Xls.Malware.Sload-7135989-0 — RTF malware analysis

Static analysis result for SHA-256 cf5616b01f1a0035…

MALICIOUS

RTF

821.6 KB Created: 2018-04-24 08:49:00 First seen: 2018-05-18
MD5: 33a652fb271437ab9cef8c3be6e93dac SHA-1: ed71676c5f7263c184279c72d0cb39ae5d3bcd21 SHA-256: cf5616b01f1a003565623100c253c673d87cff7139f52a57f7edeb95287969e6
242 Risk Score

Malware Insights

Xls.Malware.Sload-7135989-0 · confidence 95%

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple OLE objects, with heuristics indicating ".objupdate" forces OLE activation and the presence of Composite Monikers. ClamAV signatures identify the embedded content as Xls.Malware.Sload-7135989-0, suggesting an exploit targeting spreadsheet functionality. The primary attack vector is likely spearphishing, with the embedded OLE object serving as the malicious payload.

Heuristics 6

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • ClamAV: Doc.Macro.Obfuscation-6391394-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Macro.Obfuscation-6391394-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002922.bin rtf-objdata-decoded RTF \objdata at offset 0x2922 29243 bytes
SHA-256: c257c78e7ff811a43604fab025f63b5a5463ff191faaeec3c9db0e5f2c3d5934
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_01_off00016554.bin rtf-objdata-decoded RTF \objdata at offset 0x16554 29243 bytes
SHA-256: 1085e0d3098dd193e85ff57b39b45430fc555a19740f67cb675f37fd607e9575
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_02_off0002a201.bin rtf-objdata-decoded RTF \objdata at offset 0x2A201 29243 bytes
SHA-256: bf89ab97e0e490f26060e2c21bf36dc0052bef7a84feda41ba2fb91e1ff0ea59
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_03_off0003deb0.bin rtf-objdata-decoded RTF \objdata at offset 0x3DEB0 29243 bytes
SHA-256: 114464d12b688901f0376e37b3749ab975f2b0230d00f966ca0f3ac3436d8fe7
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_04_off00051b5f.bin rtf-objdata-decoded RTF \objdata at offset 0x51B5F 29243 bytes
SHA-256: 7fe98213b127e414080a9ade3dee891b1c0e8f8fe6aee48eda4fd837b520a676
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_05_off0006580e.bin rtf-objdata-decoded RTF \objdata at offset 0x6580E 29243 bytes
SHA-256: d5c18409fa09c351664471f42a827092d572665a28d1e279b41ad256f53729d7
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_06_off000794bd.bin rtf-objdata-decoded RTF \objdata at offset 0x794BD 29243 bytes
SHA-256: 0f093bdbf3e3cd1f9b2438f8411dd64c019bf4948f1f6d39e32006f7dee4d52c
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_07_off0008d16c.bin rtf-objdata-decoded RTF \objdata at offset 0x8D16C 29243 bytes
SHA-256: 1b4175eee64d087eaee7f97b0af7d5c5df07d6b7aabd89da77439c8672aac17f
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_08_off000a0e1b.bin rtf-objdata-decoded RTF \objdata at offset 0xA0E1B 29243 bytes
SHA-256: 90319e14f21dc729b7240056ef26cbeb7949608e547671129bdde688e27de4f6
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_09_off000b4aca.bin rtf-objdata-decoded RTF \objdata at offset 0xB4ACA 29243 bytes
SHA-256: ca780777e70ef6e20d92be64d054c265d68b88cba1dc6264eca8a49a2a223365
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely