SYMBOLCOMMON_NAMEaka. SYNONYMS
win.tofsee (Back to overview)

Tofsee

aka: Gheg
VTCollection     URLhaus    

According to PCrisk, Tofsee (also known as Gheg) is a malicious Trojan-type program that is capable of performing DDoS attacks, mining cryptocurrency, sending emails, stealing various account credentials, updating itself, and more.

Cyber criminals mainly use this program as an email-oriented tool (they target users' email accounts), however, having Tofsee installed can also lead to many other problems.

References
2023-10-12 ⋅ Spamhaus ⋅ Spamhaus Malware Labs
Spamhaus Botnet Threat Update Q3 2023
FluBot AsyncRAT Ave Maria Cobalt Strike DCRat Havoc IcedID ISFB Nanocore RAT NjRAT QakBot Quasar RAT RecordBreaker RedLine Stealer Remcos Rhadamanthys Sliver Stealc Tofsee Vidar
2023-07-11 ⋅ Spamhaus ⋅ Spamhaus Malware Labs
Spamhaus Botnet Threat Update Q2 2023
Hydra AsyncRAT Aurora Stealer Ave Maria BumbleBee Cobalt Strike DCRat Havoc IcedID ISFB NjRAT QakBot Quasar RAT RecordBreaker RedLine Stealer Remcos Rhadamanthys Sliver Tofsee
2023-04-12 ⋅ Spamhaus ⋅ Spamhaus Malware Labs
Spamhaus Botnet Threat Update Q1 2023
FluBot Amadey AsyncRAT Aurora Ave Maria BumbleBee Cobalt Strike DCRat Emotet IcedID ISFB NjRAT QakBot RecordBreaker RedLine Stealer Remcos Rhadamanthys Sliver Tofsee Vidar
2023-04-10 ⋅ Check Point ⋅ Check Point
March 2023’s Most Wanted Malware: New Emotet Campaign Bypasses Microsoft Blocks to Distribute Malicious OneNote Files
Agent Tesla CloudEyE Emotet Formbook Nanocore RAT NjRAT QakBot Remcos Tofsee
2023-04-06 ⋅ Spamhaus ⋅ Raashid Bhat
Neutralizing Tofsee Spambot – Part 1 | Binary file vaccine
Tofsee
2023-04-06 ⋅ Spamhaus ⋅ Raashid Bhat
Neutralizing Tofsee Spambot – Part 2 | InMemoryConfig store vaccine
Tofsee
2023-04-06 ⋅ Spamhaus ⋅ Raashid Bhat
Neutralizing Tofsee Spambot – Part 3 | Network-based kill switch
Tofsee
2023-03-28 ⋅ BitSight ⋅ André Tavares
Tofsee Botnet: Proxying and Mining
Tofsee
2022-11-21 ⋅ Github (larsborn) ⋅ Lars Wallenborn
Tofsee String Decryption Code
Tofsee
2022-10-13 ⋅ Spamhaus ⋅ Spamhaus Malware Labs
Spamhaus Botnet Threat Update Q3 2022
FluBot Arkei Stealer AsyncRAT Ave Maria BumbleBee Cobalt Strike DCRat Dridex Emotet Loki Password Stealer (PWS) Nanocore RAT NetWire RC NjRAT QakBot RecordBreaker RedLine Stealer Remcos Socelars Tofsee Vjw0rm
2022-02-11 ⋅ Cisco Talos ⋅ Talos
Threat Roundup for February 4 to February 11
DarkComet Ghost RAT Loki Password Stealer (PWS) Tinba Tofsee Zeus
2022-02-08 ⋅ Intel 471 ⋅ Intel 471
PrivateLoader: The first step in many malware schemes
Dridex Kronos LockBit Nanocore RAT NjRAT PrivateLoader Quasar RAT RedLine Stealer Remcos SmokeLoader STOP Tofsee TrickBot Vidar
2021-05-17 ⋅ Dragos ⋅ Kent Backman
Investigating the Watering Hole Linked to the Oldsmar Water Treatment Facility Breach
Tofsee
2017-10-19 ⋅ CERT.PL ⋅ Jarosław Jedynak
A deeper look at Tofsee modules
Tofsee
2017-10-06 ⋅ CERT.PL ⋅ Jarosław Jedynak, Maciej Kotowicz
Peering into spam botnets
Emotet Kelihos Necurs SendSafe Tofsee
2017-03-24 ⋅ Zerophage
Terror EK via Malvertising delivers Tofsee Spambot
Tofsee
2016-12-22 ⋅ GovCERT.ch ⋅ GovCERT.ch
Tofsee Spambot features .ch DGA - Reversal and Countermesaures
Tofsee
2016-09-29 ⋅ Cisco Talos ⋅ Edmund Brumaghin
Want Tofsee My Pictures? A Botnet Gets Aggressive
Tofsee
2016-09-16 ⋅ CERT.PL ⋅ Adam Krasuski
Tofsee – modular spambot
Tofsee
2014-04-02 ⋅ Virus Bulletin ⋅ Ryan Mi
Tofsee botnet
Tofsee
2009-03-17 ⋅ Marshal8e6 ⋅ Rodel Mendrez
Gheg spambot
Tofsee
Yara Rules
[TLP:WHITE] win_tofsee_auto (20260917 | Detects win.tofsee.)
rule win_tofsee_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.tofsee."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tofsee"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { ff75fc ffd7 85c0 0f84f2000000 0fb7859cfeffff 8b4dbc 56 }
            // n = 7, score = 400
            //   ff75fc               | push                dword ptr [ebp - 4]
            //   ffd7                 | call                edi
            //   85c0                 | test                eax, eax
            //   0f84f2000000         | je                  0xf8
            //   0fb7859cfeffff       | movzx               eax, word ptr [ebp - 0x164]
            //   8b4dbc               | mov                 ecx, dword ptr [ebp - 0x44]
            //   56                   | push                esi

        $sequence_1 = { 50 ff7570 e8???????? 59 59 ff7568 ff756c }
            // n = 7, score = 400
            //   50                   | push                eax
            //   ff7570               | push                dword ptr [ebp + 0x70]
            //   e8????????           |                     
            //   59                   | pop                 ecx
            //   59                   | pop                 ecx
            //   ff7568               | push                dword ptr [ebp + 0x68]
            //   ff756c               | push                dword ptr [ebp + 0x6c]

        $sequence_2 = { 8bce ff5004 8bf0 ff7608 ff15???????? 85c0 750d }
            // n = 7, score = 400
            //   8bce                 | mov                 ecx, esi
            //   ff5004               | call                dword ptr [eax + 4]
            //   8bf0                 | mov                 esi, eax
            //   ff7608               | push                dword ptr [esi + 8]
            //   ff15????????         |                     
            //   85c0                 | test                eax, eax
            //   750d                 | jne                 0xf

        $sequence_3 = { 53 50 ff7514 c60702 e8???????? 83c410 85c0 }
            // n = 7, score = 400
            //   53                   | push                ebx
            //   50                   | push                eax
            //   ff7514               | push                dword ptr [ebp + 0x14]
            //   c60702               | mov                 byte ptr [edi], 2
            //   e8????????           |                     
            //   83c410               | add                 esp, 0x10
            //   85c0                 | test                eax, eax

        $sequence_4 = { 57 6a07 33c9 8bc2 }
            // n = 4, score = 400
            //   57                   | push                edi
            //   6a07                 | push                7
            //   33c9                 | xor                 ecx, ecx
            //   8bc2                 | mov                 eax, edx

        $sequence_5 = { 6a00 6a00 ff7564 8d852cffffff 6880000000 50 e8???????? }
            // n = 7, score = 400
            //   6a00                 | push                0
            //   6a00                 | push                0
            //   ff7564               | push                dword ptr [ebp + 0x64]
            //   8d852cffffff         | lea                 eax, [ebp - 0xd4]
            //   6880000000           | push                0x80
            //   50                   | push                eax
            //   e8????????           |                     

        $sequence_6 = { 7443 8b5dfc 85db 7433 837d0c00 742d 57 }
            // n = 7, score = 400
            //   7443                 | je                  0x45
            //   8b5dfc               | mov                 ebx, dword ptr [ebp - 4]
            //   85db                 | test                ebx, ebx
            //   7433                 | je                  0x35
            //   837d0c00             | cmp                 dword ptr [ebp + 0xc], 0
            //   742d                 | je                  0x2f
            //   57                   | push                edi

        $sequence_7 = { 8bf7 741c 8b1e 53 ff742418 55 e8???????? }
            // n = 7, score = 400
            //   8bf7                 | mov                 esi, edi
            //   741c                 | je                  0x1e
            //   8b1e                 | mov                 ebx, dword ptr [esi]
            //   53                   | push                ebx
            //   ff742418             | push                dword ptr [esp + 0x18]
            //   55                   | push                ebp
            //   e8????????           |                     

        $sequence_8 = { 50 ff15???????? 8d4564 50 8d4550 50 ff15???????? }
            // n = 7, score = 400
            //   50                   | push                eax
            //   ff15????????         |                     
            //   8d4564               | lea                 eax, [ebp + 0x64]
            //   50                   | push                eax
            //   8d4550               | lea                 eax, [ebp + 0x50]
            //   50                   | push                eax
            //   ff15????????         |                     

        $sequence_9 = { e8???????? 80781000 75d4 56 8bcb e8???????? 837d0c03 }
            // n = 7, score = 400
            //   e8????????           |                     
            //   80781000             | cmp                 byte ptr [eax + 0x10], 0
            //   75d4                 | jne                 0xffffffd6
            //   56                   | push                esi
            //   8bcb                 | mov                 ecx, ebx
            //   e8????????           |                     
            //   837d0c03             | cmp                 dword ptr [ebp + 0xc], 3

    condition:
        7 of them and filesize < 147456
}
[TLP:WHITE] win_tofsee_w0   (20171121 | No description)
rule win_tofsee_w0 {
    meta:
        author="akrasuski1"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tofsee"
        malpedia_version = "20171121"
        malpedia_license = "CC BY-NC-SA 4.0"
        malpedia_sharing = "TLP:WHITE"
    strings:

        $decryptStr = {32 55 14 88 10 8A D1 02 55 18 F6 D9 00 55 14}
        $xorGreet = {C1 EB 03 C0 E1 05 0A D9 32 DA 34 C6 88 1E}
        $xorCrypt = {F7 FB 8A 44 0A 04 30 06 FF 41 0C}

        $string_res1 = "loader_id"
        $string_res2 = "born_date"
        $string_res3 = "work_srv"
        $string_res4 = "flags_upd"
        $string_res5 = "lid_file_upd"
        $string_res6 = "localcfg"

        $string_var0 = "%RND_NUM"
        $string_var1 = "%SYS_JR"
        $string_var2 = "%SYS_N"
        $string_var3 = "%SYS_RN"
        $string_var4 = "%RND_SPACE"
        $string_var5 = "%RND_DIGIT"
        $string_var6 = "%RND_HEX"
        $string_var7 = "%RND_hex"
        $string_var8 = "%RND_char"
        $string_var9 = "%RND_CHAR"

    condition:
        (7 of ($string_var*) and 4 of ($string_res*))
        or
        (7 of ($string_var*) and 2 of ($decryptStr, $xorGreet, $xorCrypt))
        or
        (4 of ($string_res*) and 2 of ($decryptStr, $xorGreet, $xorCrypt))
}
Download all Yara Rules