Xls.Malware.Sload-7135989-0 — RTF malware analysis

Static analysis result for SHA-256 8a81bcf9f80c6d31…

MALICIOUS

RTF

739.3 KB Created: 2018-07-13 13:19:00 First seen: 2018-07-27
MD5: d8813196d432b277dacfa59766938016 SHA-1: 38faea8969d98a3dcd69ffb88c3fd806a91c6f2f SHA-256: 8a81bcf9f80c6d31e8ac25a15d645359d81f0b0208281b25d5d8e5aaeea3e728
242 Risk Score

Malware Insights

Xls.Malware.Sload-7135989-0 · confidence 95%

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple OLE objects, with heuristics indicating ".objupdate" forces OLE activation and the presence of Composite Monikers. ClamAV signatures identify the embedded content as Xls.Malware.Sload-7135989-0, suggesting an exploit targeting spreadsheet functionality. The primary attack vector is likely spearphishing, with the embedded OLE object serving as the malicious payload.

Heuristics 6

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • ClamAV: Xls.Malware.Sload-7135989-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Malware.Sload-7135989-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00003c40.bin rtf-objdata-decoded RTF \objdata at offset 0x3C40 24635 bytes
SHA-256: beddc845f0863e435c5a6186517a4b61e9a3ce180a319518e0572f2a76b05160
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_01_off0001548d.bin rtf-objdata-decoded RTF \objdata at offset 0x1548D 24635 bytes
SHA-256: 18a94a2803f9e779b8d024b0fba55f10d02550f9243174ba644ffa95fa0bc731
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_02_off00026cda.bin rtf-objdata-decoded RTF \objdata at offset 0x26CDA 24635 bytes
SHA-256: ef448ce4008f288003ac846cce4bb4bef9e2be50876ccea3b151a97aa92dfc26
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_03_off00038527.bin rtf-objdata-decoded RTF \objdata at offset 0x38527 24635 bytes
SHA-256: 1070aec60697be8b5bac0bbc6217a5307879182a03c582b1137392e86d046917
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_04_off00049d74.bin rtf-objdata-decoded RTF \objdata at offset 0x49D74 24635 bytes
SHA-256: 66015b6606647d98dad3656f14a87f6b4e0705cfb500d296377a4cbcc17799d9
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_05_off0005c3dd.bin rtf-objdata-decoded RTF \objdata at offset 0x5C3DD 24635 bytes
SHA-256: 9a214e35261a4dc34e6d0ec58ec8dc5a9775a3b271319956153d4bc2f2f65e86
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_06_off0006dc48.bin rtf-objdata-decoded RTF \objdata at offset 0x6DC48 24635 bytes
SHA-256: 71123c4660bfcc6d96ff61b8ee715192490abd014e11cb28c1c04ea1c3741b08
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_07_off0007f4b5.bin rtf-objdata-decoded RTF \objdata at offset 0x7F4B5 24635 bytes
SHA-256: 418024d9dfc66c433d0d4ef247efb9c6e6116927082e002a384786a51e9cbc73
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_08_off00090d22.bin rtf-objdata-decoded RTF \objdata at offset 0x90D22 24635 bytes
SHA-256: 7c716607787ebd0e3409ddaf443a67836ec521af7b6727cb204ac1ec34437e2f
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_09_off000a258f.bin rtf-objdata-decoded RTF \objdata at offset 0xA258F 24635 bytes
SHA-256: 366cbabff3cd4150f75b7d8ff32646b65f54e20dae35bf81370c165b52ab33d0
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely