Formbook - Detection Rate

VirusTotal detection statistics across 97 analyzed samples.

Last updated: 2026-04-18

Detection rates show how many antivirus engines on VirusTotal identify Formbook samples as malicious. A high detection rate (30+ engines) means most AV vendors have signatures for the variant. Low or zero detection indicates recently packed or obfuscated samples that may bypass signature-based endpoint protection.

Why Detection Rate Matters

For SOC analysts and threat hunters, detection rate is a key indicator of variant freshness and evasion capability. When Formbook operators release a new build with updated packing or obfuscation, detection rates drop temporarily until AV vendors update their signatures. This window of low detection is when organizations are most vulnerable. Monitoring this page helps you understand how well your current defenses cover Formbook variants.

Recommended Actions

If you see undetected or low-detection samples, consider submitting them to your sandbox for behavioral analysis. Update your YARA rules to catch Formbook patterns that signature-based detection misses. For the latest sample hashes to cross-reference, visit the Formbook samples page. For network-level indicators, check the IOC page.

24/63
Avg Detection
97
Samples Analyzed
23
High Detection
0
Undetected

Detection Distribution

High (30+) 23 (24%)
Medium (15-29) 49 (51%)
Low (1-14) 25 (26%)
Undetected (0) 0 (0%)

Per-Sample Detection

SHA256 Detection Threat Name
78ddb86c7e16686c... 55/72 trojan.formbook/noon
2119f966c3d9382f... 53/71 trojan.msil/taskun
20b24b43f6ff60c5... 53/69 trojan.msil/taskun
cda6a5e6cfad4f58... 52/71 trojan.msil/bplogger
7cbdc3ffa1f6afc4... 52/70 trojan.garf/strab
06b4ddac05fc7398... 51/70 trojan.msil/filerepmalware
903ec037859ba0e1... 51/70 trojan.msil/fuery
67ff11dca6102d11... 51/69 trojan.msil/taskun
cb48a1b95924a62d... 50/71 trojan.msil/powershell
0035d9424bdee5b5... 50/72 trojan.msil/jalapeno
3680ce1ea0b26bed... 49/72 trojan.msil/formbook
f37e88ccac15a8cb... 48/72 trojan.msil/phantomstealer
82024b293b8ce6ac... 48/70 trojan.msil/powershell
68f76d6afc51ec80... 48/71 trojan.msil/noon
6e86685cb2897146... 45/71 trojan.msil/jalapeno
949eb105fbe7d0c4... 40/70 trojan.babar/formbook
8d813d5d24a74b6c... 40/68 trojan.msil/formbook
fde78edfa6163f53... 40/69 trojan.msil/formbook
bab2072b9bca8b95... 40/72 trojan.autoit/formbook
af3f5610187dd9fa... 39/70 trojan.msil/remcos
76cc2e6844b7360c... 36/71 trojan.msil/cryp
a8e8d4768f4c1a93... 34/71 trojan.msil/powershell
41afa43a3aea61c4... 32/72 trojan.msil/formbook
ec5a087e48fc68d2... 28/72 trojan.
3dc175bf861340b9... 27/70 trojan.msil/snakekeylogger
5bcbb96bb2579083... 26/63 trojan.genericfca/adyg
4af155941c33440f... 25/62 trojan.guloader
5e0a211f65b87058... 25/61 trojan.acsogenixx
ddd653854d3fefd8... 24/61 trojan.obfuse
58d4089e9f0cdca9... 24/61 trojan.guloader
2e3ae28c9dafea29... 24/61 trojan.acsogenixx
18f9f0b849d120f1... 23/61 trojan.cryxos
cc91735a3d21f09f... 23/62 trojan.powershell
e031abc625bdceab... 23/62 trojan.acsogenixx
69fe3d4b77a8c34c... 23/63 trojan.sagent
5289ce7c72bb012c... 23/61 trojan.cryxos
e5de1daebc620b7a... 22/61 trojan.guloader/netloader
04ed8e5814b643d4... 22/71 trojan.msil/filerepmalware
e17e39d20c194119... 22/61 trojan.
c7f7dd3b0a3b0f39... 22/61 trojan.cryxos
ecd983b0de122bb6... 22/64 trojan.calisto
e1a3a8937909e56d... 22/59 trojan.acsogenixx
9d34ab59070b5c64... 21/61 trojan.genericfca/adyg
8809ba6b44384ec4... 21/61 trojan.acsogenixx
6ba2db461aeeb228... 21/60 trojan.acsogenixx
9029bab7100d209f... 20/72 trojan.msil/formbook
9297af5f66486d11... 20/60 trojan.
5e9416a27d346185... 20/62 trojan.snakekeylogger
d285d4d5975a8e8a... 19/60 trojan.
4a33d0f6978c92df... 19/60 trojan.genericfca