{"id":10696,"date":"2026-02-17T04:04:03","date_gmt":"2026-02-17T04:04:03","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/02\/17\/32718\/"},"modified":"2026-02-17T04:04:03","modified_gmt":"2026-02-17T04:04:03","slug":"32718","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/02\/17\/32718\/","title":{"rendered":"2026 64-Bits Malware Trend, (Mon, Feb 16th)"},"content":{"rendered":"<p>    2026 64-Bits Malware Trend, (Mon, Feb 16th)<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>In 2022 (time flies!),\u00a0I wrote a diary about the 32-bits VS. 64-bits malware landscape[<a href=\"https:\/\/isc.sans.edu\/diary\/32+or+64+bits+Malware\/28968\">1<\/a>]. It demonstrated that, despite the growing number of 64-bits computers, the &#8220;old-architecture&#8221; remained the standard. In the SANS malware reversing training (FOR610[<a href=\"https:\/\/www.sans.org\/cyber-security-courses\/reverse-engineering-malware-malware-analysis-tools-techniques\">2<\/a>]), we quickly cover the main differences between the two architectures. One of the conclusions is that 32-bits code is still popular because it acts like a comme denominator and allows threat actors to target more Windows computers. Yes, Microsoft Windows can smoothly execute 32-bits code on 64-bits computers.\u00a0It is still the case in 2026? Did the situation evolved?<\/p>\n<p>Last week, I make the exact same exercise and generated some statistics. I download the malware archive from Malware Bazaar[<a href=\"https:\/\/bazaar.abuse.ch\/\">3<\/a>] and re-executed my YARA rule.<\/p>\n<p>Some basic numbers:<\/p>\n<ul>\n<li>2.167 ZIP archives (one per day)<\/li>\n<li>1.120.034.288.112 bytes\u00a0 (1.1TB)<\/li>\n<li>Time line covered: from 2020\/02\/24 &#8211; 2026\/02\/05<\/li>\n<li>346.985 samples analyzed (only PE files)<\/li>\n<li>312.307 32-bits samples<\/li>\n<li>34.677 64-bits samples<\/li>\n<li>11% of 64-bits samples<\/li>\n<\/ul>\n<p>First, an overview of the global malware trend over the complete time period:<\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/isc-20260216-1.png?ssl=1\" style=\"width: 1000px; height: 343px;\"><\/p>\n<p>Zoom on the last year:<\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/isc-20260216-2.png?ssl=1\" style=\"width: 1000px; height: 500px;\"><\/p>\n<p>Now the interesting graph: the 64-bits sample trend over the complete period:<\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/isc-20260216-3.png?ssl=1\" style=\"width: 1000px; height: 360px;\"><\/p>\n<p>Zoom on the last year:<\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/isc-20260216-4.png?ssl=1\" style=\"width: 1000px; height: 383px;\"><\/p>\n<p>We can clearly see that, compared to 2022, there is now a trend in 64-bits code! Have a look at the last 30 days:<\/p>\n<table border=\"1\" cellpadding=\"1\" cellspacing=\"1\" style=\"width: 500px;\">\n<tbody>\n<tr>\n<td>Date<\/td>\n<td>Total Files<\/td>\n<td>32-bits<\/td>\n<td>64-bits<\/td>\n<\/tr>\n<tr>\n<td>2026-01-07<\/td>\n<td>65<\/td>\n<td>41<\/td>\n<td>24<\/td>\n<\/tr>\n<tr>\n<td>2026-01-08<\/td>\n<td>69<\/td>\n<td>41<\/td>\n<td>28<\/td>\n<\/tr>\n<tr>\n<td>2026-01-09<\/td>\n<td>117<\/td>\n<td>57<\/td>\n<td>60<\/td>\n<\/tr>\n<tr>\n<td>2026-01-10<\/td>\n<td>44<\/td>\n<td>25<\/td>\n<td>19<\/td>\n<\/tr>\n<tr>\n<td>2026-01-11<\/td>\n<td>41<\/td>\n<td>25<\/td>\n<td>16<\/td>\n<\/tr>\n<tr>\n<td>2026-01-12<\/td>\n<td>60<\/td>\n<td>40<\/td>\n<td>20<\/td>\n<\/tr>\n<tr>\n<td>2026-01-13<\/td>\n<td>53<\/td>\n<td>28<\/td>\n<td>25<\/td>\n<\/tr>\n<tr>\n<td>2026-01-14<\/td>\n<td>63<\/td>\n<td>41<\/td>\n<td>22<\/td>\n<\/tr>\n<tr>\n<td>2026-01-15<\/td>\n<td>59<\/td>\n<td>36<\/td>\n<td>23<\/td>\n<\/tr>\n<tr>\n<td>2026-01-16<\/td>\n<td>32<\/td>\n<td>21<\/td>\n<td>11<\/td>\n<\/tr>\n<tr>\n<td>2026-01-17<\/td>\n<td>27<\/td>\n<td>18<\/td>\n<td>9<\/td>\n<\/tr>\n<tr>\n<td>2026-01-18<\/td>\n<td>65<\/td>\n<td>33<\/td>\n<td>32<\/td>\n<\/tr>\n<tr>\n<td>2026-01-19<\/td>\n<td>96<\/td>\n<td>60<\/td>\n<td>36<\/td>\n<\/tr>\n<tr>\n<td>2026-01-20<\/td>\n<td>71<\/td>\n<td>41<\/td>\n<td>30<\/td>\n<\/tr>\n<tr>\n<td>2026-01-21<\/td>\n<td>56<\/td>\n<td>33<\/td>\n<td>23<\/td>\n<\/tr>\n<tr>\n<td>2026-01-22<\/td>\n<td>82<\/td>\n<td>35<\/td>\n<td>47<\/td>\n<\/tr>\n<tr>\n<td>2026-01-23<\/td>\n<td>77<\/td>\n<td>52<\/td>\n<td>25<\/td>\n<\/tr>\n<tr>\n<td>2026-01-24<\/td>\n<td>50<\/td>\n<td>15<\/td>\n<td>35<\/td>\n<\/tr>\n<tr>\n<td>2026-01-25<\/td>\n<td>44<\/td>\n<td>28<\/td>\n<td>16<\/td>\n<\/tr>\n<tr>\n<td>2026-01-26<\/td>\n<td>125<\/td>\n<td>102<\/td>\n<td>23<\/td>\n<\/tr>\n<tr>\n<td>2026-01-27<\/td>\n<td>90<\/td>\n<td>64<\/td>\n<td>26<\/td>\n<\/tr>\n<tr>\n<td>2026-01-28<\/td>\n<td>66<\/td>\n<td>29<\/td>\n<td>37<\/td>\n<\/tr>\n<tr>\n<td>2026-01-29<\/td>\n<td>121<\/td>\n<td>51<\/td>\n<td>70<\/td>\n<\/tr>\n<tr>\n<td>2026-01-30<\/td>\n<td>80<\/td>\n<td>39<\/td>\n<td>41<\/td>\n<\/tr>\n<tr>\n<td>2026-01-31<\/td>\n<td>68<\/td>\n<td>28<\/td>\n<td>40<\/td>\n<\/tr>\n<tr>\n<td>2026-02-01<\/td>\n<td>62<\/td>\n<td>27<\/td>\n<td>35<\/td>\n<\/tr>\n<tr>\n<td>2026-02-02<\/td>\n<td>129<\/td>\n<td>72<\/td>\n<td>57<\/td>\n<\/tr>\n<tr>\n<td>2026-02-03<\/td>\n<td>117<\/td>\n<td>53<\/td>\n<td>64<\/td>\n<\/tr>\n<tr>\n<td>2026-02-04<\/td>\n<td>84<\/td>\n<td>42<\/td>\n<td>42<\/td>\n<\/tr>\n<tr>\n<td>2026-02-05<\/td>\n<td>437<\/td>\n<td>395<\/td>\n<td>42<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>We are getting close to a 50-50 repartition!<br \/>\n\u200b\u200b\u200b\u200b\u200b\u200b\u200b<br \/>\n[1] <a href=\"https:\/\/isc.sans.edu\/diary\/32+or+64+bits+Malware\/28968\">https:\/\/isc.sans.edu\/diary\/32+or+64+bits+Malware\/28968<\/a><br \/>\n[2] <a href=\"https:\/\/www.sans.org\/cyber-security-courses\/reverse-engineering-malware-malware-analysis-tools-techniques\">https:\/\/www.sans.org\/cyber-security-courses\/reverse-engineering-malware-malware-analysis-tools-techniques<\/a><br \/>\n[3] <a href=\"https:\/\/bazaar.abuse.ch\/\">https:\/\/bazaar.abuse.ch<\/a><\/p>\n<p>Xavier Mertens (@xme)<br \/>\nXameco<br \/>\nSenior ISC Handler &#8211; Freelance Cyber Security Consultant<br \/>\n<a href=\"https:\/\/keybase.io\/xme\/key.asc\">PGP Key<\/a><\/p>\n<p> (c) SANS Internet Storm Center. https:\/\/isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.<\/p><\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><\/p>\n<p> \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/isc.sans.edu\/diary\/rss\/32718\">Go to isc.sans.edu<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>2026 64-Bits Malware Trend, (Mon, Feb 16th) In 2022 (time flies!),\u00a0I wrote a diary about the 32-bits VS. 64-bits malware landscape[1]. It demonstrated that, despite the growing number of 64-bits computers, the &#8220;old-architecture&#8221; remained the standard. In the SANS malware reversing training (FOR610[2]), we quickly cover the main differences between the two architectures. One of [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[69],"class_list":["post-10696","post","type-post","status-publish","format-standard","hentry","category-isc-sans-edu","tag-isc-sans-edu"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10696"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10696"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10696\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10696"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10696"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10696"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}