home.social

#formbook — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #formbook, aggregated by home.social.

fetched live
  1. Чемпионат по контрактам: изучаем эволюцию атак киберпреступной группировки xplogs22

    Киберпреступные группы, атакующие Россию, отличаются разнообразием. Среди них есть те, кто специализируется на взломе исключительно российских компаний, а есть и такие, для кого организации в РФ — главная, но далеко не единственная цель. И среди них есть тоже разделение: одни киберпреступники предпочитают работать преимущественно по странам СНГ, а другие масштабируют свои атаки на Западную Европу, Ближний Восток и Юго-Восточную Азию. В этом блоге разберем атаки одной из таких группировок - xplogs22 .

    habr.com/ru/companies/F6/artic

    #xplogs22 #xworm #SnakeKeylogger #formbook #фишинговые_рассылки #threat_intelligence

  2. 🚨 0-day vibes from 2017? Yup, it’s still happening.

    A malicious Excel file using CVE-2017-0199 is out here in 2025 dropping FormBook like it's a fresh mixtape.

    The attack chain?

    • Macro-free Excel
    • Weaponized with remote .hta
    • Payload: Info-stealer FormBook

    Despite being 7+ years old, this vuln still slaps in phishing campaigns — because patching is apparently a myth.

    Full technical breakdown by @FortiGuardLabs: fortinet.com/blog/threat-resea

    TL;DR for blue teamers:

    • Watch your egress traffic
    • Harden Office apps
    • Monitor LOLBins (Living Off the Land Binaries)
    • Block outbound to shady IPs faster than your memes go viral

    Don’t let your org get dunked on by a 2017 CVE in 2025. That’s not a good look.

    #CyberSecurity #ThreatIntel #FormBook #CVE20170199 #Infosec #BlueTeam #MalwareAnalysis #HackerNews #Phishing

  3. Parked domains are used in all sorts of interesting ways. Recently we saw a set used in the sender addresses of spam delivery formbook malware. The emails disguised as salary updates, purchase orders, fines, and vendor enrollments. The sender addresses typically appear to be from HR or some other official group associated with the subject.

    The domains associated with these formbook campaigns are lookalikes, designed to impersonate legitimate brands in an attempt to dupe the victim. Some examples of the brands we have seen lookalikes for include Blue-Maritime and Vanity Case Group.

    The spam itself appears to run through actor-controlled relays (SPF failures, etc) and originate in AS203557 (Dataclub / Latvia). We see the same actor delivering Formbook via various campaigns for over a year targeting users from different regions, including the Middle East, India, and the United States.

    Because the domains are parked, it is hard to confirm whether the spam actor controls them or is just digging around parking lots.

    Fun fact: Formbook malware is known to use parked domains for decoy C2 urls as well.

    IOCs: blu-maritlme[.]com, thevenitycase[.]com
    Example filename: Gross Misconduct.rar
    Sha256: 09590f63531e7e5d7b8e86a55e1e3014cc86c99694c94a29c95215acac227c89

    #dns #threatintel #cybercrime #threatintelligence #cybersecurity #infoblox #infobloxthreatintel #infosec #malware #formbook #spam

  4. Social media post I wrote for my employer on other platforms: 2025-02-26 (Wednesday): #XLoader (#Formbook) distributed through #malspam.

    The email has an attached PDF document. The PDF has links for a ZIP download, and the ZIP contains files using DLL side-loading for XLoader.

    Details at github.com/PaloAltoNetworks/Un

  5. Campagne #Malware #Italy Week 29

    ☠️💣🔥👻
    #AgentTesla: Ordine
    #Formbook: Offerta
    #GuLoader: Fattura Elettronica
    #Remcos: Bank
    #Lokibot: Delivery
    #SmokeLoader: Pagamenti
    #Irata: Malware APK
    #RedLine: Offerta
    #Neshta: Ordine
    #Ousaban: Processo
    #SnakeKeylogger: Fattura

    #mwitaly

  6. We just released a landscape review of Registered DGAs. We review the many ways threat actors are leveraging these algorithms -- including malware, phishing, scams, porns, you name it. Our RDGA detectors find tens of thousands of domains every day, and we've seen the use continue to rise over the last several years. Most folks aren't even aware since actors are doing this in DNS and it often isn't obvious. #dns #threatintel #cybersecurity #cybercrime #infoblox #RDGA #DGA #DDGA #malware #phishing #scams #infoblox #infobloxthreatintel #cybersecurity #threatactor #c2 #revolverrabbit #threatintelligence #cyber #cyberintelligence #xloader #formbook #abusedtld insights.infoblox.com/resource

  7. Hey there! I stumbled upon a fresh sample of Formbook info-stealer malware. During analysis I found this malware hides its payload into a vulnerable WordPress website.
    Read the article to know more.
    #FormBook #Stealer #MalwareAnalysis #MalwareResearch #CTI #ThreatIntel #InfoSec ashishranax.github.io/posts/Fo

  8. Some fresh encoded #formbook in an #opendir at:

    http://dianomefs .cfd/Ajai/

  9. The malware pays homage to the League of Legends character Jinx, prominently featuring the character on its advertising poster and command-and-control login panel. JinxLoader’s primary purpose is straightforward – loading malware.

    #Cybersecurity #Formbook #JinxLoader #Malware #Xloader

    cybersec84.wordpress.com/2024/

  10. I am going to be reviewing the Formbook malware and process hooking with the interns this morning before we break off and start working on stuff. LETS GO!
    #security #malware #formbook #processhooking

  11. URLhaus is operational for over 5 years, notifying hosting providers + network operators about malware hosted in their network 🪲 It's a shame that some hosting providers ignore abuse reports, spreading malware for over four years 🤯

    Here's our current 💩-list 👇

    AS38841 kbro 🇹🇼, spreading #hajime:
    🌐 urlhaus.abuse.ch/url/86646/

    AS23520 Columbus Networks 🇧🇸, spreading #hajime:
    🌐 urlhaus.abuse.ch/url/91891/

    AS29873 Newfold Digital 🇺🇸, spreading #FormBook:
    🌐 urlhaus.abuse.ch/url/117832/

    AS58955 Bangmod 🇹🇭, spreading #Emotet:
    🌐 urlhaus.abuse.ch/url/200073/

  12. Today in our section on "uncoventional #Malware delivery": #ARJ archives! 📦
    ARJ (Archived by Robert Jung) has been around since the MS-DOS days and is occasionally used to deliver e.g. #AgentTesla, #Formbook or #Guloader

    You can recognize ARJ archives by their Magic: 60 EA
    Extraction can be handled with 7zip for example.
    For more information on the file format check out Ange Albertini's excellent graphic representation: twitter.com/angealbertini/stat

    As an example we dug up a #Lokibot sample from last year where the delivery chain looked like this: ARJ --> RAR --> EXE
    To fool the victims into opening the next file they used the common #doubleExtension tick, e.g. .pdf.exe

    IoC for those playing along at home:
    162.0.223[.]13
    kbfvzoboss[.]bid
    alphastand[.]trade
    alphastand[.]win
    alphastand[.]top
    ➡️/alien/fre.php

    PO_Payment for invoice[...].eml.arj
    d0c8824d1e19ca1af0b88a477fa4cad6

    SHIPPING_DL-PL-EXPRESS_EXPORT.PDF.exe
    88bdf4f8fe035276da984c370e4cda2c

    #infosec #cybersecurity #blueteam

  13. Quick Tip 🛠️: Threat Actors like to use archiving tools for #malware delivery to avoid #detection and reduce file size. Today we spotted a .ace Archive containing #Formbook #infostealer. This technique is not new and also occasionally used for #AgentTesla, #RedLine etc.

    ACE is a proprietary, legacy compression format. Unpacking these archives is dependend on the ACE version, e.g. "unace" v1.2 cannot handle ACE 2.0. We recommend github.com/droe/acefile by @droe if you ever come across such a file (screenshots see below).

    FormBook #IoC

    Files:
    Archive e91b62f7952825d6a87775166301d018
    Executable d539fcc11b4f5b96a1d89928f1ef87e7

    C2:
    allthekey[.]com
    mgconsultantlogistics[.]com
    bonaccorso[.]online
    vowlashes[.]co[.]uk

    Links to the samples on Malware Bazaar:

    bazaar.abuse.ch/sample/2787c73

    bazaar.abuse.ch/sample/27715b2