Autolike malware family
Autolike is a malware family tracked by MalwareAnalyzer by Cyble across 16 publicly analyzed samples. First seen 2026-07-29, most recently 2026-08-23. Observed ATT&CK techniques include T1112.
Corpus statistics
- Publicly analyzed samples: 16
- First seen: 2026-07-29
- Last seen: 2026-08-23
- Verdicts: malicious 16
- File types: html 16
ATT&CK techniques used by Autolike
- T1112 - 1 sample
Extracted command-and-control infrastructure
- http://1.bp.blogspot.com/-9FCgC3SpZ00/UPMiEedG1VI/AAAAAAAACl0/zLgl3K6_d3I/s1600/arrow_right.gif);background-repeat:no-repeat;background-position:right - 6 samples
- http://1.bp.blogspot.com/-zt3csy2DqGo/U661h1iTakI/AAAAAAAAAFc/v5tUjZIJDHs/s1600/mas-icons.png - 6 samples
- http://2.bp.blogspot.com/-QB-QrnRTSJI/UPMiEYKozJI/AAAAAAAAClw/ieBOFWLIqlM/s1600/arrow_down.gif);background-repeat:no-repeat;background-position:right - 6 samples
- http://3.bp.blogspot.com/-LzmPTNyR6po/TwETZufjSTI/AAAAAAAAATo/oisHmXUjmSY/s1600/arrow_white.gif);background-repeat - 6 samples
- http://3.bp.blogspot.com/-kci2j8VxzNY/UPw8jUo8hzI/AAAAAAAABNw/xV9j7En07ew/s1600/feed+icon.gif - 6 samples
- http://4.bp.blogspot.com/-Bt0JYGRHfpk/T7ZpN5RNSQI/AAAAAAAAGJQ/zQtrWVZwgHA/s1600/bullet.png - 6 samples
- http://4.bp.blogspot.com/-tk5hQcNMq6M/T8zPEwjH-RI/AAAAAAAAGm0/t8xkrJitkxg/s1600/batas.gif - 6 samples
- http://creativecommons.org/licenses/by/3.0/ - 6 samples
- https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css - 6 samples
- https://www.blogger.com/static/v1/jsbin/403901366-ieretrofit.js - 3 samples
- https://www.blogger.com/static/v1/widgets/1667664774-css_bundle_v2.css - 3 samples
- http://1.bp.blogspot.com/-9pktr5ue54o/U91rjM_1pMI/AAAAAAAAAAw/Qhk2b8QV-U4/s1600/Idool.jpg - 2 samples
- http://1.bp.blogspot.com/-DME_22Ocj5k/U_jwvZzJS3I/AAAAAAAAAAw/t_5wFfJ_GA4/s1600/Idool.jpg - 2 samples
- http://2.bp.blogspot.com/-Orz321Gat5Y/U9p9AMWVXYI/AAAAAAAAAGU/8K4hznEeMtQ/s1600/Idool.jpg - 2 samples
- http://2.bp.blogspot.com/-p8kDUeH5uV8/U91peIPWx5I/AAAAAAAAAAk/C3kiFW0RYzA/s150/Idool.jpg - 2 samples
- http://3.bp.blogspot.com/-4exOr_Q6AZQ/U_jywJHAMKI/AAAAAAAAAA8/mOyb16MU0kg/s728/pikachu%2BIdool.gif - 2 samples
- http://4.bp.blogspot.com/-FQcN0HoEKOM/U-KOVyHHpdI/AAAAAAAAABo/vLPl7bpLNwk/s1600/love-icon%5B1%5D.png - 2 samples
- http://luanafiorelli.blogspot.com/ - 2 samples
- http://www.campusrape.info?href=http://www.campusrape.info&layout=standard&show_faces=false&width=20&action=like&font=tahoma&colorscheme=light&height=20 - 2 samples
- https://www.blogger.com/dyn-css/authorization.css?targetBlogID=3838844169565079662&zx=562d2491-c5af-4567-9878-7deed39e64c2 - 2 samples
Recent Autolike samples
- fe9b1725cf2e9ca1a754892b131f9a4d0a32cec07ae41e2f555f74ac25a37290 - malicious (2026-08-23)
- 5bcafefd1c2b402b3ebe15e7bd1464fcc53f08a2991c6703eb1e0b6ae7d7e56e - malicious (2026-08-23)
- 2250e7f4cbfd97e6705f188b41dc8cdce1ef3839009f2920e19610c6cf695586 - malicious (2026-08-22)
- 225eee2ac7245a3c729b5b92bebca53664029fe89de193d23e6c647eec2d53fc - malicious (2026-08-22)
- 3f745bb26dae6deed8bb1e7846f2e3d9d318879245eab4edf9f931b58bc7fa54 - malicious (2026-08-22)
- df089f36edf210e4241f16ddf98440fca0f7ec9a3be9c36a948ffd1b499a2f88 - malicious (2026-08-21)
- e0dd608c77e678e46f45daedb8f19c1f3bd163678670d03929c75c72aeca7636 - malicious (2026-08-21)
- dcc66cd907af196603cff7b3fe1bb61e02ca449afddf786f64d27cc9cc86aea0 - malicious (2026-08-20)
- bd54f77f3def42f65bc0b86e24c40d6907e0f6c5469dffe61ee6e0775d4868e3 - malicious (2026-08-20)
- 9904e2e7337cc0ab5c1bb6474a1a90d4db332ce894e697c7eed08bee7a501575 - malicious (2026-08-20)
- 990e24efc9e8f573d9b6907ef26e282b47a6bf1cb2132ca420da8cfbd7e3dcd9 - malicious (2026-08-20)
- 11b91c67e35640a4123fded0e29e996e7f9d78371625d520624d2bc52b87bdc3 - malicious (2026-08-16)
- f555565c17bc97f462e95917928c283d5c135fa98e0dd3691c53448dd414c0da - malicious (2026-08-15)
- 50280127b129a9118c7f1b1f06db1bfa91449f16ef58a5eaca8fb444e3487fb5 - malicious (2026-08-14)
- 80ebe87e24b0190356507f301a5e43878ea3a22c0f8aedd7f02ff50da7268f9a - malicious (2026-08-14)
- 9a3bfa4d62d9190ea1d3af5aaf94c9af74481712cd0f460606cf4d3cd954dd3b - malicious (2026-07-29)
Frequently asked about Autolike
- What is Autolike?
- Autolike is a malware family tracked by MalwareAnalyzer by Cyble across 16 publicly analyzed samples. First seen 2026-07-29, most recently 2026-08-23. Observed ATT&CK techniques include T1112.
- How many Autolike samples have been analyzed?
- MalwareAnalyzer by Cyble holds 16 publicly analyzed samples attributed to Autolike, first seen 2026-07-29 and most recently 2026-08-23. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Autolike use?
- Across our Autolike samples the most frequently observed techniques are T1112 (1). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Autolike use?
- Autolike samples in this corpus are distributed as html (16).
- Does Autolike use command-and-control infrastructure?
- Yes. 50 distinct command-and-control indicators have been extracted from Autolike samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is Autolike malicious?
- 16 of 16 analyzed Autolike samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends