W32.Injector:Gen.21ie.1201 is a generic Windows malware detection name observed in Cisco Talos telemetry. The provided content identifies it as an injector-class detection and lists a sample associated with SHA256 96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974 and MD5 aac3165ece2959f39ff98334618d10d9, with an example filename of 96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974.exe. It appears in Talos weekly prevalence reporting alongside other malware families such as coinminers, infostealers, and droppers. No specific infection vector, technical behavior beyond its classification as an injector, targeted industries, associated threat actor, or additional indicators of compromise are directly provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A generic injector malware, typically used to inject malicious code into processes or to load additional payloads.
Generic injector malware, likely used to inject malicious code into other processes or binaries.
W32.Injector is a generic detection for trojans that inject malicious code into processes to evade detection and execute payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.