FILEMembers
FILE

Malware Sample Stalls to Dodge Sandboxes, Hides Behind Thin Infrastructure

A Windows binary posing as joduj.exe deliberately idles and polls the CPU clock to detect sandbox analysis before executing, a behavior confirmed by a malicious sandbox verdict and flagged by 55 of 75 engines. The engineering effort behind that evasion contrasts sharply with a thin, unverified network trail.

Sep 9, 2026, 22:58 (UTC+9)Last seenSep 10, 2026Severity85ByCTX TeamActorSpring DragonLotus BlossomIOC11RegionsIN

A Windows executable masquerading as joduj.exe (e9e732f7…) sits idle after launch, deliberately stalling for long stretches and polling the CPU clock directly to work out whether it has landed inside a sandbox before it will do anything else. That single behavioural signature — confirmed by a malicious verdict from the Yomi Hunter sandbox and flagged by 55 of 75 engines — is the strongest piece of evidence in this case, and it maps cleanly to time-based sandbox evasion [T1497.003].

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence