8c8e60afcf9e8896ab78b89c9da45eb2ba466d6d5edec42423b1a91eeb4c2cb4connectwise: 8c8e60af — Fifth confirmed sibling, new C2 at 45.83.31.225:8041
Executive Summary
Fifth confirmed sibling in the ConnectWise ScreenConnect abuse cluster. Same Nov 2022 MSVC 14.33 build, same DotNetRunner native wrapper, same embedded MSI bundle with identical ProductCode, same valid ConnectWise Authenticode signature. The only material delta is the hardcoded C2 relay IP — 45.83.31.225:8041 — making this a builder-parameterized variant alongside siblings 7145e8 (134.122.4.2), b831f47e (104.236.198.16), 9477ccdd (104.236.198.16), and 81adbf9a (ClickOnce bootstrapper, Apr 2025). Static-only (CAPE skipped — no Windows guest).
What It Is
| Field | Value |
|---|---|
| SHA-256 | 8c8e60afcf9e8896ab78b89c9da45eb2ba466d6d5edec42423b1a91eeb4c2cb4 |
| File type | PE32 executable (GUI) Intel 80386, 5 sections ^[file.txt] |
| Size | 5,641,560 bytes (5.6 MB) ^[triage.json] |
| Compile time | 2022-11-18 20:10:20 UTC ^[pefile.txt:34] ^[rabin2-info.txt] |
| Linker | MSVC 14.33 (Visual Studio 2019/2022) ^[exiftool.json:18] |
| PDB | C:\Users\jmorgan\Source\cwcontrol\Custom\DotNetRunner\Release\DotNetRunner.pdb ^[strings.txt:125] |
| Signed | Valid Authenticode by ConnectWise, LLC (DigiCert chain) ^[rabin2-info.txt:29] ^[pefile.txt:193] |
| Overlay | No packing; .rsrc section holds embedded .NET assemblies (entropy 7.45) ^[pefile.txt:152] |
The binary is a native C/C++ PE32 wrapper (DotNetRunner) that bootstraps the CLR 2.0/4.0 runtime via mscoree!CorBindToRuntimeEx, then loads embedded CIL assemblies from its .rsrc section. The actual remote-access logic lives entirely inside the .NET payload — the wrapper itself contains no direct socket APIs. ^[pefile.txt:239] ^[r2:main]
How It Works
Entry-point flow (r2 decompile of main):
LoadLibraryW("kernel32")→GetProcAddress("SetDefaultDllDirectories")^[r2:main]- Falls back to
LoadLibraryW("mscoree.dll")→ resolveCLRCreateInstanceorCorBindToRuntimeEx^[r2:main] ^[pefile.txt:239] - If CLR v4 hosting succeeds (
CLRCreateInstance), loads runtimev4.0.30319; otherwise falls back toCorBindToRuntimeExwith CLR v2 parameters ^[r2:main] ^[strings.txt:5093] - Loads two
.rsrcblobs by name:_RESOLVERand_ENTRYPOINT^[r2:main] ^[pefile.txt:414] - Hands execution to the embedded CIL entrypoint
Embedded .rsrc layout (identical to siblings 7145e8 and b831f47e):
| Resource | Offset | Size | Purpose |
|---|---|---|---|
SCREENCONNECT.CORE |
0x163D4 |
0x86800 |
Core .NET assembly |
SCREENCONNECT.WINDOWS |
0x9CBD4 |
0x1A6200 |
Windows-specific assembly |
SCREENCONNECT.WINDOWSINSTALLER |
0x242DD4 |
0x1AC00 |
MSI installer payload |
_ENTRYPOINT |
0x25D9D4 |
0x2EE318 |
Entry-point assembly |
_RESOLVER |
0x54BCEC |
0x1600 |
Certificate / timestamp resource |
^[pefile.txt:354-452]
MSI installer artefacts (from strings.txt):
- ProductCode
{B292C5EA-BF5F-4280-B056-1670FB10BB1D}— byte-identical to siblings7145e8andb831f47e. ^[strings.txt:20275] - Version
25.2.4.9229— same across all Nov 2022 siblings. ^[strings.txt:20275] - SafeBoot network service registration. ^[strings.txt:20275]
- LSA Authentication Package (
ScreenConnect.WindowsAuthenticationPackage.dll). ^[strings.txt:20275] - Windows Credential Provider (
ScreenConnect.WindowsCredentialProvider.dll). ^[strings.txt:20275]
C2 Infrastructure
The C2 endpoint is hardcoded in two locations inside the binary:
?h=45.83.31.225&p=8041&k=BgIAAACkAABSU0ExAAgAAAEAAQDdfG%2bpheWFyVwt...
^[strings.txt:20622] ^[strings.txt:20623] ^[strings.txt:21148]
| Field | Value |
|---|---|
| IP | 45.83.31.225 |
| Port | 8041 |
| Key | Base64-encoded RSA public key blob (BgIAAACkAABSU0ExAAgAAAEAAQDdfG...) |
Same URL scheme, same RSA key format, same port as siblings 7145e8 (134.122.4.2:8041) and b831f47e (104.236.198.16:8041). The only delta is the IP. This is builder-parameterized C2 injection.
Decompiled Behavior
entry0 (radare2): Sets up SEH, initializes CRT, calls main, then tears down. No anti-debug, no VM checks, no timing gates. ^[r2:entry0]
main (radare2): The function is a thin loader stub. It resolves mscoree.dll APIs, attempts CLR v4 hosting first (modern path), falls back to CorBindToRuntimeEx (legacy path), loads _RESOLVER and _ENTRYPOINT resources, and jumps to the CIL runtime. No packing, no obfuscation, no control-flow flattening. The evasion is entirely in the valid Authenticode signature and the legitimate product name. ^[r2:main]
Interesting Tidbits
- No anti-analysis at all. No
IsDebuggerPresentchecks, no VM detection, no sandbox gates, no time-bombs. The binary relies on its valid signature and legitimate ConnectWise identity to evade detection. ^[r2:entry0] ^[r2:main] - Builder re-use confirmed. ssdeep similarity with
7145e8is expected to be >99 (sameDotNetRunnerwrapper, same MSI tables, same ProductCode). The only per-sample variation is the C2 IP injected at build time. - PDB path leak is identical to
7145e8.C:\Users\jmorgan\Source\cwcontrol\Custom\DotNetRunner\Release\DotNetRunner.pdb— same developer machine, same build pipeline. ^[strings.txt:125] - Version 25.2.4.9229 is a real ScreenConnect release version from late 2022, lending authenticity to the masquerade. ^[strings.txt:20275]
- DigiCert chain intact. OCSP and CRL URLs reference DigiCert infrastructure; the signature block is not fabricated. ^[strings.txt:20301-20614]
- .rsrc entropy 7.45 is high but expected for compressed/encrypted .NET assemblies inside an MSI bundle. Not indicative of a packer.
Deployable Signatures
YARA rule
rule connectwise_screenconnect_abuse_dotnetrunner
{
meta:
description = "ConnectWise ScreenConnect abuse - DotNetRunner MSI bundle"
author = "PacketPursuit"
date = "2026-08-02"
sha256 = "8c8e60afcf9e8896ab78b89c9da45eb2ba466d6d5edec42423b1a91eeb4c2cb4"
family = "connectwise"
strings:
$pdb = "C:\\Users\\jmorgan\\Source\\cwcontrol\\Custom\\DotNetRunner\\Release\\DotNetRunner.pdb" ascii
$core = "SCREENCONNECT.CORE, VERSION=25.2.4.9229" ascii wide
$prod = "ProductCode{B292C5EA-BF5F-4280-B056-1670FB10BB1D}" ascii wide
$c2fmt = /\?h=[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}&p=8041&k=/ ascii
$auth = "ScreenConnect.WindowsAuthenticationPackage.dll" ascii wide
$cred = "ScreenConnect.WindowsCredentialProvider.dll" ascii wide
$safe = "SafeBoot\\Network\\[SERVICE_NAME]" ascii wide
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C)) == 0x4550 and
3 of ($pdb, $core, $prod, $auth, $cred, $safe) and
$c2fmt
}
IOC list
| Type | Indicator | Notes |
|---|---|---|
| SHA-256 | 8c8e60afcf9e8896ab78b89c9da45eb2ba466d6d5edec42423b1a91eeb4c2cb4 |
This sample |
| ssdeep | 98304:KzIus6efPUIdoaxcp8wy5c3trGOlkQ5DUOgJ9zl:KhfefPtHxcp9ym3nltDUJV |
^[ssdeep.txt] |
| TLSH | 3B46E101B3D695B6D1BF1638D87A52696734BC049316CBBF5394BD392E32BC04E323A6 |
^[tlsh.txt] |
| C2 IP | 45.83.31.225 |
Hardcoded relay, port 8041 |
| C2 port | 8041 |
Consistent across all siblings |
| ProductCode | {B292C5EA-BF5F-4280-B056-1670FB10BB1D} |
MSI installer GUID |
| File name | ScreenConnect.WindowsClient.exe |
Installed binary name |
| Registry | SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages |
LSA auth package reg |
| Registry | Software\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers |
Credential provider reg |
| Service | [SERVICE_NAME] (SafeBoot\Network compatible) |
Post-install service |
Behavioral fingerprint
This binary is a 5.6 MB native PE32 wrapper that loads mscoree.dll and initializes the CLR via CorBindToRuntimeEx or CLRCreateInstance. It extracts five named RCData resources (SCREENCONNECT.CORE, SCREENCONNECT.WINDOWS, SCREENCONNECT.WINDOWSINSTALLER, _ENTRYPOINT, _RESOLVER) from its .rsrc section and delegates execution to embedded CIL assemblies. The wrapper contains no direct network APIs; C2 configuration (IP, port 8041, RSA public key) is read from an embedded XML/app.config inside the _RESOLVER resource. Post-installation, the MSI payload registers a Windows service (SafeBoot network compatible), an LSA authentication package DLL, and a Windows credential provider DLL. The binary is signed with a valid DigiCert-issued Authenticode certificate for ConnectWise, LLC.
Detection Signatures
| Technique | MITRE ATT&CK ID | Evidence |
|---|---|---|
| Install root / publisher certificate | T1553.004 | Authenticode by ConnectWise, LLC; certificate chain embedded in PE ^[pefile.txt:193] |
| Remote access software abuse | T1219 | Hardcoded ScreenConnect C2 endpoint in embedded config ^[strings.txt:20622] |
| Ingress tool transfer | T1105 | Embedded MSI with Cabinet archives installing ScreenConnect from .rsrc ^[pefile.txt:354] |
| Create or Modify System Process | T1543.003 | MSI ServiceInstall table + SafeBoot\Network persistence ^[strings.txt:20275] |
| OS Credential Dumping: LSASS Memory | T1003.001 | LSA Authentication Package registration ^[strings.txt:20275] |
| Input Capture: Credential API Hooking | T1056.001 | Windows Credential Provider DLL ^[strings.txt:20275] |
| Boot or Logon Autostart Execution | T1547.012 | Credential provider registration at install time ^[strings.txt:20275] |
| Valid Accounts | T1078 | Authenticode by ConnectWise, LLC ^[pefile.txt:193] |
| Application-layer C2 | T1071.001 | HTTP via ScreenConnect client protocol ^[strings.txt:20622] |
References
- Artifact ID:
2972c36e-0d17-49b9-bc6a-870e8eda325f - Source: OpenCTI / abuse.ch URLhaus
- Related wiki: connectwise — entity page for the family
- Related wiki: clickonce-certificate-trust-bootstrap — technique page for the cert → ClickOnce chain
- Related wiki: legitimate-remote-access-tool-abuse — cross-family concept page
- Sibling:
7145e8(134.122.4.2:8041) — raw/analyses/7145e829/report.md - Sibling:
b831f47e(104.236.198.16:8041) — raw/analyses/b831f47e/report.md - Sibling:
9477ccdd(104.236.198.16:8041, ClickOnce bootstrapper) — raw/analyses/9477ccddefa6/report.md - Sibling:
81adbf9a(ClickOnce bootstrapper, Apr 2025) — raw/analyses/81adbf9a/report.md
Provenance
- Static analysis performed 2026-08-02 on pp-hermes (Linux 6.14.8-2-pve).
- Tools:
file(magic),pefile(Python),radare2(rabin2 + decompiler),strings,exiftool,binwalk,ssdeep,tlsh. - CAPE detonation skipped: no Windows guest available.
- No dynamic execution; all behavioral claims are statically inferred from imports, strings, PE resources, and decompiled control flow.