Phishing malware family
Phishing is a malware family tracked by MalwareAnalyzer by Cyble across 706 publicly analyzed samples. First seen 2026-08-02, most recently 2026-08-13. Observed ATT&CK techniques include T1566.002, T1105, T1112.
Corpus statistics
- Publicly analyzed samples: 706
- First seen: 2026-08-02
- Last seen: 2026-08-13
- Verdicts: malicious 705, suspicious 1
- File types: pdf 705, html 1
ATT&CK techniques used by Phishing
Extracted command-and-control infrastructure
- http://arsvet.ru/img/upload/pezibeletu.pdf - 2 samples
- http://assessmentinsight.com/ckfinder/userfiles/files/5368959863.pdf - 2 samples
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf6283f8cdb769c6dabe39/1606378116378/volume_of_revolution_disk_method.pdf - 2 samples
- http://0228339500.kad.tw/kads/ckfinder/userfiles/files/57348888937.pdf - 1 sample
- http://0851gay.org/userfiles/202106file/2021061807103870554.pdf - 1 sample
- http://104.156.58.56/~web2inbox/wp-content/plugins/formcraft/file-upload/server/content/files/1608b5c84784d1---26346536972.pdf - 1 sample
- http://104.156.58.56/~web2inbox/wp-content/plugins/formcraft/file-upload/server/content/files/1613b473dd7ff3---84151137970.pdf - 1 sample
- http://10glazsikeyrosa.ru/file/91210216728.pdf - 1 sample
- http://111-orte.de/testarea/cwsCMSlight/media/files/27091038022.pdf - 1 sample
- http://140.121.125.49/ckfinder/userfiles/files/20210918_171329.pdf - 1 sample
- http://18554080.com/userfiles/file/68860903480.pdf - 1 sample
- http://18554080.com/userfiles/file/luweregowan.pdf - 1 sample
- http://1careglobal.com/upload/files/razexurakitosulerasozumek.pdf - 1 sample
- http://211.129.1.225/system/ckfinder/userfiles/files/jajaladubij.pdf - 1 sample
- http://2478.ru/admin/ckfinder/userfiles/files/vasuletamobopopuzotig.pdf - 1 sample
- http://24cvety.ru/upload/files/43874775643.pdf - 1 sample
- http://24cvety.ru/upload/files/paragaxigejabifoma.pdf - 1 sample
- http://24cvety.ru/upload/files/zosekivizi.pdf - 1 sample
- http://2girlstrippin.com/wp-content/plugins/formcraft/file-upload/server/content/files/16147b515aecff---13222092542.pdf - 1 sample
- http://2gusevshop.space/50720453144g4co8.pdf - 1 sample
Recent Phishing samples
- 9978344e66.pdf - malicious (2026-08-13)
- venuwujogolelun.pdf - malicious (2026-08-13)
- 5b46ec_94fc2d06ef2d4bd7979aa2a75e8fb9fe.pdf - malicious (2026-08-13)
- tebabezuse.pdf - malicious (2026-08-13)
- normal_5fc655b671501.pdf - malicious (2026-08-13)
- 6745953.pdf - malicious (2026-08-12)
- 800b88_159566329ad842248b65d953f4d867e0.pdf - malicious (2026-08-12)
- taxorajirezejiwadex.pdf - malicious (2026-08-12)
- raxasevofagomiw.pdf - malicious (2026-08-12)
- 4663859.pdf - malicious (2026-08-12)
- bivejabogo-totuveselaz-botaxusaxudaw.pdf - malicious (2026-08-12)
- normal_5faf7ef37019c.pdf - malicious (2026-08-12)
- normal_5fcc45787b3e0.pdf - malicious (2026-08-12)
- d271d2.pdf - malicious (2026-08-12)
- 1466813.pdf - malicious (2026-08-12)
- 3772202.pdf - malicious (2026-08-12)
- normal_60304ef4dc04a.pdf - malicious (2026-08-12)
- normal_5fad6f4910540.pdf - malicious (2026-08-12)
- gukugi.pdf - malicious (2026-08-12)
- normal_5fc1cf624bca0.pdf - malicious (2026-08-12)
- 5558097.pdf - malicious (2026-08-12)
- normal_5fc8da32e0660.pdf - malicious (2026-08-12)
- 0a51c1_f0796f407e044497abe3744098127bd1.pdf - malicious (2026-08-12)
- 7858292.pdf - malicious (2026-08-12)
Frequently asked about Phishing
- What is Phishing?
- Phishing is a malware family tracked by MalwareAnalyzer by Cyble across 706 publicly analyzed samples. First seen 2026-08-02, most recently 2026-08-13. Observed ATT&CK techniques include T1566.002, T1105, T1112.
- How many Phishing samples have been analyzed?
- MalwareAnalyzer by Cyble holds 706 publicly analyzed samples attributed to Phishing, first seen 2026-08-02 and most recently 2026-08-13. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Phishing use?
- Across our Phishing samples the most frequently observed techniques are T1566.002 (497), T1105 (476), T1112 (380). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Phishing use?
- Phishing samples in this corpus are distributed as pdf (705), html (1).
- Does Phishing use command-and-control infrastructure?
- Yes. 50 distinct command-and-control indicators have been extracted from Phishing samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is Phishing malicious?
- 705 of 706 analyzed Phishing samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends