Update of detection situation as we have now (info credits go to Bitwiper):

Detection for 46/63 https://www.virustotal.com/en/file/320008650befd4d89bae59eb57029064b7695e2ad56278ef583b61d9b8d0438d/analysis/1502130023/

Certificate still has not been revoked, but still was being used to sign malware (at 06:36:01 CMT) - re: “20170807043601Z” in htxps://www.hybrid-analysis.com/sample/76282e7506de8f2d97eaa0957873ac55741768783b6062e07de952eeeddfbb73?environmentId=100.

File downloaded from uri (hxxp://foolerpolwer.info/admin.php?f=3) mentioned on the hybrid-analysis page and there also has an new file being launched , not digitally signed. That particular file now has 10/64, see: https://www.virustotal.com/en/file/3f172b181e579b4d7d4cb8f2b55c7424d1e7a85eb649f4845625a2a58962ec46/analysis/1502130786/

polonus (volunteer website security analyst and website error-hunter)