Xls.Malware.Sload-7135989-0 — RTF malware analysis

Static analysis result for SHA-256 f2caf7dde4d99bd4…

MALICIOUS

RTF

739.2 KB Created: 2018-07-13 12:10:00 First seen: 2019-05-31
MD5: f213519d0f9a09db9719ab2827c5d639 SHA-1: adce4b315ec211bacadc60467f6de9dcdcde5ce2 SHA-256: f2caf7dde4d99bd4a5368bcc1444172e304ed2d62bebe8e32fd53ab0807a0f31
242 Risk Score

Malware Insights

Xls.Malware.Sload-7135989-0 · confidence 95%

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple OLE objects, with heuristics indicating ".objupdate" forces OLE activation and the presence of Composite Monikers. ClamAV signatures identify the embedded content as Xls.Malware.Sload-7135989-0, suggesting an exploit targeting spreadsheet functionality. The primary attack vector is likely spearphishing, with the embedded OLE object serving as the malicious payload.

Heuristics 6

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • ClamAV: Xls.Malware.Sload-7135989-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Malware.Sload-7135989-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00003c29.bin rtf-objdata-decoded RTF \objdata at offset 0x3C29 24635 bytes
SHA-256: 3ef4ea13cd4100d838febcdd4ab17854576a1666aeea5bce0859140456d80a31
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_01_off0001546b.bin rtf-objdata-decoded RTF \objdata at offset 0x1546B 24635 bytes
SHA-256: 9e4d001d91f84ff4f4a9e10440b10303df17d15dbd6e77b85f23f8c8c8fff6b4
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_02_off00026cad.bin rtf-objdata-decoded RTF \objdata at offset 0x26CAD 24635 bytes
SHA-256: 6321dddf66a5124958001b6f62cd04795440da2ec5a1da2adf87de55a73de807
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_03_off000384ef.bin rtf-objdata-decoded RTF \objdata at offset 0x384EF 24635 bytes
SHA-256: 8e899ee0bd8aa8cc1291a61f3ef1ffe02edde7ceacaa682d747bd2a932283814
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_04_off00049d31.bin rtf-objdata-decoded RTF \objdata at offset 0x49D31 24635 bytes
SHA-256: 0ee2a1a6760455560f40e56354e62689459f6e805580980379f4f133a1047e2e
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_05_off0005c383.bin rtf-objdata-decoded RTF \objdata at offset 0x5C383 24635 bytes
SHA-256: 3653c7efd90e5e6e7786004db259d493906bb16f2ee10bb95be6bbed72b87a6a
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_06_off0006dbe3.bin rtf-objdata-decoded RTF \objdata at offset 0x6DBE3 24635 bytes
SHA-256: 9050e2c49e5389ba96b036d2ba74e710f238e4183264682e9e6f6a68a82291c8
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_07_off0007f445.bin rtf-objdata-decoded RTF \objdata at offset 0x7F445 24635 bytes
SHA-256: 409fdfdba775301bbf03e1e54ab8e30d33c76a959faab0d62eb0939456674f95
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_08_off00090ca7.bin rtf-objdata-decoded RTF \objdata at offset 0x90CA7 24635 bytes
SHA-256: 50b5df47f9e221824a303a57cde6b93750dda2b25612815c249f80ad9d63e873
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_09_off000a2509.bin rtf-objdata-decoded RTF \objdata at offset 0xA2509 24635 bytes
SHA-256: 2d28e555ae29995c8cb1c7014e69f3a9fb72f5d660eb77098047cb59614bbff3
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely