tofsee
Overview
Tofsee is a spam-botnet malware family historically distributed via exploit kits, malspam, and drive-by downloads. In this corpus it appears as an Inno Setup 6.7.0 installer that encrypts and drops the bot payload at runtime. The outer installer masquerades as a Microsoft ODBC driver pack by a fabricated vendor ("Blacker LLC" / "compager"). First confirmed sample in this knowledge base.
Confidence: medium — OpenCTI labels the sample tofsee, but the outer binary is an installer stub, not the bot itself. The inner payload is encrypted and unconfirmed.
Build Stack
- Toolchain: Inno Setup 6.7.0 (Delphi / Object Pascal compiler) ^[sample d693570c/strings.txt:7552]
- Arch: PE32 (x86), Windows GUI subsystem ^[sample d693570c/file.txt]
- Import Table: Standard IAT intact; delay-imports for
kernel32.dllanduser32.dll^[sample d693570c/pefile.txt:DelayImport] - Overlay: 8.5 MB encrypted LZMA-compressed Inno Setup archive at offset 0x2B200D ^[sample d693570c/binwalk.txt]
- Signing: Unsigned ^[sample d693570c/rabin2-info.txt:signed=false]
- Masquerade: Fabricated version info claiming "Microsoft odbc desktop driver pack 3.5" by "Blacker LLC" ^[sample d693570c/exiftool.json]
Capabilities
inno-setup-legitimate-installer-abuselzma-encrypted-overlay-archiveversion-info-masqueradedelay-import-anti-vmspam-botnet-payload-distribution
Deploy / TTPs
| Technique | ID | Evidence |
|---|---|---|
| Masquerading | T1036.002 | "Microsoft odbc desktop driver pack" by "Blacker LLC" ^[sample d693570c/exiftool.json] |
| Software Packing | T1027.002 | Encrypted LZMA(2) Inno Setup archive with embedded key/nonce ^[sample d693570c/strings.txt:7058-7059] |
| Ingress Tool Transfer | T1105 | Drops Tofsee payload via legitimate installer framework ^[/intel/analyses/d693570c4c08848b859fc2a4743183456658d8d01b5541c9032f9c04a02547e4.html] |
| Virtualization/Sandbox Evasion | T1497.001 | GetLogicalProcessorInformation delay import suggests CPU-feature anti-VM gate ^[sample d693570c/pefile.txt:634] |
Variants / Aliases
tofsee— this wiki label (OpenCTI tag)Blacker LLC / compager— observed masquerade identity- Inner payload family unconfirmed (encrypted)
Notable Analyses
- /intel/analyses/d693570c4c08848b859fc2a4743183456658d8d01b5541c9032f9c04a02547e4.html — d693570c, static-only, Inno Setup 6.7.0, encrypted overlay
Related
- inno-setup-legitimate-installer-abuse — concept page for Inno Setup abuse in malware distribution
- netsupport-inno-dropper — structurally similar Inno Setup 6.7.0 installer family (Intel driver masquerade)
- poabu-inno-dropper — structurally similar Inno Setup 6.7.0 installer family (Sectigo-signed, contact-service masquerade)
- xryus-inno-dropper — structurally similar Inno Setup 6.7.0 installer family (Microsoft-ID-Verified signed, EasySuiteer masquerade)
- version-info-masquerade — generic masquerade technique