FILEMembers
FILE

A Code-Signing Chain That Fails on the Clock, Not the Crypto

A Win32 binary tied to the Snowglobe cluster's 'babar' malware carries an intact COMODO-to-Sectigo signing chain that only fails because its leaf certificate's 2015-2016 validity window has expired. Beneath that veneer sits a packed, zero-import executable that drew 50 of 74 static AV detections but only one inconclusive sandbox run, alongside two now-dormant 'api-'-prefixed C2 domains.

Sep 5, 2026, 06:54 (UTC+9)Last seenSep 5, 2026Severity62ByCTX TeamActorSnowglobeAnimal FarmIOC3MITRE17RegionsUS

A Win32 binary carrying a full COMODO-anchored code-signing chain isn't unusual — until you notice the validation failure has nothing to do with the signature itself. The file, chained through LLC "INTELEKT-SOFT" up through COMODO RSA Code Signing CA to Sectigo (formerly Comodo CA), fails verification purely because its leaf certificate's validity window — 21 September 2015 to 20 September 2016 — no longer covers the clock the verifier is checking against (35cf61c8b0…).

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence