IOC Report
excel_to_csv.exe

loading gif

Files

File Path
Type
Category
Malicious
excel_to_csv.exe
PE32+ executable (console) x86-64, for MS Windows
initial sample
C:\Users\user\AppData\Local\Temp\94scgqrg
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\IPython\core\profile\README_STARTUP
troff or preprocessor input, ASCII text
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\IPython\core\tests\2x2.jpg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 2x2, components 1
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\IPython\core\tests\2x2.png
PNG image data, 2 x 2, 8-bit grayscale, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\IPython\extensions\__init__.py
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\IPython\extensions\__pycache__\__init__.cpython-39.pyc
python 3.9 byte-compiled
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\IPython\extensions\__pycache__\autoreload.cpython-39.pyc
python 3.9 byte-compiled
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\IPython\extensions\__pycache__\cythonmagic.cpython-39.pyc
python 3.9 byte-compiled
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\IPython\extensions\__pycache__\rmagic.cpython-39.pyc
python 3.9 byte-compiled
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\IPython\extensions\__pycache__\storemagic.cpython-39.pyc
python 3.9 byte-compiled
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\IPython\extensions\__pycache__\sympyprinting.cpython-39.pyc
python 3.9 byte-compiled
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\IPython\extensions\autoreload.py
Python script, ASCII text executable
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\IPython\extensions\cythonmagic.py
Python script, ASCII text executable
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\IPython\extensions\rmagic.py
Python script, ASCII text executable
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\IPython\extensions\storemagic.py
Python script, ASCII text executable
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\IPython\extensions\sympyprinting.py
Python script, ASCII text executable
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\IPython\extensions\tests\__pycache__\__init__.cpython-39.pyc
python 3.9 byte-compiled
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\IPython\extensions\tests\__pycache__\test_autoreload.cpython-39.pyc
python 3.9 byte-compiled
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\IPython\extensions\tests\__pycache__\test_storemagic.cpython-39.pyc
python 3.9 byte-compiled
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\IPython\extensions\tests\test_autoreload.py
Python script, ASCII text executable
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\IPython\extensions\tests\test_storemagic.py
Python script, ASCII text executable
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\IPython\lib\tests\test.wav
RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, mono 44100 Hz
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\IPython\testing\plugin\README.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\IPython\testing\plugin\test_combo.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\IPython\testing\plugin\test_example.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\IPython\testing\plugin\test_exampleip.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\PIL\_imaging.cp39-win_amd64.pyd
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\PIL\_imagingft.cp39-win_amd64.pyd
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\PIL\_imagingtk.cp39-win_amd64.pyd
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\PIL\_webp.cp39-win_amd64.pyd
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\VCRUNTIME140.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\_asyncio.pyd
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\_bz2.pyd
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\_cffi_backend.cp39-win_amd64.pyd
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\_ctypes.pyd
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\_decimal.pyd
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\_elementtree.pyd
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\_hashlib.pyd
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\_lzma.pyd
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\_multiprocessing.pyd
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\_overlapped.pyd
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\_queue.pyd
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\_socket.pyd
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\_sqlite3.pyd
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\_ssl.pyd
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\_tkinter.pyd
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\_uuid.pyd
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\_win32sysloader.pyd
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\altgraph-0.17.dist-info\INSTALLER
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\altgraph-0.17.dist-info\LICENSE
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\altgraph-0.17.dist-info\METADATA
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\altgraph-0.17.dist-info\RECORD
CSV text
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\altgraph-0.17.dist-info\WHEEL
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\altgraph-0.17.dist-info\top_level.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\altgraph-0.17.dist-info\zip-safe
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\base_library.zip
Zip archive data, at least v2.0 to extract, compression method=store
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\bcrypt\_bcrypt.pyd
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\certifi\cacert.pem
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\concrt140.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\coverage\tracer.cp39-win_amd64.pyd
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\cryptography-3.3.2.dist-info\AUTHORS.rst
Unicode text, UTF-8 text
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\cryptography-3.3.2.dist-info\LICENSE
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\cryptography-3.3.2.dist-info\LICENSE.APACHE
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\cryptography-3.3.2.dist-info\LICENSE.BSD
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\cryptography-3.3.2.dist-info\LICENSE.PSF
Unicode text, UTF-8 text
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\cryptography-3.3.2.dist-info\METADATA
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\cryptography-3.3.2.dist-info\RECORD
CSV text
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\cryptography-3.3.2.dist-info\WHEEL
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\_MEI37162\cryptography-3.3.2.dist-info\top_level.txt
ASCII text
dropped