Office365 malware family
Office365 is a malware family tracked by MalwareAnalyzer by Cyble across 9 publicly analyzed samples. First seen 2026-08-19, most recently 2026-08-26.
Corpus statistics
- Publicly analyzed samples: 9
- First seen: 2026-08-19
- Last seen: 2026-08-26
- Verdicts: suspicious 7, malicious 2
- File types: unknown 7, html 2
Extracted command-and-control infrastructure
- https://autologon.mic - 2 samples
- https://autologon.microsoftazu - 2 samples
- https://autologon.microsoftazurea - 2 samples
Recent Office365 samples
- cdd7d04fea272447b5932a371d5bdb858f2200737d200c0b87cc781618244eb9 - suspicious (2026-08-26)
- e33f2bb168135f4f78844ba43c671d7f1175f9609ea14d0539d58d6a3b4604cf - suspicious (2026-08-25)
- d3281964f0bf3283372ef3726756d0289177db490d16785aa0480e171ed40a84 - suspicious (2026-08-22)
- d3212cecb80244e2f66c763638b05c340f713b2903dad017baff04ca196ed50d - suspicious (2026-08-22)
- d328402c3353e32dad58909c1e407f2b17bb262e1760ae1f055a4b7934046d12 - suspicious (2026-08-22)
- 32355d18c0964d6a36a4c52477d5121719f8a21cfaa7b0ad1facfd38dfa8a4fe - suspicious (2026-08-21)
- d02597f6bade76936d17cec840dd9213bca005732f7cc1494c6253c79cfe3f68 - malicious (2026-08-21)
- bd5291d8d8fcefc8d2c6822931c6b4a97ef76fb5aa48aab9e6095db083048ad4 - suspicious (2026-08-20)
- fb977e876c48dbfd68168029a68182013dba924c4e7af354af0dabdd8b1cc37f - malicious (2026-08-19)
Frequently asked about Office365
- What is Office365?
- Office365 is a malware family tracked by MalwareAnalyzer by Cyble across 9 publicly analyzed samples. First seen 2026-08-19, most recently 2026-08-26.
- How many Office365 samples have been analyzed?
- MalwareAnalyzer by Cyble holds 9 publicly analyzed samples attributed to Office365, first seen 2026-08-19 and most recently 2026-08-26. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What file types does Office365 use?
- Office365 samples in this corpus are distributed as unknown (7), html (2).
- Does Office365 use command-and-control infrastructure?
- Yes. 3 distinct command-and-control indicators have been extracted from Office365 samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is Office365 malicious?
- 2 of 9 analyzed Office365 samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends