Xls.Malware.Sload-7135989-0 — RTF malware analysis

Static analysis result for SHA-256 27acf8591395927a…

MALICIOUS

RTF

789.6 KB Created: 2018-07-17 14:19:00 First seen: 2019-03-18
MD5: 00cbfd366e54e906c97400b76ab2a5f2 SHA-1: 16ad2c98a4a635355014d274f88326da7a8af398 SHA-256: 27acf8591395927a9ccff7dc794ebe05e07fba9955e043850a87c8b59a859999
242 Risk Score

Malware Insights

Xls.Malware.Sload-7135989-0 · confidence 95%

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple OLE objects, with heuristics indicating ".objupdate" forces OLE activation and the presence of Composite Monikers. ClamAV signatures identify the embedded content as Xls.Malware.Sload-7135989-0, suggesting an exploit targeting spreadsheet functionality. The primary attack vector is likely spearphishing, with the embedded OLE object serving as the malicious payload.

Heuristics 6

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • ClamAV: Xls.Malware.Sload-7135989-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Malware.Sload-7135989-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00003c2d.bin rtf-objdata-decoded RTF \objdata at offset 0x3C2D 27195 bytes
SHA-256: d6b9929e70d5ee5d97d52ca9588760c84df6de632a012305d1aa558292614a06
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_01_off00016899.bin rtf-objdata-decoded RTF \objdata at offset 0x16899 27195 bytes
SHA-256: b4f84251aa009a4ffe6a4a8b7a0ee7027329795bd97b8a13920f52b50b1f8d19
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_02_off00029505.bin rtf-objdata-decoded RTF \objdata at offset 0x29505 27195 bytes
SHA-256: 2d179b3121932d1ce7f6d8d577d20ac9c0c297ec7b9d6c1c08ff5eac1f28b509
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_03_off0003c171.bin rtf-objdata-decoded RTF \objdata at offset 0x3C171 27195 bytes
SHA-256: 528b65ffe53290bd31cb1698e9be43b15c68cef55e86696429b0350d1155077e
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_04_off0004eddd.bin rtf-objdata-decoded RTF \objdata at offset 0x4EDDD 27195 bytes
SHA-256: 0f28a0c6bfb56a2b9f0ea694c06c69def9e31eeb5e603d8d84bd95b5ffc0b90f
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_05_off00062859.bin rtf-objdata-decoded RTF \objdata at offset 0x62859 27195 bytes
SHA-256: 3f5558c53a855c8dda98380b0242064d20250ead82a36c3492e7086800b7a3d7
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_06_off000754e4.bin rtf-objdata-decoded RTF \objdata at offset 0x754E4 27195 bytes
SHA-256: 865dcc425b85765c075f65500ce74b183a8907b0887c908b08599c9f9a22f359
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_07_off00088171.bin rtf-objdata-decoded RTF \objdata at offset 0x88171 27195 bytes
SHA-256: a848fee6b7097e617dbe73526343541e545809e635afaf896a497102e1bb6845
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_08_off0009adfe.bin rtf-objdata-decoded RTF \objdata at offset 0x9ADFE 27195 bytes
SHA-256: 5b7edbbaa456366decf7c29a9eb286a20b7f0fd3ddf7f565d14ab9e9f3ac1c2d
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_09_off000ada8b.bin rtf-objdata-decoded RTF \objdata at offset 0xADA8B 27195 bytes
SHA-256: 0988c83dcdcaf42611bf8dbbadd3fc6ff3994b257804e8a0c462540e70b30b7d
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely