PULSE NAME
The Formidable FormBook Form Grabber
WHITE AlienVault 2017-09-22 Modified: 2017-09-22
12
IOCs
MEDIUM VOLUME
More and more we’ve been seeing references to a malware family known as FormBook. Per its advertisements it is an infostealer that steals form data from various web browsers and other applications. It is also a keylogger and can take screenshots. The malware code is complicated, busy, and fairly obfuscated–there are no Windows API calls or obvious strings. This post will start to explore some of these obfuscations to get a better understanding of how FormBook works.
Indicators of Compromise (3 / 12 total)
All FileHash-SHA256 FileHash-MD5 FileHash-SHA1 URL
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 0e2678f5d0173246c464a42aced9a6f5494e9f2619257ba7e468834e8708b726 2017-09-22
FileHash-SHA256 c2bbec7eb5efc46c21d5950bb625c02ee96f565d2b8202733e784e6210679db9 2017-09-22
FileHash-SHA256 d90d9e829656cb0b5dfb76faad37b35c6b5383763bd29a3d73c65311ab31dac5 2017-09-22