604e1cc7d2a390a2d211239f4335cb0c0d80d8b9ee48c35f823a78d60e861886connectwise: 604e1cc7 — ClickOnce bootstrapper twin, cross-variant C2 IP reuse from 2022 MSI era
Executive Summary
A 305 KB MSVC-compiled PE32 ClickOnce bootstrapper, byte-for-byte twin of sibling 81adbf9a (same compile timestamp, same PDB, same import surface) but parameterized with C2 IP 45.83.31.225 — an IP first seen in the Nov 2022 MSI-bundle variant (8c8e60af). This is the first observed cross-variant IP reuse: a 2025 ClickOnce bootstrapper recycling infrastructure from the 2022 MSI-bundle era. Valid Authenticode by ConnectWise, LLC. Static-only; CAPE skipped.
What It Is
- Format: PE32 executable (GUI), Intel 80386, 5 sections ^[file.txt]
- Size: 312,584 bytes
- Compile time: Tue Apr 8 18:34:09 2025 UTC ^[pefile.txt:34]
- Linker: MSVC 14.40 (Visual Studio 2022) ^[exiftool.json:18]
- PDB path:
C:\builds\cc\cwcontrol\Product\ClickOnceRunner\Release\ClickOnceRunner.pdb^[strings.txt:308] ^[rabin2-info.txt:13] - Language: C/C++ (CRT strings, no .NET metadata) ^[rabin2-info.txt:19]
- Signed: Valid Authenticode by ConnectWise, LLC (Tampa, Florida), issued by DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 ^[strings.txt:700] ^[binwalk.txt:7]
- Certificate signing time: 2025-04-08 18:45:00Z ^[strings.txt:714]
- Guard flags: CastGuard only (
0x100); no CFG, no SafeSEH ^[pefile.txt:415] - Imports: KERNEL32.dll (CRT + loader) and CRYPT32.dll (certificate store operations) ^[pefile.txt:239-344]
- No exports, no packer, no anti-debug, no VM checks.
This sample is a cluster sibling of the ConnectWise ClickOnce bootstrapper family. Shared build fingerprint, entry-point logic, and certificate-trust bootstrap are documented at connectwise; this report covers per-sample deltas only.
How It Works
See connectwise entity page and sibling report 81adbf9a for the full certificate-trust bootstrap → ClickOnce deployment chain. ^[/intel/analyses/81adbf9af2875a3f442a6453a2e4cc637ea8642a7ddedf07134a853620daa7e6.html]
This sample executes the identical two-stage flow:
- Extracts its own Authenticode signer certificates via
CryptQueryObject+CryptMsgGetParam. - Installs them into the
TrustedPublisherstore withCertAddCertificateContextToStore. - Loads
dfshim.dll→ resolvesShOpenVerbApplicationW→ launches remote.applicationmanifest. - On any Crypt32 failure, sleeps 40 s (
0x9c40ms) and retries. ^[r2:main]
Per-sample delta — C2 infrastructure and protocol:
| Field | This sample (604e1cc7) | Sibling 81adbf9a | Sibling 8c8e60af (MSI era) |
|---|---|---|---|
| Variant | ClickOnce bootstrapper (Variant B) | ClickOnce bootstrapper (Variant B) | MSI bundle (Variant A) |
| Compile time | Apr 8 2025 18:34:09 UTC | Apr 8 2025 18:34:09 UTC | Nov 2022 |
| C2 IP | 45.83.31.225 |
134.122.4.2 |
45.83.31.225 |
| Protocol | https:// |
http:// |
http:// (MSI direct) |
| Port | 8041 |
8041 |
8041 |
| URL path | /Bin/ScreenConnect.Client.application |
/Bin/ScreenConnect.Client.application |
(embedded MSI tables) |
The C2 IP 45.83.31.225 first appeared in the Nov 2022 MSI-bundle sibling 8c8e60af. Its reappearance here, 2.5 years later in a completely different deployment morph, confirms the attacker maintains a stable IP pool across variant generations. ^[entities/connectwise.md]
Decompiled Behavior
Entry point (entry0) is standard MSVC CRT startup: initializes security cookie (GuardCFCheckFunctionPointer), runs dynamic initializers, then dispatches to main(argc, argv, envp). ^[r2:entry0]
main is structurally identical to 81adbf9a:
GetModuleFileNameW→ 260-byte path buffer.CertOpenSystemStoreA("TrustedPublisher").CryptQueryObjecton self (type=1, content=0x400).- Iterates signers:
CryptMsgGetParam(CMSG_CERT_PARAM)→CertCreateCertificateContext→CertAddCertificateContextToStore. LoadLibraryA("dfshim")→GetProcAddress("ShOpenVerbApplicationW").- Calls shim with hard-coded
.applicationURL. - Cleanup:
CertCloseStore,LocalFreeblocks. ^[r2:main]
Notable addition not emphasized in prior sibling reports: CertDeleteCertificateFromStore is imported and referenced in a post-launch cleanup loop, suggesting a touch-and-go pattern where certificates are removed from the store after the ClickOnce launch to reduce forensic residue. ^[pefile.txt:336] ^[r2:main] The exact control-flow path (success vs error cleanup) is partially obscured by decompiler limitations; treat as medium-confidence inference.
C2 Infrastructure
| Indicator | Value | Notes |
|---|---|---|
| IP | 45.83.31.225 |
Reused from Nov 2022 MSI sibling 8c8e60af |
| Port | 8041 |
Consistent across all observed siblings |
| URL | https://45.83.31.225/Bin/ScreenConnect.Client.application?h=45.83.31.225&p=8041&k=BgIAAACkAABSU0ExAAgAAAEAAQDdfG%2bpheWFyVwtAzm3scDT8Y0iE%2fDYv4M942MmxBAqKBa0oVn8IG%2fP%2b%2buQvctIUe%2foceFf4AvdbIdheIn%2f8riVJxARxCGEtiCm9%2bJ2WfUyK%2btrQTBIe2%2fbEYOK6aipUgiUIuA4zReI3XhwfzX7CWFzA00hH6b%2f26F6KE8sAF86fG%2fMeAV3OU3wNf5ofu1%2f%2fGLuVXc5IexIZqCyVyZCBKIwjVwxyO6dUcrEs1RL6%2fNJm6UbILSZGp4ZHJhadCXfqAF2i6gTRyaIWOR6%2f2SX%2b3nELJ%2b%2beCEJpXgfjeshjXPROIW42qzAR67RckoX8gmqS91wjYgPY%2byEfVBSGfFxBTO9 |
Base64-wrapped RSA key; same format as all siblings |
| Certificate CN | ConnectWise, LLC |
Valid DigiCert-issued code-signing cert |
| Certificate location | Tampa, Florida, US |
Subject locality |
Static-only; no observed DNS or secondary C2.
Interesting Tidbits
- Twin build, different parameter. Same compile timestamp as
81adbf9ato the second (Apr 8 2025 18:34:09 UTC), same PDB path, same linker version, same certificate chain. The only meaningful delta is the C2 IP and protocol prefix in the embedded URL. This is builder-level parameterization, not source-code divergence. ^[pefile.txt:34] ^[rabin2-info.txt:13] - Cross-variant IP reuse. The IP
45.83.31.225was the C2 for MSI-bundle sibling8c8e60af(Nov 2022). Seeing it again in an Apr 2025 ClickOnce bootstrapper means the attacker either (a) still controls that host, (b) reuses a hardcoded IP list in the builder, or (c) both. ^[entities/connectwise.md] - HTTPS upgrade. Unlike
81adbf9awhich used plainhttp://, this sample prefixes the C2 URL withhttps://. The change is only one character in the embedded string but has operational significance: encrypted ClickOnce manifest fetch, reduced plaintext network fingerprint. ^[r2:strings] - Touch-and-go certificate cleanup. The import of
CertDeleteCertificateFromStoreand its placement in a post-launch loop suggests the binary scrubs its own certificates fromTrustedPublisherafter dfshim takes over. If confirmed dynamically, this is a notable OPSEC refinement over the81adbf9avariant. ^[pefile.txt:336] ^[r2:main] - No Rich header. Same as all prior siblings; release build artifact. ^[pefile.txt]
- 48-byte file-size delta vs 81adbf9a. 312,584 vs 312,536 bytes. Consistent with a longer C2 URL string (
https://45.83.31.225is one character longer thanhttp://134.122.4.2).
How To Mess With It (Homelab Replication)
See the 81adbf9a sibling report for the full ClickOnce certificate-trust bootstrap replication recipe. ^[/intel/analyses/81adbf9af2875a3f442a6453a2e4cc637ea8642a7ddedf07134a853620daa7e6.html]
Per-sample verification: Compile the reproducer, sign with a self-signed cert, then run under ProcMon. Expect:
CertAddCertificateContextToStore→TrustedPublisherLoadLibrary("dfshim.dll")→GetProcAddress("ShOpenVerbApplicationW")ShOpenVerbApplicationWwithhttps://<host>/Bin/ScreenConnect.Client.application?h=<host>&p=8041&k=<key>- Optional:
CertDeleteCertificateFromStorein the cleanup path (verify with breakpoint)
Deployable Signatures
YARA rule
rule ConnectWise_ClickOnce_CertBootstrap_v2 {
meta:
description = "ClickOnce runner that extracts its own Authenticode signature, installs it into TrustedPublisher, then launches a remote ScreenConnect .application manifest via dfshim"
author = "PacketPursuit"
date = "2026-08-03"
sha256 = "604e1cc7d2a390a2d211239f4335cb0c0d80d8b9ee48c35f823a78d60e861886"
strings:
$a = "TrustedPublisher" ascii wide
$b = "ShOpenVerbApplicationW" ascii wide
$c = "dfshim" ascii wide
$d = "1.3.6.1.4.1.311.4.1.1" ascii wide
$e = /ScreenConnect\.Client\.application/ ascii wide
$f = "CertAddCertificateContextToStore" ascii wide
$g = "CertDeleteCertificateFromStore" ascii wide
condition:
uint16(0) == 0x5A4D and
5 of ($a, $b, $c, $d, $e, $f, $g)
}
Behavioral hunt query (KQL / EDR)
ProcessEvents
| where ProcessImageName endswith "ClickOnceRunner.exe"
or CommandLine contains "ScreenConnect.Client.application"
| where (ModuleLoaded == "dfshim.dll" and APICall == "ShOpenVerbApplicationW")
or (StoreName == "TrustedPublisher"
and APICall in ("CertAddCertificateContextToStore",
"CertDeleteCertificateFromStore",
"CertOpenSystemStoreA"))
| project Timestamp, Hostname, ProcessId, CommandLine, ParentProcessId
IOC list
| IOC | Value | Type |
|---|---|---|
| SHA-256 | 604e1cc7d2a390a2d211239f4335cb0c0d80d8b9ee48c35f823a78d60e861886 |
File |
| SHA-1 | 1244d19ab7a28680cacbff750c6dbac20403560b |
File |
| MD5 | abbc92f0961694019af3fc68e06fb5f5 |
File |
| IP | 45.83.31.225 |
C2 |
| URL | https://45.83.31.225/Bin/ScreenConnect.Client.application |
C2 |
| Cert Subject | CN=ConnectWise, LLC, O=ConnectWise, LLC, L=Tampa, S=Florida, C=US |
Code signing |
| Cert Issuer | CN=DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, O=DigiCert, Inc., C=US |
Code signing |
Behavioral fingerprint
This binary loads only KERNEL32.dll and CRYPT32.dll. Within 5 seconds of process start it opens the TrustedPublisher certificate store, extracts its own Authenticode signer certificates via CryptQueryObject + CryptMsgGetParam, installs them with CertAddCertificateContextToStore, then loads dfshim.dll and resolves ShOpenVerbApplicationW to launch a remote .application URL containing a hard-coded IP, port, and base64-wrapped RSA key. Post-launch cleanup may call CertDeleteCertificateFromStore to remove the added certificates. No direct socket API is imported; all HTTP/S is delegated to the ClickOnce shim.
Detection Signatures
| Capability | ATT&CK Technique | Evidence |
|---|---|---|
| Certificate trust manipulation | T1553.004 — Install Root Certificate | CertOpenSystemStoreA("TrustedPublisher"), CertAddCertificateContextToStore ^[r2:main] |
| Remote access software abuse | T1219 — Remote Access Software | Hard-coded ScreenConnect .application URL, ShOpenVerbApplicationW ^[r2:strings] |
| Application-layer C2 | T1071.001 — Application Layer Protocol: HTTP/S | Remote manifest fetch via ClickOnce (delegated to dfshim) ^[r2:strings] |
| Ingress tool transfer | T1105 — Ingress Tool Transfer | Downloads remote .application manifest and payload ^[r2:main] |
| User execution | T1204.002 — User Execution: Malicious File | ClickOnce .application execution flow ^[r2:main] |
| Indicator removal | T1070.004 — File Deletion | CertDeleteCertificateFromStore in cleanup loop (medium-confidence) ^[r2:main] ^[pefile.txt:336] |
References
- connectwise — Entity page (family overview, all siblings, build-stack documentation)
- clickonce-certificate-trust-bootstrap — Technique page for the certificate → ClickOnce deployment chain
- legitimate-remote-access-tool-abuse — Cross-family concept page
/intel/analyses/81adbf9af2875a3f442a6453a2e4cc637ea8642a7ddedf07134a853620daa7e6.html— Twin sibling (same compile time, different C2 IP)- VirusTotal / MalwareBazaar:
604e1cc7d2a390a2d211239f4335cb0c0d80d8b9ee48c35f823a78d60e861886(abuse.ch)
Provenance
file.txt—file(1)outputpefile.txt— pefile parser (headers, sections, imports, debug, load config, relocations)strings.txt—strings -n 6rabin2-info.txt— radare2 binary info (iI)r2— radare2 decompilation (pdg @ main,pdg @ entry0) and string search (izz)binwalk.txt— Embedded signature and certificate extractionexiftool.json— ExifTool metadatayara.txt— GenericPE_File_Genericmatch onlycapa.txt— Capa tool failure (signatures missing)floss.txt— FLOSS tool invocation errortriage.json— Pipeline metadata with OpenCTI family label- Tools: radare2 5.x, pefile 2023.x, ExifTool 12.76,
stringsfrom binutils