Top Tweets for #TOFSEE
@medsci_yb3r @KulinskiArkadi @skocherhan @smica83 I found the 4th report on 'sdfgsdf.exe' #tofsee @anyrun_app
https://t.co/s8vMQkMVzJ related to UK Telekom 51[.]9[.]21[.]7 Look into EXIF, PE and strings: the same data>> https://t.co/YBZ1fxqCOg
![userlolxxl's tweet photo. @medsci_yb3r @KulinskiArkadi @skocherhan @smica83 I found the 4th report on 'sdfgsdf.exe' #tofsee @anyrun_app
https://t.co/s8vMQkMVzJ related to UK Telekom 51[.]9[.]21[.]7 Look into EXIF, PE and strings: the same data>> https://t.co/YBZ1fxqCOg https://t.co/1TGRnSK0f1](https://pbs.twimg.com/media/GzrwPA3WUAAjtHy.png)
@medsci_yb3r @KulinskiArkadi @skocherhan @smica83 Appologise, I forgot to add and importnant note; the common denominator is #Tofsee malware.
Payload statistics from September 2024 📊 We observed 752 tasks distributed by threat actors across the tracked botnets. This resulted in 3841 unique payloads.
Top families:
1. #StealC
2. #Amadey
3. #SmokeLoader
4. #VidarStealer
5. #Tofsee
Unpacking and detection: @unpacme

Payload statistics from July 2024 📊
We observed 459 tasks distributed by threat actors across the tracked botnets. This resulted in 4262 unique payloads.
Top families:
1. #Socks5Systemz
2. #StealC
3. #SmokeLoader
4. #Amadey
5. #Tofsee
Unpacking and detection: @unpacme 🤝

Interesting build being shared by #privateloader
/185.198.57.117/sservc.exe
That is using infected machine to brute ssh, ftp, php admin, wp-login and other services from gov and edu domains worldwide using TOR?
Have you ever seen that? Is this #tofsee?
https://t.co/pETSpHxxIx
#Tofsee is a veteran botnet that is still in service
Tofsee utilizes a one-byte encryption algorithm using a slightly modified Output Feedback (OFB) scheme with plaintext feedback.
This algorithm is used for the first packet from the server, which contains key information for the entire connection. This is why the algorithm is so important.
Check the sample 👉https://t.co/K8wEgHsc5A
We provide a unidirectional decyptor implemented in the CyberChef service for the key data from the server response.
https://t.co/5zOgUsAdbA

@g0njxa @g0njxa 👍
Amazing RUN
Samples Collections from AnyRun RUN
💯https://t.co/W2fUnmRO8Z
✅
#privateloader
#risepro
#povertystealer
#redline
#gcleaner
#fabookie
#amadey
#kelihos
#miner
#tofsee
#smokeloader
#ransomware
#ArkeiStealer
#Glupteba
etc✅
W11 Run
https://t.co/8NCmAWEPw0

hxxps://epicitem.ir/download/File_pass1234.7z
Distribution of #PrivateLoader over compromised SoundCloud accounts.
Drops
#Tofsee Trojan
#Smoke Loader 188.114.96.3:80
#Redline (6 binaries)
- 178.33.182.70:18918 - LogsDiller Cloud
- 157.254.164.98:28449 - CLOUDCOSMIC
👇👇
Last Seen Hashtags on Sotwe
小马拉大车
Seen from Singapore
สุรินทร์FWB
Seen from Thailand
old
Seen from Turkey
Publicnude
nolimit() nolimit filter:native_video
Seen from United Kingdom
nolimit() +filter:native_video since:2026-05-08
Seen from United States
climatechange
Seen from United States
japanesetonguekissing
Seen from Turkey
รับงานสุขสวัสดิ์
Seen from Thailand
momson or #exny or #zoophilia or #zopositivity or #nolimit() +filter:native_video
Seen from Russia
Trends for you
Most Popular Users

Elon Musk 
@elonmusk
240.3M followers

Barack Obama 
@barackobama
119.3M followers

Donald J. Trump 
@realdonaldtrump
111.6M followers

Cristiano Ronaldo 
@cristiano
109.6M followers

Narendra Modi 
@narendramodi
106.9M followers

Rihanna 
@rihanna
97.4M followers

NASA 
@nasa
92.1M followers

Justin Bieber 
@justinbieber
90.7M followers

KATY PERRY 
@katyperry
87.2M followers

Taylor Swift 
@taylorswift13
81M followers

Lady Gaga 
@ladygaga
72.5M followers

Kim Kardashian 
@kimkardashian
69.5M followers

Virat Kohli 
@imvkohli
69.1M followers

YouTube 
@youtube
68.6M followers

Bill Gates 
@billgates
63.6M followers

The Ellen Show
@theellenshow
62.5M followers

CNN 
@cnn
61.9M followers

Neymar Jr 
@neymarjr
61.8M followers

X 
@x
60.9M followers

Selena Gomez 
@selenagomez
60.3M followers

![userlolxxl's tweet photo. @medsci_yb3r @KulinskiArkadi @skocherhan @smica83 I found the 4th report on 'sdfgsdf.exe' #tofsee @anyrun_app
https://t.co/s8vMQkMVzJ related to UK Telekom 51[.]9[.]21[.]7 Look into EXIF, PE and strings: the same data>> https://t.co/YBZ1fxqCOg https://t.co/1TGRnSK0f1](https://pbs.twimg.com/media/GzrvmuVX0AAUb9a.png)
![userlolxxl's tweet photo. @medsci_yb3r @KulinskiArkadi @skocherhan @smica83 I found the 4th report on 'sdfgsdf.exe' #tofsee @anyrun_app
https://t.co/s8vMQkMVzJ related to UK Telekom 51[.]9[.]21[.]7 Look into EXIF, PE and strings: the same data>> https://t.co/YBZ1fxqCOg https://t.co/1TGRnSK0f1](https://pbs.twimg.com/media/Gzrui5SXAAAyZW7.jpg)



















