🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a8f82c5a5ad3d41ba6ab4f6e71706b99131cd8c7537369bf127ba2d99e83da64. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: a8f82c5a5ad3d41ba6ab4f6e71706b99131cd8c7537369bf127ba2d99e83da64
SHA3-384 hash: 49aff86bcf4e55a625fcab81d26ec5a9101b35cc64cb68124a7724a33b17a5f7ce001be356bc9340c44773034b851495
SHA1 hash: 9c6dfa9deeb4807b104346c52ca4247379c0d866
MD5 hash: 6f0a60d7e4a5bba100fba08eb8cc3691
humanhash: hydrogen-three-undress-pluto
File name:RFQ AUG12 2026.JS
Download: download sample
Signature AgentTesla
File size:3'344'454 bytes
First seen:2026-08-13 03:04:36 UTC
Last seen:2026-08-18 19:14:34 UTC
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 98304:lp7XoaS4AwHOSsG0aQDLmKn5XL7qHFbI20sy9vkPBb4PnQHO6E/n:TD84nHOo015XCMTGUYHLEv
TLSH T196F5C347A272F74EF0A829284E6E1B94593DF6E3F75798033B3C15B60B14FE12365922
Magika javascript
Reporter nat
Tags:AgentTesla js

Intelligence


File Origin
# of uploads :
2
# of downloads :
155
Origin country :
TH TH
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug dropper evasive obfuscated obfuscated packed repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-08-12T05:34:00Z UTC
Last seen:
2026-08-15T01:23:00Z UTC
Hits:
~10000
Gathering data
Threat name:
Script-JS.Trojan.Sabsik
Status:
Malicious
First seen:
2026-08-12 12:32:01 UTC
File Type:
Text (JavaScript)
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
AgentTesla DonutLoader
Result
Malware family:
donutloader
Score:
  10/10
Tags:
family:agenttesla family:donutloader collection discovery execution keylogger loader spyware stealer trojan
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Accesses Microsoft Outlook profiles
Looks up external IP address via web service
Checks computer location settings
Executes dropped EXE
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Detects DonutLoader
Family: AgentTesla
Family: DonutLoader
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments