A phishing campaign exploits the CVE-2017-0199 vulnerability in outdated Microsoft Office versions to deliver FormBook malware via malicious Excel attachments. This attack enables threat actors to control victims’ devices and steal sensitive information. #FormBook #CVE20170199 #MicrosoftOffice
Keypoints
- The campaign uses phishing emails disguised as sales orders containing malicious Excel files targeting old Microsoft Office versions.
- The Excel attachment exploits CVE-2017-0199, triggering the download of a malicious HTA file executed through mshta.exe.
- The HTA file downloads and runs “sihost.exe” which extracts a file named “springmaker” that is further decoded into FormBook malware.
- FormBook steals sensitive data such as login credentials, keystrokes, and clipboard contents from infected devices.
- Anti-debugging techniques and base64 encoding are used to obfuscate execution and payload delivery.
- Fortinet solutions including FortiGuard AntiSPAM, Web Filtering, IPS, and AntiVirus services detect and block all stages of the attack.
- Despite patches for CVE-2017-0199 being available, unpatched systems remain vulnerable due to poor update management.
MITRE Techniques
- [T1190] Exploit Public-Facing Application – The campaign exploits the CVE-2017-0199 vulnerability in Microsoft Office applications to execute malicious code (“…triggers CVE-2017-0199, causing the download and execution of the linked content”).
- [T1204.002] User Execution: Malicious File – Victims open malicious Excel attachments that trigger the attack chain (“…phishing emails with malicious Excel attachments designed to exploit the CVE-2017-0199 vulnerability”).
- [T1059.005] Command and Scripting Interpreter: Visual Basic – The HTA file contains base64-encoded VBScript that decodes and executes the payload (“…malicious HTA file with base64-encoded content”).
- [T1036.005] Masquerading: Match Legitimate Name or Location – The payload “sihost.exe” masquerades using a system-like name to evade detection (“…the malware named ‘sihost.exe’ resembling legitimate Windows processes”).
- [T1140] Deobfuscate/Decode Files or Information – The “springmaker” file is XOR-decoded using a specific key to restore the final FormBook payload (“…XORed with the string ‘3NQXSHDTVT2DPK06’ to restore the original file”).
- [T1082] System Information Discovery – FormBook malware captures sensitive information including keystrokes and clipboard data (“…known for its ability to capture sensitive data, including login credentials, keystrokes, and clipboard information”).
Indicators of Compromise
- [URL] Malicious payload hosting – hxxp://172.245.123.32/xampp/hh/wefa.hta, hxxp://172.245.123.32/199/sihost.exe
- [File Hash] Malicious Excel attachment – 33A1696D69874AD86501F739A0186F0E4C0301B5A45D73DA903F91539C0DB427 (AprilSAO2025.xls)
- [File Hash] Malicious HTA file – 2BFBF6792CA46219259424EFBBBEE09DDBE6AE8FD9426C50AA0326A530AC5B14 (wef.hta)
- [File Hash] Payload executable – 7E16ED31277C31C0370B391A1FC73F77D7F0CD13CC3BAB0EAA9E2F303B6019AF (siHOST.exe)
- [File Hash] Intermediate decoded file – A619B1057BCCB69C4D00366F62EBD6E969935CCA65FA40FDBFE1B95E36BA605D (springmaker)
- [File Hash] Final FormBook malware – 3843F96588773E2E463A4DA492C875B3241A4842D0C087A19C948E2BE0898364