Xls.Malware.Sload-7135989-0 — RTF malware analysis

Static analysis result for SHA-256 a3f5ea58e28baf75…

MALICIOUS

RTF

821.6 KB Created: 2018-04-26 09:52:00 First seen: 2018-11-05
MD5: 71b4a5db5ed0cc39a56159aa82ebfce0 SHA-1: 76b915e16576583b04aa08ec7d505d4fec5d29dd SHA-256: a3f5ea58e28baf7553286227a5e4692f2fd82c66e736c63160b43f4c5829723c
242 Risk Score

Malware Insights

Xls.Malware.Sload-7135989-0 · confidence 95%

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple OLE objects, with heuristics indicating ".objupdate" forces OLE activation and the presence of Composite Monikers. ClamAV signatures identify the embedded content as Xls.Malware.Sload-7135989-0, suggesting an exploit targeting spreadsheet functionality. The primary attack vector is likely spearphishing, with the embedded OLE object serving as the malicious payload.

Heuristics 6

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • ClamAV: Doc.Macro.Obfuscation-6391394-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Macro.Obfuscation-6391394-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0000291f.bin rtf-objdata-decoded RTF \objdata at offset 0x291F 29243 bytes
SHA-256: 1f42c1aa26ea02dcb2cd74d560b43485e2650382a1e4ab6001dd0ef94d3d403c
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_01_off00016550.bin rtf-objdata-decoded RTF \objdata at offset 0x16550 29243 bytes
SHA-256: 681942113c92368c97ebabffacb443d75d3ffe13e1ba500f64b43bde06d74d1e
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_02_off0002a1fc.bin rtf-objdata-decoded RTF \objdata at offset 0x2A1FC 29243 bytes
SHA-256: 0e4342f0ac0ce5cef17fa8722e319c7e44a13b15b0b48c98a1075121ca190af5
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_03_off0003deaa.bin rtf-objdata-decoded RTF \objdata at offset 0x3DEAA 29243 bytes
SHA-256: 7f183c351ac2501fa35e1c0f34db6d9bf4be3de82f3c98038070b896d67ffafb
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_04_off00051b58.bin rtf-objdata-decoded RTF \objdata at offset 0x51B58 29243 bytes
SHA-256: 0bf5e2b6c06a965a2faa83171f9089b421827bfabe37412b5c5f1e79c0ad8439
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_05_off00065806.bin rtf-objdata-decoded RTF \objdata at offset 0x65806 29243 bytes
SHA-256: bc6d1a86fc3eb1d3e9ec994b504d63641acfcb512ed3230b0bce3fe2722708c2
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_06_off000794b4.bin rtf-objdata-decoded RTF \objdata at offset 0x794B4 29243 bytes
SHA-256: ed6c6896099aceadd7b760436647187e88e044beb76e658331c08a4a5806678d
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_07_off0008d162.bin rtf-objdata-decoded RTF \objdata at offset 0x8D162 29243 bytes
SHA-256: cc87b6c18360b9df21196325ca97f0d964dc514fce9ecd97b433783159adb16c
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_08_off000a0e10.bin rtf-objdata-decoded RTF \objdata at offset 0xA0E10 29243 bytes
SHA-256: b4abe300d274e2f797effa59f656524f9888c829d286889f671ac825a7d35d86
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_09_off000b4abe.bin rtf-objdata-decoded RTF \objdata at offset 0xB4ABE 29243 bytes
SHA-256: 49681ad284c85c802fbe20a5b93d57c191fb615e9ce438cd527c13bc8f5b65c3
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely