810430cb80a2b4d0cfb713a72dcb40c148f5494ae06b904ebe019e8f61b79d63
Classification: Malicious
810430cb80a2b4d0cfb713a72dcb40c148f5494ae06b904ebe019e8f61b79d63 is a malicious file sample. Linked to Agent Tesla malware.
Detection summary
- 0 antivirus detections
- 0 IDS alerts
- 5 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: AGENT TESLA (S0331)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2024-10-02 08:36:54 | 2026-09-02 16:45:06 | malicious-activity | |
| AgentTesla | MalwareBazaar Abuse.ch | 2024-10-02 08:21:59 | 2024-10-02 08:21:59 | malicious-activity | S0331 Agent Tesla |
Tags
evasive windows-server-utility infostealerSample information
- Filenames
- 810430cb80a2b4d0cfb713a72dcb40c148f5494ae06b904ebe019e8f61b79d63, TEKLİF TALEP VE FİYAT TEKLİFİ_xlsx.exe, TEKLİF TALEP VE FİYAT TEKLİFİ_xlsx.exe
- File type
- PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
- Size
- 770048 bytes
- MD5
6d59e320844353e2006021b4f44598b9- SHA-1
3b41aca9c2823a30611522c424ffb408d850188c- SHA-256
810430cb80a2b4d0cfb713a72dcb40c148f5494ae06b904ebe019e8f61b79d63- First indexed
- 2024-10-02 08:25:39
- Last updated
- 2026-09-02 16:45:06
Process list
| Name | Command line |
|---|---|
| TEKL_FTALEPVEF_YATTEKL_F__xlsx.exe | |
| powershell.exe | Add-MpPreference -ExclusionPath "C:\TEKL_FTALEPVEF_YATTEKL_F__xlsx.exe" |
| powershell.exe | Add-MpPreference -ExclusionPath "%APPDATA%\LuYBkKnuHvp.exe" |
| schtasks.exe | /Create /TN "Updates\LuYBkKnuHvp" /XML "%TEMP%\tmp4A92.tmp" |
| TEKL_FTALEPVEF_YATTEKL_F__xlsx.exe | |