MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5fd276cac6c062df5554e2a6f2c776f64743db9f431bc3323b6c1df8bc978dad. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 5fd276cac6c062df5554e2a6f2c776f64743db9f431bc3323b6c1df8bc978dad
SHA3-384 hash: cb4b1037b25b9087a2fae8dc1397e612734b42f238c4a9987d0c0275b8f22d1d65a45d30a916014e994d6a158920a901
SHA1 hash: 1a8f495989c3d4d8aefef0f6b5def976d01b8382
MD5 hash: dd580cc05f826d76f2f3680fcda22691
humanhash: mike-virginia-utah-river
File name:ORDER_NEW _HUY7986.JS
Download: download sample
Signature Formbook
File size:3'092'552 bytes
First seen:2026-08-05 12:49:56 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 49152:GC4qq+DdCcj0QOgjmEKTz4GsuN9hpAHlk/xoVo4Sq6ZKSVvGJiBx5OText1W0nRp:R4qq+DdCcjBOgjqz4Gs8hSHlkZoVo4Sb
TLSH T1B0E52A80A70CD4B0AA3D7B2CE1379E645A4EB04361C5EF1D757C6704B3A2A5B638ECD6
Magika unknown
Reporter James_inthe_box
Tags:exe FormBook js

Intelligence


File Origin
# of uploads :
1
# of downloads :
171
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug downloader dropper evasive masquerade obfuscated obfuscated packed repaired xloader
Verdict:
Malicious
File Type:
js
First seen:
2026-08-05T07:14:00Z UTC
Last seen:
2026-08-06T11:11:00Z UTC
Hits:
~1000
Gathering data
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook discovery execution persistence rat spyware stealer trojan
Behaviour
Modifies registry class
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Executes a command shell one-liner
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Checks computer location settings
Executes dropped EXE
Family: Formbook
Formbook payload
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments