Threat Database Backdoors Backdoor.MSIL.Remcos.DB

Backdoor.MSIL.Remcos.DB

By CagedTech in Backdoors

Threat Scorecard

Popularity Rank: 24,993
Threat Level: 60 % (Medium)
Infected Computers: 3
First Seen: January 17, 2025
Last Seen: August 28, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Backdoor.MSIL.Remcos.DB
Signature status: No Signature

Known Samples

MD5: e1a1b50ce38af3682c97a4d672e7cc17
SHA1: 8e837b7eb6bf167370ef235ce5e83d75bbbef5ab
SHA256: 83B2F97F8DB9A96035A3797DE910DC87E46F6CB7D0FE56B9286596A987F13212
File Size: 810.50 KB, 810496 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Company Name SuperTechSys.com
File Description WindowsFormsApp1
File Version 1.0.0.0
Internal Name VZlp.exe
Legal Copyright Copyright © SuperTechSys.com 2023
Original Filename VZlp.exe
Product Name WindowsFormsApp1
Product Version 1.0.0.0

File Traits

  • .NET
  • HighEntropy
  • x86

Block Information

Total Blocks: 246
Potentially Malicious Blocks: 22
Whitelisted Blocks: 141
Unknown Blocks: 83

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? x 0 ? 0 ? 0 x x x 0 x x 0 x x x x x 0 x x 0 0 0 0 0 0 ? 0 0 0 x 0 ? x 0 0 ? 0 x 0 0 ? x 0 ? ? ? 0 ? 0 ? 0 ? 0 0 ? 0 ? 0 0 ? 0 0 ? 0 ? ? ? 0 0 ? 0 0 ? 0 ? 0 ? 0 0 ? 0 ? 0 0 ? 0 ? 0 ? 0 0 ? 0 ? 0 ? 0 ? 0 0 ? 0 ? 0 0 ? 0 ? 0 0 ? ? ? ? 0 ? 0 0 ? 0 ? 0 0 ? 0 0 0 0 0 ? ? ? ? 0 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 0 ? ? ? 0 x 0 0 0 0 0 0 x 0 0 0 0 0 x ? 0 ? ? ? ? ? x 0 0 x 0 ? 0 0 0 ? ? 0 0 0 0 ? ? ? ? ? ? 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation