This hunt hypothesis targets adversaries leveraging known Formbook indicators of compromise to identify potential data exfiltration or credential harvesting activities within the network. Proactively searching for these specific IOCs in Azure Sentinel is critical because early detection of this threat actor allows the SOC team to contain lateral movement and mitigate risks before they escalate into a broader breach.
Malware Family: Formbook Total IOCs: 12 IOC Types: sha1_hash, md5_hash, sha256_hash
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| sha1_hash | 0c8b6a85b4bcf12fbe3e274a0436000a76d6ca78 | payload | 2026-07-02 | 95% |
| md5_hash | 5ff9c0b47ad7adbba95955ad266ecbc5 | payload | 2026-07-02 | 95% |
| sha256_hash | 0b3236531c608af3cdb33b3f09ab0d5bbd61f67cc341faa92c1c2cb2258bd409 | payload | 2026-07-02 | 95% |
| md5_hash | 370ed8646f719d4e9c06a078f6515fe3 | payload | 2026-07-02 | 95% |
| sha256_hash | 0220916d9e01ad27a30af87ce47a792d11b0e2f64a189390fe72b330ace56ad6 | payload | 2026-07-02 | 95% |
| sha1_hash | 4694cec3f12a68e0a09731bb05ecfd17e5c52753 | payload | 2026-07-02 | 95% |
| md5_hash | 075eb78eeae6f23401e6f41a024dc50a | payload | 2026-07-02 | 95% |
| sha1_hash | 65495e2dc520a54bd2970ef7fb4323e40860ad73 | payload | 2026-07-02 | 95% |
| md5_hash | f455803cf736015a73d4f03f165963df | payload | 2026-07-02 | 95% |
| sha256_hash | 7212a9cb63a6703ad235ebb4db18d5c7eab2d5a3e13dfced075daf4c440f0900 | payload | 2026-07-02 | 95% |
| sha1_hash | 6fe4d55cb024c87c9196d7f9f138cb5d61e2a8cb | payload | 2026-07-02 | 95% |
| sha256_hash | c60cbde6033fe5a3bd5f127248959e1742e48aeae539ece6e137dd5179df34e7 | payload | 2026-07-02 | 95% |
// Hunt for files matching known malicious hashes
// Source: ThreatFox - Formbook
let malicious_hashes = dynamic(["0c8b6a85b4bcf12fbe3e274a0436000a76d6ca78", "5ff9c0b47ad7adbba95955ad266ecbc5", "0b3236531c608af3cdb33b3f09ab0d5bbd61f67cc341faa92c1c2cb2258bd409", "370ed8646f719d4e9c06a078f6515fe3", "0220916d9e01ad27a30af87ce47a792d11b0e2f64a189390fe72b330ace56ad6", "4694cec3f12a68e0a09731bb05ecfd17e5c52753", "075eb78eeae6f23401e6f41a024dc50a", "65495e2dc520a54bd2970ef7fb4323e40860ad73", "f455803cf736015a73d4f03f165963df", "7212a9cb63a6703ad235ebb4db18d5c7eab2d5a3e13dfced075daf4c440f0900", "6fe4d55cb024c87c9196d7f9f138cb5d61e2a8cb", "c60cbde6033fe5a3bd5f127248959e1742e48aeae539ece6e137dd5179df34e7"]);
DeviceFileEvents
| where SHA256 in (malicious_hashes) or SHA1 in (malicious_hashes) or MD5 in (malicious_hashes)
| project Timestamp, DeviceName, FileName, FolderPath, SHA256, InitiatingProcessFileName
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
DeviceFileEvents | Ensure this data connector is enabled |
Here are 5 specific false positive scenarios for the ThreatFox: Formbook IOCs detection rule, tailored for an enterprise environment relying on Microsoft ecosystem and standard DevOps practices:
Scheduled Office 365 Compliance Scans
svc-o365-audit) or the Process Name (powershell.exe running under a scheduled task) initiating the connection, rather than blocking by user identity alone.CI/CD Pipeline Artifact Deployment
10.20.50.0/24) or filter by the Build Agent Hostname (e.g., azdo-agent-01), ensuring only production user workstations are subject to strict alerting for this rule.IT Helpdesk Ticket Resolution Workflow