MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bbaab660f1d2468b7198fd5e7cd53aed7ebc8a99d5bbdbd7fc5223758e114117. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 13


Intelligence 13 IOCs YARA 4 File information Comments

SHA256 hash: bbaab660f1d2468b7198fd5e7cd53aed7ebc8a99d5bbdbd7fc5223758e114117
SHA3-384 hash: 6d7c6622eca6058c3293a5b7958eb1dee3fe37a38112fdf54211d768b29d86eb316b01a01a2ebe324b800d70ecf545f7
SHA1 hash: dacf04059818a5454856e12c29611f64c143607b
MD5 hash: 1f347e61681032429ed53da8436c04ab
humanhash: cold-don-princess-delaware
File name:Supply chain inquiry attached requirements quantity.hta
Download: download sample
Signature Formbook
File size:1'279'853 bytes
First seen:2026-07-08 12:08:01 UTC
Last seen:Never
File type:HTML Application (hta) hta
MIME type:text/html
ssdeep 24576:5ONTDmztg9GUeIqObrp42zvhvOCgB4jMbTA6rhrlbi4qkE6z:5OBQq90OGHB9V9bbEU
Threatray 3'625 similar samples on MalwareBazaar
TLSH T16F452360BF786D5A427CD374706B9E6A23A0471E844097F2F3AE74C21356F8ABE1F419
Magika txt
Reporter James_inthe_box
Tags:exe FormBook hta

Intelligence


File Origin
# of uploads :
1
# of downloads :
197
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
99.9%
Tags:
autoit emotet
Result
Verdict:
Malicious
File Type:
HTA File - Malicious
Behaviour
BlacklistAPI detected
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
obfuscated
Verdict:
Malicious
File Type:
hta
First seen:
2026-07-07T17:49:00Z UTC
Last seen:
2026-07-10T10:40:00Z UTC
Hits:
~1000
Detections:
Backdoor.Win32.Androm.sb Trojan.JS.SAgent.sb HEUR:Trojan.Script.Generic Trojan-Dropper.Win32.Injector.sb PDM:Trojan.Win32.Generic Trojan-Dropper.JS.SDrop.sb HEUR:Worm.Script.Generic HEUR:Trojan.PowerShell.Kryptik.gen Trojan.Win32.Shellcode.sb Trojan.Win32.Agent.sb
Gathering data
Verdict:
Malicious
Threat:
Trojan-Dropper.Win32.SDrop
Threat name:
Win32.Infostealer.Zeus
Status:
Malicious
First seen:
2026-07-07 22:40:03 UTC
File Type:
Text (HTML)
Extracted files:
1
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:donutloader family:formbook adware collection discovery execution loader persistence rat spyware stealer trojan
Behaviour
Modifies Internet Explorer settings
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
Command and Scripting Interpreter: PowerShell
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Adds Run key to start application
Checks computer location settings
Executes dropped EXE
Detects DonutLoader
Family: DonutLoader
Family: Formbook
Formbook payload
Malware family:
DonutLoader
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BlackGuard_Rule
Author:Jiho Kim
Description:Yara rule for BlackGuarad Stealer v1.0 - v3.0
Reference:https://www.virustotal.com/gui/file/67843d45ba538eca29c63c3259d697f7e2ba84a3da941295b9207cdb01c85b71/detection
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:html_auto_download_b64
Author:Tdawg
Description:html auto download
Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments