🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 33d543386cfbc9f5d982ffe157ef2e5dfab16bcc7fd850894ddee4bb6beaa19a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 33d543386cfbc9f5d982ffe157ef2e5dfab16bcc7fd850894ddee4bb6beaa19a
SHA3-384 hash: 4da69b2a601db12c1da81611784e26f969bf550786bf853630a3b0404a1573209ae75f74c1da079c56b0103b856ad665
SHA1 hash: 3a8afcb53aef7561565388cb838a06fb64b51c0d
MD5 hash: 988da4fc060341aa96be3c88b8cb2841
humanhash: early-missouri-montana-lamp
File name:Comprobante de pago BBVA.js
Download: download sample
Signature AgentTesla
File size:320'438 bytes
First seen:2026-09-02 11:59:53 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 768:t8SPTecU+/zv/kYiWEfeUAZJ/vNFGQc372AfkX/KXdQL1va:6c7b0YKFAZZvNFGQc37nkPogQ
TLSH T1D464AA8352A4784005BF125A9FF105C491EE1587A3C7A9B737ED6AC43BBBD20CB5AB70
Magika javascript
Reporter James_inthe_box
Tags:AgentTesla exe js

Intelligence


File Origin
# of uploads :
1
# of downloads :
182
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-09-01T15:12:00Z UTC
Last seen:
2026-09-03T10:03:00Z UTC
Hits:
~1000
Gathering data
Threat name:
Script-JS.Trojan.Heuristic
Status:
Malicious
First seen:
2026-09-02 00:57:11 UTC
File Type:
Text (JavaScript)
AV detection:
5 of 38 (13.16%)
Threat level:
  2/5
Result
Malware family:
agenttesla
Score:
  10/10
Tags:
family:agenttesla collection discovery execution keylogger spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
Command and Scripting Interpreter: JavaScript
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Command and Scripting Interpreter: PowerShell
Looks up external IP address via web service
Badlisted process makes network request
Family: AgentTesla
Process spawned unexpected child process
Malware Config
Dropper Extraction:
https://munihuacho.gob.pe/documentos/newMSI_PRO.png
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments