Spam malware family
Spam is a malware family tracked by MalwareAnalyzer by Cyble across 551 publicly analyzed samples. First seen 2026-08-02, most recently 2026-08-13. Observed ATT&CK techniques include T1105, T1112, T1566.002.
Corpus statistics
- Publicly analyzed samples: 551
- First seen: 2026-08-02
- Last seen: 2026-08-13
- Verdicts: malicious 550, suspicious 1
- File types: pdf 551
ATT&CK techniques used by Spam
Extracted command-and-control infrastructure
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/8279107.pdf - 8 samples
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/lukuxaluk.pdf - 6 samples
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/pejajofedaxevaw_kozadesupuke.pdf - 6 samples
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/busixakowun_zefisuni.pdf - 6 samples
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/9653445.pdf - 6 samples
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/debizikirapanas.pdf - 6 samples
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/kezedivalo-bolumukejufufik.pdf - 5 samples
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/zakeme.pdf - 5 samples
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/0c18874847f.pdf - 5 samples
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/1515306.pdf - 5 samples
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/logape.pdf - 5 samples
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/laresisif_kigadebokenub_bajutinerid.pdf - 5 samples
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/3808383.pdf - 5 samples
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/filosom-lusiwikafese-jerupuxorukoti-novubolifunuw.pdf - 5 samples
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/8536469.pdf - 5 samples
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/godekux.pdf - 5 samples
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/likanutavorolebonat.pdf - 5 samples
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/wovexofek.pdf - 5 samples
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/tebavu_mofevuz_punoxibera_gijipomole.pdf - 5 samples
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/aa92d.pdf - 5 samples
Recent Spam samples
- sidas-genomuki.pdf - malicious (2026-08-13)
- c6287.pdf - malicious (2026-08-13)
- nuziwozonugof.pdf - malicious (2026-08-12)
- 8fd1a9303cb.pdf - malicious (2026-08-12)
- normal_5f962aec8f447.pdf - malicious (2026-08-12)
- 1563849.pdf - malicious (2026-08-12)
- 7857710.pdf - malicious (2026-08-12)
- normal_5f88d081ea7cc.pdf - malicious (2026-08-12)
- jisomokoline_sulebukagelur_xewakolino_wudime.pdf - malicious (2026-08-12)
- 17f650c399e325c.pdf - malicious (2026-08-12)
- normal_5f88d848ec9e3.pdf - malicious (2026-08-12)
- 35719952369.pdf - malicious (2026-08-12)
- vuxipub.pdf - malicious (2026-08-12)
- normal_5f88a0916a1f6.pdf - malicious (2026-08-12)
- 2851860.pdf - malicious (2026-08-12)
- senso_s250_manual.pdf - malicious (2026-08-11)
- 400236.pdf - malicious (2026-08-11)
- ba8917e282f650e.pdf - malicious (2026-08-11)
- 5317142.pdf - malicious (2026-08-11)
- c57d7e88f8ab.pdf - malicious (2026-08-11)
- sijirige.pdf - malicious (2026-08-11)
- 999c1d3756ead95.pdf - malicious (2026-08-11)
- voful.pdf - malicious (2026-08-11)
- vuwabeputuwozupisa.pdf - malicious (2026-08-11)
Frequently asked about Spam
- What is Spam?
- Spam is a malware family tracked by MalwareAnalyzer by Cyble across 551 publicly analyzed samples. First seen 2026-08-02, most recently 2026-08-13. Observed ATT&CK techniques include T1105, T1112, T1566.002.
- How many Spam samples have been analyzed?
- MalwareAnalyzer by Cyble holds 551 publicly analyzed samples attributed to Spam, first seen 2026-08-02 and most recently 2026-08-13. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Spam use?
- Across our Spam samples the most frequently observed techniques are T1105 (502), T1112 (448), T1566.002 (394). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Spam use?
- Spam samples in this corpus are distributed as pdf (551).
- Does Spam use command-and-control infrastructure?
- Yes. 50 distinct command-and-control indicators have been extracted from Spam samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is Spam malicious?
- 550 of 551 analyzed Spam samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends