#Formbook
Just a reminder of what "Formbook Porn" looks like !!
January 30, 2025 at 10:07 AM
2024-11-22 (Friday) #XLoader / #Formbook: I've been fired by my non-existent HR department. At least I got a "salary-receipt.exe" bazaar.abuse.ch/sample/003b5...

Tria.ge and Any.Run don't identify the malware, but Joe Sandbox does: www.joesandbox.com/analysis/156...

Also runs in my lab just fine
November 22, 2024 at 7:42 PM
Honda has been tipped to create the best powertrain during the next F1 regulation cycle as new engines will shake up the formbook next season... #F1

www.planetf1.com/news/honda-t...
Honda on top in F1 2026 power unit regulation shake-up?
Honda has been tipped to create the best powertrain during the next F1 regulation cycle as new engines will shake up the formbook next season.
www.planetf1.com
March 9, 2025 at 5:05 PM
FormBook Malware Spreads via Sophisticated Phishing Attack
FormBook Malware Spreads via Sophisticated Phishing Attack
A new phishing campaign delivers FormBook malware via Word docs, exploiting CVE-2017-11882. The fileless attack uses process hollowing to evade detection.
securityonline.info
April 24, 2025 at 4:58 AM
Morning catch-up thoughts (MotoGP):
- Going about as the formbook suggested: Think Ducati look a little stronger, but Bez is in range. Not entirely a bad thing if you're Marc.
- Very close all-round though. Going to come down to on the day strength.
October 2, 2026 at 11:43 AM
2026-04-13 (Monday): #XLoader ( #Formbook ) infection. A #pcap of the traffic, along with the associated email and malware samples are available at malware-traffic-analysis.net/2026/index.h...
April 14, 2026 at 9:47 PM
🚨 FormBook malware spreads via fake installers

A new FormBook wave uses weaponized PDFs and spoofed software installers to steal passwords, browser data, keystrokes and screenshots while dropping secondary payloads. Targets include small firms and home users.

#ransomNews #FormBook #malware
November 18, 2025 at 8:37 AM
Late night thought - McLaren my by rough count, were .4 a lap quicker than Red Bull. The formbook held, this was a gimme.

Verstappen is now #F1's Ronnie O'Sullivan. Possible headloss? Sure. But he can rattle half the league to the point where their heads have gone before they've even started.
December 1, 2025 at 2:12 AM
Anatomia di un furto di dati: Analisi tecnica dell'Infostealer "Formbook"

www.redhotcyber.com/post/anatomi...

> Scopri come Formbook, un potente infostealer, colpisce le reti aziendali e come ELMI aiuta a prevenire e rilevare queste minacce con soluzioni integrate di sicurezza informatica.
Anatomia di un furto di dati: Analisi tecnica dell'Infostealer "Formbook"
Scopri come Formbook, un potente infostealer, colpisce le reti aziendali e come ELMI aiuta a prevenire e rilevare queste minacce con soluzioni integrate di sicurezza informatica.
www.redhotcyber.com
October 27, 2025 at 7:38 AM
Formbook Delivered Through Multiple Scripts https://isc.sans.edu/diary/32480
November 13, 2025 at 8:51 AM
In H2 2025, #ESETresearch saw a thirtyfold increase in #CloudEyE detections, amounting to more than 100,000 hits over the course of six months. CloudEyE is a #MaaS downloader and cryptor used to conceal and deploy other malware, such as #Rescoms, #Formbook, and #Agent Tesla. 1/5
January 6, 2026 at 10:03 AM
#opendir with lots of PowerShell fun (spreading #FormBook it seems) ⤵️

urlhaus.abuse.ch/host/87.120....
February 3, 2025 at 7:06 AM
Formbook is formiddable in its anti-forensic footprint. It self-hollows its Powershell process so that it can evade programs like Sysmon who detect process hollowing. Son of a bitch. This is why I like looking at malware man, it's endless technological wizardry.
September 1, 2026 at 8:02 AM
CTA member VMRay brings a story of a hunt: how a pile of 276 Formbook samples run through a machine learning pipeline led us to a global Business Email Compromise campaign.

www.vmray.com/hunting-a-gl...
#cybersecurity #threatresearch
From One RedLine IP to a Maritime Phishing Cluster: A Threat Intelligence Pivot Chain
A single RedLine C2 from UniqueSignal pivots into a maritime spear-phishing cluster and attacker-owned infrastructure.
www.vmray.com
October 2, 2026 at 8:00 PM
-Perforce servers widely exposed on the internet
-The Hormuz scams are here
-Malware reports on The Gentlemen, Kyber, TwizAdmin, NGate, PhantomCLR, Gh0st RAT, Formbook, FudCrypt
-Ukrainian APT goes after TrueConf
-EU sanctions hit the Kremlin disinfo peddler
-Major KEV update
April 22, 2026 at 10:07 AM
Social media post I wrote for my employer on other platforms: 2025-02-26 (Wednesday): #XLoader (#Formbook) sent thru #malspam. Email has an attached PDF document. PDF has links for a ZIP download, and the ZIP contains files using DLL side-loading for XLoader. Details at github.com/PaloAltoNetw...
February 27, 2025 at 2:44 PM
添付ファイルからマルウェア感染を狙った日本語のメールが確認されています。
■日時
2026/10/06(火)
■件名
ご教示ください
■添付ファイル
至急のお見積もり依頼[.]zip -> .js
www.virustotal.com/gui/file/a83...
tria.ge/261006-d8hwv...
情報窃取マルウェア #Formbook
■通信先
hxxps[:]//www.beinke-aufzuege[.]de/components/com_media/fkqabmp/ntxqre1/edfwcgi/secured_stub.ps1
October 6, 2026 at 9:25 AM
Sure, sometimes the historical formbook gets thrown out, but in general, "it's different this time" doesn't end better for opposition parties than it does for banks.
February 21, 2025 at 4:05 PM
Bahrain forms a blurry picture of F1’s 2025 formbook
Bahrain forms a blurry picture of F1’s 2025 formbook
Bahrain forms a blurry picture of F1’s 2025 formbook
racer.com
February 28, 2025 at 7:31 PM
🚨 IOC Alert: Formbook C2 Infrastructure Linked to Parked Domain

darkwebinformer.com/ioc-alert-fo...
IOC Alert: Formbook C2 Infrastructure Linked to Parked Domain
IOC Alert: Formbook C2 Infrastructure Linked to Parked Domain
darkwebinformer.com
October 3, 2025 at 5:20 PM
TBH I think the interesting question is, assuming, as the formbook suggests we should, that there will be a big panic after the London elections in 2026, is 'can three years of tax and spend claw back enough feelgood factor by late 2029?'
May 2, 2025 at 7:37 AM
In ESET telemetry data, Formbook replaced Agent Tesla as the No. 1 infostealer after its detections shot up by more than 200%. Despite operating since 2016, this MaaS threat is constantly under development, which explains why it is still used so frequently by cybercriminals. 3/5
February 1, 2025 at 4:38 AM
FormBook virus informatico un malware di tipo infostealer 
www.ammassi.it/blog/2025/09...
FormBook virus informatico un malware di tipo infostealer  AmmassiIT - AmmassiIT
FormBook virus informatico un malware di tipo infostealer  AmmassiIT News - AmmassiIT AmmassiIT
www.ammassi.it
September 30, 2025 at 1:05 PM