
One Reused Certificate Signs 20 Files in Wubi Input Adware Suite
All 20 VirusTotal-enriched components of a Chinese Wubi input-method installer share one identical DigiCert code-signing certificate, but detection data consistently points to adware.softcnapp rather than the trickbot/qakbot tags the upstream feed attached. Static engines flag the files heavily while every sandbox run comes back clean.
Twenty separate executables and DLLs packaged as components of "万能五笔输入法" — the Universal Wubi Input Method, a Chinese-language input tool — all carry the identical Authenticode signature from "Shanghai Oriental Webcasting Co. Ltd.," chained through DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, with the exact same certificate serial number (0B 03 D3 41 0E 57 67 8D F3 FC A1 3A 38 44 3E 84) stamped across every file.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read