Monday 6 August 2012


A Form-grabber malware who claim to grab anything, and with no dependencies.
It work with lastest version of Firefox, Chrome, Internet Explorer and Opera.


Copy the file/Execute the copy:

Registry persistence:

Drop a dll from ressource:

Looking for browser process:


Firefox injected:
(Congratulation, your browser is owned)

An interesting part of strings found inside the dll:

Doing an attempt to sign in on the service:
(Here, the injected dll compare if it's a POST request)

Malware call home procedure:

Before calling the gate it verify if the host is already decrypted, if no it decrypt the host.
(The coder of MP-Formgrabber have added a method to avoid leaks with hexed bins but look's like he have never heard of code-cave)

Retake an hardcoded strings from resource:

Host decyphered:

Encode grabbed datas and call the gate:

"gate.php" server side

The malware panel, login:


Rules settings to parse logs:

Grabbed infos parsed:

This form-grabber was fun to reverse, anyway dont take this as a game, malware can always ruin your life in two clicks.

 If you are looking for an exe of MP-FormGrabber and additional access to my panel for research purpose, feel free to contact me.


  1. What'd you think of it? Decent?

    Sales are likely going to close for it, or at least leave my hands. I recently found out sales of this tool is Illegal, and I'm not willing to involve myself with it anymore.

    Anyways, good post.

  2. Drop a dll on the hard drive ?
    What kind of shit is this formgrabber ?


    Do I see sql injection here?

  4. Yes Tadas :)
    You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'Junk')' at line 1

  5. BV1 Looks kind of lame to me, DLL injection is a big downside as it requires you to drop files to disk, easy to spot the injected dlls, and so on, so it's simple solution for people that are too inadequate to inject code directly (I guess copy-pasted projected?)

  6. is this zesu
    coz zesu drop dll to hdd to , and uses a shit encryption for the host


    you should do a report on absoboot like krebsonsecurity did :D

  8. Not really interested into ddos faggotry

