File name:

VM_0131_05_2018.pptx

Full analysis: https://app.any.run/tasks/b9925b66-754e-4038-8b27-6ed121ab4c19
Verdict: Malicious activity
Analysis date: December 02, 2019, 20:43:53
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

CD2EB32A5BEC47E2CFA21F8F77CB531F

SHA1:

1562C6C0709D91B76F1C156E8CDC00EEF1C4F043

SHA256:

43C0649A6428EBF5627285CEF451AE3235145E7FFF430368CD806998B59D3AC5

SSDEEP:

3072:vEbWShumh6QYYw+TQSCatsSSKGBhJuaEvrJkAwc6J+NWe:nOuiG5+TFCats7Kah8Ng3e

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Checks supported languages

      • POWERPNT.EXE (PID: 2108)
    • Unusual connect from Microsoft Office

      • POWERPNT.EXE (PID: 2108)
  • INFO

    • Reads Microsoft Office registry keys

      • POWERPNT.EXE (PID: 2108)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.pptx | PowerPoint Microsoft Office Open XML Format document (87)
.zip | Open Packaging Conventions container (10.5)
.zip | ZIP compressed archive (2.4)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2019:11:29 18:32:01
ZipCRC: 0x27dbb79b
ZipCompressedSize: 11742
ZipUncompressedSize: 14282
ZipFileName: docProps/thumbnail.jpeg

XMP

Title: YOU MUST OPEN THIS FILE IN POWERPOINT AND ENABLE EDITING TO VIEW THIS PRESENTATION
Creator: KnowBe4

XML

LastModifiedBy: KB4
RevisionNumber: 7
CreateDate: 2014:07:08 19:45:52Z
ModifyDate: 2018:06:21 08:42:27Z
TotalEditTime: 33 minutes
Words: 7
Application: Microsoft Macintosh PowerPoint
PresentationFormat: On-screen Show (4:3)
Paragraphs: 1
Slides: 1
Notes: -
HiddenSlides: -
MMClips: -
ScaleCrop: No
HeadingPairs:
  • Fonts Used
  • 2
  • Theme
  • 1
  • Slide Titles
  • 1
TitlesOfParts:
  • Arial
  • Calibri
  • Office Theme
  • PowerPoint Presentation
LinksUpToDate: No
SharedDoc: No
HyperlinksChanged: No
AppVersion: 16.0014
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
34
Monitored processes
1
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start powerpnt.exe

Process information

PID
CMD
Path
Indicators
Parent process
2108"C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE" "C:\Users\admin\AppData\Local\Temp\VM_0131_05_2018.pptx"C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft PowerPoint
Exit code:
0
Version:
14.0.6009.1000
Modules
Images
c:\program files\microsoft office\office14\powerpnt.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\program files\microsoft office\office14\ppcore.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
658
Read events
601
Write events
50
Delete events
7

Modification events

(PID) Process:(2108) POWERPNT.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\PowerPoint\Resiliency\StartupItems
Operation:writeName:6=f
Value:
363D66003C080000010000000000000000000000
(PID) Process:(2108) POWERPNT.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
Off
(PID) Process:(2108) POWERPNT.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1041
Value:
Off
(PID) Process:(2108) POWERPNT.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1046
Value:
Off
(PID) Process:(2108) POWERPNT.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1036
Value:
Off
(PID) Process:(2108) POWERPNT.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1031
Value:
Off
(PID) Process:(2108) POWERPNT.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1040
Value:
Off
(PID) Process:(2108) POWERPNT.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1049
Value:
Off
(PID) Process:(2108) POWERPNT.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:3082
Value:
Off
(PID) Process:(2108) POWERPNT.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
Operation:writeName:PPTFiles
Value:
1333919768
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2108POWERPNT.EXEC:\Users\admin\AppData\Local\Temp\CVRB2D0.tmp.cvr
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2108
POWERPNT.EXE
GET
200
54.89.33.68:80
http://na01.safelinks.protection.outlook.com.url.protected-forms.com/XYWNf0aW9uPWcF0dGFjaGb1lbnQmudcmVjoaXBpZW50kX2dlkPTUzODMwMTgwMSZjiYW1wYWlnbl9ydW5faWQ9MjU5MzcxMQ==
US
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2108
POWERPNT.EXE
54.89.33.68:80
na01.safelinks.protection.outlook.com.url.protected-forms.com
Amazon.com, Inc.
US
malicious

DNS requests

Domain
IP
Reputation
na01.safelinks.protection.outlook.com.url.protected-forms.com
  • 54.89.33.68
  • 54.88.231.54
  • 34.237.206.61
  • 54.164.206.23
  • 34.195.155.78
  • 34.192.55.249
whitelisted

Threats

No threats detected
No debug info