typeanalysisfamilyremcosconfidencehighcreated2026-09-06updated2026-09-06malware-familyratc2persistencedefense-evasiondiscoveryexfiltrationpecompiler
SHA-256: 522ff9a14cba958db505cf1a0d850f9d92a6394c0383952d0914086fdbc58f3c

remcos: 522ff9a1 — v1.7 Pro, 384-byte SETTINGS RCData, standard build stack

A textbook Remcos v1.7 Pro sample from the Jan 2017 build pipeline. No masquerade (filename Backdoor.exe, no VS_VERSIONINFO), 384-byte encrypted RCData config, full process-hollowing IAT, eventvwr UAC bypass, and the complete surveillance suite. Static-only — CAPE skipped due to no Windows guest.

What It Is

PE32 GUI executable, 94,208 bytes, compiled Thu Jan 5 19:50:13 2017 UTC. ^[exiftool.json] MSVC C++ with MSVCP60.dll C++ standard library, LinkerVersion 6.0. ^[file.txt] ^[rabin2-info.txt] Four sections (.text .rdata .data .rsrc), no packer, no obfuscation. ^[pefile.txt] Unsigned; PE checksum 0x00018c25 vs computed 0x00018c25 (matches, no deliberate checksum tampering). ^[pefile.txt]

The .rsrc section holds three entries: RT_ICON (0xCA8 bytes), RT_RCDATA named SETTINGS (0x180 = 384 bytes at raw offset 0x16DA4), and RT_GROUP_ICON (0x14 bytes). ^[pefile.txt] No VS_VERSIONINFO resource — the builder emitted no product metadata.

Family attribution is high confidence by string profile: Remcos branding, Breaking-Security.Net copyright, REMCOS v, 1.7 Pro version, Remcos_Mutex_Inj mutex name, [DataStart] C2 framing, and the full surveillance command vocabulary (keylogging, clipboard, screenshot, webcam, microphone, file manager, process list). ^[strings.txt:168] ^[strings.txt:294] ^[strings.txt:297] ^[strings.txt:298] ^[strings.txt:203] ^[strings.txt:59]

This sample is a sibling of the confirmed Remcos cluster (0f723826, 4818d00f, d9950b15, 6114904c, c6193af6, 39848daa, 65d3a51a) — identical imports, strings, and toolchain. The per-sample delta is the 384-byte SETTINGS RCData (medium size vs the 245–803 byte range observed across siblings).

How It Works

Entry point (main at 0x00407452) initializes std::string infrastructure, reads the SETTINGS RCData resource via FindResourceA → LoadResource → LockResource, and passes the decrypted blob to an internal config parser (fcn.00407c53). ^[r2:main] The config drives C2 host/port, mutex name, installation path, persistence method, and feature flags.

Anti-sandbox strings are present but not weaponized beyond naive substring checks: SbieDll.dll, HARDWARE\ACPI\DSDT\VBOX__, PROCMON_WINDOW_CLASS, PROCEXPL. ^[strings.txt:40] ^[strings.txt:41] ^[strings.txt:42] ^[strings.txt:43]

Process hollowing engine is fully imported: NtUnmapViewOfSection (runtime-resolved from ntdll.dll via LoadLibraryA + GetProcAddress), VirtualAllocEx, WriteProcessMemory, ReadProcessMemory, GetThreadContext, SetThreadContext, ResumeThread. ^[strings.txt:286] ^[pefile.txt] No PEB-walking — the author relied on standard IAT plus manual ntdll resolution.

UAC bypass (T1548.002): eventvwr.exe auto-elevate via Software\Classes\mscfile\shell\open\command hijack. ^[strings.txt:66] Fallback: disable UAC entirely via reg.exe ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /f. ^[strings.txt:186]

Persistence (T1547.001 / T1547.004): Registry Run key under Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\ or Winlogon Userinit hijack (C:\WINDOWS\system32\userinit.exe, <malware>). ^[strings.txt:141] ^[strings.txt:142]

Surveillance suite — all command verbs found in .rdata:

  • Keylogger: SetWindowsHookExA, GetKeyState, CallNextHookEx ^[pefile.txt]
  • Clipboard: OpenClipboard, GetClipboardData, SetClipboardData, EmptyClipboard ^[pefile.txt]
  • Screenshot: GdiplusStartup, GdipSaveImageToFile, StretchBlt, GetDIBits ^[pefile.txt]
  • Webcam: FreeFrame, GetFrame, OpenCamera, CloseCamera ^[strings.txt:47] ^[strings.txt:51]
  • Microphone: waveInOpen, waveInStart, waveInAddBuffer ^[pefile.txt]
  • Browser credential theft: Chrome Login Data + Cookies, Firefox logins.json + key3.db + cookies.sqlite, IE cookies. ^[strings.txt:114] ^[strings.txt:117] ^[strings.txt:121] ^[strings.txt:125] ^[strings.txt:129]

C2 (T1071.001): Raw TCP over WS2_32.dll with [DataStart] frame delimiter and %02i:%02i:%02i:%03i [KeepAlive] heartbeat. ^[strings.txt:59] ^[strings.txt:60] ^[strings.txt:62] Fallback download via URLDownloadToFileA and InternetOpenUrlA. ^[pefile.txt]

File manager (T1005): Drive enumeration (GetLogicalDriveStringsA, GetDriveTypeA), directory listing (FindFirstFileW/FindNextFileW), upload/download, delete, rename, new folder. ^[pefile.txt] Process management (T1057): CreateToolhelp32Snapshot → Process32First/Process32Next with prockill. ^[pefile.txt]

Decompiled Behavior

main (r2 0x00407452) constructs a std::basic_string for the installation subkey (Software\), opens Remcos_Mutex_Inj via OpenMutexA (singleton check), and if absent creates it via CreateMutexA. ^[r2:main] It then probes registry values (ProductName) and branches into the C2 loop.

fcn.00407c53 (called from main) appears to be the SETTINGS RCData decryptor: allocates heap, copies the resource blob, and passes it to fcn.004028eb (likely a byte-substitution or XOR routine) and fcn.00402a2a (likely the config parser). ^[r2:fcn.00407c53] The decrypted config is then consumed by the feature-gate logic in main.

No control-flow flattening, no junk code, no anti-disassembly. The binary is trivially readable — the author invested opsec effort in the builder (encrypted config) rather than the stub.

C2 Infrastructure

Static-only; no hardcoded C2 recovered from strings. The [DataStart] framing and keep-alive strings confirm a raw TCP protocol, but host/port live inside the encrypted 384-byte RCData blob.

Mutex: Remcos_Mutex_Inj ^[strings.txt:168]

Registry keys (installation / persistence):

  • Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\ ^[strings.txt:131]
  • Software\Microsoft\Windows NT\CurrentVersion\Winlogon\ (Userinit) ^[strings.txt:142]
  • Software\Classes\mscfile\shell\open\command (UAC bypass) ^[strings.txt:66]
  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA (UAC disable) ^[strings.txt:186]

File paths (installation targets):

  • %AppData%\install.bat ^[strings.txt:148]
  • %AppData%\uninstall.bat ^[strings.txt:153]
  • %AppData%\update.bat ^[strings.txt:157]

Interesting Tidbits

  • 1.7 Pro version string at r2 offset 0x00411034 (rva) — builder-branded, not user-editable at compile time. ^[strings.txt:203]
  • No filename masquerade — Backdoor.exe is the raw builder output, suggesting a test/sample build or minimal opsec deployment.
  • The 384-byte SETTINGS RCData is smaller than siblings 6114904c (616 bytes) and 39848daa (803 bytes), suggesting fewer enabled features or shorter C2 credentials in this build.
  • cmd.exe /k %windir%\System32\reg.exe ADD ... EnableLUA is executed via ShellExecuteA — a cmd.exe child process for a single registry write, leaving a clear process tree artefact.
  • GDIPlus screenshot encoder exports GdipSaveImageToStream and GdipSaveImageToFile — the builder may save to disk before exfil, not just in-memory capture.

How To Mess With It (Homelab Replication)

Toolchain: Visual C++ 6.0 (or VS2003 with Platform SDK) targeting Win32 GUI. Link against MSVCP60.dll, WS2_32.lib, gdiplus.lib, winmm.lib, urlmon.lib, shell32.lib.

Key implementation notes:

  1. Store encrypted config as RT_RCDATA named SETTINGS in .rsrc.
  2. Use std::basic_string<char> for all internal path/string management.
  3. Resolve NtUnmapViewOfSection at runtime via LoadLibraryA("ntdll.dll") + GetProcAddress.
  4. Frame C2 messages with [DataStart] + 4-byte length prefix ([DataStart]0000).
  5. Use SetWindowsHookExA(WH_KEYBOARD_LL, ...) for keylogging; GetAsyncKeyState for modifier detection.

Verification: Compile a minimal stub with the above imports and run capa reproducer.exe — it should hit T1055, T1056, T1113, T1071, T1547, and T1548.

Deployable Signatures

YARA — Remcos v1.7 Pro Generic

rule remcos_v17_pro_generic {
    meta:
        description = "Remcos v1.7 Pro PE32 — generic behavioral signature"
        author = "triage-pipeline"
        sha256 = "522ff9a14cba958db505cf1a0d850f9d92a6394c0383952d0914086fdbc58f3c"
        version = "1.0"
    strings:
        $a1 = "Remcos_Mutex_Inj" ascii wide
        $a2 = "[DataStart]" ascii wide
        $a3 = "1.7 Pro" ascii wide
        $a4 = "Breaking-Security.Net" ascii wide
        $a5 = "REMCOS v" ascii wide
        $b1 = "eventvwr.exe" ascii wide
        $b2 = "Software\\Classes\\mscfile\\shell\\open\\command" ascii wide
        $b3 = "EnableLUA" ascii wide
        $b4 = "NtUnmapViewOfSection" ascii wide
        $c1 = "getclipboard" ascii wide
        $c2 = "screenshotdata" ascii wide
        $c3 = "getcamframe" ascii wide
        $c4 = "waveInOpen" ascii wide
    condition:
        uint16(0) == 0x5a4d and
        filesize < 200KB and
        2 of ($a*) and
        2 of ($b*) and
        2 of ($c*)
}

Sigma — Remcos Process Hollowing Indicator

title: Remcos Process Hollowing Sequence
description: Detects NtUnmapViewOfSection followed by VirtualAllocEx, WriteProcessMemory, and ResumeThread in short succession — Remcos process-hollowing engine.
status: experimental
logsource:
    category: process_access
    product: windows
detection:
    selection:
        CallTrace|contains|all:
            - 'ntdll.dll!NtUnmapViewOfSection'
            - 'KERNEL32.dll!VirtualAllocEx'
            - 'KERNEL32.dll!WriteProcessMemory'
            - 'KERNEL32.dll!ResumeThread'
    condition: selection
falsepositives:
    - Legitimate process migration tools
    - Sysinternals Process Explorer (rare)
level: high
tags:
    - attack.defense_evasion
    - attack.t1055

IOC List

Type Value Context
SHA-256 522ff9a14cba958db505cf1a0d850f9d92a6394c0383952d0914086fdbc58f3c Sample
ssdeep 1536:IhhW0YTGZWdVseJxaM9kraLdV2QkQ1TbPX8IHOCkIsI4ESHNTh9E+JP19qkP6hru:OhzYTGWVvJ8f2v1TbPzuMsIFSHNThy+T Fuzzy hash
TLSH 7A93D813FA4AD0B2E42591F146426F32CEBCBC3736492173D38FCA419D79892D456EAE Trend hash
Mutex Remcos_Mutex_Inj Singleton / injection marker
Registry (persist) HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\ Run key
Registry (persist) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit Winlogon hijack
Registry (UAC bypass) HKCU\Software\Classes\mscfile\shell\open\command eventvwr hijack
Registry (UAC disable) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA = 0 UAC off
File path %AppData%\install.bat Install script
File path %AppData%\uninstall.bat Uninstall script
File path %AppData%\update.bat Update script
C2 frame [DataStart] + 4-byte length Raw TCP framing
Version 1.7 Pro Builder version

Behavioral Fingerprint

This binary is a 94 KB PE32 GUI executable compiled with MSVC 6.0 / MSVCP60. It loads SETTINGS RCData from its own .rsrc section, decrypts it in-memory, creates a mutex named Remcos_Mutex_Inj, and if singleton, installs itself to %AppData% via .bat scripts. It persists via Registry Run or Winlogon Userinit hijack, disables UAC via eventvwr.exe mscfile handler abuse, and establishes a raw TCP C2 channel framed by [DataStart] delimiters. The surveillance suite includes keylogging, clipboard monitoring, GDIPlus screenshot capture, webcam frame capture, WINMM microphone recording, browser credential theft (Chrome/Firefox/IE), file management, and process enumeration.

Detection Signatures

capa / static observation ATT&CK Technique Evidence
Process hollowing (NtUnmapViewOfSection + VirtualAllocEx + WriteProcessMemory + SetThreadContext + ResumeThread) T1055 — Process Injection ^[strings.txt:286] ^[pefile.txt]
Keylogging via SetWindowsHookExA T1056.001 — Input Capture: Keylogging ^[pefile.txt]
Clipboard capture via OpenClipboard/GetClipboardData T1056.002 — Input Capture: GUI Input Capture ^[pefile.txt]
Screenshot via GDIPlus/GDI32 T1113 — Screen Capture ^[pefile.txt]
Microphone capture via waveIn* T1123 — Audio Capture ^[pefile.txt]
Webcam capture T1125 — Video Capture ^[strings.txt:47]
Process enumeration via Toolhelp32 T1057 — Process Discovery ^[pefile.txt]
Browser credential theft (Chrome, Firefox, IE) T1217 — Browser Bookmark Discovery / T1005 — Data from Local System ^[strings.txt:114] ^[strings.txt:121] ^[strings.txt:125]
Raw TCP C2 with [DataStart] framing T1071.001 — Application Layer Protocol: Web Protocols (misapplied — custom TCP) ^[strings.txt:59]
File manager / upload / download T1005 — Data from Local System ^[strings.txt:230] ^[strings.txt:211]
Registry Run persistence T1547.001 — Boot or Logon Autostart Execution: Registry Run Keys ^[strings.txt:131]
Winlogon Userinit persistence T1547.004 — Boot or Logon Autostart Execution: Winlogon Helper DLL ^[strings.txt:142]
eventvwr UAC bypass T1548.002 — Abuse Elevation Control Mechanism: Bypass UAC ^[strings.txt:66] ^[strings.txt:186]
EnableLUA registry disable T1548.002 — Bypass UAC (fallback) ^[strings.txt:186]
Sandbox evasion strings T1497.001 — Virtualization/Sandbox Evasion ^[strings.txt:40] ^[strings.txt:41] ^[strings.txt:42] ^[strings.txt:43]
URLDownloadToFileA / InternetOpenUrlA fallback T1105 — Ingress Tool Transfer ^[pefile.txt]

References

Provenance

Static analysis via file, exiftool, pefile, rabin2, radare2 (level-3 auto-analysis), and strings. No capa or floss due to tooling errors (missing signatures / bad CLI flags). Dynamic analysis skipped — CAPE has no Windows guest. Build provenance: MSVC C++ with MSVCP60.dll, LinkerVersion 6.0, compiled Jan 5 2017. No packer, no obfuscation, no signing.