
1997-Timestamped Malware Resurfaces With 2025 C2 Infrastructure
A 49-kilobyte Win32 payload first seen on VirusTotal in 2015, carrying a backdated 1997 PE timestamp and near-maximum code-section entropy, is now beaconing to freshly provisioned French VPS infrastructure registered in December 2025. The binary deploys a layered evasion stack — sandbox detection, debugger checks, indicator removal, and timestamp manipulation — that has prevented any sandbox verdict despite a decade of exposure.
A single unsigned Win32 executable, first submitted to VirusTotal in June 2015 and carrying a PE timestamp deliberately set to October 1997, is appearing alongside command-and-control infrastructure provisioned as recently as December 2025 — a temporal gap of more than a decade that sits at the heart of one of the more analytically interesting evasion puzzles CTX Team has examined this cycle. The payload targets consulting-sector organisations in the United States.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read