
Shared Imphash Links Pirated Keygen Trojan to Signed 2026 Installer
A single import-table hash connects a widely pirated 2024 keygen trojan flagged by 45 of 75 engines to a validly signed 2026 'Windows Manager' utility bundle that AV engines mostly miss. One of the signed files carries an agenttesla/msil label despite only one detection, exposing how signing can erase accumulated AV knowledge.
A Shared Build Fingerprint Ties a Pirated-Software Trojan to a Freshly Signed Utility Bundle
A single import-table hash — f34d5f2d4577ed6d9ceec516c1f5a744 — is the thread connecting two very different-looking files: a widely pirated 2024 keygen trojan detected by 45 of 75 engines on VirusTotal, and a pair of 2026 binaries carrying a valid, unexpired code-signing certificate from a company called YAMICSOFT SOLUTIONS LIMITED. The shared imphash spans 2f5b5a6269675678cb646eb0e38b8731937320f470f54dc88a131b1cce455974 (the keygen), 302164acb558195bb904cbd9107c990adf65a6706615b48be3dd1cbfebab05eb (HotkeyManager.exe), and c9f215efd230954027d0c80acb2a6e30d473fcdd3c6805f2eec256d5d17ebeb3 (1-ClickFixer.exe) — three files built, whatever their outward packaging, from the same compiler pipeline.
That overlap is the real story here, more than any single named actor. CTX Team's file-level analysis shows a build toolchain that appears comfortable moving between two very different distribution models: raw pirated-software lures that rack up hundreds of downloads and heavy detection, and a signed "system utility" installer that AV engines mostly wave through. It is a pattern that says more about how detection evasion is engineered today than about who, specifically, is running the operation — and the available data leaves that second question open.
The Certificate That Covers the Whole Bundle
The 2026 side of the cohort sits inside something called "Windows Manager 2.4.0 portable" — a bundle whose individual components (1-ClickFixer.exe, HotkeyManager.exe, and a DLL named WMPCL.dll) all carry an identical code-signing chain: YAMICSOFT SOLUTIONS LIMITED, chained through Certum Code Signing 2021 CA up to Certum Trusted Network CA 2. All three share the exact same certificate serial number — 6B 31 09 C4 FE FE 00 8A 44 60 23 33 80 F2 E6 B7 — and all three were signed at the identical timestamp, 08:46 PM on 07/22/2026 [T1553.002]. The certificate itself is not expired or malformed; it is valid from October 2025 through October 2028, giving the whole package the outward legitimacy of a properly maintained software vendor.
That is precisely what makes the pattern notable. One signing operation, one key, three files bundled into a single consumer download — and one of those three, 1-ClickFixer.exe, carries a threat label of agenttesla/msil. AgentTesla is a long-running commodity .NET credential stealer and keylogger family, and while the tagging here rests on a single flagging engine (VBA32, at 1 of 75 detections) rather than broad multi-engine consensus, the presence of that label inside a cohort otherwise reading as clean signed software is the kind of asymmetry that should draw a hunter's attention. HotkeyManager.exe and WMPCL.dll, its cert-siblings, show 0 of 75 detections and no threat label at all.
Whether the certificate itself reflects a compromised legitimate developer key or an attacker-registered signing identity built to impersonate a real "Yamicsoft" utility brand cannot be resolved from the indicators available here — that distinction matters for defenders (revocation versus takedown), but the file evidence alone does not settle it. What is clear is that all three signed components — plus the unsigned 2024 keygen — were run through the same generic packer, PEiD, a fingerprint the cohort index shows spanning all four files even though the DLL carries a different imphash (dae02f32a21e03ce65412f6e56942daa) from its three siblings. That uniform packing footprint across files that otherwise diverge in imphash is itself a signal: whoever assembled the "Windows Manager" bundle appears to have run a build-and-protect step over the whole package rather than over the malicious component in isolation.
From Cracked-Software Lure to Signed Installer: The Attack Chain
The mechanism that ties this cohort together starts, as so much consumer-facing crimeware does, with piracy. The outlier file in the set — 2f5b5a6269675678cb646eb0e38b8731937320f470f54dc88a131b1cce455974, internally named Yamicsoft.exe but distributed under filenames like "Yamicsoft_AIO_6in1_Patch_Keygen_v3.2_By_DFoX.exe" — has racked up 310 submissions from 240 unique sources since it first surfaced on 2024-11-05, a spread consistent with wide circulation through crack and keygen channels [T1204.002]. A Yomi Hunter sandbox verdict tags it outright malicious, and 45 of 75 engines concur.
Execution then pivots into a very different register. Two files bearing the same imphash — HotkeyManager.exe and 1-ClickFixer.exe — arrive already signed under the YAMICSOFT/Certum chain, giving the payload the outward appearance of a legitimate desktop utility rather than a keygen [T1553.002]. Defense evasion runs underneath both stages: PEiD packing appears across the full four-file set, and the keygen trojan and HotkeyManager.exe both carry high-entropy resource sections — 7.1 on the keygen's .rsrc, 6.2 on HotkeyManager's — consistent with packed or obfuscated payload content [T1027]. The keygen sample additionally carries behavioral tags for "checks-user-input" and "detect-debug-environment," patterns consistent with sandbox- and debugger-evasion checks that alter execution when a virtualized or instrumented environment is detected [T1497.002][T1622].
Persistence is the weakest link in the chain, and it should be read that way. WMPCL.dll's recorded alternate paths include both a plausible in-application location ("Win.Manager.2.4.Portable/App/Yamicsoft/WMPCL.dll.BAK") and an unrelated path pointing to an executable inside C:\Windows — a juxtaposition that is suggestive of a rename-and-drop technique used to disguise a payload DLL as a trusted system component [T1574.002], but the underlying evidence is thin enough that this stage rests on inference rather than confirmed behavior. The chain's endpoint is the AgentTesla-tagged 1-ClickFixer.exe, which trips a YARA rule named INDICATOR_SUSPICIOUS_EXE_RegKeyComb_IExecuteCommandCOM — a signature written to catch executables that embed command execution through the IExecuteCommand COM interface [T1056]. With only a single flagging engine and zero-of-one malicious sandbox verdicts behind it, this final collection step is a lead worth tracking, not a confirmed AgentTesla infection.
A Detection Gap Hiding in Plain Sight
The most operationally interesting finding here is not any one file's payload but the gap between them. The 2024 keygen sits at 45 of 75 engines flagging it, with a broad detection base spanning names like ALYac, AVG, AhnLab-V3, Bitdefender, CrowdStrike, ESET-NOD32, Microsoft, and Kaspersky's peers — the kind of consensus you would expect on a well-circulated, multiply-analyzed crimeware sample. Its 2026 cert-siblings tell the opposite story. HotkeyManager.exe and WMPCL.dll both sit at 0 of 75, with the same twenty-engine sample of misses (ALYac, APEX, AVG, Acronis, AhnLab-V3, and onward) recorded against them; 1-ClickFixer.exe manages exactly one detection out of 75, from VBA32 alone.
That divergence within a single signer cohort is the tradecraft tell. Signing a payload with a valid third-party certificate is a well-understood way to suppress heuristic and reputation-based detections that would otherwise fire on an unsigned binary [T1553.002] — and the numbers here bear that theory out almost too cleanly: same imphash lineage, same packer, same build window, but a forty-five-point swing in detection depending on whether the file ships signed or not. Sandbox coverage compounds the blind spot. Three of the four files in this cohort have at most a single sandbox engine's verdict recorded, and the DLL has none at all — meaning behavioral confirmation for the "Windows Manager" side of the cohort is currently limited to static and signature evidence rather than dynamic execution telemetry.
Named-rule coverage is similarly sparse but pointed. Beyond the COM-execution YARA hit on 1-ClickFixer.exe, the keygen trojan trips a Snort rule flagged "(port_scan) UDP portsweep" under attempted-reconnaissance — a generic network-behavior signature rather than anything family-specific. No named Sigma rule appears anywhere in this set. For a cohort built around a shared toolchain, the rule coverage is thinner than the file linkage itself, which is exactly the kind of scenario where imphash and certificate pivoting outperform signature hunting.
Where TA505 and RockLoader Fit — and Where They Don't
The upstream feed carrying this file set attributes it to TA505 — tracked elsewhere under aliases including Hive0065, SectorJ04, Graceful Spider, Chimborazo, Spandex Tempest, and Monty Spider — and tags the associated malware family as "rockloader." Neither label, notably, appears on any of the four files analyzed here; their own threat tags read trojan.lazy/msil and agenttesla/msil, not rockloader. That gap doesn't rule out the attribution, but it does mean the family story for this specific cohort is better told as "a cracked-software-adjacent build pipeline that has, at least once, produced an AgentTesla-flagged payload" than as a confirmed RockLoader operation.
The feed's motivation tag of "espionage" sits awkwardly against what the files actually show: a pirated-utility lure bundled with what looks, on current evidence, like a commodity credential-harvesting component — a profile that reads closer to opportunistic, profit-driven crimeware than tasked intelligence collection. No historical campaign parallel or named prior operation is available in the record to anchor this cohort to a documented TA505 chapter, and stretching the attribution across paragraphs would outrun what the indicators support. The honest position is that the actor label travels with this indicator set at the feed level, while the file-level fingerprints — the imphash, the shared cert, the packer footprint — are what actually establish the campaign's mechanics.
What a Bridging Toolchain Signals
The analytically interesting takeaway isn't which crew authored this — it's what the toolchain overlap implies about how detection-evading crimeware gets assembled. A build fingerprint that appears first in a heavily-detected, widely-pirated 2024 keygen and resurfaces in a near-invisible, validly-signed 2026 utility installer describes a laundering path: take a payload lineage that AV vendors have already learned to catch in one packaging, and re-issue it wrapped in a legitimate-looking signed bundle where the same engines currently see nothing. Whether that's a deliberate operational choice by a single group or a byproduct of a shared builder circulating among multiple crimeware operators, the effect on defender visibility is the same — detection built against the unsigned crimeware form does not transfer to the signed form, even though the underlying code shares its import table.
The population exposed to this pattern skews toward individual users and small organizations pulling pirated software or "system optimizer" utilities rather than any single sector; the indicator set's own industry tag reads simply "technology," and its geographic spread — more than two dozen countries across Europe, the Americas, and Asia-Pacific — points to broad, opportunistic distribution rather than a narrowly targeted intrusion campaign. That breadth, paired with thin sandbox coverage and modest multi-engine consensus on the signed components, argues for treating this as an early-stage observation rather than a fully characterized campaign. The signal worth carrying forward is the mechanism itself: a valid certificate and a shared build pipeline can erase forty-five detections' worth of accumulated AV knowledge overnight, and that is a more durable lesson than any single actor label attached to this file set.