Xls.Malware.Sload-7135989-0 — RTF malware analysis

Static analysis result for SHA-256 bab4042a4985a6b9…

MALICIOUS

RTF

789.6 KB Created: 2018-07-17 14:23:00 First seen: 2019-08-04
MD5: ff076abd75d936a00afc5e95fde19e51 SHA-1: 55e1bc50adc514f694ef214f4c5f5c15fa23d18d SHA-256: bab4042a4985a6b9bb4ea2ee2e1fb3bd0000c8583d08875b742c9ae215b0b8e4
242 Risk Score

Malware Insights

Xls.Malware.Sload-7135989-0 · confidence 95%

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple OLE objects, with heuristics indicating ".objupdate" forces OLE activation and the presence of Composite Monikers. ClamAV signatures identify the embedded content as Xls.Malware.Sload-7135989-0, suggesting an exploit targeting spreadsheet functionality. The primary attack vector is likely spearphishing, with the embedded OLE object serving as the malicious payload.

Heuristics 6

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • ClamAV: Xls.Malware.Sload-7135989-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Malware.Sload-7135989-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00003c27.bin rtf-objdata-decoded RTF \objdata at offset 0x3C27 27195 bytes
SHA-256: b57c1b29f47aaf31a3c6e55d5f159a8d5be8fe374ae4558ff7789fe8a315c24e
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_01_off00016893.bin rtf-objdata-decoded RTF \objdata at offset 0x16893 27195 bytes
SHA-256: f9d93d77150ce59974ecad89e61c3124b5ca32b74e197c8c584748c88c34714e
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_02_off000294ff.bin rtf-objdata-decoded RTF \objdata at offset 0x294FF 27195 bytes
SHA-256: 563f05fc208692e1f98763091607f61fcd19750bb33c49c6ec0e82bad6f302e9
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_03_off0003c16b.bin rtf-objdata-decoded RTF \objdata at offset 0x3C16B 27195 bytes
SHA-256: 4bb74fe6c7101d800d10fa31295f828a4a74f180be95024b4d374b895fb6248c
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_04_off0004edd7.bin rtf-objdata-decoded RTF \objdata at offset 0x4EDD7 27195 bytes
SHA-256: 8b413ab3e832f510f66e760d599f927d2b076155fc16cb015379a70e10ba0e96
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_05_off00062853.bin rtf-objdata-decoded RTF \objdata at offset 0x62853 27195 bytes
SHA-256: a809058b8a957b788295b32e48d096e44adea1234e5c406fcb7c6c11c74fe602
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_06_off000754dc.bin rtf-objdata-decoded RTF \objdata at offset 0x754DC 27195 bytes
SHA-256: 2adf3c6bdd1495cb49c705ab3bbd22c520ca624a60ba5871bf40ea8f2e67b4b5
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_07_off00088167.bin rtf-objdata-decoded RTF \objdata at offset 0x88167 27195 bytes
SHA-256: c24a80509a7160176b33b24e7cde9f49fbf8b6052915afae625d21f5294bd496
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_08_off0009adf2.bin rtf-objdata-decoded RTF \objdata at offset 0x9ADF2 27195 bytes
SHA-256: 3913a8e480291b548538b5347d61f223860166af87626d4fad2149d830f9432b
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_09_off000ada7d.bin rtf-objdata-decoded RTF \objdata at offset 0xADA7D 27195 bytes
SHA-256: 94e9b341cf417d6e6391881263402d795b7926f15d2e24e818c749207aeb4ac0
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely