MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 967e20b5efdb7a61c2d9c6d94ae766fec4d220efb329d9a4e0c44915bc124bc3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 967e20b5efdb7a61c2d9c6d94ae766fec4d220efb329d9a4e0c44915bc124bc3
SHA3-384 hash: 1bc9a82a2b774d80959421560a9c99845b1e22f65f6e435bb2f6c3588b0f441283077b21d85ebfbace6b863c524eeb0b
SHA1 hash: ac8ef6c1396b8703988c7aa476b4d1df11dd108f
MD5 hash: 80c663110a14fe39e5d06673c2aaa09c
humanhash: gee-delaware-emma-hot
File name:OUR NEW ORDER_2026.JS
Download: download sample
Signature Formbook
File size:3'452'137 bytes
First seen:2026-07-31 12:12:44 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 98304:J8izfbhlGFf8QkMjHb+P54P+pZlZE4x5fCDjv/TdDV60OzmpwtP:6izGFf8gf+B4WRZE4xcD1ZtOzJP
TLSH T188F5E880933C9C31B63EA71CC036DE54C5A9226765C5EF2D36BC420C77A296B339D9E6
Magika javascript
Reporter James_inthe_box
Tags:exe FormBook js

Intelligence


File Origin
# of uploads :
1
# of downloads :
139
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
dropper evasive masquerade obfuscated repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-07-31T06:22:00Z UTC
Last seen:
2026-07-31T08:54:00Z UTC
Hits:
~100
Gathering data
Threat name:
Script-JS.Dropper.Heuristic
Status:
Malicious
First seen:
2026-07-31 12:13:09 UTC
File Type:
Text
AV detection:
5 of 36 (13.89%)
Threat level:
  2/5
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook discovery execution persistence rat spyware stealer trojan
Behaviour
Modifies registry class
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Executes a command shell one-liner
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Checks computer location settings
Executes dropped EXE
Family: Formbook
Formbook payload
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments