Dinwod malware family
Dinwod is a malware family tracked by MalwareAnalyzer by Cyble across 16 publicly analyzed samples. First seen 2026-08-12, most recently 2026-08-19. Observed ATT&CK techniques include T1055, T1056.001, T1105.
Corpus statistics
- Publicly analyzed samples: 16
- First seen: 2026-08-12
- Last seen: 2026-08-19
- Verdicts: malicious 16
- File types: pe 16
ATT&CK techniques used by Dinwod
Recent Dinwod samples
- bxnpvlj.exe - malicious (2026-08-19)
- xpddxhx.exe - malicious (2026-08-19)
- fjjrfb.exe - malicious (2026-08-19)
- rxfpp.exe - malicious (2026-08-18)
- bttvvhv.exe - malicious (2026-08-18)
- drddnhx.exe - malicious (2026-08-18)
- dttvbnj.exe - malicious (2026-08-18)
- nthlvpj.exe - malicious (2026-08-18)
- pnpbnl.exe - malicious (2026-08-18)
- bvplb.exe - malicious (2026-08-18)
- lpbnp.exe - malicious (2026-08-18)
- lvvpd.exe - malicious (2026-08-18)
- jphrhr.exe - malicious (2026-08-18)
- virussign.com_28fdbce5d736af67eafb1e01bd4093e0.vir - malicious (2026-08-18)
- 398e9138de13eaa5fb1c0370b8fe35289bd162139ff4aa41da0903608889ed1d - malicious (2026-08-15)
- virussign.com_e6669af2498213477e49682865f17580.vir - malicious (2026-08-12)
Frequently asked about Dinwod
- What is Dinwod?
- Dinwod is a malware family tracked by MalwareAnalyzer by Cyble across 16 publicly analyzed samples. First seen 2026-08-12, most recently 2026-08-19. Observed ATT&CK techniques include T1055, T1056.001, T1105.
- How many Dinwod samples have been analyzed?
- MalwareAnalyzer by Cyble holds 16 publicly analyzed samples attributed to Dinwod, first seen 2026-08-12 and most recently 2026-08-19. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Dinwod use?
- Across our Dinwod samples the most frequently observed techniques are T1055 (15), T1056.001 (15), T1105 (3). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Dinwod use?
- Dinwod samples in this corpus are distributed as pe (16).
- Is Dinwod malicious?
- 16 of 16 analyzed Dinwod samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends