PULSE NAME
The Formidable FormBook Form Grabber
WHITE AlienVault 2017-09-22 Modified: 2017-09-22
12
IOCs
MEDIUM VOLUME
More and more we’ve been seeing references to a malware family known as FormBook. Per its advertisements it is an infostealer that steals form data from various web browsers and other applications. It is also a keylogger and can take screenshots. The malware code is complicated, busy, and fairly obfuscated–there are no Windows API calls or obvious strings. This post will start to explore some of these obfuscations to get a better understanding of how FormBook works.
Indicators of Compromise (3 / 12 total)
All FileHash-SHA256 FileHash-MD5 FileHash-SHA1 URL
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 9a5c7cbf8b80b98afaf02e79987e678781d73d24 2017-09-22
FileHash-SHA1 2eca7643ef603dda09958a11060320540e2cc6ac 2017-09-22
FileHash-SHA1 3969410b8ef70a8a510ca0151476c9190d3a8578 2017-09-22