Dinwod malware family
Dinwod is a malware family tracked by MalwareAnalyzer by Cyble across 17 publicly analyzed samples. First seen 2026-08-12, most recently 2026-08-25. Observed ATT&CK techniques include T1055, T1056.001, T1105.
Corpus statistics
- Publicly analyzed samples: 17
- First seen: 2026-08-12
- Last seen: 2026-08-25
- Verdicts: malicious 17
- File types: pe 17
ATT&CK techniques used by Dinwod
Recent Dinwod samples
- virussign.com_303d06ebda1c6fd4997d0f2c248fe2e0.vir - malicious (2026-08-25)
- bxnpvlj.exe - malicious (2026-08-19)
- xpddxhx.exe - malicious (2026-08-19)
- fjjrfb.exe - malicious (2026-08-19)
- rxfpp.exe - malicious (2026-08-18)
- bttvvhv.exe - malicious (2026-08-18)
- drddnhx.exe - malicious (2026-08-18)
- dttvbnj.exe - malicious (2026-08-18)
- nthlvpj.exe - malicious (2026-08-18)
- pnpbnl.exe - malicious (2026-08-18)
- bvplb.exe - malicious (2026-08-18)
- lpbnp.exe - malicious (2026-08-18)
- lvvpd.exe - malicious (2026-08-18)
- jphrhr.exe - malicious (2026-08-18)
- virussign.com_28fdbce5d736af67eafb1e01bd4093e0.vir - malicious (2026-08-18)
- 398e9138de13eaa5fb1c0370b8fe35289bd162139ff4aa41da0903608889ed1d - malicious (2026-08-15)
- virussign.com_e6669af2498213477e49682865f17580.vir - malicious (2026-08-12)
Frequently asked about Dinwod
- What is Dinwod?
- Dinwod is a malware family tracked by MalwareAnalyzer by Cyble across 17 publicly analyzed samples. First seen 2026-08-12, most recently 2026-08-25. Observed ATT&CK techniques include T1055, T1056.001, T1105.
- How many Dinwod samples have been analyzed?
- MalwareAnalyzer by Cyble holds 17 publicly analyzed samples attributed to Dinwod, first seen 2026-08-12 and most recently 2026-08-25. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Dinwod use?
- Across our Dinwod samples the most frequently observed techniques are T1055 (16), T1056.001 (16), T1105 (4). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Dinwod use?
- Dinwod samples in this corpus are distributed as pe (17).
- Is Dinwod malicious?
- 17 of 17 analyzed Dinwod samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends