skip to Main Content

Cybercrime, the “Sha + bookings” email conveys Formbook

Technical analysis by the Malware Hunter JAMESWT

The “Sha + bookings” email conveys the latest Formbook campaign. The rar attachment contains an executable file: the malware itself. This, if opened, activates the infection chain

“Sha + bookings” is the subject of the latest email in the global Formbook campaign.

The rar attachment contains an executable file: the malware itself. This, if opened, activates the infection chain. The goal of cybercrime is to steal sensitive data from victims. Formbook, in fact, through the keylogger function, is able to acquire everything the user types. It can also steal email and browser credentials, as well as take screenshots. Finally, it has the ability to remotely issue commands on the infected PC, such as downloading additional payloads or updating those present.

Malware C2

Back To Top