a6ccd89558c4b5cd2fec2512b846e14620be2cb3489f85b99203a9e4b9751d6aremcos: a6ccd895 — 303-byte SETTINGS, eastvillageeatery.exe masquerade
Executive Summary
UPX-packed Remcos v1.7 Pro (Jul 2016 build) using a 303-byte encrypted SETTINGS RCData config — smaller than the 384–803 byte siblings in corpus but larger than the 245-byte baseline. Filename masquerades as eastvillageeatery.exe (restaurant social-engineering lure) instead of the plain Backdoor.exe seen in other builder runs. Identical MSVC 6.0 / MSVCP60 build fingerprint and IAT surface to confirmed Remcos siblings. Static-only analysis; no CAPE machine available.
What It Is
- SHA-256:
a6ccd89558c4b5cd2fec2512b846e14620be2cb3489f85b99203a9e4b9751d6a - On disk: 23,552 bytes UPX-packed → 57,344 bytes unpacked ^[file.txt]
- PE: PE32 GUI, i386, Linker 6.0, compiled
Tue Jul 26 19:26:59 2016 UTC^[exiftool.json] ^[rabin2-info.txt] - Packer: UPX 3.91 (three sections: UPX0, UPX1, .rsrc) ^[strings.txt:3] ^[pefile.txt]
- Toolchain: MSVC C++ with MSVCP60.dll C++ standard library; RICH header shows
Utc12_CPP9782,Linker6008047,Utc12_C8047 ^[rabin2-info.txt] - OpenCTI labels:
auto-reg,rat,remcos,remcosrat,upx^[metadata.json] - Family: Remcos (Breaking-Security.Net). The
auto-reg/autoreglabel is an OpenCTI co-tag; technically it refers to the builder's auto-install/registry persistence feature, not a distinct family.
How It Works
UPX unpacks at runtime to the standard four-section PE (.text .rdata .data .rsrc). The unpacked entry point (0x004080ef) falls through to main at 0x00402699, which:
- Reads the encrypted
SETTINGSRCData blob viaFindResourceA→LoadResource→LockResource^[r2:fcn.00402a3b] - Decrypts the blob (custom XOR-like stream cipher; RC4-like keystream fragments visible in
.rdata—UU{...,>>>KKK...) ^[r2:strings] - Parses semicolon-delimited key=value pairs into
std::basic_stringobjects ^[r2:fcn.00403997] - Opens or creates mutex
Remcos_Mutex_Injfor singleton enforcement ^[r2:main @ 0x402741] - Checks registry
Software\Microsoft\Windows\CurrentVersion\Runfor persistence path (Injsubkey) ^[strings.txt:54] - Loads optional Psapi.dll / kernel32 APIs for Wow64 detection and memory-status queries ^[r2:fcn.00402b20]
Decompiled Behavior
Entry-point flow from main (Ghidra/r2 pseudocode):
fcn.00402a3b()— decrypts RCData SETTINGS into astd::basic_string; the ciphertext starts with a length-prefixed byte array and is processed through a loop referencingfcn.004017c2(the custom decryptor). ^[r2:fcn.00402a3b]fcn.00403997()— string/vector allocation helper; heavy MSVCP60std::basic_stringconstructor/destructor traffic. ^[r2:fcn.00403997]fcn.00402b20()— late-binding loader forPsapi.dll(GetModuleFileNameExA),kernel32.dll(GlobalMemoryStatusEx), andIsWow64Process. ^[r2:fcn.00402b20]- Mutex gate at
0x00402763:OpenMutexA("Remcos_Mutex_Inj", SYNCHRONIZE)→ if exists, skip; elseCreateMutexAand continue. ^[r2:main]
No anti-debug or anti-VM beyond the standard UPX packing. No sandbox string checks observed in this build (some Remcos siblings check for SANDBOX / VIRUS in username/computername).
C2 Infrastructure
No static C2 recovered. The 303-byte SETTINGS RCData is encrypted and only decrypted at runtime. Based on sibling analysis, the decrypted map typically contains:
Host/Port— raw TCP C2 endpoint(s)Mutex—Remcos_Mutex_InjKeyLog/ClipBoard/ScreenCap— feature togglesExeName/InstallPath— persistence filenameRegPath—Software\Microsoft\Windows\CurrentVersion\Run
Behavioral inference from IAT and strings:
- Raw TCP socket C2 (
WS2_32.dll:socket,connect,send,recv) — T1071.001 - HTTP fallback download (
urlmon.dll:URLDownloadToFileA;wininet.dll:InternetOpenUrlA,InternetReadFile) — T1105 - Frame delimiter
[DataStart]visible in strings ^[strings.txt:39]
Interesting Tidbits
- Smallest SETTINGS in corpus? No. At 303 bytes it sits between the 245-byte baseline (
0f723826) and the 384-byte522ff9a1. The progression suggests this builder run used fewer C2 hosts or disabled some feature modules. ^[comparisons/remcos-settings-rcdata-sizes.md] - Filename masquerade:
eastvillageeatery.exe— a restaurant-themed social-engineering lure, unlike the plainBackdoor.exeused by eight other siblings in the corpus. ^[metadata.json] - No VS_VERSIONINFO resource — consistent with all observed Remcos v1.7 Pro builds in this corpus.
- UPX packing is atypical for Remcos; most corpus siblings are unpacked. This may indicate an extra distribution-layer repack or builder plugin.
- RICH header artifacts:
Implib7009043 andUtc13_CPP9037 entries suggest some object files were compiled with MSVC 7.0 / Visual Studio .NET 2003 tools and linked into the MSVC 6.0 final image — mixed-toolchain build. ^[rabin2-info.txt]
How To Mess With It (Homelab Replication)
Toolchain: Visual C++ 6.0 (MSVC 14.00) with MSVCP60.dll runtime. Build a Win32 GUI executable.
Key ingredients:
- Embed an RCData resource named
SETTINGSwith a simple XOR-encrypted config map. - Use
FindResourceA/LoadResource/LockResourceto read it at startup. - Decrypt with a loop:
for (i = 0; i < len; i++) buf[i] ^= key[i % keylen]. - Parse with
std::string::find(';')into astd::map<std::string, std::string>. - Create mutex
Remcos_Mutex_InjviaCreateMutexA. - Write registry Run key for persistence.
- Link against
ws2_32.lib,wininet.lib,urlmon.lib,gdiplus.lib.
Verification: Run capa <reproducer.exe> after stripping debug info — should hit create TCP socket, send data, write registry Run key, create mutex, load and execute PE resource.
Deployable Signatures
YARA Rule
rule Remcos_v17_Pro_Generic
{
meta:
description = "Remcos v1.7 Pro — MSVCP60 build with SETTINGS RCData"
author = "PacketPursuit"
reference = "raw/analyses/a6ccd89558c4b5cd2fec2512b846e14620be2cb3489f85b99203a9e4b9751d6a"
strings:
$a1 = "Remcos_Mutex_Inj" ascii wide
$a2 = "[DataStart]" ascii
$a3 = "BreakingSecurity RAT" ascii
$a4 = "* REMCOS v" ascii
$b1 = "SETTINGS" wide ascii
$b2 = "Software\\Microsoft\\Windows\\CurrentVersion\\Run\\" ascii
$b3 = "Remcos_Mutex_Inj" ascii wide
$c1 = { 55 55 7B ?? ?? } // RC4-like keystream fragment: UU{...
$c2 = { 3E 3E 3E 4B 4B 4B } // keystream fragment: >>>KKK...
condition:
uint16(0) == 0x5A4D and
2 of ($a*) and
1 of ($b*) and
filesize < 100KB and
pe.imports("MSVCP60.dll")
}
Behavioral Fingerprint
This binary unpacks from UPX, reads an RCData resource named SETTINGS, decrypts it with a custom stream cipher, creates the mutex Remcos_Mutex_Inj, and writes its path to HKCU\Software\Microsoft\Windows\CurrentVersion\Run under the Inj subkey. Within 30 seconds it opens a raw TCP socket to a runtime-resolved host and sends frames delimited by [DataStart]. The process also loads gdiplus.dll for screenshot capture and spawns cmd.exe with redirected stdin/stdout pipes for remote shell execution. No Authenticode signature; linker version 6.0; timestamp July 2016.
IOC List
| Indicator | Value | Type |
|---|---|---|
| Mutex | Remcos_Mutex_Inj |
Mutex |
| Registry key | Software\Microsoft\Windows\CurrentVersion\Run\ |
Persistence |
| Registry value | Inj |
Persistence subkey name |
| Resource name | SETTINGS |
RCData payload |
| Frame delimiter | [DataStart] |
C2 protocol |
| File masquerade | eastvillageeatery.exe |
Filename |
| PDB/toolchain | MSVC 6.0 / MSVCP60 / Linker 6.0 | Build artifact |
| Section names (packed) | UPX0, UPX1, .rsrc |
Packing indicator |
Detection Signatures
| capa capability | ATT&CK technique |
|---|---|
| Create TCP socket | T1071.001 |
| Send data | T1041 |
| Create mutex | T1078 |
| Write registry Run key | T1547.001 |
| Load and execute PE resource | T1055 |
| Capture screenshot | T1113 |
| Access clipboard data | T1115 |
| Create process | T1059 |
| Enumerate processes | T1057 |
References
- Breaking-Security.Net — Remcos vendor (commercial RAT)
- OpenCTI label:
auto-reg/remcos/remcosrat - Sibling analyses in corpus:
0f723826,4818d00f,6114904c,c6193af6,39848daa,65d3a51a,522ff9a1 - remcos — entity page with full TTP catalogue
- eventvwr-uac-bypass — UAC bypass technique observed in sibling builds
- embedded-rcdata-config — concept page for encrypted RCData staging
Provenance
- File-type:
filev5.44 ^[file.txt] - PE parsing:
pefile^[pefile.txt] - Strings:
strings^[strings.txt] - Unpacking:
upx -dv4.2.2 - Static RE:
radare2v5.x (analysis level 3, 333 functions) ^[rabin2-info.txt] - Capa: Mandiant capa v8.0 (packed-sample warning only) ^[capa.txt]
- Floss: FireEye flare-floss (execution error — no decoded strings) ^[floss.txt]
- Binwalk: no embedded artefacts beyond PE and RCData ^[binwalk.txt]
- Date analysed: 2026-09-06
Static-only analysis. CAPE detonation skipped — no Windows guest available.