
Fake .bat File Hides Packed Loader in Sprawling EU C2 Set
A single unsigned Win32 executable disguised as docs.log.bat draws 60 of 75 detections despite one submission and zero sandbox telemetry. It sits amid 57 domains and 12 IPs across European hosting providers that mostly fail to cohere into a real infrastructure cluster.
A single Win32 executable dressed up as docs.log.bat sits at the center of a c2-servers record otherwise padded with 57 domains and 12 IPs across a dozen European hosting providers — and the disguise is almost the whole story. Sixty of 75 engines flag the file as malicious, yet it was submitted to detection platforms exactly once, from a single source, and carries zero sandbox telemetry to explain what it actually does once it runs.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read