FormBook Description
The FormBook malware is developed by a programmer who uses the handle 'ng-Coder' and offers access to a "FormBook Builder" software on various Dark Web forums and code sharing platforms. The FormBook malware became the talk of the cybersecurity community in October 2017 and was covered as part of the QuantLoader and the Panda Banker campaigns extensively. The cybercrooks are offered by 'ng-Coder' to buy their way into the "FormBook Builder," which is not distributed to machines locally. Customers are given access to a PHP control panel, which they use to create and download a customized version. Interested parties are welcomed to purchase a subscription for $29/week, $59/month, and $99/three months if they are interested in incorporating the FormBook into their operations. The FormBook payload can be packed as PDFs with download links, DOC, and XLS files with macros and archives with executable inside. Once the FormBook malware is introduced to a targeted device, it offers the following capabilities to its operators:
- Clear the browser's cookies.
- Clipboard grabbing.
- Collect passwords and emails from Outlook, Mozilla Thunderbird, Mozilla Firefox, Google Chrome and Internet Explorer.
- Download and execute files.
- Download and extract files from archives.
- Install updates to the bot.
- Keyboard input logging.
- Reboot & shut down the system.
- Record HTTP;HTTPS;SPDY;HTTP2 forms.
- Remove the bot from the infected device.
- Screenshot.
The FormBook Trojan includes abilities to make it harder for AV solutions to find the threat on the compromised system. Malware analysts alert that FormBook loads on startup via a hidden entry, uses standard Windows APIs, employs encrypted channels for C&C communications and includes a function that changes the file paths, file names, and extensions used during active periods. All these features make the FormBook Trojan hard to identify and an intriguing product on the Dark Web. The FormBook Trojan was launched within the South Korean cyberspace initially. However, we expect the FormBook Trojan to receive a lot of attention and spread throughout Asia, Europe and South America. You should make sure to run a trustworthy anti-malware suite that can identify and eliminate the FormBook threat. AV engines flag FormBook-related files as:
- DR/AutoIt.Gen
- Gen:Heur.Liusky.1
- RAR/Agent.CC
- Script.Trojan.Agent.DLEUTD
- TROJ_OTOFORM.A
- Trojan ( 005126601 )
- Trojan/Win32.AutoIt.C2181283
- W32/Injector.CZM!tr
Technical Information
File System Details
# | File Name | Size | MD5 |
---|---|---|---|
1 | file.exe | 154,624 | 653922d5e914eb7e6d906a083d930e29 |
Registry Details
Site Disclaimer
This article is provided "as is" and to be used for educational information purposes only. By following any instructions on this article, you agree to be bound by the disclaimer. We make no guarantees that this article will help you completely remove the malware threats on your computer. Spyware changes regularly; therefore, it is difficult to fully clean an infected machine through manual means.