
C&CMembers
C&CDecade-Old Corrupted PE Loader Still Evades 13 of 58 AV Engines
A 2015-vintage Win32 executable tied to the injector family 'ranapama' still slips past 13 of 58 antivirus engines despite a 45/58 detection rate. CTX Team ties it to no named actor — only a structurally corrupted PE, a via-tor delivery tag, and a diffuse, low-signal 37-IP fleet.
Jul 5, 2026, 11:49 (UTC+9)Last seenJul 5, 2026Severity100ByCTX TeamIOC43MITRE31RegionsUS
Forty-five of 58 antivirus engines flag a single Win32 executable tracked by CTX Team as part of a cluster linked to the malware family "ranapama" — a detection rate that sounds decisive until you notice which 13 engines still miss it. Alibaba, ClamAV, TrendMicro, TrendMicro-HouseCall, CAT-QuickHeal, and CMC, among others, return nothing at all.
Members only
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to readSource: CTX Threat Intelligence