
Installer Hides Its Only Flagged File Among Ten Clean Decoys
Ten PNG and CSS files from a generic setup wizard register zero detections, while a single packed, unsigned executable bundled alongside them trips eighteen antivirus engines. The split shows a trojanized installer where the scannable surface and the actual payload never overlap.
Ten PNG and CSS files with an identical creation moment sit alongside a single packed Windows executable that carries every detection in the set — a pairing that reads less like a malware family and more like the internals of an ordinary software installer, repurposed. The image assets are unremarkable on inspection: a close button, a hover state, a grey button, a progress bar, a stylesheet named main.css. Individually they register 0/53 to 0/57 across antivirus engines.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read