
Fake uTorrent Installer Uses Malformed Signature to Hide Decade-Old Adware
A Windows installer posing as uTorrent build 331 carries an Authenticode signature that fails validation outright, tied to a small purpose-built redirector cluster and flagged by 52 of 76 engines as InstallCore/DealPly adware. The case shows a decade-old trick — familiar branding plus a signature that merely looks legitimate — still working largely unchanged.
A Windows installer branded as uTorrent build 331 carries an Authenticode signature that fails validation outright — VirusTotal's own signing verdict states plainly that "the digital signature of the object is malformed," pointing analysts to the decade-old Microsoft security bulletin MS13-098 that documented exactly this class of forgeable signature block.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read