522ff9a14cba958db505cf1a0d850f9d92a6394c0383952d0914086fdbc58f3cremcos: 522ff9a1 — v1.7 Pro, 384-byte SETTINGS RCData, standard build stack
A textbook Remcos v1.7 Pro sample from the Jan 2017 build pipeline. No masquerade (filename Backdoor.exe, no VS_VERSIONINFO), 384-byte encrypted RCData config, full process-hollowing IAT, eventvwr UAC bypass, and the complete surveillance suite. Static-only — CAPE skipped due to no Windows guest.
What It Is
PE32 GUI executable, 94,208 bytes, compiled Thu Jan 5 19:50:13 2017 UTC. ^[exiftool.json] MSVC C++ with MSVCP60.dll C++ standard library, LinkerVersion 6.0. ^[file.txt] ^[rabin2-info.txt] Four sections (.text .rdata .data .rsrc), no packer, no obfuscation. ^[pefile.txt] Unsigned; PE checksum 0x00018c25 vs computed 0x00018c25 (matches, no deliberate checksum tampering). ^[pefile.txt]
The .rsrc section holds three entries: RT_ICON (0xCA8 bytes), RT_RCDATA named SETTINGS (0x180 = 384 bytes at raw offset 0x16DA4), and RT_GROUP_ICON (0x14 bytes). ^[pefile.txt] No VS_VERSIONINFO resource — the builder emitted no product metadata.
Family attribution is high confidence by string profile: Remcos branding, Breaking-Security.Net copyright, REMCOS v, 1.7 Pro version, Remcos_Mutex_Inj mutex name, [DataStart] C2 framing, and the full surveillance command vocabulary (keylogging, clipboard, screenshot, webcam, microphone, file manager, process list). ^[strings.txt:168] ^[strings.txt:294] ^[strings.txt:297] ^[strings.txt:298] ^[strings.txt:203] ^[strings.txt:59]
This sample is a sibling of the confirmed Remcos cluster (0f723826, 4818d00f, d9950b15, 6114904c, c6193af6, 39848daa, 65d3a51a) — identical imports, strings, and toolchain. The per-sample delta is the 384-byte SETTINGS RCData (medium size vs the 245–803 byte range observed across siblings).
How It Works
Entry point (main at 0x00407452) initializes std::string infrastructure, reads the SETTINGS RCData resource via FindResourceA → LoadResource → LockResource, and passes the decrypted blob to an internal config parser (fcn.00407c53). ^[r2:main] The config drives C2 host/port, mutex name, installation path, persistence method, and feature flags.
Anti-sandbox strings are present but not weaponized beyond naive substring checks: SbieDll.dll, HARDWARE\ACPI\DSDT\VBOX__, PROCMON_WINDOW_CLASS, PROCEXPL. ^[strings.txt:40] ^[strings.txt:41] ^[strings.txt:42] ^[strings.txt:43]
Process hollowing engine is fully imported: NtUnmapViewOfSection (runtime-resolved from ntdll.dll via LoadLibraryA + GetProcAddress), VirtualAllocEx, WriteProcessMemory, ReadProcessMemory, GetThreadContext, SetThreadContext, ResumeThread. ^[strings.txt:286] ^[pefile.txt] No PEB-walking — the author relied on standard IAT plus manual ntdll resolution.
UAC bypass (T1548.002): eventvwr.exe auto-elevate via Software\Classes\mscfile\shell\open\command hijack. ^[strings.txt:66] Fallback: disable UAC entirely via reg.exe ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /f. ^[strings.txt:186]
Persistence (T1547.001 / T1547.004): Registry Run key under Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\ or Winlogon Userinit hijack (C:\WINDOWS\system32\userinit.exe, <malware>). ^[strings.txt:141] ^[strings.txt:142]
Surveillance suite — all command verbs found in .rdata:
- Keylogger:
SetWindowsHookExA,GetKeyState,CallNextHookEx^[pefile.txt] - Clipboard:
OpenClipboard,GetClipboardData,SetClipboardData,EmptyClipboard^[pefile.txt] - Screenshot:
GdiplusStartup,GdipSaveImageToFile,StretchBlt,GetDIBits^[pefile.txt] - Webcam:
FreeFrame,GetFrame,OpenCamera,CloseCamera^[strings.txt:47] ^[strings.txt:51] - Microphone:
waveInOpen,waveInStart,waveInAddBuffer^[pefile.txt] - Browser credential theft: Chrome
Login Data+Cookies, Firefoxlogins.json+key3.db+cookies.sqlite, IE cookies. ^[strings.txt:114] ^[strings.txt:117] ^[strings.txt:121] ^[strings.txt:125] ^[strings.txt:129]
C2 (T1071.001): Raw TCP over WS2_32.dll with [DataStart] frame delimiter and %02i:%02i:%02i:%03i [KeepAlive] heartbeat. ^[strings.txt:59] ^[strings.txt:60] ^[strings.txt:62] Fallback download via URLDownloadToFileA and InternetOpenUrlA. ^[pefile.txt]
File manager (T1005): Drive enumeration (GetLogicalDriveStringsA, GetDriveTypeA), directory listing (FindFirstFileW/FindNextFileW), upload/download, delete, rename, new folder. ^[pefile.txt] Process management (T1057): CreateToolhelp32Snapshot → Process32First/Process32Next with prockill. ^[pefile.txt]
Decompiled Behavior
main (r2 0x00407452) constructs a std::basic_string for the installation subkey (Software\), opens Remcos_Mutex_Inj via OpenMutexA (singleton check), and if absent creates it via CreateMutexA. ^[r2:main] It then probes registry values (ProductName) and branches into the C2 loop.
fcn.00407c53 (called from main) appears to be the SETTINGS RCData decryptor: allocates heap, copies the resource blob, and passes it to fcn.004028eb (likely a byte-substitution or XOR routine) and fcn.00402a2a (likely the config parser). ^[r2:fcn.00407c53] The decrypted config is then consumed by the feature-gate logic in main.
No control-flow flattening, no junk code, no anti-disassembly. The binary is trivially readable — the author invested opsec effort in the builder (encrypted config) rather than the stub.
C2 Infrastructure
Static-only; no hardcoded C2 recovered from strings. The [DataStart] framing and keep-alive strings confirm a raw TCP protocol, but host/port live inside the encrypted 384-byte RCData blob.
Mutex: Remcos_Mutex_Inj ^[strings.txt:168]
Registry keys (installation / persistence):
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\^[strings.txt:131]Software\Microsoft\Windows NT\CurrentVersion\Winlogon\(Userinit) ^[strings.txt:142]Software\Classes\mscfile\shell\open\command(UAC bypass) ^[strings.txt:66]HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA(UAC disable) ^[strings.txt:186]
File paths (installation targets):
%AppData%\install.bat^[strings.txt:148]%AppData%\uninstall.bat^[strings.txt:153]%AppData%\update.bat^[strings.txt:157]
Interesting Tidbits
1.7 Proversion string at r2 offset0x00411034(rva) — builder-branded, not user-editable at compile time. ^[strings.txt:203]- No filename masquerade —
Backdoor.exeis the raw builder output, suggesting a test/sample build or minimal opsec deployment. - The 384-byte SETTINGS RCData is smaller than siblings
6114904c(616 bytes) and39848daa(803 bytes), suggesting fewer enabled features or shorter C2 credentials in this build. cmd.exe /k %windir%\System32\reg.exe ADD ... EnableLUAis executed viaShellExecuteA— a cmd.exe child process for a single registry write, leaving a clear process tree artefact.- GDIPlus screenshot encoder exports
GdipSaveImageToStreamandGdipSaveImageToFile— the builder may save to disk before exfil, not just in-memory capture.
How To Mess With It (Homelab Replication)
Toolchain: Visual C++ 6.0 (or VS2003 with Platform SDK) targeting Win32 GUI. Link against MSVCP60.dll, WS2_32.lib, gdiplus.lib, winmm.lib, urlmon.lib, shell32.lib.
Key implementation notes:
- Store encrypted config as RT_RCDATA named
SETTINGSin.rsrc. - Use
std::basic_string<char>for all internal path/string management. - Resolve
NtUnmapViewOfSectionat runtime viaLoadLibraryA("ntdll.dll")+GetProcAddress. - Frame C2 messages with
[DataStart]+ 4-byte length prefix ([DataStart]0000). - Use
SetWindowsHookExA(WH_KEYBOARD_LL, ...)for keylogging;GetAsyncKeyStatefor modifier detection.
Verification: Compile a minimal stub with the above imports and run capa reproducer.exe — it should hit T1055, T1056, T1113, T1071, T1547, and T1548.
Deployable Signatures
YARA — Remcos v1.7 Pro Generic
rule remcos_v17_pro_generic {
meta:
description = "Remcos v1.7 Pro PE32 — generic behavioral signature"
author = "triage-pipeline"
sha256 = "522ff9a14cba958db505cf1a0d850f9d92a6394c0383952d0914086fdbc58f3c"
version = "1.0"
strings:
$a1 = "Remcos_Mutex_Inj" ascii wide
$a2 = "[DataStart]" ascii wide
$a3 = "1.7 Pro" ascii wide
$a4 = "Breaking-Security.Net" ascii wide
$a5 = "REMCOS v" ascii wide
$b1 = "eventvwr.exe" ascii wide
$b2 = "Software\\Classes\\mscfile\\shell\\open\\command" ascii wide
$b3 = "EnableLUA" ascii wide
$b4 = "NtUnmapViewOfSection" ascii wide
$c1 = "getclipboard" ascii wide
$c2 = "screenshotdata" ascii wide
$c3 = "getcamframe" ascii wide
$c4 = "waveInOpen" ascii wide
condition:
uint16(0) == 0x5a4d and
filesize < 200KB and
2 of ($a*) and
2 of ($b*) and
2 of ($c*)
}
Sigma — Remcos Process Hollowing Indicator
title: Remcos Process Hollowing Sequence
description: Detects NtUnmapViewOfSection followed by VirtualAllocEx, WriteProcessMemory, and ResumeThread in short succession — Remcos process-hollowing engine.
status: experimental
logsource:
category: process_access
product: windows
detection:
selection:
CallTrace|contains|all:
- 'ntdll.dll!NtUnmapViewOfSection'
- 'KERNEL32.dll!VirtualAllocEx'
- 'KERNEL32.dll!WriteProcessMemory'
- 'KERNEL32.dll!ResumeThread'
condition: selection
falsepositives:
- Legitimate process migration tools
- Sysinternals Process Explorer (rare)
level: high
tags:
- attack.defense_evasion
- attack.t1055
IOC List
| Type | Value | Context |
|---|---|---|
| SHA-256 | 522ff9a14cba958db505cf1a0d850f9d92a6394c0383952d0914086fdbc58f3c |
Sample |
| ssdeep | 1536:IhhW0YTGZWdVseJxaM9kraLdV2QkQ1TbPX8IHOCkIsI4ESHNTh9E+JP19qkP6hru:OhzYTGWVvJ8f2v1TbPzuMsIFSHNThy+T |
Fuzzy hash |
| TLSH | 7A93D813FA4AD0B2E42591F146426F32CEBCBC3736492173D38FCA419D79892D456EAE |
Trend hash |
| Mutex | Remcos_Mutex_Inj |
Singleton / injection marker |
| Registry (persist) | HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\ |
Run key |
| Registry (persist) | HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit |
Winlogon hijack |
| Registry (UAC bypass) | HKCU\Software\Classes\mscfile\shell\open\command |
eventvwr hijack |
| Registry (UAC disable) | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA = 0 |
UAC off |
| File path | %AppData%\install.bat |
Install script |
| File path | %AppData%\uninstall.bat |
Uninstall script |
| File path | %AppData%\update.bat |
Update script |
| C2 frame | [DataStart] + 4-byte length |
Raw TCP framing |
| Version | 1.7 Pro |
Builder version |
Behavioral Fingerprint
This binary is a 94 KB PE32 GUI executable compiled with MSVC 6.0 / MSVCP60. It loads SETTINGS RCData from its own .rsrc section, decrypts it in-memory, creates a mutex named Remcos_Mutex_Inj, and if singleton, installs itself to %AppData% via .bat scripts. It persists via Registry Run or Winlogon Userinit hijack, disables UAC via eventvwr.exe mscfile handler abuse, and establishes a raw TCP C2 channel framed by [DataStart] delimiters. The surveillance suite includes keylogging, clipboard monitoring, GDIPlus screenshot capture, webcam frame capture, WINMM microphone recording, browser credential theft (Chrome/Firefox/IE), file management, and process enumeration.
Detection Signatures
| capa / static observation | ATT&CK Technique | Evidence |
|---|---|---|
| Process hollowing (NtUnmapViewOfSection + VirtualAllocEx + WriteProcessMemory + SetThreadContext + ResumeThread) | T1055 — Process Injection | ^[strings.txt:286] ^[pefile.txt] |
| Keylogging via SetWindowsHookExA | T1056.001 — Input Capture: Keylogging | ^[pefile.txt] |
| Clipboard capture via OpenClipboard/GetClipboardData | T1056.002 — Input Capture: GUI Input Capture | ^[pefile.txt] |
| Screenshot via GDIPlus/GDI32 | T1113 — Screen Capture | ^[pefile.txt] |
| Microphone capture via waveIn* | T1123 — Audio Capture | ^[pefile.txt] |
| Webcam capture | T1125 — Video Capture | ^[strings.txt:47] |
| Process enumeration via Toolhelp32 | T1057 — Process Discovery | ^[pefile.txt] |
| Browser credential theft (Chrome, Firefox, IE) | T1217 — Browser Bookmark Discovery / T1005 — Data from Local System | ^[strings.txt:114] ^[strings.txt:121] ^[strings.txt:125] |
| Raw TCP C2 with [DataStart] framing | T1071.001 — Application Layer Protocol: Web Protocols (misapplied — custom TCP) | ^[strings.txt:59] |
| File manager / upload / download | T1005 — Data from Local System | ^[strings.txt:230] ^[strings.txt:211] |
| Registry Run persistence | T1547.001 — Boot or Logon Autostart Execution: Registry Run Keys | ^[strings.txt:131] |
| Winlogon Userinit persistence | T1547.004 — Boot or Logon Autostart Execution: Winlogon Helper DLL | ^[strings.txt:142] |
| eventvwr UAC bypass | T1548.002 — Abuse Elevation Control Mechanism: Bypass UAC | ^[strings.txt:66] ^[strings.txt:186] |
| EnableLUA registry disable | T1548.002 — Bypass UAC (fallback) | ^[strings.txt:186] |
| Sandbox evasion strings | T1497.001 — Virtualization/Sandbox Evasion | ^[strings.txt:40] ^[strings.txt:41] ^[strings.txt:42] ^[strings.txt:43] |
| URLDownloadToFileA / InternetOpenUrlA fallback | T1105 — Ingress Tool Transfer | ^[pefile.txt] |
References
- remcos — cluster entity page with full build/TTP analysis
- eventvwr-uac-bypass — technique page for mscfile hijack
- embedded-rcdata-config — concept page for encrypted RCData payload staging
- registry-run-persistence — procedure page for Run-key persistence
- raw-tcp-c2-socket — concept page for raw TCP C2
Provenance
Static analysis via file, exiftool, pefile, rabin2, radare2 (level-3 auto-analysis), and strings. No capa or floss due to tooling errors (missing signatures / bad CLI flags). Dynamic analysis skipped — CAPE has no Windows guest. Build provenance: MSVC C++ with MSVCP60.dll, LinkerVersion 6.0, compiled Jan 5 2017. No packer, no obfuscation, no signing.