signed-carrier-combo
Malware evasion technique that combines a valid Authenticode-signed carrier PE with an encrypted companion payload distributed inside a silent self-extracting archive (typically 7-Zip SFX). The signed carrier binary is either a stolen or misappropriated legitimate executable, or a malware binary that has acquired a valid code-signing certificate. The companion payload is encrypted and masquerades with a benign filename extension (.xml, .map, .yaml, .sym).
Why It Works
- Signature trust: EDR, SmartScreen, and application-whitelisting products typically trust processes launched from signed binaries, especially when the certificate chain traces to a trusted root CA (Microsoft, DigiCert, Sectigo).
- Split payload: Sandboxes that detonate only the outer archive or only the extracted carrier miss the encrypted companion, which contains the actual malicious logic. The carrier's import table is entirely benign (standard Windows + Office APIs).
- Silent extraction: 7-Zip SFX with
Progress=noandGUIFlags=8extracts to%TEMP%with no user-visible window, then auto-launches the carrier. The victim sees only a brief spinner.
Variants Observed
-
GhostPulse — InfoPath morph (
4a78e2ad) — 7-Zip SFX archive containing a renamed Microsoft InfoPath 2013 x64 executable (GeneratorB64.exe) with valid Microsoft Authenticode chain, two Office Common Dialog Framework DLLs (CDLMSO.DLL,MSOCF.DLL), and a 7.6 MB encrypted sidecarkernel-layer.xml(entropy 7.90). Carrier imports standard Windows + Office APIs; no malicious imports visible. ^[/intel/analyses/4a78e2adf2ab7c257c7c5a960a8edeb0d64fa6ac564f4c06060c92adfa12ae76.html] -
GhostPulse — Steam Error Reporter morph (
833bffd0) — 7-Zip SFX archive containing Valve's signedSteamErrorReporter.exe(Authenticode by DigiCert), Qt5 runtime DLLs, and encrypted companiontexture_mon.yaml. Carrier is an actual Valve binary repurposed as a dropper. ^[/intel/analyses/833bffd0ff2291001e0cb62f529cf947ba2753fa5888820848a2014eda2dc334.html]
Detection
| Indicator | Detection Target |
|---|---|
SFX archive >8 MB with 7ZSfxMod or 7z SFX strings |
Static file carving |
RunProgram in 7-Zip SFX config pointing to a renamed binary |
Config parser / YARA |
Signed binary in %TEMP% reading a high-entropy companion file |
EDR behavioural rule |
Entropy >7.8 on .xml/.yaml/.map files in temp dirs |
File-system monitoring |
| Import table mismatch: signed Office binary loading custom unsigned DLLs | Memory / import-table analysis |
Certificate subject CN mismatch with executable filename (e.g., Microsoft Corporation vs GeneratorB64.exe) |
Certificate telemetry correlation |
Related
- companion-file-encrypted-payload — the companion-file component in isolation
- 7z-sfx-dropper — the SFX archive delivery mechanism
- ghostpulse — family that uses this technique
- steam-error-reporter-masquerade — related signed-carrier variant
- stolen-certificate-signing — when the certificate itself is compromised
- version-info-masquerade — falsified metadata to match the signed identity