Xls.Malware.Sload-7135989-0 — RTF malware analysis

Static analysis result for SHA-256 3c4d29253e8970c7…

MALICIOUS

RTF

789.6 KB Created: 2018-07-17 14:22:00 First seen: 2019-05-10
MD5: ffaa4da3d45f920d4229b554aac5b791 SHA-1: 8cdd1ae2cdabc45782fb93fedbceecd718c36083 SHA-256: 3c4d29253e8970c7f8edbd0f3e2d09eaec570945b342516eb854727d1232b9f3
242 Risk Score

Malware Insights

Xls.Malware.Sload-7135989-0 · confidence 95%

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple OLE objects, with heuristics indicating ".objupdate" forces OLE activation and the presence of Composite Monikers. ClamAV signatures identify the embedded content as Xls.Malware.Sload-7135989-0, suggesting an exploit targeting spreadsheet functionality. The primary attack vector is likely spearphishing, with the embedded OLE object serving as the malicious payload.

Heuristics 6

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • ClamAV: Xls.Malware.Sload-7135989-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Malware.Sload-7135989-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00003c24.bin rtf-objdata-decoded RTF \objdata at offset 0x3C24 27195 bytes
SHA-256: 5a53684add536a3812545c3fa21f02a848326f029e73d4080c32905779cb7268
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_01_off00016890.bin rtf-objdata-decoded RTF \objdata at offset 0x16890 27195 bytes
SHA-256: e3306b70a454cfd8e2e48ee41ca6f73c8f3dd45d10b4da811b8d4be7bd7e0cdb
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_02_off000294fc.bin rtf-objdata-decoded RTF \objdata at offset 0x294FC 27195 bytes
SHA-256: 8035d7e72c6b22d9ed67fdd67f22a41eb3a2fd1880efe7924f762206ea94dc3e
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_03_off0003c168.bin rtf-objdata-decoded RTF \objdata at offset 0x3C168 27195 bytes
SHA-256: 4294f6d0ecabafad42302cac299c2d2e587b5243f479baf1b5d3da628ca5d5e3
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_04_off0004edd4.bin rtf-objdata-decoded RTF \objdata at offset 0x4EDD4 27195 bytes
SHA-256: c00da53237edd90301ab0de266360e2684aa946a6edcb934fd2c6f653fc0ef3b
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_05_off00062850.bin rtf-objdata-decoded RTF \objdata at offset 0x62850 27195 bytes
SHA-256: facc6e7d749062f236ed77e67b23edd41325a6a0efb438e2077ddfc14d912797
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_06_off000754d8.bin rtf-objdata-decoded RTF \objdata at offset 0x754D8 27195 bytes
SHA-256: c7d8bfd702ef5e3c6f35e6a32d035539ceeb91d8a5a0e2582fb3f0804d4b722f
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_07_off00088162.bin rtf-objdata-decoded RTF \objdata at offset 0x88162 27195 bytes
SHA-256: f82041485c614099fa0c30099b812eb485b177ab34dbd098e3d26c9c9cff8a87
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_08_off0009adec.bin rtf-objdata-decoded RTF \objdata at offset 0x9ADEC 27195 bytes
SHA-256: 10036b9f10c39f3f1adca5b4f43f70a92dc4e45cd54d91444caeb11d2bd73d3f
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_09_off000ada76.bin rtf-objdata-decoded RTF \objdata at offset 0xADA76 27195 bytes
SHA-256: 010b5c5be13d1952cfaec7faf8322db933d672eaf8a84cc6760c1cf7b149be99
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely