Encrypted RCData Resource Configuration Staging
Malware stores its operational configuration (C2 endpoints, mutex names, persistence paths, feature flags) inside a PE resource of type RT_RCDATA rather than in the .data section. The blob is typically encrypted or obfuscated and decrypted at runtime via FindResourceA → LoadResource → LockResource. This hides configuration from static string scanners unless the resource is explicitly extracted.
Variants
| Variant | Family | Blob Size | Encryption | Notes |
|---|---|---|---|---|
Named SETTINGS |
remcos | 245–803 bytes | Custom (XOR-like loop) | Builder-supplied; size grows with feature count. |
Named BIN |
Various Delphi droppers | Variable | Often RC4 or simple XOR | Frequently combined with UPX packing. |
| Unnamed / ID-only | Some .NET loaders | Variable | AES or Base64 | Embedded as Manifest or RT_RCDATA to evade YARA. |
Cross-References
- remcos — commodity RAT using
SETTINGSRCData. ^[entities/remcos.md] 65d3a51a— Remcos v1.7 Pro, 406-byteSETTINGSblob. ^[/intel/analyses/65d3a51a436d55aff9c6845dfb8974ce4ee9456e4d3beb6dd2c8b3c4e9fdcd0d.html]