Windows Analysis Report
ADHDtalk_Fabiano_Div53_03152023.pptx

Overview

General Information

Sample name: ADHDtalk_Fabiano_Div53_03152023.pptx
Analysis ID: 1426754
MD5: eeca21419e2f78ff84dbdca31efd5c31
SHA1: 534f125028c2a56e621e772f7114c2928f5dd367
SHA256: 473fb3597a79963919a4fd8560c74954b0b6d6e89fa49a10498de65d6de472b7
Infos:

Detection

Score: 2
Range: 0 - 100
Whitelisted: false
Confidence: 40%

Signatures

Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Queries the volume information (name, serial number etc) of a device
Sigma detected: Suspicious Office Outbound Connections

Classification

Source: unknown HTTPS traffic detected: 52.123.247.54:443 -> 192.168.2.16:49704 version: TLS 1.2
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 192.168.2.16:49704 -> 52.123.247.54:443
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: global traffic TCP traffic: 52.123.247.54:443 -> 192.168.2.16:49704
Source: powerpnt.exe Memory has grown: Private usage: 2MB later: 60MB
Source: unknown Network traffic detected: HTTP traffic on port 49704 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49704
Source: unknown HTTPS traffic detected: 52.123.247.54:443 -> 192.168.2.16:49704 version: TLS 1.2
Source: classification engine Classification label: clean2.winPPTX@3/154@0/46
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE File created: C:\Users\user\AppData\Roaming\Microsoft\PowerPoint
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE File created: C:\Users\user\AppData\Local\Temp\{4423C113-4676-4C72-918D-39B7EC6C6402} - OProcSessId.dat
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE File read: C:\Users\desktop.ini
Source: unknown Process created: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\POWERPNT.EXE" "C:\Users\user\Desktop\ADHDtalk_Fabiano_Div53_03152023.pptx" /ou ""
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "C7EE03BD-F81A-4353-B6B8-B6824FDB02F4" "7913559F-EC3B-4088-83D9-A352723E93A4" "7020" "C:\Program Files (x86)\Microsoft Office\Root\Office16\POWERPNT.EXE" "PowerPointCombinedFloatieLreOnline.onnx"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "C7EE03BD-F81A-4353-B6B8-B6824FDB02F4" "7913559F-EC3B-4088-83D9-A352723E93A4" "7020" "C:\Program Files (x86)\Microsoft Office\Root\Office16\POWERPNT.EXE" "PowerPointCombinedFloatieLreOnline.onnx"
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: apphelp.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: c2r64.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: userenv.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: msasn1.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: cryptsp.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: rsaenh.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: cryptbase.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: gpapi.dll
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{88d96a0f-f192-11d4-a65f-0040963251e5}\InProcServer32
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common
Source: ADHDtalk_Fabiano_Div53_03152023.pptx Static file information: File size 15410707 > 1048576
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information queried: ProcessInformation
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Queries volume information: C:\Program Files (x86)\Microsoft Office\root\Office16\AI\PowerPointCombinedFloatieLreOnline.onnx VolumeInformation
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs