www.tmcksa.com: a hacked site serving a PowerShell stub for the Formbook stealer, and what to do if your PC ran it
www.tmcksa.com is a website registered in 2013 that URLhaus listed three times on 5 October 2026 for a PowerShell script, secured_stub.ps1, tagged Formbook. Formbook is a Windows information stealer that takes passwords, keystrokes and cookies.
Visiting the home page does not run the script: it is fetched by a file someone already opened, usually an email attachment. If you only saw the name, nothing is proven. If your PC may have run it, change your passwords from another device, then scan and clean or reset Windows.
Facts checked October 6, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
If a script or attachment that downloads secured_stub.ps1 from www.tmcksa.com keeps coming back after uninstalling, a scan can find what reinstalls it.
Do it yourself · free Remove www.tmcksa.com (Formbook, PowerShell stub) yourself 5 steps, about 15 minutes, no software needed.
Start the steps
Www.tmcksa.com (Formbook, PowerShell stub): summary
| Type | A hacked website, by our reading: URLhaus lists three PowerShell scripts on it tagged Formbook, an information stealer for Windows |
|---|---|
| Risk | High if your PC ran the script: passwords, keystrokes and cookies may be taken. Low if you only saw the name or opened the home page |
| Symptoms | Often none. A flashing PowerShell window after opening an attachment, unknown startup entries or tasks, log-in alerts |
| How to get rid of it | Change passwords from another device, run Microsoft Defender Offline, remove unknown startup entries, reset Windows if unsure |
| Our check (6 October 2026) | One plain request from our server: 301 redirect to new.tmcksa.com. A working home page clears nothing; the files were still listed online |
| Running since / first seen | Domain registered 18 July 2013; malware files first reported 5 October 2026 |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 9 more facts
| Platform | Windows. Mac and phones cannot run the listed PowerShell file |
|---|---|
| Detection names | Microsoft uses Trojan:Win32/Formbook for the family. No name is known for this exact script, because we did not open it |
| Name | Www.tmcksa.com |
| Domain registered | 18 July 2013 |
| Evidence | 3 write-ups by security sites; details still limited |
| First seen | 5 October 2026 |
| Distribution | Typically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps |
| Damage | Installs other malware, often several programs at once |
| Facts checked | 6 October 2026 |
Facts checked on 6 October 2026 against the URLhaus data for www.tmcksa.com held in our database, RDAP, one plain request from our server, and published material from MITRE ATT&CK, Acronis, Microsoft and the FTC. We did not download the files and infected no PC; the removal steps follow Microsoft's pages and were not tried on a live infection.
What www.tmcksa.com is, and what we know about it
www.tmcksa.com is the address of a website that has been registered since 2013. On 5 October 2026 URLhaus, the malware tracking project of abuse.ch, listed three files on it, all named secured_stub.ps1 and tagged Formbook and powershell. An old domain with a working home page and malware files in side folders is the usual picture of a legitimate site that was broken into. We found no public write-up about this address, so what follows is the URLhaus data, our own plain request and what researchers have published about Formbook.
- 1
What URLhaus lists
Three files in three folders: /news/, /new/ and /new1/, each holding secured_stub.ps1. They were added on 5 October 2026 at 09:28, 09:31 and 09:53 UTC. All are labelled malware_download, all were reported by abuse_ch, and all were still marked online when we read the data on 6 October 2026.
- 2
What the tags mean
ps1 is the file ending of a PowerShell script, the scripting tool built into Windows. ascii means the file is plain text. Formbook is the name of an information stealer for Windows, also sold under the name XLoader since October 2020.
- 3
What the file name suggests
A stub is a small first piece of code whose job is to unpack or fetch the real program. Secured is a word attackers use to make a file look trustworthy. Our reading is that secured_stub.ps1 is a loader that starts Formbook; we did not open the file to confirm it.
- 4
Who owns the site
RDAP shows tmcksa.com registered on 18 July 2013 through Launchpad.com Inc., status active. Our plain request was sent on to new.tmcksa.com, which looks like a site being rebuilt or moved. We found nothing that says the owner placed the files there, and we do not suggest it.

What www.tmcksa.com (Formbook, PowerShell stub) does on an infected PC
What we checked on 6 October 2026, and what we could not
We sent one plain request from our server to the home page, with no browser and no clicks. It answered 301 Moved Permanently and pointed to hxxps://new.tmcksa[.]com/, from an nginx 1.29.8 server. That clears nothing: the reported files sit in other folders, and a working home page is normal for a hacked site.
www.tmcksa.com · plain request and data check · 6 October 2026
- The home pageHTTP status 301, a permanent move to new.tmcksa.com. We did not follow it with a browser and did not test the new address.
- RegistrationRegistered 18 July 2013 through Launchpad.com Inc., status active, according to RDAP. An address this old is rarely set up just for malware.
- Notification or pop-up tricksNone in the plain answer. The risk here is a script file, not a browser scam.
- The script filesWe did not download or run secured_stub.ps1. What it does comes from the URLhaus tags, not from our analysis.
- Public researchWe found no write-up about www.tmcksa.com. The chain below is how researchers describe Formbook delivery in general.
Dangerous if a PC ran the script A Windows PC that ran secured_stub.ps1 should be treated as infected with an information stealer, and its passwords as taken.
What happened to www.tmcksa.com, from registration to our test
The domain is thirteen years old; the reports all fall within half an hour on one morning. The dates come from RDAP, URLhaus and our own request, in UTC.
18 July 2013
The domain is registered
RDAP shows tmcksa.com registered through Launchpad.com Inc. It has stayed active since.
5 October 2026, 09:28
The first file is reported
abuse_ch adds
hxxps://www.tmcksa[.]com/news/secured_stub.ps1to URLhaus with the tags ascii, Formbook, powershell and ps1.5 October 2026, 09:31
A second copy
The same file name in the folder /new/ is added three minutes later, with the same tags.
5 October 2026, 09:53
A third copy
The folder /new1/ follows. Three folders with near identical names look like an attacker keeping spare copies in case one is removed. That is our reading.
6 October 2026
Our check
All three entries are still marked online. The home page answers 301 and points to new.tmcksa.com.
How a PowerShell stub on a hacked site leads to Formbook
Nobody gets Formbook by visiting www.tmcksa.com. The script is fetched by something already running on a PC, most often a file that came by email. We did not see the chain for this site; this is how MITRE ATT&CK, Acronis and the sandbox reports describe Formbook delivery.

- 1
An attachment is opened
MITRE ATT&CK (XLoader, S1207, modified 11 March 2025) says the malware is mainly delivered by phishing email with PDF, Office, ZIP, RAR or ISO attachments. Acronis (26 November 2021) names ISO, RAR and XLSX files dressed up as business mail.
- 2
A script fetches the stub
Recent samples, as the sandbox and vendor reports describe them, start with a JavaScript file that launches PowerShell. PowerShell downloads a script such as secured_stub.ps1 from a web address, often a hacked site that looks harmless to filters.
- 3
The stealer is unpacked in memory
The script decrypts a .NET program and loads it without writing a normal file to disk. MITRE lists process hollowing: the stealer runs inside a trusted Windows program, so the Task Manager shows a familiar name.
- 4
It stays and steals
MITRE lists Run keys and scheduled tasks for staying after a restart, then keystrokes, screenshots, clipboard data, cookies and saved passwords sent to the controller over HTTP.
What Formbook is
Formbook is an information stealer for Windows that has been rented out to criminals since 2016. The sources agree on what it takes and differ on details of each version.
| Question | What the sources say | Source |
|---|---|---|
| What is it? | An information stealer sold as malware as a service, renamed XLoader in October 2020 | MITRE ATT&CK S1207; Acronis |
| How old is it? | In use since at least 2016 | MITRE ATT&CK S1207 |
| What does it cost the criminal? | Acronis reported $59 a month for the Windows version and $49 for the macOS version of XLoader in 2021 | Acronis, 26 November 2021 |
| What does it take? | Keystrokes, screenshots, clipboard, cookies, and passwords from browsers, email and FTP programs | MITRE ATT&CK S1207; Acronis |
| How does it hide? | Process hollowing, anti-debugging and sandbox checks, XOR and RC4 encryption | MITRE ATT&CK S1207 |
| How does it stay? | Registry Run keys and scheduled tasks | MITRE ATT&CK S1207 |
| What does Microsoft call it? | Trojan:Win32/Formbook, an entry first published on 7 January 2019 | Microsoft Security Intelligence |
What www.tmcksa.com (Formbook, PowerShell stub) can steal or download
What Formbook can take from a Windows PC
An information stealer is built to collect logins quickly and send them out. Each item below is named by MITRE ATT&CK or Acronis; not every build does all of them.
Reported as taken
- Every key you type
- Screenshots
- Clipboard contents
- Saved browser passwords
- Browser cookies and sessions
- Email program passwords
- FTP program passwords
- Data typed into web forms
- High
Email and work accounts
Email passwords are taken from mail programs and browsers. Whoever reads your mail can reset your other accounts and write to your contacts as you.
- High
Bank and shop log-ins
Form grabbing captures what you type into log-in and payment forms before it is encrypted for sending.
- High
Signed in sessions
Stolen cookies can let someone use an account without the password, until you sign out of all sessions.
- Medium
Business mail fraud
Formbook is usually sent to companies. A stolen business mailbox is a common start for invoice fraud against your customers. That is our reading, not a quote.
What you may notice, and what you may not
Stealers try to stay invisible. Most people notice nothing until an account is misused. The signs below come from the sources and Microsoft's entry.
| Sign | What it can mean |
|---|---|
| A Defender alert naming Formbook, XLoader or a PowerShell download | Microsoft blocked part of the chain. Check Protection history for what was found and whether it was removed |
| A PowerShell window that flashed after you opened an attachment | A script may have run. That is the moment to disconnect |
| A startup entry or scheduled task you did not create | MITRE lists Run keys and scheduled tasks for Formbook |
| Slow PC, changed files, crashes | Microsoft's entry lists these as general symptoms; they prove nothing on their own |
| Log-in alerts, password reset mails, mails sent from your account | Your logins may already be in use |

How to check the PC for www.tmcksa.com (Formbook, PowerShell stub)
Who can meet www.tmcksa.com
The script is a Windows PowerShell file. People meet it through a program on their PC, not by browsing. For the site owner the question is different: how the files got onto the server.
| You are | What it means | What to do |
|---|---|---|
| Someone who opened an unexpected attachment and then saw this address in an alert or log | A script on your PC probably tried to fetch secured_stub.ps1 | Disconnect and follow the steps on this page |
| An admin who saw the address in a proxy, DNS or firewall log | The device that asked is the one to check | Find the device and the time, isolate it, check it |
| A visitor of the company site | Opening the home page does not run a .ps1 file | Nothing to remove for that visit |
| A Mac, iPhone or Android user | The listed file is a Windows PowerShell script | Nothing to remove for this threat |
| The owner or web host of tmcksa.com | Your server is serving malware from three folders | See the section for site owners below |
Check your PC before you delete anything
Start with the question that matters: did you open an unexpected attachment, script or archive around 5 October 2026, or did an alert name this address? If yes or not sure, do these checks. None of them deletes anything.
While you check, stop using the PC for banking, email and work log-ins, as the FTC advises.
- 1
Disconnect first
Turn off Wi-Fi or unplug the cable. A stealer sends data out over the network.
- 2
Read Protection history
Open Windows Security > Virus & threat protection > Protection history and look for Formbook, XLoader, PowerShell or a blocked download, with its date.
- 3
Look at Startup apps
Open Settings > Apps > Startup and note anything you do not recognise. Do not switch it off yet if you want to keep evidence.
- 4
Open Task Scheduler
Press Start, type Task Scheduler, open Task Scheduler Library and look for tasks with random names or actions that run powershell.exe.
- 5
Find the file you opened
Look in Downloads and in the mail program for the attachment. Keep it for your IT support; do not open it again.

How to remove www.tmcksa.com (Formbook, PowerShell stub)
How to remove www.tmcksa.com
A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.
Step 1: Delete scheduled tasks that bring it back
Programs like www.tmcksa.com add a scheduled task so they return after an uninstall or reopen a page at every sign-in. Start Task Scheduler, open Task Scheduler Library and sort by Last Run Time to see what ran recently.
On the Actions tab, a program in a user folder, a script or a web address is a warning sign; right-click such a task and choose Delete.
Tasks with names copying Google, Edge or Windows updaters but pointing to an odd folder are typical. The tool looks the same in Windows 11 and Windows 10.

Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs. Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 2: Remove it from startup
Press Ctrl + Shift + Esc to open Task Manager and select Startup apps (Windows 11) or the Startup tab (Windows 10). Disable entries you do not recognise, especially ones with no publisher or with a name that copies a Windows component.
Right-click an entry and choose Open file location to see where it runs from: programs in
%AppData%or%Temp%deserve a closer look. Some entries are not listed there but in the registry Run keys, which the procedure below shows how to check.Full procedure with screenshots: Stop apps from opening at startup On uGetFix
Step 3: Delete the folders left behind
Uninstalling often leaves the program's folders, and some threats reinstall themselves from them.
Press Windows + R, type
%LocalAppData%and press Enter, then do the same for%AppData%and %ProgramData%, and look for folders named after www.tmcksa.com, its publisher or created on the day the problem started. Delete those folders, and check C:\Program Files and C:\Program Files (x86) too.If Windows says a file is in use, end it in Task Manager or delete the folder after a restart in Safe Mode. The folders are the same in Windows 11 and Windows 10.
Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 4: Scan the PC, then run the offline scan
A scan finds the parts of www.tmcksa.com that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.
Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.
It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 5: Change passwords from another device and sign out other sessions
Www.tmcksa.com can copy saved passwords, cookies and session tokens and send them out in seconds, so cleaning the PC does not undo the theft.
Change your passwords on a device that was never infected, starting with the e-mail account, since every other reset goes through it. On each account, end all other sessions and check the recovery e-mail, phone number and forwarding rules.
Then turn on two-step verification. Sign in on the Windows 11 or Windows 10 PC again only after the offline scan is clean.
Full procedure with screenshots: Turn on two-step verification / secure a hacked account
If you use a Mac, an iPhone or an Android phone
The listed file is a Windows PowerShell script, and every source we read about this delivery chain describes Windows.
| Your device | What we know | What to do |
|---|---|---|
| Mac | XLoader has a macOS version, but it is not delivered as a .ps1 file | Nothing to remove for this address. Do not follow the Windows steps on a Mac |
| iPhone or iPad | No source describes Formbook on iOS | Nothing to remove. Change passwords you also used on an infected PC |
| Android | No source mentions it | Nothing to remove for this threat |
After removal: passwords, accounts and prevention
After a clean PC: protect what was taken
Removing the stealer does not take back what it already sent. Change passwords from another device first, then clean the PC.

- 1
Change passwords from a clean device
Start with email, then banking, work, cloud storage and shops. Anything saved in the browser on the infected PC should be treated as known.
- 2
Sign out everywhere and turn on two step sign in
Signing out of all sessions kills stolen cookies. The FTC advises two factor authentication so a stolen password alone is not enough.
- 3
Run Microsoft Defender Offline
In Windows Security > Virus & threat protection > Scan options choose Microsoft Defender Antivirus (offline scan) and Scan now. The PC restarts and scans without loading Windows; results appear in Protection history.
- 4
Remove what starts by itself
Switch off unknown entries in Startup apps and delete the scheduled tasks you tied to the malware.
- 5
Reset if you are not sure
Use Settings > System > Recovery > Reset this PC with Remove everything, then restore documents from a backup. That is the only way to be sure no piece is left.
- 6
Warn people who may be fooled
If your work mailbox was used, tell your IT team, your bank and customers who might receive fake invoices in your name.
If you own or host tmcksa.com
The files sit in /news/, /new/ and /new1/ on the www address. Removing them is the easy part; the way the attacker got in is what matters.
- 1
Remove the three files and keep copies
Delete secured_stub.ps1 from the three folders, but first save copies and the web server logs for the dates around 5 October 2026 for your host or an investigator.
- 2
Find the way in
Check the hosting control panel, FTP and SSH log-ins, and the content management system and its plug-ins for missing updates. Look for other new files, especially scripts in upload folders.
- 3
Change every password
Hosting panel, FTP, database, CMS admin and email. Formbook itself steals FTP passwords, so a stolen FTP login is one possible way in. That is our reading, not a finding.
- 4
Check the old and the new site
The home page now points to new.tmcksa.com. Make sure the old www site was not left running unpatched on the same server.
- 5
Ask for removal from the lists
Once the files are gone, URLhaus marks them offline after checking. Browser and mail filters follow the lists.
Keep a PC out of this kind of chain
The script on the hacked site is the middle of the chain. Every report we read starts earlier, with a file a person opened.
Do
- Treat an unexpected invoice, order or shipping notice with an archive, ISO or script attached as an attack.
- Show file name extensions in File Explorer so a .js or .ps1 file posing as a document is visible.
- Keep Windows and Microsoft Defender updated.
- Use a password manager and two step sign in, so a stolen password alone is not enough.
- Keep a backup of documents on a disk you unplug.
Don't
- Do not open attachments from senders you did not expect, even from known companies.
- Do not save important passwords in a browser on a PC that many people use.
- Do not change passwords on the PC you suspect.
- Do not trust a download because the website behind it is old or well known.
Questions about www.tmcksa.com (Formbook, PowerShell stub)
What is www.tmcksa.com?
It is the address of a website registered since 18 July 2013. On 5 October 2026 URLhaus, the abuse.ch malware tracking project, listed three files on it named secured_stub.ps1 in the folders news, new and new1, all tagged Formbook and powershell.
An old site with malware in side folders is usually a hacked site. We did not open the files, so their content is not confirmed by us.
Is www.tmcksa.com safe to open?
Opening the home page does not run a PowerShell script, and on 6 October 2026 the home page only sent us on to new.tmcksa.com.
Do not open the reported folders and do not run any .ps1 file from the address. The three files were still marked online when we checked, so the site is not clean yet, and a quiet home page clears nothing.
What is secured_stub.ps1?
It is a PowerShell script, a plain text file of commands for Windows. URLhaus tags it Formbook. A stub is a small first stage that unpacks or fetches the real program, so our reading is that this script loads the Formbook stealer.
We did not run it. The word secured in the name is there to make it look trustworthy.
What is Formbook?
Formbook is a Windows information stealer rented out to criminals since at least 2016 and renamed XLoader in October 2020.
MITRE ATT&CK lists keylogging, screenshots, clipboard theft, cookie theft and passwords from browsers, email and FTP programs. It hides inside trusted Windows programs and stays through Run keys and scheduled tasks. Microsoft detects it as Trojan:Win32/Formbook.
I saw www.tmcksa.com in my firewall or DNS log. Am I infected?
Not necessarily, but a device on your network asked for it, and if the request was for secured_stub.ps1 that was a script, not a person. Find which device it was and when. Disconnect it, check Protection history, Startup apps and Task Scheduler, run a Microsoft Defender Offline scan, and change passwords from another device.
How do I remove Formbook from Windows?
Change your passwords from another device first. Then run Microsoft Defender Offline from Windows Security, Virus and threat protection, Scan options. Remove unknown Startup apps and scheduled tasks that run PowerShell.
If you are not sure the PC is clean, reset Windows with Remove everything and restore documents from a backup. We followed Microsoft's pages and did not test the steps on an infected PC.
Can it infect a Mac or a phone?
Not through this address. The listed files are Windows PowerShell scripts.
XLoader, the newer name of Formbook, does have a macOS version, but it is not delivered as a .ps1 file and no source ties it to this site. iPhones and Android phones are not described as targets. Change any passwords you also typed on an infected PC.
Is the company behind tmcksa.com the attacker?
We have no reason to say so. The domain has been registered since 2013, the home page works and points to a new site, and the files sit in side folders.
That is the usual picture of a legitimate site that was hacked and used to host malware. The owner should remove the files, find how the attacker got in and change every password.
What should I do first if I ran an attachment?
Disconnect the PC from the internet, then stop using it for banking, email or work log-ins, as the FTC advises. From a phone or another computer change your email password first, then the others, and sign out of all sessions. Then scan the PC with Microsoft Defender Offline and check what starts with Windows.
Will Fortect remove www.tmcksa.com?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For www.tmcksa.com, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- URLhaus entries for www.tmcksa.com (abuse.ch), as held in our database: three secured_stub.ps1 files, 5 October 2026 (read October 6, 2026)
- MITRE ATT&CK: XLoader (formerly FormBook), S1207 (modified 11 March 2025) (read October 6, 2026)
- Acronis: Trojan as a service, from Formbook to XLoader (26 November 2021) (read October 6, 2026)
- Microsoft Security Intelligence: Trojan:Win32/Formbook (published 7 January 2019) (read October 6, 2026)
- Microsoft Support: Help protect my PC with Microsoft Defender Offline (read October 6, 2026)
- FTC Consumer Advice: How to recognize, remove and avoid malware (April 2025) (read October 6, 2026)