typeanalysisfamilyremcosconfidencehighmalware-familyratc2persistencedefense-evasiondiscoveryexfiltrationcompilerpe
SHA-256: d9950b1564b0d38cbaec507c8e1cdc41df08d8a638e5f050ff71cb5ceed84867

remcos: d9950b15 — 480-byte SETTINGS blob, absent VS_VERSIONINFO, generic "Backdoor.exe" filename

Executive Summary: A Jan 2017 build of Remcos v1.7 Pro, identical toolchain and IAT surface to the confirmed cluster (0f723826, 4818d00f, 6114904c, 39848daa). Notable for its 480-byte encrypted SETTINGS RCData (middleweight for the cluster), complete absence of VS_VERSIONINFO resource, and unmasked filename Backdoor.exe — no social-engineering masquerade. Static-only; CAPE skipped due to no Windows guest.

What It Is

Field Value
SHA-256 d9950b1564b0d38cbaec507c8e1cdc41df08d8a638e5f050ff71cb5ceed84867
Filename Backdoor.exe ^[metadata.json]
File type PE32 executable (GUI) Intel 80386, 4 sections ^[file.txt]
Size 94,208 bytes (≈ 92 KB) ^[triage.json]
Compile time Thu Jan 5 19:50:13 2017 UTC (timestamp 0x586EA375) ^[pefile.txt:34] ^[rabin2-info.txt:11]
Linker MSVC 6.0 (Major=6, Minor=0) ^[pefile.txt:45-46]
Library MSVCP60.dll C++ STL + MSVCRT.dll CRT ^[pefile.txt] ^[strings.txt:533]
Signed No ^[rabin2-info.txt:27]
Packer None ^[binwalk.txt]
VS_VERSIONINFO Absent ^[exiftool.json] — unusual; most siblings carry blank or masqueraded version blocks

Family ascription: High-confidence Remcos by string profile (Remcos_Mutex_Inj, REMCOS v, Breaking-Security.Net, 1.7 Pro), import surface (WINMM, GDIPlus, WININET, urlmon, WS2_32 layered over standard Win32), and builder-typical RCData SETTINGS blob. This is a cluster sibling, not a novel variant — see remcos entity page for shared behavior.

How It Works

Persistence & Installation

The binary is a self-installing RAT. At launch it:

  1. Reads the encrypted SETTINGS RCData resource (480 bytes, entropy 7.55) ^[r2:main@0x00407452].
  2. Checks for singleton mutex Remcos_Mutex_Inj; exits if already present ^[strings.txt:168] ^[r2:main].
  3. Writes an install.bat to %TEMP% containing PING 127.0.0.1 -n 2, del %0, start "" <path>, and exit ^[strings.txt:147] ^[r2:fcn.0040650d].
  4. Copies itself to the configured install path (default under %AppData% or %ProgramFiles%, derived from registry EXEpath value) via CopyFileA ^[r2:fcn.0040650d].
  5. Executes the batch via ShellExecuteA with verb open, then calls exit() ^[r2:fcn.0040650d].
  6. Registry persistence via Software\Microsoft\Windows\CurrentVersion\Run\, Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit, and Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\ ^[strings.txt:139-144] ^[r2:main].

UAC Evasion

Implements the eventvwr.exe auto-elevation bypass (T1548.002): hijacks Software\Classes\mscfile\shell\open\command to point to itself, then launches eventvwr.exe ^[strings.txt:66-69]. Falls back to disabling UAC entirely via reg.exe ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /f executed through cmd.exe /k ^[strings.txt:186] ^[r2:main].

C2 Communication

Raw TCP socket via WS2_32.dll — socket, connect, send, recv, htons, gethostbyname ^[pefile.txt]. Framing uses [DataStart] prefix with a 4-digit counter ([DataStart]0000) ^[strings.txt:59-60]. Keep-alive heartbeat with configurable timeout (%02i:%02i:%02i:%03i [KeepAlive]) ^[strings.txt:61-65]. HTTP fallback for payload updates via URLDownloadToFileA / InternetOpenUrlA ^[strings.txt:210-211] ^[pefile.txt].

Surveillance Suite

  • Keylogger: SetWindowsHookExA with WH_KEYBOARD_LL or equivalent; maps virtual keys to labels ([F1] through [F12], [Ctrl+V], etc.) ^[strings.txt:79-112].
  • Clipboard: OpenClipboard / GetClipboardData / SetClipboardData / EmptyClipboard; logs paste events with text capture ^[strings.txt:106-113].
  • Screenshot: GDIPlus image encoder pipeline (GdipSaveImageToFile, GdipGetImageEncoders) ^[strings.txt:232-233] ^[pefile.txt].
  • Webcam: DirectShow-like wrapper strings (initcamcap, getcamframe, FreeFrame, CloseCamera, OpenCamera) ^[strings.txt:51-58].
  • Microphone: WINMM waveInOpen, waveInAddBuffer, waveInStart ^[strings.txt:568-574] ^[pefile.txt].
  • Process management: CreateToolhelp32Snapshot / Process32First / Process32Next; kill via TerminateProcess ^[strings.txt:251-254].

Browser Credential Theft

  • Chrome: %LOCALAPPDATA%\Google\Chrome\User Data\Default\Login Data and Cookies ^[strings.txt:117-120].
  • Firefox: %APPDATA%\Mozilla\Firefox\Profiles\ → key3.db, logins.json, cookies.sqlite ^[strings.txt:122-128].
  • IE: Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders → Cookies ^[strings.txt:131-132].

Anti-Analysis / Sandbox Evasion

String-based checks only — no PEB debug-bit or timing gates:

  • SbieDll.dll (Sandboxie) ^[strings.txt:40]
  • HARDWARE\ACPI\DSDT\VBOX__ (VirtualBox) ^[strings.txt:41]
  • PROCMON_WINDOW_CLASS (Process Monitor) ^[strings.txt:42]
  • PROCEXPL (Process Explorer) ^[strings.txt:43]

No debugger detection, no API hashing, no control-flow obfuscation. Low sophistication anti-analysis consistent with commodity MaaS builder output.

Decompiled Behavior

Entry point (main @ 0x00407452) ^[r2:main@0x00407452]:

  • Constructs std::basic_string objects for registry paths (Software\, Remcos_Mutex_Inj, ProductName, etc.).
  • Opens mutex; if absent, creates it and proceeds.
  • Queries SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName to determine Windows version, appending (32 bit) or (64 bit).
  • Reads RCData SETTINGS via FindResourceA/LoadResource/LockResource (wrapper at 0x00407c53).
  • Calls install routine (fcn.0040650d) which builds and executes %TEMP%\install.bat.
  • Spawns C2 thread and enters tray-icon message loop.

Tray-icon thread (fcn.0040f8bf) ^[r2:fcn.0040f8bf]:

  • Calls ExtractIconA on its own module.
  • Builds NOTIFYICONDATAA with tooltip Remcos and icon handle.
  • Calls Shell_NotifyIconA(NIM_ADD, ...).
  • Standard GetMessageA → TranslateMessage → DispatchMessageA pump.

Install routine (fcn.0040650d) ^[r2:fcn.0040650d]:

  • Concatenates batch commands using std::basic_string operators.
  • Writes to %TEMP%\install.bat via std::basic_ofstream.
  • Contents: PING 127.0.0.1 -n 2, del %0, start "" <copied_path>, exit.
  • Executes via ShellExecuteA(NULL, "open", <bat_path>, NULL, NULL, SW_HIDE).
  • Calls MSVCRT.dll_exit — original process terminates after staging.

C2 Infrastructure

  • Protocol: Raw TCP (Berkeley sockets) with [DataStart] framing ^[strings.txt:59-60] ^[pefile.txt].
  • Fallback: HTTP(S) via WININET.dll (InternetOpenUrlA, InternetReadFile) and urlmon.dll (URLDownloadToFileA) for payload updates ^[pefile.txt].
  • Configuration: Encrypted inside 480-byte SETTINGS RCData resource (entropy 7.55) — C2 host, port, mutex name, install path, and feature flags are builder-configured and stored here. Static extraction without builder key is not feasible.
  • No hardcoded C2 strings recovered in plaintext.

Interesting Tidbits

  • Largest SETTINGS blob among early siblings: At 480 bytes, this exceeds the 245–300 byte typical of 2016-era Remcos builds, though later siblings (39848daa) reached 803 bytes. Growth tracks builder feature expansion.
  • No VS_VERSIONINFO: Most Remcos samples carry a blank or cloned VS_VERSIONINFO block for masquerade. This sample lacks the resource entirely, suggesting a builder config toggle or stripped template.
  • Generic filename: Backdoor.exe with no double-extension or document masquerade. Likely a post-build rename or direct builder output before distribution repackaging.
  • Heavy STL usage: Builder emits C++ source compiled against MSVCP60.dll, using std::basic_string, std::basic_ofstream, std::basic_fstream, and std::basic_ifstream for all string and file operations. This bloats the binary and leaves abundant mangled-symbol artefacts.
  • Process-hollowing imports present: NtUnmapViewOfSection, VirtualAllocEx, WriteProcessMemory, SetThreadContext, ResumeThread ^[pefile.txt]. Not all Remcos siblings carry the full hollowing set; this one does.

How To Mess With It (Homelab Replication)

Toolchain: Visual C++ 6.0 (or VS 2005 with Platform Toolset v60) + MSVCP60.dll runtime. Target Win32 GUI, /MT static CRT link if you want to avoid MSVCP60 dependency.

Reproduction steps:

  1. Build a Win32 GUI EXE in C++ using std::basic_string for all path manipulation.
  2. Embed an encrypted config blob as RCData type SETTINGS.
  3. Implement mutex check (CreateMutexA / OpenMutexA) with name Remcos_Mutex_Inj.
  4. Build an install BAT via std::ofstream to %TEMP%\install.bat using the exact template observed: PING 127.0.0.1 -n 2, del %0, start "" <path>, exit.
  5. Add tray-icon loop with Shell_NotifyIconA and ExtractIconA.
  6. Import WS2_32.dll for raw TCP, WININET.dll for HTTP fallback, GDIPlus.dll for screenshots, WINMM.dll for mic capture.

Verification: Run strings repro.exe | grep -i remcos — should hit Remcos, Remcos_Mutex_Inj, REMCOS v, and Breaking-Security.Net.

Deployable Signatures

YARA Rule

rule remcos_v1_7_pro_cluster
{
    meta:
        description = "Remcos v1.7 Pro cluster — Jan 2017 build, MSVCP60, SETTINGS RCData"
        author = "pp-hermes"
        date = "2026-08-24"
        sha256 = "d9950b1564b0d38cbaec507c8e1cdc41df08d8a638e5f050ff71cb5ceed84867"
    strings:
        $a1 = "Remcos_Mutex_Inj" ascii wide
        $a2 = "Breaking-Security.Net" ascii wide
        $a3 = "REMCOS v" ascii wide
        $a4 = "1.7 Pro" ascii wide
        $a5 = "[DataStart]" ascii wide
        $a6 = "eventvwr.exe" ascii wide
        $a7 = "Software\\Classes\\mscfile\\shell\\open\\command" ascii wide
        $b1 = "Settings" ascii wide
        $b2 = "origmsc" ascii wide
        $c1 = "initcamcap" ascii wide
        $c2 = "waveInOpen" ascii
        $c3 = "GdipSaveImageToFile" ascii
        $c4 = "URLDownloadToFileA" ascii
    condition:
        uint16(0) == 0x5A4D and
        pe.number_of_sections == 4 and
        pe.imports("MSVCP60.dll") and
        4 of ($a*) and
        2 of ($b*) and
        2 of ($c*)
}

Behavioral Hunt Query (Sigma-like)

title: Remcos Installation BAT Execution
logsource:
  product: windows
  category: process_creation
detection:
  selection_install:
    CommandLine|contains:
      - 'install.bat'
      - 'PING 127.0.0.1 -n 2'
      - 'del %0'
  selection_persistence:
    - CommandLine|contains: 'Software\Microsoft\Windows\CurrentVersion\Run'
    - CommandLine|contains: 'Winlogon\Userinit'
    - CommandLine|contains: 'Policies\Explorer\Run'
  selection_uac:
    - CommandLine|contains: 'eventvwr.exe'
    - CommandLine|contains: 'mscfile\shell\open\command'
  selection_mutex:
    - CommandLine|contains: 'Remcos_Mutex_Inj'
  condition: 1 of selection_*
falsepositives:
  - Unlikely
level: high

IOC List

Type Value Note
Mutex Remcos_Mutex_Inj Singleton check ^[strings.txt:168]
Filename Backdoor.exe This sample; often renamed in the wild ^[metadata.json]
Registry (UAC) HKCU\Software\Classes\mscfile\shell\open\command eventvwr hijack ^[strings.txt:67]
Registry (persist) HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ Standard Run key ^[strings.txt:144]
Registry (persist) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit Userinit hijack ^[strings.txt:142]
File path %TEMP%\install.bat Staged install script ^[r2:fcn.0040650d]
File path %TEMP%\uninstall.bat Removal script ^[strings.txt:153]
File path %TEMP%\update.bat Update script ^[strings.txt:157]
Resource RCData SETTINGS Encrypted config blob, 480 bytes in this sample
API SetWindowsHookExA Keylogging ^[pefile.txt]
API NtUnmapViewOfSection Process hollowing preparation ^[pefile.txt]

Behavioral Fingerprint

This PE32 GUI binary imports MSVCP60.dll and uses C++ STL strings for all path and registry manipulation. It creates a mutex named Remcos_Mutex_Inj, reads an RCData resource named SETTINGS, writes a batch file to %TEMP%\install.bat containing PING 127.0.0.1 -n 2 and del %0, executes it via ShellExecuteA, then enters a tray-icon message loop. Concurrently it opens raw TCP sockets via WS2_32 for C2 framed with [DataStart]. Browser credential harvesting targets Chrome, Firefox, and IE storage paths. Sandbox evasion is limited to string checks for Sandboxie, VirtualBox, Process Monitor, and Process Explorer.

Detection Signatures (ATT&CK Mapping)

Technique ID Evidence
Registry Run Keys / Startup Folder T1547.001 Software\Microsoft\Windows\CurrentVersion\Run\ ^[strings.txt:144]
Winlogon Helper DLL T1547.004 Winlogon\Userinit hijack ^[strings.txt:142]
Bypass User Account Control T1548.002 eventvwr + mscfile handler ^[strings.txt:66-69]
Input Capture: Keylogging T1056.001 SetWindowsHookExA, key labels ^[strings.txt:79-112]
Input Capture: Clipboard Data T1056.002 OpenClipboard, GetClipboardData ^[strings.txt:106-113]
Screen Capture T1113 GDIPlus GdipSaveImageToFile ^[pefile.txt]
Audio Capture T1123 WINMM waveInOpen ^[strings.txt:568-574]
Video Capture T1125 initcamcap, OpenCamera ^[strings.txt:51-58]
Process Discovery T1057 CreateToolhelp32Snapshot ^[pefile.txt]
Browser Information Discovery T1217 Chrome/Firefox/IE credential paths ^[strings.txt:117-132]
Data from Local System T1005 File manager upload/download ^[strings.txt:256-271]
Application Layer Protocol: Web Protocols T1071.001 Raw TCP with [DataStart] framing ^[strings.txt:59-60]
Ingress Tool Transfer T1105 URLDownloadToFileA, InternetOpenUrlA ^[pefile.txt]
Windows Command Shell T1059.003 cmdoutput, execcom, consolecmd ^[strings.txt:245-247]
Obfuscated Files or Information T1027 Encrypted RCData SETTINGS blob (entropy 7.55)

References

  • Artifact ID: c03d0f6f-b382-444b-94f2-06b5aa50543b
  • Source: OpenCTI / MalwareBazaar
  • Related wiki: remcos — cluster entity page with shared build/TTP analysis
  • Sibling analyses: 0f723826, 4818d00f, 6114904c, 39848daa

Provenance

  • Static triage run 2026-05-29: file, exiftool, pefile, strings, ssdeep, tlsh, yara.
  • floss.txt and capa.txt not usable — floss argument error, capa signatures missing.
  • radare2 analysis 2026-08-24: rabin2 -I, r2 with aaa (level 3), decompilation of main, fcn.0040f8bf, fcn.0040650d.
  • No dynamic analysis — CAPE skipped (no Windows guest available).