MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 75ebdaee1723f1157d81132bc667504e1353f9bba6863e4b804aa867dfcfa09c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 75ebdaee1723f1157d81132bc667504e1353f9bba6863e4b804aa867dfcfa09c
SHA3-384 hash: f56ae7991b1780587582c7e4745d5b551d84bbf1cef2e6f2b66936fdaf4d18e145c44b17ed0eb204c9fdffd2c49dbc50
SHA1 hash: 3c7699cd8f83ff2b9daea1ab15c19bc445c1fb3c
MD5 hash: cfa79d2e28273aeecdd8e57fd423af18
humanhash: lion-lithium-grey-cold
File name:CHQUE SWIFT COPY.JS
Download: download sample
Signature AgentTesla
File size:3'592'963 bytes
First seen:2026-07-23 13:42:32 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 98304:44cWO3eKPAQ5MrSh9f8Sh9QGwB00fE/n+iJ2YDu6aiWSKvWNA/Qwslsy9:ULbFQSrk0Jv/n+82Qu/WNL/lb
TLSH T11DF54B10E6642122919DDB3DC125FF68442D600B63B9EF0E37A895B4669AF07734EBF3
Magika javascript
Reporter James_inthe_box
Tags:AgentTesla exe js

Intelligence


File Origin
# of uploads :
1
# of downloads :
185
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug downloader dropper evasive obfuscated obfuscated packed repaired xloader
Verdict:
Malicious
File Type:
js
First seen:
2026-07-23T03:31:00Z UTC
Last seen:
2026-07-23T10:16:00Z UTC
Hits:
~100
Gathering data
Result
Malware family:
donutloader
Score:
  10/10
Tags:
family:agenttesla family:donutloader collection execution keylogger loader persistence spyware stealer trojan
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
outlook_office_path
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Executes a command shell one-liner
Accesses Microsoft Outlook profiles
Looks up external IP address via web service
Checks computer location settings
Executes dropped EXE
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Detects DonutLoader
Family: AgentTesla
Family: DonutLoader
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments