Table of Contents
This practical guide explains how to Open the Infected PowerPoint File, Causing Hackers to Invade the Computer. It organizes the essential steps, important checks, and common issues into a clear sequence.
The remote code execution vulnerability in Microsoft Office (CVE-2017-0199) is in Windows Object Linking and Embedding (OLE), so the patch was released in April this year. But hazards can still appear in other ways.
Network security researchers at Trend Micro have discovered a new malware campaign that uses the same vulnerability, but this is the first time it has been hidden behind a PowerPoint file (PPSX).
According to the researchers, the attack will begin with a fake email attachment from the cable provider and is primarily targeted at companies in the electronics manufacturing industry. Researchers believe that this type of attack uses a disguised sender address as the business department's real email.
How to Attack via PowerPoint File
Step 1 : The email contains the malicious PowerPoint file (PPSX) in the fake attachment, providing delivery information about a certain order.
Fake email with content providing order information.
Step 2 : Once executed, the PPSX file will call a pre-programmed XML file in which to download the logo.doc file from the remote address and run it through the PowerPoint Show feature.
Step 3 : The logo file.doc will exploit the CVE-2017-0199 vulnerability, load and execute RATMAN.exe on the target system.
Step 4 : RATMAN.exe is a trojan version of Remcos Remote Control tool, when installed, will allow an attacker to control the infected computer from a remote C&C server.
Remcos is a legitimate tool but hackers create trojans.
Remcos is a legally customizable remote access tool and allows users to control their system from anywhere in the world with certain capabilities, such as loading, executing command lines, recording table activity keys, screen and record webcam images as well as microphones.
Because the vulnerability used to get Rich Text File (RTF) is poisoned, most detection methods CVE-2017-0199 focus on RTF. Using the new PPSX file also allows an attacker to bypass the virus detection tool.
The easiest way to prevent you from this type of attack is to download a Microsoft patch that was released in April at this address. https://portal.msrc.microsoft.com/en-US/eula.
FAQ
How to Open the Infected PowerPoint File, Causing Hackers to Invade the Computer?
The remote code execution vulnerability in Microsoft Office (CVE-2017-0199) is in Windows Object Linking and Embedding (OLE), so the patch was released in April this year. But hazards can still appear in other ways.
What should you check before working on open the infected powerpoint file, causing hackers to invade the computer?
Review the required tools, software version, account access, compatibility, and any backup or safety steps mentioned in the guide before you begin.
What can you do if open the infected powerpoint file, causing hackers to invade the computer does not work as expected?
Recheck each step, confirm the relevant settings and requirements, and use the article's troubleshooting notes. For high-risk tasks, seek qualified support.
Reader Comments 0
Sign in with email or Google to join the discussion.