Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We named this payload WinorDLL64 based on its filename WinorDLL64.dll ... The WinorDLL64 payload serves as a backdoor that most notably acquires extensive system information, provides means for file manipulation, such as exfiltrating, overwriting, and removing files, and executes additional commands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
T1012 Query Registry WinorDLL64 can query the Windows registry to gather system information.
T1016 System Network Configuration Discovery WinorDLL64 can enumerate network adapter information.
T1033 System Owner/User Discovery WinorDLL64 can enumerate sessions and list associated user, domain, and client names –among other details.
T1049 System Network Connections Discovery WinorDLL64 can collect a list of listening ports.
T1057 Process Discovery WinorDLL64 can collect information about running processes.
T1082 System Information Discovery WinorDLL64 can obtain information such as computer name, OS and latest service pack version, processor architecture, processor name, and amount of space on fixed drives.
T1083 File and Directory Discovery WinorDLL64 can obtain file and directory listings.
T1087.001 Account Discovery: Local Account WinorDLL64 can enumerate sessions and list associated user, and client names, among other details.
T1087.002 Account Discovery: Domain Account WinorDLL64 can enumerate sessions and list associated domain names –among other details.
T1135 Network Share Discovery WinorDLL64 can discover shared network drives.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.