MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 956be196929073e58a92f45d7f2d6fb682d8d284f76616686e12cbf4e5319c56. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 956be196929073e58a92f45d7f2d6fb682d8d284f76616686e12cbf4e5319c56
SHA3-384 hash: fd330a3c153e3902b574fd5c3b63b90edd4f26c29561c1379ae5e79472c1c0665d0ae534b5c143a397e151e2142276e4
SHA1 hash: 82314eef73a346e574065435d1a0c103d0e01c4f
MD5 hash: 14ce9da0dffe44f88a5e1ca82b5b25b3
humanhash: butter-edward-twenty-high
File name:Factura_Electronica Banco_Sabadell_pdf_BS350698.js
Download: download sample
Signature Formbook
File size:841'006 bytes
First seen:2026-08-02 12:22:08 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 768:o4KfrHwZFCZwZNFCRANFARv1ofcvNNfqZKf4KFAFjVrAwRHKKFHFHRLNRojfcHvC:yF1
TLSH T1AA0510A661C2BFBC7CAC1726EDCFF50CD019D9EE824E89483059F2CD0695A4BD44A9F1
Magika javascript
Reporter gjtrh4
Tags:FormBook js

Intelligence


File Origin
# of uploads :
1
# of downloads :
32
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm fingerprint masquerade powershell repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-07-31T14:06:00Z UTC
Last seen:
2026-08-03T23:37:00Z UTC
Hits:
~100
Gathering data
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook execution rat spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Command and Scripting Interpreter: PowerShell
Suspicious use of SetThreadContext
Badlisted process makes network request
Family: Formbook
Formbook payload
Process spawned unexpected child process
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments