analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

VM_0131_05_2018.pptx

Full analysis: https://app.any.run/tasks/b9925b66-754e-4038-8b27-6ed121ab4c19
Verdict: Malicious activity
Analysis date: December 02, 2019, 20:43:53
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

CD2EB32A5BEC47E2CFA21F8F77CB531F

SHA1:

1562C6C0709D91B76F1C156E8CDC00EEF1C4F043

SHA256:

43C0649A6428EBF5627285CEF451AE3235145E7FFF430368CD806998B59D3AC5

SSDEEP:

3072:vEbWShumh6QYYw+TQSCatsSSKGBhJuaEvrJkAwc6J+NWe:nOuiG5+TFCats7Kah8Ng3e

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Unusual connect from Microsoft Office

      • POWERPNT.EXE (PID: 2108)
    • Checks supported languages

      • POWERPNT.EXE (PID: 2108)
  • INFO

    • Reads Microsoft Office registry keys

      • POWERPNT.EXE (PID: 2108)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.pptx | PowerPoint Microsoft Office Open XML Format document (87)
.zip | Open Packaging Conventions container (10.5)
.zip | ZIP compressed archive (2.4)

EXIF

XML

AppVersion: 16.0014
HyperlinksChanged: No
SharedDoc: No
LinksUpToDate: No
TitlesOfParts:
  • Arial
  • Calibri
  • Office Theme
  • PowerPoint Presentation
HeadingPairs:
  • Fonts Used
  • 2
  • Theme
  • 1
  • Slide Titles
  • 1
ScaleCrop: No
MMClips: -
HiddenSlides: -
Notes: -
Slides: 1
Paragraphs: 1
PresentationFormat: On-screen Show (4:3)
Application: Microsoft Macintosh PowerPoint
Words: 7
TotalEditTime: 33 minutes
ModifyDate: 2018:06:21 08:42:27Z
CreateDate: 2014:07:08 19:45:52Z
RevisionNumber: 7
LastModifiedBy: KB4

XMP

Creator: KnowBe4
Title: YOU MUST OPEN THIS FILE IN POWERPOINT AND ENABLE EDITING TO VIEW THIS PRESENTATION

ZIP

ZipFileName: docProps/thumbnail.jpeg
ZipUncompressedSize: 14282
ZipCompressedSize: 11742
ZipCRC: 0x27dbb79b
ZipModifyDate: 2019:11:29 18:32:01
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
34
Monitored processes
1
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start powerpnt.exe

Process information

PID
CMD
Path
Indicators
Parent process
2108"C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE" "C:\Users\admin\AppData\Local\Temp\VM_0131_05_2018.pptx"C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft PowerPoint
Version:
14.0.6009.1000
Total events
658
Read events
601
Write events
50
Delete events
7

Modification events

(PID) Process:(2108) POWERPNT.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\PowerPoint\Resiliency\StartupItems
Operation:writeName:6=f
Value:
363D66003C080000010000000000000000000000
(PID) Process:(2108) POWERPNT.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
Off
(PID) Process:(2108) POWERPNT.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1041
Value:
Off
(PID) Process:(2108) POWERPNT.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1046
Value:
Off
(PID) Process:(2108) POWERPNT.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1036
Value:
Off
(PID) Process:(2108) POWERPNT.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1031
Value:
Off
(PID) Process:(2108) POWERPNT.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1040
Value:
Off
(PID) Process:(2108) POWERPNT.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1049
Value:
Off
(PID) Process:(2108) POWERPNT.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:3082
Value:
Off
(PID) Process:(2108) POWERPNT.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
Operation:writeName:PPTFiles
Value:
1333919768
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2108POWERPNT.EXEC:\Users\admin\AppData\Local\Temp\CVRB2D0.tmp.cvr
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2108
POWERPNT.EXE
GET
200
54.89.33.68:80
http://na01.safelinks.protection.outlook.com.url.protected-forms.com/XYWNf0aW9uPWcF0dGFjaGb1lbnQmudcmVjoaXBpZW50kX2dlkPTUzODMwMTgwMSZjiYW1wYWlnbl9ydW5faWQ9MjU5MzcxMQ==
US
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2108
POWERPNT.EXE
54.89.33.68:80
na01.safelinks.protection.outlook.com.url.protected-forms.com
Amazon.com, Inc.
US
malicious

DNS requests

Domain
IP
Reputation
na01.safelinks.protection.outlook.com.url.protected-forms.com
  • 54.89.33.68
  • 54.88.231.54
  • 34.237.206.61
  • 54.164.206.23
  • 34.195.155.78
  • 34.192.55.249
whitelisted

Threats

No threats detected
No debug info