Sload — Office (OLE) malware analysis

Static analysis result for SHA-256 8cc4d5b3a499c794…

MALICIOUS

Office (OLE)

96.5 KB Created: 2018-10-05 15:22:00 Authoring application: Microsoft Office Word First seen: 2019-01-12
MD5: 1f12fe2355f4dc9f5e9d72ac31fb37df SHA-1: f6fc5f690fa776d959e5661552c92a0e77f728c8 SHA-256: 8cc4d5b3a499c794f0d6e1be851e3d438a9f166f43ceae3d42a4be721d87f0d7
64 Risk Score

Malware Insights

Sload · confidence 95%

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1105 Ingress Tool Transfer

The file was detected by ClamAV as Doc.Downloader.Sload-6710134-0, indicating it functions as a downloader. Although VBA macros could not be extracted due to an unsupported format, the presence of an embedded URL and the ClamAV signature strongly suggest the document's purpose is to fetch and execute a secondary payload. This aligns with the typical behavior of downloader malware.

Heuristics 3

  • ClamAV: Doc.Downloader.Sload-6710134-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Downloader.Sload-6710134-0
  • Unsupported Office format for VBA extraction info OFFICE_FORMAT_UNSUPPORTED
    olevba could not extract VBA macros (AssertionError); format-agnostic byte-level scans still ran. Likely legacy, encrypted, or malformed OLE/OOXML — re-scanning the same bytes will yield the same outcome.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.openxmlformats.org/drawingml/2006/main In document text (OLE body)