C&CMembers
C&C

Signed 2345HomePage Adware Installer Splits AV Detection in Two

A validly signed installer from Shanghai 2345 Mobile Technology is flagged by 31 of 77 antivirus engines as PUA, yet both sandboxes that ran it returned clean verdicts. The finding surfaces inside a Chinese phorpiex-tagged C2 cluster whose six-host certificate pool for *.2345.com and *.hao774.com remains unchanged from the prior snapshot.

Aug 19, 2026, 06:51 (UTC+9)Last seenAug 19, 2026Severity100ByCTX TeamIOC29MITRE20RegionsCN

A validly signed homepage-hijacking installer from Shanghai 2345 Mobile Technology Co., Ltd. is drawing detections from 31 of 77 antivirus engines, yet neither of the two sandboxes that detonated the file called it malicious. That split — a firm static-engine consensus sitting on top of a clean dynamic verdict — is the most concrete new finding to surface in this update to a Chinese command-and-control cluster carrying a phorpiex family tag and a financial-gain motivation.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence