Scrinject malware family
Scrinject is a malware family tracked by MalwareAnalyzer by Cyble across 1 publicly analyzed sample. First seen 2026-07-29, most recently 2026-07-29. Observed ATT&CK techniques include T1112.
Corpus statistics
- Publicly analyzed samples: 1
- First seen: 2026-07-29
- Last seen: 2026-07-29
- Verdicts: malicious 1
- File types: html 1
ATT&CK techniques used by Scrinject
- T1112 - 1 sample
Extracted command-and-control infrastructure
- http://2.bp.blogspot.com/-trePMSNoxaY/U4UHOqz6hwI/AAAAAAAAAGo/cfn2S4W4nqQ/s1600/Odd-Themes-Logo.png - 1 sample
- http://3.bp.blogspot.com/-zP87C2q9yog/UVopoHY30SI/AAAAAAAAE5k/AIyPvrpGLn8/s1600/picture_not_available.png - 1 sample
- http://www.oddthemes.com - 1 sample
- https://bogolive.blogspot.com//__/firebase/7.14.0/firebase-analytics.js - 1 sample
- https://bogolive.blogspot.com/favicon.ico - 1 sample
- https://bogolive.blogspot.com/feeds/posts/default - 1 sample
- https://bogolive.blogspot.com/feeds/posts/default?alt=rss - 1 sample
- https://cdn.onesignal.com/sdks/OneSignalSDK.js - 1 sample
- https://ogp.me/ns# - 1 sample
- https://www.blogger.com/dyn-css/authorization.css?targetBlogID=3533755401777908645&zx=1b57ebc2-ef27-460c-9f6d-d1d4a85382ff - 1 sample
- https://www.blogger.com/feeds/3533755401777908645/posts/default - 1 sample
- https://www.blogger.com/static/v1/jsbin/403901366-ieretrofit.js - 1 sample
- https://www.blogger.com/static/v1/widgets/1667664774-css_bundle_v2.css - 1 sample
Recent Scrinject samples
- d31a2f171ef9799638a940149fbe7a025f10efbf0daccc1e270637447ce405be - malicious (2026-07-29)
Frequently asked about Scrinject
- What is Scrinject?
- Scrinject is a malware family tracked by MalwareAnalyzer by Cyble across 1 publicly analyzed sample. First seen 2026-07-29, most recently 2026-07-29. Observed ATT&CK techniques include T1112.
- How many Scrinject samples have been analyzed?
- MalwareAnalyzer by Cyble holds 1 publicly analyzed sample attributed to Scrinject, first seen 2026-07-29 and most recently 2026-07-29. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Scrinject use?
- Across our Scrinject samples the most frequently observed techniques are T1112 (1). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Scrinject use?
- Scrinject samples in this corpus are distributed as html (1).
- Does Scrinject use command-and-control infrastructure?
- Yes. 13 distinct command-and-control indicators have been extracted from Scrinject samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is Scrinject malicious?
- 1 of 1 analyzed Scrinject sample was scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends