| File name: | gtky-magazine-covers.pptx |
| Full analysis: | https://app.any.run/tasks/a7754745-3ae3-48be-8548-68dab61ca09b |
| Verdict: | No threats detected |
| Analysis date: | July 19, 2018, 13:13:24 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| MIME: | application/vnd.openxmlformats-officedocument.presentationml.presentation |
| File info: | Microsoft PowerPoint 2007+ |
| MD5: | 0A7E11581B48808E8351454AFA59E20F |
| SHA1: | 0D0CC2D91E08687E4CC5C04F055F7F382DDAE488 |
| SHA256: | D062FAA41377CDFB1653C94B08118F1B6C12C2995FB90737E87402441D61876B |
| SSDEEP: | 49152:tB+qJWBCCppLaSmZdxMRQANxYWgeUGYoiFzkdzDvKzUBRUtHvqk6LugRifc26:tB6ZXYb3ixBUlFVWnKWRQHyXLhRiS |
| .pptx | | | PowerPoint Microsoft Office Open XML Format document (87) |
|---|---|---|
| .zip | | | Open Packaging Conventions container (10.5) |
| .zip | | | ZIP compressed archive (2.4) |
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0006 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 1980:01:01 00:00:00 |
| ZipCRC: | 0x5769257a |
| ZipCompressedSize: | 492 |
| ZipUncompressedSize: | 3569 |
| ZipFileName: | [Content_Types].xml |
| TotalEditTime: | 44 minutes |
|---|---|
| Words: | 53 |
| Application: | Microsoft Macintosh PowerPoint |
| PresentationFormat: | On-screen Show (4:3) |
| Paragraphs: | 4 |
| Slides: | 3 |
| Notes: | - |
| HiddenSlides: | - |
| MMClips: | - |
| ScaleCrop: | No |
| HeadingPairs: |
|
| TitlesOfParts: |
|
| Company: | - |
| LinksUpToDate: | No |
| SharedDoc: | No |
| HyperlinksChanged: | No |
| AppVersion: | 14 |
| LastModifiedBy: | Lozzie |
| RevisionNumber: | 7 |
| CreateDate: | 2012:03:30 07:55:29Z |
| ModifyDate: | 2016:11:10 11:22:12Z |
| Title: | Scenario: |
|---|---|
| Creator: | Erin Fenton |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3796 | "C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE" "C:\Users\admin\AppData\Local\Temp\gtky-magazine-covers.pptx" | C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft PowerPoint Exit code: 0 Version: 14.0.6009.1000 Modules
| |||||||||||||||
| (PID) Process: | (3796) POWERPNT.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\PowerPoint\Resiliency\StartupItems |
| Operation: | write | Name: | <s6 |
Value: 3C733600D40E0000010000000000000000000000 | |||
| (PID) Process: | (3796) POWERPNT.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: Off | |||
| (PID) Process: | (3796) POWERPNT.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: On | |||
| (PID) Process: | (3796) POWERPNT.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Outlook\Journaling\Microsoft PowerPoint |
| Operation: | write | Name: | Enabled |
Value: 0 | |||
| (PID) Process: | (3796) POWERPNT.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\PowerPoint |
| Operation: | write | Name: | MTTT |
Value: D40E00008A1EEE57621FD40100000000 | |||
| (PID) Process: | (3796) POWERPNT.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\PowerPoint\Resiliency\StartupItems |
| Operation: | write | Name: | ut6 |
Value: 75743600D40E000006000000010000008800000002000000780000000400000063003A005C00750073006500720073005C00610064006D0069006E005C0061007000700064006100740061005C006C006F00630061006C005C00740065006D0070005C00670074006B0079002D006D006100670061007A0069006E0065002D0063006F0076006500720073002E007000700074007800000000000000 | |||
| (PID) Process: | (3796) POWERPNT.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3796) POWERPNT.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (3796) POWERPNT.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage |
| Operation: | write | Name: | PPTFiles |
Value: 1290993689 | |||
| (PID) Process: | (3796) POWERPNT.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage |
| Operation: | write | Name: | ProductFiles |
Value: 1290993739 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3796 | POWERPNT.EXE | C:\Users\admin\AppData\Local\Temp\CVRAB4B.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 3796 | POWERPNT.EXE | C:\Users\admin\AppData\Local\Temp\~DF7CD668BCF2B497B6.TMP | — | |
MD5:— | SHA256:— | |||
| 3796 | POWERPNT.EXE | C:\Users\admin\AppData\Local\Temp\~DFA64EE055156F2B04.TMP | — | |
MD5:— | SHA256:— | |||
| 3796 | POWERPNT.EXE | C:\Users\admin\AppData\Local\Temp\~$gtky-magazine-covers.pptx | — | |
MD5:— | SHA256:— | |||
| 3796 | POWERPNT.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\13127241.png | — | |
MD5:— | SHA256:— | |||
| 3796 | POWERPNT.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\7C77EB40.png | — | |
MD5:— | SHA256:— | |||
| 3796 | POWERPNT.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\5A45AF7B.png | — | |
MD5:— | SHA256:— | |||
| 3796 | POWERPNT.EXE | C:\Users\admin\AppData\Roaming\Microsoft\UProof\ExcludeDictionaryEN0409.lex | text | |
MD5:F3B25701FE362EC84616A93A45CE9998 | SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209 | |||