d9950b1564b0d38cbaec507c8e1cdc41df08d8a638e5f050ff71cb5ceed84867remcos: d9950b15 — 480-byte SETTINGS blob, absent VS_VERSIONINFO, generic "Backdoor.exe" filename
Executive Summary: A Jan 2017 build of Remcos v1.7 Pro, identical toolchain and IAT surface to the confirmed cluster (0f723826, 4818d00f, 6114904c, 39848daa). Notable for its 480-byte encrypted SETTINGS RCData (middleweight for the cluster), complete absence of VS_VERSIONINFO resource, and unmasked filename Backdoor.exe — no social-engineering masquerade. Static-only; CAPE skipped due to no Windows guest.
What It Is
| Field | Value |
|---|---|
| SHA-256 | d9950b1564b0d38cbaec507c8e1cdc41df08d8a638e5f050ff71cb5ceed84867 |
| Filename | Backdoor.exe ^[metadata.json] |
| File type | PE32 executable (GUI) Intel 80386, 4 sections ^[file.txt] |
| Size | 94,208 bytes (≈ 92 KB) ^[triage.json] |
| Compile time | Thu Jan 5 19:50:13 2017 UTC (timestamp 0x586EA375) ^[pefile.txt:34] ^[rabin2-info.txt:11] |
| Linker | MSVC 6.0 (Major=6, Minor=0) ^[pefile.txt:45-46] |
| Library | MSVCP60.dll C++ STL + MSVCRT.dll CRT ^[pefile.txt] ^[strings.txt:533] |
| Signed | No ^[rabin2-info.txt:27] |
| Packer | None ^[binwalk.txt] |
| VS_VERSIONINFO | Absent ^[exiftool.json] — unusual; most siblings carry blank or masqueraded version blocks |
Family ascription: High-confidence Remcos by string profile (Remcos_Mutex_Inj, REMCOS v, Breaking-Security.Net, 1.7 Pro), import surface (WINMM, GDIPlus, WININET, urlmon, WS2_32 layered over standard Win32), and builder-typical RCData SETTINGS blob. This is a cluster sibling, not a novel variant — see remcos entity page for shared behavior.
How It Works
Persistence & Installation
The binary is a self-installing RAT. At launch it:
- Reads the encrypted
SETTINGSRCData resource (480 bytes, entropy 7.55) ^[r2:main@0x00407452]. - Checks for singleton mutex
Remcos_Mutex_Inj; exits if already present ^[strings.txt:168] ^[r2:main]. - Writes an
install.batto%TEMP%containingPING 127.0.0.1 -n 2,del %0,start "" <path>, andexit^[strings.txt:147] ^[r2:fcn.0040650d]. - Copies itself to the configured install path (default under
%AppData%or%ProgramFiles%, derived from registryEXEpathvalue) viaCopyFileA^[r2:fcn.0040650d]. - Executes the batch via
ShellExecuteAwith verbopen, then callsexit()^[r2:fcn.0040650d]. - Registry persistence via
Software\Microsoft\Windows\CurrentVersion\Run\,Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit, andSoftware\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\^[strings.txt:139-144] ^[r2:main].
UAC Evasion
Implements the eventvwr.exe auto-elevation bypass (T1548.002): hijacks Software\Classes\mscfile\shell\open\command to point to itself, then launches eventvwr.exe ^[strings.txt:66-69]. Falls back to disabling UAC entirely via reg.exe ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /f executed through cmd.exe /k ^[strings.txt:186] ^[r2:main].
C2 Communication
Raw TCP socket via WS2_32.dll — socket, connect, send, recv, htons, gethostbyname ^[pefile.txt]. Framing uses [DataStart] prefix with a 4-digit counter ([DataStart]0000) ^[strings.txt:59-60]. Keep-alive heartbeat with configurable timeout (%02i:%02i:%02i:%03i [KeepAlive]) ^[strings.txt:61-65]. HTTP fallback for payload updates via URLDownloadToFileA / InternetOpenUrlA ^[strings.txt:210-211] ^[pefile.txt].
Surveillance Suite
- Keylogger:
SetWindowsHookExAwithWH_KEYBOARD_LLor equivalent; maps virtual keys to labels ([F1]through[F12],[Ctrl+V], etc.) ^[strings.txt:79-112]. - Clipboard:
OpenClipboard/GetClipboardData/SetClipboardData/EmptyClipboard; logs paste events with text capture ^[strings.txt:106-113]. - Screenshot: GDIPlus image encoder pipeline (
GdipSaveImageToFile,GdipGetImageEncoders) ^[strings.txt:232-233] ^[pefile.txt]. - Webcam: DirectShow-like wrapper strings (
initcamcap,getcamframe,FreeFrame,CloseCamera,OpenCamera) ^[strings.txt:51-58]. - Microphone: WINMM
waveInOpen,waveInAddBuffer,waveInStart^[strings.txt:568-574] ^[pefile.txt]. - Process management:
CreateToolhelp32Snapshot/Process32First/Process32Next; kill viaTerminateProcess^[strings.txt:251-254].
Browser Credential Theft
- Chrome:
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Login DataandCookies^[strings.txt:117-120]. - Firefox:
%APPDATA%\Mozilla\Firefox\Profiles\→key3.db,logins.json,cookies.sqlite^[strings.txt:122-128]. - IE:
Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders→Cookies^[strings.txt:131-132].
Anti-Analysis / Sandbox Evasion
String-based checks only — no PEB debug-bit or timing gates:
SbieDll.dll(Sandboxie) ^[strings.txt:40]HARDWARE\ACPI\DSDT\VBOX__(VirtualBox) ^[strings.txt:41]PROCMON_WINDOW_CLASS(Process Monitor) ^[strings.txt:42]PROCEXPL(Process Explorer) ^[strings.txt:43]
No debugger detection, no API hashing, no control-flow obfuscation. Low sophistication anti-analysis consistent with commodity MaaS builder output.
Decompiled Behavior
Entry point (main @ 0x00407452) ^[r2:main@0x00407452]:
- Constructs
std::basic_stringobjects for registry paths (Software\,Remcos_Mutex_Inj,ProductName, etc.). - Opens mutex; if absent, creates it and proceeds.
- Queries
SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductNameto determine Windows version, appending(32 bit)or(64 bit). - Reads RCData SETTINGS via
FindResourceA/LoadResource/LockResource(wrapper at0x00407c53). - Calls install routine (
fcn.0040650d) which builds and executes%TEMP%\install.bat. - Spawns C2 thread and enters tray-icon message loop.
Tray-icon thread (fcn.0040f8bf) ^[r2:fcn.0040f8bf]:
- Calls
ExtractIconAon its own module. - Builds
NOTIFYICONDATAAwith tooltipRemcosand icon handle. - Calls
Shell_NotifyIconA(NIM_ADD, ...). - Standard
GetMessageA→TranslateMessage→DispatchMessageApump.
Install routine (fcn.0040650d) ^[r2:fcn.0040650d]:
- Concatenates batch commands using
std::basic_stringoperators. - Writes to
%TEMP%\install.batviastd::basic_ofstream. - Contents:
PING 127.0.0.1 -n 2,del %0,start "" <copied_path>,exit. - Executes via
ShellExecuteA(NULL, "open", <bat_path>, NULL, NULL, SW_HIDE). - Calls
MSVCRT.dll_exit— original process terminates after staging.
C2 Infrastructure
- Protocol: Raw TCP (Berkeley sockets) with
[DataStart]framing ^[strings.txt:59-60] ^[pefile.txt]. - Fallback: HTTP(S) via
WININET.dll(InternetOpenUrlA,InternetReadFile) andurlmon.dll(URLDownloadToFileA) for payload updates ^[pefile.txt]. - Configuration: Encrypted inside 480-byte
SETTINGSRCData resource (entropy 7.55) — C2 host, port, mutex name, install path, and feature flags are builder-configured and stored here. Static extraction without builder key is not feasible. - No hardcoded C2 strings recovered in plaintext.
Interesting Tidbits
- Largest SETTINGS blob among early siblings: At 480 bytes, this exceeds the 245–300 byte typical of 2016-era Remcos builds, though later siblings (
39848daa) reached 803 bytes. Growth tracks builder feature expansion. - No VS_VERSIONINFO: Most Remcos samples carry a blank or cloned VS_VERSIONINFO block for masquerade. This sample lacks the resource entirely, suggesting a builder config toggle or stripped template.
- Generic filename:
Backdoor.exewith no double-extension or document masquerade. Likely a post-build rename or direct builder output before distribution repackaging. - Heavy STL usage: Builder emits C++ source compiled against MSVCP60.dll, using
std::basic_string,std::basic_ofstream,std::basic_fstream, andstd::basic_ifstreamfor all string and file operations. This bloats the binary and leaves abundant mangled-symbol artefacts. - Process-hollowing imports present:
NtUnmapViewOfSection,VirtualAllocEx,WriteProcessMemory,SetThreadContext,ResumeThread^[pefile.txt]. Not all Remcos siblings carry the full hollowing set; this one does.
How To Mess With It (Homelab Replication)
Toolchain: Visual C++ 6.0 (or VS 2005 with Platform Toolset v60) + MSVCP60.dll runtime. Target Win32 GUI, /MT static CRT link if you want to avoid MSVCP60 dependency.
Reproduction steps:
- Build a Win32 GUI EXE in C++ using
std::basic_stringfor all path manipulation. - Embed an encrypted config blob as RCData type
SETTINGS. - Implement mutex check (
CreateMutexA/OpenMutexA) with nameRemcos_Mutex_Inj. - Build an install BAT via
std::ofstreamto%TEMP%\install.batusing the exact template observed:PING 127.0.0.1 -n 2,del %0,start "" <path>,exit. - Add tray-icon loop with
Shell_NotifyIconAandExtractIconA. - Import
WS2_32.dllfor raw TCP,WININET.dllfor HTTP fallback,GDIPlus.dllfor screenshots,WINMM.dllfor mic capture.
Verification: Run strings repro.exe | grep -i remcos — should hit Remcos, Remcos_Mutex_Inj, REMCOS v, and Breaking-Security.Net.
Deployable Signatures
YARA Rule
rule remcos_v1_7_pro_cluster
{
meta:
description = "Remcos v1.7 Pro cluster — Jan 2017 build, MSVCP60, SETTINGS RCData"
author = "pp-hermes"
date = "2026-08-24"
sha256 = "d9950b1564b0d38cbaec507c8e1cdc41df08d8a638e5f050ff71cb5ceed84867"
strings:
$a1 = "Remcos_Mutex_Inj" ascii wide
$a2 = "Breaking-Security.Net" ascii wide
$a3 = "REMCOS v" ascii wide
$a4 = "1.7 Pro" ascii wide
$a5 = "[DataStart]" ascii wide
$a6 = "eventvwr.exe" ascii wide
$a7 = "Software\\Classes\\mscfile\\shell\\open\\command" ascii wide
$b1 = "Settings" ascii wide
$b2 = "origmsc" ascii wide
$c1 = "initcamcap" ascii wide
$c2 = "waveInOpen" ascii
$c3 = "GdipSaveImageToFile" ascii
$c4 = "URLDownloadToFileA" ascii
condition:
uint16(0) == 0x5A4D and
pe.number_of_sections == 4 and
pe.imports("MSVCP60.dll") and
4 of ($a*) and
2 of ($b*) and
2 of ($c*)
}
Behavioral Hunt Query (Sigma-like)
title: Remcos Installation BAT Execution
logsource:
product: windows
category: process_creation
detection:
selection_install:
CommandLine|contains:
- 'install.bat'
- 'PING 127.0.0.1 -n 2'
- 'del %0'
selection_persistence:
- CommandLine|contains: 'Software\Microsoft\Windows\CurrentVersion\Run'
- CommandLine|contains: 'Winlogon\Userinit'
- CommandLine|contains: 'Policies\Explorer\Run'
selection_uac:
- CommandLine|contains: 'eventvwr.exe'
- CommandLine|contains: 'mscfile\shell\open\command'
selection_mutex:
- CommandLine|contains: 'Remcos_Mutex_Inj'
condition: 1 of selection_*
falsepositives:
- Unlikely
level: high
IOC List
| Type | Value | Note |
|---|---|---|
| Mutex | Remcos_Mutex_Inj |
Singleton check ^[strings.txt:168] |
| Filename | Backdoor.exe |
This sample; often renamed in the wild ^[metadata.json] |
| Registry (UAC) | HKCU\Software\Classes\mscfile\shell\open\command |
eventvwr hijack ^[strings.txt:67] |
| Registry (persist) | HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ |
Standard Run key ^[strings.txt:144] |
| Registry (persist) | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit |
Userinit hijack ^[strings.txt:142] |
| File path | %TEMP%\install.bat |
Staged install script ^[r2:fcn.0040650d] |
| File path | %TEMP%\uninstall.bat |
Removal script ^[strings.txt:153] |
| File path | %TEMP%\update.bat |
Update script ^[strings.txt:157] |
| Resource | RCData SETTINGS |
Encrypted config blob, 480 bytes in this sample |
| API | SetWindowsHookExA |
Keylogging ^[pefile.txt] |
| API | NtUnmapViewOfSection |
Process hollowing preparation ^[pefile.txt] |
Behavioral Fingerprint
This PE32 GUI binary imports MSVCP60.dll and uses C++ STL strings for all path and registry manipulation. It creates a mutex named Remcos_Mutex_Inj, reads an RCData resource named SETTINGS, writes a batch file to %TEMP%\install.bat containing PING 127.0.0.1 -n 2 and del %0, executes it via ShellExecuteA, then enters a tray-icon message loop. Concurrently it opens raw TCP sockets via WS2_32 for C2 framed with [DataStart]. Browser credential harvesting targets Chrome, Firefox, and IE storage paths. Sandbox evasion is limited to string checks for Sandboxie, VirtualBox, Process Monitor, and Process Explorer.
Detection Signatures (ATT&CK Mapping)
| Technique | ID | Evidence |
|---|---|---|
| Registry Run Keys / Startup Folder | T1547.001 | Software\Microsoft\Windows\CurrentVersion\Run\ ^[strings.txt:144] |
| Winlogon Helper DLL | T1547.004 | Winlogon\Userinit hijack ^[strings.txt:142] |
| Bypass User Account Control | T1548.002 | eventvwr + mscfile handler ^[strings.txt:66-69] |
| Input Capture: Keylogging | T1056.001 | SetWindowsHookExA, key labels ^[strings.txt:79-112] |
| Input Capture: Clipboard Data | T1056.002 | OpenClipboard, GetClipboardData ^[strings.txt:106-113] |
| Screen Capture | T1113 | GDIPlus GdipSaveImageToFile ^[pefile.txt] |
| Audio Capture | T1123 | WINMM waveInOpen ^[strings.txt:568-574] |
| Video Capture | T1125 | initcamcap, OpenCamera ^[strings.txt:51-58] |
| Process Discovery | T1057 | CreateToolhelp32Snapshot ^[pefile.txt] |
| Browser Information Discovery | T1217 | Chrome/Firefox/IE credential paths ^[strings.txt:117-132] |
| Data from Local System | T1005 | File manager upload/download ^[strings.txt:256-271] |
| Application Layer Protocol: Web Protocols | T1071.001 | Raw TCP with [DataStart] framing ^[strings.txt:59-60] |
| Ingress Tool Transfer | T1105 | URLDownloadToFileA, InternetOpenUrlA ^[pefile.txt] |
| Windows Command Shell | T1059.003 | cmdoutput, execcom, consolecmd ^[strings.txt:245-247] |
| Obfuscated Files or Information | T1027 | Encrypted RCData SETTINGS blob (entropy 7.55) |
References
- Artifact ID:
c03d0f6f-b382-444b-94f2-06b5aa50543b - Source: OpenCTI / MalwareBazaar
- Related wiki: remcos — cluster entity page with shared build/TTP analysis
- Sibling analyses:
0f723826,4818d00f,6114904c,39848daa
Provenance
- Static triage run 2026-05-29:
file,exiftool,pefile,strings,ssdeep,tlsh,yara. floss.txtandcapa.txtnot usable — floss argument error, capa signatures missing.- radare2 analysis 2026-08-24:
rabin2 -I,r2withaaa(level 3), decompilation ofmain,fcn.0040f8bf,fcn.0040650d. - No dynamic analysis — CAPE skipped (no Windows guest available).