Xls.Malware.Sload-7135989-0 — RTF malware analysis

Static analysis result for SHA-256 af5db7dc727d071d…

MALICIOUS

RTF

821.6 KB Created: 2018-04-03 13:25:00 First seen: 2018-06-21
MD5: e173ea72d01c0c2c4bdc23e9204734a8 SHA-1: 2679a506ac0b7f41f1a509ced0cbba69547384a1 SHA-256: af5db7dc727d071d622e2eb93aefe13f5e2464e411d23c7d99025aa17eb22007
242 Risk Score

Malware Insights

Xls.Malware.Sload-7135989-0 · confidence 95%

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple OLE objects, with heuristics indicating ".objupdate" forces OLE activation and the presence of Composite Monikers. ClamAV signatures identify the embedded content as Xls.Malware.Sload-7135989-0, suggesting an exploit targeting spreadsheet functionality. The primary attack vector is likely spearphishing, with the embedded OLE object serving as the malicious payload.

Heuristics 6

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • ClamAV: Doc.Macro.Obfuscation-6391394-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Macro.Obfuscation-6391394-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002922.bin rtf-objdata-decoded RTF \objdata at offset 0x2922 29243 bytes
SHA-256: b892e2a622721214b039fbb55a85c683cf8bf0f6b6fd0fb3f2c5057ae8228ef3
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_01_off00016554.bin rtf-objdata-decoded RTF \objdata at offset 0x16554 29243 bytes
SHA-256: 8f4b9b0759d9b6ef2b4e8471694107203e505cbb60e697574700ef8cc6bce175
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_02_off0002a201.bin rtf-objdata-decoded RTF \objdata at offset 0x2A201 29243 bytes
SHA-256: 0b0aba478d080b3ad38b64ba33138ccfbfa3a784cc460030a7d89b6f743461fd
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_03_off0003deb0.bin rtf-objdata-decoded RTF \objdata at offset 0x3DEB0 29243 bytes
SHA-256: bf5c0e4471a95fc067bc793b646026b0874450ca7ab81556b1a115ba2833e43e
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_04_off00051b5f.bin rtf-objdata-decoded RTF \objdata at offset 0x51B5F 29243 bytes
SHA-256: d0ae98bd323f6691ca610196f46342e62cd15ddb3d0ea76f1e2ae603c3c1308c
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_05_off0006580e.bin rtf-objdata-decoded RTF \objdata at offset 0x6580E 29243 bytes
SHA-256: 6deab1741a79182d05fe7af157087e08ae67429a67f042360dac0508b921a406
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_06_off000794bd.bin rtf-objdata-decoded RTF \objdata at offset 0x794BD 29243 bytes
SHA-256: be2909c569bc4dd0874df3e3c9d3469db9901d3cf300907391205d5f88f5d731
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_07_off0008d16c.bin rtf-objdata-decoded RTF \objdata at offset 0x8D16C 29243 bytes
SHA-256: a4f81866eee9453d1ed86fa7b263d43e7e7ddcc06c06b5424b60bb66ad0a4cbc
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_08_off000a0e1b.bin rtf-objdata-decoded RTF \objdata at offset 0xA0E1B 29243 bytes
SHA-256: e3322f1d3580e723f8b88c1a77a2909b015991cd7d3873cd61fcb34c6f97f1eb
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_09_off000b4aca.bin rtf-objdata-decoded RTF \objdata at offset 0xB4ACA 29243 bytes
SHA-256: ee24098d5f53106e1519a437a3f2b09bf03917b2b5bdb2e9437f0bc3981fb8f0
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely