Xls.Malware.Sload-7135989-0 — RTF malware analysis

Static analysis result for SHA-256 885cd499267bc8bc…

MALICIOUS

RTF

821.6 KB Created: 2018-04-25 10:05:00 First seen: 2018-07-04
MD5: 6c33ee9c5d694b6c110d60b22b9df31e SHA-1: 9b46e402d23748e84465328b3bd290366cbdb069 SHA-256: 885cd499267bc8bc4ac7a26d8337311eb29c1dd168e1ec3b42cd26d0506b79be
242 Risk Score

Malware Insights

Xls.Malware.Sload-7135989-0 · confidence 95%

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple OLE objects, with heuristics indicating ".objupdate" forces OLE activation and the presence of Composite Monikers. ClamAV signatures identify the embedded content as Xls.Malware.Sload-7135989-0, suggesting an exploit targeting spreadsheet functionality. The primary attack vector is likely spearphishing, with the embedded OLE object serving as the malicious payload.

Heuristics 6

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • ClamAV: Doc.Macro.Obfuscation-6391394-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Macro.Obfuscation-6391394-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0000291f.bin rtf-objdata-decoded RTF \objdata at offset 0x291F 29243 bytes
SHA-256: 624059dc48b27b269b8d79e7dd9044364781b0a825c07d636a00713df1754fcc
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_01_off0001654c.bin rtf-objdata-decoded RTF \objdata at offset 0x1654C 29243 bytes
SHA-256: 8555a4768136cd7496ab3a051fb4cf968bb3d8798bf10291e09c360b4b5c76ca
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_02_off0002a1f5.bin rtf-objdata-decoded RTF \objdata at offset 0x2A1F5 29243 bytes
SHA-256: a009a73edda51d885f58a53070a7d0ccb7751ba91c71165b15213240100388ee
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_03_off0003dea0.bin rtf-objdata-decoded RTF \objdata at offset 0x3DEA0 29243 bytes
SHA-256: bb2a06aae9faf3c93dfc37ee7c3f29b73ae08cacd826599aefd4a6db2386e9fb
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_04_off00051b4b.bin rtf-objdata-decoded RTF \objdata at offset 0x51B4B 29243 bytes
SHA-256: 25d7bc2ac1804a55403661bfe0ef25950cef5f03bdc2e495ad2b5f2ada265b16
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_05_off000657f6.bin rtf-objdata-decoded RTF \objdata at offset 0x657F6 29243 bytes
SHA-256: 3eaa2341a8f8c8895d1c2f2e5d39bdb7722d8b1b614b82acd646e4d9954cd653
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_06_off000794a1.bin rtf-objdata-decoded RTF \objdata at offset 0x794A1 29243 bytes
SHA-256: df65576f602351568307b1d64759fe88bd66b3a64042ae962c4848d2599a92c7
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_07_off0008d14c.bin rtf-objdata-decoded RTF \objdata at offset 0x8D14C 29243 bytes
SHA-256: cc19034a758aaebc59b6c625da193d9bc951721ed760c2159a65b28499fa16b9
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_08_off000a0df7.bin rtf-objdata-decoded RTF \objdata at offset 0xA0DF7 29243 bytes
SHA-256: f40de7cc057ff439b24a318031085527ce8b98133806f8d897e4c4ef99282fe7
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_09_off000b4aa2.bin rtf-objdata-decoded RTF \objdata at offset 0xB4AA2 29243 bytes
SHA-256: 54dcd51c7e40f01d76f08ff4537d085837b3097bb726f0aa468664714f3e7c8c
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely