Rich_Text_Format_Zero - Rich Text Format Signature Zero
SUSP_INDICATOR_RTF_MalVer_Objects - Detects RTF documents with non-standard version and embedding one of the object mostly observed in exploit (e.g. CVE-2017-11882) documents.
GET http://www.sqlite.org/2017/sqlite-dll-win32-x86-3190000.zip
request
GET http://www.local-masterfab.pro/m6vg/?3e4VFiK=qlsSz55dMEDh80zakVPbHjaF8j4oNypzrjIj/nO5OsiiIMQ4OCb3eb3/aciAfJPzlTtsA232D702JdziOuhcEJIUeFVyn6zrybpmvBo=&FFb=fqnK4mKb5F
request
POST http://www.sonokiz.xyz/m6vg/
request
GET http://www.sonokiz.xyz/m6vg/?3e4VFiK=OU8I4t4PJh7jLwKM8g7zNLnIXKzFYO4EOKNLYn2/07El/+gDHE38bA7ufp76Z7q9f8ZNVj+wQy/7gIPBvltigVtQEDdIb2L6NYl27Fw=&FFb=fqnK4mKb5F
request
POST http://www.belatofo.com/m6vg/
request
GET http://www.belatofo.com/m6vg/?3e4VFiK=zU2i1DyrLTvj8GmsZ3o7R6kW1xY2b3weixFFYEzXXEr/gEIBiemlOi0xftl7Tao5JEAa7dRSygfLZB5gXWVWN+Vv06aLmgNr2ZdGEQw=&FFb=fqnK4mKb5F