Formbook Delivered Through Multiple Scripts, (Thu, Nov 13th)
ID: 7b6c9541-e0dd-5f69-ba6b-abe48d83f6a4
STIX ID: report--7b6c9541-e0dd-5f69-ba6b-abe48d83f6a4
Feed Name: SANS ISC Diary
Threat Score
This report analyzes a multi-stage email-delivered FormBook campaign: an obfuscated VBS downloader waits, reconstructs and executes an obfuscated PowerShell loader which fetches a second PowerShell payload from Google Drive, writes payloads to user AppData/Temp, and injects FormBook (bin.exe) into msiexec.exe; included are SHA256s for the VBS and PE, a C2 endpoint (216.250.252.227:7719), VirusTotal references, and behavioral indicators observed on the infected host.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
