FILEMembers
FILE

Valid 360 EV Certificate Still Gets Flagged by AV, Trips IDS

Four Windows binaries signed with a fully valid Qihu 360 EV code-signing certificate still draw adware/malware flags from a handful of antivirus engines, and two trigger an IDS signature for DNS contact with the signer's own domain. The case shows how certificate trust and detection coverage can diverge even under a legitimate signing chain.

Jul 13, 2026, 21:51 (UTC+9)Last seenJul 13, 2026Severity100ByCTX TeamActorSnowglobeAnimal FarmIOC17MITRE18

Four Windows binaries branded as a "游戏助手" (game assistant) utility package carry a fully valid Extended Validation code-signing chain from Beijing Qihu Technology Co., Ltd. — the entity behind the 360 security and gaming ecosystem — chained through GlobalSign GCC R45 EV CodeSigning CA 2020 under certificate serial 77 D9 12 68 10 B4 7A D8 41 65 66 51. That should be the strongest trust signal a Windows binary can carry.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence