www.tmcksa.com: a hacked site serving a PowerShell stub for the Formbook stealer, and what to do if your PC ran it

www.tmcksa.com is a website registered in 2013 that URLhaus listed three times on 5 October 2026 for a PowerShell script, secured_stub.ps1, tagged Formbook. Formbook is a Windows information stealer that takes passwords, keystrokes and cookies.

Visiting the home page does not run the script: it is fetched by a file someone already opened, usually an email attachment. If you only saw the name, nothing is proven. If your PC may have run it, change your passwords from another device, then scan and clean or reset Windows.

Facts checked October 6, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

If a script or attachment that downloads secured_stub.ps1 from www.tmcksa.com keeps coming back after uninstalling, a scan can find what reinstalls it.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove www.tmcksa.com (Formbook, PowerShell stub) yourself 5 steps, about 15 minutes, no software needed.

Start the steps
Three cards for the URLhaus entries of www.tmcksa.com: secured_stub.ps1 in the folders news, new and new1, tagged Formbook and powershell
The three URLhaus entries for www.tmcksa.com that we read on 6 October 2026. There is no browser screenshot: our check was a plain request from our server, which got a 301 redirect to new.tmcksa.com.

Www.tmcksa.com (Formbook, PowerShell stub): summary

TypeA hacked website, by our reading: URLhaus lists three PowerShell scripts on it tagged Formbook, an information stealer for Windows
RiskHigh if your PC ran the script: passwords, keystrokes and cookies may be taken. Low if you only saw the name or opened the home page
SymptomsOften none. A flashing PowerShell window after opening an attachment, unknown startup entries or tasks, log-in alerts
How to get rid of itChange passwords from another device, run Microsoft Defender Offline, remove unknown startup entries, reset Windows if unsure
Our check (6 October 2026)One plain request from our server: 301 redirect to new.tmcksa.com. A working home page clears nothing; the files were still listed online
Running since / first seenDomain registered 18 July 2013; malware files first reported 5 October 2026
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 9 more facts
PlatformWindows. Mac and phones cannot run the listed PowerShell file
Detection namesMicrosoft uses Trojan:Win32/Formbook for the family. No name is known for this exact script, because we did not open it
NameWww.tmcksa.com
Domain registered18 July 2013
Evidence3 write-ups by security sites; details still limited
First seen5 October 2026
DistributionTypically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps
DamageInstalls other malware, often several programs at once
Facts checked6 October 2026

Facts checked on 6 October 2026 against the URLhaus data for www.tmcksa.com held in our database, RDAP, one plain request from our server, and published material from MITRE ATT&CK, Acronis, Microsoft and the FTC. We did not download the files and infected no PC; the removal steps follow Microsoft's pages and were not tried on a live infection.

What www.tmcksa.com is, and what we know about it

www.tmcksa.com is the address of a website that has been registered since 2013. On 5 October 2026 URLhaus, the malware tracking project of abuse.ch, listed three files on it, all named secured_stub.ps1 and tagged Formbook and powershell. An old domain with a working home page and malware files in side folders is the usual picture of a legitimate site that was broken into. We found no public write-up about this address, so what follows is the URLhaus data, our own plain request and what researchers have published about Formbook.

  1. 1

    What URLhaus lists

    Three files in three folders: /news/, /new/ and /new1/, each holding secured_stub.ps1. They were added on 5 October 2026 at 09:28, 09:31 and 09:53 UTC. All are labelled malware_download, all were reported by abuse_ch, and all were still marked online when we read the data on 6 October 2026.

  2. 2

    What the tags mean

    ps1 is the file ending of a PowerShell script, the scripting tool built into Windows. ascii means the file is plain text. Formbook is the name of an information stealer for Windows, also sold under the name XLoader since October 2020.

  3. 3

    What the file name suggests

    A stub is a small first piece of code whose job is to unpack or fetch the real program. Secured is a word attackers use to make a file look trustworthy. Our reading is that secured_stub.ps1 is a loader that starts Formbook; we did not open the file to confirm it.

  4. 4

    Who owns the site

    RDAP shows tmcksa.com registered on 18 July 2013 through Launchpad.com Inc., status active. Our plain request was sent on to new.tmcksa.com, which looks like a site being rebuilt or moved. We found nothing that says the owner placed the files there, and we do not suggest it.

Three cards for the URLhaus entries of www.tmcksa.com: secured_stub.ps1 in the folders news, new and new1, added on 5 October 2026 and tagged ascii, Formbook, powershell and ps1
Our summary of the three URLhaus entries for www.tmcksa.com, read on 6 October 2026. All three were still marked online.

What www.tmcksa.com (Formbook, PowerShell stub) does on an infected PC

What we checked on 6 October 2026, and what we could not

We sent one plain request from our server to the home page, with no browser and no clicks. It answered 301 Moved Permanently and pointed to hxxps://new.tmcksa[.]com/, from an nginx 1.29.8 server. That clears nothing: the reported files sit in other folders, and a working home page is normal for a hacked site.

www.tmcksa.com · plain request and data check · 6 October 2026

  • The home pageHTTP status 301, a permanent move to new.tmcksa.com. We did not follow it with a browser and did not test the new address.
  • RegistrationRegistered 18 July 2013 through Launchpad.com Inc., status active, according to RDAP. An address this old is rarely set up just for malware.
  • Notification or pop-up tricksNone in the plain answer. The risk here is a script file, not a browser scam.
  • The script filesWe did not download or run secured_stub.ps1. What it does comes from the URLhaus tags, not from our analysis.
  • Public researchWe found no write-up about www.tmcksa.com. The chain below is how researchers describe Formbook delivery in general.

Dangerous if a PC ran the script A Windows PC that ran secured_stub.ps1 should be treated as infected with an information stealer, and its passwords as taken.

What happened to www.tmcksa.com, from registration to our test

The domain is thirteen years old; the reports all fall within half an hour on one morning. The dates come from RDAP, URLhaus and our own request, in UTC.

  1. 18 July 2013

    The domain is registered

    RDAP shows tmcksa.com registered through Launchpad.com Inc. It has stayed active since.

  2. 5 October 2026, 09:28

    The first file is reported

    abuse_ch adds hxxps://www.tmcksa[.]com/news/secured_stub.ps1 to URLhaus with the tags ascii, Formbook, powershell and ps1.

  3. 5 October 2026, 09:31

    A second copy

    The same file name in the folder /new/ is added three minutes later, with the same tags.

  4. 5 October 2026, 09:53

    A third copy

    The folder /new1/ follows. Three folders with near identical names look like an attacker keeping spare copies in case one is removed. That is our reading.

  5. 6 October 2026

    Our check

    All three entries are still marked online. The home page answers 301 and points to new.tmcksa.com.

How a PowerShell stub on a hacked site leads to Formbook

Nobody gets Formbook by visiting www.tmcksa.com. The script is fetched by something already running on a PC, most often a file that came by email. We did not see the chain for this site; this is how MITRE ATT&CK, Acronis and the sandbox reports describe Formbook delivery.

Four steps: an email attachment, PowerShell fetching secured_stub.ps1 from a hacked site, Formbook running in memory inside a trusted Windows program, and data leaving the PC
The usual Formbook chain as vendors describe it. The first step for www.tmcksa.com is not known.
  1. 1

    An attachment is opened

    MITRE ATT&CK (XLoader, S1207, modified 11 March 2025) says the malware is mainly delivered by phishing email with PDF, Office, ZIP, RAR or ISO attachments. Acronis (26 November 2021) names ISO, RAR and XLSX files dressed up as business mail.

  2. 2

    A script fetches the stub

    Recent samples, as the sandbox and vendor reports describe them, start with a JavaScript file that launches PowerShell. PowerShell downloads a script such as secured_stub.ps1 from a web address, often a hacked site that looks harmless to filters.

  3. 3

    The stealer is unpacked in memory

    The script decrypts a .NET program and loads it without writing a normal file to disk. MITRE lists process hollowing: the stealer runs inside a trusted Windows program, so the Task Manager shows a familiar name.

  4. 4

    It stays and steals

    MITRE lists Run keys and scheduled tasks for staying after a restart, then keystrokes, screenshots, clipboard data, cookies and saved passwords sent to the controller over HTTP.

What Formbook is

Formbook is an information stealer for Windows that has been rented out to criminals since 2016. The sources agree on what it takes and differ on details of each version.

Formbook in short. The Mac version is XLoader, not the PowerShell stub listed here.
QuestionWhat the sources saySource
What is it?An information stealer sold as malware as a service, renamed XLoader in October 2020MITRE ATT&CK S1207; Acronis
How old is it?In use since at least 2016MITRE ATT&CK S1207
What does it cost the criminal?Acronis reported $59 a month for the Windows version and $49 for the macOS version of XLoader in 2021Acronis, 26 November 2021
What does it take?Keystrokes, screenshots, clipboard, cookies, and passwords from browsers, email and FTP programsMITRE ATT&CK S1207; Acronis
How does it hide?Process hollowing, anti-debugging and sandbox checks, XOR and RC4 encryptionMITRE ATT&CK S1207
How does it stay?Registry Run keys and scheduled tasksMITRE ATT&CK S1207
What does Microsoft call it?Trojan:Win32/Formbook, an entry first published on 7 January 2019Microsoft Security Intelligence

What www.tmcksa.com (Formbook, PowerShell stub) can steal or download

What Formbook can take from a Windows PC

An information stealer is built to collect logins quickly and send them out. Each item below is named by MITRE ATT&CK or Acronis; not every build does all of them.

Reported as taken

  • Every key you type
  • Screenshots
  • Clipboard contents
  • Saved browser passwords
  • Browser cookies and sessions
  • Email program passwords
  • FTP program passwords
  • Data typed into web forms
  • High

    Email and work accounts

    Email passwords are taken from mail programs and browsers. Whoever reads your mail can reset your other accounts and write to your contacts as you.

  • High

    Bank and shop log-ins

    Form grabbing captures what you type into log-in and payment forms before it is encrypted for sending.

  • High

    Signed in sessions

    Stolen cookies can let someone use an account without the password, until you sign out of all sessions.

  • Medium

    Business mail fraud

    Formbook is usually sent to companies. A stolen business mailbox is a common start for invoice fraud against your customers. That is our reading, not a quote.

What you may notice, and what you may not

Stealers try to stay invisible. Most people notice nothing until an account is misused. The signs below come from the sources and Microsoft's entry.

None of these signs is certain, and the absence of all of them clears nothing.
SignWhat it can mean
A Defender alert naming Formbook, XLoader or a PowerShell downloadMicrosoft blocked part of the chain. Check Protection history for what was found and whether it was removed
A PowerShell window that flashed after you opened an attachmentA script may have run. That is the moment to disconnect
A startup entry or scheduled task you did not createMITRE lists Run keys and scheduled tasks for Formbook
Slow PC, changed files, crashesMicrosoft's entry lists these as general symptoms; they prove nothing on their own
Log-in alerts, password reset mails, mails sent from your accountYour logins may already be in use
Windows Security Protection history page listing recent detections with their date and status
Windows 11 24H2, Windows Security > Protection history: look here for a Formbook or PowerShell detection and its date.

How to check the PC for www.tmcksa.com (Formbook, PowerShell stub)

Who can meet www.tmcksa.com

The script is a Windows PowerShell file. People meet it through a program on their PC, not by browsing. For the site owner the question is different: how the files got onto the server.

Our reading of the file type and tags.
You areWhat it meansWhat to do
Someone who opened an unexpected attachment and then saw this address in an alert or logA script on your PC probably tried to fetch secured_stub.ps1Disconnect and follow the steps on this page
An admin who saw the address in a proxy, DNS or firewall logThe device that asked is the one to checkFind the device and the time, isolate it, check it
A visitor of the company siteOpening the home page does not run a .ps1 fileNothing to remove for that visit
A Mac, iPhone or Android userThe listed file is a Windows PowerShell scriptNothing to remove for this threat
The owner or web host of tmcksa.comYour server is serving malware from three foldersSee the section for site owners below

Check your PC before you delete anything

Start with the question that matters: did you open an unexpected attachment, script or archive around 5 October 2026, or did an alert name this address? If yes or not sure, do these checks. None of them deletes anything.

While you check, stop using the PC for banking, email and work log-ins, as the FTC advises.

  1. 1

    Disconnect first

    Turn off Wi-Fi or unplug the cable. A stealer sends data out over the network.

  2. 2

    Read Protection history

    Open Windows Security > Virus & threat protection > Protection history and look for Formbook, XLoader, PowerShell or a blocked download, with its date.

  3. 3

    Look at Startup apps

    Open Settings > Apps > Startup and note anything you do not recognise. Do not switch it off yet if you want to keep evidence.

  4. 4

    Open Task Scheduler

    Press Start, type Task Scheduler, open Task Scheduler Library and look for tasks with random names or actions that run powershell.exe.

  5. 5

    Find the file you opened

    Look in Downloads and in the mail program for the attachment. Keep it for your IT support; do not open it again.

Windows 11 Settings Apps Startup page with a list of programs and switches
Windows 11 24H2, Settings > Apps > Startup: programs that start at sign-in. Note any you do not recognise.

How to remove www.tmcksa.com (Formbook, PowerShell stub)

How to remove www.tmcksa.com

A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.

  1. Step 1: Delete scheduled tasks that bring it back

    Programs like www.tmcksa.com add a scheduled task so they return after an uninstall or reopen a page at every sign-in. Start Task Scheduler, open Task Scheduler Library and sort by Last Run Time to see what ran recently.

    On the Actions tab, a program in a user folder, a script or a web address is a warning sign; right-click such a task and choose Delete.

    Tasks with names copying Google, Edge or Windows updaters but pointing to an odd folder are typical. The tool looks the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  2. Step 2: Remove it from startup

    Press Ctrl + Shift + Esc to open Task Manager and select Startup apps (Windows 11) or the Startup tab (Windows 10). Disable entries you do not recognise, especially ones with no publisher or with a name that copies a Windows component.

    Right-click an entry and choose Open file location to see where it runs from: programs in %AppData% or %Temp% deserve a closer look. Some entries are not listed there but in the registry Run keys, which the procedure below shows how to check.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  3. Step 3: Delete the folders left behind

    Uninstalling often leaves the program's folders, and some threats reinstall themselves from them.

    Press Windows + R, type %LocalAppData% and press Enter, then do the same for %AppData% and %ProgramData%, and look for folders named after www.tmcksa.com, its publisher or created on the day the problem started. Delete those folders, and check C:\Program Files and C:\Program Files (x86) too.

    If Windows says a file is in use, end it in Task Manager or delete the folder after a restart in Safe Mode. The folders are the same in Windows 11 and Windows 10.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  4. Step 4: Scan the PC, then run the offline scan

    A scan finds the parts of www.tmcksa.com that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.

    Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.

    It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  5. Step 5: Change passwords from another device and sign out other sessions

    Www.tmcksa.com can copy saved passwords, cookies and session tokens and send them out in seconds, so cleaning the PC does not undo the theft.

    Change your passwords on a device that was never infected, starting with the e-mail account, since every other reset goes through it. On each account, end all other sessions and check the recovery e-mail, phone number and forwarding rules.

    Then turn on two-step verification. Sign in on the Windows 11 or Windows 10 PC again only after the offline scan is clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

If you use a Mac, an iPhone or an Android phone

The listed file is a Windows PowerShell script, and every source we read about this delivery chain describes Windows.

Your deviceWhat we knowWhat to do
MacXLoader has a macOS version, but it is not delivered as a .ps1 fileNothing to remove for this address. Do not follow the Windows steps on a Mac
iPhone or iPadNo source describes Formbook on iOSNothing to remove. Change passwords you also used on an infected PC
AndroidNo source mentions itNothing to remove for this threat

After removal: passwords, accounts and prevention

After a clean PC: protect what was taken

Removing the stealer does not take back what it already sent. Change passwords from another device first, then clean the PC.

Five steps in order: disconnect, change passwords on another device, run an offline scan, check startup entries, reset Windows if unsure
The order of actions if a PC may have run secured_stub.ps1, based on Microsoft and FTC advice. We did not test them on an infected PC.
  1. 1

    Change passwords from a clean device

    Start with email, then banking, work, cloud storage and shops. Anything saved in the browser on the infected PC should be treated as known.

  2. 2

    Sign out everywhere and turn on two step sign in

    Signing out of all sessions kills stolen cookies. The FTC advises two factor authentication so a stolen password alone is not enough.

  3. 3

    Run Microsoft Defender Offline

    In Windows Security > Virus & threat protection > Scan options choose Microsoft Defender Antivirus (offline scan) and Scan now. The PC restarts and scans without loading Windows; results appear in Protection history.

  4. 4

    Remove what starts by itself

    Switch off unknown entries in Startup apps and delete the scheduled tasks you tied to the malware.

  5. 5

    Reset if you are not sure

    Use Settings > System > Recovery > Reset this PC with Remove everything, then restore documents from a backup. That is the only way to be sure no piece is left.

  6. 6

    Warn people who may be fooled

    If your work mailbox was used, tell your IT team, your bank and customers who might receive fake invoices in your name.

If you own or host tmcksa.com

The files sit in /news/, /new/ and /new1/ on the www address. Removing them is the easy part; the way the attacker got in is what matters.

  1. 1

    Remove the three files and keep copies

    Delete secured_stub.ps1 from the three folders, but first save copies and the web server logs for the dates around 5 October 2026 for your host or an investigator.

  2. 2

    Find the way in

    Check the hosting control panel, FTP and SSH log-ins, and the content management system and its plug-ins for missing updates. Look for other new files, especially scripts in upload folders.

  3. 3

    Change every password

    Hosting panel, FTP, database, CMS admin and email. Formbook itself steals FTP passwords, so a stolen FTP login is one possible way in. That is our reading, not a finding.

  4. 4

    Check the old and the new site

    The home page now points to new.tmcksa.com. Make sure the old www site was not left running unpatched on the same server.

  5. 5

    Ask for removal from the lists

    Once the files are gone, URLhaus marks them offline after checking. Browser and mail filters follow the lists.

Keep a PC out of this kind of chain

The script on the hacked site is the middle of the chain. Every report we read starts earlier, with a file a person opened.

Do

  • Treat an unexpected invoice, order or shipping notice with an archive, ISO or script attached as an attack.
  • Show file name extensions in File Explorer so a .js or .ps1 file posing as a document is visible.
  • Keep Windows and Microsoft Defender updated.
  • Use a password manager and two step sign in, so a stolen password alone is not enough.
  • Keep a backup of documents on a disk you unplug.

Don't

  • Do not open attachments from senders you did not expect, even from known companies.
  • Do not save important passwords in a browser on a PC that many people use.
  • Do not change passwords on the PC you suspect.
  • Do not trust a download because the website behind it is old or well known.

Questions about www.tmcksa.com (Formbook, PowerShell stub)

What is www.tmcksa.com?

It is the address of a website registered since 18 July 2013. On 5 October 2026 URLhaus, the abuse.ch malware tracking project, listed three files on it named secured_stub.ps1 in the folders news, new and new1, all tagged Formbook and powershell.

An old site with malware in side folders is usually a hacked site. We did not open the files, so their content is not confirmed by us.

Is www.tmcksa.com safe to open?

Opening the home page does not run a PowerShell script, and on 6 October 2026 the home page only sent us on to new.tmcksa.com.

Do not open the reported folders and do not run any .ps1 file from the address. The three files were still marked online when we checked, so the site is not clean yet, and a quiet home page clears nothing.

What is secured_stub.ps1?

It is a PowerShell script, a plain text file of commands for Windows. URLhaus tags it Formbook. A stub is a small first stage that unpacks or fetches the real program, so our reading is that this script loads the Formbook stealer.

We did not run it. The word secured in the name is there to make it look trustworthy.

What is Formbook?

Formbook is a Windows information stealer rented out to criminals since at least 2016 and renamed XLoader in October 2020.

MITRE ATT&CK lists keylogging, screenshots, clipboard theft, cookie theft and passwords from browsers, email and FTP programs. It hides inside trusted Windows programs and stays through Run keys and scheduled tasks. Microsoft detects it as Trojan:Win32/Formbook.

I saw www.tmcksa.com in my firewall or DNS log. Am I infected?

Not necessarily, but a device on your network asked for it, and if the request was for secured_stub.ps1 that was a script, not a person. Find which device it was and when. Disconnect it, check Protection history, Startup apps and Task Scheduler, run a Microsoft Defender Offline scan, and change passwords from another device.

How do I remove Formbook from Windows?

Change your passwords from another device first. Then run Microsoft Defender Offline from Windows Security, Virus and threat protection, Scan options. Remove unknown Startup apps and scheduled tasks that run PowerShell.

If you are not sure the PC is clean, reset Windows with Remove everything and restore documents from a backup. We followed Microsoft's pages and did not test the steps on an infected PC.

Can it infect a Mac or a phone?

Not through this address. The listed files are Windows PowerShell scripts.

XLoader, the newer name of Formbook, does have a macOS version, but it is not delivered as a .ps1 file and no source ties it to this site. iPhones and Android phones are not described as targets. Change any passwords you also typed on an infected PC.

Is the company behind tmcksa.com the attacker?

We have no reason to say so. The domain has been registered since 2013, the home page works and points to a new site, and the files sit in side folders.

That is the usual picture of a legitimate site that was hacked and used to host malware. The owner should remove the files, find how the attacker got in and change every password.

What should I do first if I ran an attachment?

Disconnect the PC from the internet, then stop using it for banking, email or work log-ins, as the FTC advises. From a phone or another computer change your email password first, then the others, and sign out of all sessions. Then scan the PC with Microsoft Defender Offline and check what starts with Windows.

Will Fortect remove www.tmcksa.com?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For www.tmcksa.com, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove porterneuman.mx: PowerShell and JavaScript files tied to the AveMaria remote access trojan, and what to do

porterneuman.mx is a web address where URLhaus found five script files in a WordPress plugin folder on 30 September 2026: four PowerShell stubs and one JavaScript file. One stub is tagged AveMariaRAT, a remote access...TrojansHigh riskUgnius Kiguolis ·

Remove Memz virus

Memz virus is the custom-made trojan that overwrites Windows boot sequence with Nyan Cat meme animation Memz virus is the trojan originally created by Leurak as viewer-made malware forTrojansHigh riskLucia Danes ·

Remove qpwot.cfd: a server handing out scripts that lead to the MassLogger and VIP Keylogger stealers, and what to do if one ran

qpwot.cfd is a web address that URLhaus listed seven times on 6 October 2026 for JavaScript files and PowerShell files named secured_stub.ps1, tagged MassLogger and VIPKeylogger, two keyloggers that steal passwords...TrojansHigh riskUgnius Kiguolis ·

Remove www.beinke-aufzuege.de: a hacked website hosting FormBook PowerShell stubs, and what to do if a script fetched them

www.beinke-aufzuege.de is the address of a German website that URLhaus lists for four PowerShell files tagged Formbook, a password stealer for Windows, hidden in random folders inside the site's own Joomla media...TrojansHigh riskUgnius Kiguolis ·

Questions and experiences: www.tmcksa.com (Formbook, PowerShell stub)

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year