65d3a51a436d55aff9c6845dfb8974ce4ee9456e4d3beb6dd2c8b3c4e9fdcd0dremcos: 65d3a51a — v1.7 Pro, 406-byte RCData SETTINGS, no VS_VERSIONINFO, Backdoor.exe
Executive Summary
Remcos v1.7 Pro (Breaking-Security.Net) compiled 5 Jan 2017. This sibling carries a 406-byte encrypted RCData SETTINGS blob, no VS_VERSIONINFO resource, and the unmasked filename Backdoor.exe. Full process-hollowing injection engine, eventvwr UAC bypass, raw TCP C2 with [DataStart] framing, and the full surveillance feature set (keylogger, clipboard, screen/webcam/mic capture, browser credential theft). Static-only; CAPE skipped — no Windows guest available.
What It Is
| Field | Value |
|---|---|
| SHA-256 | 65d3a51a436d55aff9c6845dfb8974ce4ee9456e4d3beb6dd2c8b3c4e9fdcd0d |
| Filename | Backdoor.exe ^[triage.json] |
| Type | PE32 executable (GUI) Intel 80386, 4 sections ^[file.txt] |
| Compile | Thu 2017-01-05 19:50:13 UTC ^[pefile.txt:34] ^[rabin2-info.txt:11] |
| Linker | MSVC 6.0 (MajorLinkerVersion=6, Minor=0) ^[pefile.txt:45-46] |
| Runtime | MSVCP60.dll C++ STL (std::basic_string, iostream, fstream) ^[pefile.txt:405-494] |
| Signed | No ^[rabin2-info.txt:27] |
| Packer | None ^[binwalk.txt] |
| RCData | SETTINGS, 406 bytes (0x196) ^[pefile.txt:704] |
| Resources | RT_ICON, RT_GROUP_ICON, RT_RCDATA only — no RT_VERSIONINFO ^[pefile.txt:644-738] |
| Family | Remcos v1.7 Pro ^[strings.txt:203] ^[strings.txt:297] |
This sample is a cluster sibling of the existing Remcos entity page; shared build-stack and TTPs are documented there. This report focuses on per-sample deltas.
How It Works
Persistence & Elevation
The entry point (main @ 0x00407452) resolves the RCData SETTINGS blob via FindResourceA/LoadResource/LockResource (imported in IAT ^[pefile.txt:228-229]), decrypts it in fcn.00407c53, and branches into installation logic.
- Registry Run —
Software\Microsoft\Windows\CurrentVersion\Run\andSoftware\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\^[strings.txt:139] ^[strings.txt:144] - Winlogon Userinit hijack —
C:\WINDOWS\system32\userinit.exe,andexplorer.exe,strings ^[strings.txt:141] ^[strings.txt:143] ^[strings.txt:155] ^[strings.txt:156] - UAC bypass via eventvwr.exe — hijacks
Software\Classes\mscfile\shell\open\commandto redirect to self ^[strings.txt:66] ^[strings.txt:67] ^[strings.txt:69]. If that fails, disables UAC entirely viaEnableLUA=0registry write spawned throughcmd.exe /k reg.exe ADD ...^[strings.txt:186]. Decompiled infcn.004084b8^[r2:fcn.004084b8].
Process Injection (Process Hollowing)
The full hollowing engine is present in fcn.0040d477 ^[r2:fcn.0040d477]:
- Resolves
NtUnmapViewOfSectiondynamically fromntdll.dll^[strings.txt:286]. - Creates target process suspended via
CreateProcessA. - Reads PE headers from remote process with
ReadProcessMemory. - Allocates remote memory with
VirtualAllocEx. - Writes payload sections with
WriteProcessMemory. - Sets new entry point via
SetThreadContext, resumes withResumeThread.
All required APIs are in the IAT: CreateProcessA, VirtualAllocEx, WriteProcessMemory, ReadProcessMemory, SetThreadContext, GetThreadContext, ResumeThread ^[pefile.txt:236-255].
Surveillance & Credential Theft
Static strings reveal the complete feature set:
- Keylogger —
SetWindowsHookExA,GetKeyState, keyboard layout queries ^[pefile.txt:304-335] - Clipboard —
OpenClipboard,GetClipboardData,SetClipboardData,EmptyClipboard^[pefile.txt:308-311] - Screenshots —
StretchBlt,GetDIBits, GDIPlus image encoder/save APIs ^[pefile.txt:348-356] ^[pefile.txt:610-619] - Webcam —
OpenCamera,CloseCamera,GetFrame,FreeFrame,initcamcap,getcamframe,startcamcap,getcamsingleframe^[strings.txt:47-56] - Microphone —
waveInOpen,waveInStart,waveInAddBuffer,waveInPrepareHeader,waveInClose^[pefile.txt:556-562] - Browser credential theft — Chrome
Login Data/Cookies, Firefoxlogins.json/key3.db/cookies.sqlite, IE cookies ^[strings.txt:114-133] - Process enumeration —
CreateToolhelp32Snapshot,Process32First/Next^[pefile.txt:223-224] ^[pefile.txt:231-232] - File manager —
downloadfromurltofile,downloadfromlocaltofile,upload,delete,rename,newfolder,search^[strings.txt:256-275] - Remote shell —
cmdoutput,consolecmd,execcom^[strings.txt:245-247] - Registry editor —
initregedit,regopen,regcreatekey,regeditval,regdelkey,regdelval^[strings.txt:190-199] - System power —
SetSuspendStatefromPowrProf.dll^[strings.txt:215-216]
Anti-Analysis
Minimal. Sandbox string checks only:
SbieDll.dll(Sandboxie) ^[strings.txt:40]HARDWARE\ACPI\DSDT\VBOX__(VirtualBox) ^[strings.txt:41]PROCMON_WINDOW_CLASS(Process Monitor) ^[strings.txt:42]PROCEXPL(Process Explorer) ^[strings.txt:43]
No anti-debug APIs, no VM detection beyond these strings. No code obfuscation.
C2 Infrastructure
Primary transport: raw TCP sockets via WS2_32.dll ordinals — connect, send, recv, htons, gethostbyname, WSAStartup ^[pefile.txt:582-590].
Protocol framing: [DataStart] and [DataStart]0000 delimiters ^[strings.txt:59-60].
Keep-alive: heartbeat messages with %02i:%02i:%02i:%03i [KeepAlive] format and configurable timeout ^[strings.txt:61-65].
Fallback HTTP download: URLDownloadToFileA (urlmon.dll) and InternetOpenUrlA/InternetReadFile (WININET.dll) for payload updates ^[pefile.txt:600] ^[pefile.txt:630-633].
C2 command strings (protocol verbs observed in binary):
initfun, initremscript, getclipboard, setclipboard, emptyclipboard, screenshotdata, scrslist, getscrslist, dwnldscr, scrcap, initializescrcap, freescrcap, getofflinelogs, autogetofflinelogs, startonlinekl, stoponlinekl, deletekeylog, clearlogins, initklfrm, upload, download, listfiles, getdrives, driveslist, fileslist, filemgr, prockill, proclist, getproclist, getwindows, closewindow, maxwindow, restorewindow, closeprocfromwindow, execcom, consolecmd, cmdoutput, openaddress, keepaliveoff, showmsg, search, stopsearch, newfolder, rename, delete, sendfiledata, uploadprogress, downloadfromurltofile, downloadfromlocaltofile, updatefromurl, updatefromlocal, uninstall, deletefile, pwgrab, miccapture, stopmiccapture, getcamlib, freecamcap, getcamframe, initcamcap, startcamcap, getcamsingleframe, freecamcap, keyinput, mclick, msgbox, OSpower, autopswdata, pswdata, regmsg, regopened, regcreatekey, regeditval, regdelkey, regdelval, regopen, initregedit, remscripterr, remscriptsuccess, remscriptexecd, subsplt, wndsplt ^[strings.txt:207-284].
No hardcoded IP, domain, or URL recovered from static analysis. C2 endpoint is builder-supplied in the encrypted RCData SETTINGS blob.
Mutex: Remcos_Mutex_Inj ^[strings.txt:168].
Interesting Tidbits
- Builder opsec: filename is literally
Backdoor.exe— no masquerade attempt. ^[triage.json] - No version resource: absent
VS_VERSIONINFOmeans noFileDescription/CompanyNameto pivot on in EDR. ^[pefile.txt] - Std::string bloat: ~90KB binary with heavy MSVCP60
basic_stringchurn. Builder likely emits literal C++ source compiled with MSVC 6.0. - Batch self-destruct:
del %0andPING 127.0.0.1 -n 2strings suggest install/uninstall batch wrappers. ^[strings.txt:145-147] - UAC fallback chain: eventvwr hijack first; if that fails, brute-force
EnableLUA=0via cmd.exe spawned withCreateProcessA. ^[r2:fcn.004084b8] - Settings blob size: 406 bytes sits mid-range within the observed Remcos v1.7 Pro cluster (245–803 bytes). ^[pefile.txt:704]
How To Mess With It (Homelab Replication)
Goal: produce a PE32 GUI binary that imports MSVCP60.dll + WS2_32.dll + WINMM.dll + urlmon.dll + gdiplus.dll, embeds an RCData blob named SETTINGS, and prints [DataStart] — enough to trigger a generic Remcos YARA.
- Toolchain: Visual C++ 6.0 (or MSVC 2019 with
/MTlinking to legacy MSVCP60 import table). Target: Win32 GUI. - Resources: Add RCData named
SETTINGSvia.rcfile andrc.exe. - Imports: Explicitly link against
ws2_32.lib,winmm.lib,urlmon.lib,gdiplus.lib. - Strings: include
Remcos,1.7 Pro,Breaking-Security.Net,Remcos_Mutex_Inj,[DataStart]. - Verification: compile, then run
yara remcos_v17.yar reproducer.exe— should match.
Deployable Signatures
YARA Rule
rule remcos_v17_pro_generic
{
meta:
description = "Remcos v1.7 Pro - generic family rule"
author = "PacketPursuit"
date = "2026-09-05"
hash = "65d3a51a436d55aff9c6845dfb8974ce4ee9456e4d3beb6dd2c8b3c4e9fdcd0d"
strings:
$s1 = "Remcos" ascii wide
$s2 = "1.7 Pro" ascii
$s3 = "Breaking-Security.Net" ascii
$s4 = "Remcos_Mutex_Inj" ascii
$s5 = "[DataStart]" ascii
$s6 = "SETTINGS" wide
$s7 = "eventvwr.exe" ascii
$s8 = "NtUnmapViewOfSection" ascii
$s9 = "initcamcap" ascii
$s10 = "waveInOpen" ascii
condition:
uint16(0) == 0x5a4d and
pe.number_of_sections == 4 and
pe.imports("MSVCP60.dll") and
pe.imports("WS2_32.dll") and
6 of ($s*)
}
Sigma Rule
title: Remcos UAC Bypass via eventvwr.exe mscfile Hijack
description: Detects registry modification used by Remcos for UAC bypass
logsource:
category: registry_event
product: windows
detection:
selection:
EventType: SetValue
TargetObject|contains: '\\Classes\\mscfile\\shell\\open\\command'
condition: selection
falsepositives:
- Unlikely in normal operations
level: high
references:
- https://attack.mitre.org/techniques/T1548/002/
- /intel/analyses/65d3a51a436d55aff9c6845dfb8974ce4ee9456e4d3beb6dd2c8b3c4e9fdcd0d.html
IOC List
| Indicator | Type | Note |
|---|---|---|
65d3a51a436d55aff9c6845dfb8974ce4ee9456e4d3beb6dd2c8b3c4e9fdcd0d |
SHA-256 | This sample |
Backdoor.exe |
Filename | No masquerade |
Remcos_Mutex_Inj |
Mutex | Singleton check |
Software\Classes\mscfile\shell\open\command |
Registry key | UAC bypass vector |
Software\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA=0 |
Registry value | UAC disable fallback |
Software\Microsoft\Windows\CurrentVersion\Run\ |
Registry key | Persistence |
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\ |
Registry key | Persistence |
Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit |
Registry key | Persistence |
\AppData\Local\Google\Chrome\User Data\Default\Login Data |
File path | Chrome credential target |
\AppData\Roaming\Mozilla\Firefox\Profiles\ |
File path | Firefox credential target |
[DataStart] |
Network framing | C2 delimiter |
initcamcap, getcamframe, waveInOpen, SetSuspendState |
API strings | Surveillance feature markers |
Behavioral Fingerprint
At launch, this binary checks for a singleton mutex (Remcos_Mutex_Inj) via OpenMutexA; if absent, creates it. It then decrypts an embedded RCData resource named SETTINGS (406 bytes) and writes registry Run keys for persistence. Within seconds it may spawn eventvwr.exe or cmd.exe /k reg.exe ... EnableLUA 0 to elevate. Network behavior begins with WSAStartup followed by socket/connect to a builder-supplied host, sending [DataStart]-delimited frames. Concurrent threads enumerate processes via CreateToolhelp32Snapshot, capture keystrokes via SetWindowsHookExA, and periodically screenshot the desktop via GDIPlus. HTTP fallback downloads use URLDownloadToFileA with a hardcoded URL from the SETTINGS blob.
Detection Signatures
Static-only; no CAPE runtime data. ATT&CK mappings inferred from imports and strings:
| Technique | ID | Evidence |
|---|---|---|
| Registry Run Keys | T1547.001 | Software\...\Run\ strings ^[strings.txt:139] ^[strings.txt:144] |
| Winlogon Userinit | T1547.004 | userinit.exe + registry string ^[strings.txt:141-143] ^[strings.txt:155-156] |
| UAC Bypass: Event Viewer | T1548.002 | eventvwr.exe + mscfile\shell\open\command ^[strings.txt:66-69] |
| Input Capture: Keylogging | T1056.001 | SetWindowsHookExA, GetKeyState ^[pefile.txt:332] ^[pefile.txt:330] |
| Input Capture: Clipboard | T1056.002 | OpenClipboard, GetClipboardData ^[pefile.txt:308-309] |
| Screen Capture | T1113 | StretchBlt, GetDIBits, GDIPlus save ^[pefile.txt:353-356] ^[pefile.txt:610-619] |
| Audio Capture | T1123 | waveInOpen, waveInStart ^[pefile.txt:556-557] |
| Video Capture | T1125 | OpenCamera, GetFrame, initcamcap ^[strings.txt:47-56] |
| Browser Credential Theft | T1217 | Chrome/Firefox/IE storage paths ^[strings.txt:114-133] |
| Data from Local System | T1005 | File manager strings ^[strings.txt:256-275] |
| Application Layer Protocol | T1071.001 | Raw TCP via WS2_32.dll ^[pefile.txt:582-590] |
| Ingress Tool Transfer | T1105 | URLDownloadToFileA, InternetOpenUrlA ^[pefile.txt:600] ^[pefile.txt:630-633] |
| Process Discovery | T1057 | CreateToolhelp32Snapshot, Process32First ^[pefile.txt:223-224] |
| Process Injection: Process Hollowing | T1055.012 | NtUnmapViewOfSection, VirtualAllocEx, WriteProcessMemory, SetThreadContext, ResumeThread ^[r2:fcn.0040d477] |
| Disable or Modify System Firewall | T1562.004 | EnableLUA=0 registry write ^[strings.txt:186] ^[r2:fcn.004084b8] |
References
- remcos — entity page for the Remcos family cluster. ^[entities/remcos.md]
- eventvwr-uac-bypass — technique page for the mscfile hijack. ^[techniques/eventvwr-uac-bypass.md]
- embedded-rcdata-config — concept page for encrypted RCData payload staging. ^[concepts/embedded-rcdata-config.md]
Provenance
file.txt— file(1) outputpefile.txt— pefile library dump (DOS/NT headers, sections, imports, resources)strings.txt—strings -n 6outputrabin2-info.txt— radare2rabin2 -Iheader summarybinwalk.txt—binwalk -Bembedded artifact scantriage.json— triage pipeline metadatadynamic-analysis.md— CAPE skipped (no Windows guest)floss.txt— failed (CLI argument error during triage)capa.txt— failed (default signature path missing during triage)- radare2 decompilation —
fcn.004084b8(UAC disable),fcn.0040d477(process hollowing),fcn.00407c53(SETTINGS decryption),main@0x00407452