🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 78aa211440dc945fde98a9d035a45c014813331edc9d2d5dc0ebbeb78ecc77ea. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 12


Intelligence 12 IOCs YARA File information Comments

SHA256 hash: 78aa211440dc945fde98a9d035a45c014813331edc9d2d5dc0ebbeb78ecc77ea
SHA3-384 hash: b156fbdd2243ef183d9fb6338293ca6a337a0a6233a8a8619c4a20f6b9326b21715bfab2397b8da72238ab0df8e1ddff
SHA1 hash: 5c793b7673af9c092687cb2a0c5ca2bd08db54e0
MD5 hash: 077e58942aa6f4c706d1efdd456246f1
humanhash: pizza-whiskey-five-yellow
File name:SCANNED_DOCUMENT_HSBC_PAYMENT_COPY_pdf.JS
Download: download sample
Signature Formbook
File size:3'931'565 bytes
First seen:2026-08-17 05:38:41 UTC
Last seen:2026-08-17 12:14:59 UTC
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 98304:wJrSTu/W8HNkz41tXd4yDbB2ycGiiJw2zqJvXrEH925uZ4xB5cDBWVO:wAMO41tDbBkiD8vXQH9UuZ4xgBWVO
TLSH T1E20661A077C899397360E75D42369921A00E254725E3CB163BFDF2043B2BA977358AF7
Magika txt
Reporter lowmal3
Tags:FormBook js

Intelligence


File Origin
# of uploads :
2
# of downloads :
176
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug dbatloader downloader dropper evasive formbook loader masquerade obfuscated obfuscated packed repaired xloader
Verdict:
Malicious
File Type:
js
First seen:
2026-08-16T07:52:00Z UTC
Last seen:
2026-08-17T02:32:00Z UTC
Hits:
~1000
Result
Threat name:
FormBook
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
Found API chain indicative of debugger detection
Found direct / indirect Syscall (likely to bypass EDR)
JavaScript source code contains functionality to generate code involving a shell, file or stream
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for submitted file
Queues an APC in another process (thread injection)
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Switches to a custom stack to bypass stack traces
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Unusual module load detection (module proxying)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Yara detected FormBook
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1958816 Sample: SCANNED_DOCUMENT_HSBC_PAYME... Startdate: 17/08/2026 Architecture: WINDOWS Score: 100 31 www.forex-hk.com 2->31 33 www.babnam.live 2->33 35 6 other IPs or domains 2->35 47 Suricata IDS alerts for network traffic 2->47 49 Multi AV Scanner detection for submitted file 2->49 51 Yara detected FormBook 2->51 53 3 other signatures 2->53 10 wscript.exe 3 2->10         started        signatures3 process4 signatures5 63 Windows Scripting host queries suspicious COM object (likely to drop second stage) 10->63 13 UJGTIMFWJVUQVOKA.PIF 1 10->13         started        process6 signatures7 65 Found API chain indicative of debugger detection 13->65 67 Modifies the context of a thread in another process (thread injection) 13->67 69 Maps a DLL or memory area into another process 13->69 71 3 other signatures 13->71 16 n06YxmhzWW.exe 13->16 injected 19 conhost.exe 13->19         started        process8 signatures9 43 Maps a DLL or memory area into another process 16->43 45 Found direct / indirect Syscall (likely to bypass EDR) 16->45 21 cmdl32.exe 13 16->21         started        24 autochk.exe 16->24         started        process10 signatures11 55 Tries to steal Mail credentials (via file / registry access) 21->55 57 Tries to harvest and steal browser information (history, passwords, etc) 21->57 59 Modifies the context of a thread in another process (thread injection) 21->59 61 3 other signatures 21->61 26 ct0GCi98D.exe 21->26 injected 29 firefox.exe 21->29         started        process12 dnsIp13 37 www.babnam.live 66.29.152.246, 49718, 49719, 49720 NAMECHEAP-NET-NamecheapIncUS United States 26->37 39 aristrials.com 185.199.111.153, 49722, 49723, 49724 FASTLY-FastlyIncUS United States 26->39 41 3 other IPs or domains 26->41
Gathering data
Threat name:
Win32.Trojan.Malgent
Status:
Malicious
First seen:
2026-08-16 12:52:42 UTC
File Type:
Text (JavaScript)
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook execution rat spyware stealer trojan
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Checks computer location settings
Executes dropped EXE
Family: Formbook
Formbook payload
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments