What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
A phishing campaign reported by Fortinet in November 2024 used a malicious Excel attachment and the long-known CVE-2017-0199 vulnerability to deliver Remcos, a remote-administration tool abused as a remote-access trojan (RAT). The attack combined script obfuscation, PowerShell, process hollowing and registry persistence, then ran its Remcos payload in memory. This was not a newly discovered Microsoft zero-day, and the 2024 report does not establish that the same campaign infrastructure is active today.
What happened in the Remcos campaign?
Fortinet described a business-order-themed phishing email carrying a malicious Excel document. The observed targets were Windows users; the evidence does not justify saying that all Microsoft 365 customers, all Microsoft users or a particular industry was affected. The risk centered on opening the attachment on a system with vulnerable Office/WordPad parsing components.
Remcos is commercially sold as remote-administration software. Its capabilities can be used legitimately, but in this incident attackers used it as a RAT to register infected systems with command-and-control (C2) infrastructure and potentially control them remotely. Fortinet’s technical analysis, published in 2024, is the primary source for the chain and indicators below: Fortinet’s campaign analysis. Dark Reading reported the campaign on November 11, 2024: Dark Reading’s coverage.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchHow the infection chain worked
- A victim received an order-themed email with an Excel attachment.
- Opening the document activated an embedded OLE object that abused CVE-2017-0199, a remote-code-execution flaw involving how Microsoft Office and WordPad parse specially crafted files.
- Excel retrieved an HTA file, which was launched through
mshta.exe. - JavaScript, VBScript, Base64 and URL-encoding layers obscured subsequent commands, including PowerShell execution.
- A file named
dllhost.exewas downloaded to%AppData%. The loader extracted additional files and invoked 32-bit PowerShell. - Obfuscated code decrypted and injected malicious code. Process hollowing then created or repurposed a process named
Vaccinerende.exe. - The malware established registry-based persistence and downloaded an encrypted Remcos payload.
- The Remcos payload was decrypted and executed in memory, then the infected host registered with C2 and awaited commands.
In short: phishing email → Excel/OLE → CVE-2017-0199 → mshta.exe → scripts and PowerShell → process hollowing → registry persistence → in-memory Remcos → C2.
#1 Best Overall
- Designed for Your Windows and Apple Devices | Install premium Office apps on your Windows laptop, desktop, MacBook or iMac. Works seamlessly across your devices for home, school, or personal productivity.
- Includes Word, Excel, PowerPoint & Outlook | Get premium versions of the essential Office apps that help you work, study, create, and stay organized.
- 1 TB Secure Cloud Storage | Store and access your documents, photos, and files from your Windows, Mac or mobile devices.
- Premium Tools Across Your Devices | Your subscription lets you work across all of your Windows, Mac, iPhone, iPad, and Android devices with apps that sync instantly through the cloud.
- Easy Digital Download with Microsoft Account | Product delivered electronically for quick setup. Sign in with your Microsoft account, redeem your code, and download your apps instantly to your Windows, Mac, iPhone, iPad, and Android devices.
CVE-2017-0199 is an old vulnerability, not a zero-day newly discovered for this operation. Patching vulnerable Office and Windows installations closes this exploit path, but does not stop phishing or every other way attackers may deliver a RAT.
Why analysis and detection were difficult
Fortinet documented several layers intended to frustrate inspection: multiple scripting languages and encodings, heavily obfuscated PowerShell, reliance on 32-bit PowerShell, dynamic API resolution using hashes, and checks for debuggers and debug ports. The sample also used a vectored exception handler, attempted to hide a thread from debuggers with ZwSetInformationThread(), queried process debugging state with ZwQueryInformationProcess(), constructed constants at runtime, and used API-hooking and breakpoint-disruption techniques. Process hollowing and memory execution further complicated ordinary file-based analysis.
Rank #2
Calling the final stage “fileless” needs qualification. The Remcos payload ran from memory rather than being saved as a conventional payload, but the earlier stages created and extracted files, wrote registry persistence, launched processes and generated network traffic. Those are useful investigation opportunities. Fileless does not mean traceless or undetectable.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →What an infected host could expose
The reported sample and configuration supported host and operating-system discovery, process enumeration, collection of user and privilege information, keylogging, screenshots, audio recording, browser-login or credential-related access, remote command-and-control, and further payload or data-transfer activity. These are capabilities available in the sample’s command handling; they should not be read as proof that every action occurred on every victim.
Historical indicators of compromise
The following are campaign-specific indicators reported in Fortinet’s analysis. They are historical hunting leads, not evidence that these URLs or infrastructure are active in 2026. Filenames and addresses are defanged for safe handling. Search for behavioral context as well as exact matches.
URLs and C2
hxxps://og1[.]in/2Rxzb3hxxp://192[.]3[.]220[.]22/xampp/en/cookienetbookinetcahce[.]htahxxp://192[.]3[.]220[.]22/430/dllhost[.]exehxxp://192[.]3[.]220[.]22/hFXELFSwRHRwqbE214[.]bin- C2:
107[.]173[.]4[.]16:2404
SHA-256 hashes
- Excel file:
4A670E3D4B8481CED88C74458FEC448A0FE40064AB2B1B00A289AB504015E944 - HTA file:
F99757C98007DA241258AE12EC0FD5083F0475A993CA6309811263AAD17D4661 dllhost.exe/Vaccinerende.exe:9124D7696D2B94E7959933C3F7A8F68E61A5CE29CD5934A4D0379C2193B126BEAerognosy.Res:D4D98FDBE306D61986BED62340744554E0A288C5A804ED5C924F66885CBF3514Valvulate.Cru:F9B744D0223EFE3C01C94D526881A95523C2F5E457F03774DD1D661944E60852- Decrypted Remcos payload:
24A4EBF1DE71F332F38DE69BAF2DA3019A87D45129411AD4F7D3EA48F506119D
Files, registry locations and detections
- Reported paths included
%AppData%dllhost.exe, a copied executable namedVaccinerende.exe, and extracted files in a deceptively or randomly named%AppData%subdirectory. - Persistence used a Run key under
HKCUSoftwareMicrosoftWindowsCurrentVersionRun. PowerShell content was also stored underHKCU:SoftwareRoscoelite. - These names and locations are sample-specific, not universal Remcos signatures.
dllhost.exeis also a legitimate Windows filename; its location, signature, parent process, command line, timing and behavior matter. - Fortinet detection names included
MSExcel/CVE-2017-0199.REM!exploit,JS/Remcos.CB!tr.dldr,PowerShell/Remcos.SER!tr,Data/Remcos.LAV!trandW32/Remcos.LD!tr.
What defenders should hunt for
Behavioral relationships are generally more durable than this campaign’s hashes, filenames or C2 address. Useful signals include:
Rank #4
- Excel or another Office application launching
mshta.exe, PowerShell,cmd.exeorreg.exe. - 32-bit PowerShell launched by an unusual parent process, especially when it runs encoded or obfuscated commands.
- An executable created in
%AppData%or%Temp%and run shortly afterward, including a system-like name such asdllhost.exe. - A new or unusual per-user Run-key entry, particularly alongside suspicious script or process activity.
- Process-hollowing behavior: a process created suspended, followed by suspicious memory allocation or section mapping, thread-context changes and thread resumption.
- Executable memory regions that do not correspond to an expected on-disk image, or suspicious code mapped into PowerShell or a newly created process.
- Outbound requests from Office, PowerShell or an unexpected user-writable-directory executable, especially after a document is opened. The historical sample retrieved HTA, executable and
.bincontent and used a high-numbered C2 port. - Untrusted processes accessing browser data or creating keylogger-related artifacts.
For a SIEM or EDR hunt, correlate these events by host and time: Office document opened; Office starts mshta.exe or PowerShell; script downloads or creates content in a user-writable directory; that content executes; registry Run persistence or hollowing-like memory behavior follows; then the process makes an unusual outbound connection. A single matching filename or network indicator is weaker evidence than that sequence.
Prevention: patch, filter and monitor
- Patch Windows and Office. Inventory legacy and unsupported systems and confirm that fixes for CVE-2017-0199 are applied where relevant. Do not assume every current Microsoft 365 installation is vulnerable—or that modern systems are immune to phishing.
- Reduce risky attachment execution. Use email filtering, attachment sandboxing and content disarm/reconstruction where available. Fortinet discusses anti-spam, web filtering, IPS, antivirus, sandboxing and content-disarm controls as relevant layers in its analysis; those are vendor-described protections, not a guarantee against compromise.
- Restrict or closely monitor
mshta.exe. Pay particular attention when an Office process starts it or when it retrieves remote content. - Collect endpoint telemetry. Retain process trees and command lines, PowerShell logs, registry changes, network connections and memory-based detections so investigators can connect stages rather than rely only on signatures.
- Use application control and endpoint protection. Alert on execution from user-writable locations and suspicious process injection or hollowing. Broadly disabling PowerShell is not a complete fix: it can disrupt administration and does not stop
mshta.exe, registry persistence, process hollowing or alternate scripting paths. - Make reporting easy. Treat unexpected orders, invoices and delivery notices as untrusted until verified. Users should report suspicious messages rather than forward attachments or bypass Office warnings.
If someone opened the attachment
- Isolate the computer from the network and contact the organization’s IT or security team. Do not use it for email, banking or password changes.
- Preserve evidence where procedures allow. Security staff should capture volatile process and network state and preserve relevant email, PowerShell, registry and endpoint telemetry before removing artifacts.
- Search beyond the first machine. Check for the historical indicators above, then identify other recipients of the same message and neighboring systems with similar process or network behavior.
- Review identity exposure. From a known-clean device, investigate suspicious sign-ins, revoke active sessions and rotate affected credentials—especially if browser credentials may have been accessible.
- Contain and recover carefully. Remove persistence only after evidence collection. If memory-resident execution, credential theft or administrative access cannot be confidently ruled out, reimage the system rather than relying on deleting a suspicious file.
- Do not rely on indicator blocks alone. Block known domains, addresses and hashes as an immediate measure, but filenames and infrastructure can change. Confirm containment through endpoint, identity and network investigation.
Is this campaign still active?
The reported operation dates to November 2024. Fortinet described it as ongoing in the context of its observation at that time; that wording is not confirmation that the same campaign or C2 infrastructure remains active in September 2026. Remcos and the underlying techniques remain relevant defensive concerns, but the historical indicators here should not be presented as a current threat alert. Organizations should use current telemetry and threat-intelligence reporting to assess present activity.
Quick Recap
Best Value
- Classic Office Apps | Includes classic desktop versions of Word, Excel, PowerPoint, and OneNote for creating documents, spreadsheets, and presentations with ease.
- Install on a Single Device | Install classic desktop Office Apps for use on a single Windows laptop, Windows desktop, MacBook, or iMac.
- Ideal for One Person | With a one-time purchase of Microsoft Office 2024, you can create, organize, and get things done.
- Consider Upgrading to Microsoft 365 | Get premium benefits with a Microsoft 365 subscription, including ongoing updates, advanced security, and access to premium versions of Word, Excel, PowerPoint, Outlook, and more, plus 1TB cloud storage per person and multi-device support for Windows, Mac, iPhone, iPad, and Android.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

