logo

Formbook Delivered Through Multiple Scripts, (Thu, Nov 13th)

ID: 7b6c9541-e0dd-5f69-ba6b-abe48d83f6a4

STIX ID: report--7b6c9541-e0dd-5f69-ba6b-abe48d83f6a4

Feed Name: SANS ISC Diary

Threat Score
70/100

Date Published: 2025-11-13

Date Updated: 2026-04-19

...
...

This report analyzes a multi-stage email-delivered FormBook campaign: an obfuscated VBS downloader waits, reconstructs and executes an obfuscated PowerShell loader which fetches a second PowerShell payload from Google Drive, writes payloads to user AppData/Temp, and injects FormBook (bin.exe) into msiexec.exe; included are SHA256s for the VBS and PE, a C2 endpoint (216.250.252.227:7719), VirusTotal references, and behavioral indicators observed on the infected host.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.