0600f397e12f8eee94623728448eb6a39d3720ca9fed34499715caed8a42f481connectwise: 0600f397 — Eleventh confirmed MSI-bundle sibling, C2 178.16.55.11:8041
Executive Summary
Eleventh confirmed sibling of the ConnectWise ScreenConnect MSI-bundle Variant A cluster (Nov 2022 build). Identical compile timestamp, PDB path, ProductCode, and WiX MSI tables to the ten prior siblings; ssdeep similarity 99 against the canonical sample 7145e8. The only delta is the hardcoded C2 endpoint, swapped to 178.16.55.11:8041 — the sixth distinct IP observed in this cluster. Valid Authenticode by ConnectWise, LLC (DigiCert) with a 2024 timestamp counter-signature. Static-only analysis (CAPE skipped — no Windows guest).
What It Is
- Format: PE32 executable (GUI), Intel 80386, 5 sections ^[file.txt]
- Size: 5,641,496 bytes
- Compile time: Fri Nov 18 20:10:20 2022 UTC ^[pefile.txt:34]
- Linker: MSVC 14.33 (Visual Studio 2019/2022, linker 14.33) ^[exiftool.json:18]
- PDB path:
C:\Users\jmorgan\Source\cwcontrol\Custom\DotNetRunner\Release\DotNetRunner.pdb^[strings.txt:125] ^[rabin2-info.txt:13] - Language: C/C++ native wrapper bootstrapping embedded .NET 2.0 assemblies (CIL runtime loaded via
mscoree!CorBindToRuntimeEx) ^[rabin2-info.txt:19] ^[pefile.txt:239] - Signed: Valid Authenticode signature by ConnectWise, LLC (C=US, ST=Florida, L=Tampa), issued by DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1. Timestamp counter-signature via DigiCert Timestamp 2024. ^[openssl-pkcs7-extraction]
- Subsystem: Windows GUI ^[rabin2-info.txt:34]
- Guard flags:
/DYNAMICBASE,/NXCOMPAT, Terminal Server aware; no CFG ^[pefile.txt:73] - No packing, no obfuscation, no anti-debug, no VM checks. Evasion is the signature itself.
- Static analysis tools: capa failed (missing signatures installation); floss failed (argument parsing error). ^[capa.txt] ^[floss.txt]
OpenCTI labels: connectwise, exe, urlhaus ^[triage.json:7-11].
How It Works
Stage 1 — Native C++ Bootstrap (DotNetRunner)
entry0 is standard MSVC CRT startup (security-cookie init, TLS callback dispatch) that calls main. The wrapper loads mscoree.dll, resolves CorBindToRuntimeEx to spin up CLR 2.0, then enumerates named resources in .rsrc and loads the embedded assemblies reflectively. ^[pefile.txt:239] ^[rabin2-list_imports]
Stage 2 — Embedded .NET Assemblies in .rsrc
The .rsrc section (5.4 MB, entropy 7.45) contains five named resource entries identical in structure to prior siblings:
| Resource Name | Offset | Size | Content |
|---|---|---|---|
SCREENCONNECT.CORE |
0x163D4 | 0x86800 | Core assembly ^[pefile.txt:354] |
SCREENCONNECT.WINDOWS |
0x9CBD4 | 0x1A6200 | Windows-specific assembly ^[pefile.txt:374] |
SCREENCONNECT.WINDOWSINSTALLER |
0x242DD4 | 0x1AC00 | MSI installer logic ^[pefile.txt:394] |
_ENTRYPOINT |
0x25D9D4 | 0x2EE318 | Bootstrap / resolver (largest blob) ^[pefile.txt:414] |
_RESOLVER |
0x54BCEC | 0x1600 | Config resolver ^[pefile.txt:434] |
Stage 3 — MSI Bundle + Service/Credential Provider Registration
The _ENTRYPOINT resource contains a WiX-generated MSI bundle (ScreenConnect.ScreenConnect.ClientSetup.msi) with standard MSI tables (Component, Feature, File, Registry, ServiceInstall, ServiceControl, CustomAction). ^[strings.txt:20275-20276] The installer:
- Drops files to
ProgramFilesFolderunder a GUID-derived directory. - Registers a Windows service (
[SERVICE_NAME]) withSafeBoot\Networkpersistence. ^[strings.txt:20276] - Registers an LSA Authentication Package (
ScreenConnect.WindowsAuthenticationPackage.dll). ^[strings.txt:20276] - Registers a Windows Credential Provider (
ScreenConnect.WindowsCredentialProvider.dll). ^[strings.txt:20276] - Sets URL protocol handler for
[URL_SCHEME]pointing toScreenConnect.WindowsClient.exe. ^[strings.txt:20276]
Per-Sample Delta — C2 Endpoint
The embedded system.config (inside _ENTRYPOINT / MSI tables) contains the C2 launch parameter:
?h=178.16.55.11&p=8041&k=BgIAAACkAABSU0ExAAgAAAEAAQB9Vyq7qCynGBufrhEpRlDFQCwhP2UMdMI7s9oQbORSn3VtmpQvCs9gEg1%2bzQx5c9rKMXfQjrdLlQXA9abqVUaAqTlUWdIu6gOcniJtX8d68UID9P71iGJ7jM7x2Pr9ZRboGQt3Iw1m5d8Pp8ly7woXL46C%2fI8ANRLIhgKGYYzL0CZsJ4s1hxVI154%2bnQ3FIuOwGt6a15Z1IHcgNpve0z3NJPKIyWhVKuw5sx9baI%2fsB%2fVIR9sm%2fIT6He%2bbXdsTC87T1OTUCUecqh3bU6%2b6vWERCvkHpJLR%2bxp50fauwBA2a9bTyc0bZoRVNj8D52jOKprr2pX1FQq136Kawe5rownp
This is a Base64-encoded RSA public key (BgIAAACkAABSU0ExAAgAAAEAAQ...) paired with the C2 host/port. The same key structure is reused across all siblings; only the IP changes.
Decompiled Behavior
Radare2 analysis completed at level 2 (478 functions). The entry0 decompilation shows standard MSVC CRT startup (__security_init_cookie, TLS callback dispatch, main call at 0x401140) followed by mscoree.dll load and CorBindToRuntimeEx invocation. No novel control-flow patterns; behavior is entirely delegated to the embedded .NET assemblies. No Ghidra decompilation was performed (radare2 pdc output is standard CRT bootstrap and resource enumeration). The .rsrc blobs are opaque CIL / MSI binary data not meaningfully decompilable without .NET runtime reconstruction.
C2 Infrastructure
- C2 IP:
178.16.55.11^[strings.txt:20621] - C2 Port:
8041^[strings.txt:20621] - Protocol: HTTP (implied by ScreenConnect client internal launcher parameter format)
- Public key: RSA key embedded in
system.configClientLaunchParametersConstraintvalue ^[strings.txt:20621]
No DNS names, no fallback IPs, no hardcoded URLs beyond the ScreenConnect launcher parameter.
Interesting Tidbits
- Sixth distinct C2 IP in Variant A cluster. Prior IPs:
134.122.4.2,104.236.198.16,45.83.31.225,84.54.33.84,193.26.115.231. This sample brings the total to six. ^[entities/connectwise.md] - 2024 timestamp counter-signature on a Nov 2022 build. Same pattern as sibling
aa116a62, reinforcing the hypothesis of delayed re-signing of stockpiled builds. ^[openssl-pkcs7-extraction] - Identical ProductCode
{B292C5EA-BF5F-4280-B056-1670FB10BB1D}and UpgradeCode{20AB6B9A-CF56-446C-A5AB-99B56F58BAFF}across all eleven siblings. The builder does not regenerate GUIDs per build. ^[strings.txt:20276] - WiX toolchain artefacts (
WixBroadcastSettingChange,WixCloseApplications,WixInternetShortcut) confirm the MSI bundle was built with WiX Toolset v3.x. ^[strings.txt:19119-19233] - No anti-analysis whatsoever. No debugger checks, no VM detection, no obfuscation. The threat model relies entirely on the valid Authenticode certificate and the legitimate software appearance. ^[triage.json]
How To Mess With It (Homelab Replication)
Not recommended. This sample is a signed installer for a legitimate remote-access platform. Replicating it requires:
- A valid ConnectWise ScreenConnect build environment (WiX v3.x, Visual Studio 2019/2022, .NET Framework 2.0/4.x).
- A code-signing certificate (self-signed will not replicate the SmartScreen bypass; stolen/fraudulent cert required for the real evasion).
- Embedding your own C2 endpoint into
system.configbefore MSI compilation.
Verification step: If you build a test MSI with WiX and embed a custom system.config, strings on the resulting PE should show your C2 IP inside an XML <value> block, and pefile should reveal the five named .rsrc entries.
What you'll learn: How legitimate installer frameworks (WiX + MSI) are abused to distribute attacker-controlled remote-access clients that bypass most signature-based detection.
Deployable Signatures
YARA rule
rule ConnectWise_ScreenConnect_MSI_Bundle_VariantA
{
meta:
description = "ConnectWise ScreenConnect MSI-bundle Variant A (Nov 2022) — DotNetRunner wrapper with embedded assemblies"
author = "PacketPursuit SOC"
date = "2026-08-11"
sha256 = "0600f397e12f8eee94623728448eb6a39d3720ca9fed34499715caed8a42f481"
family = "connectwise"
confidence = "high"
strings:
$pdb = "DotNetRunner.pdb" ascii wide
$core = "SCREENCONNECT.CORE, VERSION=" ascii wide
$windows = "SCREENCONNECT.WINDOWS, VERSION=" ascii wide
$installer = "SCREENCONNECT.WINDOWSINSTALLER, VERSION=" ascii wide
$productcode = "ProductCode{B292C5EA-BF5F-4280-B056-1670FB10BB1D}" ascii wide
$upgrade = "{20AB6B9A-CF56-446C-A5AB-99B56F58BAFF}" ascii wide
$wix1 = "WixBroadcastSettingChange" ascii wide
$wix2 = "WixCloseApplications" ascii wide
$c2_param = "ClientLaunchParametersConstraint" ascii wide
$auth_pkg = "ScreenConnect.WindowsAuthenticationPackage.dll" ascii wide
$cred_prov = "ScreenConnect.WindowsCredentialProvider.dll" ascii wide
condition:
uint16(0) == 0x5A4D and
($pdb or $productcode or $upgrade) and
3 of ($core, $windows, $installer, $auth_pkg, $cred_prov) and
any of ($wix*)
}
Behavioral hunt query (Sigma-like pseudocode)
title: ConnectWise ScreenConnect Malicious MSI Installer Execution
description: Detects execution of the DotNetRunner-wrapped ScreenConnect MSI bundle with embedded LSA auth package and credential provider registration.
logsource:
category: process_creation
product: windows
detection:
selection_pe:
- Image|endswith: 'ScreenConnect.ClientInstallerRunner.exe'
- CommandLine|contains:
- 'DotNetRunner'
- 'ScreenConnect.WindowsAuthenticationPackage.dll'
- 'ScreenConnect.WindowsCredentialProvider.dll'
selection_registry:
- EventType: SetValue
- TargetObject|contains:
- 'SYSTEM\\CurrentControlSet\\Control\\Lsa\\Authentication Packages'
- 'Authentication\\Credential Providers\\'
- 'SafeBoot\\Network\\ScreenConnect'
selection_service:
- EventType: CreateService
- ServiceName|contains: 'ScreenConnect'
condition: 1 of selection_*
falsepositives:
- Legitimate ConnectWise ScreenConnect enterprise deployments (verify C2 IP against known-good inventory).
level: high
IOC list
| Indicator | Value | Notes |
|---|---|---|
| SHA-256 | 0600f397e12f8eee94623728448eb6a39d3720ca9fed34499715caed8a42f481 |
This sample |
| ssdeep | 98304:KzIus6efPUIdoaxcp8wy5c3trGOlkQ5DUOgJ9zl:KhfefPtHxcp9ym3nltDUJV |
99 similarity to 7145e8 |
| Compile time | 2022-11-18 20:10:20 UTC |
Cluster timestamp |
| PDB path | C:\Users\jmorgan\Source\cwcontrol\Custom\DotNetRunner\Release\DotNetRunner.pdb |
Cluster artefact |
| ProductCode | {B292C5EA-BF5F-4280-B056-1670FB10BB1D} |
Identical across all siblings |
| UpgradeCode | {20AB6B9A-CF56-446C-A5AB-99B56F58BAFF} |
Identical across all siblings |
| C2 IP | 178.16.55.11 |
New for this sibling |
| C2 Port | 8041 |
Consistent across cluster |
| Signer | ConnectWise, LLC (DigiCert chain) |
Valid Authenticode |
| Registry — SafeBoot | SYSTEM\CurrentControlSet\Control\SafeBoot\Network\[SERVICE_NAME] |
Service persistence |
| Registry — LSA | SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages → ScreenConnect.WindowsAuthenticationPackage.dll |
Credential dumping prep |
| Registry — Credential Provider | Software\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\[CREDENTIAL_PROVIDER_CLASS_ID] |
Logon capture |
| Dropped files | ScreenConnect.WindowsClient.exe, ScreenConnect.ClientService.exe, ScreenConnect.WindowsBackstageShell.exe, ScreenConnect.WindowsFileManager.exe |
Standard ScreenConnect client suite |
Behavioral fingerprint
This binary is a 5.4–5.6 MB PE32 GUI executable with a valid ConnectWise, LLC Authenticode signature. On execution, it loads mscoree.dll and calls CorBindToRuntimeEx to bootstrap the CLR, then loads five named .rsrc entries (SCREENCONNECT.CORE, SCREENCONNECT.WINDOWS, SCREENCONNECT.WINDOWSINSTALLER, _ENTRYPOINT, _RESOLVER). The _ENTRYPOINT blob contains a WiX-generated MSI that installs a Windows service with SafeBoot persistence, registers an LSA Authentication Package DLL, and registers a Windows Credential Provider DLL. All six observed variants share the same compile timestamp (Nov 18 2022 20:10:20 UTC), ProductCode, and UpgradeCode; the only per-build variance is the hardcoded C2 IP inside system.config.
Detection Signatures
| Technique | MITRE ID | Evidence |
|---|---|---|
| Install root / publisher certificate | T1553.004 | Certificate present in .rsrc security directory ^[rabin2-info.txt:29] |
| Remote access software abuse | T1219 | Hard-coded ScreenConnect C2 endpoint in embedded config ^[strings.txt:20621] |
| Ingress tool transfer | T1105 | Embedded MSI with Cabinet archives installing ScreenConnect from .rsrc ^[binwalk.txt:23-25] |
| Create or Modify System Process (Windows Service) | T1543.003 | MSI ServiceInstall table + SafeBoot\Network persistence ^[strings.txt:20276] |
| OS Credential Dumping: LSASS Memory | T1003.001 | LSA Authentication Package registration ^[strings.txt:20276] |
| Input Capture: Credential API Hooking | T1056.001 | Windows Credential Provider DLL ^[strings.txt:20276] |
| Boot or Logon Autostart Execution | T1547.012 | Credential provider registration at install time ^[strings.txt:20276] |
| Valid Accounts (code-signing abuse) | T1078 | Authenticode by ConnectWise, LLC ^[rabin2-info.txt:29] |
| User execution | T1204.002 | Malicious signed installer execution ^[triage.json] |
References
- Artifact ID:
4e0d1d1b-3cf1-4df7-a991-c179df563e47(OpenCTI) - Source: OpenCTI / abuse.ch URLhaus
- Related wiki pages: connectwise, clickonce-certificate-trust-bootstrap, legitimate-remote-access-tool-abuse
- Cluster canonical sibling:
raw/analyses/7145e829/report.md
Provenance
file.txt— file(1) 5.44exiftool.json— ExifTool 12.76pefile.txt— pefile 2023.2.7strings.txt— strings (binutils) 2.42rabin2-info.txt— radare2 5.9.2binwalk.txt— binwalk 2.3.4capa.txt— capa 7.0.0 (failed — missing signatures)floss.txt— flare-floss 2.3.0 (failed — argument parsing error)- Certificate chain extracted via OpenSSL 3.0.13 from PE
IMAGE_DIRECTORY_ENTRY_SECURITY - ssdeep comparison vs
7145e8computed with pyssdeep 3.4