Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now
25
Global rank
17
Month rank
17 infographic chevron week
Week rank
0
IOCs

FormBook is a data stealer that is being distributed as a MaaS. FormBook differs from a lot of competing malware by its extreme ease of use that allows even the unexperienced threat actors to use FormBook virus.

Spyware
Type
Unknown
Origin
1 January, 2016
First seen
28 August, 2026
Last seen
Also known as
Xloader

How to analyze Formbook with ANY.RUN

Type
Unknown
Origin
1 January, 2016
First seen
28 August, 2026
Last seen

IOCs

IP addresses
139.99.85.213
154.91.34.165
188.114.97.3
75.119.193.253
149.154.166.110
2.16.241.205
213.180.204.127
208.95.112.1
45.141.233.69
132.148.178.5
150.171.22.17
132.226.247.73
185.121.177.177
150.171.28.11
2.59.254.111
176.65.144.23
217.78.234.145
74.120.9.233
192.178.183.94
185.156.72.2
Hashes
82042ec4e11fffbf1b0b5e6721afce8ac960267b2061c1ca2b30ebc2e58f4d17
f91dbb7c64b4582f529c968c480d2dce1c8727390482f31e4355a27bb3d9b450
5e32f16d52a5577a937f2c8513ca35c9e6be351a7a0fbb74278407df504d86a5
0dda9a17d54e586598a6200db854be52654d3e9def07363cd1e837569af88974
0c5490ca2f6d61c2d410e7907be97b3bc36b3e4de614e1f5431278dbccad4c79
69cb93351b7b2b3c33fa6826be062c454924a34bae7dd812de27eb70767843f1
3935a289417a1f1584f163ae93bddac534a69f69af224dbd4a434300ced93382
a5c1700269d33046833d6165b026dbaf1305ad612a892dff4ba3fa6701744027
fb75d593076ef30f9ba4601a09bf5ea50bcf9c84f8dd0750d113429a71104a13
1091a5225a1cce78601515acec1f2d35976158852bb1a263d9b4ceb6506990f5
a7055562772c30feadf7fccf3f22da1acda82d995d536b7ff91cfef3551d9789
82eaf8e8bc7275aeaf5834f57b8cf4d53cbbe5d551a561bedd0de43ff3786708
d2ac55b4450b3d379ec28eddc138eeab49584c0c8a9328fb5158cd35bfa9e03f
96e670b631a8e0520dcbfd8067d75ef4b167df8dc3c4bb42d9e62023259adc51
dbcb1915cd4d696290d550b5c3169b9be00931df18c06b7dd157206220cab1f9
39e641a906d7f511496c49a711976117946bdfd05f8ddc6a8c495c32cb50c990
d4b23edc5e796b44c8f86e88445068bd5456ecd5d719f5b65138b682fe8a161f
fbb710d9e5dfd5037d2f5d382497c4cd36bd48d76889bc244457442e38da9d65
02546eb94be966d89abb363ff318fc1414a86a8de222654d9419d221687b8e11
ba1639606ec3b0f61526d08d8ec2efd83dc0d6327c385b80698e8898e9bf9550
Domains
reallyfreegeoip.org
www.dontlookhere.com
s3.timeweb.cloud
api.telegram.org
ip-api.com
dontlookhere.com
gstatic.com
www.bing.com
api.pcloud.com
config.edge.skype.com
mail.dhakahome.com
edge.microsoft.com
checkip.dyndns.org
google.com
cloud-api.yandex.net
login.live.com
iplogger.org
settings-win.data.microsoft.com
slscr.update.microsoft.com
grabify.link
URLs
https://gstatic.com/generate_204
https://api.pcloud.com/listfolder?path=/
https://cloud-api.yandex.net/v1/disk/resources?path=/&limit=500
http://ip-api.com/json/
http://checkip.dyndns.org/
http://ip-api.com/line/?fields=hosting
https://edge.microsoft.com/serviceexperimentation/v2/
https://config.edge.skype.com/config/v1/edge/109.0.1518.115?clientid=-626569875466424637&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfull=0&scpguard=1&scpfre=0&scpver=18&osarch=x86&osver=6.1.7601&wu=0&devicefamily=desktop&uma=1&sessionid=17&mngd=0&installdate=1604373552&edu=0&bphint=0
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x86&os_arch=x86&nacl_arch=x86-32&prod=edgecrx&prodchannel=&prodversion=109.0.1518.115&lang=en-us&acceptformat=crx3&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d837%2526e%253d1
https://reallyfreegeoip.org/xml/85.203.47.38
https://api.telegram.org/bot/sendmessage?chat_id=&text=%20%0d%0a%0d%0apc%20name:user-pc%0d%0adate%20and%20time:%208/28/2026%20/%205:37:26%20pm%0d%0acountry%20name:%20%0d%0a%5b%20user-pc%20clicked%20on%20the%20file%20if%20you%20see%20nothing%20this's%20mean%20the%20system%20storage's%20empty.%20%5d
https://dontlookhere.com/
http://www.dontlookhere.com/blog
http://dontlookhere.com/blog
https://dontlookhere.com/blog/
http://dontlookhere.com/blog/
https://api.telegram.org/bot7950066405:aae5kuvk04df6lzjfoe-yzt3f12hjhmziqg/senddocument?chat_id=-4703613545&caption=%20pc%20name:%20admin%20%7c%20/%20vip%20recovery%20%5c%0d%0a%0d%0apw%20%7c%20admin%20%7c%20vip%20recovery
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://login.live.com/rst2.srf
https://gateway.discord.gg/?v=9&encording=json
Last Seen at
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 3153
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 8509
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 11265
comments 0

What is FormBook malware?

FormBook stealer is an infostealer‍ trojan available as a malware-as-service. This malware is often used by attackers with low technical literacy and little programming knowledge. FormBook can be used to steal various information from infected machines.

Despite how easy it is to set up and use, the malware has advanced stealing and evasion functions including the ability to pull stored and recorded user input. In addition, the FormBook stealer is capable of searching for, viewing, and interacting with files, and taking screenshots. Even though the stealing capability of this virus can be considered somewhat average, its ease of operation, the injection schema, and a set of effective measures that the malware takes to avoid detection by antivirus software made FormBook a popular virus in the hacker community and, unfortunately, its popularity is only continuing to rise in 2019.

General description of the FormBook stealer

Written in C and x86 assembly language, FormBook is sold as a PHP control panel and can be purchased on highly accessible online forums for merely 30 dollars.

Uniquely, unlike the majority of existing viruses that exploit the latest vulnerabilities or zero-days, FormBook can inject into processes and set up function hooks utilizing already known issues. Hence the claim made by the makers, that the virus will work flawlessly regardless of the Windows version.

Together with its stealer functionality and evasion techniques, the virus knows how to execute instructions from a control server that includes starting new processes, their injection, and rebooting the victim’s PC. What’s more, the virus is able to record Windows’ ntdll.dll module into memory and call it directly, which makes API monitoring and user-mode hooking almost insufficient.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

FormBook malware analysis

A video simulation recorded on the ANY.RUN interactive malware analysis service allows us to take an in-depth look at the behavior of this clever virus and other malware such as Dridex and Lokibot with their elaborate anti-evasion techniques.

formbook execution process graph

Figure 1: Processes created by FormBook during execution as shown by ANY.RUN simulation

  • As shown by the ANY.RUN simulation, firstly the virus established connection to the CnC server;
  • After this, a malicious executable file, in this analysis's case pretending to be a .png is being dropped or overwritten and executed;
  • Then, FormBook proceeds to steal the personal data and change the autorun value in the registry. Also, the virus loads DLL from Mozilla Firefox creates files in the user directory, and starts CMD.EXE to set up persistence and later begin process injection;
  • Finally, injected Firefox.exe is executed for logging keystrokes, stealing clipboard data, and extracting authentication information from browser HTTP sessions.

Distribution of the FormBook stealer

According to FormBook analysis, malware is usually distributed via email campaigns that utilized a wide array of infecting mechanisms and can contain a number of various file attachments. Among the most commonly observed attachments are either PDFs, DOC or EXE, or ZIP, RAR, ACE, and ISO files.

Campaigns in which the virus is distributed through files with PDF extensions are known to utilize shipping-related themes and usually include a download link that points at the malicious code instead of the actual virus. DOC and EXE campaigns utilize macros to install and run the virus. Often, the virus is retrieved as a .PDF file in such a case. Finally, archive campaigns are considered to be the most common attack vector for this virus and usually revolve around a business-related theme, such as a payment order. In the case of this attack vector, attachments either contain a link to the FormBook stealer EXE file or install and run the virus on victims' PCs directly.

In 2020 Formbook has become quite popular as it used Covid-themed emails for decoys with subject headings such as “Government Response to Coronavirus Covid-19”.

FormBook execution process

Sandbox simulation performed on the ANY.RUN interactive malware hunting service allows us to detect and investigate the behavior of FormBook in a lot of detail.

text report of the formbook malware analysis

Figure 2: A text report generated by ANY.RUN

After downloading the malicious file the only thing needed to start the contamination is for the file to be opened. In a case when Microsoft Office file (doc, xls, rtf) is used as an infection source, after it is opened the malware exploits the CVE-2017-11882 vulnerability, thus Microsoft Office Equation Editor proceeds to download a malicious executable file and run it.

After infecting the victim's PC, the virus copies and renames itself into a directory that differs based on the privileges of the user. If an admin account is used, the virus installs itself in either %ProgramFiles% or %CommonProgramFiles%. On the other hand, if the privileges are not elevated, then the virus will copy itself into %TEMP% or %APPDATA.

Also, Formbook trojan changes the autorun value in the registry depending on is it was running with normal or elevated privileges. Next, the malware copies itself into a directory it proceeds to check if it’s being run on a virtual machine or analyzed, evaluating the best anti-evasion option that can be utilized in a particular situation. Meanwhile, the virus will try to evaluate the USERNAME environment variable to find out if it’s launched in simulation, while also checking for the presence of debuggers. It should be noted that the malware uses particularly clever techniques while performing an analysis, for example, all shared strings such as command server names are decoded only briefly if they are absolutely required, which makes FormBook highly elusive. In the next step, the virus uses the same injection method to an active explorer.exe process which is only employed as a non-permanent staging ground.

The virus occasionally performs injections into web browser processes and explorer.exe. After injecting into the process, the virus chooses a random application from a static list. Then, the virus proceeds to run the chosen application in suspended mode and copy itself in the address space of the suspended process, thus mimicking a genuine Microsoft process. Next, the virus exits the original process which leaves FormBook's dead code in explorer.exe as a result. From this stage, new FormBook processes can inject targeted applications like web browser processes, which in the case of this particular ANY.RUN simulation is Firefox.

Depending on the objective process, the virus can establish various function hooks. Being run from inside the context of an already generated process, the virus starts to go through every currently active process, trying to identify targeted programs. As soon as a target is found, FormBook will inject itself into it and install a particular set of API hooks, that are based on the target program. The data is then saved in files in the %APPDATA% directory until it is sent to the C&C server. Pay attention to this function to detect malware.

How to avoid infection by FormBook?

The best counteraction technique is to exhibit caution when receiving emails with attachments from unknown senders. Attackers usually use social engineering to trick victims into downloading and opening infected files.

Deleting any suspicious emails from the inbox is a good way to stay safe. If the infection is already detected, a good practice is to carry out an analysis of all devices connected to the network for established CnC or potentially malicious URL connections. Once a suspicious email is received, perimeter settings can be adjusted to block all related emails in the future. Finally, if an infected file is already downloaded, the host should be quarantined until the threat is completely mitigated.

How to detect Formbook using ANY.RUN?

Formbook trojan usually injects into explorer.exe and another processes from the list, such as firefox.exe and msiexec.exe. Knowing this malware's function you can take a look at the process tree after a while during execution and easily determine either the sample is Formbook or not.

formbook execution process tree Figure 3: A tree of processes created by Formbook during its execution

Conclusion

Thanks to extreme ease of use and low cost, FormBook is gaining traction in the criminal community. Not only is the virus's functionality freely accessible for download on open hacker forums and easy to set up without any programming knowledge, but it also comes equipped with some highly advanced anti-evasion techniques, that make detecting it with anti-virus software ultra-difficult. ANY.RUN interactive malware hunting service enables to study FormBook in detail from a secure environment and implement cybersecurity measures accordingly.

HAVE A LOOK AT

Xeno RAT screenshot
Xeno RAT
xenorat
Xeno RAT is an open-source malware mainly distributed through drive-by downloads. The core capabilities of this threat include remote control, keystroke logging, webcam and microphone access. Equipped with advanced utilities, such as Hidden Virtual Network Computing and Socks5 reverse proxy, Xeno RAT is most frequently used in attacks against individual users.
Read More
SVCStealer screenshot
SVCStealer
svcstealer
SVCStealer is an information-stealing malware targeting sensitive user data through spear-phishing email attachments. It systematically extracts credentials, financial data, and system information from various applications, including browsers and messaging platforms.
Read More
Mamba 2FA screenshot
Mamba 2FA
mamba
Mamba 2FA is an advanced phishing-as-a-service (PhaaS) platform designed to bypass multi-factor authentication (MFA) and target Microsoft 365 accounts. It focuses on intercepting authentication flows in real-time and enables threat actors to hijack user sessions and access sensitive systems even when additional security measures are in place.
Read More
AsyncRAT screenshot
AsyncRAT
asyncrat
AsyncRAT is a RAT that can monitor and remotely control infected systems. This malware was introduced on Github as a legitimate open-source remote administration software, but hackers use it for its many powerful malicious functions.
Read More
Backdoor screenshot
Backdoor
backdoor
A backdoor is a type of cybersecurity threat that allows attackers to secretly compromise a system and conduct malicious activities, such as stealing data and modifying files. Backdoors can be difficult to detect, as they often use legitimate system applications to evade defense mechanisms. Threat actors often utilize special malware, such as PlugX, to establish backdoors on target devices.
Read More
CastleLoader screenshot
CastleLoader
castleloader
CastleLoader is a modern malware loader designed to quietly establish initial access and deliver follow-up payloads such as stealers, RATs, and ransomware. It focuses on stealth, flexibility, and rapid payload rotation, making it an effective tool for financially motivated threat actors and a persistent problem for enterprise defenders.
Read More