MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7590a307a9cfbe88f7aea528b890bf8f1e8d81228ef06fd65ceb06ab758fe0ee. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 7590a307a9cfbe88f7aea528b890bf8f1e8d81228ef06fd65ceb06ab758fe0ee
SHA3-384 hash: f1df6e22561cd0a918c10a04c29f227fd5d2ae00a674dfc9a8aa7fae63a0d06b01d12d959c1d300a36d602922bd0466d
SHA1 hash: 48d4a32edaed80a43d94940f75687abe9e9d8d70
MD5 hash: df718cc88fd3c87474f054a1b763a134
humanhash: bakerloo-social-winter-video
File name:Payment slip EDR4658.JS
Download: download sample
Signature AgentTesla
File size:3'212'591 bytes
First seen:2026-06-01 12:29:38 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 98304:s/EBy/DVBt2+QrOvQ1havXbq156yFQ90SYOL8u+fCN33:VyLV/OOvQ1hoXu6ARSguPNH
TLSH T106E56D449970E105BBC2CF5A6932AAF4B14F29477E284660610FE1761DDFF93C0A29BF
Magika javascript
Reporter James_inthe_box
Tags:AgentTesla exe js

Intelligence


File Origin
# of uploads :
1
# of downloads :
143
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
94.9%
Tags:
xtreme shell lien sage
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
aes base64 crypto evasive masquerade obfuscated obfuscated powershell repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-05-26T03:44:00Z UTC
Last seen:
2026-06-01T08:54:00Z UTC
Hits:
~1000
Gathering data
Threat name:
Win32.Trojan.Malgent
Status:
Malicious
First seen:
2026-05-26 13:10:24 UTC
File Type:
Binary
AV detection:
8 of 36 (22.22%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
donutloader agenttesla
Result
Malware family:
agenttesla
Score:
  10/10
Tags:
family:agenttesla collection discovery execution keylogger spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Accesses Microsoft Outlook profiles
Command and Scripting Interpreter: PowerShell
Looks up external IP address via web service
Checks computer location settings
Badlisted process makes network request
Family: AgentTesla
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments