MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3383eb3b2432c941b970d677a508b424c0748cce78467c4e947c90fb616e9f59. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 3383eb3b2432c941b970d677a508b424c0748cce78467c4e947c90fb616e9f59
SHA3-384 hash: ff835b4326d912471c4c69cb6b682b00fb9d78f9668155bd0ffae0fdea9bb228ddbf05cf01626cf8aa31c5542ecbd209
SHA1 hash: 2804464c93e3d0b0b9e97e877107ef050d870bce
MD5 hash: c44e14a4f0921fbe131130823a71704c
humanhash: zebra-golf-wyoming-florida
File name:Comprobante transferencia.pdf.js
Download: download sample
Signature Formbook
File size:67'553 bytes
First seen:2026-07-30 15:13:28 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 768:V7L3tzL1pG83xEt50t/8XkPxjnj8c86h8YpF8Fhy3K8r5r:Vxc5M/F
TLSH T1E363C9337BDB4989486833AEEE26C704EBDD6B0C5D518AF323729B5CD42DC1905319BA
Magika javascript
Reporter James_inthe_box
Tags:exe FormBook js

Intelligence


File Origin
# of uploads :
1
# of downloads :
173
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm fingerprint masquerade powershell repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-07-30T12:16:00Z UTC
Last seen:
2026-08-01T12:02:00Z UTC
Hits:
~100
Gathering data
Threat name:
Script-JS.Downloader.RemcosRAT
Status:
Malicious
First seen:
2026-07-30 15:13:30 UTC
File Type:
Binary
AV detection:
8 of 24 (33.33%)
Threat level:
  3/5
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook execution rat spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Command and Scripting Interpreter: PowerShell
Suspicious use of SetThreadContext
Badlisted process makes network request
Family: Formbook
Formbook payload
Process spawned unexpected child process
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments