Netskope Threat Labs

DDE

ATP Sandbox Adv. HeuristicsAV

This generic detection identifies malware that exploits the Windows Dynamic Data Exchange (DDE) protocol to execute commands through malicious Office documents.

First seen
January 2022
Last seen
October 2026
Dde
Alert Name
DeepScan:Generic.DDE.Exploit.E.FFFFFFFE
DeepScan:Generic.DDE.Exploit.F.FFFFFFFE
Document-Word.Trojan.Dde
Dump:Generic.DDE.Exploit.B.FFFFFFFE
Dump:Generic.DDE.Exploit.D.FFFFFFFE
Dump:Generic.DDE.Exploit.E.FFFFFFFE
Dump:Generic.DDE.Exploit.E.FFFFFFFE:41715
Dump:Generic.DDE.Exploit.E.FFFFFFFE:8A816
Dump:Generic.DDE.Exploit.E.FFFFFFFE:9F237
Dump:Generic.DDE.Exploit.F.FFFFFFFE