FKLR malware family
FKLR is a malware family tracked by MalwareAnalyzer by Cyble across 1 publicly analyzed sample. First seen 2026-07-29, most recently 2026-07-29. Observed ATT&CK techniques include T1112.
Corpus statistics
- Publicly analyzed samples: 1
- First seen: 2026-07-29
- Last seen: 2026-07-29
- Verdicts: malicious 1
- File types: html 1
ATT&CK techniques used by FKLR
- T1112 - 1 sample
Extracted command-and-control infrastructure
- https://1.bp.blogspot.com/-6fW8xhif7Jc/YX1dc3YPsWI/AAAAAAAABA8/nN8VECXXr3sOemDjxyNu59xbtRXKqCa7wCNcBGAsYHQ/s16000/logo.jpg - 1 sample
- https://1.bp.blogspot.com/-B-SDu_dcewk/YX1dcxx7RRI/AAAAAAAABAw/3T6_NWhCc3wndZLr9PzoYNaTCb01AMXjwCNcBGAsYHQ/s16000/img.jpg - 1 sample
- https://1.bp.blogspot.com/-EAKkugDWy2Q/YX1dc-ViSvI/AAAAAAAABA0/gWmu-pZzvO8Qx7g2nADtSDmhCVLx8Pr2wCNcBGAsYHQ/s16000/heaa.jpg - 1 sample
- https://1.bp.blogspot.com/-WK8lxctGlik/YXhlDGq_fGI/AAAAAAAAA7g/Y4NKI09N5q0E71tqaiRQKJb2ecXDOivpQCNcBGAsYHQ/s16000/box3.png - 1 sample
- https://1.bp.blogspot.com/-XuCuIjJVhJI/YX1dc_6cq-I/AAAAAAAABAs/M3_mJD1luzcsOgxobi1EUBcOgVw8A2HngCNcBGAsYHQ/s16000/favicon.png - 1 sample
- https://1.bp.blogspot.com/-Zvz8MUJhQd8/YKsjY50KasI/AAAAAAAABgs/o_EK8ZiVbMQao5jkfesk20OrHxWDf8PGgCLcBGAsYHQ/s16000/Canada_outbox.png - 1 sample
- https://1.bp.blogspot.com/-aEF2lKWyOkA/YXhlDNeTDYI/AAAAAAAAA7Y/QrT0Q9xG-pUWz-LHxYFBrZ98HHby-RQcQCNcBGAsYHQ/s16000/box2.png - 1 sample
- https://1.bp.blogspot.com/-aTY9n9cuvSw/YXhlDDe_wLI/AAAAAAAAA7c/ItDBhEnJRzYzxvBNaBxo2PgKE58UfF_FgCNcBGAsYHQ/s16000/box1.png - 1 sample
- https://1.bp.blogspot.com/-d21zH2LJidk/YKsjYotdIwI/AAAAAAAABgo/_cIc6G5N84QjTpb3BnAR1i2Ft0lxhEO0wCLcBGAsYHQ/s16000/Canada_inbox.png - 1 sample
- https://1.bp.blogspot.com/-ecBxs3aVgXg/YX1dc-cbNPI/AAAAAAAABAo/8ZA55SORe8I7KbX4r3gdVH6tDvVxVNhiwCNcBGAsYHQ/s16000/hebb.png - 1 sample
- https://1.bp.blogspot.com/-is_68M0nfg4/YX1dc2Q2HMI/AAAAAAAABA4/n1p55JtfviIz9dovCKw-ce1ayZIq1YoKwCNcBGAsYHQ/s16000/og.jpg - 1 sample
- https://cdn.jsdelivr.cc/npm/bootstrap@4.6.0/dist/css/bootstrap.min.css - 1 sample
- https://cdn.jsdelivr.cc/npm/bootstrap@4.6.0/dist/js/bootstrap.min.js - 1 sample
- https://cdn.jsdelivr.cc/npm/jquery@3.6.0/dist/jquery.min.js - 1 sample
- https://cdn.jsdelivr.cc/npm/lazyload@2.0.0-rc.2/lazyload.min.js - 1 sample
- https://cdn.jsdelivr.cc/npm/popper.js@1.16.1/dist/umd/popper.min.js - 1 sample
- https://cdn.jsdelivr.cc/npm/sweetalert2@10.16.0/dist/sweetalert2.all.min.js - 1 sample
- https://www.mcb.com.pk/ - 1 sample
Recent FKLR samples
- 33640afc6c3f5006c6fdb55473e1655a9754e3dd66dc160e04919dfc7fedcc6f - malicious (2026-07-29)
Frequently asked about FKLR
- What is FKLR?
- FKLR is a malware family tracked by MalwareAnalyzer by Cyble across 1 publicly analyzed sample. First seen 2026-07-29, most recently 2026-07-29. Observed ATT&CK techniques include T1112.
- How many FKLR samples have been analyzed?
- MalwareAnalyzer by Cyble holds 1 publicly analyzed sample attributed to FKLR, first seen 2026-07-29 and most recently 2026-07-29. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does FKLR use?
- Across our FKLR samples the most frequently observed techniques are T1112 (1). Counts are the number of analyzed samples in which each technique was observed.
- What file types does FKLR use?
- FKLR samples in this corpus are distributed as html (1).
- Does FKLR use command-and-control infrastructure?
- Yes. 18 distinct command-and-control indicators have been extracted from FKLR samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is FKLR malicious?
- 1 of 1 analyzed FKLR sample was scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends