Xls.Malware.Sload-7135989-0 — RTF malware analysis

Static analysis result for SHA-256 6daecd02c801840d…

MALICIOUS

RTF

740.9 KB Created: 2018-05-07 07:59:00 First seen: 2018-06-30
MD5: 36d7acb7eb7269372bf497cf938a3cbb SHA-1: 0044c9c30ec7f7adc93e1ef95908be695638b71b SHA-256: 6daecd02c801840d6731b00166d6f18874118bf396893b93bba97ef72bad69ed
242 Risk Score

Malware Insights

Xls.Malware.Sload-7135989-0 · confidence 95%

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple OLE objects, with heuristics indicating ".objupdate" forces OLE activation and the presence of Composite Monikers. ClamAV signatures identify the embedded content as Xls.Malware.Sload-7135989-0, suggesting an exploit targeting spreadsheet functionality. The primary attack vector is likely spearphishing, with the embedded OLE object serving as the malicious payload.

Heuristics 6

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0000291a.bin rtf-objdata-decoded RTF \objdata at offset 0x291A 25147 bytes
SHA-256: c4400aff44cdb8a862a8bd1278559d1edc99500176c94bd08cc8312687b4c31c
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off00014504.bin rtf-objdata-decoded RTF \objdata at offset 0x14504 25147 bytes
SHA-256: f4d676bc99bc176aff58cf6812182bb3671ca104fcd8fb52afe5b7bc3ef53784
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off0002616a.bin rtf-objdata-decoded RTF \objdata at offset 0x2616A 25147 bytes
SHA-256: 4621338ba4ce7b5e8fda1d706f154f13ac9aac0d5db7b5788887acb5288616b8
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off00037dd2.bin rtf-objdata-decoded RTF \objdata at offset 0x37DD2 25147 bytes
SHA-256: 5fb4519896b62fa6656088b5d455e551827d1a11f9fbeca1aa5cfcc4b60863df
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off00049a3a.bin rtf-objdata-decoded RTF \objdata at offset 0x49A3A 25147 bytes
SHA-256: 58523cb838ee632272235575de97fd06555d4c3dbfb00c95a1b24753633829e7
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off0005b6a2.bin rtf-objdata-decoded RTF \objdata at offset 0x5B6A2 25147 bytes
SHA-256: 7c24b3510b3eb949ac8584ce13ebba5cea3c42374f86ecbbf2d7317d6ba85c76
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_06_off0006d30a.bin rtf-objdata-decoded RTF \objdata at offset 0x6D30A 25147 bytes
SHA-256: f9f8c76e335f60460785fb79509f2c68c5ea2337afb73f1f7eb4f2a95def5cf0
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off0007ef72.bin rtf-objdata-decoded RTF \objdata at offset 0x7EF72 25147 bytes
SHA-256: 47cc5aa6e0424515918c7184808672ccce9a8cf36cbb0dac2c84acd6c584f4ed
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off00090bda.bin rtf-objdata-decoded RTF \objdata at offset 0x90BDA 25147 bytes
SHA-256: 1ab7dab087557318ce4c8661f8322c82ce40b3fa55e8ad6fd4021c76d7c28b2b
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off000a2842.bin rtf-objdata-decoded RTF \objdata at offset 0xA2842 25147 bytes
SHA-256: b60cf99c3afbbe194049e10000f82ec6e8bbc20396dddc4a2570e7802822ec89
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely