How a Malicious Excel File (CVE-2017-0199) Delivers the FormBook Payload

How a Malicious Excel File (CVE-2017-0199) Delivers the FormBook Payload

A phishing campaign exploits the CVE-2017-0199 vulnerability in outdated Microsoft Office versions to deliver FormBook malware via malicious Excel attachments. This attack enables threat actors to control victims’ devices and steal sensitive information. #FormBook #CVE20170199 #MicrosoftOffice

Keypoints

  • The campaign uses phishing emails disguised as sales orders containing malicious Excel files targeting old Microsoft Office versions.
  • The Excel attachment exploits CVE-2017-0199, triggering the download of a malicious HTA file executed through mshta.exe.
  • The HTA file downloads and runs “sihost.exe” which extracts a file named “springmaker” that is further decoded into FormBook malware.
  • FormBook steals sensitive data such as login credentials, keystrokes, and clipboard contents from infected devices.
  • Anti-debugging techniques and base64 encoding are used to obfuscate execution and payload delivery.
  • Fortinet solutions including FortiGuard AntiSPAM, Web Filtering, IPS, and AntiVirus services detect and block all stages of the attack.
  • Despite patches for CVE-2017-0199 being available, unpatched systems remain vulnerable due to poor update management.

MITRE Techniques

  • [T1190] Exploit Public-Facing Application – The campaign exploits the CVE-2017-0199 vulnerability in Microsoft Office applications to execute malicious code (“…triggers CVE-2017-0199, causing the download and execution of the linked content”).
  • [T1204.002] User Execution: Malicious File – Victims open malicious Excel attachments that trigger the attack chain (“…phishing emails with malicious Excel attachments designed to exploit the CVE-2017-0199 vulnerability”).
  • [T1059.005] Command and Scripting Interpreter: Visual Basic – The HTA file contains base64-encoded VBScript that decodes and executes the payload (“…malicious HTA file with base64-encoded content”).
  • [T1036.005] Masquerading: Match Legitimate Name or Location – The payload “sihost.exe” masquerades using a system-like name to evade detection (“…the malware named ‘sihost.exe’ resembling legitimate Windows processes”).
  • [T1140] Deobfuscate/Decode Files or Information – The “springmaker” file is XOR-decoded using a specific key to restore the final FormBook payload (“…XORed with the string ‘3NQXSHDTVT2DPK06’ to restore the original file”).
  • [T1082] System Information Discovery – FormBook malware captures sensitive information including keystrokes and clipboard data (“…known for its ability to capture sensitive data, including login credentials, keystrokes, and clipboard information”).

Indicators of Compromise

  • [URL] Malicious payload hosting – hxxp://172.245.123.32/xampp/hh/wefa.hta, hxxp://172.245.123.32/199/sihost.exe
  • [File Hash] Malicious Excel attachment – 33A1696D69874AD86501F739A0186F0E4C0301B5A45D73DA903F91539C0DB427 (AprilSAO2025.xls)
  • [File Hash] Malicious HTA file – 2BFBF6792CA46219259424EFBBBEE09DDBE6AE8FD9426C50AA0326A530AC5B14 (wef.hta)
  • [File Hash] Payload executable – 7E16ED31277C31C0370B391A1FC73F77D7F0CD13CC3BAB0EAA9E2F303B6019AF (siHOST.exe)
  • [File Hash] Intermediate decoded file – A619B1057BCCB69C4D00366F62EBD6E969935CCA65FA40FDBFE1B95E36BA605D (springmaker)
  • [File Hash] Final FormBook malware – 3843F96588773E2E463A4DA492C875B3241A4842D0C087A19C948E2BE0898364


Read more: https://feeds.fortinet.com/~/919745468/0/fortinet/blog/threat-research~How-a-Malicious-Excel-File-CVE-Delivers-the-FormBook-Payload