Xls.Malware.Sload-7135989-0 — RTF malware analysis

Static analysis result for SHA-256 4e04e20a5ef41c39…

MALICIOUS

RTF

821.6 KB Created: 2018-04-19 09:40:00 First seen: 2018-06-21
MD5: 22848fe2de4424fba05954bd93f39aee SHA-1: e7547ccaa50722f9b1d1a328f7535196c4ca5c6b SHA-256: 4e04e20a5ef41c39daddeb225f119251e42815de7afc3a5b5bd851a3e73217fd
242 Risk Score

Malware Insights

Xls.Malware.Sload-7135989-0 · confidence 95%

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple OLE objects, with heuristics indicating ".objupdate" forces OLE activation and the presence of Composite Monikers. ClamAV signatures identify the embedded content as Xls.Malware.Sload-7135989-0, suggesting an exploit targeting spreadsheet functionality. The primary attack vector is likely spearphishing, with the embedded OLE object serving as the malicious payload.

Heuristics 6

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • ClamAV: Doc.Macro.Obfuscation-6391394-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Macro.Obfuscation-6391394-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0000291c.bin rtf-objdata-decoded RTF \objdata at offset 0x291C 29243 bytes
SHA-256: b329cd86398b621dc42f6c53acf05d23c3c4eca6bb5ada99f604927556ba92be
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_01_off00016548.bin rtf-objdata-decoded RTF \objdata at offset 0x16548 29243 bytes
SHA-256: 4dd12cf8f56a305e97c60d5ed25c4883fa199ae861497b576ea9bf7790a58fe6
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_02_off0002a1f0.bin rtf-objdata-decoded RTF \objdata at offset 0x2A1F0 29243 bytes
SHA-256: 474bd55b4d3d1f0ba8ef0ab6dd54030a726e20a91b663d171e6d60a372dee391
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_03_off0003de9a.bin rtf-objdata-decoded RTF \objdata at offset 0x3DE9A 29243 bytes
SHA-256: 47e1515c6702c62ab8815002ee6e1901cca51363b573cbd2fab8d8ecfd3e17fc
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_04_off00051b44.bin rtf-objdata-decoded RTF \objdata at offset 0x51B44 29243 bytes
SHA-256: 94621fd3d89e8e9b57ebda22f74ecc42a9db6541020e037f16057b5572a180b4
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_05_off000657ee.bin rtf-objdata-decoded RTF \objdata at offset 0x657EE 29243 bytes
SHA-256: 0fe83cab6d201fa10629c454d24bd217e0505f7ec3e03f1a8f02cf3bed6df6b7
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_06_off00079498.bin rtf-objdata-decoded RTF \objdata at offset 0x79498 29243 bytes
SHA-256: de0b7f8d92b4e8ee6e90c90d7d5d32e7f656c1395e2814c45591b58c262186ab
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_07_off0008d142.bin rtf-objdata-decoded RTF \objdata at offset 0x8D142 29243 bytes
SHA-256: 1e28517c58d66aa3ec984cee9c5f36736a6021a0adcb4797f3ceedbc721a3f47
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_08_off000a0dec.bin rtf-objdata-decoded RTF \objdata at offset 0xA0DEC 29243 bytes
SHA-256: fe171ff0f7b2f1c03fed684e1c8c355ef3f92562b5528544da31f9e47497845f
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_09_off000b4a96.bin rtf-objdata-decoded RTF \objdata at offset 0xB4A96 29243 bytes
SHA-256: c1ff36454d214bb0d6175befb0715f002008d7c8f774e5c71e1121a3b6e04b62
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely