MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 60fcd18da15bc9a2af79d3a3354b8f2c7d58597962fa30af5ef695790821f8e3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 60fcd18da15bc9a2af79d3a3354b8f2c7d58597962fa30af5ef695790821f8e3
SHA3-384 hash: 37b0b5d6b289779e924af11affd0f0dd5fa2dedbb50202a06ee33534674c3f453aa1162f32c8a1657b26bb55ea14947d
SHA1 hash: 40cece7626179b0e979214be2c05073c25d1dfe7
MD5 hash: 2584a07c58e9825b48341d34bdde0429
humanhash: fruit-lithium-alanine-lamp
File name:Zapytanie Ofertowe_743.js
Download: download sample
Signature Formbook
File size:520'932 bytes
First seen:2026-08-20 07:55:40 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 6144:BKn14lbACWNPKvqS+qQhmj3VVTYlJ+tgQjbSM1mVKXfQjbP40Ey7Yq:BKusNPKDUmjzxNp3leYq
TLSH T140B4662DE2EC429598D08928D2FDA7830A3DFC8E3BEE3158259F54DC9BA435417739C6
TrID 66.6% (.TXT) Text - UTF-16 (LE) encoded (2000/1)
33.3% (.MP3) MP3 audio (1000/1)
Magika txt
Reporter abuse_ch
Tags:FormBook js

Intelligence


File Origin
# of uploads :
1
# of downloads :
151
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
aes base64 base64 conhost crypto evasive lolbin obfuscated overlay persistence powershell repaired wscript
Result
Threat name:
FormBook
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
AI detected malicious Powershell script
Bypasses PowerShell execution policy
Creates a thread in another existing process (thread injection)
Early bird code injection technique detected
Found direct / indirect Syscall (likely to bypass EDR)
JScript performs obfuscated calls to suspicious functions
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for submitted file
Potential evasive JS / VBS script found (domain check)
Queues an APC in another process (thread injection)
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious PowerShell Parameter Substring
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: WScript or CScript Dropper
Sigma detected: WScript or CScript Dropper - File
Suricata IDS alerts for network traffic
Suspicious powershell command line found
Switches to a custom stack to bypass stack traces
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Unusual module load detection (module proxying)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript called in batch mode (surpress errors)
Yara detected FormBook
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1961009 Sample: Zapytanie Ofertowe_743.js Startdate: 20/08/2026 Architecture: WINDOWS Score: 100 69 www.verab.top 2->69 71 www.roket16.net 2->71 73 7 other IPs or domains 2->73 85 Suricata IDS alerts for network traffic 2->85 87 Malicious sample detected (through community Yara rule) 2->87 89 Multi AV Scanner detection for submitted file 2->89 91 11 other signatures 2->91 12 powershell.exe 14 16 2->12         started        16 powershell.exe 15 2->16         started        18 wscript.exe 1 7 2->18         started        21 2 other processes 2->21 signatures3 process4 dnsIp5 81 nieuw.technoberg.nl 185.183.203.16, 443, 49701, 49702 TECHNOBERGNL Netherlands 12->81 111 Early bird code injection technique detected 12->111 113 Writes to foreign memory regions 12->113 115 Maps a DLL or memory area into another process 12->115 23 ilasm.exe 12->23         started        117 Queues an APC in another process (thread injection) 16->117 26 dwm.exe 16->26         started        55 C:\Users\user\AppData\Local\...\s1vmt1a9v9yb, ASCII 18->55 dropped 57 C:\Users\user\AppData\Local\...\s1vmt1a9v9ya, ASCII 18->57 dropped 59 C:\Users\user\AppData\...\s1vmt1a9v9y.ps1, ASCII 18->59 dropped 61 C:\Users\user\AppData\...\PhotoStudio.js, Unicode 18->61 dropped 119 JScript performs obfuscated calls to suspicious functions 18->119 121 Windows Scripting host queries suspicious COM object (likely to drop second stage) 18->121 123 Potential evasive JS / VBS script found (domain check) 18->123 83 127.0.0.1 unknown unknown 21->83 63 C:\Users\user\AppData\Local\...\bj4mt1a9xpkb, ASCII 21->63 dropped 65 C:\Users\user\AppData\Local\...\bj4mt1a9xpka, ASCII 21->65 dropped 67 C:\Users\user\AppData\...\bj4mt1a9xpk.ps1, ASCII 21->67 dropped file6 signatures7 process8 signatures9 99 Maps a DLL or memory area into another process 23->99 101 Creates a thread in another existing process (thread injection) 23->101 28 dChHX9XdHs.exe 23->28 injected 31 WerFault.exe 21 23->31         started        33 WerFault.exe 21 26->33         started        process10 signatures11 107 Maps a DLL or memory area into another process 28->107 109 Found direct / indirect Syscall (likely to bypass EDR) 28->109 35 explorer.exe 28->35         started        38 explorer.exe 28->38         started        process12 signatures13 93 Modifies the context of a thread in another process (thread injection) 35->93 95 Maps a DLL or memory area into another process 35->95 97 Switches to a custom stack to bypass stack traces 35->97 40 BsmrDNoB.exe 35->40 injected 43 pPu6xqyZi7hGR.exe 38->43 injected process14 signatures15 103 Maps a DLL or memory area into another process 40->103 105 Found direct / indirect Syscall (likely to bypass EDR) 40->105 45 PATHPING.EXE 13 40->45         started        48 PATHPING.EXE 43->48         started        process16 signatures17 125 Tries to steal Mail credentials (via file / registry access) 45->125 127 Tries to harvest and steal browser information (history, passwords, etc) 45->127 129 Modifies the context of a thread in another process (thread injection) 45->129 131 3 other signatures 45->131 50 T9KOIbBXS15.exe 45->50 injected 53 firefox.exe 45->53         started        process18 dnsIp19 75 roket16.net 220.158.235.210, 49730, 49731, 49732 VIETTELCAMBODIA-AS-APISPIXPINCAMBODIAWITHTHEBESTVERVICEINTHEREKH Bangladesh 50->75 77 www.eblackwidow.net 208.98.35.91, 49726, 49727, 49728 SHARKTECH-SharktechUS United States 50->77 79 5 other IPs or domains 50->79
Gathering data
Threat name:
Script-JS.Trojan.Heuristic
Status:
Malicious
First seen:
2026-08-20 08:11:30 UTC
File Type:
Text (JavaScript)
AV detection:
10 of 24 (41.67%)
Threat level:
  2/5
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook discovery execution persistence rat spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Command and Scripting Interpreter: JavaScript
System Location Discovery: System Language Discovery
Suspicious use of NtCreateThreadExHideFromDebugger
Suspicious use of SetThreadContext
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Downloads MZ/PE file
Family: Formbook
Formbook payload
Suspicious use of NtCreateUserProcessOtherParentProcess
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments