Office365 malware family
Office365 is a malware family tracked by MalwareAnalyzer by Cyble across 7 publicly analyzed samples. First seen 2026-08-19, most recently 2026-08-22.
Corpus statistics
- Publicly analyzed samples: 7
- First seen: 2026-08-19
- Last seen: 2026-08-22
- Verdicts: suspicious 5, malicious 2
- File types: unknown 5, html 2
Extracted command-and-control infrastructure
- https://autologon.mic - 2 samples
- https://autologon.microsoftazu - 2 samples
- https://autologon.microsoftazurea - 2 samples
Recent Office365 samples
- d3281964f0bf3283372ef3726756d0289177db490d16785aa0480e171ed40a84 - suspicious (2026-08-22)
- d3212cecb80244e2f66c763638b05c340f713b2903dad017baff04ca196ed50d - suspicious (2026-08-22)
- d328402c3353e32dad58909c1e407f2b17bb262e1760ae1f055a4b7934046d12 - suspicious (2026-08-22)
- 32355d18c0964d6a36a4c52477d5121719f8a21cfaa7b0ad1facfd38dfa8a4fe - suspicious (2026-08-21)
- d02597f6bade76936d17cec840dd9213bca005732f7cc1494c6253c79cfe3f68 - malicious (2026-08-21)
- bd5291d8d8fcefc8d2c6822931c6b4a97ef76fb5aa48aab9e6095db083048ad4 - suspicious (2026-08-20)
- fb977e876c48dbfd68168029a68182013dba924c4e7af354af0dabdd8b1cc37f - malicious (2026-08-19)
Frequently asked about Office365
- What is Office365?
- Office365 is a malware family tracked by MalwareAnalyzer by Cyble across 7 publicly analyzed samples. First seen 2026-08-19, most recently 2026-08-22.
- How many Office365 samples have been analyzed?
- MalwareAnalyzer by Cyble holds 7 publicly analyzed samples attributed to Office365, first seen 2026-08-19 and most recently 2026-08-22. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What file types does Office365 use?
- Office365 samples in this corpus are distributed as unknown (5), html (2).
- Does Office365 use command-and-control infrastructure?
- Yes. 3 distinct command-and-control indicators have been extracted from Office365 samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is Office365 malicious?
- 2 of 7 analyzed Office365 samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends