Iframe malware family
Iframe is a malware family tracked by MalwareAnalyzer by Cyble across 3 publicly analyzed samples. First seen 2026-07-28, most recently 2026-08-20. Observed ATT&CK techniques include T1112.
Corpus statistics
- Publicly analyzed samples: 3
- First seen: 2026-07-28
- Last seen: 2026-08-20
- Verdicts: malicious 2, suspicious 1
- File types: html 2, unknown 1
ATT&CK techniques used by Iframe
- T1112 - 1 sample
Extracted command-and-control infrastructure
- http://ondashvideocamera.blogspot.com/ - 1 sample
- http://ondashvideocamera.blogspot.com/2013/12/best-deals-acti-5mp-box-with-dn-basic.html - 1 sample
- http://ondashvideocamera.blogspot.com/favicon.ico - 1 sample
- http://ondashvideocamera.blogspot.com/feeds/4536736745869072298/comments/default - 1 sample
- http://ondashvideocamera.blogspot.com/feeds/posts/default - 1 sample
- http://ondashvideocamera.blogspot.com/feeds/posts/default?alt=rss - 1 sample
- https://draft.blogger.com/dyn-css/authorization.css?targetBlogID=8403186252409469039&zx=40fa020e-dfe3-4a79-be67-8c798cfd2065 - 1 sample
- https://draft.blogger.com/feeds/8403186252409469039/posts/default - 1 sample
- https://draft.blogger.com/post-edit.g?blogID=8403186252409469039&postID=4536736745869072298&from=pencil - 1 sample
- https://draft.blogger.com/share-post.g?blogID=8403186252409469039&postID=4536736745869072298&target=blog - 1 sample
- https://draft.blogger.com/share-post.g?blogID=8403186252409469039&postID=4536736745869072298&target=email - 1 sample
- https://resources.blogblog.com/img/icon18_edit_allbkg.gif - 1 sample
- https://www.blogger.com/static/v1/jsbin/403901366-ieretrofit.js - 1 sample
- https://www.blogger.com/static/v1/widgets/1667664774-css_bundle_v2.css - 1 sample
Recent Iframe samples
- bd57e462fa7bca008c0417e41082909b8b7b22d6e8ff7d2f10aeef0f2ac54f0d - malicious (2026-08-20)
- 7fa72a60b63204f1264fd850931acd9683148a665f08c4108c2ba26035b385bd - malicious (2026-08-05)
- virussign.com_05a5cb9d82885f092e8e02024bbb1f40.vir - suspicious (2026-07-28)
Frequently asked about Iframe
- What is Iframe?
- Iframe is a malware family tracked by MalwareAnalyzer by Cyble across 3 publicly analyzed samples. First seen 2026-07-28, most recently 2026-08-20. Observed ATT&CK techniques include T1112.
- How many Iframe samples have been analyzed?
- MalwareAnalyzer by Cyble holds 3 publicly analyzed samples attributed to Iframe, first seen 2026-07-28 and most recently 2026-08-20. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Iframe use?
- Across our Iframe samples the most frequently observed techniques are T1112 (1). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Iframe use?
- Iframe samples in this corpus are distributed as html (2), unknown (1).
- Does Iframe use command-and-control infrastructure?
- Yes. 14 distinct command-and-control indicators have been extracted from Iframe samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is Iframe malicious?
- 2 of 3 analyzed Iframe samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends