What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

A phishing campaign reported by Fortinet in November 2024 used a malicious Excel attachment and the long-known CVE-2017-0199 vulnerability to deliver Remcos, a remote-administration tool abused as a remote-access trojan (RAT). The attack combined script obfuscation, PowerShell, process hollowing and registry persistence, then ran its Remcos payload in memory. This was not a newly discovered Microsoft zero-day, and the 2024 report does not establish that the same campaign infrastructure is active today.

What happened in the Remcos campaign?

Fortinet described a business-order-themed phishing email carrying a malicious Excel document. The observed targets were Windows users; the evidence does not justify saying that all Microsoft 365 customers, all Microsoft users or a particular industry was affected. The risk centered on opening the attachment on a system with vulnerable Office/WordPad parsing components.

Remcos is commercially sold as remote-administration software. Its capabilities can be used legitimately, but in this incident attackers used it as a RAT to register infected systems with command-and-control (C2) infrastructure and potentially control them remotely. Fortinet’s technical analysis, published in 2024, is the primary source for the chain and indicators below: Fortinet’s campaign analysis. Dark Reading reported the campaign on November 11, 2024: Dark Reading’s coverage.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the infection chain worked

  1. A victim received an order-themed email with an Excel attachment.
  2. Opening the document activated an embedded OLE object that abused CVE-2017-0199, a remote-code-execution flaw involving how Microsoft Office and WordPad parse specially crafted files.
  3. Excel retrieved an HTA file, which was launched through mshta.exe.
  4. JavaScript, VBScript, Base64 and URL-encoding layers obscured subsequent commands, including PowerShell execution.
  5. A file named dllhost.exe was downloaded to %AppData%. The loader extracted additional files and invoked 32-bit PowerShell.
  6. Obfuscated code decrypted and injected malicious code. Process hollowing then created or repurposed a process named Vaccinerende.exe.
  7. The malware established registry-based persistence and downloaded an encrypted Remcos payload.
  8. The Remcos payload was decrypted and executed in memory, then the infected host registered with C2 and awaited commands.

In short: phishing email → Excel/OLE → CVE-2017-0199 → mshta.exe → scripts and PowerShell → process hollowing → registry persistence → in-memory Remcos → C2.

#1 Best Overall
Microsoft 365 Personal | 12-Month Subscription | 1 Person | Premium Office Apps: Word, Excel, PowerPoint and more | 1TB Cloud Storage | Windows Laptop or MacBook Instant Download | Activation Required
  • Designed for Your Windows and Apple Devices | Install premium Office apps on your Windows laptop, desktop, MacBook or iMac. Works seamlessly across your devices for home, school, or personal productivity.
  • Includes Word, Excel, PowerPoint & Outlook | Get premium versions of the essential Office apps that help you work, study, create, and stay organized.
  • 1 TB Secure Cloud Storage | Store and access your documents, photos, and files from your Windows, Mac or mobile devices.
  • Premium Tools Across Your Devices | Your subscription lets you work across all of your Windows, Mac, iPhone, iPad, and Android devices with apps that sync instantly through the cloud.
  • Easy Digital Download with Microsoft Account | Product delivered electronically for quick setup. Sign in with your Microsoft account, redeem your code, and download your apps instantly to your Windows, Mac, iPhone, iPad, and Android devices.

CVE-2017-0199 is an old vulnerability, not a zero-day newly discovered for this operation. Patching vulnerable Office and Windows installations closes this exploit path, but does not stop phishing or every other way attackers may deliver a RAT.

Why analysis and detection were difficult

Fortinet documented several layers intended to frustrate inspection: multiple scripting languages and encodings, heavily obfuscated PowerShell, reliance on 32-bit PowerShell, dynamic API resolution using hashes, and checks for debuggers and debug ports. The sample also used a vectored exception handler, attempted to hide a thread from debuggers with ZwSetInformationThread(), queried process debugging state with ZwQueryInformationProcess(), constructed constants at runtime, and used API-hooking and breakpoint-disruption techniques. Process hollowing and memory execution further complicated ordinary file-based analysis.

Calling the final stage “fileless” needs qualification. The Remcos payload ran from memory rather than being saved as a conventional payload, but the earlier stages created and extracted files, wrote registry persistence, launched processes and generated network traffic. Those are useful investigation opportunities. Fileless does not mean traceless or undetectable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What an infected host could expose

The reported sample and configuration supported host and operating-system discovery, process enumeration, collection of user and privilege information, keylogging, screenshots, audio recording, browser-login or credential-related access, remote command-and-control, and further payload or data-transfer activity. These are capabilities available in the sample’s command handling; they should not be read as proof that every action occurred on every victim.

Historical indicators of compromise

The following are campaign-specific indicators reported in Fortinet’s analysis. They are historical hunting leads, not evidence that these URLs or infrastructure are active in 2026. Filenames and addresses are defanged for safe handling. Search for behavioral context as well as exact matches.

URLs and C2

  • hxxps://og1[.]in/2Rxzb3
  • hxxp://192[.]3[.]220[.]22/xampp/en/cookienetbookinetcahce[.]hta
  • hxxp://192[.]3[.]220[.]22/430/dllhost[.]exe
  • hxxp://192[.]3[.]220[.]22/hFXELFSwRHRwqbE214[.]bin
  • C2: 107[.]173[.]4[.]16:2404

SHA-256 hashes

  • Excel file: 4A670E3D4B8481CED88C74458FEC448A0FE40064AB2B1B00A289AB504015E944
  • HTA file: F99757C98007DA241258AE12EC0FD5083F0475A993CA6309811263AAD17D4661
  • dllhost.exe / Vaccinerende.exe: 9124D7696D2B94E7959933C3F7A8F68E61A5CE29CD5934A4D0379C2193B126BE
  • Aerognosy.Res: D4D98FDBE306D61986BED62340744554E0A288C5A804ED5C924F66885CBF3514
  • Valvulate.Cru: F9B744D0223EFE3C01C94D526881A95523C2F5E457F03774DD1D661944E60852
  • Decrypted Remcos payload: 24A4EBF1DE71F332F38DE69BAF2DA3019A87D45129411AD4F7D3EA48F506119D

Files, registry locations and detections

  • Reported paths included %AppData%dllhost.exe, a copied executable named Vaccinerende.exe, and extracted files in a deceptively or randomly named %AppData% subdirectory.
  • Persistence used a Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. PowerShell content was also stored under HKCU:SoftwareRoscoelite.
  • These names and locations are sample-specific, not universal Remcos signatures. dllhost.exe is also a legitimate Windows filename; its location, signature, parent process, command line, timing and behavior matter.
  • Fortinet detection names included MSExcel/CVE-2017-0199.REM!exploit, JS/Remcos.CB!tr.dldr, PowerShell/Remcos.SER!tr, Data/Remcos.LAV!tr and W32/Remcos.LD!tr.

What defenders should hunt for

Behavioral relationships are generally more durable than this campaign’s hashes, filenames or C2 address. Useful signals include:

  • Excel or another Office application launching mshta.exe, PowerShell, cmd.exe or reg.exe.
  • 32-bit PowerShell launched by an unusual parent process, especially when it runs encoded or obfuscated commands.
  • An executable created in %AppData% or %Temp% and run shortly afterward, including a system-like name such as dllhost.exe.
  • A new or unusual per-user Run-key entry, particularly alongside suspicious script or process activity.
  • Process-hollowing behavior: a process created suspended, followed by suspicious memory allocation or section mapping, thread-context changes and thread resumption.
  • Executable memory regions that do not correspond to an expected on-disk image, or suspicious code mapped into PowerShell or a newly created process.
  • Outbound requests from Office, PowerShell or an unexpected user-writable-directory executable, especially after a document is opened. The historical sample retrieved HTA, executable and .bin content and used a high-numbered C2 port.
  • Untrusted processes accessing browser data or creating keylogger-related artifacts.

For a SIEM or EDR hunt, correlate these events by host and time: Office document opened; Office starts mshta.exe or PowerShell; script downloads or creates content in a user-writable directory; that content executes; registry Run persistence or hollowing-like memory behavior follows; then the process makes an unusual outbound connection. A single matching filename or network indicator is weaker evidence than that sequence.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Prevention: patch, filter and monitor

  • Patch Windows and Office. Inventory legacy and unsupported systems and confirm that fixes for CVE-2017-0199 are applied where relevant. Do not assume every current Microsoft 365 installation is vulnerable—or that modern systems are immune to phishing.
  • Reduce risky attachment execution. Use email filtering, attachment sandboxing and content disarm/reconstruction where available. Fortinet discusses anti-spam, web filtering, IPS, antivirus, sandboxing and content-disarm controls as relevant layers in its analysis; those are vendor-described protections, not a guarantee against compromise.
  • Restrict or closely monitor mshta.exe. Pay particular attention when an Office process starts it or when it retrieves remote content.
  • Collect endpoint telemetry. Retain process trees and command lines, PowerShell logs, registry changes, network connections and memory-based detections so investigators can connect stages rather than rely only on signatures.
  • Use application control and endpoint protection. Alert on execution from user-writable locations and suspicious process injection or hollowing. Broadly disabling PowerShell is not a complete fix: it can disrupt administration and does not stop mshta.exe, registry persistence, process hollowing or alternate scripting paths.
  • Make reporting easy. Treat unexpected orders, invoices and delivery notices as untrusted until verified. Users should report suspicious messages rather than forward attachments or bypass Office warnings.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

If someone opened the attachment

  1. Isolate the computer from the network and contact the organization’s IT or security team. Do not use it for email, banking or password changes.
  2. Preserve evidence where procedures allow. Security staff should capture volatile process and network state and preserve relevant email, PowerShell, registry and endpoint telemetry before removing artifacts.
  3. Search beyond the first machine. Check for the historical indicators above, then identify other recipients of the same message and neighboring systems with similar process or network behavior.
  4. Review identity exposure. From a known-clean device, investigate suspicious sign-ins, revoke active sessions and rotate affected credentials—especially if browser credentials may have been accessible.
  5. Contain and recover carefully. Remove persistence only after evidence collection. If memory-resident execution, credential theft or administrative access cannot be confidently ruled out, reimage the system rather than relying on deleting a suspicious file.
  6. Do not rely on indicator blocks alone. Block known domains, addresses and hashes as an immediate measure, but filenames and infrastructure can change. Confirm containment through endpoint, identity and network investigation.

Is this campaign still active?

The reported operation dates to November 2024. Fortinet described it as ongoing in the context of its observation at that time; that wording is not confirmation that the same campaign or C2 infrastructure remains active in September 2026. Remcos and the underlying techniques remain relevant defensive concerns, but the historical indicators here should not be presented as a current threat alert. Organizations should use current telemetry and threat-intelligence reporting to assess present activity.

Best Value
Microsoft Office Home 2024 | Classic Office Apps: Word, Excel, PowerPoint | One-Time Purchase for a single Windows laptop or Mac | Instant Download
  • Classic Office Apps | Includes classic desktop versions of Word, Excel, PowerPoint, and OneNote for creating documents, spreadsheets, and presentations with ease.
  • Install on a Single Device | Install classic desktop Office Apps for use on a single Windows laptop, Windows desktop, MacBook, or iMac.
  • Ideal for One Person | With a one-time purchase of Microsoft Office 2024, you can create, organize, and get things done.
  • Consider Upgrading to Microsoft 365 | Get premium benefits with a Microsoft 365 subscription, including ongoing updates, advanced security, and access to premium versions of Word, Excel, PowerPoint, Outlook, and more, plus 1TB cloud storage per person and multi-device support for Windows, Mac, iPhone, iPad, and Android.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.