MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4d7e7e33d21e8fce44f975e4085ad999ca2337dbb39c003160f3aaebb298cba2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 4d7e7e33d21e8fce44f975e4085ad999ca2337dbb39c003160f3aaebb298cba2
SHA3-384 hash: e06a3a93363cfe8a98894f47db9a578f760faf609749ee3053b53144cd14197f509e34905820dc9e5d56c5a95f7804b8
SHA1 hash: 181b1c0a77f7ade56e84c62561eb3c9a5dd60cfa
MD5 hash: df30f659d28cc34ba7b41cbad430ae1f
humanhash: whiskey-emma-bulldog-monkey
File name:RFQ 206.JS
Download: download sample
Signature AgentTesla
File size:3'380'850 bytes
First seen:2026-05-06 07:01:11 UTC
Last seen:2026-05-06 07:30:09 UTC
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 98304:xUxGvQsVDB0npQINXZy7kitA+pVQX3mPYDcNt7KFFjHV5F6PokX4K2rIbnoOMUJI:IGIsVSpLNXZy7kitA+pVQX2PYDcNt7KV
TLSH T19CF54B8666E7A2237360EFD9473DDDB1D80E95031849CF14B18EE73C381CE4A6266B67
Magika javascript
Reporter jahlives
Tags:AgentTesla exe-in-archive js spamtrap

Intelligence


File Origin
# of uploads :
2
# of downloads :
175
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Gathering data
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug dropper evasive formbook obfuscated obfuscated packed repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-05-05T05:58:00Z UTC
Last seen:
2026-05-08T05:44:00Z UTC
Hits:
~10000
Detections:
Trojan-Downloader.JS.Cryptoload.sb HEUR:Trojan-Dropper.Script.Generic HEUR:Trojan.Script.Generic HEUR:Trojan-Downloader.Script.Generic
Gathering data
Threat name:
Script-JS.Trojan.Generic
Status:
Suspicious
First seen:
2026-05-05 13:04:12 UTC
File Type:
Binary
AV detection:
7 of 24 (29.17%)
Threat level:
  5/5
Result
Malware family:
donutloader
Score:
  10/10
Tags:
family:agenttesla family:donutloader execution keylogger loader spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Looks up external IP address via web service
Checks computer location settings
Executes dropped EXE
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Detects DonutLoader
Family: AgentTesla
Family: DonutLoader
Malware family:
AgentTesla
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments