#formbook — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #formbook, aggregated by home.social.
-
Чемпионат по контрактам: изучаем эволюцию атак киберпреступной группировки xplogs22
Киберпреступные группы, атакующие Россию, отличаются разнообразием. Среди них есть те, кто специализируется на взломе исключительно российских компаний, а есть и такие, для кого организации в РФ — главная, но далеко не единственная цель. И среди них есть тоже разделение: одни киберпреступники предпочитают работать преимущественно по странам СНГ, а другие масштабируют свои атаки на Западную Европу, Ближний Восток и Юго-Восточную Азию. В этом блоге разберем атаки одной из таких группировок - xplogs22 .
https://habr.com/ru/companies/F6/articles/1057908/
#xplogs22 #xworm #SnakeKeylogger #formbook #фишинговые_рассылки #threat_intelligence
-
🚨 0-day vibes from 2017? Yup, it’s still happening.
A malicious Excel file using CVE-2017-0199 is out here in 2025 dropping FormBook like it's a fresh mixtape.
The attack chain?
- Macro-free Excel
- Weaponized with remote .hta
- Payload: Info-stealer FormBook
Despite being 7+ years old, this vuln still slaps in phishing campaigns — because patching is apparently a myth.
Full technical breakdown by @FortiGuardLabs: https://www.fortinet.com/blog/threat-research/how-a-malicious-excel-file-cve-2017-0199-delivers-the-formbook-payload
TL;DR for blue teamers:
- Watch your egress traffic
- Harden Office apps
- Monitor LOLBins (Living Off the Land Binaries)
- Block outbound to shady IPs faster than your memes go viral
Don’t let your org get dunked on by a 2017 CVE in 2025. That’s not a good look.
#CyberSecurity #ThreatIntel #FormBook #CVE20170199 #Infosec #BlueTeam #MalwareAnalysis #HackerNews #Phishing
-
Parked domains are used in all sorts of interesting ways. Recently we saw a set used in the sender addresses of spam delivery formbook malware. The emails disguised as salary updates, purchase orders, fines, and vendor enrollments. The sender addresses typically appear to be from HR or some other official group associated with the subject.
The domains associated with these formbook campaigns are lookalikes, designed to impersonate legitimate brands in an attempt to dupe the victim. Some examples of the brands we have seen lookalikes for include Blue-Maritime and Vanity Case Group.
The spam itself appears to run through actor-controlled relays (SPF failures, etc) and originate in AS203557 (Dataclub / Latvia). We see the same actor delivering Formbook via various campaigns for over a year targeting users from different regions, including the Middle East, India, and the United States.
Because the domains are parked, it is hard to confirm whether the spam actor controls them or is just digging around parking lots.
Fun fact: Formbook malware is known to use parked domains for decoy C2 urls as well.
IOCs: blu-maritlme[.]com, thevenitycase[.]com
Example filename: Gross Misconduct.rar
Sha256: 09590f63531e7e5d7b8e86a55e1e3014cc86c99694c94a29c95215acac227c89
#dns #threatintel #cybercrime #threatintelligence #cybersecurity #infoblox #infobloxthreatintel #infosec #malware #formbook #spam -
Analysis of Top Infostealers: Redline, Vidar and Formbook https://hackread.com/top-infostealers-analysis-redline-vidar-formbook/ #ThreatIntelligence #Cybersecurity #Infostealer #Security #Formbook #Malware #Redline #TROJAN #Vidar
-
Campagne #Malware #Italy Week 29
☠️💣🔥👻
#AgentTesla: Ordine
#Formbook: Offerta
#GuLoader: Fattura Elettronica
#Remcos: Bank
#Lokibot: Delivery
#SmokeLoader: Pagamenti
#Irata: Malware APK
#RedLine: Offerta
#Neshta: Ordine
#Ousaban: Processo
#SnakeKeylogger: Fattura -
We just released a landscape review of Registered DGAs. We review the many ways threat actors are leveraging these algorithms -- including malware, phishing, scams, porns, you name it. Our RDGA detectors find tens of thousands of domains every day, and we've seen the use continue to rise over the last several years. Most folks aren't even aware since actors are doing this in DNS and it often isn't obvious. #dns #threatintel #cybersecurity #cybercrime #infoblox #RDGA #DGA #DDGA #malware #phishing #scams #infoblox #infobloxthreatintel #cybersecurity #threatactor #c2 #revolverrabbit #threatintelligence #cyber #cyberintelligence #xloader #formbook #abusedtld https://insights.infoblox.com/resources-research-report/infoblox-research-report-registered-dgas-the-prolific-new-menace-no-one-is-talking-about
-
Hey there! I stumbled upon a fresh sample of Formbook info-stealer malware. During analysis I found this malware hides its payload into a vulnerable WordPress website.
Read the article to know more.
#FormBook #Stealer #MalwareAnalysis #MalwareResearch #CTI #ThreatIntel #InfoSec https://ashishranax.github.io/posts/FormBook-Malware-The-Uninvited-Guest-of-WordPress/ -
Not sure when it happened, but #xloader / #formbook now appears to rotate through campaign ID's:
https://app.any.run/tasks/4cb7b5ef-5c1d-4565-a370-5d0cf1a5c255
-
Seen 3 of these, so might as well share.... NSIS installer -> powershell -> #formbook
https://app.any.run/tasks/b8fe6ed2-d843-4340-b03d-4f8be11006e4
https://app.any.run/tasks/723d54ab-4480-4dba-af6c-6bd4f4eadbfe/
https://app.any.run/tasks/98e899be-47e4-4d90-a8a7-07ec13b1e809/ -
-
The malware pays homage to the League of Legends character Jinx, prominently featuring the character on its advertising poster and command-and-control login panel. JinxLoader’s primary purpose is straightforward – loading malware.
-
First time I've seen #formbook #malware actually embedded in an rtf:
https://app.any.run/tasks/ca41f860-0e0c-4489-b59c-7b62ca089061
-
📬 XLoader: macOS-Malware tarnt sich als OfficeNote-Anwendung
#ITSicherheit #Malware #DineshDevadoss #Formbook #Keylogger #macOS #macOSMalware #OfficeNote #PhilStokes #SentinelOne #XLoader https://tarnkappe.info/artikel/it-sicherheit/xloader-macos-malware-tarnt-sich-als-officenote-anwendung-279902.html -
An interesting #loader that drops #formbook via:
http://172.93.161[.]118/onlysim/Mdtiho.pdf
https://app.any.run/tasks/0a1b6fbb-60b2-4a9a-aa38-89b47f6cf20d
-
ISC Diary: @malware_traffic reviews loader-style infection for #Formbook on 2023-07-11 https://i5c.us/d30020
-
ISC Diary: @malware_traffic reviews #Formbook from possible #ModiLoader (#DBatLoader) https://i5c.us/d29958
-
I am going to be reviewing the Formbook malware and process hooking with the interns this morning before we break off and start working on stuff. LETS GO!
#security #malware #formbook #processhooking -
URLhaus is operational for over 5 years, notifying hosting providers + network operators about malware hosted in their network 🪲 It's a shame that some hosting providers ignore abuse reports, spreading malware for over four years 🤯
Here's our current 💩-list 👇
AS38841 kbro 🇹🇼, spreading #hajime:
🌐 https://urlhaus.abuse.ch/url/86646/AS23520 Columbus Networks 🇧🇸, spreading #hajime:
🌐 https://urlhaus.abuse.ch/url/91891/AS29873 Newfold Digital 🇺🇸, spreading #FormBook:
🌐 https://urlhaus.abuse.ch/url/117832/AS58955 Bangmod 🇹🇭, spreading #Emotet:
🌐 https://urlhaus.abuse.ch/url/200073/ -
Today in our section on "uncoventional #Malware delivery": #ARJ archives! 📦
ARJ (Archived by Robert Jung) has been around since the MS-DOS days and is occasionally used to deliver e.g. #AgentTesla, #Formbook or #GuloaderYou can recognize ARJ archives by their Magic: 60 EA
Extraction can be handled with 7zip for example.
For more information on the file format check out Ange Albertini's excellent graphic representation: https://twitter.com/angealbertini/status/1619006171360395264As an example we dug up a #Lokibot sample from last year where the delivery chain looked like this: ARJ --> RAR --> EXE
To fool the victims into opening the next file they used the common #doubleExtension tick, e.g. .pdf.exeIoC for those playing along at home:
162.0.223[.]13
kbfvzoboss[.]bid
alphastand[.]trade
alphastand[.]win
alphastand[.]top
➡️/alien/fre.phpPO_Payment for invoice[...].eml.arj
d0c8824d1e19ca1af0b88a477fa4cad6SHIPPING_DL-PL-EXPRESS_EXPORT.PDF.exe
88bdf4f8fe035276da984c370e4cda2c -
📬 Virtualisierte Malware versteckt sich in Google-Werbung für Blender
#Malware #AntivirenSoftware #Blender #Formbook #GoogleAds #GoogleWerbeanzeigen #Infostealer #KoiVM #MalVirt #MalwareAnalyse #MalwareLoader #virtualisierteMalware https://tarnkappe.info/artikel/malware/virtualisierte-malware-versteckt-sich-in-google-werbung-fuer-blender-264651.html -
Quick Tip 🛠️: Threat Actors like to use archiving tools for #malware delivery to avoid #detection and reduce file size. Today we spotted a .ace Archive containing #Formbook #infostealer. This technique is not new and also occasionally used for #AgentTesla, #RedLine etc.
ACE is a proprietary, legacy compression format. Unpacking these archives is dependend on the ACE version, e.g. "unace" v1.2 cannot handle ACE 2.0. We recommend https://github.com/droe/acefile by @droe if you ever come across such a file (screenshots see below).
FormBook #IoC
Files:
Archive e91b62f7952825d6a87775166301d018
Executable d539fcc11b4f5b96a1d89928f1ef87e7C2:
allthekey[.]com
mgconsultantlogistics[.]com
bonaccorso[.]online
vowlashes[.]co[.]ukLinks to the samples on Malware Bazaar:
https://bazaar.abuse.ch/sample/2787c73ed16419f6c5cfb81ae4e2db23c91507eaf1d8c1c10e8b965b394fe443/
https://bazaar.abuse.ch/sample/27715b211a7693bd15a4580b6ee1e9b9d01c2b1142170b47888b7be538ecb084/