Xls.Malware.Sload-7135989-0 — RTF malware analysis

Static analysis result for SHA-256 67b3b3f8d803dd3b…

MALICIOUS

RTF

741.0 KB Created: 2018-04-30 11:06:00 First seen: 2018-06-30
MD5: 09560e01b9376cc74c455a0fe4a4b41c SHA-1: 17bcf9878ecb4128f26a1cdc7243c8a7324df2e0 SHA-256: 67b3b3f8d803dd3b3d0f40b7019f74fcff324f2d6bc663cf8fb9a32508a7dd91
242 Risk Score

Malware Insights

Xls.Malware.Sload-7135989-0 · confidence 95%

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple OLE objects, with heuristics indicating ".objupdate" forces OLE activation and the presence of Composite Monikers. ClamAV signatures identify the embedded content as Xls.Malware.Sload-7135989-0, suggesting an exploit targeting spreadsheet functionality. The primary attack vector is likely spearphishing, with the embedded OLE object serving as the malicious payload.

Heuristics 6

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0000291f.bin rtf-objdata-decoded RTF \objdata at offset 0x291F 25147 bytes
SHA-256: 7a01284fc19c2b06c9704f6eba2b550b8c03c3fa58decfef9b887a584b39fc93
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off0001450a.bin rtf-objdata-decoded RTF \objdata at offset 0x1450A 25147 bytes
SHA-256: fa434d0104fcd0ce48b888dfda6b137ff70d7060758938d1a99d81ba482d39b9
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off00026171.bin rtf-objdata-decoded RTF \objdata at offset 0x26171 25147 bytes
SHA-256: 2be9ae012ee051020415d1f48ab451a8af16275c0d079d204d27dc6b9e9696c4
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off00037dda.bin rtf-objdata-decoded RTF \objdata at offset 0x37DDA 25147 bytes
SHA-256: d464115541618bc3085505ff2c0f0a3444bfcfddbe924de4e2ce1a6aa8b86e8d
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off00049a43.bin rtf-objdata-decoded RTF \objdata at offset 0x49A43 25147 bytes
SHA-256: 6142fc6b9e3fe2b3456b1b3b414937469d579ffa49ea8ec66ef2a4f9bd7a2ac0
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off0005b6ac.bin rtf-objdata-decoded RTF \objdata at offset 0x5B6AC 25147 bytes
SHA-256: 5c6f02fe123ed49bbfc49828fbfe8e041a71f528f275d9aa225a26d68ed5d6db
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_06_off0006d315.bin rtf-objdata-decoded RTF \objdata at offset 0x6D315 25147 bytes
SHA-256: 716c91f5bb39802a7ab688f723da5e16c34058ecc0c0d26388f06375107833bd
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off0007ef7e.bin rtf-objdata-decoded RTF \objdata at offset 0x7EF7E 25147 bytes
SHA-256: ba782c6e385467f873dd6d83f48e02552e887d8e30cff3114b44d9dcf0f67eb7
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off00090be7.bin rtf-objdata-decoded RTF \objdata at offset 0x90BE7 25147 bytes
SHA-256: 847988a65753e4a9e900c1fc14b7dddfffc989c54e986be2b4af51fdc2d62f74
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off000a2850.bin rtf-objdata-decoded RTF \objdata at offset 0xA2850 25147 bytes
SHA-256: 322b135de85e7b9a3443b80b6772786028625102fcd6f1475ce27e430957cd32
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely