MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 eda99519f7e5ef015a4450927bc96f26f837f07e54eb692eaa4ad12ed2a837a1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 11


Intelligence 11 IOCs YARA File information Comments

SHA256 hash: eda99519f7e5ef015a4450927bc96f26f837f07e54eb692eaa4ad12ed2a837a1
SHA3-384 hash: f99970b12f1321f59a5c41ba927ebde044c4a98f2910ad9665042e30d613a52abaa7c2535825226142745746d34703c2
SHA1 hash: d996f063f45b201c337b2c3a2b4c66773bb080f3
MD5 hash: 22b0a687a3130cb683e619d80320412f
humanhash: don-coffee-river-whiskey
File name:Pago (1).js
Download: download sample
Signature Formbook
File size:2'085'213 bytes
First seen:2026-07-20 16:21:10 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 192:ncmHEviuR/HMjxhUsMaW8+sM3+ajEqcDqmyLlq7DP0MzluFF3d:kvE/BaViW3d
TLSH T13AA5029973A71112D29F22420BA80C2DD9417C2F3EFB2EDCBDAE41D934117689E9DC75
Magika javascript
Reporter proxylife
Tags:FormBook js

Intelligence


File Origin
# of uploads :
1
# of downloads :
196
Origin country :
BR BR
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
90.2%
Tags:
cryxos virus shell spawn
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm fingerprint powershell repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-07-20T12:45:00Z UTC
Last seen:
2026-07-22T10:33:00Z UTC
Hits:
~100
Gathering data
Threat name:
Script-JS.Trojan.Cryxos
Status:
Malicious
First seen:
2026-07-21 01:37:14 UTC
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook execution rat spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Command and Scripting Interpreter: PowerShell
Suspicious use of SetThreadContext
Badlisted process makes network request
Family: Formbook
Formbook payload
Process spawned unexpected child process
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments