
Validly Signed uTorrent Installer Hides Trojan.Offercore
A `utorrent_installer.exe` carries a fully valid BitTorrent Inc/DigiCert signature chain, yet 18 of 76 engines flag it as trojan.offercore. The payload leans on anti-sandbox timing and P2P-mimicking traffic to slip past defenses that trust signed code.
An executable calling itself utorrent_installer.exe carries a fully valid four-tier code-signing chain — BitTorrent Inc, chained up through DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 to DigiCert Trusted Root G4 — and yet 18 of 76 engines still flag it as trojan.offercore/r783575. That combination is the story here: not a forged certificate, but a genuine one riding on top of a payload the security industry has learned to distrust.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read