Obfus malware family
Obfus is a malware family tracked by MalwareAnalyzer by Cyble across 31 publicly analyzed samples. First seen 2026-07-26, most recently 2026-08-24. Observed ATT&CK techniques include T1112, T1071.001.
Corpus statistics
- Publicly analyzed samples: 31
- First seen: 2026-07-26
- Last seen: 2026-08-24
- Verdicts: malicious 31
- File types: pe 16, html 15
ATT&CK techniques used by Obfus
Extracted command-and-control infrastructure
- http://gmpg.org/xfn/11 - 4 samples
- http://rozblog.com/temp/pp/blue.css - 2 samples
- http://rozblog.com/temp/pp/jquery-1.5.2.min.js - 2 samples
- http://rozblog.com/temp/pp/jquery.animate-colors-min.js - 2 samples
- http://rozblog.com/temp/pp/jquery.easing.1.3.js - 2 samples
- http://rozblog.com/temp/pp/jquery.skitter.min.js - 2 samples
- http://rozblog.com/temp/pp/pagenum.css - 2 samples
- http://rozblog.com/temp/pp/script.js - 2 samples
- http://rozblog.com/temp/pp/skitter.css - 2 samples
- http://rozblog.com/temp/pp/starrating.png - 2 samples
- http://rozblog.com/temp/pp/ticker.js - 2 samples
- http://blog.a3cfestival.com/hs-fs/hub/73154/file-2500758454-png/blog-files/bornfly-e1380165917379.png#keepProtocol - 1 sample
- http://blog.a3cfestival.com/post/news/style-village-vendor-born-fly - 1 sample
- http://blog.a3cfestival.com/post/news/style-village-vendor-born-fly?hs_amp=true - 1 sample
- http://born-fly.com/ - 1 sample
- http://clanonlinecs.ucoz.ru/3.jpg - 1 sample
- http://clanonlinecs.ucoz.ru/4.jpg - 1 sample
- http://clanonlinecs.ucoz.ru/6.jpg - 1 sample
- http://click.hotlog.ru/?2064007 - 1 sample
- http://fantasyflash.ru/vr2/vr16.htm - 1 sample
Recent Obfus samples
- b6e9176cfcc00c45695d05f4e2fa22bcf5d564a3284a33f6b268f68d1f6e1f88 - malicious (2026-08-24)
- 5a349836c0c4b3c5a09107568e4cb4353d449ce5f82b0f594dc54d6a5f277f46 - malicious (2026-08-23)
- 5bc254e4c096337c83b5f2ccbe1be9f25fe329f67717fb2c8236dbe7adc6047d - malicious (2026-08-23)
- 225022ef7b21707d7c89a1efbe913e49f4cab26027195564c92b60e6be5e60d0 - malicious (2026-08-22)
- d3271d526831d4629b35d968049c48274acc4c153ecba876075b1576c86aa9f5 - malicious (2026-08-22)
- df0df041668975f6cccee2c5ed47f09bb11536d861e95f2b4bdfe3ace1e76241 - malicious (2026-08-21)
- df0fe01fe12fe5f7d4441269962249bcfd1326616b6c658091e4a716bedf4530 - malicious (2026-08-21)
- e0dbf82caffa7267f46f644a40bc450863c5bcf5dae29ed4769a4be8d2e20bec - malicious (2026-08-21)
- bd5d583a67929a0df9d8f1369f921414da31823c8abd641c4df53267f5d4ce79 - malicious (2026-08-20)
- 990d351d210f4076b9e87421855cb1f2f68291bfdd7250b24d8e8ae7e4753665 - malicious (2026-08-20)
- 990dff7ba8267b11d35402e8acab13d6db2036756434641bf196461acc07f52a - malicious (2026-08-19)
- 257f60440e3081a3861a1f62f25031e52c09ce48c7ba54e90b0dd0d485956e01 - malicious (2026-08-19)
- 11b0ed1c6339e630e315ab7d87e6a05359fbac4a20ff5eb30882bf7fee4cbf30 - malicious (2026-08-16)
- virussign.com_008b021670cbdafe0ba02346a6e30e00.vir - malicious (2026-08-15)
- f555608a5f067cd37a7da087d8577cbf852c2098da434c04e97711bc4fb45b3f - malicious (2026-08-15)
- 502341e1c2605c1e6c4b719ef0b831297ba2dcda07da2d6f87ad364d26cc80f4 - malicious (2026-08-14)
- virussign.com_41a0d5189ab84ecf098c466413e5b4a0.vir - malicious (2026-08-13)
- virussign.com_da4cb71b1aa2148f4a15fd7af8a34b30.vir - malicious (2026-08-13)
- virussign.com_6d7bf24d52cabda9ccbae655cbdf9750.vir - malicious (2026-08-13)
- virussign.com_db1e97ac67c9a673ca8cd1319d796bf0.vir - malicious (2026-08-13)
- virussign.com_530bded18b9c67b01f8256d891b53d00.vir - malicious (2026-08-12)
- virussign.com_7c438095a2e03fb33521dfdd105f8de0.vir - malicious (2026-08-12)
- virussign.com_50f207fcc215cda310cddf55ae8e75a0.vir - malicious (2026-07-28)
- virussign.com_c9d8bda1823e061e667a23b4862573f0.vir - malicious (2026-07-28)
Frequently asked about Obfus
- What is Obfus?
- Obfus is a malware family tracked by MalwareAnalyzer by Cyble across 31 publicly analyzed samples. First seen 2026-07-26, most recently 2026-08-24. Observed ATT&CK techniques include T1112, T1071.001.
- How many Obfus samples have been analyzed?
- MalwareAnalyzer by Cyble holds 31 publicly analyzed samples attributed to Obfus, first seen 2026-07-26 and most recently 2026-08-24. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Obfus use?
- Across our Obfus samples the most frequently observed techniques are T1112 (10), T1071.001 (2). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Obfus use?
- Obfus samples in this corpus are distributed as pe (16), html (15).
- Does Obfus use command-and-control infrastructure?
- Yes. 50 distinct command-and-control indicators have been extracted from Obfus samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is Obfus malicious?
- 31 of 31 analyzed Obfus samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends