zero static C2.

Related