submitted timesheet Sept 2020_0987.xls
Classification: Malicious
submitted timesheet Sept 2020_0987.xls is a malicious file sample. Linked to Ta505 activity. Reported by 1 threat source, last seen 2020-09-02.
Detection summary
- 17 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Intrusion sets: TA505 (G0092)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| TA505 | Abuse.ch | 2020-09-02 12:13:50 | 2020-09-02 12:13:50 | G0092 TA505 |
Sample information
- Filenames
- submitted timesheet Sept 2020_0987.xls
- File type
- application/vnd.ms-excel
- MD5
1b91a22b966d1a89be7701aa6f8f60bf- SHA-1
fc9599ec756d97cf2806d77bb1cefbb5c48e4dfe- SHA-256
d7c174026af455cf1a1da6f15c08f5e6cb231c67d9befabd6f0786155522a34f- First indexed
- 2020-09-02 13:15:04
- Last updated
- 2026-05-03 09:06:22
Antivirus detections
| Engine | Detection |
|---|---|
| Elastic | malicious (moderate confidence) |
| MicroWorld-eScan | VBA:Logan.2 |
| ALYac | VBA:Logan.2 |
| Sangfor | Malware |
| Kaspersky | HEUR:Trojan-Downloader.Win32.Gangola.vho |
| BitDefender | VBA:Logan.2 |
| Rising | Dropper.StealthLoader/VBA!1.C75E (CLASSIC:2nmRHxkKwZdmYl71F2cFpA) |
| Ad-Aware | VBA:Logan.2 |
| FireEye | VBA:Logan.2 |
| Arcabit | VBA:Logan.2 |
| ZoneAlarm | HEUR:Trojan-Downloader.Win32.Gangola.vho |
| GData | VBA:Logan.2 |
| McAfee | W97M/Downloader.dds |
| MAX | malware (ai score=81) |
| VBA32 | Malware-Cryptor.Bambarbiya |
| ESET-NOD32 | a variant of Win64/Kryptik.BZZ |
| Fortinet | W64/Kryptik.BVG!tr |