HTML malware family
HTML is a malware family tracked by MalwareAnalyzer by Cyble across 7 publicly analyzed samples. First seen 2026-07-28, most recently 2026-07-29. Observed ATT&CK techniques include T1112, T1071.004.
Corpus statistics
- Publicly analyzed samples: 7
- First seen: 2026-07-28
- Last seen: 2026-07-29
- Verdicts: malicious 7
- File types: html 7
ATT&CK techniques used by HTML
Extracted command-and-control infrastructure
- http://ogp.me/ns/fb# - 4 samples
- https://cdn2.editmysite.com/js/jquery-1.8.3.min.js - 2 samples
- http://image.slidesharecdn.com/assessmentfinal2-131208223610-phpapp01/95/validity-and-reliability-in-assessment-23-638.jpg - 1 sample
- http://images2.fanpop.com/image/photos/13600000/The-English-Patient-Picspam-the-english-patient-13664360-786-525.jpg - 1 sample
- http://ios-data-recover.com/wp-content/uploads/2014/05/iphone-broken.png - 1 sample
- http://oasispin.weebly.com/2/post/2020/09/skate-2-ps3-rom.html - 1 sample
- http://oasispin.weebly.com/blog/skate-2-ps3-rom&is_mobile=&r=3&is_light=0 - 1 sample
- http://oasispin.weebly.com/uploads/1/2/6/9/126905046/821987156_orig.jpg - 1 sample
- http://ogp.me/ns# - 1 sample
- http://yfdpco4.com/sk-park.php?pid=9PO15V947&dn=getpdf.pw&ua=Mozilla%2F5.0+%28Windows+NT+10.0%3B+Win64%3B+x64%29+AppleWebKit%2F537.36+%28KHTML%2C+like+Gecko%29+Chrome%2F128.0.0.0+Safari%2F537.36&requrl=http%3A%2F%2Fgetpdf.pw%2Fbook%3Fres%3Dvista%26isbn%3D9781603585101%26kwd%3DMarijuana%2520is%2520Safer%3A%2520So%2520Why%2520are%2520We%2520Driving%2520People%2520to%2520Drink%3F - 1 sample
- https://2.bp.blogspot.com/-GOodtcP5Sxg/VXwo2aksCuI/AAAAAAAAAPw/Ehp2Gfer_LU/s1600/Family-Tree-Maker-Complete-2014-FULLY-Activated.jpg - 1 sample
- https://babesyare.weebly.com/blog/omegle-similar-sites - 1 sample
- https://batmansearch.weebly.com/blog/trump-golf-course-locations - 1 sample
- https://dikiea.weebly.com/blog/az-game-and-fish-locations - 1 sample
- https://euob.northwavepoint.com/sxp/i/636f8b858f681acb7bfa6f583a96630a.js - 1 sample
- https://fsmedia.imgix.net/da/f5/ed/71/f6c6/48e9/895c/4b062ecaef29/promotional-art-for-the-legend-of-vox-machina-featuring-the-characters-of-critical-roles-vox-ma.jpeg - 1 sample
- https://gasetell.weebly.com/blog/default-windows-7-sp1-xml-autounattend-user-create - 1 sample
- https://i.pinimg.com/originals/e8/0a/d4/e80ad4ccdefa8e207e60bd16bf41468b.jpg - 1 sample
- https://i.ytimg.com/vi/963W4XcI6PI/maxresdefault.jpg - 1 sample
- https://i.ytimg.com/vi/q09zvPrSFiA/maxresdefault.jpg - 1 sample
Recent HTML samples
- 1e05dfc72bbd95f7c7b8b4b9b4d68f3db8a2727e981d6d0fdc54d322f8b9f88e - malicious (2026-07-29)
- virussign.com_d113f05fea5d484a6475862bb71c9720.vir - malicious (2026-07-28)
- virussign.com_1a26b1c91eb6dda61d434b86f750ab30.vir - malicious (2026-07-28)
- virussign.com_a6bdcdafc183189537a9483acbea87b0.vir - malicious (2026-07-28)
- virussign.com_56029e4676b3671ea1dcfb76bb5d8920.vir - malicious (2026-07-28)
- virussign.com_048dd1a0f370749810ac364cb06418b0.vir - malicious (2026-07-28)
- virussign.com_c677a0d316a3da35225c67f0ae9c60b0.vir - malicious (2026-07-28)
Frequently asked about HTML
- What is HTML?
- HTML is a malware family tracked by MalwareAnalyzer by Cyble across 7 publicly analyzed samples. First seen 2026-07-28, most recently 2026-07-29. Observed ATT&CK techniques include T1112, T1071.004.
- How many HTML samples have been analyzed?
- MalwareAnalyzer by Cyble holds 7 publicly analyzed samples attributed to HTML, first seen 2026-07-28 and most recently 2026-07-29. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does HTML use?
- Across our HTML samples the most frequently observed techniques are T1112 (6), T1071.004 (1). Counts are the number of analyzed samples in which each technique was observed.
- What file types does HTML use?
- HTML samples in this corpus are distributed as html (7).
- Does HTML use command-and-control infrastructure?
- Yes. 50 distinct command-and-control indicators have been extracted from HTML samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is HTML malicious?
- 7 of 7 analyzed HTML samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends