CHQ020114862.xls
Classification: Malicious
CHQ020114862.xls is a malicious file sample. Linked to Ta505 activity. Reported by 1 threat source, last seen 2020-07-03. Detected by 27 antivirus engines.
Detection summary
- 27 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Intrusion sets: TA505 (G0092)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| TA505 | Abuse.ch | 2020-07-03 10:12:51 | 2020-07-03 10:12:51 | G0092 TA505 |
Sample information
- Filenames
- CHQ020114862.xls
- File type
- application/vnd.ms-excel
- MD5
bb921af7b9c502c207b6f40fa9937cb7- SHA-1
c205c932952bfa8acfee0f4fb8aee0d0d27608e1- SHA-256
02ec074f0269a8c818c9c7909b0a199ef6eda4e345e2b1517d09244fe4ab7dd9- First indexed
- 2020-07-03 11:15:03
- Last updated
- 2026-03-26 11:19:12
Antivirus detections
| Engine | Detection |
|---|---|
| ClamAV | Win.Dropper.Hideproc-6663113-0 |
| FireEye | VB:Trojan.Valyria.3290 |
| McAfee | X97M/Dropper.ad |
| Arcabit | VB:Trojan.Valyria.DCDA |
| BitDefenderTheta | Gen:NN.ZedlaF.34130.tu4@aujb2Ki |
| Symantec | ISB.Exploit!gen9 |
| ESET-NOD32 | a variant of VBA/TrojanDropper.Agent.BHV |
| Cynet | Malicious (score: 85) |
| Kaspersky | HEUR:Trojan.MSOffice.SAgent.gen |
| BitDefender | VB:Trojan.Valyria.3290 |
| MicroWorld-eScan | VB:Trojan.Valyria.3290 |
| Rising | Dropper.StealthLoader/VBA!1.C75D (CLASSIC:dGZlOgbmVzPg3k21qQ) |
| Ad-Aware | VB:Trojan.Valyria.3290 |
| F-Secure | Heuristic.HEUR/Macro.Downloader.MRUZ.Gen |
| Emsisoft | VB:Trojan.Valyria.3290 (B) |
| Avira | HEUR/Macro.Downloader.MRUZ.Gen |
| Fortinet | W32/Dropper.GIF!tr |
| Antiy-AVL | Trojan[Exploit]/OLE.CVE-2014-6352 |
| Endgame | malicious (high confidence) |
| ZoneAlarm | HEUR:Trojan.MSOffice.SAgent.gen |
| TACHYON | Suspicious/W97.NS.Gen |
| AhnLab-V3 | Dropper/XLS.TA505.S1242 |
| ALYac | VB:Trojan.Valyria.3290 |
| MAX | malware (ai score=80) |
| VBA32 | BScope.Trojan.Wacatac |
| SentinelOne | DFI - Malicious OLE |
| GData | VB:Trojan.Valyria.3290 |