Xls.Malware.Sload-7135989-0 — RTF malware analysis

Static analysis result for SHA-256 c87d605f7534a924…

MALICIOUS

RTF

741.0 KB Created: 2018-04-28 01:23:00 First seen: 2018-05-18
MD5: 8dff7f2c1c975b4f47d8f2a94fb15274 SHA-1: d9250a700d9ce06b45ad067e2d36099f8ecaa42f SHA-256: c87d605f7534a9245e735761be11aadf77a6e203202a0135cce2e089b35b07e9
242 Risk Score

Malware Insights

Xls.Malware.Sload-7135989-0 · confidence 95%

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple OLE objects, with heuristics indicating ".objupdate" forces OLE activation and the presence of Composite Monikers. ClamAV signatures identify the embedded content as Xls.Malware.Sload-7135989-0, suggesting an exploit targeting spreadsheet functionality. The primary attack vector is likely spearphishing, with the embedded OLE object serving as the malicious payload.

Heuristics 6

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0000291f.bin rtf-objdata-decoded RTF \objdata at offset 0x291F 25147 bytes
SHA-256: 1302342e4ed8c3281bf414f1862f5ffa6009b6741709a16e1da6ebf1815cbd9f
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off0001450a.bin rtf-objdata-decoded RTF \objdata at offset 0x1450A 25147 bytes
SHA-256: 7817442faf70a62084389530bea309f47731b7519e42c53bf652018aa4eb2f12
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off00026171.bin rtf-objdata-decoded RTF \objdata at offset 0x26171 25147 bytes
SHA-256: 825ac8a79cf3ece3adf531d7012bcb05c16ed14e09e5b0077fe348c5b3c19e73
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off00037dda.bin rtf-objdata-decoded RTF \objdata at offset 0x37DDA 25147 bytes
SHA-256: 071b4cfb940729a453e17cbeb2986f61095b9b1f4b9b5c7bca87aa1e4b569c73
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off00049a43.bin rtf-objdata-decoded RTF \objdata at offset 0x49A43 25147 bytes
SHA-256: d7c7af30ac8c0691db50bc3c9971841ed18c679a6cede4f5e75e3c52d05d4324
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off0005b6ac.bin rtf-objdata-decoded RTF \objdata at offset 0x5B6AC 25147 bytes
SHA-256: 6fec776d944915aa4585ed8173444a704c06b8377888b414264994350cc097db
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_06_off0006d315.bin rtf-objdata-decoded RTF \objdata at offset 0x6D315 25147 bytes
SHA-256: ea425ba87765aea9301d937387ee927172bd5b06355b0c2068cc2e316321ea22
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off0007ef7e.bin rtf-objdata-decoded RTF \objdata at offset 0x7EF7E 25147 bytes
SHA-256: e1d15bb9453854282598629b7fde7d2f5b5b784e408482945aba6badb47edc70
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off00090be7.bin rtf-objdata-decoded RTF \objdata at offset 0x90BE7 25147 bytes
SHA-256: 5428fd9f35d3f127b268388b9ff8922f5202509b6184059f77bf8b54b5f8bbb3
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off000a2850.bin rtf-objdata-decoded RTF \objdata at offset 0xA2850 25147 bytes
SHA-256: 2b9dca44f17a994bf2b49adcbe600635e7a3a1b00dd289119f4b46918edeb2a4
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely