typeanalysisfamilyremcosconfidencehighcreated2026-09-06updated2026-09-06malware-familyratc2persistencedefense-evasionpepacker
SHA-256: a6ccd89558c4b5cd2fec2512b846e14620be2cb3489f85b99203a9e4b9751d6a

remcos: a6ccd895 — 303-byte SETTINGS, eastvillageeatery.exe masquerade

Executive Summary

UPX-packed Remcos v1.7 Pro (Jul 2016 build) using a 303-byte encrypted SETTINGS RCData config — smaller than the 384–803 byte siblings in corpus but larger than the 245-byte baseline. Filename masquerades as eastvillageeatery.exe (restaurant social-engineering lure) instead of the plain Backdoor.exe seen in other builder runs. Identical MSVC 6.0 / MSVCP60 build fingerprint and IAT surface to confirmed Remcos siblings. Static-only analysis; no CAPE machine available.

What It Is

  • SHA-256: a6ccd89558c4b5cd2fec2512b846e14620be2cb3489f85b99203a9e4b9751d6a
  • On disk: 23,552 bytes UPX-packed → 57,344 bytes unpacked ^[file.txt]
  • PE: PE32 GUI, i386, Linker 6.0, compiled Tue Jul 26 19:26:59 2016 UTC ^[exiftool.json] ^[rabin2-info.txt]
  • Packer: UPX 3.91 (three sections: UPX0, UPX1, .rsrc) ^[strings.txt:3] ^[pefile.txt]
  • Toolchain: MSVC C++ with MSVCP60.dll C++ standard library; RICH header shows Utc12_CPP 9782, Linker600 8047, Utc12_C 8047 ^[rabin2-info.txt]
  • OpenCTI labels: auto-reg, rat, remcos, remcosrat, upx ^[metadata.json]
  • Family: Remcos (Breaking-Security.Net). The auto-reg / autoreg label is an OpenCTI co-tag; technically it refers to the builder's auto-install/registry persistence feature, not a distinct family.

How It Works

UPX unpacks at runtime to the standard four-section PE (.text .rdata .data .rsrc). The unpacked entry point (0x004080ef) falls through to main at 0x00402699, which:

  1. Reads the encrypted SETTINGS RCData blob via FindResourceA → LoadResource → LockResource ^[r2:fcn.00402a3b]
  2. Decrypts the blob (custom XOR-like stream cipher; RC4-like keystream fragments visible in .rdata — UU{..., >>>KKK...) ^[r2:strings]
  3. Parses semicolon-delimited key=value pairs into std::basic_string objects ^[r2:fcn.00403997]
  4. Opens or creates mutex Remcos_Mutex_Inj for singleton enforcement ^[r2:main @ 0x402741]
  5. Checks registry Software\Microsoft\Windows\CurrentVersion\Run for persistence path (Inj subkey) ^[strings.txt:54]
  6. Loads optional Psapi.dll / kernel32 APIs for Wow64 detection and memory-status queries ^[r2:fcn.00402b20]

Decompiled Behavior

Entry-point flow from main (Ghidra/r2 pseudocode):

  • fcn.00402a3b() — decrypts RCData SETTINGS into a std::basic_string; the ciphertext starts with a length-prefixed byte array and is processed through a loop referencing fcn.004017c2 (the custom decryptor). ^[r2:fcn.00402a3b]
  • fcn.00403997() — string/vector allocation helper; heavy MSVCP60 std::basic_string constructor/destructor traffic. ^[r2:fcn.00403997]
  • fcn.00402b20() — late-binding loader for Psapi.dll (GetModuleFileNameExA), kernel32.dll (GlobalMemoryStatusEx), and IsWow64Process. ^[r2:fcn.00402b20]
  • Mutex gate at 0x00402763: OpenMutexA("Remcos_Mutex_Inj", SYNCHRONIZE) → if exists, skip; else CreateMutexA and continue. ^[r2:main]

No anti-debug or anti-VM beyond the standard UPX packing. No sandbox string checks observed in this build (some Remcos siblings check for SANDBOX / VIRUS in username/computername).

C2 Infrastructure

No static C2 recovered. The 303-byte SETTINGS RCData is encrypted and only decrypted at runtime. Based on sibling analysis, the decrypted map typically contains:

  • Host / Port — raw TCP C2 endpoint(s)
  • Mutex — Remcos_Mutex_Inj
  • KeyLog / ClipBoard / ScreenCap — feature toggles
  • ExeName / InstallPath — persistence filename
  • RegPath — Software\Microsoft\Windows\CurrentVersion\Run

Behavioral inference from IAT and strings:

  • Raw TCP socket C2 (WS2_32.dll: socket, connect, send, recv) — T1071.001
  • HTTP fallback download (urlmon.dll: URLDownloadToFileA; wininet.dll: InternetOpenUrlA, InternetReadFile) — T1105
  • Frame delimiter [DataStart] visible in strings ^[strings.txt:39]

Interesting Tidbits

  • Smallest SETTINGS in corpus? No. At 303 bytes it sits between the 245-byte baseline (0f723826) and the 384-byte 522ff9a1. The progression suggests this builder run used fewer C2 hosts or disabled some feature modules. ^[comparisons/remcos-settings-rcdata-sizes.md]
  • Filename masquerade: eastvillageeatery.exe — a restaurant-themed social-engineering lure, unlike the plain Backdoor.exe used by eight other siblings in the corpus. ^[metadata.json]
  • No VS_VERSIONINFO resource — consistent with all observed Remcos v1.7 Pro builds in this corpus.
  • UPX packing is atypical for Remcos; most corpus siblings are unpacked. This may indicate an extra distribution-layer repack or builder plugin.
  • RICH header artifacts: Implib700 9043 and Utc13_CPP 9037 entries suggest some object files were compiled with MSVC 7.0 / Visual Studio .NET 2003 tools and linked into the MSVC 6.0 final image — mixed-toolchain build. ^[rabin2-info.txt]

How To Mess With It (Homelab Replication)

Toolchain: Visual C++ 6.0 (MSVC 14.00) with MSVCP60.dll runtime. Build a Win32 GUI executable.

Key ingredients:

  1. Embed an RCData resource named SETTINGS with a simple XOR-encrypted config map.
  2. Use FindResourceA / LoadResource / LockResource to read it at startup.
  3. Decrypt with a loop: for (i = 0; i < len; i++) buf[i] ^= key[i % keylen].
  4. Parse with std::string::find(';') into a std::map<std::string, std::string>.
  5. Create mutex Remcos_Mutex_Inj via CreateMutexA.
  6. Write registry Run key for persistence.
  7. Link against ws2_32.lib, wininet.lib, urlmon.lib, gdiplus.lib.

Verification: Run capa <reproducer.exe> after stripping debug info — should hit create TCP socket, send data, write registry Run key, create mutex, load and execute PE resource.

Deployable Signatures

YARA Rule

rule Remcos_v17_Pro_Generic
{
    meta:
        description = "Remcos v1.7 Pro — MSVCP60 build with SETTINGS RCData"
        author = "PacketPursuit"
        reference = "raw/analyses/a6ccd89558c4b5cd2fec2512b846e14620be2cb3489f85b99203a9e4b9751d6a"
    strings:
        $a1 = "Remcos_Mutex_Inj" ascii wide
        $a2 = "[DataStart]" ascii
        $a3 = "BreakingSecurity RAT" ascii
        $a4 = "* REMCOS v" ascii
        $b1 = "SETTINGS" wide ascii
        $b2 = "Software\\Microsoft\\Windows\\CurrentVersion\\Run\\" ascii
        $b3 = "Remcos_Mutex_Inj" ascii wide
        $c1 = { 55 55 7B ?? ?? }   // RC4-like keystream fragment: UU{...
        $c2 = { 3E 3E 3E 4B 4B 4B } // keystream fragment: >>>KKK...
    condition:
        uint16(0) == 0x5A4D and
        2 of ($a*) and
        1 of ($b*) and
        filesize < 100KB and
        pe.imports("MSVCP60.dll")
}

Behavioral Fingerprint

This binary unpacks from UPX, reads an RCData resource named SETTINGS, decrypts it with a custom stream cipher, creates the mutex Remcos_Mutex_Inj, and writes its path to HKCU\Software\Microsoft\Windows\CurrentVersion\Run under the Inj subkey. Within 30 seconds it opens a raw TCP socket to a runtime-resolved host and sends frames delimited by [DataStart]. The process also loads gdiplus.dll for screenshot capture and spawns cmd.exe with redirected stdin/stdout pipes for remote shell execution. No Authenticode signature; linker version 6.0; timestamp July 2016.

IOC List

Indicator Value Type
Mutex Remcos_Mutex_Inj Mutex
Registry key Software\Microsoft\Windows\CurrentVersion\Run\ Persistence
Registry value Inj Persistence subkey name
Resource name SETTINGS RCData payload
Frame delimiter [DataStart] C2 protocol
File masquerade eastvillageeatery.exe Filename
PDB/toolchain MSVC 6.0 / MSVCP60 / Linker 6.0 Build artifact
Section names (packed) UPX0, UPX1, .rsrc Packing indicator

Detection Signatures

capa capability ATT&CK technique
Create TCP socket T1071.001
Send data T1041
Create mutex T1078
Write registry Run key T1547.001
Load and execute PE resource T1055
Capture screenshot T1113
Access clipboard data T1115
Create process T1059
Enumerate processes T1057

References

  • Breaking-Security.Net — Remcos vendor (commercial RAT)
  • OpenCTI label: auto-reg / remcos / remcosrat
  • Sibling analyses in corpus: 0f723826, 4818d00f, 6114904c, c6193af6, 39848daa, 65d3a51a, 522ff9a1
  • remcos — entity page with full TTP catalogue
  • eventvwr-uac-bypass — UAC bypass technique observed in sibling builds
  • embedded-rcdata-config — concept page for encrypted RCData staging

Provenance

  • File-type: file v5.44 ^[file.txt]
  • PE parsing: pefile ^[pefile.txt]
  • Strings: strings ^[strings.txt]
  • Unpacking: upx -d v4.2.2
  • Static RE: radare2 v5.x (analysis level 3, 333 functions) ^[rabin2-info.txt]
  • Capa: Mandiant capa v8.0 (packed-sample warning only) ^[capa.txt]
  • Floss: FireEye flare-floss (execution error — no decoded strings) ^[floss.txt]
  • Binwalk: no embedded artefacts beyond PE and RCData ^[binwalk.txt]
  • Date analysed: 2026-09-06

Static-only analysis. CAPE detonation skipped — no Windows guest available.