
Adware Operator Re-Signs Same Stale Build Across Two CAs
A twelve-file Authenticode cohort tied to 'OneBrowser' shows an operator repeatedly re-signing an eight-month-old executable under fresh certificates rather than rebuilding it. Compile timestamps stuck at 30 May 2025 sit against signing dates through early March 2026, revealing certificate churn as a distribution mechanic rather than active malware development.
A twelve-file Authenticode cohort tied to a Windows browser product called "OneBrowser" shows something unusual for a piece of adware: the operator kept re-signing the same eight-month-old executable under a fresh certificate every time the previous one lapsed. The pattern surfaces in a batch of files carrying the identical certificate serial 0E F9 0B 20 6A 1B 07 82 E0 D0 FD 33 88 24 EC 42, issued under a GoGetSSL G4 CS RSA4096 chain rooted in DigiCert, with Authenticode signing dates falling…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read