Xls.Malware.Sload-7135989-0 — RTF malware analysis

Static analysis result for SHA-256 806098afc2148dab…

MALICIOUS

RTF

1022.4 KB Created: 2018-06-01 14:52:00 First seen: 2018-06-21
MD5: 8b54211cf8a4cd5621bef3464a4f74c3 SHA-1: 880fd320bf0b6dd749f0bc37d7d14027777b5aa3 SHA-256: 806098afc2148dabb838b24c4dfaa148269ac3ddf769aee54e75d46bfef0c506
242 Risk Score

Malware Insights

Xls.Malware.Sload-7135989-0 · confidence 95%

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple OLE objects, with heuristics indicating ".objupdate" forces OLE activation and the presence of Composite Monikers. ClamAV signatures identify the embedded content as Xls.Malware.Sload-7135989-0, suggesting an exploit targeting spreadsheet functionality. The primary attack vector is likely spearphishing, with the embedded OLE object serving as the malicious payload.

Heuristics 6

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • ClamAV: Xls.Malware.Generic-6834349-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Malware.Generic-6834349-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00003d14.bin rtf-objdata-decoded RTF \objdata at offset 0x3D14 35899 bytes
SHA-256: 2b7c4143afe8f71aa7f88ea03184541a63be7a031412b8f9912ea368e4992dae
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely
objdata_01_off0001ae2b.bin rtf-objdata-decoded RTF \objdata at offset 0x1AE2B 35899 bytes
SHA-256: e0f24f6b38ae92acdbfa56b68ede4a3bcf2ce60fe52e8c5127fe28b0810afe6f
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely
objdata_02_off00031f42.bin rtf-objdata-decoded RTF \objdata at offset 0x31F42 35899 bytes
SHA-256: 2643cae536117623162f4ba2ead9a6909299c0e41b77cf3740ffacfde4dd6450
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely
objdata_03_off00049059.bin rtf-objdata-decoded RTF \objdata at offset 0x49059 35899 bytes
SHA-256: 1f0b2b210a19d4e740b08cee5ac20f4c90a0c88642213c444757d405d880a8dd
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely
objdata_04_off00060170.bin rtf-objdata-decoded RTF \objdata at offset 0x60170 35899 bytes
SHA-256: 4751e58f661af9a84cca430f935659c8e6a7ced1895d7e4e6aab0301772eedf7
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely
objdata_05_off0007728e.bin rtf-objdata-decoded RTF \objdata at offset 0x7728E 35899 bytes
SHA-256: 658f664d9dbe3c6362b2031c3d7d91fb3db5c9761deff4ee10ae8b034c733554
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely
objdata_06_off0008e3a5.bin rtf-objdata-decoded RTF \objdata at offset 0x8E3A5 35899 bytes
SHA-256: a5ef8c487f0f70d9bcca15de9f151f6d4057d44b4eb4d93f0395363fdad147c4
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely
objdata_07_off000a54bc.bin rtf-objdata-decoded RTF \objdata at offset 0xA54BC 35899 bytes
SHA-256: 1bd8fb8a8a2b6949229bf91c65f869e45bb7e246c80285006400f6c6a26e4f28
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely
objdata_08_off000bc5d3.bin rtf-objdata-decoded RTF \objdata at offset 0xBC5D3 35899 bytes
SHA-256: 294875e2e5490c32d32447fc755440a4d6773a440fce94656f5547677993a021
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely
objdata_09_off000d36ea.bin rtf-objdata-decoded RTF \objdata at offset 0xD36EA 35899 bytes
SHA-256: 952fb2e78efee6a6a6c2885808c7f7464544ed5ff7f96611266077fc096d0118
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely