Rich_Text_Format_Zero - Rich Text Format Signature Zero
SUSP_INDICATOR_RTF_MalVer_Objects - Detects RTF documents with non-standard version and embedding one of the object mostly observed in exploit (e.g. CVE-2017-11882) documents.
GET http://www.fagallery.com/mcon/?uGlQwPJu=rJW8o27P/gqPRSI0wuqXCcBWV3MCPe3Qi8ROeqUr40lzOd+BRDuNmyU/daBjpYLNNDfdIaWQHB2/zU0cdz0dSZCY/Bbb6xMd8kQ8zBA=&9Y84=6fRJZ
request
GET http://www.sqlite.org/2019/sqlite-dll-win32-x86-3290000.zip
request
POST http://www.bc081.com/mcon/
request
GET http://www.bc081.com/mcon/?uGlQwPJu=pskxmoRFchsAbXFIn6Ds6WJWm93GPZXrd/fIfWEPkz26aGEkZ87oGPy24JF+yxwF1h0P/zwK8gLwn+yMtUteEtVFAkBJqDM7Jup+RKc=&9Y84=6fRJZ
request
POST http://www.purelyunorthodox.com/mcon/
request
GET http://www.purelyunorthodox.com/mcon/?uGlQwPJu=JxkY46YC9LBm3OkL8orXF7D68oVhabe0uO4APku638FfxldkBjOvcbwo9sb38aK0GSbzu/P0eNN4w2ybAPlnTHOTDB1A0VrJVW01pJA=&9Y84=6fRJZ
request
POST http://www.paybillnow.info/mcon/
request
GET http://www.paybillnow.info/mcon/?uGlQwPJu=6l2bJH3lYuggsJGye7Ek7Djc2AhxQovbvd2YkjgUuVZ2vqa0aW8Pwj2WXOk/QoHCXwbnfhEZTCtL08rWUqnG/IhfnQVtlui9LEQGFPc=&9Y84=6fRJZ
request
POST http://www.superxwin.app/mcon/
request
GET http://www.superxwin.app/mcon/?uGlQwPJu=zXOJUe1DiQqRpKX/iPrmQy7/Wg64w+pTL1bjt+yOL2NGV+wW4eH3xNfsFSFyKke75OeaWtpTehrF3ed1/bJdwY3kBcAY+jnnbA/ldzE=&9Y84=6fRJZ
request
POST http://www.triplemshipssupplies.com/mcon/
request
GET http://www.triplemshipssupplies.com/mcon/?uGlQwPJu=dnPohqZh5otnQV3RPwhvaI5Uo8JzxtGuHQ1wIyfjEImxMkpvtO72FR5odLVFga56TxKG3zu640027WzcyBBbGjRHowMwiJmzi8hzv3g=&9Y84=6fRJZ