Xls.Malware.Sload-7135989-0 — RTF malware analysis

Static analysis result for SHA-256 20ba7a62ea217c16…

MALICIOUS

RTF

789.7 KB Created: 2018-07-17 13:55:00 First seen: 2019-04-18
MD5: 5fdc9394bbbecb8b59b938877a6f067c SHA-1: d10f78fac43b1d8b72ccaabcc0174c64f8d642e5 SHA-256: 20ba7a62ea217c16beadbb43b116a1b9834fd86689e15894353363d0c2839596
242 Risk Score

Malware Insights

Xls.Malware.Sload-7135989-0 · confidence 95%

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple OLE objects, with heuristics indicating ".objupdate" forces OLE activation and the presence of Composite Monikers. ClamAV signatures identify the embedded content as Xls.Malware.Sload-7135989-0, suggesting an exploit targeting spreadsheet functionality. The primary attack vector is likely spearphishing, with the embedded OLE object serving as the malicious payload.

Heuristics 6

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • ClamAV: Xls.Malware.Sload-7135989-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Malware.Sload-7135989-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00003c40.bin rtf-objdata-decoded RTF \objdata at offset 0x3C40 27195 bytes
SHA-256: fbbc32eb14b1590c2e36eb3139566fe6a69de1ed323edd05b4ff0944c1179c0d
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_01_off000168b0.bin rtf-objdata-decoded RTF \objdata at offset 0x168B0 27195 bytes
SHA-256: 98b15c508135835e8cc6518396ff43688587a4f6836390e5c80497f1ae363dc5
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_02_off00029520.bin rtf-objdata-decoded RTF \objdata at offset 0x29520 27195 bytes
SHA-256: e8d93305e69a11c17c1ebaf309119320d461aaf8bf7b95d8093c3a758ec19bef
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_03_off0003c190.bin rtf-objdata-decoded RTF \objdata at offset 0x3C190 27195 bytes
SHA-256: 58ca8e8a1cab0c9df2a9275f88eb55b58bc422aba61f04b3c72b3da62d279510
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_04_off0004ee00.bin rtf-objdata-decoded RTF \objdata at offset 0x4EE00 27195 bytes
SHA-256: 98f36643e820f9fb1e9fc5538624a3786078acd11ba6e17de075187dbec0d8b6
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_05_off0006288c.bin rtf-objdata-decoded RTF \objdata at offset 0x6288C 27195 bytes
SHA-256: a44e75c574068001c7bae75f5a22404af46f36789f5e5fda3bacec51635733f1
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_06_off0007551a.bin rtf-objdata-decoded RTF \objdata at offset 0x7551A 27195 bytes
SHA-256: 03ddce043d4ce6341d942b9f0914baad1b0b936fd9cf453a5a0c0c60ab8109bf
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_07_off000881aa.bin rtf-objdata-decoded RTF \objdata at offset 0x881AA 27195 bytes
SHA-256: 11d08ac8ccc2eb096fd021a4b4972f7e3102d1611284c29039dcc44a786bd2b8
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_08_off0009ae3a.bin rtf-objdata-decoded RTF \objdata at offset 0x9AE3A 27195 bytes
SHA-256: bc91aa8577ca02c72b99d2cfcd4c31494203cb35f9bc1800c104279ed726bde2
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_09_off000adaca.bin rtf-objdata-decoded RTF \objdata at offset 0xADACA 27195 bytes
SHA-256: 593d381bd1f0d57bfe1803bf632d91caa7a9768c9276f15a64e11d25ab2e7ba9
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely