87130921-60-20220830152356.webstarterz.com: an open folder serving Formbook and XWorm PowerShell scripts, and what to do if one ran
87130921-60-20220830152356.webstarterz.com is a subdomain that URLhaus lists six times in September and October 2026 for PowerShell scripts (crypted.ps1, secured_stub.ps1) and a compressed JavaScript lure named like a parts inquiry. Two scripts are tagged Formbook, one XWorm, and two were still online on 8 October 2026.
A script on a server does nothing until a lure on a Windows PC runs it. If you only saw the name, nothing is proven. If you opened such a file, change your passwords from another device, then scan and clean or reset Windows.
Facts checked October 8, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
If a script or attachment that downloads PowerShell files from this webstarterz.com address keeps coming back after uninstalling, a scan can find what reinstalls it.
Do it yourself · free Remove 87130921-60-20220830152356.webstarterz.com (Formbook, XWorm, PowerShell scripts) yourself 5 steps, about 15 minutes, no software needed.
Start the steps
87130921-60-20220830152356.webstarterz.com (Formbook, XWorm, PowerShell scripts): summary
| Type | A malware download host: an open folder with PowerShell scripts tagged Formbook and XWorm and a compressed JavaScript lure |
|---|---|
| Risk | High if the lure or a script ran on your PC: passwords and accounts should be treated as stolen. Low if you only saw the name |
| Symptoms | Often none. Microsoft lists slow performance, changed files and freezing for Formbook; an opened .js or .js.xz attachment is the clearest sign |
| How to get rid of it | Change passwords from another device, run Microsoft Defender Offline, remove startup entries, and reset Windows if you are not sure |
| Our check (8 October 2026) | One plain request: HTTP 200, an Apache page titled Index of /, an open folder listing |
| Running since / first seen | Parent domain registered 21 July 2015; first files reported 9 September 2026, newest 1 October 2026; 2 of 6 online on 8 October |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 9 more facts
| Platform | Windows. Nothing we read says Mac or phones are affected |
|---|---|
| Detection names | No detection name is known for these exact files. Microsoft detects the family as Trojan:Win32/Formbook |
| Name | 87130921-60-20220830152356.webstarterz.com |
| Domain registered | 21 July 2015 |
| Evidence | 6 write-ups by security sites; details still limited |
| First seen | 9 September 2026 |
| Distribution | Typically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps |
| Damage | Installs other malware, often several programs at once |
| Facts checked | 8 October 2026 |
Facts checked on 8 October 2026 against the URLhaus data held in our database, RDAP for webstarterz.com, one plain request from our server (no browser), and pages by Microsoft, Malpedia and Seqrite Labs. We did not download or run the files and infected no PC; the removal steps follow Microsoft's pages and were not tried on a live infection.
What this webstarterz.com address is, and what we know about it
87130921-60-20220830152356.webstarterz.com is not a program on your PC. It is a web address on a subdomain of webstarterz.com that URLhaus lists six times, on 9 September and 1 October 2026, for PowerShell scripts and one compressed JavaScript file. Two scripts are tagged Formbook and one XWorm. Two addresses were still online in our copy of the data on 8 October 2026.
The long name looks generated:
- a number
- a short number and what reads like a date and time
- 30 August 2022 at 15:23:56
That pattern suggests an account or site created automatically on a hosting or site builder service, not a name someone chose. This is our reading of the name; we found no page that explains it, and webstarterz.com itself did not resolve when our reading tool tried it.
- 1
What URLhaus lists
Six file addresses on this host. Three were added on 9 September 2026 at about 18:31 UTC: crypted.ps1 at the top, vic/crypted.ps1, and a file in new/vvv named Alloy, Parts inquiry, ending in .js.xz. Three were added on 1 October at about 15:11 UTC: vic/crypted.ps1 again over plain http, secured_stub.ps1 and new/secured_stub.ps1.
- 2
What the tags mean
ps1 and powershell mean a Windows PowerShell script. ascii means plain text. xz is a compression format. opendir means the folder could be listed by anyone. Formbook names a Windows malware family that Microsoft detects as Trojan:Win32/Formbook. XWorm names a remote access trojan; it is tagged on the oldest crypted.ps1 only.
- 3
What we could not confirm
We did not download or run any file, so we cannot tell you which build of Formbook or XWorm the scripts deliver, or where they send data. URLhaus shows tags, not a full analysis. We also do not know who controls this account or whether the host company knows.
- 4
What this means for you
If you only saw the address in a log or a warning, you are not infected by that alone. The risk is for a Windows PC where someone opened the lure file or where a script already running fetched one of these PowerShell files.
- Kind of threat
- A web folder that serves PowerShell scripts tagged Formbook and XWorm, plus a compressed JavaScript lure
- Where the files are
- hxxp://87130921-60-20220830152356[.]webstarterz[.]com/secured_stub.ps1 and /new/secured_stub.ps1 (online on 8 October 2026); older files in /vic/ and /new/vvv/
- Parent domain
- webstarterz.com, registered 21 July 2015 through GMO Internet Group, Inc. d/b/a Onamae.com, status client transfer prohibited (RDAP, read 8 October 2026)
- URLhaus entries
- 6 file addresses, added 9 September and 1 October 2026; 2 online, 4 offline in our copy of the data
- Lure file
- A compressed .js file named like a business request for parts, a typical email attachment disguise (our reading of the name)
- Platform
- Windows. PowerShell and the Formbook and XWorm families are Windows threats; nothing we read points to Mac or phones
What 87130921-60-20220830152356.webstarterz.com (Formbook, XWorm, PowerShell scripts) does on an infected PC
What we checked on 8 October 2026, and what we could not
We sent one plain request to 87130921-60-20220830152356.webstarterz.com from our server on 8 October 2026: no browser, no clicks, no file downloads. The server answered HTTP 200 with a page titled Index of /, served by Apache. That title is what an open folder listing looks like, which matches the opendir tag in URLhaus.
Our check, 8 October 2026
- An open folder listingThe top of the host answered with a page titled Index of /. Anyone can see which files and folders sit there. We did not open the folders or download anything.
- What a plain request cannot seeWe did not run any script and did not test the file addresses themselves. An answer from the server says nothing about what the scripts do.
- Notification requestOur tool found no browser notification request in the answer. A folder listing has no reason to ask for one.
- URLhaus listingSix PowerShell and JavaScript files; two tagged Formbook and online, one tagged XWorm.
- Parent domainOur web reading tool could not resolve webstarterz.com itself on 8 October 2026, so we could not read the service's own page or its abuse contact.
Dangerous: treat it as a malware download host The rating comes from the six URLhaus reports, the two files still online and the open folder we saw. Do not open files from this address, and do not run anything that fetches them.
What happened at this address, from the account name to our check
The parent domain is eleven years old and the account name hints at 2022, but every report falls in September and October 2026. The dates come from RDAP and from the URLhaus data we hold; the times are UTC.
21 July 2015
webstarterz.com is registered
RDAP shows the parent domain registered through GMO Internet Group, Inc. d/b/a Onamae.com, a Japanese registrar. RDAP says nothing about the subdomain.
30 August 2022
A date inside the name
The subdomain contains 20220830152356, which reads as 30 August 2022, 15:23:56. If that is a creation time, the account is about four years old. This is our reading, not a fact we could check.
9 September 2026
Three files are reported
At about 18:31 UTC abuse.ch adds crypted.ps1 (tagged xworm), vic/crypted.ps1 and the lure new/vvv/Alloy, Parts inquiry.js.xz, all tagged opendir. All three are offline by our check.
1 October 2026
Three more, two tagged Formbook
At about 15:11 UTC abuse.ch adds vic/crypted.ps1 over http, secured_stub.ps1 and new/secured_stub.ps1. The two secured_stub.ps1 files are tagged Formbook and are still online on 8 October.

All six URLhaus entries as we read them on 8 October 2026. Two Formbook scripts are still online. 8 October 2026
Our check
Our plain request gets an Apache page titled Index of /. The folder is still open.
What the pattern suggests, and what it does not: the operator came back after three weeks and placed new scripts beside the old ones, with names like crypted and secured_stub. That looks like an active, reused account rather than a single upload. It is our reading of the dates, not something any report says.
How a script on this host reaches a PC
A PowerShell file on a web server cannot run on your PC by itself. Something on the PC has to open the lure or fetch the script. We did not run these files; the chain below joins the file names and tags with what Seqrite describes for script loaders in another campaign.

- 1
The lure arrives
The file Alloy, Parts inquiry.js.xz is named like a request from a supplier. Compressing a script in .xz hides its real type from a quick look and from some mail filters. That a person received it by email is our reading of the name; URLhaus does not say how it was sent.
- 2
The script runs
Inside the .xz archive is a .js file. On Windows a .js file opened from File Explorer is run as a script rather than shown as text. That is why the file ending matters more than the name before it.
- 3
PowerShell fetches the next part
Seqrite describes the same shape in another campaign: a script decodes a PowerShell command, and PowerShell downloads the next stage from a web address. The crypted.ps1 and secured_stub.ps1 files on this host are the kind of file such a command fetches.
- 4
The final malware is hidden in a genuine program
In Seqrite's chain the last stage is injected into a genuine Windows program such as msbuild.exe through process hollowing. Malpedia says FormBook carries its own crypter with RunPE behaviour, a related way to run code inside another process.
- 5
The malware sends data out
Microsoft says Trojan:Win32/Formbook can perform actions of a malicious actor's choice on the device. Which data this build collects is not known to us.
What Formbook and XWorm are, as far as our sources go
We read two reference pages on Formbook for this guide. They confirm the family and how Microsoft detects it, but they do not list its features. We do not repeat lists from pages we did not read.
| Question | What the sources say | Source |
|---|---|---|
| What is Formbook? | A Windows trojan that Microsoft Defender detects as Trojan:Win32/Formbook, published 7 January 2019 | Microsoft |
| What can it do? | Microsoft says it can perform a number of actions of a malicious actor's choice on the device; its technical details section is empty | Microsoft |
| How does it hide? | Malpedia says it contains a unique crypter with RunPE behaviour and was first called Babushka Crypter | Malpedia |
| Other names | Malpedia lists XLoader (win.xloader) as an alias | Malpedia |
| Signs on a PC | Slow performance, added or changed files, changed desktop settings, freezing or crashing, less free disk space | Microsoft |
| What is XWorm? | URLhaus tags one older script xworm, a remote access trojan name. We read no reference page on XWorm for this guide | Not available |
| Which builds are here? | Not known. We did not open the files | Not available |
What 87130921-60-20220830152356.webstarterz.com (Formbook, XWorm, PowerShell scripts) can steal or download
What this can cost you
Seeing this address in a log costs nothing. The risks below apply to a Windows PC where the lure was opened or a script from this host ran. They follow from the tags, not from a test of these files.
- High
Passwords and accounts
Formbook is tagged on the two live scripts, and the name stands for a family vendors classify as a stealer. Treat every password typed or saved on the PC as known, and change them from another device.
- High
Someone using your PC
XWorm is tagged on one older script. If it ran, a remote access trojan lets a stranger use the PC while you are signed in.
- Medium
Business email and payments
A lure about a parts inquiry is aimed at people who handle orders. A stolen work mailbox can be used to send fake invoices to your customers.
- Medium
More malware on the same PC
A script loader can fetch anything its operator puts on the server, and this server held more than one family.
- Low
Nothing, if you only saw the name
A name in a block list, a log or a warning is not an infection.
What you may notice, and what you may not
Stealers and loaders are made to stay quiet. The signs below come from Microsoft's Formbook entry and from what the files imply; none is certain.
| Sign | What the reports show |
|---|---|
| A file ending in .js.xz or .js that you opened | The lure on this host has that form. If you opened such a file, assume the chain started |
| A PowerShell window that flashed and closed | PowerShell is how the next stage is fetched. A brief window is common; many builds hide it. This is our reading |
| Slow performance, freezing or crashing | Microsoft lists these for Trojan:Win32/Formbook |
| Added or changed files, less free disk space | Microsoft lists these too |
| A Defender detection naming Formbook | Microsoft detects the family as Trojan:Win32/Formbook |
| Accounts you did not touch | Logins from new places, password reset emails or messages sent from your mailbox follow from stolen passwords |
| Nothing at all | The most common result for a working stealer |
How to check the PC for 87130921-60-20220830152356.webstarterz.com (Formbook, XWorm, PowerShell scripts)
If this account or the hosting service is yours
An open folder of scripts on a generated subdomain is typical of a hosting account that was abused or created for abuse. If you run the account or the service, act as if it is in a stranger's hands. This is our advice, not a vendor procedure.
Take the folder listing offline, keep copies of crypted.ps1, secured_stub.ps1 and the .js.xz file for investigators, then remove them. Change the account's passwords and any FTP or deploy keys, look at access logs from early September 2026, and close the account if no customer owns it. After cleaning, ask URLhaus to recheck the listed addresses.
Check your PC before you delete anything
Start with the question that matters: did you open an email attachment about a parts inquiry, or any .js or .js.xz file, around 9 September or 1 October 2026? Or did a firewall or DNS log show a device asking for this address? If yes or not sure, do the checks below. None of them deletes anything.
While you check, stop using the PC for banking, email, work or crypto.
- 1
Disconnect first
Turn off Wi-Fi or unplug the network cable. A stealer sends data out, and a remote access trojan needs the connection to be used.
- 2
Find which device asked for the address
If you came here from a log, a router page or an alert, note the device and the time. Only that device is in question.
- 3
Look at Startup apps
Open Settings > Apps > Startup and look for names you did not install, especially scripts or programs from your user folder. Write them down; do not delete yet.
- 4
Look for genuine programs that should not be running
Open Task Manager and look for PowerShell, msbuild.exe or any process with high network or CPU use for no reason. Seqrite names msbuild.exe as a hiding place in a script loader chain. These are real Windows programs, so their presence is not proof.
- 5
Open Protection history
In Windows Security > Virus & threat protection > Protection history, look for a detection naming Formbook or XWorm, or anything blocked around the dates above. Microsoft says offline scan results also appear here.
- 6
Check Defender exclusions
In Windows Security > Virus & threat protection > Manage settings > Exclusions, look for folders or file types you did not add. Loaders sometimes add exclusions so they are not scanned. We have no source saying these scripts do that, so a clean list does not clear the PC.
- 7
Check your accounts from another device
Look at the sign in activity of your email, bank and work accounts, and at the sent folder of your mailbox. This is quicker than any file check.
- 8
A scan helps, but it does not clear the PC
Microsoft notes that even after Defender removes Formbook, remnant files and system changes can remain, and says to run a full scan with updated definitions. We did not infect a PC, so this plan is our judgement from Microsoft's pages, not a tested result.
How to remove 87130921-60-20220830152356.webstarterz.com (Formbook, XWorm, PowerShell scripts)
How to remove 87130921-60-20220830152356.webstarterz.com
A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.
Step 1: Delete scheduled tasks that bring it back
Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:
- a task that starts a file in
%AppData%or%Temp% - runs
powershellwith a long encoded line - opens a web address belongs to 87130921-60-20220830152356.webstarterz.com or a similar program
Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs. Full procedure with screenshots: Remove what malware leaves behind in Windows
- a task that starts a file in
Step 2: Remove it from startup
Whatever 87130921-60-20220830152356.webstarterz.com installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.
Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.
Full procedure with screenshots: Stop apps from opening at startup On uGetFix
Step 3: Delete the folders left behind
What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through
%LocalAppData%,%AppData%, %ProgramData% and the two Program Files folders.Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold
.exe,.dll, .js or .ps1 files are the strongest sign.Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 4: Scan the PC, then run the offline scan
Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.
Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 5: Change passwords from another device and sign out other sessions
Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.
Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.
Full procedure with screenshots: Turn on two-step verification / secure a hacked account
If you use a Mac, an iPhone or an Android phone
The files are PowerShell scripts and a JavaScript lure for Windows, and both tagged families are Windows malware. We found nothing that says they affect anything else.
| Your device | What we know | What to do |
|---|---|---|
| Mac | Microsoft and Malpedia describe Formbook as Windows malware; PowerShell lures target Windows | Nothing to remove for this threat. Do not follow the Windows steps on a Mac |
| iPhone or iPad | No source we read mentions these files on iOS | Nothing to remove. If you typed a password into a page from the email, change it |
| Android | No source we read mentions it | Nothing to remove for this threat; change passwords if you entered any |
After removal: passwords, accounts and prevention
After a clean PC: protect what was taken
A stealer sends what it finds within minutes, so cleaning the PC does not undo the theft. Accounts first, from another device, then the PC.

- 1
Change passwords from a clean device
Use your phone or another computer. Start with email, because it resets everything else, then bank, work systems, cloud storage and any shop or supplier portals. Passwords saved in the browser on that PC count as known.
- 2
Sign out other sessions and turn on two step sign in
Most email and bank accounts let you sign out of all devices and add a second step at sign in. Do both, and check that the recovery email, phone and mail forwarding rules are still yours.
- 3
Warn your customers and suppliers
If your work mailbox may be stolen, tell regular contacts that you will never change bank details by email. Fake invoices from a real mailbox are the usual next step.
- 4
Run Microsoft Defender Offline
Microsoft says to open Windows Security > Virus & threat protection > Scan options, choose Microsoft Defender Offline scan and select Scan now. Save your work first: Windows signs you out and the scan takes about 15 minutes outside the normal Windows. Results are under Protection history. If BitLocker is on, suspend it first.
- 5
Remove what the check found, with care
If Startup apps, Task Manager or the exclusions list showed an entry you can tie to the malware, remove it and the file it points to. If you cannot tell, do not guess: the safe answer is the reset below.
- 6
If you are not sure, reset Windows
In Windows 11 the reset sits at Settings > System > Recovery > Reset this PC. Microsoft says keeping personal files removes apps and settings, and removing everything also deletes your files. Microsoft calls the reset the most disruptive option and says to back up first.
- 7
Restore only documents by hand
Copy back documents and photos, not programs and not scripts. Delete the .js.xz attachment and any copy of it in Downloads or in your mail program.
- 8
Watch your money and your accounts
Check card statements and payment logs for a few weeks, turn on alerts, and look at your mailbox rules for forwarding you did not set.
Keep a PC out of this kind of chain
The script on this host is the second step. The first is a file a person opened, so that is where the defence is strongest.
Do
- Show file endings in File Explorer, so a file named like an inquiry but ending in .js stands out.
- Treat any .js, .vbs, .hta or .ps1 attachment as an attack, compressed or not.
- Ask a sender through a known phone number when a request for quotes or parts comes from someone new.
- Keep Windows and Microsoft Defender updated.
- Use a password manager and two step sign in, so one stolen password is not enough.
- Keep a backup of documents on a disk that you unplug.
Don't
- Do not open archives such as .xz, .zip or .rar from unexpected senders to see what is inside.
- Do not save passwords in the browser on a shared or work PC that handles email attachments.
- Do not change your passwords on the PC you suspect.
- Do not rely on a quiet scan to say that you are safe.
Questions about 87130921-60-20220830152356.webstarterz.com (Formbook, XWorm, PowerShell scripts)
What is 87130921-60-20220830152356.webstarterz.com?
It is a subdomain of webstarterz.com that URLhaus lists for six files: PowerShell scripts named crypted.ps1 and secured_stub.ps1 and a compressed JavaScript file named like a parts inquiry.
Two scripts are tagged Formbook and one XWorm. Two were still online on 8 October 2026, and the host showed an open folder listing. It is not a program on your PC.
Is this address safe to open?
No. Do not open it or download files from it. Our plain request on 8 October 2026 got an Apache page titled Index of /, an open folder.
The danger rating comes from the six URLhaus reports and the two Formbook scripts still online. A quiet or empty page later would not clear it either, because the files can come back under new names.
I opened Alloy, Parts inquiry.js.xz. What now?
Assume the chain started. Disconnect the PC, change your email and other passwords from another device, then run a Microsoft Defender Offline scan and check Startup apps, Task Manager, Protection history and Defender exclusions. If you cannot tie what you find to the malware, reset Windows with Remove everything and restore only documents.
What is Formbook?
Microsoft detects it as Trojan:Win32/Formbook and says it can perform actions of a malicious actor's choice on a device. Malpedia says it carries its own crypter with RunPE behaviour, was first called Babushka Crypter and lists XLoader as an alias. The pages we read do not list its features, so we treat every password on an affected PC as stolen.
What is XWorm?
XWorm is the name of a remote access trojan family. URLhaus tags only the oldest crypted.ps1 on this host with it, and that file is offline.
We read no reference page on XWorm for this guide, so we do not list its features here. If a Defender detection on your PC names XWorm, follow the same plan as for Formbook.
I saw this address in my firewall or DNS log. Am I infected?
Not necessarily. It means a device on your network asked for it, and a person does not usually type such a name. Find the device, disconnect it, and do the checks on this page.
Change account passwords from another device. If the log shows a request for a .ps1 file, treat that device as infected until checked, and run a Microsoft Defender Offline scan on it.
How do I remove Formbook from Windows?
Change your passwords from another device first. Then run a Microsoft Defender Offline scan from Windows Security, Virus and threat protection, Scan options, followed by a full scan with updated definitions as Microsoft advises.
Remove startup entries you can tie to the malware. If you are not sure, reset Windows. We did not test this on an infected PC.
What is webstarterz.com, and is the whole domain malicious?
RDAP shows webstarterz.com registered on 21 July 2015 through a Japanese registrar. The long generated subdomain looks like one account on a hosting or site builder service; that is our reading.
URLhaus lists this one subdomain. We could not read the service's own page, so we cannot say anything about other accounts on it.
Does this affect Mac, iPhone or Android?
We found nothing that says so. The files are PowerShell scripts and a JavaScript lure for Windows, and Formbook is Windows malware.
On a Mac or a phone there is nothing to remove; if you typed a password into a page from the email, change it. Forward the email to your IT team or delete it.
Will Fortect remove 87130921-60-20220830152356.webstarterz.com?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For 87130921-60-20220830152356.webstarterz.com, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- Microsoft Security Intelligence: Trojan:Win32/Formbook (published 7 January 2019) (read October 8, 2026)
- Malpedia (Fraunhofer FKIE): FormBook, win.formbook (read October 8, 2026)
- Seqrite Labs: New Steganographic Campaign Distributing Multiple Malware (17 March 2025; a different campaign, used for how script and PowerShell loaders work) (read October 8, 2026)
- Microsoft Learn: Microsoft Defender Offline scan in Windows (updated 25 August 2026) (read October 8, 2026)
- Microsoft Support: Recovery options in Windows (Reset this PC) (read October 8, 2026)