Formbook - Detection Rate

VirusTotal detection statistics across 217 analyzed samples.

Last updated: 2026-06-16

Detection rates show how many antivirus engines on VirusTotal identify Formbook samples as malicious. A high detection rate (30+ engines) means most AV vendors have signatures for the variant. Low or zero detection indicates recently packed or obfuscated samples that may bypass signature-based endpoint protection.

Why Detection Rate Matters

For SOC analysts and threat hunters, detection rate is a key indicator of variant freshness and evasion capability. When Formbook operators release a new build with updated packing or obfuscation, detection rates drop temporarily until AV vendors update their signatures. This window of low detection is when organizations are most vulnerable. Monitoring this page helps you understand how well your current defenses cover Formbook variants.

Recommended Actions

If you see undetected or low-detection samples, consider submitting them to your sandbox for behavioral analysis. Update your YARA rules to catch Formbook patterns that signature-based detection misses. For the latest sample hashes to cross-reference, visit the Formbook samples page. For network-level indicators, check the IOC page.

26/63
Avg Detection
217
Samples Analyzed
69
High Detection
0
Undetected

Detection Distribution

High (30+) 69 (32%)
Medium (15-29) 93 (43%)
Low (1-14) 55 (25%)
Undetected (0) 0 (0%)

Per-Sample Detection

SHA256 Detection Threat Name
78ddb86c7e16686c... 55/72 trojan.formbook/noon
f186833e139a32ea... 54/71 trojan.msil/taskun
2119f966c3d9382f... 53/71 trojan.msil/taskun
20b24b43f6ff60c5... 53/69 trojan.msil/taskun
851cfb84502c1e3d... 53/71 trojan.msil/darkcloud
cda6a5e6cfad4f58... 52/71 trojan.msil/bplogger
7cbdc3ffa1f6afc4... 52/70 trojan.garf/strab
2788fb910102febe... 52/71 trojan.formbook/mikey
bfe08186ed24f6d2... 52/69 trojan.formbook/babar
aad25d1908ba6198... 52/70 trojan.autoit/noon
0becdb662b66302f... 52/71 trojan.msil/lazy
06b4ddac05fc7398... 51/70 trojan.msil/filerepmalware
903ec037859ba0e1... 51/70 trojan.msil/fuery
67ff11dca6102d11... 51/69 trojan.msil/taskun
560eebed936f112b... 51/70 trojan.msil/noon
83b22649ee530fda... 51/71 trojan.autoit/noon
585a0ca324498651... 51/69 trojan.msil/injuke
5b4f596d3cf54c94... 51/71 trojan.msil/snakelogger
cb48a1b95924a62d... 50/71 trojan.msil/powershell
0035d9424bdee5b5... 50/72 trojan.msil/jalapeno
422417f778a34bff... 50/64 trojan.formbook/noon
0cfbc10a408c5747... 50/71 trojan.msil/msilheracles
3680ce1ea0b26bed... 49/72 trojan.msil/formbook
2af9816b540cfa33... 49/65 trojan.msil/cryp
f97e2ce9f20d7211... 49/71 trojan.autoit/noon
fc944b5465a41ab4... 49/64 trojan.msil/formbook
bd1b6a05dbbb3958... 49/68 trojan.msil/loki
34b0d10ee1f8927d... 49/66 trojan.msil/noon
f37e88ccac15a8cb... 48/72 trojan.msil/phantomstealer
82024b293b8ce6ac... 48/70 trojan.msil/powershell
68f76d6afc51ec80... 48/71 trojan.msil/noon
274137298b71f344... 47/70 trojan.msil/formbook
a4ca575207a3457b... 47/72 trojan.msil/basic
05af48bc123af763... 47/66 trojan.msil/darkcloud
cae269e0773f6380... 47/67 trojan.msil/formbook
dcea95d8021d391a... 47/63 trojan.msil/injectornett
b28e7ee3053e8944... 46/64 trojan.msil/agenttesla
39603c646ed7cc71... 46/69 trojan.msil/basic
6e86685cb2897146... 45/71 trojan.msil/jalapeno
eb663f16fb1e5112... 45/69 trojan.aotera/tl0101e126zw
6c6902cea5aabd38... 45/69 trojan.msil/xworm
b9277014b5a639d3... 44/68 trojan.giant/lazy
cdc6e7817adde2c0... 42/63 trojan.msil/dnoper
70b469b8018947ea... 41/71 trojan.loki/msil
949eb105fbe7d0c4... 40/70 trojan.babar/formbook
8d813d5d24a74b6c... 40/68 trojan.msil/formbook
fde78edfa6163f53... 40/69 trojan.msil/formbook
bab2072b9bca8b95... 40/72 trojan.autoit/formbook
042f6d8fff507d22... 40/69 trojan.msil/injectornett
af3f5610187dd9fa... 39/70 trojan.msil/remcos