Neutralizing Tofsee Spambot – Part 1 | Binary file vaccine
ID: 3bfafcf4-2e1b-56b9-9e41-a6b11f68b3bd
STIX ID: report--3bfafcf4-2e1b-56b9-9e41-a6b11f68b3bd
Feed Name: The Spamhaus Project
Threat Score
Tofsee (also known as Gheg) is a sophisticated, modular C/C++ malware family used to send spam, steal login and email credentials, perform cryptomining, and download further payloads such as ransomware and banking trojans. The report discusses its persistence and anti-detection techniques and proposes reverse-engineering steps and a method to ‘vaccinate’ systems by mimicking parts of the malware (e.g., its binary) to trick it into not re-infecting a host.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
