C&CMembers
C&C

1997-Timestamped Malware Resurfaces With 2025 C2 Infrastructure

A 49-kilobyte Win32 payload first seen on VirusTotal in 2015, carrying a backdated 1997 PE timestamp and near-maximum code-section entropy, is now beaconing to freshly provisioned French VPS infrastructure registered in December 2025. The binary deploys a layered evasion stack — sandbox detection, debugger checks, indicator removal, and timestamp manipulation — that has prevented any sandbox verdict despite a decade of exposure.

Jun 26, 2026, 17:23 (UTC+9)Last seenJun 27, 2026Severity100ByCTX TeamIOC10MITRE16RegionsUS

A single unsigned Win32 executable, first submitted to VirusTotal in June 2015 and carrying a PE timestamp deliberately set to October 1997, is appearing alongside command-and-control infrastructure provisioned as recently as December 2025 — a temporal gap of more than a decade that sits at the heart of one of the more analytically interesting evasion puzzles CTX Team has examined this cycle. The payload targets consulting-sector organisations in the United States.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence