MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 d2a4ad1db761a3776160317ba0325d100e65d2baea62d52effee899ab5d355a8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
DarkTortilla
Vendor detections: 16
| SHA256 hash: | d2a4ad1db761a3776160317ba0325d100e65d2baea62d52effee899ab5d355a8 |
|---|---|
| SHA3-384 hash: | e2459dc4977febe552e19760a2f88e1afc186b417c8413ad959c49d30f0824deb078fba3dea1600b98623b8e01b5d92e |
| SHA1 hash: | 46cb66556e0b2b44df79d815fc27cd65859d759d |
| MD5 hash: | 6b058559a54275746bfc645d5c5214d0 |
| humanhash: | shade-mountain-kentucky-network |
| File name: | invoice and packing list.exe |
| Download: | download sample |
| Signature | DarkTortilla |
| File size: | 1'242'624 bytes |
| First seen: | 2026-09-01 06:17:27 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (49'219 x AgentTesla, 20'418 x Formbook, 12'370 x SnakeKeylogger) |
| ssdeep | 24576:4cUAtPa6ObJ+SAmkqkX7YhQzi5IO7WL4iAJR:HXPalESAmyWQzmHWL |
| TLSH | T10E45F02112D99F59F5BF97348875501887F3BC46DF31D7EE3E8C18EA3A22A818661723 |
| TrID | 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 6.6% (.EXE) Win64 Executable (generic) (6522/11/2) 4.5% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Magika | pebin |
| dhash icon | 4db292f2d88cb40b (40 x DarkTortilla, 27 x AgentTesla, 15 x RemcosRAT) |
| Reporter | |
| Tags: | DarkTortilla exe |
Intelligence
File Origin
DEVendor Threat Intelligence
Result
Behaviour
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
d2a4ad1db761a3776160317ba0325d100e65d2baea62d52effee899ab5d355a8
db25d1a378f932e8e6afd0ad46e0181a68310ab9e7a6e204ed7609e302082a39
9f2eca136750c9310914a50d810ee8102c513e628fa37b6795ac5fd653afbd36
0910fc3c5cb222b5b43eef9b187784e36e484728acaa1198b41fb54707c3e167
252f94e8ae17237b19cb38dd3b82e8c09f53c33a323d4a6a6ddd202dd4b59435
bbb3b4379bfe5ad9bc6776afeea7b583225f957e49d79b9c3610325c58697634
d2a4ad1db761a3776160317ba0325d100e65d2baea62d52effee899ab5d355a8
db25d1a378f932e8e6afd0ad46e0181a68310ab9e7a6e204ed7609e302082a39
9f2eca136750c9310914a50d810ee8102c513e628fa37b6795ac5fd653afbd36
0910fc3c5cb222b5b43eef9b187784e36e484728acaa1198b41fb54707c3e167
252f94e8ae17237b19cb38dd3b82e8c09f53c33a323d4a6a6ddd202dd4b59435
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.