
A Code-Signing Chain That Fails on the Clock, Not the Crypto
A Win32 binary tied to the Snowglobe cluster's 'babar' malware carries an intact COMODO-to-Sectigo signing chain that only fails because its leaf certificate's 2015-2016 validity window has expired. Beneath that veneer sits a packed, zero-import executable that drew 50 of 74 static AV detections but only one inconclusive sandbox run, alongside two now-dormant 'api-'-prefixed C2 domains.
A Win32 binary carrying a full COMODO-anchored code-signing chain isn't unusual — until you notice the validation failure has nothing to do with the signature itself. The file, chained through LLC "INTELEKT-SOFT" up through COMODO RSA Code Signing CA to Sectigo (formerly Comodo CA), fails verification purely because its leaf certificate's validity window — 21 September 2015 to 20 September 2016 — no longer covers the clock the verifier is checking against (35cf61c8b0…).
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read