Formbook - Detection Rate

VirusTotal detection statistics across 297 analyzed samples.

Last updated: 2026-08-15

Detection rates show how many antivirus engines on VirusTotal identify Formbook samples as malicious. A high detection rate (30+ engines) means most AV vendors have signatures for the variant. Low or zero detection indicates recently packed or obfuscated samples that may bypass signature-based endpoint protection.

Why Detection Rate Matters

For SOC analysts and threat hunters, detection rate is a key indicator of variant freshness and evasion capability. When Formbook operators release a new build with updated packing or obfuscation, detection rates drop temporarily until AV vendors update their signatures. This window of low detection is when organizations are most vulnerable. Monitoring this page helps you understand how well your current defenses cover Formbook variants.

Recommended Actions

If you see undetected or low-detection samples, consider submitting them to your sandbox for behavioral analysis. Update your YARA rules to catch Formbook patterns that signature-based detection misses. For the latest sample hashes to cross-reference, visit the Formbook samples page. For network-level indicators, check the IOC page.

27/62
Avg Detection
297
Samples Analyzed
100
High Detection
0
Undetected

Detection Distribution

High (30+) 100 (34%)
Medium (15-29) 134 (45%)
Low (1-14) 63 (21%)
Undetected (0) 0 (0%)

Per-Sample Detection

SHA256 Detection Threat Name
78ddb86c7e16686c... 55/72 trojan.formbook/noon
f186833e139a32ea... 54/71 trojan.msil/taskun
2119f966c3d9382f... 53/71 trojan.msil/taskun
20b24b43f6ff60c5... 53/69 trojan.msil/taskun
851cfb84502c1e3d... 53/71 trojan.msil/darkcloud
c5c2c8515c39bb07... 53/70 trojan.msil/cryp
3e1b1fe0edaa2aa1... 53/71 trojan.msil/formbook
cda6a5e6cfad4f58... 52/71 trojan.msil/bplogger
7cbdc3ffa1f6afc4... 52/70 trojan.garf/strab
2788fb910102febe... 52/71 trojan.formbook/mikey
bfe08186ed24f6d2... 52/69 trojan.formbook/babar
aad25d1908ba6198... 52/70 trojan.autoit/noon
0becdb662b66302f... 52/71 trojan.msil/lazy
69642cd14966d9ab... 52/70 trojan.msil/formbook
6ebd94209f4a45ea... 52/69 trojan.msil/formbook
06b4ddac05fc7398... 51/70 trojan.msil/filerepmalware
903ec037859ba0e1... 51/70 trojan.msil/fuery
67ff11dca6102d11... 51/69 trojan.msil/taskun
560eebed936f112b... 51/70 trojan.msil/noon
83b22649ee530fda... 51/71 trojan.autoit/noon
585a0ca324498651... 51/69 trojan.msil/injuke
5b4f596d3cf54c94... 51/71 trojan.msil/snakelogger
fbbb5b74e9d1d24d... 51/68 trojan.msil/xworm
f10a3669a6a50dbf... 51/69 trojan.msil/formbook
cb48a1b95924a62d... 50/71 trojan.msil/powershell
0035d9424bdee5b5... 50/72 trojan.msil/jalapeno
422417f778a34bff... 50/64 trojan.formbook/noon
0cfbc10a408c5747... 50/71 trojan.msil/msilheracles
1797f76fed29dfe0... 50/69 trojan.msil/yogi
f0e29d11e1800cf4... 50/68 trojan.formbook/icnw
3680ce1ea0b26bed... 49/72 trojan.msil/formbook
2af9816b540cfa33... 49/65 trojan.msil/cryp
f97e2ce9f20d7211... 49/71 trojan.autoit/noon
fc944b5465a41ab4... 49/64 trojan.msil/formbook
bd1b6a05dbbb3958... 49/68 trojan.msil/loki
34b0d10ee1f8927d... 49/66 trojan.msil/noon
33522ec6cd83ae54... 49/70 trojan.msil/xworm
bac16a48407ea22b... 49/67 trojan.msil/basic
a73cd72f82f334e3... 49/68 trojan.msil/agenttesla
f37e88ccac15a8cb... 48/72 trojan.msil/phantomstealer
82024b293b8ce6ac... 48/70 trojan.msil/powershell
68f76d6afc51ec80... 48/71 trojan.msil/noon
274137298b71f344... 47/70 trojan.msil/formbook
a4ca575207a3457b... 47/72 trojan.msil/basic
05af48bc123af763... 47/66 trojan.msil/darkcloud
cae269e0773f6380... 47/67 trojan.msil/formbook
dcea95d8021d391a... 47/63 trojan.msil/injectornett
b28e7ee3053e8944... 46/64 trojan.msil/agenttesla
39603c646ed7cc71... 46/69 trojan.msil/basic
6e86685cb2897146... 45/71 trojan.msil/jalapeno