MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 43885d920258d6685b0896c6214b22b5c9f242b1ab76e75797abd91b09c52810. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
DarkTortilla
Vendor detections: 15
| SHA256 hash: | 43885d920258d6685b0896c6214b22b5c9f242b1ab76e75797abd91b09c52810 |
|---|---|
| SHA3-384 hash: | f395a4d32ec7ec1482db5ad1d9e5d1b2e70c85d88a915652c517ee2dd3b436bc165046f63c24dd05cace4b26f5d40cb6 |
| SHA1 hash: | 7adfbfa78e0a303a238cd64bdb29f698f3192a9a |
| MD5 hash: | 00a03fa3acbedb19ddbedede4fc36861 |
| humanhash: | timing-zebra-orange-artist |
| File name: | 00a03fa3acbedb19ddbedede4fc36861 |
| Download: | download sample |
| Signature | DarkTortilla |
| File size: | 1'405'440 bytes |
| First seen: | 2026-02-02 09:03:12 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'754 x AgentTesla, 19'662 x Formbook, 12'252 x SnakeKeylogger) |
| ssdeep | 24576:3fMUdfMs1hsAdBen2pqpOpojZ6tm48Y01KObVQezrdD:3fMUdfTfemOj94pGvQeN |
| Threatray | 9 similar samples on MalwareBazaar |
| TLSH | T17755F10907D58598F4B9DB34A37A361547F0B41BD836EFAF938421F88E3679AA143363 |
| TrID | 67.7% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 9.7% (.EXE) Win64 Executable (generic) (10522/11/4) 6.0% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.6% (.EXE) Win16 NE executable (generic) (5038/12/1) 4.1% (.EXE) Win32 Executable (generic) (4504/4/1) |
| Magika | pebin |
| Reporter | |
| Tags: | DarkTortilla exe |
Intelligence
File Origin
HUVendor Threat Intelligence
Result
Behaviour
Unpacked files
0e211c13ea627d3f7ae9023d2d7c1f972f56f8f0c0cd3cf3a52b2565d2e638ca
b6eb415d7b1be65850ede04ebe14006c319b11be80702c1d10ffd58a915a4f0f
b59f237069f8faccd2b47d23767c95ef269ea70bd910ad816728568afb9bec65
3ed85c60a5587bcf3c5c7cffd46c90491dfc3e3e74f91aac3f91c429a63c1792
67a9288baf5c274fae60465c54accb0973ea5e570c4eb992de3c5babc16b8dae
af45e7ab9d8c10b174c3ae27c54f39e69311c1716be6af42cc50eaaf96e29710
36d359de0808170809afdb8fa45e4403644de6eb4921eab83917d2952f3b6e2e
4abd169c2e8280b1e13b34af291b91138473bafd4b996ce020363f52371d77b6
43885d920258d6685b0896c6214b22b5c9f242b1ab76e75797abd91b09c52810
c3c30fc030de442cede5c078e0ba3ff227c4c57c10c23c4d7dba78e1147f3428
b5c87ae305492fcb39c332e34bb86cf96e0906d89eb7bedf552b740a877ca97d
cff9fc02dfb06bb740609505345e93c40b2b240734913b1122f2ca68a436bc2c
0cbb7f1b15b8cd50b8269b954738cbad9099994d60df5309ac5326c3886c3d10
8109a0528091c8be7fc71e941604672f1cfba50a020c9b4fce74be6e092764f4
65ca5368c87b5c53a24995aa3bb88240abf1766e2fd013ad10756e5006be286c
e53905be786890e707d3afe844cbb853b3b5db4f52768df923ac867a2659c3b1
897221ef7bedd400fc45ef4ebdb769c7993836942e77be5c5c34687eaf345bfc
8e428ed7bec47c35783cca6568a6a8f8d5229669d1cce764d30ecac9ff9c28d4
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
| Rule name: | Sus_CMD_Powershell_Usage |
|---|---|
| Author: | XiAnzheng |
| Description: | May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP) |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.