FILEPublic
FILE

Expired Certificate Still Signs Circulating UltraSurf-Branded Binary

A packed executable branded as the anti-censorship tool UltraSurf/Ultrareach carries a code-signing certificate that lapsed in June 2024 but was still seen in submissions in July 2026. Underneath sits debugger-evasion tagging, long-sleep stalling, and Tor-routed egress, with sandboxes split on whether it's malicious.

Jul 20, 2026, 05:35 (UTC+9)Last seenJul 20, 2026Severity100ByCTX TeamActorMuddyWaterTEMP.ZagrosIOC5

A Circumvention Tool's Signature Outlives Its Certificate

A Win32 binary distributed under the UltraSurf and Ultrareach brand names — tools historically marketed as anti-censorship proxy utilities — carries a code-signing certificate from Ultrareach Internet Corp. that expired more than two years ago, yet the file was still circulating in submission traffic as recently as July 7, 2026. VirusTotal's certificate chain flags the leaf signature status outright as "not time valid," with validity running June 9, 2021 to June 9, 2024, even as the intermediate GlobalSign GCC R45 CodeSigning CA 2020 and its parent roots remain valid through 2029~2030. The result is a binary that looks signed at a glance — a green padlock's worth of legitimacy borrowed from a real vendor — while the actual trust anchor holding that signature together has quietly lapsed.

That mismatch alone would be a minor curiosity. What makes the sample (sha256 168e625c7eb51720f5ce1922aec6ad316b3aaca838bd864ee2bcdbd9b66171d0, 3,320 KB) worth a longer look is what sits underneath the signature: a maximally packed executable tagged for debugger detection, input-checking, and long sleep intervals, with a Tor-routing behavior tag stitched into the same file. Detection sits at 19 of 74 engines, and sandbox verdicts split cleanly down the middle — two calling it malicious, naming a family, two calling it clean. It's the kind of dual-use ambiguity that has made circumvention and proxy tools a durable low-cost vehicle for slipping payloads into a "legitimate software" category that many defenses are reluctant to block outright.

Inside the Packed Binary: Evasion Layered on Expired Trust

The file's internal structure tells a fairly explicit packing story. Its UPX0 section carries an entropy reading of 0.0 — essentially empty, a placeholder the unpacking stub will populate at runtime — while UPX1 registers entropy of 8.0, the theoretical maximum for a byte stream and a textbook signature of tight UPX compression. That combination triggers two separate hits from the kevoreilly-authored "UPX" YARA rule (sourced from the CAPEv2 sandbox project), which specifically detects UPX dumps at the original entry point, and a third hit from ditekSHen's "PUA_Win_UltraSurf" rule, purpose-built to flag UltraSurf/Ultrareach repackaging. Together those three rule hits corroborate what the tags already suggest: this isn't a stock UltraSurf installer, it's been run through a packer explicitly to blunt static analysis [T1027.002] before whatever payload sits inside gets to execute.

The delivery path backs that framing. Alternate filenames captured alongside the sample point to a portable-app bundle — a path referencing PortableApps and a file named UltraSurf_22.11.exe — and a temp-directory execution artifact (AppData\Local\Temp\qv0xvwcs.p4z\usf.exe) consistent with a self-extracting installer unpacking itself before running. Tags for "known-distributor" and "signed" reinforce that the intended delivery model leans on user trust in a familiar circumvention brand [T1204.002] rather than a cold dropped executable — the malicious value proposition here is riding a name users already associate with getting past censorship, not disguising itself as something novel.

Nine IDS rule hits round out the picture of what this binary does once running: a "Non-Standard IP protocol" alert, a spoofed DNS response with a one-minute TTL and no authority record, and a cluster of ICMP ping/echo signatures consistent with network reconnaissance activity. Three Sigma detections — one rated critical from the Joe Security rule set, and a medium/low pair from a general Sigma rule collection — add a second, independent layer of behavioral corroboration on top of the YARA hits. This is not a file that merely looks suspicious on paper; multiple independent rule authors, working from different angles, converged on flagging the same behaviors.

The Sandbox Split and What the Named Family Signals

Running the sample across four sandboxes produced a genuinely divided verdict, and the split is worth sitting with rather than glossing over. C2AE returned a malicious classification at 70% confidence and named the payload "Glupteba2," a trojan family label; Dr.Web's vxCube independently returned a malicious/malware verdict without a specific family name. DAS-Security Orcas and Zenbox, by contrast, both called the sample clean — Zenbox at full 100% confidence. Two of four calling it outright malicious, with one sandbox willing to attach a specific trojan family name, while two others see nothing worth flagging, is a pattern consistent with the file's own anti-analysis tagging: "detect-debug-environment," "checks-user-input," and "long-sleeps" together describe a binary built to behave differently depending on whether it believes it's being watched [T1497].

That behavioral hedge matters for how the Glupteba2 attribution should be read. A single sandbox naming a family, unconfirmed by the other three engines, is meaningfully weaker evidence than a cross-vendor consensus — it should be treated as a lead worth tracking, not a confirmed payload identity. What can be stated with more confidence is the pattern itself: a file wearing a legitimate anti-censorship tool's branding, riding an expired-but-plausible signature chain, exhibiting textbook sandbox-evasion tagging, and drawing a split verdict from automated analysis tools designed to catch exactly this kind of behavior.

The "via-tor" tag attached to the sample's own behavioral profile is the detail that ties this file conceptually to network anonymization, and it's the thread that connects the binary to the infrastructure discussed next — Tor-routed egress and VPN-style traffic anonymization sit on the same conceptual axis, even though nothing in the current record directly resolves this specific file to any specific IP [T1090.003].

Four IPs, Four Certificates, One Autonomous System

Sitting alongside the file indicator, and unconnected to it by any direct technical link, are four IP addresses that share a single autonomous system: AS6939, Hurricane Electric LLC. Two — 74.82.60.17 and 74.82.60.27 and 74.82.60.32 — sit inside the 74.82.60.0/23 block; the fourth, 64.62.219.46, sits in the adjacent 64.62.216.0/21 range. All four carry identical VirusTotal tags of "vpn" and "self-signed," and all four show 0 detections out of 91 engines, with zero community votes and a reputation score of 0 apiece — this cohort has no confirmed malicious activity attached to it at all.

What makes the four worth flagging is the certificate rotation pattern rather than any detection signal. Each IP presents its own distinct self-signed TLS certificate, each valid for exactly 30 days, and each carrying a different, plausible-sounding corporate identity that never repeats across nodes: 74.82.60.17 signs as "brexo.com" (valid June 25 to July 25, 2026), 64.62.219.46 as "jouchou.com" (June 9 to July 9), 74.82.60.27 as "wyong.com" (July 15 to August 14), and 74.82.60.32 as "waldeck.com" (July 17 to August 16). The issuance dates stagger roughly every two to five weeks between June 9 and July 17, 2026 — a cadence that reads less like organic infrastructure turnover and more like a scripted process spinning up replacement relay identities on a fixed hosting fabric.

That reading should be held loosely. No certificate serial, subject name, or DNS resolution in this record ties any of the four IPs back to the UltraSurf-branded file — the linkage exists only at the conceptual level, where a Tor-tagged binary and a cohort of "vpn, self-signed" IPs on the same ASN both point toward anonymized-egress tradecraft without actually touching each other in the data. Treating the AS6939 cluster as confirmed C2 infrastructure for this specific sample would outrun the evidence; treating it as a structurally interesting pattern that happens to sit in the same feed entry is the more defensible position, and it's the one the underlying analysis explicitly supports.

An Attribution Picture Too Crowded to Trust

The feed entry carrying this file and IP cohort attaches three named actor clusters — MuddyWater (also tracked as Seedworm, Static Kitten, Mercury, and Mango Sandstorm), Silent Chollima (overlapping with Andariel, Stonefly, and Onyx Sleet), and a cluster labeled Dalbit — plus a ransomware family tag, "hive," none of which surface anywhere in the file's own behavioral profile, build provenance, or rule matches. Iran-aligned espionage tooling, a DPRK-aligned cluster, and a ransomware family label sharing a single record with a repackaged VPN circumvention tool is a combination too heterogeneous to support any single coherent attribution. Motivation tags mix espionage and financial-gain in the same way — a reflection of the actor list's breadth rather than evidence about what actually drove this specific sample into the wild.

The honest read here is that current evidence does not support attributing this activity to any one of the named clusters, and stretching the file's UPX-packed, Tor-tagged behavior to fit a specific group's known playbook would be speculative. What the record supports is narrower and more useful: a single well-corroborated file indicator showing deliberate evasion engineering riding a lapsed trust chain, sitting near — but not proven to be operationally connected to — a set of IPs exhibiting infrastructure-recycling behavior on Hurricane Electric's network.

What a Stale Certificate on a Trusted Brand Still Buys an Operator

The durable lesson in this record isn't about a specific actor — it's about the persistent value of dual-use software categories as cover. UltraSurf and Ultrareach carry two decades of reputation as anti-censorship proxy tools, which means a binary bearing that name and a plausible, if expired, signature chain starts from a position of assumed legitimacy that many endpoint policies and users alike will extend automatically. Pairing that brand cover with maximal-entropy packing, sandbox-aware stalling, and Tor-tagged egress behavior describes an operator optimizing for exactly the gap between "looks like a known utility" and "behaves like it's evading analysis" — a gap that static detection and signature-trust models are structurally bad at closing.

The infrastructure sitting nearby reinforces the same theme from a different angle: even when no vendor engine flags a single one of four candidate relay IPs, a certificate-rotation cadence on a single ASN can still describe operational discipline — replacing short-lived self-signed identities on a fixed schedule is cheap, low-risk infrastructure hygiene whether or not it's tied to this particular file. For defenders and analysts tracking this space, the more transferable finding is procedural: a signed file whose signature has quietly expired should not inherit trust from the fact that it was once signed at all, and a hosting cluster's certificate-churn pattern is worth logging as a watch item long before any single node draws a detection. Neither observation closes the case on this sample — but together they describe a threat surface that keeps proving cheaper to exploit than most organizations' trust models account for.

Indicators of compromise5 indicators

Files

(1)

IPs

(4)
Source: CTX Threat Intelligence