MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5bf7c864ad602906093f5498b90b8ecb749825aaed4ac8ff3d7219a5d6da34dd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkTortilla


Vendor detections: 9


Intelligence 9 IOCs YARA 22 File information Comments

SHA256 hash: 5bf7c864ad602906093f5498b90b8ecb749825aaed4ac8ff3d7219a5d6da34dd
SHA3-384 hash: 3d83b0c340a1b349d324c14622cc67fd5b9b2de1e84e1f7862edc8b666cbf313fb136cdf0c904e5adb598a21d146ba53
SHA1 hash: 328745c09f05d06984216f5e230e90f4dd013dff
MD5 hash: 56446c9052951ba9840b5c7471915ab3
humanhash: twelve-august-whiskey-black
File name:Solicitud de cotizaci´+¢n #PO 1100620230526_pdf(39kb).z
Download: download sample
Signature DarkTortilla
File size:2'694'370 bytes
First seen:2025-08-09 01:52:14 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 49152:lF7l+gX8vKws/pq6jOod++ybFf6qgxHAqRYoRHqU9:sC8aRrTybFfjgzHqU9
TLSH T182C533D4272B06178F0E6ABEFFDF85800AB3F4569450BDD09AB314F2B7754A49BE4128
Magika zip
Reporter aachum
Tags:DarkTortilla QuasarRAT rency-ydns-eu z zip


Avatar
iamaachum
C2: rency.ydns.eu

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
ES ES
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Solicitud de cotización #PO 1100620230526_pdf(39kb).com
File size:4'042'240 bytes
SHA256 hash: 75dc57d77a03f52e7d4490f57b440258d1231f0f2efd9e1bd5af0f3e6e169ba8
MD5 hash: d02015413dd415c6b13ac5e2cc1a5d3b
MIME type:application/x-dosexec
Signature DarkTortilla
Vendor Threat Intelligence
Verdict:
Malicious
Score:
96.5%
Tags:
quasar virus micro msil
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
formbook obfuscated obfuscated vbnet
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Verdict:
inconclusive
YARA:
2 match(es)
Tags:
.Net Executable PE (Portable Executable) SOS: 0.62 Zip Archive
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2025-08-09 01:53:38 UTC
File Type:
Binary (Archive)
Extracted files:
219
AV detection:
20 of 24 (83.33%)
Threat level:
  5/5
Result
Malware family:
darktortilla
Score:
  10/10
Tags:
family:darktortilla crypter discovery execution loader persistence
Behaviour
Scheduled Task/Job: Scheduled Task
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Executes dropped EXE
Darktortilla
Darktortilla family
Detects Darktortilla crypter.
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Costura_Protobuf
Author:@bartblaze
Description:Identifies Costura and Protobuf in .NET assemblies, respectively for storing resources and (de)serialization. Seen together might indicate a suspect binary.
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Thread
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:INDICATOR_EXE_Packed_Fody
Author:ditekSHen
Description:Detects executables manipulated with Fody
Rule name:Indicator_MiniDumpWriteDump
Author:Obscurity Labs LLC
Description:Detects PE files and PowerShell scripts that use MiniDumpWriteDump either through direct imports or string references
Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

DarkTortilla

zip 5bf7c864ad602906093f5498b90b8ecb749825aaed4ac8ff3d7219a5d6da34dd

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments