Tofsee – modular spambot
ID: 198f9656-0860-5d57-a845-dd25eccbb42e
STIX ID: report--198f9656-0860-5d57-a845-dd25eccbb42e
Feed Name: CERT Polska
Tofsee (aka Gheg) is a modular botnet primarily used for mass spam but capable of additional tasks (DDoS, proxying, spreading, and cryptocurrency mining). The analysis details its non-standard TCP-based C2 protocol with a 128-byte session key delivered in a fixed-size greeting, an in-memory resource list (including a work_srv redirector), a flexible spam script language with macros, and numerous downloadable plugin DLLs (MD5 hashes provided); the report concludes with the analyzed sample hash and YARA rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
