MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 72c5259286ef8e5e2173b3fd798015767709d8a60d84d195bba3440d197d5efb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 12


Intelligence 12 IOCs YARA 16 File information Comments

SHA256 hash: 72c5259286ef8e5e2173b3fd798015767709d8a60d84d195bba3440d197d5efb
SHA3-384 hash: f8ff61ba78f401b1a4bd618d2b6da8ecc75340c8c3a2424e811a5b2ae420bd7ad3de7ad4cce1f54114149b2da875727d
SHA1 hash: ac903b037de395cc8b1c86b9baa1bbacfd508b75
MD5 hash: 2291539ead4fb1f64fe9b16ff00e86fe
humanhash: river-massachusetts-sodium-mockingbird
File name:PO_N0_2026_ORDER.js
Download: download sample
Signature Formbook
File size:3'219'702 bytes
First seen:2026-07-21 07:22:03 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 12288:jyztysqcmd41OtJuw6af8GBotduf6cdUX2hXt0jLoP34nWWvHHdS:2ztysRmdyXrtdK6c6Mt0j/WWQ
TLSH T195E519E720DF790F1949BA3A849D2D594FBEE0192BC3BDF1E0D60D84104E89726199EF
Magika javascript
Reporter lowmal3
Tags:FormBook js

Intelligence


File Origin
# of uploads :
1
# of downloads :
168
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
94.9%
Tags:
autorun dropper shell blic
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
downloader formbook masquerade obfuscated repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-07-21T03:53:00Z UTC
Last seen:
2026-07-23T04:45:00Z UTC
Hits:
~1000
Result
Threat name:
FormBook
Detection:
malicious
Classification:
troj.spyw.expl.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
Antivirus detection for URL or domain
Binary is likely a compiled AutoIt script file
Bypasses PowerShell execution policy
Creates autostart registry keys with suspicious values (likely registry only malware)
Found direct / indirect Syscall (likely to bypass EDR)
Injects a PE file into a foreign processes
JavaScript file contains suspicious strings
JavaScript source code contains functionality to generate code involving a shell, file or stream
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for submitted file
Performs DNS queries to domains with low reputation
Queues an APC in another process (thread injection)
Sigma detected: New RUN Key Pointing to Suspicious Folder
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Suspicious execution chain found
Suspicious powershell command line found
Switches to a custom stack to bypass stack traces
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Unusual module load detection (module proxying)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Yara detected FormBook
Yara detected Powershell decode and execute
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1945680 Sample: PO_N0_2026_ORDER.js Startdate: 21/07/2026 Architecture: WINDOWS Score: 100 58 www.skylyforge.xyz 2->58 60 www.wkexnue.click 2->60 62 7 other IPs or domains 2->62 76 Suricata IDS alerts for network traffic 2->76 78 Malicious sample detected (through community Yara rule) 2->78 80 Antivirus detection for URL or domain 2->80 84 10 other signatures 2->84 11 wscript.exe 2 4 2->11         started        14 powershell.exe 2->14         started        16 powershell.exe 19 2->16         started        18 powershell.exe 17 2->18         started        signatures3 82 Performs DNS queries to domains with low reputation 58->82 process4 signatures5 112 Suspicious powershell command line found 11->112 114 Wscript starts Powershell (via cmd or directly) 11->114 116 Creates autostart registry keys with suspicious values (likely registry only malware) 11->116 122 3 other signatures 11->122 20 powershell.exe 16 11->20         started        118 Writes to foreign memory regions 14->118 120 Injects a PE file into a foreign processes 14->120 23 conhost.exe 14->23         started        25 aspnet_compiler.exe 14->25         started        33 7 other processes 14->33 27 conhost.exe 16->27         started        35 7 other processes 16->35 29 conhost.exe 1 18->29         started        31 aspnet_compiler.exe 18->31         started        37 5 other processes 18->37 process6 signatures7 94 Writes to foreign memory regions 20->94 96 Injects a PE file into a foreign processes 20->96 39 aspnet_compiler.exe 20->39         started        42 aspnet_compiler.exe 20->42         started        44 conhost.exe 20->44         started        46 10 other processes 20->46 process8 signatures9 98 Modifies the context of a thread in another process (thread injection) 39->98 100 Maps a DLL or memory area into another process 39->100 102 Queues an APC in another process (thread injection) 39->102 104 Found direct / indirect Syscall (likely to bypass EDR) 39->104 48 wgGC0g8Ld.exe 39->48 injected 106 Unusual module load detection (module proxying) 42->106 108 Switches to a custom stack to bypass stack traces 42->108 process10 signatures11 70 Binary is likely a compiled AutoIt script file 48->70 72 Maps a DLL or memory area into another process 48->72 74 Found direct / indirect Syscall (likely to bypass EDR) 48->74 51 getmac.exe 13 48->51         started        process12 signatures13 86 Tries to steal Mail credentials (via file / registry access) 51->86 88 Tries to harvest and steal browser information (history, passwords, etc) 51->88 90 Modifies the context of a thread in another process (thread injection) 51->90 92 3 other signatures 51->92 54 XW9HGMb5Uk0Y.exe 51->54 injected process14 dnsIp15 64 www.skylyforge.xyz 199.192.19.23, 49788, 49789, 49790 NAMECHEAP-NET-NamecheapIncUS United States 54->64 66 facai10zubm.xinjiuzubm5088.app 199.180.117.16, 49776, 49777, 49778 IT7NET-IT7NetworksIncCA United States 54->66 68 4 other IPs or domains 54->68 110 Binary is likely a compiled AutoIt script file 54->110 signatures16
Gathering data
Threat name:
Script-JS.Trojan.Acsogenixx
Status:
Malicious
First seen:
2026-07-21 07:22:35 UTC
File Type:
Text (JavaScript)
AV detection:
10 of 38 (26.32%)
Threat level:
  5/5
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook discovery execution persistence rat spyware stealer trojan
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Adds Run key to start application
Drops startup file
Command and Scripting Interpreter: PowerShell
Family: Formbook
Formbook payload
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Base64_Encoded_Powershell_Directives
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__GlobalFlags
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Active
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Thread
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:dgaagas
Author:Harshit
Description:Uses certutil.exe to download a file named test.txt
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns
Rule name:TH_Win_ETW_Bypass_2025_CYFARE
Author:CYFARE
Description:Windows ETW Bypass Detection Rule - 2025
Reference:https://cyfare.net/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments