🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f2474cc8073b759dc03d185b6ea00563b04b78dfa77f0997a14e2d0f99574f22. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: f2474cc8073b759dc03d185b6ea00563b04b78dfa77f0997a14e2d0f99574f22
SHA3-384 hash: 07fa184bd7415ee017f66b8fae95e30fd0b5cae17ef18857305d7547d136cc796f21ff6043aae644ce6846847ec9fadc
SHA1 hash: d71e5ef8779831a18e9e821375e229a9a7db8414
MD5 hash: 2549d1985010a83d58c0b6b7ee55fc24
humanhash: uncle-black-bravo-jupiter
File name:doc0082620260000826.JS
Download: download sample
Signature Formbook
File size:4'194'481 bytes
First seen:2026-08-26 13:25:37 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 98304:wu/5chS9+dyhRtNRkUhKfYlSuqXQYRnnwN/LYznRd/eCL69FsDm1wmwFpQgeZ6r:B/5cW++dRhKfWZYZneTYz/NmgQgeZa
TLSH T1A81663CC83455472B67C9B5D49B749209D0913A311C5EF3D322CEA2F3B68A0BDB6C6E6
Magika javascript
Reporter abuse_ch
Tags:FormBook js

Intelligence


File Origin
# of uploads :
1
# of downloads :
167
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
js
First seen:
2026-08-26T05:25:00Z UTC
Last seen:
2026-08-28T11:28:00Z UTC
Hits:
~100
Result
Threat name:
FormBook
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
Found API chain indicative of debugger detection
Found direct / indirect Syscall (likely to bypass EDR)
JavaScript source code contains functionality to generate code involving a shell, file or stream
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for submitted file
Queues an APC in another process (thread injection)
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Sigma detected: Suspicious Command Patterns In Scheduled Task Creation
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Switches to a custom stack to bypass stack traces
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Unusual module load detection (module proxying)
Uses schtasks.exe or at.exe to add and modify task schedules
Uses whoami command line tool to query computer and username
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Yara detected FormBook
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1964129 Sample: doc0082620260000826.JS.js Startdate: 26/08/2026 Architecture: WINDOWS Score: 100 66 www.tyskweb.com 2->66 68 www.manackertransport.nl 2->68 70 6 other IPs or domains 2->70 86 Suricata IDS alerts for network traffic 2->86 88 Multi AV Scanner detection for submitted file 2->88 90 Yara detected FormBook 2->90 92 6 other signatures 2->92 10 wscript.exe 2 2->10         started        13 cmd.exe 1 4 2->13         started        signatures3 process4 signatures5 118 Windows Scripting host queries suspicious COM object (likely to drop second stage) 10->118 15 YTAEZPVHMARNCDLM.PIF 3 10->15         started        19 cmd.exe 1 13->19         started        21 conhost.exe 13->21         started        process6 file7 64 C:\Users\user\...\MLDCNRAMHVPZEATY.url, MS 15->64 dropped 78 Found API chain indicative of debugger detection 15->78 80 Modifies the context of a thread in another process (thread injection) 15->80 82 Maps a DLL or memory area into another process 15->82 84 3 other signatures 15->84 23 EQTCjKrkxSkD.exe 15->23 injected 26 cmd.exe 1 15->26         started        28 cmd.exe 1 15->28         started        34 2 other processes 15->34 30 YTAEZPVHMARNCDLM.PIF 1 19->30         started        32 conhost.exe 19->32         started        signatures8 process9 signatures10 108 Maps a DLL or memory area into another process 23->108 110 Found direct / indirect Syscall (likely to bypass EDR) 23->110 36 print.exe 13 23->36         started        112 Uses schtasks.exe or at.exe to add and modify task schedules 26->112 114 Uses whoami command line tool to query computer and username 26->114 39 whoami.exe 1 26->39         started        41 schtasks.exe 1 28->41         started        116 Modifies the context of a thread in another process (thread injection) 30->116 43 ztXO2PDvzHr.exe 30->43 injected 45 cmd.exe 1 30->45         started        47 cmd.exe 1 30->47         started        49 conhost.exe 30->49         started        51 schtasks.exe 1 34->51         started        process11 signatures12 94 Tries to steal Mail credentials (via file / registry access) 36->94 96 Tries to harvest and steal browser information (history, passwords, etc) 36->96 98 Modifies the context of a thread in another process (thread injection) 36->98 106 2 other signatures 36->106 53 mli3O8eH9m.exe 36->53 injected 56 firefox.exe 36->56         started        100 Maps a DLL or memory area into another process 43->100 102 Found direct / indirect Syscall (likely to bypass EDR) 43->102 58 print.exe 43->58         started        104 Uses whoami command line tool to query computer and username 45->104 60 whoami.exe 1 45->60         started        62 schtasks.exe 1 47->62         started        process13 dnsIp14 72 uk999game.com.pk 185.244.36.210, 49724, 49725, 49726 SPECTRAIPSpectraIPBVNL Netherlands 53->72 74 www.tyskweb.com 46.30.215.222, 49715, 80 ONECOMDK Denmark 53->74 76 2 other IPs or domains 53->76
Gathering data
Threat name:
Script-JS.Trojan.Heuristic
Status:
Malicious
First seen:
2026-08-26 12:37:23 UTC
File Type:
Text (JavaScript)
AV detection:
11 of 38 (28.95%)
Threat level:
  2/5
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook discovery execution persistence rat spyware stealer trojan
Behaviour
Modifies registry class
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Executes a command shell one-liner
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Checks computer location settings
Executes dropped EXE
Family: Formbook
Formbook payload
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments