MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ba32aebc04dc365af12126586dabecfd34c70b3f60103410b6f0086761e3f42e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: ba32aebc04dc365af12126586dabecfd34c70b3f60103410b6f0086761e3f42e
SHA3-384 hash: d23d5e5171c4b526c67a2c437e992fd3eda69614e5b56b326b367f6a99245e27b3aba2f9a2d0bfb4b063be708e99e6de
SHA1 hash: 46013a3d089c3c683692e36cadff8093b2078af0
MD5 hash: 4623d6173759575088a063ffa5e309a8
humanhash: cup-lima-moon-kilo
File name:ORDER_LIST.js
Download: download sample
Signature Formbook
File size:1'028'416 bytes
First seen:2026-08-06 14:35:01 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 6144:XF3XR9WYdXpKIGu+oQ2qwIh05WqIT0yZ3iEVe8mnBa:Lz2Xbhm8
TLSH T1CD25EACF6372091C648A7A0FC8386E9E7A9BCF830510FDB9BDA45947C50C74253A5B6B
Magika javascript
Reporter abuse_ch
Tags:FormBook js

Intelligence


File Origin
# of uploads :
1
# of downloads :
151
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
forfiles lolbin masquerade repaired
Verdict:
Malicious
File Type:
text
First seen:
2026-08-06T07:58:00Z UTC
Last seen:
2026-08-08T11:33:00Z UTC
Hits:
~1000
Result
Threat name:
FormBook
Detection:
malicious
Classification:
troj.spyw.expl.evad
Score:
100 / 100
Signature
Antivirus detection for URL or domain
Binary is likely a compiled AutoIt script file
Creates an undocumented autostart registry key
Found direct / indirect Syscall (likely to bypass EDR)
Injects a PE file into a foreign processes
Injects code into the Windows Explorer (explorer.exe)
Joe Sandbox ML detected suspicious sample
JScript performs obfuscated calls to suspicious functions
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for submitted file
Queues an APC in another process (thread injection)
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Switches to a custom stack to bypass stack traces
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Unusual module load detection (module proxying)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
WScript reads language and country specific registry keys (likely country aware script)
Yara detected FormBook
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1953483 Sample: ORDER_LIST.js Startdate: 06/08/2026 Architecture: WINDOWS Score: 100 43 www.team57.site 2->43 45 www.taoc-app.net 2->45 47 14 other IPs or domains 2->47 65 Malicious sample detected (through community Yara rule) 2->65 67 Antivirus detection for URL or domain 2->67 69 Multi AV Scanner detection for submitted file 2->69 71 3 other signatures 2->71 13 wscript.exe 1 1 2->13         started        signatures3 process4 signatures5 91 JScript performs obfuscated calls to suspicious functions 13->91 93 Windows Scripting host queries suspicious COM object (likely to drop second stage) 13->93 95 Suspicious execution chain found 13->95 97 WScript reads language and country specific registry keys (likely country aware script) 13->97 16 forfiles.exe 1 13->16         started        process6 process7 18 cmd.exe 1 16->18         started        20 conhost.exe 16->20         started        process8 22 powershell.exe 15 10 18->22         started        26 cmd.exe 1 18->26         started        dnsIp9 55 durakutihs.com 161.248.188.172, 443, 49770 UHB-AS-APUmmahHostBD Bangladesh 22->55 75 Creates an undocumented autostart registry key 22->75 77 Injects code into the Windows Explorer (explorer.exe) 22->77 79 Writes to foreign memory regions 22->79 81 Injects a PE file into a foreign processes 22->81 28 explorer.exe 22->28         started        signatures10 process11 signatures12 83 Modifies the context of a thread in another process (thread injection) 28->83 85 Maps a DLL or memory area into another process 28->85 87 Queues an APC in another process (thread injection) 28->87 89 2 other signatures 28->89 31 KV9FOp1o.exe 28->31 injected process13 signatures14 99 Binary is likely a compiled AutoIt script file 31->99 101 Maps a DLL or memory area into another process 31->101 103 Found direct / indirect Syscall (likely to bypass EDR) 31->103 34 odbcconf.exe 13 31->34         started        process15 signatures16 57 Tries to steal Mail credentials (via file / registry access) 34->57 59 Tries to harvest and steal browser information (history, passwords, etc) 34->59 61 Modifies the context of a thread in another process (thread injection) 34->61 63 3 other signatures 34->63 37 9wpnpHyzFz.exe 34->37 injected 41 firefox.exe 34->41         started        process17 dnsIp18 49 www.taoc-app.net 191.214.240.240, 49774, 49775, 49776 SH2206-APUNITA179FSILVERCORPINTLTOWER707-713NATHANRDHK Hong Kong SAR China 37->49 51 team57.site 185.157.46.227, 49772, 80 SAGANETWORKTR Turkey 37->51 53 6 other IPs or domains 37->53 73 Binary is likely a compiled AutoIt script file 37->73 signatures19
Gathering data
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-08-06 13:00:20 UTC
File Type:
Text (JavaScript)
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
defense_evasion execution persistence
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Executes a command shell one-liner
Suspicious use of SetThreadContext
Checks computer location settings
Indirect Command Execution
Registers new Windows logon scripts automatically executed at logon.
Badlisted process makes network request
Downloads MZ/PE file
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments