WinDealer
Essential information
- Confidence
- 100/100
- Is family
- No
- Published
- 20/12/2025 19:33
- Modified
- 20/12/2025 20:00
- Revoked
- No
- Author / Source
- AlienVault
- Related entities
- 10 attack patterns (mitre), 1 intrusion sets (apt), 4 sectors, 7 countries, 11 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators, intrusion sets and other entities linked to this malware.
Attack patterns (MITRE) (10)
-
T1046 usesNetwork Service Discovery MITRE
-
T1059 usesCommand and Scripting Interpreter MITRE
-
T1592 usesGather Victim Host Information MITRE
-
T1407 MITRE
-
T1140 usesDeobfuscate/Decode Files or Information MITRE
-
T1547 usesBoot or Logon Autostart Execution MITRE
-
T1590 usesGather Victim Network Information MITRE
-
T1113 usesScreen Capture MITRE
-
T1189 usesDrive-by Compromise MITRE
-
T1589 usesGather Victim Identity Information MITRE
Intrusion sets (APT) (1)
-
LuoYu usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Sectors (4)
-
Defense targets
-
Logistics targets
-
Telecommunications targets
-
Government targets
Countries (7)
-
India targets
-
Russian Federation targets
-
Austria targets
-
Czechia targets
-
United States of America targets
-
China targets
-
Germany targets
Indicators (11)
-
stix 100/100 Revoked
stack_string SHA256 of 313b231491408bd107cecf0207868336f26d79ba SHA256 of 313b231491408bd107cecf0207868336f26d79ba
· Valid until 06/09/2023 · Source: AlienVault -
stix 100/100 Revoked
stack_string SHA256 of 64a1785683858d8b6f4e7e2b2fac213fb752bae0
· Valid until 06/09/2023 · Source: AlienVault -
stix 100/100 Revoked
stack_string SHA256 of b062773bdd9f8433cbd6e7642226221972ecd4e1 SHA256 of b062773bdd9f8433cbd6e7642226221972ecd4e1
· Valid until 06/09/2023 · Source: AlienVault -
stix 100/100 Revoked
Win32/WinDealer, Win32.Dostre SHA256 of 204a603c409e559b65c35208200a169a232da94c
· Valid until 06/09/2023 · Source: AlienVault -
stix 100/100 Revoked
Win32/WinDealer SHA256 of 84e749c37978f9387e16fab29c7b1b291be93a63
· Valid until 06/09/2023 · Source: AlienVault -
stix 100/100 Revoked
stack_string SHA256 of f64c63f6e17f082ea254f0e56a69b389e35857fd
· Valid until 06/09/2023 · Source: AlienVault -
stix 100/100 Revoked· Valid until 06/09/2023 · Source: AlienVault
-
stix 100/100 Revoked
stack_string SHA256 of 0d3a5725b6f740929b51f9a8611b4f843e2e07b1
· Valid until 06/09/2023 · Source: AlienVault -
stix 100/100 Revoked· Valid until 06/09/2023 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 06/09/2023 · Source: AlienVault
-
stix 100/100 Revoked
stack_string SHA256 of 78294dfc4874b54c870b8daf7c43cfb5d8c211d0
· Valid until 06/09/2023 · Source: AlienVault