I don't get it. If they are hidden within valid but never occurring crontab dates then they don't get executed. What am I missing?
The actual malware uses the task name from these "never occurring crontab". The invalid date is just a kind of signature.
...after reading: but also because one entry has a valid "every 30 minutes" specification :) and the rest are only used for storage.