MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b190fbd2a225dfd5734a559de0f6256490067e1b3686dc74e55f6b84ef7609ed. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: b190fbd2a225dfd5734a559de0f6256490067e1b3686dc74e55f6b84ef7609ed
SHA3-384 hash: b746481f08ce2d50d95bf6b5654e6e6f5070e407d2727acb681a437965517de589a0e37071014c7fefbcb57f55f5dd4a
SHA1 hash: 49173b8da95706b2c387339bc8868fd2eff052d2
MD5 hash: 690e3318a83fdfa7f0145cb5f0241182
humanhash: maryland-oranges-venus-cola
File name:NEW_ORDER_2026_N0_DF987.JS
Download: download sample
Signature Formbook
File size:3'452'137 bytes
First seen:2026-08-04 12:01:38 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 98304:6XHnL/kAR4itBNSqMgLpjSqfQhm2+DxVxvZnBoSuz4fR4+nrvHParmZaJgef9Ti7:6XHnL/kAxBNH8qfQI2UVxvZnBoSS4fuW
TLSH T157F5F8858B148C36B12DEB3CC07AAE609E29628710C5EF2D31BD624D37D1D6763BD8D6
Magika javascript
Reporter James_inthe_box
Tags:exe FormBook js

Intelligence


File Origin
# of uploads :
1
# of downloads :
181
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
evasive masquerade obfuscated repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-08-04T06:08:00Z UTC
Last seen:
2026-08-06T09:50:00Z UTC
Hits:
~1000
Gathering data
Threat name:
Script-JS.Trojan.Multiverze
Status:
Malicious
First seen:
2026-08-04 11:22:37 UTC
File Type:
Text
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook discovery execution persistence rat spyware stealer trojan
Behaviour
Modifies registry class
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Executes a command shell one-liner
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Checks computer location settings
Executes dropped EXE
Family: Formbook
Formbook payload
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments