Xls.Malware.Sload-7135989-0 — RTF malware analysis

Static analysis result for SHA-256 96565776d0edb59a…

MALICIOUS

RTF

789.5 KB Created: 2018-07-17 14:10:00 First seen: 2019-08-04
MD5: 920c55a53d060cefe1bed02a6e154171 SHA-1: 41388b663302316319f0cfd98cd4f0955ae7df08 SHA-256: 96565776d0edb59a67c1a75b8f80f2797df405eeaacc9022fa7dc708905f3a7d
242 Risk Score

Malware Insights

Xls.Malware.Sload-7135989-0 · confidence 95%

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple OLE objects, with heuristics indicating ".objupdate" forces OLE activation and the presence of Composite Monikers. ClamAV signatures identify the embedded content as Xls.Malware.Sload-7135989-0, suggesting an exploit targeting spreadsheet functionality. The primary attack vector is likely spearphishing, with the embedded OLE object serving as the malicious payload.

Heuristics 6

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • ClamAV: Xls.Malware.Sload-7135989-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Malware.Sload-7135989-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00003c00.bin rtf-objdata-decoded RTF \objdata at offset 0x3C00 27195 bytes
SHA-256: fc1cca3a650aaa3d7706638fa3089099b99fdbcb29eceafbafbc4b140b95eb1f
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_01_off00016862.bin rtf-objdata-decoded RTF \objdata at offset 0x16862 27195 bytes
SHA-256: f5c3f6538ed2166e94c7d3b49c31d17737384dd0d697e1c5f913497aed9fd460
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_02_off000294c4.bin rtf-objdata-decoded RTF \objdata at offset 0x294C4 27195 bytes
SHA-256: 0d060f02fc15035a869f995ae236e5354e39559cbda89f0fdc14a532520a830a
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_03_off0003c126.bin rtf-objdata-decoded RTF \objdata at offset 0x3C126 27195 bytes
SHA-256: 717bb36c4f00b300c0de0fb8516bc1cdde48acf47c2059ba402ca7effdf04292
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_04_off0004ed88.bin rtf-objdata-decoded RTF \objdata at offset 0x4ED88 27195 bytes
SHA-256: 6d0411f2162ff965ffc603c06320994a67842cacbe6813bc88c0a235140716cb
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_05_off000627e2.bin rtf-objdata-decoded RTF \objdata at offset 0x627E2 27195 bytes
SHA-256: 617c729fa72ddab425930fdc60677d461d10a984be17f26b56e865fad6b8151c
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_06_off00075465.bin rtf-objdata-decoded RTF \objdata at offset 0x75465 27195 bytes
SHA-256: 32e77a3ade771751b7649f158f5c78f7f20c85c24ad113a56bd0699fa6717686
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_07_off000880ea.bin rtf-objdata-decoded RTF \objdata at offset 0x880EA 27195 bytes
SHA-256: eefa039879317ecb993d2767ad86ac605b81392a50eb9476926bafa484ab04d7
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_08_off0009ad6f.bin rtf-objdata-decoded RTF \objdata at offset 0x9AD6F 27195 bytes
SHA-256: 0734f6a81aed77c45009b27599d989c28a5366959babba26503cbe75fb6491e2
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_09_off000ad9f4.bin rtf-objdata-decoded RTF \objdata at offset 0xAD9F4 27195 bytes
SHA-256: 41da3f4b4d1cee1a0d0afcc04347f65255f211cf57198ef30cea05f200ee92b3
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely