T1562.004 in real malware
ATT&CK technique T1562.004 appears in 8 publicly analyzed samples on MalwareAnalyzer by Cyble, 0.0% of the analyzed corpus. Seven-day prevalence is rising (8 recent vs 0 prior). Most associated families: AgentTesla, HUILoader, Njrat, Bladabindi.
Prevalence in the corpus
- Samples exhibiting T1562.004: 8
- Share of analyzed corpus: 0.0%
- Last 7 days: 8 · prior 7 days: 0 (rising)
Malware families using T1562.004
- AgentTesla - 2 samples
- HUILoader - 2 samples
- Njrat - 2 samples
- Bladabindi - 1 sample
Example samples
- 8b89fdf7c7909848e69002fd4212e9649a8db8aa2c974c365e56860a7a08aaf7 - malicious
- 66c8041d27975655f2a1bb1b42e454ad51a0e4e93dfbbf765fb995afdeaa40d0 - malicious
- 296fa7d869009b88b0638c32a8255ac5bf0c12b6f3863ece179f2c1a0a074787 - malicious
- 0e61e8e6d4118a5b4a3a11fdf887fd2f504be8468c56dd5601c5d41fb5e845eb - malicious
- ba36ce6b0f2cfdf84d018a1ad461810642ecd62a7448a13b688d3e4bb098b1df - malicious
- 073014b0a7e0f63737113433a2f65bb6bed016e50f8fac93c49c10af3b5405a5 - malicious
- f7a874c61002aa8d23bb89b407ab1a8bd13a22e0fe0bc0deed2ab3b7135a325a - malicious
- 25245350be0d0b3277bfa71ea274a0a0dee3e884ee6c1a9b6e477465b49edbc0 - suspicious
Frequently asked about T1562.004
- How common is ATT&CK T1562.004 in real malware?
- ATT&CK technique T1562.004 appears in 8 publicly analyzed samples on MalwareAnalyzer by Cyble, 0.0% of the analyzed corpus. Seven-day prevalence is rising (8 recent vs 0 prior). Most associated families: AgentTesla, HUILoader, Njrat, Bladabindi.
- Is T1562.004 becoming more common?
- Prevalence is rising: 8 samples in the last seven days against 0 in the seven days before. This measures submissions to MalwareAnalyzer by Cyble, so it reflects what is being submitted here rather than global attacker behaviour.
- Which malware families use T1562.004?
- In this corpus T1562.004 is most associated with AgentTesla (2), HUILoader (2), Njrat (2), Bladabindi (1). Counts are analyzed samples per family in which the technique was observed.
- What share of analyzed samples use T1562.004?
- 0.0% of the publicly analyzed corpus (8 of 100981 samples) exhibits T1562.004. Technique attribution comes from behavior captured during real sandbox detonation and from static analysis, not from a vendor label.
All ATT&CK techniques in the corpus · Latest analyzed threats