.. /.Ppam

Executable
Phishing
Doubleclick

Contributors:

Adithya - @ravooriadithya

Description:

A PPAM file is a PowerPoint macro-enabled Open XML add-in file used by Microsoft PowerPoint, a program used to develop slide show presentations. This file type was introduced in 2007 with the release of Microsoft Office 2007. It contains components that add additional functionality, including extra commands, custom macros, and new tools for extending default PowerPoint functions. PPAM files are found to be misused by various threat actors which include cyber crime where Agent tesla has been found to be leveraging these types more often

OS:

Windows
Mac

Recommendation:

Block PPAM extensions over Email and Web Proxies

Resources:

https://www.mcafee.com/blogs/other-blogs/mcafee-labs/malicious-powerpoint-documents-on-the-rise/

File Samples:

https://www.virustotal.com/gui/file/fb594d96d2eaeb8817086ae8dcc7cc5bd1367f2362fc2194aea8e0802024b182/details