MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 448b6f8ac2a740cb13774eaca02c09ca372514fa30eddd67e1e3894ab4226cc5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 11


Intelligence 11 IOCs YARA File information Comments

SHA256 hash: 448b6f8ac2a740cb13774eaca02c09ca372514fa30eddd67e1e3894ab4226cc5
SHA3-384 hash: 7fac0d5c05c52c4dedb57e24789dfcfdb42f1b9c801f437f7d041bc305d4457e7b047d5ff84c9b4a4cafb58934ab2888
SHA1 hash: 7db0c62230facf79126c8daecfdd87be6e659b84
MD5 hash: 39aa13e31edc12fbb2c24573575e35f0
humanhash: shade-sixteen-nine-zebra
File name:New PO for bulk order.zip
Download: download sample
Signature AgentTesla
File size:1'462'125 bytes
First seen:2026-06-18 05:12:28 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:C4Pa0otVlvhoIsWMz8IQ/4HdQYOkxq8veY0ULHK1uCS1o8gnRt/K+raJeQGB364Y:pPa0obthtsNzweOks8jBbK1uCx8Uv/yH
TLSH T11B65338DCA1C99A81C42B33C1D34219F57F0B759D31E9A5B28FADBA2C27E63453FA444
Magika zip
Reporter cocaman
Tags:AgentTesla zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
126
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:New PO for bulk order.JS
File size:3'642'968 bytes
SHA256 hash: 8dffead0450847a53d2c7d585aa2150acc44a4813ecbd31f0e7f6c61d7b08c05
MD5 hash: a523a5e6046da45a3d62b64c5bab0618
MIME type:text/plain
Signature AgentTesla
Vendor Threat Intelligence
Verdict:
Malicious
Score:
92.5%
Tags:
spawn lien blic hype
Result
Verdict:
Malicious
File Type:
JS File - Malicious
Behaviour
BlacklistAPI detected
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug base64 dropper evasive masquerade obfuscated obfuscated packed repaired
Verdict:
Malicious
File Type:
zip
First seen:
2026-06-17T03:17:00Z UTC
Last seen:
2026-06-18T10:33:00Z UTC
Hits:
~10
Gathering data
Threat name:
Script-JS.Spyware.Negasteal
Status:
Malicious
First seen:
2026-06-17 14:40:00 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
12 of 24 (50.00%)
Threat level:
  2/5
Result
Malware family:
agenttesla
Score:
  10/10
Tags:
family:agenttesla collection discovery execution keylogger spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of NtSetInformationThreadHideFromDebugger
Accesses Microsoft Outlook profiles
Looks up external IP address via web service
Checks computer location settings
Executes dropped EXE
Reads WinSCP keys stored on the system
Reads data files stored by FTP clients
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Family: AgentTesla
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 448b6f8ac2a740cb13774eaca02c09ca372514fa30eddd67e1e3894ab4226cc5

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments