Formbook - Detection Rate
VirusTotal detection statistics across 97 analyzed samples.
Last updated: 2026-04-18
Detection rates show how many antivirus engines on VirusTotal identify Formbook samples as malicious. A high detection rate (30+ engines) means most AV vendors have signatures for the variant. Low or zero detection indicates recently packed or obfuscated samples that may bypass signature-based endpoint protection.
Why Detection Rate Matters
For SOC analysts and threat hunters, detection rate is a key indicator of variant freshness and evasion capability. When Formbook operators release a new build with updated packing or obfuscation, detection rates drop temporarily until AV vendors update their signatures. This window of low detection is when organizations are most vulnerable. Monitoring this page helps you understand how well your current defenses cover Formbook variants.
Recommended Actions
If you see undetected or low-detection samples, consider submitting them to your sandbox for behavioral analysis. Update your YARA rules to catch Formbook patterns that signature-based detection misses. For the latest sample hashes to cross-reference, visit the Formbook samples page. For network-level indicators, check the IOC page.
Detection Distribution
Per-Sample Detection
| SHA256 | Detection | Threat Name |
|---|---|---|
| 78ddb86c7e16686c... | 55/72 | trojan.formbook/noon |
| 2119f966c3d9382f... | 53/71 | trojan.msil/taskun |
| 20b24b43f6ff60c5... | 53/69 | trojan.msil/taskun |
| cda6a5e6cfad4f58... | 52/71 | trojan.msil/bplogger |
| 7cbdc3ffa1f6afc4... | 52/70 | trojan.garf/strab |
| 06b4ddac05fc7398... | 51/70 | trojan.msil/filerepmalware |
| 903ec037859ba0e1... | 51/70 | trojan.msil/fuery |
| 67ff11dca6102d11... | 51/69 | trojan.msil/taskun |
| cb48a1b95924a62d... | 50/71 | trojan.msil/powershell |
| 0035d9424bdee5b5... | 50/72 | trojan.msil/jalapeno |
| 3680ce1ea0b26bed... | 49/72 | trojan.msil/formbook |
| f37e88ccac15a8cb... | 48/72 | trojan.msil/phantomstealer |
| 82024b293b8ce6ac... | 48/70 | trojan.msil/powershell |
| 68f76d6afc51ec80... | 48/71 | trojan.msil/noon |
| 6e86685cb2897146... | 45/71 | trojan.msil/jalapeno |
| 949eb105fbe7d0c4... | 40/70 | trojan.babar/formbook |
| 8d813d5d24a74b6c... | 40/68 | trojan.msil/formbook |
| fde78edfa6163f53... | 40/69 | trojan.msil/formbook |
| bab2072b9bca8b95... | 40/72 | trojan.autoit/formbook |
| af3f5610187dd9fa... | 39/70 | trojan.msil/remcos |
| 76cc2e6844b7360c... | 36/71 | trojan.msil/cryp |
| a8e8d4768f4c1a93... | 34/71 | trojan.msil/powershell |
| 41afa43a3aea61c4... | 32/72 | trojan.msil/formbook |
| ec5a087e48fc68d2... | 28/72 | trojan. |
| 3dc175bf861340b9... | 27/70 | trojan.msil/snakekeylogger |
| 5bcbb96bb2579083... | 26/63 | trojan.genericfca/adyg |
| 4af155941c33440f... | 25/62 | trojan.guloader |
| 5e0a211f65b87058... | 25/61 | trojan.acsogenixx |
| ddd653854d3fefd8... | 24/61 | trojan.obfuse |
| 58d4089e9f0cdca9... | 24/61 | trojan.guloader |
| 2e3ae28c9dafea29... | 24/61 | trojan.acsogenixx |
| 18f9f0b849d120f1... | 23/61 | trojan.cryxos |
| cc91735a3d21f09f... | 23/62 | trojan.powershell |
| e031abc625bdceab... | 23/62 | trojan.acsogenixx |
| 69fe3d4b77a8c34c... | 23/63 | trojan.sagent |
| 5289ce7c72bb012c... | 23/61 | trojan.cryxos |
| e5de1daebc620b7a... | 22/61 | trojan.guloader/netloader |
| 04ed8e5814b643d4... | 22/71 | trojan.msil/filerepmalware |
| e17e39d20c194119... | 22/61 | trojan. |
| c7f7dd3b0a3b0f39... | 22/61 | trojan.cryxos |
| ecd983b0de122bb6... | 22/64 | trojan.calisto |
| e1a3a8937909e56d... | 22/59 | trojan.acsogenixx |
| 9d34ab59070b5c64... | 21/61 | trojan.genericfca/adyg |
| 8809ba6b44384ec4... | 21/61 | trojan.acsogenixx |
| 6ba2db461aeeb228... | 21/60 | trojan.acsogenixx |
| 9029bab7100d209f... | 20/72 | trojan.msil/formbook |
| 9297af5f66486d11... | 20/60 | trojan. |
| 5e9416a27d346185... | 20/62 | trojan.snakekeylogger |
| d285d4d5975a8e8a... | 19/60 | trojan. |
| 4a33d0f6978c92df... | 19/60 | trojan.genericfca |