Xls.Malware.Sload-7135989-0 — RTF malware analysis

Static analysis result for SHA-256 298c2ae3ca43faab…

MALICIOUS

RTF

789.6 KB Created: 2018-07-17 13:54:00 First seen: 2019-03-18
MD5: 53e592d0ed2274c7062aa5cf31ba1ca6 SHA-1: 88d3cc90348e9256f89f5b6d0a99891b5b161713 SHA-256: 298c2ae3ca43faabcd4fa4669fd93e249375efb6c7f7beac6f5e94649ddb9066
242 Risk Score

Malware Insights

Xls.Malware.Sload-7135989-0 · confidence 95%

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple OLE objects, with heuristics indicating ".objupdate" forces OLE activation and the presence of Composite Monikers. ClamAV signatures identify the embedded content as Xls.Malware.Sload-7135989-0, suggesting an exploit targeting spreadsheet functionality. The primary attack vector is likely spearphishing, with the embedded OLE object serving as the malicious payload.

Heuristics 6

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • ClamAV: Xls.Malware.Sload-7135989-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Malware.Sload-7135989-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00003c2d.bin rtf-objdata-decoded RTF \objdata at offset 0x3C2D 27195 bytes
SHA-256: 46f56a27519430b7ec47e03acd8b2a75ba5fd726fa37fd83c26ea094045a85b7
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_01_off00016899.bin rtf-objdata-decoded RTF \objdata at offset 0x16899 27195 bytes
SHA-256: 2b5a464758b55e1f6c47688d3fa872453fdea80262fdd0180743621dbfe17dad
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_02_off00029505.bin rtf-objdata-decoded RTF \objdata at offset 0x29505 27195 bytes
SHA-256: 682165faa4349a43286d7676a2ff51cf177af52cc852473854eb0dbc944d4786
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_03_off0003c171.bin rtf-objdata-decoded RTF \objdata at offset 0x3C171 27195 bytes
SHA-256: 64173cb232dd697265a4b494f7d235ffb4d5652ba6821568c2b0d7d3dd4eafa4
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_04_off0004eddd.bin rtf-objdata-decoded RTF \objdata at offset 0x4EDDD 27195 bytes
SHA-256: a8507561c97139fde3c9ab675d5fff17ad1d03807a66136ca8c3dbe1b43aaf3a
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_05_off00062859.bin rtf-objdata-decoded RTF \objdata at offset 0x62859 27195 bytes
SHA-256: da0c19b9b001b47a43aae468bdac1f290943623b9fb051bcbfa3651423f2ab20
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_06_off000754e4.bin rtf-objdata-decoded RTF \objdata at offset 0x754E4 27195 bytes
SHA-256: 36456cc7adeedb1c7e366322cc100568881f3248ea75e2782c3aa0b9cf807f36
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_07_off00088171.bin rtf-objdata-decoded RTF \objdata at offset 0x88171 27195 bytes
SHA-256: fdaa6c56563d6fa21a5d76c21327801bb1686d44e1b9ad2720c74207991c2bed
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_08_off0009adfe.bin rtf-objdata-decoded RTF \objdata at offset 0x9ADFE 27195 bytes
SHA-256: f4b6dced96360bca9b350afbde4a9ed8c1cb1120ce62f8cacc3a76177aa75ef8
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_09_off000ada8b.bin rtf-objdata-decoded RTF \objdata at offset 0xADA8B 27195 bytes
SHA-256: 45196a82c086b876fc5b9d9b6830cec9d34749ea314b9ff10ec0d34420555409
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely