typeanalysisfamilyconnectwiseconfidencehighcreated2026-08-03updated2026-08-03pecompilersigningc2mitre-attckdefense-evasionlegitimate-remote-access-tool-abuse
SHA-256: 604e1cc7d2a390a2d211239f4335cb0c0d80d8b9ee48c35f823a78d60e861886

connectwise: 604e1cc7 — ClickOnce bootstrapper twin, cross-variant C2 IP reuse from 2022 MSI era

Executive Summary

A 305 KB MSVC-compiled PE32 ClickOnce bootstrapper, byte-for-byte twin of sibling 81adbf9a (same compile timestamp, same PDB, same import surface) but parameterized with C2 IP 45.83.31.225 — an IP first seen in the Nov 2022 MSI-bundle variant (8c8e60af). This is the first observed cross-variant IP reuse: a 2025 ClickOnce bootstrapper recycling infrastructure from the 2022 MSI-bundle era. Valid Authenticode by ConnectWise, LLC. Static-only; CAPE skipped.

What It Is

  • Format: PE32 executable (GUI), Intel 80386, 5 sections ^[file.txt]
  • Size: 312,584 bytes
  • Compile time: Tue Apr 8 18:34:09 2025 UTC ^[pefile.txt:34]
  • Linker: MSVC 14.40 (Visual Studio 2022) ^[exiftool.json:18]
  • PDB path: C:\builds\cc\cwcontrol\Product\ClickOnceRunner\Release\ClickOnceRunner.pdb ^[strings.txt:308] ^[rabin2-info.txt:13]
  • Language: C/C++ (CRT strings, no .NET metadata) ^[rabin2-info.txt:19]
  • Signed: Valid Authenticode by ConnectWise, LLC (Tampa, Florida), issued by DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 ^[strings.txt:700] ^[binwalk.txt:7]
  • Certificate signing time: 2025-04-08 18:45:00Z ^[strings.txt:714]
  • Guard flags: CastGuard only (0x100); no CFG, no SafeSEH ^[pefile.txt:415]
  • Imports: KERNEL32.dll (CRT + loader) and CRYPT32.dll (certificate store operations) ^[pefile.txt:239-344]
  • No exports, no packer, no anti-debug, no VM checks.

This sample is a cluster sibling of the ConnectWise ClickOnce bootstrapper family. Shared build fingerprint, entry-point logic, and certificate-trust bootstrap are documented at connectwise; this report covers per-sample deltas only.

How It Works

See connectwise entity page and sibling report 81adbf9a for the full certificate-trust bootstrap → ClickOnce deployment chain. ^[/intel/analyses/81adbf9af2875a3f442a6453a2e4cc637ea8642a7ddedf07134a853620daa7e6.html]

This sample executes the identical two-stage flow:

  1. Extracts its own Authenticode signer certificates via CryptQueryObject + CryptMsgGetParam.
  2. Installs them into the TrustedPublisher store with CertAddCertificateContextToStore.
  3. Loads dfshim.dll → resolves ShOpenVerbApplicationW → launches remote .application manifest.
  4. On any Crypt32 failure, sleeps 40 s (0x9c40 ms) and retries. ^[r2:main]

Per-sample delta — C2 infrastructure and protocol:

Field This sample (604e1cc7) Sibling 81adbf9a Sibling 8c8e60af (MSI era)
Variant ClickOnce bootstrapper (Variant B) ClickOnce bootstrapper (Variant B) MSI bundle (Variant A)
Compile time Apr 8 2025 18:34:09 UTC Apr 8 2025 18:34:09 UTC Nov 2022
C2 IP 45.83.31.225 134.122.4.2 45.83.31.225
Protocol https:// http:// http:// (MSI direct)
Port 8041 8041 8041
URL path /Bin/ScreenConnect.Client.application /Bin/ScreenConnect.Client.application (embedded MSI tables)

The C2 IP 45.83.31.225 first appeared in the Nov 2022 MSI-bundle sibling 8c8e60af. Its reappearance here, 2.5 years later in a completely different deployment morph, confirms the attacker maintains a stable IP pool across variant generations. ^[entities/connectwise.md]

Decompiled Behavior

Entry point (entry0) is standard MSVC CRT startup: initializes security cookie (GuardCFCheckFunctionPointer), runs dynamic initializers, then dispatches to main(argc, argv, envp). ^[r2:entry0]

main is structurally identical to 81adbf9a:

  1. GetModuleFileNameW → 260-byte path buffer.
  2. CertOpenSystemStoreA("TrustedPublisher").
  3. CryptQueryObject on self (type=1, content=0x400).
  4. Iterates signers: CryptMsgGetParam(CMSG_CERT_PARAM) → CertCreateCertificateContext → CertAddCertificateContextToStore.
  5. LoadLibraryA("dfshim") → GetProcAddress("ShOpenVerbApplicationW").
  6. Calls shim with hard-coded .application URL.
  7. Cleanup: CertCloseStore, LocalFree blocks. ^[r2:main]

Notable addition not emphasized in prior sibling reports: CertDeleteCertificateFromStore is imported and referenced in a post-launch cleanup loop, suggesting a touch-and-go pattern where certificates are removed from the store after the ClickOnce launch to reduce forensic residue. ^[pefile.txt:336] ^[r2:main] The exact control-flow path (success vs error cleanup) is partially obscured by decompiler limitations; treat as medium-confidence inference.

C2 Infrastructure

Indicator Value Notes
IP 45.83.31.225 Reused from Nov 2022 MSI sibling 8c8e60af
Port 8041 Consistent across all observed siblings
URL https://45.83.31.225/Bin/ScreenConnect.Client.application?h=45.83.31.225&p=8041&k=BgIAAACkAABSU0ExAAgAAAEAAQDdfG%2bpheWFyVwtAzm3scDT8Y0iE%2fDYv4M942MmxBAqKBa0oVn8IG%2fP%2b%2buQvctIUe%2foceFf4AvdbIdheIn%2f8riVJxARxCGEtiCm9%2bJ2WfUyK%2btrQTBIe2%2fbEYOK6aipUgiUIuA4zReI3XhwfzX7CWFzA00hH6b%2f26F6KE8sAF86fG%2fMeAV3OU3wNf5ofu1%2f%2fGLuVXc5IexIZqCyVyZCBKIwjVwxyO6dUcrEs1RL6%2fNJm6UbILSZGp4ZHJhadCXfqAF2i6gTRyaIWOR6%2f2SX%2b3nELJ%2b%2beCEJpXgfjeshjXPROIW42qzAR67RckoX8gmqS91wjYgPY%2byEfVBSGfFxBTO9 Base64-wrapped RSA key; same format as all siblings
Certificate CN ConnectWise, LLC Valid DigiCert-issued code-signing cert
Certificate location Tampa, Florida, US Subject locality

Static-only; no observed DNS or secondary C2.

Interesting Tidbits

  • Twin build, different parameter. Same compile timestamp as 81adbf9a to the second (Apr 8 2025 18:34:09 UTC), same PDB path, same linker version, same certificate chain. The only meaningful delta is the C2 IP and protocol prefix in the embedded URL. This is builder-level parameterization, not source-code divergence. ^[pefile.txt:34] ^[rabin2-info.txt:13]
  • Cross-variant IP reuse. The IP 45.83.31.225 was the C2 for MSI-bundle sibling 8c8e60af (Nov 2022). Seeing it again in an Apr 2025 ClickOnce bootstrapper means the attacker either (a) still controls that host, (b) reuses a hardcoded IP list in the builder, or (c) both. ^[entities/connectwise.md]
  • HTTPS upgrade. Unlike 81adbf9a which used plain http://, this sample prefixes the C2 URL with https://. The change is only one character in the embedded string but has operational significance: encrypted ClickOnce manifest fetch, reduced plaintext network fingerprint. ^[r2:strings]
  • Touch-and-go certificate cleanup. The import of CertDeleteCertificateFromStore and its placement in a post-launch loop suggests the binary scrubs its own certificates from TrustedPublisher after dfshim takes over. If confirmed dynamically, this is a notable OPSEC refinement over the 81adbf9a variant. ^[pefile.txt:336] ^[r2:main]
  • No Rich header. Same as all prior siblings; release build artifact. ^[pefile.txt]
  • 48-byte file-size delta vs 81adbf9a. 312,584 vs 312,536 bytes. Consistent with a longer C2 URL string (https://45.83.31.225 is one character longer than http://134.122.4.2).

How To Mess With It (Homelab Replication)

See the 81adbf9a sibling report for the full ClickOnce certificate-trust bootstrap replication recipe. ^[/intel/analyses/81adbf9af2875a3f442a6453a2e4cc637ea8642a7ddedf07134a853620daa7e6.html]

Per-sample verification: Compile the reproducer, sign with a self-signed cert, then run under ProcMon. Expect:

  1. CertAddCertificateContextToStore → TrustedPublisher
  2. LoadLibrary("dfshim.dll") → GetProcAddress("ShOpenVerbApplicationW")
  3. ShOpenVerbApplicationW with https://<host>/Bin/ScreenConnect.Client.application?h=<host>&p=8041&k=<key>
  4. Optional: CertDeleteCertificateFromStore in the cleanup path (verify with breakpoint)

Deployable Signatures

YARA rule

rule ConnectWise_ClickOnce_CertBootstrap_v2 {
    meta:
        description = "ClickOnce runner that extracts its own Authenticode signature, installs it into TrustedPublisher, then launches a remote ScreenConnect .application manifest via dfshim"
        author = "PacketPursuit"
        date = "2026-08-03"
        sha256 = "604e1cc7d2a390a2d211239f4335cb0c0d80d8b9ee48c35f823a78d60e861886"
    strings:
        $a = "TrustedPublisher" ascii wide
        $b = "ShOpenVerbApplicationW" ascii wide
        $c = "dfshim" ascii wide
        $d = "1.3.6.1.4.1.311.4.1.1" ascii wide
        $e = /ScreenConnect\.Client\.application/ ascii wide
        $f = "CertAddCertificateContextToStore" ascii wide
        $g = "CertDeleteCertificateFromStore" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        5 of ($a, $b, $c, $d, $e, $f, $g)
}

Behavioral hunt query (KQL / EDR)

ProcessEvents
| where ProcessImageName endswith "ClickOnceRunner.exe" 
   or CommandLine contains "ScreenConnect.Client.application"
| where (ModuleLoaded == "dfshim.dll" and APICall == "ShOpenVerbApplicationW")
   or (StoreName == "TrustedPublisher" 
       and APICall in ("CertAddCertificateContextToStore", 
                        "CertDeleteCertificateFromStore",
                        "CertOpenSystemStoreA"))
| project Timestamp, Hostname, ProcessId, CommandLine, ParentProcessId

IOC list

IOC Value Type
SHA-256 604e1cc7d2a390a2d211239f4335cb0c0d80d8b9ee48c35f823a78d60e861886 File
SHA-1 1244d19ab7a28680cacbff750c6dbac20403560b File
MD5 abbc92f0961694019af3fc68e06fb5f5 File
IP 45.83.31.225 C2
URL https://45.83.31.225/Bin/ScreenConnect.Client.application C2
Cert Subject CN=ConnectWise, LLC, O=ConnectWise, LLC, L=Tampa, S=Florida, C=US Code signing
Cert Issuer CN=DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, O=DigiCert, Inc., C=US Code signing

Behavioral fingerprint

This binary loads only KERNEL32.dll and CRYPT32.dll. Within 5 seconds of process start it opens the TrustedPublisher certificate store, extracts its own Authenticode signer certificates via CryptQueryObject + CryptMsgGetParam, installs them with CertAddCertificateContextToStore, then loads dfshim.dll and resolves ShOpenVerbApplicationW to launch a remote .application URL containing a hard-coded IP, port, and base64-wrapped RSA key. Post-launch cleanup may call CertDeleteCertificateFromStore to remove the added certificates. No direct socket API is imported; all HTTP/S is delegated to the ClickOnce shim.

Detection Signatures

Capability ATT&CK Technique Evidence
Certificate trust manipulation T1553.004 — Install Root Certificate CertOpenSystemStoreA("TrustedPublisher"), CertAddCertificateContextToStore ^[r2:main]
Remote access software abuse T1219 — Remote Access Software Hard-coded ScreenConnect .application URL, ShOpenVerbApplicationW ^[r2:strings]
Application-layer C2 T1071.001 — Application Layer Protocol: HTTP/S Remote manifest fetch via ClickOnce (delegated to dfshim) ^[r2:strings]
Ingress tool transfer T1105 — Ingress Tool Transfer Downloads remote .application manifest and payload ^[r2:main]
User execution T1204.002 — User Execution: Malicious File ClickOnce .application execution flow ^[r2:main]
Indicator removal T1070.004 — File Deletion CertDeleteCertificateFromStore in cleanup loop (medium-confidence) ^[r2:main] ^[pefile.txt:336]

References

  • connectwise — Entity page (family overview, all siblings, build-stack documentation)
  • clickonce-certificate-trust-bootstrap — Technique page for the certificate → ClickOnce deployment chain
  • legitimate-remote-access-tool-abuse — Cross-family concept page
  • /intel/analyses/81adbf9af2875a3f442a6453a2e4cc637ea8642a7ddedf07134a853620daa7e6.html — Twin sibling (same compile time, different C2 IP)
  • VirusTotal / MalwareBazaar: 604e1cc7d2a390a2d211239f4335cb0c0d80d8b9ee48c35f823a78d60e861886 (abuse.ch)

Provenance

  • file.txt — file(1) output
  • pefile.txt — pefile parser (headers, sections, imports, debug, load config, relocations)
  • strings.txt — strings -n 6
  • rabin2-info.txt — radare2 binary info (iI)
  • r2 — radare2 decompilation (pdg @ main, pdg @ entry0) and string search (izz)
  • binwalk.txt — Embedded signature and certificate extraction
  • exiftool.json — ExifTool metadata
  • yara.txt — Generic PE_File_Generic match only
  • capa.txt — Capa tool failure (signatures missing)
  • floss.txt — FLOSS tool invocation error
  • triage.json — Pipeline metadata with OpenCTI family label
  • Tools: radare2 5.x, pefile 2023.x, ExifTool 12.76, strings from binutils