Skip to content

A validly signed dropper carrying a stealer

At a glance

Sample
3c6b036f2eebc124c17db51960d9f6c9b39e236e9a33d5ac0c3a3a2cabe36833.exe (1.8 MB, PE32+, RemusStealer set, signed 2026-07-16)
Question
Windows says the signature is good, and the certificate is current. Does that make the file trustworthy, and where is the program it runs?
You'll use
Authenticode · Resource directory · Code analysis · Navigator strip · --hashes
Time
about 5 minutes, nothing executed

The sample is copied to C:\MalwareSamples\. Every command below runs on Windows with ppee-cli.exe.

Step 1 Check the signature

PS> ppee-cli.exe --security C:\MalwareSamples\3c6b036f….exe
Security (certificate table): 1 entrie(s)
  offset=1BAE00 length=12336 revision=0200 type=0002 sha256=81ED37…4384
  Validity: SIGNED & VERIFIED
  Signature #1 (certificate[0])
    Digest Algorithm: SHA256
    Embedded Digest (SHA256): 5E1100…BAFFA4
    Authentihash (SHA256):    5E1100…BAFFA4
    Signer Certificate:
      Subject Name: DESIGN COLOUR AS  (Private Organization, O=DESIGN COLOUR AS, C=NO)
      Issuer Name:  GlobalSign GCC R45 EV CodeSigning CA 2020
      Valid: 2026/04/09 16:02:50 - 2027/04/10 16:02:50 UTC
    TimeStamp kind: RFC3161 token
    TimeDateStamp: 2026/07/16 07:54:21
Row Value Meaning
Validity SIGNED & VERIFIED Windows (WinVerifyTrust) accepts the signature
Embedded digest / Authentihash both 5E1100…BAFFA4 The signed bytes are unchanged since signing
Issuer GlobalSign GCC R45 EV CodeSigning CA 2020 An Extended Validation certificate: the strictest vetting tier
Valid To 2027-04-10 The certificate is still valid today
Timestamp RFC3161, 2026-07-16 Signed recently, while the certificate was valid

Because the certificate is current, the signature is not "expired" in the way an old one would be. That is why this sample is a good test: the signature check passes, and it still says nothing about what the program does.

The signature answers who signed it and whether the bytes changed. It says nothing about what the file does. EV certificates are vetted, but they are bought, rented and stolen too.

Step 2 Look for an overlay, then the resources

The signature sits in an overlay (the certificate table, offset 0x1BAE00, 12,336 bytes). Check whether anything else is appended:

PS> ppee-cli.exe --hash-range overlay C:\MalwareSamples\3c6b036f….exe
overlay  offset=0x1BAE00 size=12336 entropy=7.626

The overlay is only the certificate table. There is no installer payload appended, unlike an installer. The data directories show a large resource directory (DataDirectory[2], 1.5 MB) instead, so the payload is probably in the resources:

PS> ppee-cli.exe --resources C:\MalwareSamples\3c6b036f….exe
  #10 (RT_RCDATA)
    #100
      lang=#1033 offset=4C500 size=1515568 codePage=0 entropy=6.49614 typeDetected=PE File
        first bytes: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 | MZ..........
  • RT_RCDATA/100 is a 1.5 MB blob at entropy 6.5 whose first bytes are MZ: a whole PE file stored as a resource.
  • The rest of the resources are small icons. A dropper keeps its real program in one resource and only needs the loader code to start it.

Step 3 Read the embedded PE

PPEE can open the resource as a file of its own, with #resource: on the path:

PS> ppee-cli.exe --hashes "C:\MalwareSamples\3c6b036f….exe#resource:RT_RCDATA/100"
FileInfo:
  SHA256:  CEE89827F4E8E7E32EC9F0B484586283CD7E345BFA06F458CE631D4FA9C098BC
  MD5:     AC7A167EE7269BD790F220BB104CCA22
  Entropy: 6.49614
  ImpHash: CB361184DEE84C900F07807ADCCCD63A
PS> ppee-cli.exe --imports "C:\MalwareSamples\3c6b036f….exe#resource:RT_RCDATA/100"
  SHELL32.dll  - 1 function(s)
  USER32.dll   - 1 function(s)
  KERNEL32.dll - 94 function(s)
  • A PE32+ x64 file with 7 sections, subsystem 2 (GUI): a normal Windows program, not a console tool.
  • Its import table is short, and most of its imports are plain kernel32 calls. The API names it uses for networking are stored as strings in the resource, not imported. That is the usual way to hide network use from a quick look at the imports.
  • The embedded copy also carries its own certificate table, signed by the same signer. Its embedded digest matches its Authentihash, so the bytes are the ones that were signed. PPEE still reports this layer's validity as Broken: it is a resource layer, not a file on disk, so WinVerifyTrust can't check it the way it checks the outer file. Don't read that as "the payload is unsigned"; read it as "the payload has its own copy of the signature".

Step 4 See what the outer program does

The outer file is a small loader. Its code is short, and the analysis says what it does:

PS> ppee-cli.exe --analysis C:\MalwareSamples\3c6b036f….exe
Detected: x64 machine code
Run-time linking: GetModuleHandleW (2), GetProcAddress (3), LoadLibraryExW (4), GetModuleHandleExW (1)
Memory protection: VirtualProtect (3)
Debugger queries: IsDebuggerPresent (2)
Starting programs: ShellExecuteExW (1)
Decoded: 48693 instructions, 1232 functions
  • LoadLibraryExW and GetProcAddress are the loader's way to call APIs it doesn't import. This is why its import table is so small.
  • VirtualProtect changes memory permissions, which a loader needs to prepare the code it has just unpacked.
  • ShellExecuteExW can start a program. It is the step that runs the payload.
  • IsDebuggerPresent is a classic anti-analysis check. Note it, but don't read more into it than that.
  • Repeated cpuid calls in the entry code look like an environment check, and the GetModuleFileNameW call suggests the loader looks at where it runs from.

For the code itself, see the resource walkthrough and --xrefs, which trace the same resource.

Verdict

A genuine, current EV signature from DESIGN COLOUR AS, with an RFC3161 timestamp from 2026-07-16. The signed bytes are unchanged, and Windows verifies them. The signature covers the dropper and the stealer inside its resources: the embedded copy is part of the signed file. So the signer signed this program, whatever it does.

Report the signer and the certificate serial (68 7A E2 E8 C4 77 85 DB CA 41 41 33) to the issuing CA, and treat the embedded PE as the sample of interest: extract it in an isolated environment.

Hunting with the signer

The same certificate can sign other files in the set. Search your collection for it:

Get-ChildItem C:\MalwareSamples\*.exe | ForEach-Object {
  ppee-cli.exe --no-similarity --json --security $_.FullName |
    ConvertFrom-Json | ForEach-Object { $_.security.signatures } |
    ForEach-Object { "$($_.signerCertificate.serialNumber)`t$($_.signerCertificate.subjectName)`t$($_.certificateIndex)" }
}

The similarity engine's Authentihash check groups re-signed copies of the same image.

More walkthroughs: all walkthroughs · From a URL to its call site

References