Xls.Malware.Sload-7135989-0 — RTF malware analysis

Static analysis result for SHA-256 886473f5291c4202…

MALICIOUS

RTF

789.6 KB Created: 2018-07-17 14:26:00 First seen: 2019-04-17
MD5: fcae302b97d4fef942af47ef3925e80f SHA-1: 2a764b9872725a468d68a94f1c61c953b00cc572 SHA-256: 886473f5291c420272dc8dd3f7bddb81ffa282ca98352985159db8cab9bb3217
242 Risk Score

Malware Insights

Xls.Malware.Sload-7135989-0 · confidence 95%

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple OLE objects, with heuristics indicating ".objupdate" forces OLE activation and the presence of Composite Monikers. ClamAV signatures identify the embedded content as Xls.Malware.Sload-7135989-0, suggesting an exploit targeting spreadsheet functionality. The primary attack vector is likely spearphishing, with the embedded OLE object serving as the malicious payload.

Heuristics 6

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • ClamAV: Xls.Malware.Sload-7135989-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Malware.Sload-7135989-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00003c2d.bin rtf-objdata-decoded RTF \objdata at offset 0x3C2D 27195 bytes
SHA-256: 2bfece4ed9587ce78d3ca498565f132029f140b86fd21a54672981f9e430717f
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_01_off00016899.bin rtf-objdata-decoded RTF \objdata at offset 0x16899 27195 bytes
SHA-256: d38d2e6f3f2f582a7987fb9c152306d88aa3f657fe9e68fa3625eb289e007665
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_02_off00029505.bin rtf-objdata-decoded RTF \objdata at offset 0x29505 27195 bytes
SHA-256: e9d08763c71b85bcd0f41c2b0e6651f03ccd667f39edff37751e6153834039de
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_03_off0003c171.bin rtf-objdata-decoded RTF \objdata at offset 0x3C171 27195 bytes
SHA-256: 674ba3b35053e9c7623069e1c7b24a95f95f3dcf1f2d75d61c60e3e03d190f8b
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_04_off0004eddd.bin rtf-objdata-decoded RTF \objdata at offset 0x4EDDD 27195 bytes
SHA-256: 14205d5be9bbcf9fa80c7851d08e16d7d27f4358bc461e2ed0fa63def7813ecb
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_05_off00062859.bin rtf-objdata-decoded RTF \objdata at offset 0x62859 27195 bytes
SHA-256: 752df7e69d7967a12e548360c819b9642d89ee304b6d4517557dd653769a7a41
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_06_off000754e4.bin rtf-objdata-decoded RTF \objdata at offset 0x754E4 27195 bytes
SHA-256: 98140eb12897abe5f08b607e074fba51729e6fc150080212d0e58c2e1cead52d
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_07_off00088171.bin rtf-objdata-decoded RTF \objdata at offset 0x88171 27195 bytes
SHA-256: b4dd9b5847222c89b13ea0674ab1423d376e21c2d90410e8db012d432d4302e8
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_08_off0009adfe.bin rtf-objdata-decoded RTF \objdata at offset 0x9ADFE 27195 bytes
SHA-256: 72e49d3d9018bb2d06f99823a43bab922a9db448d2e55f8386a13193e401812b
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_09_off000ada8b.bin rtf-objdata-decoded RTF \objdata at offset 0xADA8B 27195 bytes
SHA-256: b7c5d582ac02b5d2d6121f2f59a2bca8a72b05d3d93c073fd5ac5df140b8325f
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely