MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 482cbda2421163b53a99d8fefc44d8e208557eb851eb651542ec076bdee693b3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 10
| SHA256 hash: | 482cbda2421163b53a99d8fefc44d8e208557eb851eb651542ec076bdee693b3 |
|---|---|
| SHA3-384 hash: | a45f02f6de0dc6ee59e47b2bfc570f22ad11f6e7e065ffe2cf1babb0b5ebebb0821d4372960ef645b3d4e585b5940c10 |
| SHA1 hash: | b97d6a04191b9471b05d42059afe7d40ba38229b |
| MD5 hash: | 0c20a775bf9a8ce4ffecdf4626d2e84e |
| humanhash: | zebra-april-fruit-ten |
| File name: | TT_Copy.JS |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 3'139'404 bytes |
| First seen: | 2026-07-24 12:18:02 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | text/plain |
| ssdeep | 49152:2ZGs9s6rDdWM9YgBsGCk2pg8xVTgF4Q4v6RzgYerxISgbgLVaD/5HQFbJkokBNV+:2ZGs9s6rDdWM9YgBsGC/pg8TTgF4Zv6m |
| TLSH | T1B0E53A5157A4917B7321EBED413ADE38940EA40328D9CF44359EDB28B91CE4BA358BF3 |
| Magika | javascript |
| Reporter | |
| Tags: | AgentTesla js |
Intelligence
File Origin
# of uploads :
1
# of downloads :
147
Origin country :
CHVendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
10/10
Confidence:
100%
Tags:
anti-debug downloader dropper evasive obfuscated obfuscated packed repaired xloader
Verdict:
Malicious
File Type:
js
First seen:
2026-07-06T07:27:00Z UTC
Last seen:
2026-07-25T10:54:00Z UTC
Hits:
~10000
Score:
98%
Verdict:
Malware
File Type:
SCRIPT
Gathering data
Detection:
agenttesla
Threat name:
Win32.Trojan.Malgent
Status:
Malicious
First seen:
2026-07-06 13:24:22 UTC
File Type:
Text (JavaScript)
AV detection:
12 of 36 (33.33%)
Threat level:
5/5
Detection(s):
Malicious file
Verdict:
malicious
Label(s):
AgentTesla
DonutLoader
Similar samples:
Result
Malware family:
donutloader
Score:
10/10
Tags:
family:agenttesla family:donutloader collection execution keylogger loader spyware stealer trojan
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Accesses Microsoft Outlook profiles
Looks up external IP address via web service
Checks computer location settings
Executes dropped EXE
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Detects DonutLoader
Family: AgentTesla
Family: DonutLoader
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Suspicious File
Score:
0.55
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.