<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help with Memory corruption exploitation event in excel.exe in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/help-with-memory-corruption-exploitation-event-in-excel-exe/m-p/592780#M6986</link>
    <description>&lt;P&gt;maybe is this the problem???&amp;nbsp;&lt;BR /&gt;&lt;A href="https://answers.microsoft.com/en-us/msoffice/forum/all/why-is-splwow64exe-being-created-when-running/46f80fb4-0aa2-47f0-b64f-0985240929e8" target="_blank"&gt;Why is splwow64.exe being created when running Office 64-bit Word or - Microsoft Community&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 23 Jul 2024 12:16:46 GMT</pubDate>
    <dc:creator>tlmarques</dc:creator>
    <dc:date>2024-07-23T12:16:46Z</dc:date>
    <item>
      <title>Help with Memory corruption exploitation event in excel.exe</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/help-with-memory-corruption-exploitation-event-in-excel-exe/m-p/592778#M6985</link>
      <description>&lt;P&gt;Hi, I need your help.&lt;BR /&gt;When analyzing a Memory corruption exploitation event in excel.exe, the &lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;usually doesn't provide much information&lt;/P&gt;
&lt;P&gt;I can only see in the graphical interface that the user executed Excel at that moment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my case, it shows that the user opened an Excel file that was on a file share.&lt;/P&gt;
&lt;P&gt;I would like to know if anyone knows how I can obtain more data/information.&lt;BR /&gt;I downloaded all the Alert data...however, there is a lot of information that I can't understand.&lt;/P&gt;
&lt;P&gt;In the alert data I've downloaded, is it possible to know if it was a macro or another process that caused this error?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;some information below:&lt;/P&gt;
&lt;P&gt;{ec:DSE:EcDsePipeline:} cgo: path: C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE signer_name: Microsoft Corporation hash_sha256: 32f8bf94bdd77fa972809f01c755e2f51453cc2e5e48a689d5828b9e97592d82 { severity:4 do_not_disable: friendlyName:excel_exploit technique_id: [T1204.002, T1588.005, T1588.006, ] tactic_id: [TA0002, ] action:block external_description:Memory corruption exploitation in excel.exe profile_override: } Full activation: bioc.excel_exploit&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;"files": [&lt;BR /&gt;{&lt;BR /&gt;"companyName": "Microsoft Corporation",&lt;BR /&gt;"fileName": "EXCEL.EXE",&lt;BR /&gt;"fileSize": "18379976",&lt;BR /&gt;"md5": "f123e71cf4b7a68eaf5506f545e7db61",&lt;BR /&gt;"rawFullPath": "C:\\Program Files (x86)\\Microsoft Office\\Office12\\EXCEL.EXE",&lt;BR /&gt;"sha256": "32f8bf94bdd77fa972809f01c755e2f51453cc2e5e48a689d5828b9e97592d82",&lt;BR /&gt;"signers": [&lt;BR /&gt;"Microsoft Corporation"&lt;BR /&gt;],&lt;BR /&gt;"version": "12.0.6787.5000",&lt;BR /&gt;"versionCopyright": "© 2006 Microsoft Corporation. All rights reserved.",&lt;BR /&gt;"versionDescription": "Microsoft Office Excel",&lt;BR /&gt;"versionInternalName": "Excel",&lt;BR /&gt;"versionOriginalName": "Excel.exe"&lt;BR /&gt;},&lt;BR /&gt;{&lt;BR /&gt;"companyName": "Microsoft Corporation",&lt;BR /&gt;"fileName": "splwow64.exe",&lt;BR /&gt;"fileSize": "133632",&lt;BR /&gt;"md5": "fba2ce5c57ca89584e2f2ec4adad324f",&lt;BR /&gt;"rawFullPath": "C:\\Windows\\splwow64.exe",&lt;BR /&gt;"sha256": "67376910254b65243f4aa4c2c4d338eb4beb4111d0a82ec48ae7d438f581203c",&lt;BR /&gt;"signers": [&lt;BR /&gt;"Microsoft Corporation"&lt;BR /&gt;],&lt;BR /&gt;"version": "10.0.17763.4644 (WinBuild.160101.0800)",&lt;BR /&gt;"versionCopyright": "© Microsoft Corporation. All rights reserved.",&lt;BR /&gt;"versionDescription": "Print driver host for applications",&lt;BR /&gt;"versionInternalName": "splwow64.exe",&lt;BR /&gt;"versionOriginalName": "splwow64.exe"&lt;BR /&gt;}&lt;BR /&gt;],&lt;BR /&gt;"ipBlocked": 0,&lt;BR /&gt;"isScan": 0,&lt;BR /&gt;"moduleId": 71,&lt;BR /&gt;"moduleStatusId": 3225419879,&lt;BR /&gt;"modules": [&lt;/P&gt;
&lt;P&gt;],&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 12:07:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/help-with-memory-corruption-exploitation-event-in-excel-exe/m-p/592778#M6985</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2024-07-23T12:07:08Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Memory corruption exploitation event in excel.exe</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/help-with-memory-corruption-exploitation-event-in-excel-exe/m-p/592780#M6986</link>
      <description>&lt;P&gt;maybe is this the problem???&amp;nbsp;&lt;BR /&gt;&lt;A href="https://answers.microsoft.com/en-us/msoffice/forum/all/why-is-splwow64exe-being-created-when-running/46f80fb4-0aa2-47f0-b64f-0985240929e8" target="_blank"&gt;Why is splwow64.exe being created when running Office 64-bit Word or - Microsoft Community&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 12:16:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/help-with-memory-corruption-exploitation-event-in-excel-exe/m-p/592780#M6986</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2024-07-23T12:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Memory corruption exploitation event in excel.exe</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/help-with-memory-corruption-exploitation-event-in-excel-exe/m-p/592785#M6987</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tlmarques_2-1721737324810.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60997iD82A8C10B5037825/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="tlmarques_2-1721737324810.png" alt="tlmarques_2-1721737324810.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 12:22:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/help-with-memory-corruption-exploitation-event-in-excel-exe/m-p/592785#M6987</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2024-07-23T12:22:11Z</dc:date>
    </item>
  </channel>
</rss>

