logo

Tofsee – modular spambot

ID: 198f9656-0860-5d57-a845-dd25eccbb42e

STIX ID: report--198f9656-0860-5d57-a845-dd25eccbb42e

Feed Name: CERT Polska

Threat Score
70/100

Date Published: 2016-09-16

Date Updated: 2026-04-19

Author: Adam Krasuski

...
...

Tofsee (aka Gheg) is a modular botnet primarily used for mass spam but capable of additional tasks (DDoS, proxying, spreading, and cryptocurrency mining). The analysis details its non-standard TCP-based C2 protocol with a 128-byte session key delivered in a fixed-size greeting, an in-memory resource list (including a work_srv redirector), a flexible spam script language with macros, and numerous downloadable plugin DLLs (MD5 hashes provided); the report concludes with the analyzed sample hash and YARA rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.