MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 acdfb377eb9c6e5856320667956513ee6148b6fc1e484cef804ddaceedd7e57d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 13


Intelligence 13 IOCs YARA File information Comments

SHA256 hash: acdfb377eb9c6e5856320667956513ee6148b6fc1e484cef804ddaceedd7e57d
SHA3-384 hash: 278a2ed9f3d40cf835230e1725ae5669041f18c92862b37de82bb2abf317e78090662c32f0a38e1e2c1d645b6c7fa6e5
SHA1 hash: 3e599617176d88335dd5c763a0a6f210e9b06c92
MD5 hash: 4fa54218c2ed6c2411fd908e62c796a1
humanhash: winner-arizona-music-lithium
File name:Project.JS
Download: download sample
Signature AgentTesla
File size:3'714'037 bytes
First seen:2026-07-20 14:21:32 UTC
Last seen:2026-07-21 05:56:12 UTC
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 98304:R6zc7pYmae+aOs9Ph6KbdASANRcj18j2TMWzqV2g1Lwb6xyIWr/x0GJd:ROcSzIP6Kxhs1Lw+TC/xt
TLSH T1F8063A00A75CA472552FD72CF636EEAC951E204321C9CF5C306D9A34B66EE47A38D6E3
Magika javascript
Reporter James_inthe_box
Tags:AgentTesla exe js

Intelligence


File Origin
# of uploads :
2
# of downloads :
227
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
92.5%
Tags:
shell lien sage blic
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug downloader dropper evasive obfuscated obfuscated packed repaired xloader
Verdict:
Malicious
File Type:
js
First seen:
2026-07-20T12:13:00Z UTC
Last seen:
2026-07-22T09:18:00Z UTC
Hits:
~100
Gathering data
Threat name:
Script-JS.Trojan.Heuristic
Status:
Malicious
First seen:
2026-07-20 14:21:39 UTC
File Type:
Text (JavaScript)
AV detection:
11 of 24 (45.83%)
Threat level:
  2/5
Result
Malware family:
agenttesla
Score:
  10/10
Tags:
family:agenttesla collection discovery execution keylogger spyware stealer trojan
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Executes a command shell one-liner
System Location Discovery: System Language Discovery
Suspicious use of NtSetInformationThreadHideFromDebugger
Accesses Microsoft Outlook profiles
Looks up external IP address via web service
Checks computer location settings
Executes dropped EXE
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Family: AgentTesla
Malware family:
AgentTesla
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments