typeanalysisfamilyconnectwiseconfidencehighcreated2026-08-11updated2026-08-11pedotnetcompilersigningc2mitre-attckdefense-evasionpersistenceremote-access-tool-abuse
SHA-256: 0600f397e12f8eee94623728448eb6a39d3720ca9fed34499715caed8a42f481

connectwise: 0600f397 — Eleventh confirmed MSI-bundle sibling, C2 178.16.55.11:8041

Executive Summary

Eleventh confirmed sibling of the ConnectWise ScreenConnect MSI-bundle Variant A cluster (Nov 2022 build). Identical compile timestamp, PDB path, ProductCode, and WiX MSI tables to the ten prior siblings; ssdeep similarity 99 against the canonical sample 7145e8. The only delta is the hardcoded C2 endpoint, swapped to 178.16.55.11:8041 — the sixth distinct IP observed in this cluster. Valid Authenticode by ConnectWise, LLC (DigiCert) with a 2024 timestamp counter-signature. Static-only analysis (CAPE skipped — no Windows guest).

What It Is

  • Format: PE32 executable (GUI), Intel 80386, 5 sections ^[file.txt]
  • Size: 5,641,496 bytes
  • Compile time: Fri Nov 18 20:10:20 2022 UTC ^[pefile.txt:34]
  • Linker: MSVC 14.33 (Visual Studio 2019/2022, linker 14.33) ^[exiftool.json:18]
  • PDB path: C:\Users\jmorgan\Source\cwcontrol\Custom\DotNetRunner\Release\DotNetRunner.pdb ^[strings.txt:125] ^[rabin2-info.txt:13]
  • Language: C/C++ native wrapper bootstrapping embedded .NET 2.0 assemblies (CIL runtime loaded via mscoree!CorBindToRuntimeEx) ^[rabin2-info.txt:19] ^[pefile.txt:239]
  • Signed: Valid Authenticode signature by ConnectWise, LLC (C=US, ST=Florida, L=Tampa), issued by DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1. Timestamp counter-signature via DigiCert Timestamp 2024. ^[openssl-pkcs7-extraction]
  • Subsystem: Windows GUI ^[rabin2-info.txt:34]
  • Guard flags: /DYNAMICBASE, /NXCOMPAT, Terminal Server aware; no CFG ^[pefile.txt:73]
  • No packing, no obfuscation, no anti-debug, no VM checks. Evasion is the signature itself.
  • Static analysis tools: capa failed (missing signatures installation); floss failed (argument parsing error). ^[capa.txt] ^[floss.txt]

OpenCTI labels: connectwise, exe, urlhaus ^[triage.json:7-11].

How It Works

Stage 1 — Native C++ Bootstrap (DotNetRunner)

entry0 is standard MSVC CRT startup (security-cookie init, TLS callback dispatch) that calls main. The wrapper loads mscoree.dll, resolves CorBindToRuntimeEx to spin up CLR 2.0, then enumerates named resources in .rsrc and loads the embedded assemblies reflectively. ^[pefile.txt:239] ^[rabin2-list_imports]

Stage 2 — Embedded .NET Assemblies in .rsrc

The .rsrc section (5.4 MB, entropy 7.45) contains five named resource entries identical in structure to prior siblings:

Resource Name Offset Size Content
SCREENCONNECT.CORE 0x163D4 0x86800 Core assembly ^[pefile.txt:354]
SCREENCONNECT.WINDOWS 0x9CBD4 0x1A6200 Windows-specific assembly ^[pefile.txt:374]
SCREENCONNECT.WINDOWSINSTALLER 0x242DD4 0x1AC00 MSI installer logic ^[pefile.txt:394]
_ENTRYPOINT 0x25D9D4 0x2EE318 Bootstrap / resolver (largest blob) ^[pefile.txt:414]
_RESOLVER 0x54BCEC 0x1600 Config resolver ^[pefile.txt:434]

Stage 3 — MSI Bundle + Service/Credential Provider Registration

The _ENTRYPOINT resource contains a WiX-generated MSI bundle (ScreenConnect.ScreenConnect.ClientSetup.msi) with standard MSI tables (Component, Feature, File, Registry, ServiceInstall, ServiceControl, CustomAction). ^[strings.txt:20275-20276] The installer:

  1. Drops files to ProgramFilesFolder under a GUID-derived directory.
  2. Registers a Windows service ([SERVICE_NAME]) with SafeBoot\Network persistence. ^[strings.txt:20276]
  3. Registers an LSA Authentication Package (ScreenConnect.WindowsAuthenticationPackage.dll). ^[strings.txt:20276]
  4. Registers a Windows Credential Provider (ScreenConnect.WindowsCredentialProvider.dll). ^[strings.txt:20276]
  5. Sets URL protocol handler for [URL_SCHEME] pointing to ScreenConnect.WindowsClient.exe. ^[strings.txt:20276]

Per-Sample Delta — C2 Endpoint

The embedded system.config (inside _ENTRYPOINT / MSI tables) contains the C2 launch parameter:

?h=178.16.55.11&p=8041&k=BgIAAACkAABSU0ExAAgAAAEAAQB9Vyq7qCynGBufrhEpRlDFQCwhP2UMdMI7s9oQbORSn3VtmpQvCs9gEg1%2bzQx5c9rKMXfQjrdLlQXA9abqVUaAqTlUWdIu6gOcniJtX8d68UID9P71iGJ7jM7x2Pr9ZRboGQt3Iw1m5d8Pp8ly7woXL46C%2fI8ANRLIhgKGYYzL0CZsJ4s1hxVI154%2bnQ3FIuOwGt6a15Z1IHcgNpve0z3NJPKIyWhVKuw5sx9baI%2fsB%2fVIR9sm%2fIT6He%2bbXdsTC87T1OTUCUecqh3bU6%2b6vWERCvkHpJLR%2bxp50fauwBA2a9bTyc0bZoRVNj8D52jOKprr2pX1FQq136Kawe5rownp

This is a Base64-encoded RSA public key (BgIAAACkAABSU0ExAAgAAAEAAQ...) paired with the C2 host/port. The same key structure is reused across all siblings; only the IP changes.

Decompiled Behavior

Radare2 analysis completed at level 2 (478 functions). The entry0 decompilation shows standard MSVC CRT startup (__security_init_cookie, TLS callback dispatch, main call at 0x401140) followed by mscoree.dll load and CorBindToRuntimeEx invocation. No novel control-flow patterns; behavior is entirely delegated to the embedded .NET assemblies. No Ghidra decompilation was performed (radare2 pdc output is standard CRT bootstrap and resource enumeration). The .rsrc blobs are opaque CIL / MSI binary data not meaningfully decompilable without .NET runtime reconstruction.

C2 Infrastructure

  • C2 IP: 178.16.55.11 ^[strings.txt:20621]
  • C2 Port: 8041 ^[strings.txt:20621]
  • Protocol: HTTP (implied by ScreenConnect client internal launcher parameter format)
  • Public key: RSA key embedded in system.config ClientLaunchParametersConstraint value ^[strings.txt:20621]

No DNS names, no fallback IPs, no hardcoded URLs beyond the ScreenConnect launcher parameter.

Interesting Tidbits

  • Sixth distinct C2 IP in Variant A cluster. Prior IPs: 134.122.4.2, 104.236.198.16, 45.83.31.225, 84.54.33.84, 193.26.115.231. This sample brings the total to six. ^[entities/connectwise.md]
  • 2024 timestamp counter-signature on a Nov 2022 build. Same pattern as sibling aa116a62, reinforcing the hypothesis of delayed re-signing of stockpiled builds. ^[openssl-pkcs7-extraction]
  • Identical ProductCode {B292C5EA-BF5F-4280-B056-1670FB10BB1D} and UpgradeCode {20AB6B9A-CF56-446C-A5AB-99B56F58BAFF} across all eleven siblings. The builder does not regenerate GUIDs per build. ^[strings.txt:20276]
  • WiX toolchain artefacts (WixBroadcastSettingChange, WixCloseApplications, WixInternetShortcut) confirm the MSI bundle was built with WiX Toolset v3.x. ^[strings.txt:19119-19233]
  • No anti-analysis whatsoever. No debugger checks, no VM detection, no obfuscation. The threat model relies entirely on the valid Authenticode certificate and the legitimate software appearance. ^[triage.json]

How To Mess With It (Homelab Replication)

Not recommended. This sample is a signed installer for a legitimate remote-access platform. Replicating it requires:

  1. A valid ConnectWise ScreenConnect build environment (WiX v3.x, Visual Studio 2019/2022, .NET Framework 2.0/4.x).
  2. A code-signing certificate (self-signed will not replicate the SmartScreen bypass; stolen/fraudulent cert required for the real evasion).
  3. Embedding your own C2 endpoint into system.config before MSI compilation.

Verification step: If you build a test MSI with WiX and embed a custom system.config, strings on the resulting PE should show your C2 IP inside an XML <value> block, and pefile should reveal the five named .rsrc entries.

What you'll learn: How legitimate installer frameworks (WiX + MSI) are abused to distribute attacker-controlled remote-access clients that bypass most signature-based detection.

Deployable Signatures

YARA rule

rule ConnectWise_ScreenConnect_MSI_Bundle_VariantA
{
    meta:
        description = "ConnectWise ScreenConnect MSI-bundle Variant A (Nov 2022) — DotNetRunner wrapper with embedded assemblies"
        author = "PacketPursuit SOC"
        date = "2026-08-11"
        sha256 = "0600f397e12f8eee94623728448eb6a39d3720ca9fed34499715caed8a42f481"
        family = "connectwise"
        confidence = "high"
    strings:
        $pdb = "DotNetRunner.pdb" ascii wide
        $core = "SCREENCONNECT.CORE, VERSION=" ascii wide
        $windows = "SCREENCONNECT.WINDOWS, VERSION=" ascii wide
        $installer = "SCREENCONNECT.WINDOWSINSTALLER, VERSION=" ascii wide
        $productcode = "ProductCode{B292C5EA-BF5F-4280-B056-1670FB10BB1D}" ascii wide
        $upgrade = "{20AB6B9A-CF56-446C-A5AB-99B56F58BAFF}" ascii wide
        $wix1 = "WixBroadcastSettingChange" ascii wide
        $wix2 = "WixCloseApplications" ascii wide
        $c2_param = "ClientLaunchParametersConstraint" ascii wide
        $auth_pkg = "ScreenConnect.WindowsAuthenticationPackage.dll" ascii wide
        $cred_prov = "ScreenConnect.WindowsCredentialProvider.dll" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        ($pdb or $productcode or $upgrade) and
        3 of ($core, $windows, $installer, $auth_pkg, $cred_prov) and
        any of ($wix*)
}

Behavioral hunt query (Sigma-like pseudocode)

title: ConnectWise ScreenConnect Malicious MSI Installer Execution
description: Detects execution of the DotNetRunner-wrapped ScreenConnect MSI bundle with embedded LSA auth package and credential provider registration.
logsource:
    category: process_creation
    product: windows
detection:
    selection_pe:
        - Image|endswith: 'ScreenConnect.ClientInstallerRunner.exe'
        - CommandLine|contains:
            - 'DotNetRunner'
            - 'ScreenConnect.WindowsAuthenticationPackage.dll'
            - 'ScreenConnect.WindowsCredentialProvider.dll'
    selection_registry:
        - EventType: SetValue
        - TargetObject|contains:
            - 'SYSTEM\\CurrentControlSet\\Control\\Lsa\\Authentication Packages'
            - 'Authentication\\Credential Providers\\'
            - 'SafeBoot\\Network\\ScreenConnect'
    selection_service:
        - EventType: CreateService
        - ServiceName|contains: 'ScreenConnect'
    condition: 1 of selection_*
falsepositives:
    - Legitimate ConnectWise ScreenConnect enterprise deployments (verify C2 IP against known-good inventory).
level: high

IOC list

Indicator Value Notes
SHA-256 0600f397e12f8eee94623728448eb6a39d3720ca9fed34499715caed8a42f481 This sample
ssdeep 98304:KzIus6efPUIdoaxcp8wy5c3trGOlkQ5DUOgJ9zl:KhfefPtHxcp9ym3nltDUJV 99 similarity to 7145e8
Compile time 2022-11-18 20:10:20 UTC Cluster timestamp
PDB path C:\Users\jmorgan\Source\cwcontrol\Custom\DotNetRunner\Release\DotNetRunner.pdb Cluster artefact
ProductCode {B292C5EA-BF5F-4280-B056-1670FB10BB1D} Identical across all siblings
UpgradeCode {20AB6B9A-CF56-446C-A5AB-99B56F58BAFF} Identical across all siblings
C2 IP 178.16.55.11 New for this sibling
C2 Port 8041 Consistent across cluster
Signer ConnectWise, LLC (DigiCert chain) Valid Authenticode
Registry — SafeBoot SYSTEM\CurrentControlSet\Control\SafeBoot\Network\[SERVICE_NAME] Service persistence
Registry — LSA SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages → ScreenConnect.WindowsAuthenticationPackage.dll Credential dumping prep
Registry — Credential Provider Software\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\[CREDENTIAL_PROVIDER_CLASS_ID] Logon capture
Dropped files ScreenConnect.WindowsClient.exe, ScreenConnect.ClientService.exe, ScreenConnect.WindowsBackstageShell.exe, ScreenConnect.WindowsFileManager.exe Standard ScreenConnect client suite

Behavioral fingerprint

This binary is a 5.4–5.6 MB PE32 GUI executable with a valid ConnectWise, LLC Authenticode signature. On execution, it loads mscoree.dll and calls CorBindToRuntimeEx to bootstrap the CLR, then loads five named .rsrc entries (SCREENCONNECT.CORE, SCREENCONNECT.WINDOWS, SCREENCONNECT.WINDOWSINSTALLER, _ENTRYPOINT, _RESOLVER). The _ENTRYPOINT blob contains a WiX-generated MSI that installs a Windows service with SafeBoot persistence, registers an LSA Authentication Package DLL, and registers a Windows Credential Provider DLL. All six observed variants share the same compile timestamp (Nov 18 2022 20:10:20 UTC), ProductCode, and UpgradeCode; the only per-build variance is the hardcoded C2 IP inside system.config.

Detection Signatures

Technique MITRE ID Evidence
Install root / publisher certificate T1553.004 Certificate present in .rsrc security directory ^[rabin2-info.txt:29]
Remote access software abuse T1219 Hard-coded ScreenConnect C2 endpoint in embedded config ^[strings.txt:20621]
Ingress tool transfer T1105 Embedded MSI with Cabinet archives installing ScreenConnect from .rsrc ^[binwalk.txt:23-25]
Create or Modify System Process (Windows Service) T1543.003 MSI ServiceInstall table + SafeBoot\Network persistence ^[strings.txt:20276]
OS Credential Dumping: LSASS Memory T1003.001 LSA Authentication Package registration ^[strings.txt:20276]
Input Capture: Credential API Hooking T1056.001 Windows Credential Provider DLL ^[strings.txt:20276]
Boot or Logon Autostart Execution T1547.012 Credential provider registration at install time ^[strings.txt:20276]
Valid Accounts (code-signing abuse) T1078 Authenticode by ConnectWise, LLC ^[rabin2-info.txt:29]
User execution T1204.002 Malicious signed installer execution ^[triage.json]

References

Provenance

  • file.txt — file(1) 5.44
  • exiftool.json — ExifTool 12.76
  • pefile.txt — pefile 2023.2.7
  • strings.txt — strings (binutils) 2.42
  • rabin2-info.txt — radare2 5.9.2
  • binwalk.txt — binwalk 2.3.4
  • capa.txt — capa 7.0.0 (failed — missing signatures)
  • floss.txt — flare-floss 2.3.0 (failed — argument parsing error)
  • Certificate chain extracted via OpenSSL 3.0.13 from PE IMAGE_DIRECTORY_ENTRY_SECURITY
  • ssdeep comparison vs 7145e8 computed with pyssdeep 3.4