typeanalysisfamilyremcosconfidencehighcreated2026-09-06updated2026-09-06malware-familyratc2persistencedefense-evasiondiscoveryexfiltrationpecompiler
SHA-256: 3bd5345502072fdb537ae2f36daaf4c8b0c36058484bb52887a57fa59381795f

remcos: 3bd53455 — v1.1 Free, Jul 2016 build, 303-byte SETTINGS, restaurant masquerade

Executive Summary

Earliest Remcos RAT sample in the corpus — v1.1 Free compiled July 2016, nine months before the v1.7 Pro Jan 2017 cluster. Filename eastvillageeatery.exe masquerades as a benign restaurant application. 303-byte encrypted SETTINGS RCData (mid-size between the 245-byte baseline and 384+ byte Pro siblings). Same MSVCP60 C++ build fingerprint, same command-string surface, same raw-TCP C2 framing. Static-only (CAPE skipped — no Windows guest).

What It Is

  • SHA-256: 3bd5345502072fdb537ae2f36daaf4c8b0c36058484bb52887a57fa59381795f
  • Filename: eastvillageeatery.exe ^[metadata.json:4]
  • Type: PE32 executable (GUI) Intel 80386, 4 sections ^[file.txt:1]
  • Size: 56 KB (57,344 bytes) ^[metadata.json:5]
  • Compiled: Tue Jul 26 19:26:59 2016 UTC (timestamp 0x5797B983) ^[rabin2-info.txt:11]
  • Linker: MSVC 6.0 (MajorLinkerVersion 0x6, Minor 0x0) ^[pefile.txt:45-46]
  • Language: MSVC C++ with MSVCP60.dll standard library ^[rabin2-info.txt:17]
  • Signed: No ^[rabin2-info.txt:27]
  • Packer: None observed statically (entropy .text=5.75, .rsrc=6.20). OpenCTI label upx-dec may reflect a historical upstream state, but the binary on disk is unpacked. ^[pefile.txt:92,152]
  • Family: Remcos RAT (Breaking-Security.Net) — high confidence.

How It Works

Singleton Gating via Mutex

On launch the binary attempts OpenMutexA("Remcos_Mutex_Inj"). ^[strings.txt:18] If the mutex exists, the process exits. Otherwise it creates the mutex with bInitialOwner = TRUE and continues. ^[r2:main@0x00402763] This is the standard Remcos singleton pattern.

Encrypted RCData Config

The .rsrc section contains an RT_RCDATA resource named SETTINGS (303 bytes at offset 0xDDA4, size 0x12F). ^[pefile.txt:602-604] The decryption routine at fcn.00402a3b loads the resource via FindResourceA/LoadResource/LockResource, ^[r2:fcn.00403152] skips the first byte (likely a length or key field), allocates a buffer, copies the remainder, then passes it through fcn.00401683 → fcn.004017c2 for decryption. ^[r2:fcn.00402a3b] The decrypted payload is presumed to be a semicolon-delimited key=value flat map consumed by the parser at main().

The 303-byte size places this sample between the 245-byte baseline (0f723826) and the 384–803 byte v1.7 Pro siblings. ^[comparisons/remcos-settings-rcdata-sizes.md]

Registry Persistence & UAC Disable

main() constructs the registry path Software\Microsoft\Windows\CurrentVersion\Run\ appended with the injector suffix "Inj". ^[r2:main@0x00402763] The same binary embeds a cmd.exe /k command to disable UAC via reg.exe ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /f. ^[strings.txt:44] This maps to T1548.002 (bypass UAC) and T1547.001 (registry Run persistence). ^[procedures/registry-run-persistence.md]

C2 Communication

Dual stack:

  • Raw TCP via WS2_32.dll ordinals (socket, connect, send, recv, gethostbyname). ^[pefile.txt:523-532]
  • HTTP fallback via WININET.dll (InternetOpenA, InternetOpenUrlA, InternetReadFile) and urlmon.dll (URLDownloadToFileA). ^[pefile.txt:510-513,465]

C2 protocol uses [DataStart] and [DataStart]0000 frame delimiters. ^[strings.txt:10-11] Status messages: Initializing connection to C&C... and Connected to C&C Interface!. ^[strings.txt:56,55]

Embedded Batch Scripts

The binary carries three batch script templates for staging, updating, and uninstalling: install.bat, update.bat, uninstall.bat. ^[strings.txt:37,42,49] Each uses if exist loops, del %0 self-deletion, PING 127.0.0.1 -n 2 sleep, and start "" process spawning. ^[strings.txt:35-48] This is the classic Remcos installer choreography.

Runtime API Loading

fcn.00402b20 runtime-loads Psapi.dll and resolves GetModuleFileNameExA, then loads kernel32.dll and resolves GlobalMemoryStatusEx and IsWow64Process. ^[r2:fcn.00402b20] This is consistent with the v1.7 Pro process-hollowing / system-info harvest flow.

Decompiled Behavior

Entry point (entry0 @ 0x004080ef) is standard MSVCRT __getmainargs → main() @ 0x00402699. ^[r2:entry0] main() executes in this order:

  1. Call fcn.00402a3b() to decrypt the SETTINGS RCData blob into a std::basic_string.
  2. Open/create Remcos_Mutex_Inj singleton mutex.
  3. Build registry path Software\...\Run\Inj and write persistence via RegSetValueExA.
  4. Call fcn.00402b20() to runtime-resolve Psapi/kernel32 APIs for system profiling.
  5. Enter the C2 connect loop using decoded host/port from SETTINGS.

Notable functions:

  • fcn.00403152 — FindResourceA("SETTINGS", 10 /*RT_RCDATA*/) loader. ^[r2:fcn.00403152]
  • fcn.00402a3b — Decrypts SETTINGS: skips byte 0, mallocs remainder, copies, calls decryptor chain. ^[r2:fcn.00402a3b]
  • fcn.00402b20 — Runtime DLL/API resolution for Psapi + kernel32 profiling imports. ^[r2:fcn.00402b20]

C2 Infrastructure

C2 host and port are runtime-decoded from encrypted SETTINGS; no hardcoded IP/domain in plaintext. The C2 surface is inferable from strings only:

  • Protocol: raw TCP with [DataStart] framing, HTTP fallback via WinInet/URLMon.
  • Commands: addnew, keepaliveoff, upload, download, scrcap, freescrcap, initializescrcap, clipboarddata, getclipboard, setclipboard, emptyclipboard, keyinput, mclick, msgbox, proclist, prockill, getproclist, getwindows, closewindow, closeprocfromwindow, consolecmd, cmdoutput, execcom, openaddress, filemgr, listfiles, driveslist, getdrives, search, stopsearch, showmsg, delete, rename, newfolder, uploadprogress, filedown, updatefromlocal, updatefromurl, uninstall, deletefile, downloadfromlocaltofile, downloadfromurltofile. ^[strings.txt:51-110]

Interesting Tidbits

  • Version string 1.1 Free is the earliest Remcos branding in the corpus. Prior siblings were all v1.7 Pro Jan 2017. This pushes the confirmed Remcos timeline back nine months. ^[strings.txt:52]
  • Restaurant masquerade (eastvillageeatery.exe) is a social-engineering lure uncommon in the corpus — most Remcos samples use generic filenames like Backdoor.exe or system masquerades.
  • No VS_VERSIONINFO resource — same as the v1.7 Pro cluster, confirming builder omission rather than stripping.
  • No capa or floss output — capa signatures missing from the triage host; floss command-line misparsed. These are tooling gaps, not sample gaps.

How To Mess With It (Homelab Replication)

Goal: Reproduce a binary with the same MSVCP60 + RCData config + std::string build fingerprint.

Toolchain: Visual C++ 6.0 (MSVC 12.00) or Visual Studio .NET 2002/2003 with Platform SDK.

Steps:

  1. Write a Win32 GUI project in C++ using std::basic_string<char> and std::iostream.
  2. Link dynamically against MSVCP60.dll and MSVCRT.dll.
  3. Embed an RCData resource named SETTINGS with a flat encrypted config (XOR or single-byte add).
  4. At runtime call FindResourceA(NULL, "SETTINGS", RT_RCDATA) → LoadResource → LockResource.
  5. Decrypt in-memory and parse as key=value; pairs.
  6. Open mutex Remcos_Mutex_Inj for singleton gating.
  7. Write registry persistence under HKCU\Software\Microsoft\Windows\CurrentVersion\Run\<suffix>.
  8. Resolve WS2_32.dll socket APIs and WININET.dll fallback APIs.

Verification: Run yara against the reproducer with the rule below. Match on Remcos_Mutex_Inj + SETTINGS + MSVCP60.dll confirms structural parity.

Deployable Signatures

YARA

rule remcos_rat_msvcp60_settings {
    meta:
        description = "Remcos RAT - MSVCP60 build with SETTINGS RCData"
        author = "Titus"
        date = "2026-09-06"
        sha256 = "3bd5345502072fdb537ae2f36daaf4c8b0c36058484bb52887a57fa59381795f"
    strings:
        $a1 = "Remcos_Mutex_Inj" ascii
        $a2 = "BreakingSecurity RAT" ascii
        $a3 = " * Breaking-Security.Net" ascii
        $a4 = " * REMCOS v" ascii
        $b1 = "SETTINGS" wide
        $b2 = "[DataStart]" ascii
        $b3 = "Initializing connection to C&C..." ascii
        $b4 = "Connected to C&C Interface!" ascii
        $c1 = "MSVCP60.dll" ascii
    condition:
        uint16(0) == 0x5A4D and
        filesize < 200KB and
        2 of ($a*) and
        2 of ($b*) and
        $c1
}

Sigma

title: Remcos RAT Process Behavioral Hunt
status: experimental
description: Detects Remcos RAT based on known static indicators and runtime behavior
logsource:
    category: process_creation
    product: windows
detection:
    selection_mutex:
        CommandLine|contains: 'Remcos_Mutex_Inj'
    selection_registry:
        CommandLine|contains:
            - 'Software\Microsoft\Windows\CurrentVersion\Run'
            - 'EnableLUA'
    selection_bat:
        CommandLine|contains:
            - 'install.bat'
            - 'update.bat'
            - 'uninstall.bat'
    selection_strings:
        CommandLine|contains:
            - 'eastvillageeatery'
            - 'BreakingSecurity'
            - 'REMCOS'
    condition: 1 of selection_*
falsepositives:
    - Unknown
level: high

IOC List

Indicator Value
SHA-256 3bd5345502072fdb537ae2f36daaf4c8b0c36058484bb52887a57fa59381795f
Filename eastvillageeatery.exe
Mutex Remcos_Mutex_Inj
Registry (persistence) HKCU\Software\Microsoft\Windows\CurrentVersion\Run\<Inj>
Registry (UAC disable) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA = 0
Batch scripts install.bat, update.bat, uninstall.bat
RCData resource SETTINGS (RT_RCDATA, 303 bytes)
C2 framing [DataStart] / [DataStart]0000
C2 strings Initializing connection to C&C..., Connected to C&C Interface!

Behavioral Fingerprint Statement

This binary is a 56 KB PE32 GUI executable compiled with MSVC C++ and linked against MSVCP60.dll. On execution it attempts to open a mutex named Remcos_Mutex_Inj; if absent, it creates the mutex and proceeds. It loads a 303-byte encrypted SETTINGS blob from its own RT_RCDATA resource, decrypts it in-memory, and uses the decoded parameters to establish a raw TCP socket C2 connection framed by [DataStart] delimiters. Fallback HTTP download is available via WinInet/URLMon. The binary can spawn batch scripts (install.bat, update.bat, uninstall.bat) for persistence and self-deletion, and it queries system memory and WOW64 state via runtime-loaded Psapi.dll and kernel32.dll APIs.

Detection Signatures

Capability ATT&CK Technique Evidence
Registry Run persistence T1547.001 Software\Microsoft\Windows\CurrentVersion\Run\ string ^[strings.txt:33]
UAC disable via EnableLUA T1548.002 Embedded reg.exe ADD ... EnableLUA /d 0 command ^[strings.txt:44]
Raw TCP C2 T1071.001 WS2_32 ordinals (socket, connect, send, recv) ^[pefile.txt:523-532]
HTTP fallback C2 T1071.001 WinInet + URLMon imports ^[pefile.txt:510-513,465]
Screenshot capture T1113 GDI32 + GDI+ imports (StretchBlt, GdipSaveImageToStream) ^[pefile.txt:305-313,324-333]
Keylogger / input capture T1056.001 / T1056.002 SendInput, clipboard APIs, keyinput, mclick strings ^[strings.txt:66-67,320-333]
Process enumeration T1057 Toolhelp32Snapshot, Process32First/Next ^[pefile.txt:222-223]
File manager / exfil T1005 upload, download, filemgr, sendfiledata strings ^[strings.txt:86-100]
Mutex singleton — Remcos_Mutex_Inj ^[strings.txt:18]
Process hollowing (IAT present) T1055.012 CreateProcessA, NtUnmapViewOfSection not in IAT but MapViewOfFileEx, CreateFileMappingA present; full hollowing engine observed in v1.7 siblings ^[pefile.txt:267-268]

References

Provenance

Analysis derived from:

  • file.txt — file(1) output
  • metadata.json — OpenCTI artifact metadata
  • pefile.txt — pefile.py structural dump
  • rabin2-info.txt — radare2 binary header summary
  • strings.txt — raw ASCII/Unicode strings
  • r2 decompilation — radare2 v5.x analysis with aaa (level 3), functions decompiled via pdg

All provenance markers inline above. Capa and floss did not produce usable output during triage (missing signatures and command-line error, respectively).