<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Secure Endpoint Closing Excel in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/secure-endpoint-closing-excel/m-p/4572447#M6758</link>
    <description>&lt;P&gt;So, You have Exprev Script control with enabled Quarantine - in the policy. This is the reason of shutting down the MS Excel. You might want to check details of the malicious dll, which was prevented from loading with the Excel launch. This could put you on the right track, to find the root cause. You better look up the events:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;in the Secure Console for details or&lt;/LI&gt;
&lt;LI&gt;the Windows event viewer&amp;gt;Applications and Services logs &amp;gt; Cisco Secure Client, filter current log and in the keywords field just insert the&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;filter current log and in the keywords field just insert the "&lt;STRONG&gt;Script Control:wbemdisp.dll&lt;/STRONG&gt;" or "&lt;STRONG&gt;Script Control"&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 17 Mar 2022 08:52:06 GMT</pubDate>
    <dc:creator>David Janulik</dc:creator>
    <dc:date>2022-03-17T08:52:06Z</dc:date>
    <item>
      <title>Secure Endpoint Closing Excel</title>
      <link>https://community.cisco.com/t5/endpoint-security/secure-endpoint-closing-excel/m-p/4571825#M6757</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A user is reporting that every time they try to work on a specific CSV file Secure Endpoint is shutting excel down.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;In the device trajectory i am getting the below info:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;An attack was prevented in&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Script Control:wbemdisp.dll&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;at base address&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;0x00007FF7EC730000&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;inside the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;EXCEL.EXE&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;process.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I think perhaps, the office version needs to be updated? has anyone else seen somthing similar?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;TIA&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 16:20:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/secure-endpoint-closing-excel/m-p/4571825#M6757</guid>
      <dc:creator>johnmac</dc:creator>
      <dc:date>2022-03-16T16:20:50Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Endpoint Closing Excel</title>
      <link>https://community.cisco.com/t5/endpoint-security/secure-endpoint-closing-excel/m-p/4572447#M6758</link>
      <description>&lt;P&gt;So, You have Exprev Script control with enabled Quarantine - in the policy. This is the reason of shutting down the MS Excel. You might want to check details of the malicious dll, which was prevented from loading with the Excel launch. This could put you on the right track, to find the root cause. You better look up the events:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;in the Secure Console for details or&lt;/LI&gt;
&lt;LI&gt;the Windows event viewer&amp;gt;Applications and Services logs &amp;gt; Cisco Secure Client, filter current log and in the keywords field just insert the&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;filter current log and in the keywords field just insert the "&lt;STRONG&gt;Script Control:wbemdisp.dll&lt;/STRONG&gt;" or "&lt;STRONG&gt;Script Control"&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2022 08:52:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/secure-endpoint-closing-excel/m-p/4572447#M6758</guid>
      <dc:creator>David Janulik</dc:creator>
      <dc:date>2022-03-17T08:52:06Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Endpoint Closing Excel</title>
      <link>https://community.cisco.com/t5/endpoint-security/secure-endpoint-closing-excel/m-p/4577828#M6769</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1321068"&gt;@johnmac&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;have you checked the policy and being able so solve the issue?&lt;BR /&gt;Greetings, Thorsten&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2022 13:47:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/secure-endpoint-closing-excel/m-p/4577828#M6769</guid>
      <dc:creator>Troja007</dc:creator>
      <dc:date>2022-03-24T13:47:26Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Endpoint Closing Excel</title>
      <link>https://community.cisco.com/t5/endpoint-security/secure-endpoint-closing-excel/m-p/4582864#M6777</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/201848"&gt;@David Janulik&lt;/a&gt;, thanks for the response.&amp;nbsp; The details of the event when i try to open the CSV file myself are below...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;PID 18388&lt;BR /&gt;TimeStamp 1648552388&lt;BR /&gt;ProcessName C:\Program Files\Microsoft Office\Office16\EXCEL.EXE&lt;BR /&gt;AttackInfo {"afps":"C:\\Program Files\\Microsoft Office\\Office16\\EXCEL.EXE","ams":"Script Control:wbemdisp.dll","at":"2022-03-29 11:13:03","bas":"0x00007FF623E80000","edvs":"4.1.10.65","sfs":["C:\\Users\\johnwmcnamara\\Downloads\\Model 4000 Data Capture WMI 32+64Bit Trial.xls","7ddd900311d2865ff2664a80c079c81302d8f5184cf9d4e0369c94920b98334f"],"sus":[""],"u":"johnwmcnamara@RCSI"}&lt;BR /&gt;SuspiciousFiles C:\Users\johnwmcnamara\Downloads\Model 4000 Data Capture WMI 32+64Bit Trial.xls&lt;BR /&gt;ParentProcessName C:\Windows\explorer.exe&lt;BR /&gt;ParentProcessPID 15756&lt;BR /&gt;ScriptControlBadDll wbemdisp.dll&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;I know there was a notice sent out recently regarding false positives with explorer.exe, could this be related to that?&lt;/DIV&gt;</description>
      <pubDate>Thu, 31 Mar 2022 08:31:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/secure-endpoint-closing-excel/m-p/4582864#M6777</guid>
      <dc:creator>johnmac</dc:creator>
      <dc:date>2022-03-31T08:31:48Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Endpoint Closing Excel</title>
      <link>https://community.cisco.com/t5/endpoint-security/secure-endpoint-closing-excel/m-p/4582880#M6778</link>
      <description>&lt;P&gt;What I can see is a clear message to you from the Event:&lt;BR /&gt;wbemdisp.dll (Common Excel DLL) is used-injected by this file, most probably for WMI script&lt;BR /&gt;SuspiciousFiles C:\Users\johnwmcnamara\Downloads\Model 4000 Data Capture WMI 32+64Bit Trial.xls&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You need to investigate this particular file for malicious activity. This is job e.g. for Secure Malware Analytics, or investigate the event in the Secure Console via event - is there any Mitre ATT&amp;amp;CK link? This has nothing to do with explorer.exe, because to open the file you always use Explorer.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 08:50:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/secure-endpoint-closing-excel/m-p/4582880#M6778</guid>
      <dc:creator>David Janulik</dc:creator>
      <dc:date>2022-03-31T08:50:58Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Endpoint Closing Excel</title>
      <link>https://community.cisco.com/t5/endpoint-security/secure-endpoint-closing-excel/m-p/4583034#M6779</link>
      <description>&lt;P&gt;Thanks for your help &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/201848"&gt;@David Janulik&lt;/a&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 12:57:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/secure-endpoint-closing-excel/m-p/4583034#M6779</guid>
      <dc:creator>johnmac</dc:creator>
      <dc:date>2022-03-31T12:57:33Z</dc:date>
    </item>
  </channel>
</rss>

