73a8126b8d5443295250815df160f550effeedf1f8adfd0ac2d5160824ca8f37connectwise: 73a8126b — Sixth confirmed sibling, Nov 2022 MSI bundle, C2 84.54.33.84:8041
Executive Summary
Sixth confirmed sibling in the ConnectWise ScreenConnect abuse cluster. Self-contained PE32 MSI bundle (Nov 2022 build, MSVC 14.33) embedding full .NET ScreenConnect client with LSA authentication package and credential provider registration. Hardcoded C2 at 84.54.33.84:8041 — fourth distinct IP observed for this build timestamp. Valid Authenticode by ConnectWise, LLC. Static-only; CAPE skipped (no Windows guest).
What It Is
- SHA-256:
73a8126b8d5443295250815df160f550effeedf1f8adfd0ac2d5160824ca8f37 - Size: 5.6 MB (5,648,336 bytes)
- Type: PE32 executable (GUI) Intel 80386, 5 sections ^[file.txt]
- Compiler: MSVC 14.33 (Visual Studio 2019/2022), LinkerVersion 14.33 ^[exiftool.json]
- Timestamp: Fri Nov 18 20:10:20 2022 UTC ^[pefile.txt:34]
- Language: C/C++ native wrapper bootstrapping .NET CLR assemblies (CIL) ^[rabin2-info.txt:19]
- Signed: Valid Authenticode (rabin2
signed: true) ^[rabin2-info.txt:29] - PDB:
C:\Users\jmorgan\Source\cwcontrol\Custom\DotNetRunner\Release\DotNetRunner.pdb^[strings.txt:125] - Family: ConnectWise ScreenConnect abuse — Variant A (MSI bundle) per connectwise
This sample shares the same compilation timestamp, PDB path, ProductCode, and MSI structure as confirmed siblings 7145e8, b831f47e, and 8c8e60af. The only delta is the hardcoded C2 IP and the resulting SHA-256.
How It Works
The outer PE is a minimal MSVC C++ bootstrapper. Its main() loads kernel32.dll, resolves SetDefaultDllDirectories, then loads mscoree.dll and attempts CLRCreateInstance before falling back to CorBindToRuntimeEx to host CLR v4.0.30319 ^[r2:main@0x401140]. Once the runtime is active, it loads two named resources from .rsrc: _RESOLVER and _ENTRYPOINT ^[r2:main@0x401140]. These are the .NET entry points for the embedded ScreenConnect client.
The .rsrc section (5.4 MB, entropy 7.45) contains:
SCREENCONNECT.CORE— Core client assembly (0x86C00 bytes)SCREENCONNECT.WINDOWS— Windows-specific assembly (0x1A6200 bytes)SCREENCONNECT.WINDOWSIINSTALLER— Installer assembly (0x1AC00 bytes)_ENTRYPOINT— Main entry payload (0x2EF318 bytes)_RESOLVER— Dependency resolver (0x1600 bytes)- An RT_MANIFEST resource (0x188 bytes)
- Multiple PNG icons, XML documents, DER certificates, and Cabinet archives ^[binwalk.txt]
The embedded MSI (built with WiX Toolset 3.11.0.1701) installs a Windows service and registers LSA authentication packages and credential providers. The C2 endpoint is baked into an app.config-style XML fragment inside the resources:
?h=84.54.33.84&p=8041&k=BgIAAACkAABSU0ExAAgAAAEAAQCdLjAD8yszihPgOEc2eP4iyP%2f7mfVDiz7Z%2fkjBjBEEhJhrg2GrG1Ns7mZe1LsyQGju4XhsfbfjSu2p2a3pkzdO76r69wzEAMS2zz8HSAYH2OAd8pGPIOqhrkBR8ZHgiOx%2fRIxrjfCVGGodbBe6pD%2fp8nZrIRMaN%2ba9YN8%2bK2MN305MUjoKryIvKPVwSmnFavzQ1qGnE3RBVw5Kc8J3blUJn612ObUvDQh1bbqX0TGXgEMC5cqzVX3GHK0HTcqTYB%2fAhi%2fWi9hJ4gLMsMZKftSVrtcMGEDOTGCbAUn621vyUCJWVSa1XGFC6zJZCt9TGYdz6UHfwEFh3jEXONvhlPvc ^[strings.txt:20608]
Decompiled Behavior
entry0 @ 0x4014ad: Standard MSVC C++ entry point. Sets up SEH frame, initializes CRT (fcn.00401ba0), processes constructors, then calls main(0x400000, NULL) ^[r2:entry0].
main @ 0x401140: The bootstrap sequence is unambiguous:
LoadLibraryW("kernel32")→GetProcAddress(..., "SetDefaultDllDirectories")LoadLibraryW("mscoree.dll")→GetProcAddress(..., "CLRCreateInstance")- If CLRCreateInstance succeeds:
CLRCreateInstance(CLSID_CLRMetaHost, ...)→GetRuntime("v4.0.30319", ...)→GetInterface(CLSID_CLRRuntimeHost, ...)→Start() - If CLRCreateInstance fails: direct
CorBindToRuntimeEx("v4.0.30319", ...)^[r2:main] - Once runtime is live, load
_RESOLVERand_ENTRYPOINTresources viafcn.00401010and dispatch them through the CLR host ^[r2:main]
No anti-debug, no anti-VM, no packing, no obfuscation. The evasion is entirely the valid signature and the legitimate tool chain.
C2 Infrastructure
| Indicator | Value | Provenance |
|---|---|---|
| C2 IP | 84.54.33.84 |
^[strings.txt:20608] |
| C2 Port | 8041 |
^[strings.txt:20608] |
| C2 URL pattern | ?h=<IP>&p=8041&k=<base64 RSA key> |
^[strings.txt:20608] |
| RSA public key blob | BgIAAACkAABSU0ExAAgAAAEAAQCdLjAD8yszihPgOEc2eP4iyP%2f7mfVDiz7Z%2fkjBjBEEhJhrg2GrG1Ns7mZe1LsyQGju4XhsfbfjSu2p2a3pkzdO76r69wzEAMS2zz8HSAYH2OAd8pGPIOqhrkBR8ZHgiOx%2fRIxrjfCVGGodbBe6pD%2fp8nZrIRMaN%2ba9YN8%2bK2MN305MUjoKryIvKPVwSmnFavzQ1qGnE3RBVw5Kc8J3blUJn612ObUvDQh1bbqX0TGXgEMC5cqzVX3GHK0HTcqTYB%2fAhi%2fWi9hJ4gLMsMZKftSVrtcMGEDOTGCbAUn621vyUCJWVSa1XGFC6zJZCt9TGYdz6UHfwEFh3jEXONvhlPvc |
^[strings.txt:20608] |
This is the fourth distinct C2 IP observed for the Nov 18 2022 build timestamp. Siblings:
7145e8→134.122.4.2:8041b831f47e→104.236.198.16:80418c8e60af→45.83.31.225:804173a8126b→84.54.33.84:8041(this sample)
All share the same ProductCode {B292C5EA-BF5F-4280-B056-1670FB10BB1D} and ProductVersion {20AB6B9A-CF56-446C-A5AB-99B56F58BAFF} ^[strings.txt:20264].
Interesting Tidbits
- Builder parameterization confirmed: The only meaningful difference between this sample and its three Nov 2022 siblings is the hardcoded C2 IP. Same timestamp, same PDB, same ProductCode, same MSI tables, same embedded assemblies. The builder was a parameterized pipeline that swapped the relay endpoint and re-signed the output.
- WiX Toolset 3.11.0.1701: The MSI was built with the open-source WiX toolchain, not a commercial installer builder. ^[strings.txt:16886]
.rsrcsection entropy of 7.45 indicates compressed/encrypted content — the Cabinet archives and .NET assemblies are densely packed. ^[pefile.txt]- The
_ENTRYPOINTresource (0x2EF318 bytes ≈ 3 MB) is the largest single artefact and likely contains the main ScreenConnect client logic. - No CAPE detonation: No Windows guest available for PE32 at time of analysis. All behavioral claims are inferred from static strings, decompiled bootstrapper, and cross-sibling comparison.
How To Mess With It (Homelab Replication)
This sample is a signed, legitimate remote-access tool installer repackaged with attacker-controlled C2. Replication for research purposes:
- Obtain ScreenConnect trial installer from ConnectWise (legitimate source).
- Extract MSI tables with
Dark.exeormsiinfo.exeto locate theScreenConnect.ApplicationSettingsconfig. - Patch the relay host in the
app.configor MSI property table to point to your own relay server. - Rebuild with WiX 3.11 using the same ProductCode/Version to observe how Windows handles same-GUID reinstalls.
- Sign with a test Authenticode cert and observe SmartScreen behavior versus the original.
Verification: Compare the resulting PE's .rsrc layout and import table to this sample. The capa signature (if signatures were installed) would hit .NET assembly loading and create or modify system process.
Deployable Signatures
YARA Rule
rule ConnectWise_ScreenConnect_Abuse_Nov2022 {
meta:
description = "ConnectWise ScreenConnect abused MSI bundle (Nov 2022 build)"
author = "PacketPursuit SOC"
date = "2026-08-02"
reference = "/intel/analyses/73a8126b8d5443295250815df160f550effeedf1f8adfd0ac2d5160824ca8f37.html"
hash = "73a8126b8d5443295250815df160f550effeedf1f8adfd0ac2d5160824ca8f37"
strings:
$pdb = "C:\\Users\\jmorgan\\Source\\cwcontrol\\Custom\\DotNetRunner\\Release\\DotNetRunner.pdb" ascii wide
$prod_code = "{B292C5EA-BF5F-4280-B056-1670FB10BB1D}" ascii wide
$prod_ver = "{20AB6B9A-CF56-446C-A5AB-99B56F58BAFF}" ascii wide
$screenconnect = "ScreenConnect Software" ascii wide
$corbind = "CorBindToRuntimeEx" ascii
$mscoree = "mscoree.dll" ascii
$entrypoint = "_ENTRYPOINT" wide
$resolver = "_RESOLVER" wide
$c2_pattern = "?h=" ascii wide
$port_8041 = "&p=8041&k=" ascii wide
condition:
uint16(0) == 0x5A4D and
filesize > 4MB and filesize < 7MB and
4 of ($pdb, $prod_code, $prod_ver, $screenconnect) and
($corbind and $mscoree) and
any of ($entrypoint, $resolver) and
any of ($c2_pattern, $port_8041)
}
Sigma Rule
title: ConnectWise ScreenConnect Abused Installer Execution
status: experimental
description: Detects execution of abused ConnectWise ScreenConnect MSI bundle with known malicious C2 hardcoding
logsource:
category: process_creation
product: windows
detection:
selection_msiexec:
CommandLine|contains:
- '{B292C5EA-BF5F-4280-B056-1670FB10BB1D}'
- 'ScreenConnect Software'
selection_service:
Image|endswith: '\ScreenConnect.WindowsClient.exe'
CommandLine|contains: '84.54.33.84'
selection_network:
Initiated: 'true'
DestinationIp: '84.54.33.84'
DestinationPort: 8041
condition: selection_msiexec or selection_service or selection_network
falsepositives:
- Legitimate ScreenConnect installations using the same ProductCode (rare, but possible if the attacker copied a real trial installer)
level: high
IOC List
| Indicator | Type | Value |
|---|---|---|
| SHA-256 | Hash | 73a8126b8d5443295250815df160f550effeedf1f8adfd0ac2d5160824ca8f37 |
| ssdeep | Fuzzy hash | 49152:IfmLDKJkGYYpT0+TFiH7efP4yfy3Ys6vPHYs00Yrxl/jgq36+hKls/LG2XwygONw:Prs6efPRy3BIvY44TnDTGvyEvgVxe7l |
| C2 IP | Network | 84.54.33.84 |
| C2 Port | Network | 8041 |
| ProductCode | Registry | {B292C5EA-BF5F-4280-B056-1670FB10BB1D} |
| ProductVersion | Registry | {20AB6B9A-CF56-446C-A5AB-99B56F58BAFF} |
| ServiceName | Service | ScreenConnect Client (inferred from sibling behavior) |
| LSA Package | Registry | ScreenConnect.WindowsAuthenticationPackage (inferred from strings) |
| CredProvider | Registry | ScreenConnect.WindowsCredentialProvider (inferred from strings) |
Behavioral Fingerprint
This binary is a 5–6 MB PE32 GUI with a valid Authenticode signature by ConnectWise, LLC. On launch, it loads mscoree.dll and calls CorBindToRuntimeEx to bootstrap CLR v4.0.30319. It then extracts _RESOLVER and _ENTRYPOINT resources from its .rsrc section (which contains multiple embedded PEs, Cabinet archives, and MSI tables). The embedded MSI installs a Windows service and registers LSA authentication packages and Windows credential providers. Network connections, if observed, target TCP port 8041 on a hardcoded IP with an HTTP query string containing a Base64-encoded RSA public key.
Detection Signatures
| Capability | ATT&CK ID | Evidence |
|---|---|---|
| Remote access software | T1219 | Embedded ScreenConnect assemblies, hardcoded C2 ^[strings.txt:2427] |
| Ingress tool transfer | T1105 | Embedded MSI with Cabinet archives ^[binwalk.txt] |
| Create/Modify System Process | T1543.003 | MSI ServiceInstall table (inferred from sibling reports and MSI strings) |
| OS Credential Dumping | T1003.001 | LSA Authentication Package registration ^[strings.txt] |
| Input Capture | T1056.001 | Windows Credential Provider DLL ^[strings.txt] |
| Boot/Logon Autostart | T1547.012 | Credential provider registration at install time (inferred) |
| Valid Accounts | T1078 | Authenticode by ConnectWise, LLC ^[rabin2-info.txt] |
| Application-layer C2 | T1071.001 | HTTP via ScreenConnect client (inferred) |
References
- ConnectWise ScreenConnect abuse entity page: connectwise
- Legitimate remote-access tool abuse concept: legitimate-remote-access-tool-abuse
- Sibling analysis
7145e8:/intel/analyses/7145e8299053bea02c520460f9a379711ed4455318d434fd5785981295a3a4f4.html - Sibling analysis
b831f47e:/intel/analyses/b831f47ee0fedb819d1060a68fdfe4500d2a1a5f18f5e613fe8454c452626c48.html - Sibling analysis
8c8e60af:/intel/analyses/8c8e60afcf9e8896ab78b89c9da45eb2ba466d6d5edec42423b1a91eeb4c2cb4.html
Provenance
file.txt—filecommand outputexiftool.json— ExifTool PE metadatapefile.txt— pefile.py dumpstrings.txt— GNU stringsrabin2-info.txt— radare2rabin2 -Isummarybinwalk.txt— Binwalk embedded artefact scancapa.txt— Mandiant capa (failed: missing signatures)floss.txt— FireEye flare-floss (failed: argument error)r2:entry0,r2:main— radare2 decompiled functions at 0x4014ad and 0x401140dynamic-analysis.md— CAPE status: skipped (no Windows guest)