MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 5a7e30f8306b5487f44f8418f635fb52b5d239690342e1c2983f3aceb74f8b50. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Tofsee
Vendor detections: 14
| SHA256 hash: | 5a7e30f8306b5487f44f8418f635fb52b5d239690342e1c2983f3aceb74f8b50 |
|---|---|
| SHA3-384 hash: | 6ea4e9584d38e95bca81b1ee0f6d0c73b948cba20b52fa870ba903739359b2e164ed29c6bc1dd37452c82fb2b5d94142 |
| SHA1 hash: | d0f4368eef4ea6eda65f992f24a006bc362ee359 |
| MD5 hash: | 28ab5238e88a228c758dc962bffc378b |
| humanhash: | indigo-fourteen-golf-kentucky |
| File name: | 28ab5238e88a228c758dc962bffc378b.exe |
| Download: | download sample |
| Signature | Tofsee |
| File size: | 271'872 bytes |
| First seen: | 2022-02-24 17:14:18 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 917b0dc587f632b60bbe39ab8c418265 (2 x RedLineStealer, 1 x ArkeiStealer, 1 x DanaBot) |
| ssdeep | 3072:y4dNeYfd5K7YYiDvwMPuAQ5EVggjcGkNIVqIOM/h36qV0QB/LjF:Xzfd5K7YEL+7ITsqxsDRLj |
| Threatray | 244 similar samples on MalwareBazaar |
| TLSH | T10B44ADE17980D435C486F230982BCFA0592DEC61CE645A4772B83F5FBE722D166B921F |
| File icon (PE): | |
| dhash icon | 327e7c7f727e6e62 (2 x RedLineStealer, 1 x Tofsee) |
| Reporter | |
| Tags: | exe Tofsee |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
ovicrush.cn
Unpacked files
9cab0c7efdafdcab54b20bf295f36ecb1cc35cdad27dddb7b568a637263e8003
f6ca96e0301249fbada0e52bcd3c9b2b6ee0cec95f13e8984ef747d513651fc9
f7024727c4d979b2b200345c3785945aa7c125670fb7ad570f3cf0b45273d966
5d84be18669beb78b0993523cbaf3e66f352ce34888a6f63245290ca02436785
fed7c4e47ea734756b34a457fbb402ce63624e1c8bbe48441a9634f4130e022c
3db9a9633bb3097ee7f34cd85bbc168ed3a59496c0c407cf1d22087d58fa2763
5a7e30f8306b5487f44f8418f635fb52b5d239690342e1c2983f3aceb74f8b50
84cc4707c97905c1082d9eb31dd7d995e04955506b9275b6c4bfd19683150430
de5704d6579398a4b51f7458c105759c46096567661a26bffe1159ef11a16eb8
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | MALWARE_Win_Tofsee |
|---|---|
| Author: | ditekSHen |
| Description: | Detects Tofsee |
| Rule name: | win_tofsee_w0 |
|---|---|
| Author: | akrasuski1 |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.