Trojan

Trojan:MSIL/Formbook.VC!MTB (file analysis)

Malware Removal

The Trojan:MSIL/Formbook.VC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Formbook.VC!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the Formbook malware family
  • CAPE detected injection into a browser process, likely for Man-In-Browser (MITB) infostealing
  • Harvests cookies for information gathering
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:MSIL/Formbook.VC!MTB?


File Info:

name: 4CC70823820A4C89F88A.mlw
path: /opt/CAPEv2/storage/binaries/1fba5d3c9b01df4ba0f4b644d3eb1a35d1aeb5bc945cdbba4262fc414e184aa1
crc32: 20FDF84B
md5: 4cc70823820a4c89f88a42aa77599cb7
sha1: a144f7cffaeb5d3871712a9b267a519431b6f24d
sha256: 1fba5d3c9b01df4ba0f4b644d3eb1a35d1aeb5bc945cdbba4262fc414e184aa1
sha512: 02950476c44bf4f2a54934bb22b4706af46960f80b1da3a00ddb5dfca0a24ccb629e48036a98db85b14a20bd45ed0431283f3e10e12bac78de1704b419b46ce7
ssdeep: 6144:y3lgHzMl0ZrzV0/Q3GmQZ6w/zCGDalyPXn9xxsHB:y3lEgl+rqsGIw/jFf9xWh
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T11074E103B4C8CCB0E053227EE928DE63AD7EFD6662724167B6D4721DBAB02814977353
sha3_384: 113593f7c3e02d1bbcb20843a83d8260076ec11b4eab435e642bf149c4599b9b4e1b44b329a21b698a32c0c5dd8ee613
ep_bytes: e848350000e987feffffcccc57568b74
timestamp: 2020-07-23 17:23:04

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Office Word
FileVersion: 12.0.4518.1014
InternalName: WinWord
LegalCopyright: © 2006 Microsoft Corporation. All rights reserved.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: WinWord.exe
ProductName: 2007 Microsoft Office system
ProductVersion: 12.0.4518.1014
Translation: 0x0000 0x04e4

Trojan:MSIL/Formbook.VC!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Inject.4!c
MicroWorld-eScanGen:Variant.Zusy.379034
FireEyeGeneric.mg.4cc70823820a4c89
ALYacGen:Variant.Zusy.379034
MalwarebytesMalware.AI.2044784445
ZillyaTrojan.Inject.Win32.304876
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:MSIL/Formbook.13da65b8
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HFCU
APEXMalicious
ClamAVWin.Dropper.Formbook-9164797-0
KasperskyTrojan.Win32.Inject.andyt
BitDefenderGen:Variant.Zusy.379034
NANO-AntivirusTrojan.Win32.Inject.hpbpip
AvastWin32:Malware-gen
TencentWin32.Trojan.FalseSign.Anhl
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.Agent.btnqx
DrWebTrojan.Siggen10.13997
VIPREGen:Variant.Zusy.379034
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Zusy.379034 (B)
IkarusTrojan.Win32.Formbook
GDataGen:Variant.Zusy.379034
AviraTR/Crypt.Agent.btnqx
XcitiumMalware@#3ikdi9eyhqaj4
ArcabitTrojan.Zusy.D5C89A
ZoneAlarmTrojan.Win32.Inject.andyt
MicrosoftTrojan:MSIL/Formbook.VC!MTB
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Inject.R437701
McAfeeArtemis!4CC70823820A
MAXmalware (ai score=83)
VBA32Trojan.MSIL.Formbook
Cylanceunsafe
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.C940 (CLASSIC)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.104312370.susgen
FortinetW32/Inject.ANDYT!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Trojan:MSIL/Formbook.VC!MTB?

Trojan:MSIL/Formbook.VC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment