Concrete signature match: Trojan - Appears legitimate but performs malicious actions for .NET (Microsoft Intermediate Language) platform, family FormBook
This is a detection for the FormBook infostealer trojan, a common malware family designed to steal sensitive information. The threat was delivered via a malicious document that used PowerShell to execute its payload, enabling it to steal credentials from browsers, capture keystrokes, and exfiltrate data.
No detailed analysis available from definition files.
e4ec8eb8a0729479977a73c132dd2bdf4dac30483c590f3dd29af60e48ce0ebbImmediately isolate the affected machine from the network. Use antivirus to perform a full scan and remove all detected components. Since FormBook is an infostealer, reset all passwords for the user account and any credentials stored on the system. Investigate the initial access vector, likely a phishing email with a malicious attachment, and delete it.