FormBook Description

The FormBook malware is developed by a programmer who uses the handle 'ng-Coder' and offers access to a "FormBook Builder" software on various Dark Web forums and code sharing platforms. The FormBook malware became the talk of the cybersecurity community in October 2017 and was covered as part of the QuantLoader and the Panda Banker campaigns extensively. The cybercrooks are offered by 'ng-Coder' to buy their way into the "FormBook Builder," which is not distributed to machines locally. Customers are given access to a PHP control panel, which they use to create and download a customized version. Interested parties are welcomed to purchase a subscription for $29/week, $59/month, and $99/three months if they are interested in incorporating the FormBook into their operations. The FormBook payload can be packed as PDFs with download links, DOC, and XLS files with macros and archives with executable inside. Once the FormBook malware is introduced to a targeted device, it offers the following capabilities to its operators:

  • Clear the browser's cookies.
  • Clipboard grabbing.
  • Collect passwords and emails from Outlook, Mozilla Thunderbird, Mozilla Firefox, Google Chrome and Internet Explorer.
  • Download and execute files.
  • Download and extract files from archives.
  • Install updates to the bot.
  • Keyboard input logging.
  • Reboot & shut down the system.
  • Record HTTP;HTTPS;SPDY;HTTP2 forms.
  • Remove the bot from the infected device.
  • Screenshot.

The FormBook Trojan includes abilities to make it harder for AV solutions to find the threat on the compromised system. Malware analysts alert that FormBook loads on startup via a hidden entry, uses standard Windows APIs, employs encrypted channels for C&C communications and includes a function that changes the file paths, file names, and extensions used during active periods. All these features make the FormBook Trojan hard to identify and an intriguing product on the Dark Web. The FormBook Trojan was launched within the South Korean cyberspace initially. However, we expect the FormBook Trojan to receive a lot of attention and spread throughout Asia, Europe and South America. You should make sure to run a trustworthy anti-malware suite that can identify and eliminate the FormBook threat. AV engines flag FormBook-related files as:

  • DR/AutoIt.Gen
  • Gen:Heur.Liusky.1
  • RAR/Agent.CC
  • Script.Trojan.Agent.DLEUTD
  • Trojan ( 005126601 )
  • Trojan/Win32.AutoIt.C2181283
  • W32/Injector.CZM!tr

Technical Information

File System Details

FormBook creates the following file(s):
# File Name Size MD5
1 file.exe 154,624 653922d5e914eb7e6d906a083d930e29
More files

Registry Details

FormBook creates the following registry entry or registry entries:
Regexp file mask

Site Disclaimer is not associated, affiliated, sponsored or owned by the malware creators or distributors mentioned on this article. This article should NOT be mistaken or confused in being associated in any way with the promotion or endorsement of malware. Our intent is to provide information that will educate computer users on how to detect, and ultimately remove, malware from their computer with the help of SpyHunter and/or manual removal instructions provided on this article.

This article is provided "as is" and to be used for educational information purposes only. By following any instructions on this article, you agree to be bound by the disclaimer. We make no guarantees that this article will help you completely remove the malware threats on your computer. Spyware changes regularly; therefore, it is difficult to fully clean an infected machine through manual means.

Leave a Reply

Please DO NOT use this comment system for support or billing questions. For SpyHunter technical support requests, please contact our technical support team directly by opening a customer support ticket via your SpyHunter. For billing issues, please refer to our "Billing Questions or Problems?" page. For general inquiries (complaints, legal, press, marketing, copyright), visit our "Inquiries and Feedback" page.

HTML is not allowed.