MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b721bbe345a775c346e36af404ea28602c92ed7b7f451b1b9eb4e5aac6bbe976. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 11


Intelligence 11 IOCs YARA File information Comments

SHA256 hash: b721bbe345a775c346e36af404ea28602c92ed7b7f451b1b9eb4e5aac6bbe976
SHA3-384 hash: 1a364845efcb6f958fa20e883738a35503bbd52ec88abb13f26ecd30e69d22f379ff6668843d170acab1e9f941cc674c
SHA1 hash: 0631d8b428ef85e1ae5ca04460b7a7dd73f138b4
MD5 hash: 333b7c65d9d95c045d2847a95abffbed
humanhash: nevada-nitrogen-batman-may
File name:Proforma Invoice No. 00124 - CONFIRM.JS
Download: download sample
Signature AgentTesla
File size:3'410'540 bytes
First seen:2026-08-04 01:43:32 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 98304:wOdQf/H+qxoJAFkYimTGINWfM3m1bccdQm+bo0jqP+LbJMyr:wv/H+/m2pvIAfA5m6qWJMyr
TLSH T1F5F5C4421788A032777A679C533AE930D90B919714C9DF16347CD228BF6CE1793E8AF6
Magika javascript
Reporter nat
Tags:AgentTesla js

Intelligence


File Origin
# of uploads :
1
# of downloads :
175
Origin country :
TH TH
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug dbatloader downloader dropper evasive formbook masquerade obfuscated obfuscated packed repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-08-03T06:25:00Z UTC
Last seen:
2026-08-05T23:10:00Z UTC
Hits:
~1000
Gathering data
Threat name:
Script-JS.Spyware.Negasteal
Status:
Malicious
First seen:
2026-08-03 09:40:19 UTC
File Type:
Text (JavaScript)
AV detection:
13 of 24 (54.17%)
Threat level:
  2/5
Result
Malware family:
agenttesla
Score:
  10/10
Tags:
family:agenttesla collection discovery execution keylogger spyware stealer trojan
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of NtSetInformationThreadHideFromDebugger
Accesses Microsoft Outlook profiles
Looks up external IP address via web service
Checks computer location settings
Executes dropped EXE
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Family: AgentTesla
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments