skip to Main Content

Cybercrime, courier-themed double Formbook campaign

Malware Hunter JAMESWT Technical Analysis

Courier-themed double Formbook campaign. The emails carry an img attachment and a rar. Both contain an exe file – the malware itself

Double global Formbook campaign. The bait is a fake email from a courier, which in one case carries an img attachment and in the other a rar.

Both contain an exe file – the malware itself. Formbook, through the keylogger function, is able to acquire everything the user types. It can also steal email and browser credentials, as well as take screenshots. Finally, it has the ability to remotely issue commands on the infected PC, such as downloading additional payloads or updating those present.

Malware C2

   

Back To Top