Xls.Malware.Sload-7135989-0 — RTF malware analysis

Static analysis result for SHA-256 1259ee90dfbfd093…

MALICIOUS

RTF

739.3 KB Created: 2018-07-13 12:57:00 First seen: 2019-05-16
MD5: a1bf81348819dd7904fea2029150e0fa SHA-1: 782fa11918cf59bd1c871d19f5a759dde17d8db3 SHA-256: 1259ee90dfbfd09317a198bce3c1e0473bf3ea43601d389c60fe6ce930c28dea
242 Risk Score

Malware Insights

Xls.Malware.Sload-7135989-0 · confidence 95%

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple OLE objects, with heuristics indicating ".objupdate" forces OLE activation and the presence of Composite Monikers. ClamAV signatures identify the embedded content as Xls.Malware.Sload-7135989-0, suggesting an exploit targeting spreadsheet functionality. The primary attack vector is likely spearphishing, with the embedded OLE object serving as the malicious payload.

Heuristics 6

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • ClamAV: Xls.Malware.Sload-7135989-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Malware.Sload-7135989-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00003c40.bin rtf-objdata-decoded RTF \objdata at offset 0x3C40 24635 bytes
SHA-256: 5f0081617ef39983bb3c91817f5428033921f9f54af26de9d53c89b2e68976ea
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_01_off00015486.bin rtf-objdata-decoded RTF \objdata at offset 0x15486 24635 bytes
SHA-256: 94506b5eaa1cfe007320d82afa1ee9ee8f3fd3e0f5b8020e5f2d90b327d38e2a
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_02_off00026ccc.bin rtf-objdata-decoded RTF \objdata at offset 0x26CCC 24635 bytes
SHA-256: 90e72921b089aca1f04ca1a756de67d0546c6004db7752bc3b354bd4f3e58cfa
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_03_off00038512.bin rtf-objdata-decoded RTF \objdata at offset 0x38512 24635 bytes
SHA-256: 87cbb181b51a685e727ef0c5b067aa22f02ed0dbf888552f297e55d813193502
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_04_off00049d58.bin rtf-objdata-decoded RTF \objdata at offset 0x49D58 24635 bytes
SHA-256: 6cc235850e7bb48c0ce2683ab593352f618e3760961baed3e14508fa43aae741
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_05_off0005c3ba.bin rtf-objdata-decoded RTF \objdata at offset 0x5C3BA 24635 bytes
SHA-256: b2ef44fae175483e53856be8e17a3d6b7976118b2ea9e349b82569d0ae63bb4f
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_06_off0006dc1e.bin rtf-objdata-decoded RTF \objdata at offset 0x6DC1E 24635 bytes
SHA-256: 9cc9bc1573cd03e030ab4d8813df175586c499a514c40009e7a862b8f3f42190
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_07_off0007f484.bin rtf-objdata-decoded RTF \objdata at offset 0x7F484 24635 bytes
SHA-256: a24a98da81a343d58e724d42f320ed6add4d7fafe72730a207756beb55473520
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_08_off00090cea.bin rtf-objdata-decoded RTF \objdata at offset 0x90CEA 24635 bytes
SHA-256: ab04e368533ef596b4bb951a5e0b9401fbf95a55e4da51a4a6ae7a66bbb0151a
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_09_off000a2550.bin rtf-objdata-decoded RTF \objdata at offset 0xA2550 24635 bytes
SHA-256: 198d62597e3813258a0279209966593876b9e83cfa587ed72b7d7fab307d050b
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely