C&CMembers
C&C

Fake .bat File Hides Packed Loader in Sprawling EU C2 Set

A single unsigned Win32 executable disguised as docs.log.bat draws 60 of 75 detections despite one submission and zero sandbox telemetry. It sits amid 57 domains and 12 IPs across European hosting providers that mostly fail to cohere into a real infrastructure cluster.

Jul 24, 2026, 13:39 (UTC+9)Last seenJul 24, 2026Severity100ByCTX TeamIOC83MITRE31RegionsUS

A single Win32 executable dressed up as docs.log.bat sits at the center of a c2-servers record otherwise padded with 57 domains and 12 IPs across a dozen European hosting providers — and the disguise is almost the whole story. Sixty of 75 engines flag the file as malicious, yet it was submitted to detection platforms exactly once, from a single source, and carries zero sandbox telemetry to explain what it actually does once it runs.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence