A validly signed dropper carrying a stealer¶
At a glance
- Sample
3c6b036f2eebc124c17db51960d9f6c9b39e236e9a33d5ac0c3a3a2cabe36833.exe(1.8 MB, PE32+, RemusStealer set, signed 2026-07-16)- Question
- Windows says the signature is good, and the certificate is current. Does that make the file trustworthy, and where is the program it runs?
- You'll use
- Authenticode · Resource directory · Code analysis · Navigator strip ·
--hashes - Time
- about 5 minutes, nothing executed
The sample is copied to C:\MalwareSamples\. Every command below runs on Windows with ppee-cli.exe.
Step 1 Check the signature¶
PS> ppee-cli.exe --security C:\MalwareSamples\3c6b036f….exe
Security (certificate table): 1 entrie(s)
offset=1BAE00 length=12336 revision=0200 type=0002 sha256=81ED37…4384
Validity: SIGNED & VERIFIED
Signature #1 (certificate[0])
Digest Algorithm: SHA256
Embedded Digest (SHA256): 5E1100…BAFFA4
Authentihash (SHA256): 5E1100…BAFFA4
Signer Certificate:
Subject Name: DESIGN COLOUR AS (Private Organization, O=DESIGN COLOUR AS, C=NO)
Issuer Name: GlobalSign GCC R45 EV CodeSigning CA 2020
Valid: 2026/04/09 16:02:50 - 2027/04/10 16:02:50 UTC
TimeStamp kind: RFC3161 token
TimeDateStamp: 2026/07/16 07:54:21
| Row | Value | Meaning |
|---|---|---|
| Validity | SIGNED & VERIFIED | Windows (WinVerifyTrust) accepts the signature |
| Embedded digest / Authentihash | both 5E1100…BAFFA4 | The signed bytes are unchanged since signing |
| Issuer | GlobalSign GCC R45 EV CodeSigning CA 2020 | An Extended Validation certificate: the strictest vetting tier |
| Valid To | 2027-04-10 | The certificate is still valid today |
| Timestamp | RFC3161, 2026-07-16 | Signed recently, while the certificate was valid |
Because the certificate is current, the signature is not "expired" in the way an old one would be. That is why this sample is a good test: the signature check passes, and it still says nothing about what the program does.
The signature answers who signed it and whether the bytes changed. It says nothing about what the file does. EV certificates are vetted, but they are bought, rented and stolen too.
Step 2 Look for an overlay, then the resources¶
The signature sits in an overlay (the certificate table, offset 0x1BAE00, 12,336 bytes). Check whether anything else is appended:
PS> ppee-cli.exe --hash-range overlay C:\MalwareSamples\3c6b036f….exe
overlay offset=0x1BAE00 size=12336 entropy=7.626
The overlay is only the certificate table. There is no installer payload appended, unlike an installer. The data directories show a large resource directory (DataDirectory[2], 1.5 MB) instead, so the payload is probably in the resources:
PS> ppee-cli.exe --resources C:\MalwareSamples\3c6b036f….exe
#10 (RT_RCDATA)
#100
lang=#1033 offset=4C500 size=1515568 codePage=0 entropy=6.49614 typeDetected=PE File
first bytes: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 | MZ..........
RT_RCDATA/100is a 1.5 MB blob at entropy 6.5 whose first bytes areMZ: a whole PE file stored as a resource.- The rest of the resources are small icons. A dropper keeps its real program in one resource and only needs the loader code to start it.
Step 3 Read the embedded PE¶
PPEE can open the resource as a file of its own, with #resource: on the path:
PS> ppee-cli.exe --hashes "C:\MalwareSamples\3c6b036f….exe#resource:RT_RCDATA/100"
FileInfo:
SHA256: CEE89827F4E8E7E32EC9F0B484586283CD7E345BFA06F458CE631D4FA9C098BC
MD5: AC7A167EE7269BD790F220BB104CCA22
Entropy: 6.49614
ImpHash: CB361184DEE84C900F07807ADCCCD63A
PS> ppee-cli.exe --imports "C:\MalwareSamples\3c6b036f….exe#resource:RT_RCDATA/100"
SHELL32.dll - 1 function(s)
USER32.dll - 1 function(s)
KERNEL32.dll - 94 function(s)
- A PE32+ x64 file with 7 sections, subsystem 2 (GUI): a normal Windows program, not a console tool.
- Its import table is short, and most of its imports are plain kernel32 calls. The API names it uses for networking are stored as strings in the resource, not imported. That is the usual way to hide network use from a quick look at the imports.
- The embedded copy also carries its own certificate table, signed by the same signer. Its embedded digest matches its Authentihash, so the bytes are the ones that were signed. PPEE still reports this layer's validity as Broken: it is a resource layer, not a file on disk, so WinVerifyTrust can't check it the way it checks the outer file. Don't read that as "the payload is unsigned"; read it as "the payload has its own copy of the signature".
Step 4 See what the outer program does¶
The outer file is a small loader. Its code is short, and the analysis says what it does:
PS> ppee-cli.exe --analysis C:\MalwareSamples\3c6b036f….exe
Detected: x64 machine code
Run-time linking: GetModuleHandleW (2), GetProcAddress (3), LoadLibraryExW (4), GetModuleHandleExW (1)
Memory protection: VirtualProtect (3)
Debugger queries: IsDebuggerPresent (2)
Starting programs: ShellExecuteExW (1)
Decoded: 48693 instructions, 1232 functions
LoadLibraryExWandGetProcAddressare the loader's way to call APIs it doesn't import. This is why its import table is so small.VirtualProtectchanges memory permissions, which a loader needs to prepare the code it has just unpacked.ShellExecuteExWcan start a program. It is the step that runs the payload.IsDebuggerPresentis a classic anti-analysis check. Note it, but don't read more into it than that.- Repeated
cpuidcalls in the entry code look like an environment check, and theGetModuleFileNameWcall suggests the loader looks at where it runs from.
For the code itself, see the resource walkthrough and --xrefs, which trace the same resource.
Verdict
A genuine, current EV signature from DESIGN COLOUR AS, with an RFC3161 timestamp from 2026-07-16. The signed bytes are unchanged, and Windows verifies them. The signature covers the dropper and the stealer inside its resources: the embedded copy is part of the signed file. So the signer signed this program, whatever it does.
Report the signer and the certificate serial (68 7A E2 E8 C4 77 85 DB CA 41 41 33) to the issuing CA, and treat the embedded PE as the sample of interest: extract it in an isolated environment.
Hunting with the signer
The same certificate can sign other files in the set. Search your collection for it:
Get-ChildItem C:\MalwareSamples\*.exe | ForEach-Object {
ppee-cli.exe --no-similarity --json --security $_.FullName |
ConvertFrom-Json | ForEach-Object { $_.security.signatures } |
ForEach-Object { "$($_.signerCertificate.serialNumber)`t$($_.signerCertificate.subjectName)`t$($_.certificateIndex)" }
}
The similarity engine's Authentihash check groups re-signed copies of the same image.
More walkthroughs: all walkthroughs · From a URL to its call site
References¶
- MITRE ATT&CK T1553.002: Subvert Trust Controls: Code Signing: abusing a valid signature.
- Authenticode signing overview (Microsoft): how signatures and timestamps are produced and verified.