.. /.Ppa

Executable
Phishing
Doubleclick

Contributors:

Adithya - @ravooriadithya

Description:

A PPA file is an add-in file used by Microsoft PowerPoint, a program that allows users to create presentations. It contains custom commands and macros written in the VBA (Visual Basic for Applications) language and is used to extend the capabilities of Microsoft PowerPoint. .ppa including .ppam file types had been traditionally used by various cybercrime groups to conduct their campaigns and operations.

OS:

Windows
Mac

Recommendation:

Block .ppa on email and web proxies.

Resources:

https://unit42.paloaltonetworks.com/operation-comando-or-how-to-run-a-cheap-and-effective-credit-card-business/

File Samples:

https://www.virustotal.com/gui/file/ee9d3c90df5c01dc6e2079d1219be752542a452988c4a25f34b8ee22be799332/details