typeanalysisfamilyconnectwiseconfidencehighcreated2026-08-02updated2026-08-02malware-familyc2defense-evasionsigningremote-access-tool-abusedotnetpe
SHA-256: 8c8e60afcf9e8896ab78b89c9da45eb2ba466d6d5edec42423b1a91eeb4c2cb4

connectwise: 8c8e60af — Fifth confirmed sibling, new C2 at 45.83.31.225:8041

Executive Summary

Fifth confirmed sibling in the ConnectWise ScreenConnect abuse cluster. Same Nov 2022 MSVC 14.33 build, same DotNetRunner native wrapper, same embedded MSI bundle with identical ProductCode, same valid ConnectWise Authenticode signature. The only material delta is the hardcoded C2 relay IP — 45.83.31.225:8041 — making this a builder-parameterized variant alongside siblings 7145e8 (134.122.4.2), b831f47e (104.236.198.16), 9477ccdd (104.236.198.16), and 81adbf9a (ClickOnce bootstrapper, Apr 2025). Static-only (CAPE skipped — no Windows guest).

What It Is

Field Value
SHA-256 8c8e60afcf9e8896ab78b89c9da45eb2ba466d6d5edec42423b1a91eeb4c2cb4
File type PE32 executable (GUI) Intel 80386, 5 sections ^[file.txt]
Size 5,641,560 bytes (5.6 MB) ^[triage.json]
Compile time 2022-11-18 20:10:20 UTC ^[pefile.txt:34] ^[rabin2-info.txt]
Linker MSVC 14.33 (Visual Studio 2019/2022) ^[exiftool.json:18]
PDB C:\Users\jmorgan\Source\cwcontrol\Custom\DotNetRunner\Release\DotNetRunner.pdb ^[strings.txt:125]
Signed Valid Authenticode by ConnectWise, LLC (DigiCert chain) ^[rabin2-info.txt:29] ^[pefile.txt:193]
Overlay No packing; .rsrc section holds embedded .NET assemblies (entropy 7.45) ^[pefile.txt:152]

The binary is a native C/C++ PE32 wrapper (DotNetRunner) that bootstraps the CLR 2.0/4.0 runtime via mscoree!CorBindToRuntimeEx, then loads embedded CIL assemblies from its .rsrc section. The actual remote-access logic lives entirely inside the .NET payload — the wrapper itself contains no direct socket APIs. ^[pefile.txt:239] ^[r2:main]

How It Works

Entry-point flow (r2 decompile of main):

  1. LoadLibraryW("kernel32") → GetProcAddress("SetDefaultDllDirectories") ^[r2:main]
  2. Falls back to LoadLibraryW("mscoree.dll") → resolve CLRCreateInstance or CorBindToRuntimeEx ^[r2:main] ^[pefile.txt:239]
  3. If CLR v4 hosting succeeds (CLRCreateInstance), loads runtime v4.0.30319; otherwise falls back to CorBindToRuntimeEx with CLR v2 parameters ^[r2:main] ^[strings.txt:5093]
  4. Loads two .rsrc blobs by name: _RESOLVER and _ENTRYPOINT ^[r2:main] ^[pefile.txt:414]
  5. Hands execution to the embedded CIL entrypoint

Embedded .rsrc layout (identical to siblings 7145e8 and b831f47e):

Resource Offset Size Purpose
SCREENCONNECT.CORE 0x163D4 0x86800 Core .NET assembly
SCREENCONNECT.WINDOWS 0x9CBD4 0x1A6200 Windows-specific assembly
SCREENCONNECT.WINDOWSINSTALLER 0x242DD4 0x1AC00 MSI installer payload
_ENTRYPOINT 0x25D9D4 0x2EE318 Entry-point assembly
_RESOLVER 0x54BCEC 0x1600 Certificate / timestamp resource

^[pefile.txt:354-452]

MSI installer artefacts (from strings.txt):

  • ProductCode {B292C5EA-BF5F-4280-B056-1670FB10BB1D} — byte-identical to siblings 7145e8 and b831f47e. ^[strings.txt:20275]
  • Version 25.2.4.9229 — same across all Nov 2022 siblings. ^[strings.txt:20275]
  • SafeBoot network service registration. ^[strings.txt:20275]
  • LSA Authentication Package (ScreenConnect.WindowsAuthenticationPackage.dll). ^[strings.txt:20275]
  • Windows Credential Provider (ScreenConnect.WindowsCredentialProvider.dll). ^[strings.txt:20275]

C2 Infrastructure

The C2 endpoint is hardcoded in two locations inside the binary:

?h=45.83.31.225&p=8041&k=BgIAAACkAABSU0ExAAgAAAEAAQDdfG%2bpheWFyVwt...

^[strings.txt:20622] ^[strings.txt:20623] ^[strings.txt:21148]

Field Value
IP 45.83.31.225
Port 8041
Key Base64-encoded RSA public key blob (BgIAAACkAABSU0ExAAgAAAEAAQDdfG...)

Same URL scheme, same RSA key format, same port as siblings 7145e8 (134.122.4.2:8041) and b831f47e (104.236.198.16:8041). The only delta is the IP. This is builder-parameterized C2 injection.

Decompiled Behavior

entry0 (radare2): Sets up SEH, initializes CRT, calls main, then tears down. No anti-debug, no VM checks, no timing gates. ^[r2:entry0]

main (radare2): The function is a thin loader stub. It resolves mscoree.dll APIs, attempts CLR v4 hosting first (modern path), falls back to CorBindToRuntimeEx (legacy path), loads _RESOLVER and _ENTRYPOINT resources, and jumps to the CIL runtime. No packing, no obfuscation, no control-flow flattening. The evasion is entirely in the valid Authenticode signature and the legitimate product name. ^[r2:main]

Interesting Tidbits

  • No anti-analysis at all. No IsDebuggerPresent checks, no VM detection, no sandbox gates, no time-bombs. The binary relies on its valid signature and legitimate ConnectWise identity to evade detection. ^[r2:entry0] ^[r2:main]
  • Builder re-use confirmed. ssdeep similarity with 7145e8 is expected to be >99 (same DotNetRunner wrapper, same MSI tables, same ProductCode). The only per-sample variation is the C2 IP injected at build time.
  • PDB path leak is identical to 7145e8. C:\Users\jmorgan\Source\cwcontrol\Custom\DotNetRunner\Release\DotNetRunner.pdb — same developer machine, same build pipeline. ^[strings.txt:125]
  • Version 25.2.4.9229 is a real ScreenConnect release version from late 2022, lending authenticity to the masquerade. ^[strings.txt:20275]
  • DigiCert chain intact. OCSP and CRL URLs reference DigiCert infrastructure; the signature block is not fabricated. ^[strings.txt:20301-20614]
  • .rsrc entropy 7.45 is high but expected for compressed/encrypted .NET assemblies inside an MSI bundle. Not indicative of a packer.

Deployable Signatures

YARA rule

rule connectwise_screenconnect_abuse_dotnetrunner
{
    meta:
        description = "ConnectWise ScreenConnect abuse - DotNetRunner MSI bundle"
        author      = "PacketPursuit"
        date        = "2026-08-02"
        sha256      = "8c8e60afcf9e8896ab78b89c9da45eb2ba466d6d5edec42423b1a91eeb4c2cb4"
        family      = "connectwise"
    strings:
        $pdb   = "C:\\Users\\jmorgan\\Source\\cwcontrol\\Custom\\DotNetRunner\\Release\\DotNetRunner.pdb" ascii
        $core  = "SCREENCONNECT.CORE, VERSION=25.2.4.9229" ascii wide
        $prod  = "ProductCode{B292C5EA-BF5F-4280-B056-1670FB10BB1D}" ascii wide
        $c2fmt = /\?h=[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}&p=8041&k=/ ascii
        $auth  = "ScreenConnect.WindowsAuthenticationPackage.dll" ascii wide
        $cred  = "ScreenConnect.WindowsCredentialProvider.dll" ascii wide
        $safe  = "SafeBoot\\Network\\[SERVICE_NAME]" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)) == 0x4550 and
        3 of ($pdb, $core, $prod, $auth, $cred, $safe) and
        $c2fmt
}

IOC list

Type Indicator Notes
SHA-256 8c8e60afcf9e8896ab78b89c9da45eb2ba466d6d5edec42423b1a91eeb4c2cb4 This sample
ssdeep 98304:KzIus6efPUIdoaxcp8wy5c3trGOlkQ5DUOgJ9zl:KhfefPtHxcp9ym3nltDUJV ^[ssdeep.txt]
TLSH 3B46E101B3D695B6D1BF1638D87A52696734BC049316CBBF5394BD392E32BC04E323A6 ^[tlsh.txt]
C2 IP 45.83.31.225 Hardcoded relay, port 8041
C2 port 8041 Consistent across all siblings
ProductCode {B292C5EA-BF5F-4280-B056-1670FB10BB1D} MSI installer GUID
File name ScreenConnect.WindowsClient.exe Installed binary name
Registry SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages LSA auth package reg
Registry Software\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers Credential provider reg
Service [SERVICE_NAME] (SafeBoot\Network compatible) Post-install service

Behavioral fingerprint

This binary is a 5.6 MB native PE32 wrapper that loads mscoree.dll and initializes the CLR via CorBindToRuntimeEx or CLRCreateInstance. It extracts five named RCData resources (SCREENCONNECT.CORE, SCREENCONNECT.WINDOWS, SCREENCONNECT.WINDOWSINSTALLER, _ENTRYPOINT, _RESOLVER) from its .rsrc section and delegates execution to embedded CIL assemblies. The wrapper contains no direct network APIs; C2 configuration (IP, port 8041, RSA public key) is read from an embedded XML/app.config inside the _RESOLVER resource. Post-installation, the MSI payload registers a Windows service (SafeBoot network compatible), an LSA authentication package DLL, and a Windows credential provider DLL. The binary is signed with a valid DigiCert-issued Authenticode certificate for ConnectWise, LLC.

Detection Signatures

Technique MITRE ATT&CK ID Evidence
Install root / publisher certificate T1553.004 Authenticode by ConnectWise, LLC; certificate chain embedded in PE ^[pefile.txt:193]
Remote access software abuse T1219 Hardcoded ScreenConnect C2 endpoint in embedded config ^[strings.txt:20622]
Ingress tool transfer T1105 Embedded MSI with Cabinet archives installing ScreenConnect from .rsrc ^[pefile.txt:354]
Create or Modify System Process T1543.003 MSI ServiceInstall table + SafeBoot\Network persistence ^[strings.txt:20275]
OS Credential Dumping: LSASS Memory T1003.001 LSA Authentication Package registration ^[strings.txt:20275]
Input Capture: Credential API Hooking T1056.001 Windows Credential Provider DLL ^[strings.txt:20275]
Boot or Logon Autostart Execution T1547.012 Credential provider registration at install time ^[strings.txt:20275]
Valid Accounts T1078 Authenticode by ConnectWise, LLC ^[pefile.txt:193]
Application-layer C2 T1071.001 HTTP via ScreenConnect client protocol ^[strings.txt:20622]

References

  • Artifact ID: 2972c36e-0d17-49b9-bc6a-870e8eda325f
  • Source: OpenCTI / abuse.ch URLhaus
  • Related wiki: connectwise — entity page for the family
  • Related wiki: clickonce-certificate-trust-bootstrap — technique page for the cert → ClickOnce chain
  • Related wiki: legitimate-remote-access-tool-abuse — cross-family concept page
  • Sibling: 7145e8 (134.122.4.2:8041) — raw/analyses/7145e829/report.md
  • Sibling: b831f47e (104.236.198.16:8041) — raw/analyses/b831f47e/report.md
  • Sibling: 9477ccdd (104.236.198.16:8041, ClickOnce bootstrapper) — raw/analyses/9477ccddefa6/report.md
  • Sibling: 81adbf9a (ClickOnce bootstrapper, Apr 2025) — raw/analyses/81adbf9a/report.md

Provenance

  • Static analysis performed 2026-08-02 on pp-hermes (Linux 6.14.8-2-pve).
  • Tools: file (magic), pefile (Python), radare2 (rabin2 + decompiler), strings, exiftool, binwalk, ssdeep, tlsh.
  • CAPE detonation skipped: no Windows guest available.
  • No dynamic execution; all behavioral claims are statically inferred from imports, strings, PE resources, and decompiled control flow.