MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 5514013d690dfff22d7fa5f30a8896481754efd28ed24611ea74c7cfa5898e75. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 9
| SHA256 hash: | 5514013d690dfff22d7fa5f30a8896481754efd28ed24611ea74c7cfa5898e75 |
|---|---|
| SHA3-384 hash: | 7730a0bd81e09c7e7bde52daa9664a5157cd05e8b216e622776a0eef02603558aca3245e6c5941f9e8566331e30599be |
| SHA1 hash: | 7b1d49c2dfd68336e5fe1a1c2d33f4ca0cf0357a |
| MD5 hash: | 36ab5d5048d0a62ae10819f0c00a5dfb |
| humanhash: | berlin-hamper-lake-failed |
| File name: | PO-2603113056899.JS |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 3'291'847 bytes |
| First seen: | 2026-07-24 12:19:49 UTC |
| Last seen: | 2026-07-24 12:35:32 UTC |
| File type: | |
| MIME type: | text/plain |
| ssdeep | 98304:WbQvWRftf+Ru1NsES0u5PYukk9u2V5kQTuQA+jxbgd+UHmEouatnK:GYWR1+RcNsESPwoViQTCfgUHmEovtK |
| TLSH | T1C5E52B4087386571696DD72CD13A9F68094F3043609DEF1D35FA0728BAAAF27A34D9E3 |
| Magika | javascript |
| Reporter | |
| Tags: | AgentTesla js |
Intelligence
File Origin
# of uploads :
2
# of downloads :
152
Origin country :
CHVendor Threat Intelligence
No detections
Detection(s):
Verdict:
Malicious
Threat level:
10/10
Confidence:
100%
Tags:
anti-debug dropper evasive obfuscated obfuscated packed repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-07-13T10:27:00Z UTC
Last seen:
2026-07-25T11:11:00Z UTC
Hits:
~10000
Score:
97%
Verdict:
Malware
File Type:
SCRIPT
Gathering data
Detection:
agenttesla
Threat name:
Win32.Trojan.Malgent
Status:
Malicious
First seen:
2026-07-13 21:07:48 UTC
File Type:
Text (JavaScript)
AV detection:
12 of 36 (33.33%)
Threat level:
5/5
Detection(s):
Malicious file
Verdict:
malicious
Label(s):
AgentTesla
DonutLoader
Similar samples:
Result
Malware family:
donutloader
Score:
10/10
Tags:
family:agenttesla family:donutloader collection execution keylogger loader persistence spyware stealer trojan
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
outlook_office_path
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Executes a command shell one-liner
Accesses Microsoft Outlook profiles
Looks up external IP address via web service
Checks computer location settings
Executes dropped EXE
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Detects DonutLoader
Family: AgentTesla
Family: DonutLoader
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Suspicious File
Score:
0.45
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.