typeanalysisfamilytofseeconfidencemediumpeinstallermasqueradingevasionmalware-familyloader
SHA-256: d693570c4c08848b859fc2a4743183456658d8d01b5541c9032f9c04a02547e4

tofsee: d693570c — Inno Setup 6.7.0 installer, Blacker LLC masquerade, 8.5 MB encrypted LZMA overlay

Executive Summary

This 11.3 MB PE32 is an Inno Setup 6.7.0 installer — not the Tofsee payload itself — distributing an encrypted LZMA-compressed archive that likely contains the Tofsee spam-botnet modules. The outer binary masquerades as a "Microsoft ODBC Desktop Driver Pack" by "Blacker LLC" and is unsigned. No network IAT is present in the installer stub; C2 strings live inside the encrypted overlay, which innoextract cannot unpack without the embedded key. Static-only analysis (CAPE skipped — no Windows guest). First Tofsee-tagged sample in this corpus.

What It Is

Field Value
SHA-256 d693570c4c08848b859fc2a4743183456658d8d01b5541c9032f9c04a02547e4
MD5 af24372528149e387938f8ce1adb9423
SHA-1 58efb3896063c734dac0e2f7686f90625fa82d43
File type PE32 executable (GUI) Intel 80386, 11 sections ^[file.txt]
Size 11,364,091 bytes
Compiler Inno Setup 6.7.0 (Delphi / Object Pascal) ^[strings.txt:7552]
Linker 2.25 ^[pefile.txt:49]
Compiled Fri Jan 2 11:55:47 2026 UTC ^[pefile.txt:38]
Subsystem Windows GUI ^[rabin2-info.txt]
ASLR / NX Enabled (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt:78]
Signed No ^[rabin2-info.txt:27]
Overlay 8.5 MB encrypted LZMA data at offset 0x2B200D ^[binwalk.txt]

The binary is the Inno Setup loader stub (SetupLdr.e32) plus an encrypted archive. Version-info fields claim:

  • CompanyName: Blacker LLC ^[exiftool.json:37]
  • FileDescription: Microsoft odbc desktop driver pack 3.5. ole db provider for ^[exiftool.json:38]
  • ProductName: compager ^[exiftool.json:42]
  • FileVersion: 7.85.47.0 ^[exiftool.json:39]
  • Copyright: Copyright 2026-2029 Blacker LLC ^[exiftool.json:40]

How It Works

  1. Execution: The Inno Setup loader stub runs as a standard Windows GUI installer. It requests asInvoker privileges via its embedded manifest ^[strings.txt:9458].
  2. Archive Decryption: The stub reads the encrypted overlay (8.5 MB) using an embedded TSetupEncryptionKey / TSetupEncryptionNonce pair ^[strings.txt:7058-7059]. innoextract fails because the archive is encrypted: "Could not determine setup data version" and "Setup loader checksum mismatch" ^[innoextract stderr].
  3. Payload Drop: Once decrypted and decompressed (LZMA2), the archive likely drops the Tofsee spam-bot executable and supporting modules into a temporary or Program-Data directory. The exact filenames are not recoverable statically.
  4. Persistence: Standard Inno Setup can write an uninstall registry key; whether this sample adds Run-key persistence depends on the inner script, which is encrypted.

Decompiled Behavior

Ghidra was not run against this sample during triage. Radare2 analysis (level 2) found 6,885 functions, most of which are Inno Setup runtime and Delphi RTL / VCL stubs. The entry point at 0xB1E60 ^[pefile.txt:54] leads into the standard Inno Setup initialization sequence.

Notable import surface (delay-imported):

  • kernel32.dll.GetLogicalProcessorInformation — anti-VM gate (checks for hypervisor CPU features) ^[pefile.txt:634]
  • user32.dll.MessageBoxA — UI error dialogs ^[pefile.txt:646]
  • kernel32.dll.GetNativeSystemInfo — architecture detection ^[pefile.txt:658]

No network DLLs (WinInet, WinHTTP, WSOCK32) appear in the IAT — consistent with an installer stub that delegates networking to the dropped payload.

C2 Infrastructure

C2 obfuscated / runtime-resolved. No hardcoded IPs, domains, or URLs were recovered from the installer stub. The Tofsee payload lives inside the encrypted LZMA overlay and would only reveal its C2 endpoints after decryption and execution. Historical Tofsee campaigns use raw TCP or HTTP C2; this sample’s inner payload is unconfirmed.

Interesting Tidbits

  • Lazy masquerade: The company name "Blacker LLC" and product "compager" do not correspond to any known legitimate software vendor. The file description is a truncated, nonsensical string about ODBC drivers ^[exiftool.json].
  • Future-dated copyright: Claims copyright through 2029 despite a January 2026 compilation timestamp ^[exiftool.json:40].
  • Double Inno Setup marker: The string Inno Setup Setup Data (6.7.0) appears twice in the binary ^[strings.txt:7552,12597] — once in the loader stub and once in the encrypted archive header, confirming the archive format.
  • Capa limitation: Mandiant capa correctly identified the sample as an installer and refused to analyze it further ^[capa.txt]. This is expected behavior, not a failure.
  • FLOSS failure: The triage script passed an invalid --no argument to FLOSS, producing no decoded strings ^[floss.txt].
  • Icon suite: Six RT_ICON resources (IDs 0x64–0x68) totaling ~68 KB, standard Inno Setup generic icons ^[pefile.txt:ResourceDirectory].

How To Mess With It (Homelab Replication)

Goal: Build a comparable Inno Setup dropper for red-team or detection-engineering exercises.

  1. Toolchain: Download Inno Setup 6.7.0 from jrsoftware.org. Install on a Windows VM.
  2. Script: Write an .iss script that:
    • Sets AppName=Microsoft ODBC Driver Pack
    • Sets AppPublisher=Blacker LLC
    • Embeds a payload file via [Files] directive
    • Uses Encryption=yes with a password to produce an encrypted LZMA archive
  3. Compile: Run iscc.exe /O to build the installer.
  4. Verification: Run binwalk on the output — should show LZMA compressed data at a high offset. Run innoextract — should fail with "Could not determine setup data version" if encryption is enabled.
  5. What you learn: How legitimate installer frameworks are repurposed for malware distribution, and why static analysis of the outer binary yields almost no actionable IOCs.

Deployable Signatures

YARA Rule

rule Tofsee_InnoSetup_Installer_2026
{
    meta:
        description = "Inno Setup 6.7.0 installer with Blacker LLC masquerade — Tofsee distribution cluster"
        author = "PacketPursuit"
        date = "2026-08-11"
        sha256 = "d693570c4c08848b859fc2a4743183456658d8d01b5541c9032f9c04a02547e4"
        family = "tofsee"

    strings:
        $inno1 = "Inno Setup Setup Data (6.7.0)" ascii wide
        $inno2 = "TSetupEncryptionKey" ascii wide
        $inno3 = "TSetupEncryptionNonce" ascii wide
        $masq1 = "Blacker LLC" ascii wide
        $masq2 = "compager" ascii wide
        $masq3 = "Microsoft odbc desktop driver pack" ascii wide

    condition:
        uint16(0) == 0x5A4D and
        $inno1 and ($inno2 or $inno3) and
        any of ($masq*)
}

Behavioral Hunt Query (Sigma)

title: Inno Setup Installer with Blacker LLC Masquerade
logsource:
    product: windows
    category: process_creation
detection:
    selection:
        Image|endswith: '.exe'
        Product: 'compager'
        Company: 'Blacker LLC'
    condition: selection
falsepositives:
    - Unknown (no legitimate software known to use this identity)
level: high

IOC List

Indicator Type Value Notes
SHA-256 Hash d693570c4c08848b859fc2a4743183456658d8d01b5541c9032f9c04a02547e4 Installer stub
MD5 Hash af24372528149e387938f8ce1adb9423 —
SHA-1 Hash 58efb3896063c734dac0e2f7686f90625fa82d43 —
ssdeep Fuzzy 49152:2uI5hZdHd7zhdYiQ/sDuAaTu2Sr5F7fy9RxjV9gDXWc7y5lnGQr6SA7okhtgvN:25/ZpB1dYic/AsuLEVVytokhtw —
TLSH Fuzzy 80B6E12B634A263DD05986753671E21F683F6E706DD28C0D86FCB47CFBB6170192E682 —
CompanyName String Blacker LLC Version-info masquerade
ProductName String compager Version-info masquerade
FileVersion String 7.85.47.0 Version-info masquerade
Inno Setup Version String Inno Setup Setup Data (6.7.0) Toolchain fingerprint

Behavioral Fingerprint

This binary is an 11 MB PE32 GUI executable compiled with Inno Setup 6.7.0. It presents fabricated version information claiming to be a Microsoft ODBC driver pack by "Blacker LLC" (product name "compager"). The file contains an 8.5 MB encrypted LZMA-compressed overlay archive beginning at offset 0x2B200D, protected by an embedded TSetupEncryptionKey / TSetupEncryptionNonce pair. The import table is limited to standard Windows installer APIs (kernel32, user32, oleaut32, advapi32) with no network surface exposed in the stub. Delay imports include GetLogicalProcessorInformation and GetNativeSystemInfo, suggesting anti-VM and architecture-gating logic may execute before archive extraction. The binary is unsigned. Upon execution, the installer stub decrypts and decompresses the overlay, then drops and executes the concealed payload without writing the inner files to disk in their encrypted form.

Detection Signatures

capa / static capability ATT&CK Technique Evidence
Installer stub T1027.002 (Software Packing) Inno Setup 6.7.0 encrypted LZMA overlay ^[binwalk.txt]
Version-info masquerade T1036.002 (Masquerading) "Blacker LLC" / "compager" / "Microsoft odbc desktop driver pack" ^[exiftool.json]
Delay-import anti-VM T1497.001 (Virtualization/Sandbox Evasion) GetLogicalProcessorInformation delay import ^[pefile.txt:634]
Ingress tool transfer T1105 Drops encrypted payload from installer archive ^[report.md]

References

Provenance

Analysis derived from:

  • file.txt — file(1) output
  • pefile.txt — pefile parser (DOS/NT headers, sections, imports, resources, delay imports)
  • strings.txt — strings(1) output (14,760 lines)
  • exiftool.json — ExifTool PE metadata extraction
  • rabin2-info.txt — radare2 rabin2 -I header summary
  • binwalk.txt — binwalk signature scan
  • capa.txt — Mandiant capa v7+ installer-detection warning
  • floss.txt — FLOSS invocation error (no decoded strings produced)
  • triage.json — triage pipeline metadata
  • Radare2 analysis level 2 (6,885 functions, entry point 0xB1E60)
  • innoextract 1.9 invocation (failed on encrypted archive)

All static analysis. No dynamic execution was performed (CAPE skipped — no Windows guest available as of 2026-08-11).