Redirector malware family
Redirector is a malware family tracked by MalwareAnalyzer by Cyble across 9 publicly analyzed samples. First seen 2026-07-27, most recently 2026-08-15. Observed ATT&CK techniques include T1112.
Corpus statistics
- Publicly analyzed samples: 9
- First seen: 2026-07-27
- Last seen: 2026-08-15
- Verdicts: malicious 9
- File types: html 9
ATT&CK techniques used by Redirector
- T1112 - 7 samples
Extracted command-and-control infrastructure
- https://router.parklogic.com/ - 3 samples
- http://gmpg.org/xfn/11 - 2 samples
- http://intraserv.com.br/wp-content/uploads/2017/06/favicon.png - 1 sample
- http://template.com/wp/ - 1 sample
- http://template.com/wp/?feed=rss2 - 1 sample
- http://template.com/wp/wp-includes/wlwmanifest.xml - 1 sample
- http://template.com/wp/xmlrpc.php - 1 sample
- http://template.com/wp/xmlrpc.php?rsd - 1 sample
- https://besixoni.tripod.com/20-foot-1993-chaparral/ - 1 sample
- https://besixoni.tripod.com/alta-vista-college-seattle/ - 1 sample
- https://besixoni.tripod.com/babado-novo-pensando-em-vc/ - 1 sample
- https://besixoni.tripod.com/clonazepam-addiction/ - 1 sample
- https://besixoni.tripod.com/errin-tablets-dietary-supplements/ - 1 sample
- https://besixoni.tripod.com/first-synthesis-of-methyl-salicylate/ - 1 sample
- https://besixoni.tripod.com/polio-encephalitis-goats/ - 1 sample
- https://besixoni.tripod.com/replenishment-specialist/ - 1 sample
- https://besixoni.tripod.com/todsen-pennyroyal-white-sands/ - 1 sample
- https://intraserv.com.br/ - 1 sample
- https://intraserv.com.br/#logo - 1 sample
- https://intraserv.com.br/#organization - 1 sample
Recent Redirector samples
- 40889e60c787095f6f74fb51a7431d3bbcd64054b6dae6472300169857e358b1 - malicious (2026-08-15)
- 750852a54f6c7e03cbd619490d398b77a80f117a1ecbb8a3924c39abed602f7c - malicious (2026-08-09)
- a47efa1ce5edb1559b1eb0bdef034a0f58a66225c60c1db935c5304b8bade710 - malicious (2026-08-03)
- 8859780c4575748898796b5c34cab9b63b98e0fa83b9230501e28102da84d86c - malicious (2026-07-29)
- 9ee75b45dae56f41b1b22ad4ff01890f703f1434b12070378eb5c17834503315 - malicious (2026-07-29)
- virussign.com_d933155aee22192ddc8c19d53e0b3110.vir - malicious (2026-07-28)
- virussign.com_bf42d71f15e1ef1cb9fdbe74e5a66580.vir - malicious (2026-07-28)
- virussign.com_0492031468718ff2f127692851970210.vir - malicious (2026-07-28)
- virussign.com_a5dc42e966658f8bacc4b6ea63f69320.vir - malicious (2026-07-27)
Frequently asked about Redirector
- What is Redirector?
- Redirector is a malware family tracked by MalwareAnalyzer by Cyble across 9 publicly analyzed samples. First seen 2026-07-27, most recently 2026-08-15. Observed ATT&CK techniques include T1112.
- How many Redirector samples have been analyzed?
- MalwareAnalyzer by Cyble holds 9 publicly analyzed samples attributed to Redirector, first seen 2026-07-27 and most recently 2026-08-15. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Redirector use?
- Across our Redirector samples the most frequently observed techniques are T1112 (7). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Redirector use?
- Redirector samples in this corpus are distributed as html (9).
- Does Redirector use command-and-control infrastructure?
- Yes. 50 distinct command-and-control indicators have been extracted from Redirector samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is Redirector malicious?
- 9 of 9 analyzed Redirector samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends