Neutralizing Tofsee Spambot - Part 2 | InMemoryConfig store vaccine
ID: 29ae578d-cd0c-540b-8845-89e6efdcf5da
STIX ID: report--29ae578d-cd0c-540b-8845-89e6efdcf5da
Feed Name: The Spamhaus Project
Threat Score
This excerpt describes Tofsee botnet configuration storage and retrieval: it enumerates multiple filesystem (including ADS and user-profile paths) and registry locations used to persist XOR-encoded chained configuration buffers, and identifies the 'work_srv' and 'start_srv' structures retrieved during the initial command-and-control connection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
