🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fac3bf7ac5e4fd0a0840486d42180a84350c8fa3799e1f7568d0326e9827cac9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 11


Intelligence 11 IOCs YARA File information Comments

SHA256 hash: fac3bf7ac5e4fd0a0840486d42180a84350c8fa3799e1f7568d0326e9827cac9
SHA3-384 hash: 25ec110a3ba9637be6785591bb364492d226e7e21f5d82527aa77ce193188f961507598b33213cea6eb6cf0b9593aa91
SHA1 hash: 7390f5d438d867c98ae908d2ddeb18f70817fed6
MD5 hash: 03564de0414ad6a7dbfc295cb877907b
humanhash: colorado-river-neptune-hamper
File name:Proforma Invoice 5628-1.vbs
Download: download sample
Signature Formbook
File size:2'146'883 bytes
First seen:2026-06-18 12:12:10 UTC
Last seen:2026-07-03 17:58:55 UTC
File type:Visual Basic Script (vbs) vbs
MIME type:text/csv
ssdeep 384:bbFnyZ5nQCxTIrtnzivGvbV+4PGRH120wteU/Qrn74Ow9IehKlToUQ1w/HTF74k0:u2
Threatray 154 similar samples on MalwareBazaar
TLSH T178A58FC2C5060A13BBD3049DB590FF914DF3993AB9432DE7ABA7868141470E84FF9B66
Magika autoit
Reporter James_inthe_box
Tags:exe FormBook vbs

Intelligence


File Origin
# of uploads :
5
# of downloads :
219
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
90.9%
Tags:
obfuscate xtreme shell
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm base64 evasive fingerprint masquerade obfuscated overlay powershell
Verdict:
Malicious
File Type:
text.utf8
First seen:
2026-06-18T07:21:00Z UTC
Last seen:
2026-06-20T09:13:00Z UTC
Hits:
~1000
Detections:
Trojan.JS.SAgent.sb HEUR:Trojan.Script.Generic
Gathering data
Threat name:
Script-WScript.Trojan.Generic
Status:
Suspicious
First seen:
2026-06-18 10:47:37 UTC
File Type:
Binary
AV detection:
6 of 23 (26.09%)
Threat level:
  5/5
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook execution rat spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Suspicious use of SetThreadContext
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Family: Formbook
Formbook payload
Process spawned unexpected child process
Malware Config
Dropper Extraction:
https://brenmayasociados.com/sass/optimized_MSIjune.png
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments