
Trojanized Ultrasurf Sample Wraps Genuine Signature in UPX Packer
A UPX-packed copy of the Ultrasurf/Ultrareach anti-censorship tool carries a legitimate but expired GlobalSign code-signing chain, drawing malicious or PUA verdicts from 19 of 74 engines while other vendors return nothing. Sandbox runs split evenly between clean and malicious, with one run naming the payload Glupteba2.
A copy of Ultrasurf — the anti-censorship proxy client used for over two decades by activists and ordinary internet users to route around national firewalls — is circulating in a UPX-packed form that nineteen of 74 engines now flag as trojan or PUA activity, even though the file still carries a genuine Ultrareach Internet Corp. code-signing chain.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read