MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1b341c92a2bc3e9081b16d2b2521d3b6415fd6d717c066593a172daf2885cf7c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 1b341c92a2bc3e9081b16d2b2521d3b6415fd6d717c066593a172daf2885cf7c
SHA3-384 hash: ce2ca5062bfc63e3bf8b73ab8a5b79e5f368971bb2826ea68c6d62a46780dd8c0d6ecc1df1539cf5ba5eeb141f2de302
SHA1 hash: 47c3720a608083c6916ddd393beaca77e302b183
MD5 hash: 26fb1c9c1e679c743f2d493c0a889bbd
humanhash: bakerloo-blossom-winter-pluto
File name:Quotation.JS
Download: download sample
Signature AgentTesla
File size:3'041'778 bytes
First seen:2026-08-10 11:54:29 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 49152:MGURS3nAph9sNeSQxwowW9MbacWX6+TXZBf97xdaB0KbnXxYgE/nBGNh62crh7:MGURS3n4h9pJw6MqZBf97xdaCKzXxYgs
TLSH T17CE53CA056087BB0AA3D672ED4276F080F2EF10BD254FE1F367C564477A675B22CD8A1
Magika txt
Reporter James_inthe_box
Tags:AgentTesla exe js

Intelligence


File Origin
# of uploads :
1
# of downloads :
142
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug downloader dropper evasive obfuscated packed repaired xloader
Verdict:
Malicious
File Type:
js
First seen:
2026-08-07T21:40:00Z UTC
Last seen:
2026-08-10T06:12:00Z UTC
Hits:
~100
Gathering data
Threat name:
Script-JS.Trojan.Generic
Status:
Suspicious
First seen:
2026-08-08 03:02:31 UTC
File Type:
Binary
AV detection:
11 of 38 (28.95%)
Threat level:
  5/5
Result
Malware family:
agenttesla
Score:
  10/10
Tags:
family:agenttesla collection discovery execution keylogger spyware stealer trojan
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of NtSetInformationThreadHideFromDebugger
Accesses Microsoft Outlook profiles
Looks up external IP address via web service
Checks computer location settings
Executes dropped EXE
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Family: AgentTesla
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments