How to retrieve a forgotten Word document password through Hashca

In our daily work and study, we often use Microsoft Word to store important files and set up password protection to prevent unauthorized access. However, over time, we may forget our passwords, making it impossible to open our documents. That's when Hashcat, a powerful password recovery tool, comes in handy.

This article will detail how to use Hashcat to crack Word document passwords, including preparation, the basic principles of Hashcat, specific operation steps, and how to improve the success rate of cracking. Even if you're a tech novice, you can follow this guide step by step to recover your lost password.


I. Encryption mechanism for Word documents

Microsoft Word (2010 and later versions) uses AES-256 encryption by default, which is highly secure. Earlier versions of Word 97-2003 used RC4 encryption, which was relatively easy to crack.

When a user sets a password, Word:

  1. hashes the password (converts it to a fixed-length string).

  2. Use this hash to encrypt the document contents.

Therefore, the essence of cracking a Word password is:

  • Extract the password hash value of the document (similar to a "fingerprint").

  • Use Hashcat to try different password combinations until a successful match occurs.


II. Preparation: Obtain the Word password hash

Hashcat cannot directly read .docx or .doc files; the hash value of the password needs to be extracted first. We can do this using the office2john.py tool (from the John the Ripper toolset).

1. Install Python and download office2john.py

  • Visit  Python official website Download and install Python (version 3.8+ recommended).

  • Download the office2john.py script (available on GitHub by searching for "John the Ripper").

2. Extract the hash value of the Word document

Open the command line (Windows: cmd / macOS/Linux: Terminal) and run:

bash

copy

download

python office2john.py yourfile.docx > hash.txt

After execution, the hash.txt file will contain hash values similar to the following:


copy

download

$Office$*2013*100000*256*16*...*your hash value

This hash value is the target we want to crack.


III. Steps to Crack Word Password with Hashcat

1. Install Hashcat

  • Download from the official website:https://hashcat.net/hashcat/

  • 支持Windows/Linux/macOS,建议使用NVIDIA显卡(CUDA加速)或AMD显卡(OpenCL加速)。

2. Choose the appropriate Attack mode

Hashcat supports multiple cracking modes, the most common of which are:

  • Dictionary Attack: Try using a list of common passwords (such as rockyou.txt).

  • Mask Attack: A known partial password structure (e.g., "Pass123?").

  • Brute-Force: Try all possible combinations (for short passwords).

(1) Dictionary attack (recommended to try first)

bash

copy

download

hashcat -m 9600 hash.txt rockyou.txt
  • -m 9600  represents the hash pattern of Word 2013+.

  • rockyou.txt  is a commonly used password dictionary (available for download online).

(2) Mask attack (known partial password)

If you remember that the password starts with "Pass" followed by a number, you can try:

bash

copy

download

hashcat -m 9600 hash.txt -a 3 "Pass? d? d? d"
  • ? d  represents a number (0-9).

  • ? l  represents lowercase letters (a-z).

  • ? u  represents a capital letter (A-Z).

(3) Brute force cracking (short password applies)

bash

copy

download

hashcat -m 9600 hash.txt -a 3 ? l? l? l? l? l? l

This will try all 6-digit lowercase letter combinations for simple passwords.


IV. Techniques for Improving the Success Rate of Cracking

1. Use the more powerful dictionary

  • rockyou.txt (which contains tens of millions of common passwords).

  • Custom dictionary: Combines personal information (such as birthday, name, commonly used words).

2. Use rules to optimize the dictionary

Hashcat supports "rules" to transform the dictionary, such as:

  • case conversion (password → password, password).

  • Add numbers/symbols (pass → pass123, pass!).

Example:

bash

copy

download

hashcat -m 9600 hash.txt dict.txt -r rules/best64.rule

3. Using high-performance hardware acceleration

  • GPU cracking is more than 100 times faster than CPU. It is recommended to use high-end graphics cards such as NVIDIA RTX 4090.

  • If your computer is underperforming, consider a cloud server (such as an AWS GPU instance) or a proxy service (to save time).


V. Successful Cases

Case 1: Quickly crack a simple password

The user forgets a 6-digit plain numeric password (such as "198504"), and uses a mask attack:

bash

copy

download

hashcat -m 9600 hash.txt -a 3 ? d? d? d? d? d? d

successfully recovered the password in just 10 seconds.

Case 2: Dictionary + Rule Cracking for Complex Passwords

The password may be "Company2024!", but the case and symbols are uncertain. Use rules:

bash

copy

download

hashcat -m 9600 hash.txt dict.txt -r rules/leetspeak.rule

2 hours later it matches "COMPANY2024!".


VI. Summary

  1. Extract hash: Use office2john.py to obtain the hash value of the Word password.

  2. Select attack mode: dictionary attack (recommended first attempt), mask attack (partially known), brute force attack (short password).

  3. Optimization strategy: Use stronger dictionaries, rules, and GPU acceleration.

  4. Consider a running service: If the hardware is insufficient, you can find a professional team to run it for you to save time.

If you encounter the problem of forgetting your Word password, you may want to try to crack it by following this tutorial. If you have a high technical skill level, you can also choose a professional Hashcat service to retrieve your password efficiently and securely!

Previous: Professional Hashcat proxy service: efficient
Next: PDF forced password release

Featured articles

  • Word/Excel/Pdf/PPT/RAR/zip/7z-Online password cracking
  • offfice, PDF, Compressed file, WPS,online password recovery
  • hashcatonline.comOnline password cracking Copyright 2010-2025