submitted timesheet Sept 2020_0987.xls

Classification: Malicious

submitted timesheet Sept 2020_0987.xls is a malicious file sample. Linked to Ta505 activity. Reported by 1 threat source, last seen 2020-09-02.

Detection summary

  • 17 antivirus detections
  • 0 IDS alerts
  • 0 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Intrusion sets: TA505 (G0092)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
TA505 Abuse.ch 2020-09-02 12:13:50 2020-09-02 12:13:50 G0092 TA505

Sample information

Filenames
submitted timesheet Sept 2020_0987.xls
File type
application/vnd.ms-excel
MD5
1b91a22b966d1a89be7701aa6f8f60bf
SHA-1
fc9599ec756d97cf2806d77bb1cefbb5c48e4dfe
SHA-256
d7c174026af455cf1a1da6f15c08f5e6cb231c67d9befabd6f0786155522a34f
First indexed
2020-09-02 13:15:04
Last updated
2026-05-03 09:06:22

Antivirus detections

EngineDetection
Elasticmalicious (moderate confidence)
MicroWorld-eScanVBA:Logan.2
ALYacVBA:Logan.2
SangforMalware
KasperskyHEUR:Trojan-Downloader.Win32.Gangola.vho
BitDefenderVBA:Logan.2
RisingDropper.StealthLoader/VBA!1.C75E (CLASSIC:2nmRHxkKwZdmYl71F2cFpA)
Ad-AwareVBA:Logan.2
FireEyeVBA:Logan.2
ArcabitVBA:Logan.2
ZoneAlarmHEUR:Trojan-Downloader.Win32.Gangola.vho
GDataVBA:Logan.2
McAfeeW97M/Downloader.dds
MAXmalware (ai score=81)
VBA32Malware-Cryptor.Bambarbiya
ESET-NOD32a variant of Win64/Kryptik.BZZ
FortinetW64/Kryptik.BVG!tr