Windows Analysis Report
07762.zip

Overview

General Information

Sample name: 07762.zip
Analysis ID: 1431104
MD5: 28d34d33496fa2ea685355ccd94d2210
SHA1: 3d3ea089e37c1bc81ab8a6055606a96459a6b196
SHA256: cc44f1bf066ba41193ad714cb091aee60d89883e44fefa8aebbb1c6016b5a9f1

Detection

Score: 0
Range: 0 - 100
Whitelisted: false
Confidence: 80%

Signatures

Queries the volume information (name, serial number etc) of a device

Classification

Source: C:\Windows\System32\notepad.exe Window detected: IMPORTANT NOTICE: This license only applies if you downloaded this content asan unsubscribed user. If you are a premium user (ie you pay a subscription)you are bound to the license terms described in the accompanying file"License Premium.txt".---------------------You must attribute the template to its author:In order to use a content or a part of it you must attribute it to Author Name / PoweredTemplateso we will be able to continue creating new graphic resources every day.How to attribute it?For presentations:Insert the attribution line in the credits section of your presentation. For example: This presentation has been designed using resources from PoweredTemplate.comFor websites:Please copy this code on your website to accredit the author:<a href="https://PoweredTemplate.com">Designed by Author Name / PoweredTemplate</a>For printing:Paste this text on the final work so the authorship is known.- For example in the acknowledgements chapter of a book:"Designed by Author Name / PoweredTemplate"You are free to use this template:- For both personal and commercial projects and to modify it.- Presentation template or application or as part of your design.You are not allowed to:- Sub-license resell distribute or rent it.- Include it in any online or offline archive or database.- To use content or any of its part in stock items/templates.- For presentation templates: The use of content totally or partially as part of a website design.The full terms of the license are described in sections 7 and 8 of the PoweredTemplateterms of use available online in the following link: https://poweredtemplate.com/policy.htmlThe terms described in the above link have precedence over the terms describedin the present document. In case of disagreement the PoweredTemplate Terms of Use will prevail.
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE File opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dll
Source: powerpnt.exe Memory has grown: Private usage: 17MB later: 76MB
Source: classification engine Classification label: clean0.winZIP@11/93@0/34
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE File created: C:\Users\user\AppData\Roaming\Microsoft\PowerPoint
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE File created: C:\Users\user\AppData\Local\Temp\{BE8F30FD-744E-4700-B501-AFAD5F00A642} - OProcSessId.dat
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE File read: C:\Users\desktop.ini
Source: C:\Windows\System32\rundll32.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: unknown Process created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: unknown Process created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: unknown Process created: C:\Windows\System32\notepad.exe "C:\Windows\system32\NOTEPAD.EXE" C:\Users\user\AppData\Local\Temp\Temp1_07762.zip\License Free.txt
Source: unknown Process created: C:\Windows\System32\notepad.exe "C:\Windows\system32\NOTEPAD.EXE" C:\Users\user\AppData\Local\Temp\Temp1_07762.zip\License Premium.txt
Source: unknown Process created: C:\Windows\System32\notepad.exe "C:\Windows\system32\NOTEPAD.EXE" C:\Users\user\AppData\Local\Temp\Temp1_07762.zip\License Free.txt
Source: unknown Process created: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\POWERPNT.EXE" "C:\Users\user\AppData\Local\Temp\Temp1_07762.zip\9147.pptx" /ou ""
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "CE8C68FA-3231-4514-8C06-29F37A756456" "8D683D65-D06C-48E9-BE7E-725356EC104A" "3900" "C:\Program Files (x86)\Microsoft Office\Root\Office16\POWERPNT.EXE" "PowerPointCombinedFloatieLreOnline.onnx"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "CE8C68FA-3231-4514-8C06-29F37A756456" "8D683D65-D06C-48E9-BE7E-725356EC104A" "3900" "C:\Program Files (x86)\Microsoft Office\Root\Office16\POWERPNT.EXE" "PowerPointCombinedFloatieLreOnline.onnx"
Source: unknown Process created: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\POWERPNT.EXE" "C:\Users\user\Desktop\07762\9147.pptx" /ou ""
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "6897F103-C475-47A1-B4D2-6F32E7B382BE" "2CB64361-22CC-4FC4-B8B0-5769DC4D85C0" "6968" "C:\Program Files (x86)\Microsoft Office\Root\Office16\POWERPNT.EXE" "PowerPointCombinedFloatieLreOnline.onnx"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "6897F103-C475-47A1-B4D2-6F32E7B382BE" "2CB64361-22CC-4FC4-B8B0-5769DC4D85C0" "6968" "C:\Program Files (x86)\Microsoft Office\Root\Office16\POWERPNT.EXE" "PowerPointCombinedFloatieLreOnline.onnx"
Source: unknown Process created: C:\Windows\System32\notepad.exe "C:\Windows\system32\NOTEPAD.EXE" C:\Users\user\Desktop\07762\License Free.txt
Source: C:\Windows\System32\notepad.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\System32\notepad.exe Section loaded: uxtheme.dll
Source: C:\Windows\System32\notepad.exe Section loaded: mrmcorer.dll
Source: C:\Windows\System32\notepad.exe Section loaded: windows.storage.dll
Source: C:\Windows\System32\notepad.exe Section loaded: wldp.dll
Source: C:\Windows\System32\notepad.exe Section loaded: textshaping.dll
Source: C:\Windows\System32\notepad.exe Section loaded: efswrt.dll
Source: C:\Windows\System32\notepad.exe Section loaded: mpr.dll
Source: C:\Windows\System32\notepad.exe Section loaded: wintypes.dll
Source: C:\Windows\System32\notepad.exe Section loaded: twinapi.appcore.dll
Source: C:\Windows\System32\notepad.exe Section loaded: oleacc.dll
Source: C:\Windows\System32\notepad.exe Section loaded: textinputframework.dll
Source: C:\Windows\System32\notepad.exe Section loaded: coreuicomponents.dll
Source: C:\Windows\System32\notepad.exe Section loaded: coremessaging.dll
Source: C:\Windows\System32\notepad.exe Section loaded: ntmarta.dll
Source: C:\Windows\System32\notepad.exe Section loaded: urlmon.dll
Source: C:\Windows\System32\notepad.exe Section loaded: iertutil.dll
Source: C:\Windows\System32\notepad.exe Section loaded: srvcli.dll
Source: C:\Windows\System32\notepad.exe Section loaded: netutils.dll
Source: C:\Windows\System32\notepad.exe Section loaded: propsys.dll
Source: C:\Windows\System32\notepad.exe Section loaded: policymanager.dll
Source: C:\Windows\System32\notepad.exe Section loaded: msvcp110_win.dll
Source: C:\Windows\System32\notepad.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\System32\notepad.exe Section loaded: uxtheme.dll
Source: C:\Windows\System32\notepad.exe Section loaded: mrmcorer.dll
Source: C:\Windows\System32\notepad.exe Section loaded: windows.storage.dll
Source: C:\Windows\System32\notepad.exe Section loaded: wldp.dll
Source: C:\Windows\System32\notepad.exe Section loaded: textshaping.dll
Source: C:\Windows\System32\notepad.exe Section loaded: efswrt.dll
Source: C:\Windows\System32\notepad.exe Section loaded: mpr.dll
Source: C:\Windows\System32\notepad.exe Section loaded: wintypes.dll
Source: C:\Windows\System32\notepad.exe Section loaded: twinapi.appcore.dll
Source: C:\Windows\System32\notepad.exe Section loaded: oleacc.dll
Source: C:\Windows\System32\notepad.exe Section loaded: textinputframework.dll
Source: C:\Windows\System32\notepad.exe Section loaded: coreuicomponents.dll
Source: C:\Windows\System32\notepad.exe Section loaded: coremessaging.dll
Source: C:\Windows\System32\notepad.exe Section loaded: ntmarta.dll
Source: C:\Windows\System32\notepad.exe Section loaded: urlmon.dll
Source: C:\Windows\System32\notepad.exe Section loaded: iertutil.dll
Source: C:\Windows\System32\notepad.exe Section loaded: srvcli.dll
Source: C:\Windows\System32\notepad.exe Section loaded: netutils.dll
Source: C:\Windows\System32\notepad.exe Section loaded: propsys.dll
Source: C:\Windows\System32\notepad.exe Section loaded: policymanager.dll
Source: C:\Windows\System32\notepad.exe Section loaded: msvcp110_win.dll
Source: C:\Windows\System32\notepad.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\System32\notepad.exe Section loaded: uxtheme.dll
Source: C:\Windows\System32\notepad.exe Section loaded: mrmcorer.dll
Source: C:\Windows\System32\notepad.exe Section loaded: windows.storage.dll
Source: C:\Windows\System32\notepad.exe Section loaded: wldp.dll
Source: C:\Windows\System32\notepad.exe Section loaded: textshaping.dll
Source: C:\Windows\System32\notepad.exe Section loaded: efswrt.dll
Source: C:\Windows\System32\notepad.exe Section loaded: mpr.dll
Source: C:\Windows\System32\notepad.exe Section loaded: wintypes.dll
Source: C:\Windows\System32\notepad.exe Section loaded: twinapi.appcore.dll
Source: C:\Windows\System32\notepad.exe Section loaded: oleacc.dll
Source: C:\Windows\System32\notepad.exe Section loaded: textinputframework.dll
Source: C:\Windows\System32\notepad.exe Section loaded: coreuicomponents.dll
Source: C:\Windows\System32\notepad.exe Section loaded: coremessaging.dll
Source: C:\Windows\System32\notepad.exe Section loaded: ntmarta.dll
Source: C:\Windows\System32\notepad.exe Section loaded: coremessaging.dll
Source: C:\Windows\System32\notepad.exe Section loaded: urlmon.dll
Source: C:\Windows\System32\notepad.exe Section loaded: iertutil.dll
Source: C:\Windows\System32\notepad.exe Section loaded: srvcli.dll
Source: C:\Windows\System32\notepad.exe Section loaded: netutils.dll
Source: C:\Windows\System32\notepad.exe Section loaded: propsys.dll
Source: C:\Windows\System32\notepad.exe Section loaded: policymanager.dll
Source: C:\Windows\System32\notepad.exe Section loaded: msvcp110_win.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: apphelp.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: c2r64.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: userenv.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: msasn1.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: cryptsp.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: rsaenh.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: cryptbase.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: gpapi.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: c2r64.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: userenv.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: msasn1.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: cryptsp.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: rsaenh.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: cryptbase.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: gpapi.dll
Source: C:\Windows\System32\notepad.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\System32\notepad.exe Section loaded: uxtheme.dll
Source: C:\Windows\System32\notepad.exe Section loaded: mrmcorer.dll
Source: C:\Windows\System32\notepad.exe Section loaded: windows.storage.dll
Source: C:\Windows\System32\notepad.exe Section loaded: wldp.dll
Source: C:\Windows\System32\notepad.exe Section loaded: textshaping.dll
Source: C:\Windows\System32\notepad.exe Section loaded: efswrt.dll
Source: C:\Windows\System32\notepad.exe Section loaded: mpr.dll
Source: C:\Windows\System32\notepad.exe Section loaded: wintypes.dll
Source: C:\Windows\System32\notepad.exe Section loaded: twinapi.appcore.dll
Source: C:\Windows\System32\notepad.exe Section loaded: oleacc.dll
Source: C:\Windows\System32\notepad.exe Section loaded: textinputframework.dll
Source: C:\Windows\System32\notepad.exe Section loaded: coreuicomponents.dll
Source: C:\Windows\System32\notepad.exe Section loaded: coremessaging.dll
Source: C:\Windows\System32\notepad.exe Section loaded: ntmarta.dll
Source: C:\Windows\System32\notepad.exe Section loaded: coremessaging.dll
Source: C:\Windows\System32\notepad.exe Section loaded: urlmon.dll
Source: C:\Windows\System32\notepad.exe Section loaded: iertutil.dll
Source: C:\Windows\System32\notepad.exe Section loaded: srvcli.dll
Source: C:\Windows\System32\notepad.exe Section loaded: netutils.dll
Source: C:\Windows\System32\notepad.exe Section loaded: propsys.dll
Source: C:\Windows\System32\notepad.exe Section loaded: policymanager.dll
Source: C:\Windows\System32\notepad.exe Section loaded: msvcp110_win.dll
Source: C:\Windows\System32\notepad.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11659a23-5884-4d1b-9cf6-67d6f4f90b36}\InProcServer32
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Windows\System32\notepad.exe Window detected: IMPORTANT NOTICE: This license only applies if you downloaded this content asan unsubscribed user. If you are a premium user (ie you pay a subscription)you are bound to the license terms described in the accompanying file"License Premium.txt".---------------------You must attribute the template to its author:In order to use a content or a part of it you must attribute it to Author Name / PoweredTemplateso we will be able to continue creating new graphic resources every day.How to attribute it?For presentations:Insert the attribution line in the credits section of your presentation. For example: This presentation has been designed using resources from PoweredTemplate.comFor websites:Please copy this code on your website to accredit the author:<a href="https://PoweredTemplate.com">Designed by Author Name / PoweredTemplate</a>For printing:Paste this text on the final work so the authorship is known.- For example in the acknowledgements chapter of a book:"Designed by Author Name / PoweredTemplate"You are free to use this template:- For both personal and commercial projects and to modify it.- Presentation template or application or as part of your design.You are not allowed to:- Sub-license resell distribute or rent it.- Include it in any online or offline archive or database.- To use content or any of its part in stock items/templates.- For presentation templates: The use of content totally or partially as part of a website design.The full terms of the license are described in sections 7 and 8 of the PoweredTemplateterms of use available online in the following link: https://poweredtemplate.com/policy.htmlThe terms described in the above link have precedence over the terms describedin the present document. In case of disagreement the PoweredTemplate Terms of Use will prevail.
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office
Source: 07762.zip Static file information: File size 2334361 > 1048576
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE File opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dll
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE Process information queried: ProcessInformation
Source: C:\Windows\System32\notepad.exe Queries volume information: C:\Users\user\AppData\Local\Temp\Temp1_07762.zip\License Free.txt VolumeInformation
Source: C:\Windows\System32\notepad.exe Queries volume information: C:\Users\user\AppData\Local\Temp\Temp1_07762.zip\License Premium.txt VolumeInformation
Source: C:\Windows\System32\notepad.exe Queries volume information: C:\Users\user\AppData\Local\Temp\Temp1_07762.zip\License Free.txt VolumeInformation
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Queries volume information: C:\Program Files (x86)\Microsoft Office\root\Office16\AI\PowerPointCombinedFloatieLreOnline.onnx VolumeInformation
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Queries volume information: C:\Program Files (x86)\Microsoft Office\root\Office16\AI\PowerPointCombinedFloatieLreOnline.onnx VolumeInformation
Source: C:\Windows\System32\notepad.exe Queries volume information: C:\Users\user\Desktop\07762\License Free.txt VolumeInformation
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs