
Expired Signature Still Fooled Users Two Years Later
A Win32 installer in the 'orcinius' PUP family carried a VeriSign code-signing chain that had lapsed sixteen months before VirusTotal ever saw it. Underneath sat a zero-import, oversized-data PE paired with a same-day-registered domain pair split into dedicated implant and configuration hosts.
A Win32 installer tagged to the commodity PUP family "orcinius" surfaced on VirusTotal on 2015-12-13 carrying a full three-tier code-signing chain — "Premium Installer; VeriSign Class 3 Code Signing 2010 CA; VeriSign" — and a verification status that reads, verbatim, "A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file." The leaf certificate issued to "Premium Installer" was valid from 1:00 AM on 7/13/2013…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read