This hypothesis targets Formbook, a data-stealing malware that exfiltrates sensitive information like credentials and banking details while establishing persistence through stolen access. Proactively hunting for these IOCs in Azure Sentinel is critical to identify compromised endpoints early, preventing the malware from leveraging persistence mechanisms to maintain a foothold and steal additional sensitive data.
Malware Family: Formbook Total IOCs: 15 IOC Types: md5_hash, sha256_hash, sha1_hash
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| sha256_hash | 1b77d3f9e71c57cd5a3bf17f9fa4fbb051d1571d63c3223e3201f82ef7be9b14 | payload | 2026-09-13 | 95% |
| sha1_hash | d2476b5c451720dd76902b9e575f3b685d89cfc3 | payload | 2026-09-13 | 95% |
| md5_hash | 5ad1b2748b02c7d9e65b4f990bdacb29 | payload | 2026-09-13 | 95% |
| md5_hash | 9b8e765efa5ec8ec2929102723b3f754 | payload | 2026-09-13 | 95% |
| md5_hash | 95f15b2bb39901645985addaf2b596b5 | payload | 2026-09-13 | 95% |
| sha256_hash | 17ad3b76cf99eb60d1a47c70ffc1076c68a07ed7292253389b4ebc760bbce430 | payload | 2026-09-13 | 95% |
| sha1_hash | a0beb5d130c3f9e1b0ab6eb3c96d3af9afbd6eda | payload | 2026-09-13 | 95% |
| sha256_hash | 03115f6c0b387cc021c61632006b57859e65b25abc48923369d5caba71481544 | payload | 2026-09-13 | 95% |
| sha1_hash | 558f4fc9f5f565f15242ba80d12d28067e3655c2 | payload | 2026-09-13 | 95% |
| sha1_hash | aefb2aeb4d9cf90d66785cd14d3f597c47969e12 | payload | 2026-09-13 | 95% |
| md5_hash | 2f142ac7959a2abdd836de4d78cac59c | payload | 2026-09-13 | 95% |
| sha256_hash | af44a80e5b05d59894b0970c46eea3b489f7e936e1e834531f1652a4eeb66fe5 | payload | 2026-09-13 | 95% |
| sha1_hash | e4f11c4bb4353382fcac5daef0c597e4f1f22cfa | payload | 2026-09-13 | 95% |
| md5_hash | 6ff26b74fc9ec8a190966a9caa97ae39 | payload | 2026-09-13 | 95% |
| sha256_hash | ab456fcf30eea0dfadf5cde1ebe81dd692adbb0330660ab3d5eb9314bd292dd5 | payload | 2026-09-13 | 95% |
// Hunt for files matching known malicious hashes
// Source: ThreatFox - Formbook
let malicious_hashes = dynamic(["1b77d3f9e71c57cd5a3bf17f9fa4fbb051d1571d63c3223e3201f82ef7be9b14", "d2476b5c451720dd76902b9e575f3b685d89cfc3", "5ad1b2748b02c7d9e65b4f990bdacb29", "9b8e765efa5ec8ec2929102723b3f754", "95f15b2bb39901645985addaf2b596b5", "17ad3b76cf99eb60d1a47c70ffc1076c68a07ed7292253389b4ebc760bbce430", "a0beb5d130c3f9e1b0ab6eb3c96d3af9afbd6eda", "03115f6c0b387cc021c61632006b57859e65b25abc48923369d5caba71481544", "558f4fc9f5f565f15242ba80d12d28067e3655c2", "aefb2aeb4d9cf90d66785cd14d3f597c47969e12", "2f142ac7959a2abdd836de4d78cac59c", "af44a80e5b05d59894b0970c46eea3b489f7e936e1e834531f1652a4eeb66fe5", "e4f11c4bb4353382fcac5daef0c597e4f1f22cfa", "6ff26b74fc9ec8a190966a9caa97ae39", "ab456fcf30eea0dfadf5cde1ebe81dd692adbb0330660ab3d5eb9314bd292dd5"]);
DeviceFileEvents
| where SHA256 in (malicious_hashes) or SHA1 in (malicious_hashes) or MD5 in (malicious_hashes)
| project Timestamp, DeviceName, FileName, FolderPath, SHA256, InitiatingProcessFileName
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
DeviceFileEvents | Ensure this data connector is enabled |
Scenario: Automated Web Scraping or SEO Auditing Tools
node.exe with puppeteer or chromedriver.exe) or where the user agent string contains “HeadlessChrome” or “Selenium”. Additionally, exclude network connections to internal staging environments or known SEO tool IP ranges.Scenario: Enterprise Backup and Archiving Agents
%APPDATA% or %LOCALAPPDATA% for configuration or state files.VeeamBackupSvc.exe, CommvaultAgent.exe) or services registered under backup-related names. Also, exclude network destinations that are internal backup servers or known cloud storage endpoints (e.g., *.aws.com, *.azure.com backup buckets) if the rule triggers on outbound traffic to these specific internal ranges.