Xls.Malware.Sload-7135989-0 — RTF malware analysis

Static analysis result for SHA-256 72c111d7e6430b6b…

MALICIOUS

RTF

821.6 KB Created: 2018-04-23 10:04:00 First seen: 2018-06-21
MD5: 0bb81b7e93c1e7799affbacf3fb487d3 SHA-1: 584fbbce972c411fd299f11313e966294f087c04 SHA-256: 72c111d7e6430b6bf6905cf162cfbced65f03d4921ad8dbfa56976555810f704
242 Risk Score

Malware Insights

Xls.Malware.Sload-7135989-0 · confidence 95%

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple OLE objects, with heuristics indicating ".objupdate" forces OLE activation and the presence of Composite Monikers. ClamAV signatures identify the embedded content as Xls.Malware.Sload-7135989-0, suggesting an exploit targeting spreadsheet functionality. The primary attack vector is likely spearphishing, with the embedded OLE object serving as the malicious payload.

Heuristics 6

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • ClamAV: Doc.Macro.Obfuscation-6391394-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Macro.Obfuscation-6391394-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0000291c.bin rtf-objdata-decoded RTF \objdata at offset 0x291C 29243 bytes
SHA-256: f6c55a2fa220d8256d2ef60ccd1c66ffbddc51c08a0779d5c6b1a21d35ec7cd1
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_01_off00016548.bin rtf-objdata-decoded RTF \objdata at offset 0x16548 29243 bytes
SHA-256: 88a9521fa85887159100b2af71440e45a5a853b4dd9ffcf4cb9da81427d2bb5f
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_02_off0002a1f0.bin rtf-objdata-decoded RTF \objdata at offset 0x2A1F0 29243 bytes
SHA-256: 496e2977a9e261b56fb116995454bbd47ad728e80487aec992bd2cd354453129
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_03_off0003de9a.bin rtf-objdata-decoded RTF \objdata at offset 0x3DE9A 29243 bytes
SHA-256: 9c889ebde48c822fb37d65e8ee5a22b19b4b2dfed561dbde41415d0f37c055da
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_04_off00051b44.bin rtf-objdata-decoded RTF \objdata at offset 0x51B44 29243 bytes
SHA-256: d86d3b8fffe3dcb38423001d1f07c27b8fced095c91837d6d41a53a3a4d9637a
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_05_off000657ee.bin rtf-objdata-decoded RTF \objdata at offset 0x657EE 29243 bytes
SHA-256: 7710e568eb4aa6711a992183fb32acccf6f16a2d814c85d5fde37c662e37137b
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_06_off00079498.bin rtf-objdata-decoded RTF \objdata at offset 0x79498 29243 bytes
SHA-256: 9ce999fc0d20f2c77d6e9e98eabd4f5e21a8204501b7be99a01a7ccd6e8c8dcd
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_07_off0008d142.bin rtf-objdata-decoded RTF \objdata at offset 0x8D142 29243 bytes
SHA-256: e8795c57f19b4280554547ca92873a038f822e7f5be65d2e01d45c13c2be49da
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_08_off000a0dec.bin rtf-objdata-decoded RTF \objdata at offset 0xA0DEC 29243 bytes
SHA-256: 38951358a96e050ed285124cfb056c3320b838480b75a4638ce09113ea8df88b
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_09_off000b4a96.bin rtf-objdata-decoded RTF \objdata at offset 0xB4A96 29243 bytes
SHA-256: db36f7bca2d4b017311bb4db40d07391efd4c94b682324db8f9e0df08b1ed179
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely