Agent Tesla - Malware Samples
500 samples tracked (rolling 30 days)
Last updated: 2026-06-26
This page lists the most recent Agent Tesla malware samples collected from MalwareBazaar. Each entry includes the SHA256 hash (linked to the MalwareBazaar sample page), original file name, file type, size, and VirusTotal detection rate where available. Samples are updated daily and retained for a rolling 30-day window.
How to Use This Data
Security teams can use these hashes in several ways. Import them into your SIEM or EDR platform to detect known Agent Tesla variants in your environment. Cross-reference file names against your email gateway logs to identify phishing campaigns delivering this family. The file type distribution reveals which delivery formats are currently in use - a shift from .exe to .msi or .js may indicate the operators are adapting to your defenses. Samples with low or missing VirusTotal detection rates are the most dangerous - these are fresh variants that may bypass signature-based protection.
About the Data
All samples are sourced from MalwareBazaar, a free malware sample sharing platform operated by abuse.ch. Detection rates come from VirusTotal. This data is provided for defensive purposes only. For the latest Agent Tesla indicators of compromise including C2 servers and domains, see the IOC page.
| SHA256 | File Name | Type | Size | Detection | First Seen | Country |
|---|---|---|---|---|---|---|
| 51ce23480bb91da1... | SecuriteInfo.com.FileRepMalware.35212541 | exe | 609.1 KB | 40/70 | 2026-06-26 | - |
| b0e94f6295e469e7... | NEW-ORDER-EXPORT1234244.exe | exe | 627.7 KB | 40/70 | 2026-06-26 | - |
| ebcd88eefbf66c31... | HSBC_PAYMENT_ADVISE.js | js | 1.8 MB | 26/60 | 2026-06-26 | - |
| fcdfc76171113214... | SWIFT_Payment_Receipt_25062026.exe | exe | 596.1 KB | 47/70 | 2026-06-26 | - |
| 30589245784138e5... | PI No.358 - SPB ñ FCL.tar | tar | 282.2 KB | 16/62 | 2026-06-25 | - |
| ee35b5d05f075965... | PO250000Corbela.js | js | 1.6 MB | 28/60 | 2026-06-25 | - |
| b481b6034d399f7f... | MCPO-0178-0179.exe | exe | 224.4 KB | 29/69 | 2026-06-25 | - |
| d7a9ec8f2af174b5... | payload.js | js | 880.7 KB | 5/55 | 2026-06-24 | - |
| bfbfc055824ea3e0... | Quote 240145.vbs | vbs | 2.4 MB | 25/60 | 2026-06-24 | - |
| 013e0807afdbbe14... | PURCHASE ORDER.js | js | 1.5 MB | 22/59 | 2026-06-23 | - |
| 059f89bc7b83b669... | 00992883xeroxscan.exe | exe | 219.8 KB | - | 2026-06-23 | - |
| db59ee3698f5ef62... | PO-147290.JS | js | 3.2 MB | - | 2026-06-23 | - |
| 78fe34cb9cbde2fb... | Estado de cuenta de reembolso de pago.JS | js | 3.2 MB | - | 2026-06-23 | - |
| 5b376f070770cc01... | nsc.hta | hta | 33.6 KB | - | 2026-06-23 | - |
| 8a7d33c292edfc76... | mobbbbi gee.hta | hta | 35.6 KB | - | 2026-06-23 | - |
| 921f390d5cff31a4... | overdue invoice.hta | hta | 33.3 KB | - | 2026-06-23 | - |
| 63960c6aa8b507e1... | Quotation.vbs | vbs | 1.9 MB | - | 2026-06-23 | - |
| 24f8892321f28698... | LPD-Home-Quote-Request.JS | js | 5.4 MB | - | 2026-06-23 | - |
| f1099d8d2c3b6cb2... | New PO P453691.JS | js | 3.2 MB | - | 2026-06-23 | - |
| a16287ca39603813... | doc000621026006.JS | js | 3.6 MB | - | 2026-06-22 | - |
| a52d3a7d53a18ad4... | Zahlungsnachweis.JS | js | 3.2 MB | - | 2026-06-22 | - |
| cf9161ef4c3a30e7... | doc-22305447dubai proposal2026.JS | js | 3.6 MB | - | 2026-06-22 | - |
| 9743d3cf43fd03b0... | DHL_456865.PDF.JS | js | 3.6 MB | - | 2026-06-22 | - |
| 22664b468509d5a3... | SOA MAY 2026.JS | js | 3.6 MB | - | 2026-06-22 | - |
| 507224977a9112b7... | Request for Quotation FPG SDN RFQ260619_Pdf.JS | js | 3.2 MB | - | 2026-06-22 | - |
| c8783cbbf98e577e... | 2026.06.22 Juni.pdf.js | js | 107.7 KB | - | 2026-06-22 | - |
| f5dc559fb2d25f2f... | Request for Quotation FPG SDN RFQ260619_Pdf.js | js | 33.6 KB | - | 2026-06-22 | - |
| 3205d3115baa4425... | Quotation 6000042898 AUTOLIV ROMANIA SRL.JS | js | 3.2 MB | - | 2026-06-22 | - |
| d62f4ce1e36efc4a... | Invoice-01972.JS | js | 3.6 MB | - | 2026-06-22 | - |
| aa074f6fbba3f59d... | Request for Quotation FPG SDN RFQ260619.JS | js | 3.2 MB | - | 2026-06-22 | - |
| f1511d38d6b64d36... | Urgent part P14797-24-A.JS | js | 3.2 MB | - | 2026-06-22 | - |
| 65b38711711172a1... | PDT5737083-HTCOSF0736.hta | hta | 32.7 KB | - | 2026-06-22 | - |
| 12a0143bf4da5fdd... | Nowe zamówienie PO-2087441006.hta | hta | 36.2 KB | - | 2026-06-22 | - |
| d19a522185230969... | NEW QUOTATION.hta | hta | 31.1 KB | - | 2026-06-22 | - |
| acdf019b7899b10a... | PAGO FACTURA.JS | js | 3.2 MB | - | 2026-06-22 | - |
| 05c491f3252964d7... | FACTURA 0027560.JS | js | 3.2 MB | - | 2026-06-22 | - |
| b89249511d088ee5... | Estado de cuenta de reembolso de pago.JS | js | 3.2 MB | - | 2026-06-22 | - |
| 63a6137794416354... | doc_Ref0000001_pdf.js | js | 41.9 KB | - | 2026-06-22 | - |
| fa74415147a3f022... | SGC-MSH-CPR-26-170601.JS | js | 3.2 MB | - | 2026-06-22 | - |
| 8ad65f2edc59082f... | PURCHASE ORDER.js | js | 1.5 MB | - | 2026-06-22 | - |
| 81301f724ee7b7a4... | REQN_MF-E-26-019~028pdf.vbe | vbe | 48.1 KB | - | 2026-06-22 | - |
| 3ef93bcdc790775d... | Letter_of_Intent_LOI_pdf.vbs | vbs | 18.7 KB | - | 2026-06-22 | - |
| 345c5005adad32db... | Orden de compra POF0000095.vbs | vbs | 1.8 MB | - | 2026-06-22 | - |
| 1d47d23590a3fa04... | Directrices de políticas para empleados_2026.pdf.exe | exe | 370.2 KB | - | 2026-06-22 | - |
| 99bee9c7498d8bbf... | Quote-034600_500 KB.exe | exe | 1.1 MB | - | 2026-06-22 | - |
| 2009c2095160ce4c... | Scan002233220626.exe | exe | 229.4 KB | - | 2026-06-22 | - |
| 6ceb1540bb2e1a52... | Order959858868-699686767696.exe | exe | 237.9 KB | - | 2026-06-22 | - |
| 3dd7e1077e79e24d... | Directrices de políticas para empleados 2026.exe | exe | 366.9 KB | - | 2026-06-22 | - |
| 49457f4873d15deb... | Cs2Hack.exe | exe | 96.0 KB | 40/70 | 2026-06-20 | - |
| dc12faa460faab18... | P.O #77644..JS | js | 3.2 MB | 25/59 | 2026-06-19 | - |
| d6447792486b2abb... | Remittance Copy.2026-19-6.pdf.JS | js | 3.2 MB | 25/60 | 2026-06-19 | - |
| bfbb0a7e74db621c... | PAYMENT - INVOICE .NO. QFB-18-06 - 2026.JS | js | 3.6 MB | 24/60 | 2026-06-19 | - |
| 5593330d791aca75... | Commercial_Invoice.bat | exe | 496.7 KB | 31/69 | 2026-06-19 | - |
| b3e6f481349149ac... | Commercial_Invoice.tar | tar | 500.0 KB | 23/61 | 2026-06-19 | - |
| 61c5833831b300b9... | Orden de compra POF0000095.vbs | vbs | 1.8 MB | 25/59 | 2026-06-19 | - |
| 836e2235a35bbe9b... | Notificación de transacción BBVA n.º 0000245 Pedido del cliente n.º 76890.js | js | 15.4 MB | 12/60 | 2026-06-18 | - |
| bc37921377b4fe39... | Vessel_Description_Particulars.pdf.bat | exe | 963.5 KB | 47/65 | 2026-06-18 | - |
| 36436e163209fd79... | BIK1910486_20260618.js | js | 655.2 KB | 22/60 | 2026-06-18 | - |
| 597a70be6838e1c5... | Purchase Order No. 25-26266.zip | zip | 1.4 MB | - | 2026-06-18 | - |
| 251d17c39b20cdd7... | Purchase Order - PO.zip | zip | 1.4 MB | - | 2026-06-18 | - |
| 448b6f8ac2a740cb... | New PO for bulk order.zip | zip | 1.4 MB | - | 2026-06-18 | - |
| b7e0dcd4f0b7db95... | nDocumentos_Datos_Bancarios_17062026_xml.bz2 | rar | 17.5 KB | - | 2026-06-17 | - |
| 488a04dd1b79adde... | rDocumentos_Datos_Bancarios_17062026_xml.wsf | wsf | 43.4 KB | - | 2026-06-17 | - |
| 5b7146ddfce30ff5... | crypted_f1e94135.exe | exe | 1.6 MB | - | 2026-06-17 | - |
| afb2a9d47c0786a7... | SHIPING DOCUMENTS 39952312.JS | js | 3.5 MB | - | 2026-06-17 | - |
| e8fe51be55737313... | Purchase Inquiry-89765456747.rar | rar | 21.9 KB | - | 2026-06-17 | - |
| 9cb040c0df025901... | PAYMENT - INVOICE .NO. QFB-15-06 - 2026.JS | js | 3.5 MB | - | 2026-06-17 | - |
| 07a018c6af370b03... | Items For Quote.exe | exe | 969.5 KB | - | 2026-06-17 | - |
| a9c435768ee164b6... | Aviso de pago.xml.wsf | wsf | 38.5 KB | - | 2026-06-17 | - |
| f138d8f7d5bdbeac... | eec3a2227cc2a468f4da59f593ecd216.exe | exe | 47.0 KB | - | 2026-06-17 | - |
| 0e79179b62a46576... | ae8c8b5b455dd6cff53fc77bb3333497.exe | exe | 47.0 KB | - | 2026-06-17 | - |
| 14f62053739732d9... | rzdtyigydgthyfgjmuhk.exe | exe | 1.1 MB | - | 2026-06-17 | - |
| fcda75eb7bc30baf... | PO_5778.js | js | 23.4 MB | - | 2026-06-17 | - |
| 093b27955f0d326e... | ShoulderAliasesPediatricAlrightPartitions_EnduranceGuardiansNearestCautious.exe | exe | 347.0 KB | - | 2026-06-17 | - |
| f16b1132787a8991... | InevitablyDraggingHilfiger_BloombergNightclubEvidence.exe | exe | 65.5 KB | - | 2026-06-17 | - |
| 08e895274092d92b... | BIK1910486_20260616.js | js | 980.3 KB | - | 2026-06-16 | - |
| b37c715ffd26966a... | KJHFHJHJ34.js | js | 34.9 KB | - | 2026-06-16 | - |
| eedaa2e28f5b4464... | #PL ISTinv.JS | js | 3.5 MB | - | 2026-06-15 | - |
| 0ca1f5f738e604a7... | fmzfmwha.JS | js | 3.5 MB | - | 2026-06-15 | - |
| 96e22da4d5c0ea4b... | Quotatin-HKT Marine- Belgorod--ODME.JS | js | 3.5 MB | - | 2026-06-15 | - |
| dade827559fd38f2... | invoice.JS | js | 3.5 MB | - | 2026-06-15 | - |
| 592d04f599e74368... | Order006015202600.JS | js | 3.5 MB | - | 2026-06-15 | - |
| b5a07b0143689e8a... | New Purchase 0BLQO935.JS | js | 3.5 MB | - | 2026-06-15 | - |
| be9c17a6e0b2cf14... | 261F0001477-00548F.JS | js | 3.4 MB | - | 2026-06-15 | - |
| 8ca5fd18b28ccbaf... | doc90237899010260615.JS | js | 3.5 MB | - | 2026-06-15 | - |
| 2b16e197fc68d40d... | Invoice.JS | js | 3.4 MB | - | 2026-06-15 | - |
| 83f9b935de576d5f... | PURCHASE ORDER 150626.110238.JS | js | 3.4 MB | - | 2026-06-15 | - |
| 10ace64cc4a574ee... | Purchase order BPD-003455 - Copy.JS | js | 3.4 MB | - | 2026-06-15 | - |
| bb5fdae6b68a6a3a... | Comprobante de pago.JS | js | 3.4 MB | - | 2026-06-15 | - |
| 3f134e8a51b64911... | Purchase Order NO5100010780.JS | js | 3.5 MB | - | 2026-06-15 | - |
| 52fdc47f680002ef... | Invoice Document 2026-15-6.JS | js | 3.4 MB | - | 2026-06-15 | - |
| f70e007f742ccf69... | invoice and account details.JS | js | 3.5 MB | - | 2026-06-15 | - |
| 4f56842b8f540a4b... | Payment Confirmation-00103.JS | js | 3.4 MB | - | 2026-06-15 | - |
| 85bee0feb1e8263b... | Transfer Detayları 61526.js | js | 1.5 MB | - | 2026-06-15 | - |
| 01621746f16ecfcd... | njhzswnl.JS | js | 3.4 MB | - | 2026-06-15 | - |
| 8996cbc60a9dc1b0... | PO#LHPE00044.JS | js | 3.5 MB | - | 2026-06-15 | - |
| bc9f105b6d2ca481... | 20260615-001173.js | js | 85.5 KB | - | 2026-06-15 | - |
| 365f6bdd30765b0e... | Transferencia.JS | js | 3.5 MB | - | 2026-06-15 | - |
| f491cda4469903da... | JUSTIFICANTE DE PAGO.JS | js | 3.5 MB | - | 2026-06-15 | - |
| 01b37f0d37df249f... | PO 008-01.JS | js | 3.4 MB | - | 2026-06-15 | - |