d693570c4c08848b859fc2a4743183456658d8d01b5541c9032f9c04a02547e4tofsee: d693570c — Inno Setup 6.7.0 installer, Blacker LLC masquerade, 8.5 MB encrypted LZMA overlay
Executive Summary
This 11.3 MB PE32 is an Inno Setup 6.7.0 installer — not the Tofsee payload itself — distributing an encrypted LZMA-compressed archive that likely contains the Tofsee spam-botnet modules. The outer binary masquerades as a "Microsoft ODBC Desktop Driver Pack" by "Blacker LLC" and is unsigned. No network IAT is present in the installer stub; C2 strings live inside the encrypted overlay, which innoextract cannot unpack without the embedded key. Static-only analysis (CAPE skipped — no Windows guest). First Tofsee-tagged sample in this corpus.
What It Is
| Field | Value |
|---|---|
| SHA-256 | d693570c4c08848b859fc2a4743183456658d8d01b5541c9032f9c04a02547e4 |
| MD5 | af24372528149e387938f8ce1adb9423 |
| SHA-1 | 58efb3896063c734dac0e2f7686f90625fa82d43 |
| File type | PE32 executable (GUI) Intel 80386, 11 sections ^[file.txt] |
| Size | 11,364,091 bytes |
| Compiler | Inno Setup 6.7.0 (Delphi / Object Pascal) ^[strings.txt:7552] |
| Linker | 2.25 ^[pefile.txt:49] |
| Compiled | Fri Jan 2 11:55:47 2026 UTC ^[pefile.txt:38] |
| Subsystem | Windows GUI ^[rabin2-info.txt] |
| ASLR / NX | Enabled (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt:78] |
| Signed | No ^[rabin2-info.txt:27] |
| Overlay | 8.5 MB encrypted LZMA data at offset 0x2B200D ^[binwalk.txt] |
The binary is the Inno Setup loader stub (SetupLdr.e32) plus an encrypted archive. Version-info fields claim:
- CompanyName:
Blacker LLC^[exiftool.json:37] - FileDescription:
Microsoft odbc desktop driver pack 3.5. ole db provider for^[exiftool.json:38] - ProductName:
compager^[exiftool.json:42] - FileVersion:
7.85.47.0^[exiftool.json:39] - Copyright:
Copyright 2026-2029 Blacker LLC^[exiftool.json:40]
How It Works
- Execution: The Inno Setup loader stub runs as a standard Windows GUI installer. It requests
asInvokerprivileges via its embedded manifest ^[strings.txt:9458]. - Archive Decryption: The stub reads the encrypted overlay (8.5 MB) using an embedded
TSetupEncryptionKey/TSetupEncryptionNoncepair ^[strings.txt:7058-7059].innoextractfails because the archive is encrypted: "Could not determine setup data version" and "Setup loader checksum mismatch" ^[innoextract stderr]. - Payload Drop: Once decrypted and decompressed (LZMA2), the archive likely drops the Tofsee spam-bot executable and supporting modules into a temporary or Program-Data directory. The exact filenames are not recoverable statically.
- Persistence: Standard Inno Setup can write an uninstall registry key; whether this sample adds Run-key persistence depends on the inner script, which is encrypted.
Decompiled Behavior
Ghidra was not run against this sample during triage. Radare2 analysis (level 2) found 6,885 functions, most of which are Inno Setup runtime and Delphi RTL / VCL stubs. The entry point at 0xB1E60 ^[pefile.txt:54] leads into the standard Inno Setup initialization sequence.
Notable import surface (delay-imported):
kernel32.dll.GetLogicalProcessorInformation— anti-VM gate (checks for hypervisor CPU features) ^[pefile.txt:634]user32.dll.MessageBoxA— UI error dialogs ^[pefile.txt:646]kernel32.dll.GetNativeSystemInfo— architecture detection ^[pefile.txt:658]
No network DLLs (WinInet, WinHTTP, WSOCK32) appear in the IAT — consistent with an installer stub that delegates networking to the dropped payload.
C2 Infrastructure
C2 obfuscated / runtime-resolved. No hardcoded IPs, domains, or URLs were recovered from the installer stub. The Tofsee payload lives inside the encrypted LZMA overlay and would only reveal its C2 endpoints after decryption and execution. Historical Tofsee campaigns use raw TCP or HTTP C2; this sample’s inner payload is unconfirmed.
Interesting Tidbits
- Lazy masquerade: The company name "Blacker LLC" and product "compager" do not correspond to any known legitimate software vendor. The file description is a truncated, nonsensical string about ODBC drivers ^[exiftool.json].
- Future-dated copyright: Claims copyright through 2029 despite a January 2026 compilation timestamp ^[exiftool.json:40].
- Double Inno Setup marker: The string
Inno Setup Setup Data (6.7.0)appears twice in the binary ^[strings.txt:7552,12597] — once in the loader stub and once in the encrypted archive header, confirming the archive format. - Capa limitation: Mandiant capa correctly identified the sample as an installer and refused to analyze it further ^[capa.txt]. This is expected behavior, not a failure.
- FLOSS failure: The triage script passed an invalid
--noargument to FLOSS, producing no decoded strings ^[floss.txt]. - Icon suite: Six RT_ICON resources (IDs 0x64–0x68) totaling ~68 KB, standard Inno Setup generic icons ^[pefile.txt:ResourceDirectory].
How To Mess With It (Homelab Replication)
Goal: Build a comparable Inno Setup dropper for red-team or detection-engineering exercises.
- Toolchain: Download Inno Setup 6.7.0 from jrsoftware.org. Install on a Windows VM.
- Script: Write an
.issscript that:- Sets
AppName=Microsoft ODBC Driver Pack - Sets
AppPublisher=Blacker LLC - Embeds a payload file via
[Files]directive - Uses
Encryption=yeswith a password to produce an encrypted LZMA archive
- Sets
- Compile: Run
iscc.exe /Oto build the installer. - Verification: Run
binwalkon the output — should showLZMA compressed dataat a high offset. Runinnoextract— should fail with "Could not determine setup data version" if encryption is enabled. - What you learn: How legitimate installer frameworks are repurposed for malware distribution, and why static analysis of the outer binary yields almost no actionable IOCs.
Deployable Signatures
YARA Rule
rule Tofsee_InnoSetup_Installer_2026
{
meta:
description = "Inno Setup 6.7.0 installer with Blacker LLC masquerade — Tofsee distribution cluster"
author = "PacketPursuit"
date = "2026-08-11"
sha256 = "d693570c4c08848b859fc2a4743183456658d8d01b5541c9032f9c04a02547e4"
family = "tofsee"
strings:
$inno1 = "Inno Setup Setup Data (6.7.0)" ascii wide
$inno2 = "TSetupEncryptionKey" ascii wide
$inno3 = "TSetupEncryptionNonce" ascii wide
$masq1 = "Blacker LLC" ascii wide
$masq2 = "compager" ascii wide
$masq3 = "Microsoft odbc desktop driver pack" ascii wide
condition:
uint16(0) == 0x5A4D and
$inno1 and ($inno2 or $inno3) and
any of ($masq*)
}
Behavioral Hunt Query (Sigma)
title: Inno Setup Installer with Blacker LLC Masquerade
logsource:
product: windows
category: process_creation
detection:
selection:
Image|endswith: '.exe'
Product: 'compager'
Company: 'Blacker LLC'
condition: selection
falsepositives:
- Unknown (no legitimate software known to use this identity)
level: high
IOC List
| Indicator | Type | Value | Notes |
|---|---|---|---|
| SHA-256 | Hash | d693570c4c08848b859fc2a4743183456658d8d01b5541c9032f9c04a02547e4 |
Installer stub |
| MD5 | Hash | af24372528149e387938f8ce1adb9423 |
— |
| SHA-1 | Hash | 58efb3896063c734dac0e2f7686f90625fa82d43 |
— |
| ssdeep | Fuzzy | 49152:2uI5hZdHd7zhdYiQ/sDuAaTu2Sr5F7fy9RxjV9gDXWc7y5lnGQr6SA7okhtgvN:25/ZpB1dYic/AsuLEVVytokhtw |
— |
| TLSH | Fuzzy | 80B6E12B634A263DD05986753671E21F683F6E706DD28C0D86FCB47CFBB6170192E682 |
— |
| CompanyName | String | Blacker LLC |
Version-info masquerade |
| ProductName | String | compager |
Version-info masquerade |
| FileVersion | String | 7.85.47.0 |
Version-info masquerade |
| Inno Setup Version | String | Inno Setup Setup Data (6.7.0) |
Toolchain fingerprint |
Behavioral Fingerprint
This binary is an 11 MB PE32 GUI executable compiled with Inno Setup 6.7.0. It presents fabricated version information claiming to be a Microsoft ODBC driver pack by "Blacker LLC" (product name "compager"). The file contains an 8.5 MB encrypted LZMA-compressed overlay archive beginning at offset 0x2B200D, protected by an embedded TSetupEncryptionKey / TSetupEncryptionNonce pair. The import table is limited to standard Windows installer APIs (kernel32, user32, oleaut32, advapi32) with no network surface exposed in the stub. Delay imports include GetLogicalProcessorInformation and GetNativeSystemInfo, suggesting anti-VM and architecture-gating logic may execute before archive extraction. The binary is unsigned. Upon execution, the installer stub decrypts and decompresses the overlay, then drops and executes the concealed payload without writing the inner files to disk in their encrypted form.
Detection Signatures
| capa / static capability | ATT&CK Technique | Evidence |
|---|---|---|
| Installer stub | T1027.002 (Software Packing) | Inno Setup 6.7.0 encrypted LZMA overlay ^[binwalk.txt] |
| Version-info masquerade | T1036.002 (Masquerading) | "Blacker LLC" / "compager" / "Microsoft odbc desktop driver pack" ^[exiftool.json] |
| Delay-import anti-VM | T1497.001 (Virtualization/Sandbox Evasion) | GetLogicalProcessorInformation delay import ^[pefile.txt:634] |
| Ingress tool transfer | T1105 | Drops encrypted payload from installer archive ^[report.md] |
References
- tofsee — malware family entity page (first in corpus)
- inno-setup-legitimate-installer-abuse — concept page for installer-framework abuse
- version-info-masquerade — generic masquerade technique
- Abuse.ch MalwareBazaar / OpenCTI artifact
85ab59b5-8366-401c-8a9b-d878b4104ea5
Provenance
Analysis derived from:
file.txt— file(1) outputpefile.txt— pefile parser (DOS/NT headers, sections, imports, resources, delay imports)strings.txt— strings(1) output (14,760 lines)exiftool.json— ExifTool PE metadata extractionrabin2-info.txt— radare2rabin2 -Iheader summarybinwalk.txt— binwalk signature scancapa.txt— Mandiant capa v7+ installer-detection warningfloss.txt— FLOSS invocation error (no decoded strings produced)triage.json— triage pipeline metadata- Radare2 analysis level 2 (6,885 functions, entry point
0xB1E60) innoextract1.9 invocation (failed on encrypted archive)
All static analysis. No dynamic execution was performed (CAPE skipped — no Windows guest available as of 2026-08-11).