Xls.Malware.Sload-7135989-0 — RTF malware analysis

Static analysis result for SHA-256 51c1f60ed10be433…

MALICIOUS

RTF

843.3 KB Created: 2018-07-17 14:02:00 First seen: 2018-11-05
MD5: c8b0cd8ea14e32b828b0a6064d008c53 SHA-1: 7b0809745d71aeb6d327de91a7e61b94b76e418b SHA-256: 51c1f60ed10be433cfbbf275028cab0b46bc6194226f753caecf814ee6d49dfb
242 Risk Score

Malware Insights

Xls.Malware.Sload-7135989-0 · confidence 95%

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple OLE objects, with heuristics indicating ".objupdate" forces OLE activation and the presence of Composite Monikers. ClamAV signatures identify the embedded content as Xls.Malware.Sload-7135989-0, suggesting an exploit targeting spreadsheet functionality. The primary attack vector is likely spearphishing, with the embedded OLE object serving as the malicious payload.

Heuristics 6

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • ClamAV: Xls.Malware.Sload-7135989-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Malware.Sload-7135989-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00003c54.bin rtf-objdata-decoded RTF \objdata at offset 0x3C54 27195 bytes
SHA-256: 2ffc25443e533e00d43819a97964a6f647b9abe41eaa80c91028140802f23ae7
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_01_off000168f5.bin rtf-objdata-decoded RTF \objdata at offset 0x168F5 27195 bytes
SHA-256: 1826de349952e059c2da784a86e03184f44cc2982c0a77710489e4bbedaed7ef
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_02_off00029596.bin rtf-objdata-decoded RTF \objdata at offset 0x29596 27195 bytes
SHA-256: 03679c106b3ec71ec70338fd927e1d4c753ded749c8147ef7a51b34c9e4f4956
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_03_off0003c237.bin rtf-objdata-decoded RTF \objdata at offset 0x3C237 27195 bytes
SHA-256: 69390b708fb258c349fd1a3fc75773d965f6e83e02265b2ce0e62f4868c1f097
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_04_off0004eed8.bin rtf-objdata-decoded RTF \objdata at offset 0x4EED8 27195 bytes
SHA-256: 2fcdcb2044e134cc5ccef55d2dbaf21252809356eaf0f2499994c30ed7f806d1
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_05_off000693d6.bin rtf-objdata-decoded RTF \objdata at offset 0x693D6 27195 bytes
SHA-256: e9a20c41bdc65ed5a61ecca13716012b403fa540e7a4cc89c4af7e2af549f505
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_06_off0007c098.bin rtf-objdata-decoded RTF \objdata at offset 0x7C098 27195 bytes
SHA-256: f1a9d694e1f1d62938348f49da9463381b237dbf940cf18c4b7f2f7e9b08d243
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_07_off0008ed5a.bin rtf-objdata-decoded RTF \objdata at offset 0x8ED5A 27195 bytes
SHA-256: 9976a5ffa8ec8a83d48cd7bcba323db5d1d4d4829f648be90dce7cb6bd1248f9
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_08_off000a1a1c.bin rtf-objdata-decoded RTF \objdata at offset 0xA1A1C 27195 bytes
SHA-256: c516b8670aa7c383b0e087e216113cbae668cff14872ad03fffbb10a0e798ae2
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_09_off000b46de.bin rtf-objdata-decoded RTF \objdata at offset 0xB46DE 27195 bytes
SHA-256: d7da00ffb4293e7c14fd8c97dc1e6c6ed3b78dec1ba0b0f21b72b40f3bd9d4f1
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely