2020_06_22_harvest_expense_report.xls

Classification: Malicious

2020_06_22_harvest_expense_report.xls is a malicious file sample. Linked to Ta505 activity. Reported by 1 threat source, last seen 2020-06-22.

Detection summary

  • 21 antivirus detections
  • 0 IDS alerts
  • 0 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Intrusion sets: TA505 (G0092)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
TA505 Abuse.ch 2020-06-22 12:23:38 2020-06-22 12:23:38 G0092 TA505

Sample information

Filenames
2020_06_22_harvest_expense_report.xls
File type
application/vnd.ms-excel
MD5
e796d64a1dbe3675a6d7ae12f33c8ca2
SHA-1
4b0cdda90016315194f56d600772254590dde472
SHA-256
2a520ba3cbc0dc830b35ee739b49c78e01932712ff61ab2e300d65a24c21810e
First indexed
2020-06-22 14:15:07
Last updated
2026-03-07 07:49:40

Antivirus detections

EngineDetection
ClamAVWin.Dropper.Hideproc-6663113-0
CynetMalicious (score: 85)
BitDefenderVB:Trojan.Valyria.3290
MicroWorld-eScanVB:Trojan.Valyria.3290
RisingDropper.StealthLoader/VBA!1.C75E (CLASSIC)
Ad-AwareVB:Trojan.Valyria.3290
F-SecureHeuristic.HEUR/Macro.Downloader.MRUZ.Gen
McAfee-GW-EditionBehavesLike.Dropper.jg
FireEyeVB:Trojan.Valyria.3290
EmsisoftVB:Trojan.Valyria.3290 (B)
SentinelOneDFI - Malicious OLE
AviraHEUR/Macro.Downloader.MRUZ.Gen
MAXmalware (ai score=83)
Antiy-AVLTrojan[Exploit]/OLE.CVE-2014-6352
MicrosoftTrojanDropper:O97M/GraceWire.ARJ!MTB
Endgamemalicious (high confidence)
ArcabitVB:Trojan.Valyria.DCDA
AegisLabTrojan.MSExcel.Valyria.4!c
GDataVB:Trojan.Valyria.3290
ZonerProbably Heur.W97Obfuscated
Qihoo-360virus.office.qexvmc.1065