
Conduit-Signed Adware Dropper Achieved 6/54 Detections With Stomped Timestamps and C2 Victim Profiling
A 1.28 MB Windows installer signed with a legitimate Conduit Ltd. certificate suppressed detection by up to 50 antivirus engines while concealing a four-payload adware bundle. The campaign's command-and-control beacon encoded victim OS version and administrator privilege level as GET parameters before the server decided what to deliver, a structured triage technique unusual for adware distributors of the era.
A 1.28 MB Windows executable signed with a then-valid Conduit Ltd. code-signing certificate achieved just 6 of 54 possible antivirus detections while concealing a compressed multi-payload bundle in a resource section registering entropy of 8.0 — the maximum possible for a randomly distributed byte stream. That single file, the entry point for a vigram-family adware campaign targeting technology-sector users in Spain, illustrates a layered evasion architecture that goes well beyond commodity…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read