typeanalysisfamilyremcosconfidencehighcreated2026-09-05updated2026-09-05malware-familyratc2persistencedefense-evasiondiscoveryexfiltrationpecompilercode-injectionmitre-attck
SHA-256: 65d3a51a436d55aff9c6845dfb8974ce4ee9456e4d3beb6dd2c8b3c4e9fdcd0d

remcos: 65d3a51a — v1.7 Pro, 406-byte RCData SETTINGS, no VS_VERSIONINFO, Backdoor.exe

Executive Summary

Remcos v1.7 Pro (Breaking-Security.Net) compiled 5 Jan 2017. This sibling carries a 406-byte encrypted RCData SETTINGS blob, no VS_VERSIONINFO resource, and the unmasked filename Backdoor.exe. Full process-hollowing injection engine, eventvwr UAC bypass, raw TCP C2 with [DataStart] framing, and the full surveillance feature set (keylogger, clipboard, screen/webcam/mic capture, browser credential theft). Static-only; CAPE skipped — no Windows guest available.

What It Is

Field Value
SHA-256 65d3a51a436d55aff9c6845dfb8974ce4ee9456e4d3beb6dd2c8b3c4e9fdcd0d
Filename Backdoor.exe ^[triage.json]
Type PE32 executable (GUI) Intel 80386, 4 sections ^[file.txt]
Compile Thu 2017-01-05 19:50:13 UTC ^[pefile.txt:34] ^[rabin2-info.txt:11]
Linker MSVC 6.0 (MajorLinkerVersion=6, Minor=0) ^[pefile.txt:45-46]
Runtime MSVCP60.dll C++ STL (std::basic_string, iostream, fstream) ^[pefile.txt:405-494]
Signed No ^[rabin2-info.txt:27]
Packer None ^[binwalk.txt]
RCData SETTINGS, 406 bytes (0x196) ^[pefile.txt:704]
Resources RT_ICON, RT_GROUP_ICON, RT_RCDATA only — no RT_VERSIONINFO ^[pefile.txt:644-738]
Family Remcos v1.7 Pro ^[strings.txt:203] ^[strings.txt:297]

This sample is a cluster sibling of the existing Remcos entity page; shared build-stack and TTPs are documented there. This report focuses on per-sample deltas.

How It Works

Persistence & Elevation

The entry point (main @ 0x00407452) resolves the RCData SETTINGS blob via FindResourceA/LoadResource/LockResource (imported in IAT ^[pefile.txt:228-229]), decrypts it in fcn.00407c53, and branches into installation logic.

  • Registry Run — Software\Microsoft\Windows\CurrentVersion\Run\ and Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\ ^[strings.txt:139] ^[strings.txt:144]
  • Winlogon Userinit hijack — C:\WINDOWS\system32\userinit.exe, and explorer.exe, strings ^[strings.txt:141] ^[strings.txt:143] ^[strings.txt:155] ^[strings.txt:156]
  • UAC bypass via eventvwr.exe — hijacks Software\Classes\mscfile\shell\open\command to redirect to self ^[strings.txt:66] ^[strings.txt:67] ^[strings.txt:69]. If that fails, disables UAC entirely via EnableLUA=0 registry write spawned through cmd.exe /k reg.exe ADD ... ^[strings.txt:186]. Decompiled in fcn.004084b8 ^[r2:fcn.004084b8].

Process Injection (Process Hollowing)

The full hollowing engine is present in fcn.0040d477 ^[r2:fcn.0040d477]:

  1. Resolves NtUnmapViewOfSection dynamically from ntdll.dll ^[strings.txt:286].
  2. Creates target process suspended via CreateProcessA.
  3. Reads PE headers from remote process with ReadProcessMemory.
  4. Allocates remote memory with VirtualAllocEx.
  5. Writes payload sections with WriteProcessMemory.
  6. Sets new entry point via SetThreadContext, resumes with ResumeThread.

All required APIs are in the IAT: CreateProcessA, VirtualAllocEx, WriteProcessMemory, ReadProcessMemory, SetThreadContext, GetThreadContext, ResumeThread ^[pefile.txt:236-255].

Surveillance & Credential Theft

Static strings reveal the complete feature set:

  • Keylogger — SetWindowsHookExA, GetKeyState, keyboard layout queries ^[pefile.txt:304-335]
  • Clipboard — OpenClipboard, GetClipboardData, SetClipboardData, EmptyClipboard ^[pefile.txt:308-311]
  • Screenshots — StretchBlt, GetDIBits, GDIPlus image encoder/save APIs ^[pefile.txt:348-356] ^[pefile.txt:610-619]
  • Webcam — OpenCamera, CloseCamera, GetFrame, FreeFrame, initcamcap, getcamframe, startcamcap, getcamsingleframe ^[strings.txt:47-56]
  • Microphone — waveInOpen, waveInStart, waveInAddBuffer, waveInPrepareHeader, waveInClose ^[pefile.txt:556-562]
  • Browser credential theft — Chrome Login Data / Cookies, Firefox logins.json / key3.db / cookies.sqlite, IE cookies ^[strings.txt:114-133]
  • Process enumeration — CreateToolhelp32Snapshot, Process32First/Next ^[pefile.txt:223-224] ^[pefile.txt:231-232]
  • File manager — downloadfromurltofile, downloadfromlocaltofile, upload, delete, rename, newfolder, search ^[strings.txt:256-275]
  • Remote shell — cmdoutput, consolecmd, execcom ^[strings.txt:245-247]
  • Registry editor — initregedit, regopen, regcreatekey, regeditval, regdelkey, regdelval ^[strings.txt:190-199]
  • System power — SetSuspendState from PowrProf.dll ^[strings.txt:215-216]

Anti-Analysis

Minimal. Sandbox string checks only:

  • SbieDll.dll (Sandboxie) ^[strings.txt:40]
  • HARDWARE\ACPI\DSDT\VBOX__ (VirtualBox) ^[strings.txt:41]
  • PROCMON_WINDOW_CLASS (Process Monitor) ^[strings.txt:42]
  • PROCEXPL (Process Explorer) ^[strings.txt:43]

No anti-debug APIs, no VM detection beyond these strings. No code obfuscation.

C2 Infrastructure

Primary transport: raw TCP sockets via WS2_32.dll ordinals — connect, send, recv, htons, gethostbyname, WSAStartup ^[pefile.txt:582-590].

Protocol framing: [DataStart] and [DataStart]0000 delimiters ^[strings.txt:59-60].

Keep-alive: heartbeat messages with %02i:%02i:%02i:%03i [KeepAlive] format and configurable timeout ^[strings.txt:61-65].

Fallback HTTP download: URLDownloadToFileA (urlmon.dll) and InternetOpenUrlA/InternetReadFile (WININET.dll) for payload updates ^[pefile.txt:600] ^[pefile.txt:630-633].

C2 command strings (protocol verbs observed in binary): initfun, initremscript, getclipboard, setclipboard, emptyclipboard, screenshotdata, scrslist, getscrslist, dwnldscr, scrcap, initializescrcap, freescrcap, getofflinelogs, autogetofflinelogs, startonlinekl, stoponlinekl, deletekeylog, clearlogins, initklfrm, upload, download, listfiles, getdrives, driveslist, fileslist, filemgr, prockill, proclist, getproclist, getwindows, closewindow, maxwindow, restorewindow, closeprocfromwindow, execcom, consolecmd, cmdoutput, openaddress, keepaliveoff, showmsg, search, stopsearch, newfolder, rename, delete, sendfiledata, uploadprogress, downloadfromurltofile, downloadfromlocaltofile, updatefromurl, updatefromlocal, uninstall, deletefile, pwgrab, miccapture, stopmiccapture, getcamlib, freecamcap, getcamframe, initcamcap, startcamcap, getcamsingleframe, freecamcap, keyinput, mclick, msgbox, OSpower, autopswdata, pswdata, regmsg, regopened, regcreatekey, regeditval, regdelkey, regdelval, regopen, initregedit, remscripterr, remscriptsuccess, remscriptexecd, subsplt, wndsplt ^[strings.txt:207-284].

No hardcoded IP, domain, or URL recovered from static analysis. C2 endpoint is builder-supplied in the encrypted RCData SETTINGS blob.

Mutex: Remcos_Mutex_Inj ^[strings.txt:168].

Interesting Tidbits

  • Builder opsec: filename is literally Backdoor.exe — no masquerade attempt. ^[triage.json]
  • No version resource: absent VS_VERSIONINFO means no FileDescription/CompanyName to pivot on in EDR. ^[pefile.txt]
  • Std::string bloat: ~90KB binary with heavy MSVCP60 basic_string churn. Builder likely emits literal C++ source compiled with MSVC 6.0.
  • Batch self-destruct: del %0 and PING 127.0.0.1 -n 2 strings suggest install/uninstall batch wrappers. ^[strings.txt:145-147]
  • UAC fallback chain: eventvwr hijack first; if that fails, brute-force EnableLUA=0 via cmd.exe spawned with CreateProcessA. ^[r2:fcn.004084b8]
  • Settings blob size: 406 bytes sits mid-range within the observed Remcos v1.7 Pro cluster (245–803 bytes). ^[pefile.txt:704]

How To Mess With It (Homelab Replication)

Goal: produce a PE32 GUI binary that imports MSVCP60.dll + WS2_32.dll + WINMM.dll + urlmon.dll + gdiplus.dll, embeds an RCData blob named SETTINGS, and prints [DataStart] — enough to trigger a generic Remcos YARA.

  1. Toolchain: Visual C++ 6.0 (or MSVC 2019 with /MT linking to legacy MSVCP60 import table). Target: Win32 GUI.
  2. Resources: Add RCData named SETTINGS via .rc file and rc.exe.
  3. Imports: Explicitly link against ws2_32.lib, winmm.lib, urlmon.lib, gdiplus.lib.
  4. Strings: include Remcos, 1.7 Pro, Breaking-Security.Net, Remcos_Mutex_Inj, [DataStart].
  5. Verification: compile, then run yara remcos_v17.yar reproducer.exe — should match.

Deployable Signatures

YARA Rule

rule remcos_v17_pro_generic
{
    meta:
        description = "Remcos v1.7 Pro - generic family rule"
        author = "PacketPursuit"
        date = "2026-09-05"
        hash = "65d3a51a436d55aff9c6845dfb8974ce4ee9456e4d3beb6dd2c8b3c4e9fdcd0d"
    strings:
        $s1 = "Remcos" ascii wide
        $s2 = "1.7 Pro" ascii
        $s3 = "Breaking-Security.Net" ascii
        $s4 = "Remcos_Mutex_Inj" ascii
        $s5 = "[DataStart]" ascii
        $s6 = "SETTINGS" wide
        $s7 = "eventvwr.exe" ascii
        $s8 = "NtUnmapViewOfSection" ascii
        $s9 = "initcamcap" ascii
        $s10 = "waveInOpen" ascii
    condition:
        uint16(0) == 0x5a4d and
        pe.number_of_sections == 4 and
        pe.imports("MSVCP60.dll") and
        pe.imports("WS2_32.dll") and
        6 of ($s*)
}

Sigma Rule

title: Remcos UAC Bypass via eventvwr.exe mscfile Hijack
description: Detects registry modification used by Remcos for UAC bypass
logsource:
    category: registry_event
    product: windows
detection:
    selection:
        EventType: SetValue
        TargetObject|contains: '\\Classes\\mscfile\\shell\\open\\command'
    condition: selection
falsepositives:
    - Unlikely in normal operations
level: high
references:
    - https://attack.mitre.org/techniques/T1548/002/
    - /intel/analyses/65d3a51a436d55aff9c6845dfb8974ce4ee9456e4d3beb6dd2c8b3c4e9fdcd0d.html

IOC List

Indicator Type Note
65d3a51a436d55aff9c6845dfb8974ce4ee9456e4d3beb6dd2c8b3c4e9fdcd0d SHA-256 This sample
Backdoor.exe Filename No masquerade
Remcos_Mutex_Inj Mutex Singleton check
Software\Classes\mscfile\shell\open\command Registry key UAC bypass vector
Software\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA=0 Registry value UAC disable fallback
Software\Microsoft\Windows\CurrentVersion\Run\ Registry key Persistence
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\ Registry key Persistence
Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit Registry key Persistence
\AppData\Local\Google\Chrome\User Data\Default\Login Data File path Chrome credential target
\AppData\Roaming\Mozilla\Firefox\Profiles\ File path Firefox credential target
[DataStart] Network framing C2 delimiter
initcamcap, getcamframe, waveInOpen, SetSuspendState API strings Surveillance feature markers

Behavioral Fingerprint

At launch, this binary checks for a singleton mutex (Remcos_Mutex_Inj) via OpenMutexA; if absent, creates it. It then decrypts an embedded RCData resource named SETTINGS (406 bytes) and writes registry Run keys for persistence. Within seconds it may spawn eventvwr.exe or cmd.exe /k reg.exe ... EnableLUA 0 to elevate. Network behavior begins with WSAStartup followed by socket/connect to a builder-supplied host, sending [DataStart]-delimited frames. Concurrent threads enumerate processes via CreateToolhelp32Snapshot, capture keystrokes via SetWindowsHookExA, and periodically screenshot the desktop via GDIPlus. HTTP fallback downloads use URLDownloadToFileA with a hardcoded URL from the SETTINGS blob.

Detection Signatures

Static-only; no CAPE runtime data. ATT&CK mappings inferred from imports and strings:

Technique ID Evidence
Registry Run Keys T1547.001 Software\...\Run\ strings ^[strings.txt:139] ^[strings.txt:144]
Winlogon Userinit T1547.004 userinit.exe + registry string ^[strings.txt:141-143] ^[strings.txt:155-156]
UAC Bypass: Event Viewer T1548.002 eventvwr.exe + mscfile\shell\open\command ^[strings.txt:66-69]
Input Capture: Keylogging T1056.001 SetWindowsHookExA, GetKeyState ^[pefile.txt:332] ^[pefile.txt:330]
Input Capture: Clipboard T1056.002 OpenClipboard, GetClipboardData ^[pefile.txt:308-309]
Screen Capture T1113 StretchBlt, GetDIBits, GDIPlus save ^[pefile.txt:353-356] ^[pefile.txt:610-619]
Audio Capture T1123 waveInOpen, waveInStart ^[pefile.txt:556-557]
Video Capture T1125 OpenCamera, GetFrame, initcamcap ^[strings.txt:47-56]
Browser Credential Theft T1217 Chrome/Firefox/IE storage paths ^[strings.txt:114-133]
Data from Local System T1005 File manager strings ^[strings.txt:256-275]
Application Layer Protocol T1071.001 Raw TCP via WS2_32.dll ^[pefile.txt:582-590]
Ingress Tool Transfer T1105 URLDownloadToFileA, InternetOpenUrlA ^[pefile.txt:600] ^[pefile.txt:630-633]
Process Discovery T1057 CreateToolhelp32Snapshot, Process32First ^[pefile.txt:223-224]
Process Injection: Process Hollowing T1055.012 NtUnmapViewOfSection, VirtualAllocEx, WriteProcessMemory, SetThreadContext, ResumeThread ^[r2:fcn.0040d477]
Disable or Modify System Firewall T1562.004 EnableLUA=0 registry write ^[strings.txt:186] ^[r2:fcn.004084b8]

References

  • remcos — entity page for the Remcos family cluster. ^[entities/remcos.md]
  • eventvwr-uac-bypass — technique page for the mscfile hijack. ^[techniques/eventvwr-uac-bypass.md]
  • embedded-rcdata-config — concept page for encrypted RCData payload staging. ^[concepts/embedded-rcdata-config.md]

Provenance

  • file.txt — file(1) output
  • pefile.txt — pefile library dump (DOS/NT headers, sections, imports, resources)
  • strings.txt — strings -n 6 output
  • rabin2-info.txt — radare2 rabin2 -I header summary
  • binwalk.txt — binwalk -B embedded artifact scan
  • triage.json — triage pipeline metadata
  • dynamic-analysis.md — CAPE skipped (no Windows guest)
  • floss.txt — failed (CLI argument error during triage)
  • capa.txt — failed (default signature path missing during triage)
  • radare2 decompilation — fcn.004084b8 (UAC disable), fcn.0040d477 (process hollowing), fcn.00407c53 (SETTINGS decryption), main @ 0x00407452