typeanalysisfamilyconnectwiseconfidencehighmalware-familyc2defense-evasionsigningremote-access-tool-abusepedotnet
SHA-256: aa116a6279aebc383ed7a9321d580f998436e34f06d07f2cb8ac2d7fd876ba60

connectwise: aa116a62 — tenth confirmed sibling, new C2 193.26.115.231:8041, Oct 2024 cert timestamp

Executive Summary

Self-contained MSI-bundle variant of the ConnectWise ScreenConnect abuse cluster. PE32 wrapper compiled Nov 2022 (MSVC 14.33) embeds .NET 2.0 assemblies via mscoree!CorBindToRuntimeEx, then drives a full WiX-based MSI install registering services, credential providers, and an LSA authentication package. Valid Authenticode by ConnectWise, LLC. The hardcoded C2 endpoint 193.26.115.231:8041 is new to this cluster. Certificate timestamping signature is dated 2024-10-28 — roughly two years after compilation, suggesting either delayed signing or preserved build-time artefacts. Static-only; CAPE skipped (no Windows guest).

What It Is

Field Value
SHA-256 aa116a6279aebc383ed7a9321d580f998436e34f06d07f2cb8ac2d7fd876ba60
SHA-1 e3565ac3b44d7223389e8182df4747b1f21db061
MD5 8859c93067029a6515b293523db7d79b
Size 5.64 MB (5,640,960 bytes)
Type PE32 executable (GUI) Intel 80386, 5 sections ^[file.txt]
Compile time Fri Nov 18 20:10:20 2022 UTC ^[pefile.txt:34]
Cert timestamp 2024-10-28T17:44:14 UTC (PKCS#7 signingTime) ^[strings.txt:20139]
Signer ConnectWise, LLC — DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA ^[strings.txt:20119]
Linker MSVC 14.33 (Visual Studio 2019/2022) ^[exiftool.json:18]
Subsystem Windows GUI ^[exiftool.json:26]
PDB C:\Users\jmorgan\Source\cwcontrol\Custom\DotNetRunner\Release\DotNetRunner.pdb ^[strings.txt:125]
ProductCode {B292C5EA-BF5F-4280-B056-1670FB10BB1D} ^[strings.txt:20084]
ScreenConnect version 24.3.7.9067 ^[strings.txt:20083]

This is the tenth confirmed sibling in the ConnectWise abuse cluster, joining the Nov 2022 MSI-bundle Variant A lineage (7145e8, b831f47e, 8c8e60af, 73a8126b). The compile timestamp, PDB path, ProductCode, and assembly version all match the Nov 2022 batch exactly; only the hardcoded C2 IP and the SHA-256 differ. ^[entities/connectwise.md]

How It Works

The outer PE32 is a C/C++ bootstrap stub (DotNetRunner) with a minimal import table (KERNEL32.dll, mscoree.dll, OLEAUT32.dll). On launch it calls CorBindToRuntimeEx to spin up the CLR, loads embedded .NET assemblies from the .rsrc section, and hands execution to the ScreenConnect client installer logic. ^[pefile.txt:239]

The .rsrc section (~5.4 MB, entropy 7.45) contains five named assembly streams: ^[pefile.txt:334-454]

  • SCREENCONNECT.CORE, VERSION=24.3.7.9067, CULTURE=NEUTRAL, PUBLICKEYTOKEN=4B14C015C87C1AD8
  • SCREENCONNECT.WINDOWS, VERSION=24.3.7.9067, CULTURE=NEUTRAL, PUBLICKEYTOKEN=4B14C015C87C1AD8
  • SCREENCONNECT.WINDOWSINSTALLER, VERSION=24.3.7.9067, CULTURE=NEUTRAL, PUBLICKEYTOKEN=4B14C015C87C1AD8
  • _ENTRYPOINT
  • _RESOLVER

binwalk identifies two Cabinet archives inside the resource blob (1.66 MB / 14 files at 0x25F54C, and 949 KB / 8 files at 0x41734C), consistent with a WiX-generated MSI payload. ^[binwalk.txt:23,25]

The MSI database tables observed in strings include ServiceInstall, Component, File, Registry, CustomAction, Upgrade, LaunchCondition, and FeatureComponents. ^[strings.txt:20083] Installation artefacts include:

  • Windows service registration (ScreenConnect.ClientService.exe) with SafeBoot\Network persistence
  • LSA Authentication Package registration (ScreenConnect.WindowsAuthenticationPackage.dll)
  • Windows Credential Provider registration (ScreenConnect.WindowsCredentialProvider.dll)
  • URL-scheme handler ([URL_SCHEME]\shell\open\command → ScreenConnect.WindowsClient.exe)

Decompiled Behavior

radare2 analysis (level 2, 478 functions) shows a standard MSVC CRT entry-point at 0x004014ad. ^[rabin2-info.txt:9]

0x00401140  main
0x004014ad  entry0

Decompilation of entry0 reveals boilerplate SEH setup (__security_init_cookie), CRT initialization (fcn.00401ba0 — likely __scrt_common_main_seh), and a call to main() at 0x0040140f. The main function itself is thin; the heavy lifting is delegated to mscoree!CorBindToRuntimeEx and subsequent .NET assembly resolution. ^[r2:entry0]

No anti-debug, anti-VM, or packing artefacts are present in the native stub. The evasion surface is entirely the valid Authenticode signature and the legitimate ScreenConnect installer logic.

C2 Infrastructure

  • IP: 193.26.115.231
  • Port: 8041
  • Connection string: ?h=193.26.115.231&p=8041&k=BgIAAACkAABSU0ExAAgAAAEAAQAxPYeVPg7eE8YLDkwWCe89HblsflX/djko+4s8sQxc383azfZc1kIVrlBLF9Xpu1af+j0HkRhxK5LaobBLLp3qiqBsSbtErIRefMxFxCv/2Ttd+s7CrRSPxHy1k2CAL/GR0oSXiT+3HNb0FFgW8dgWCSn51u8PFlv6cxuCzaKyQ72y1NCA8O9YjPV8oIULjKGISfq87gXuZb6PPPpn5sbKv088rp0h0eoPNto9If2ftj88f/6REI6Rv3MVpCLvK2kIajMCFHUN6O98csL9PPjjSJ+Mneu1yRHmja+YaQiAaRU8KzSudMhEb2B9QSZ3I4b7EqectT3zA1bffGcdW3e7

The connection string appears twice in plaintext and once XML-escaped inside an embedded .config fragment. ^[strings.txt:20429,20430,21032] The k= parameter is a Base64-encoded RSA public key (spki format, 2048-bit) used for session encryption — consistent with ScreenConnect's standard client behaviour.

This is the fifth distinct C2 IP observed across the cluster. Prior IPs: 134.122.4.2, 104.236.198.16, 45.83.31.225, 84.54.33.84. ^[entities/connectwise.md]

Interesting Tidbits

  1. Certificate vs compile time gap. The PE was compiled in Nov 2022 but carries a DigiCert timestamp signature dated 2024-10-28. The simplest explanation is that the attackers retained stockpiled Nov 2022 builds and re-signed them with a fresh ConnectWise certificate when the old one expired or was revoked. ^[strings.txt:20139]
  2. Identical ProductCode. The MSI ProductCode {B292C5EA-BF5F-4280-B056-1670FB10BB1D} matches prior Nov 2022 siblings, confirming a single WiX project template with parameterised C2. ^[strings.txt:20084]
  3. No ClickOnce bootstrap. Unlike the Apr–May 2025 variants (81adbf9a, 050e5825, etc.), this sample does not import CertAddCertificateContextToStore, CertDeleteCertificateFromStore, or dfshim!ShOpenVerbApplicationW. The trust bootstrap is achieved by the valid Authenticode signature itself — Windows treats the installer as trusted software from a known publisher. ^[pefile.txt:229-333]
  4. Zstandard compression. Strings reference ZSTD_c_experimentalParam, ZSTD_compressStream2, and ZSTD_btultra2, indicating the embedded assemblies use Zstandard for payload compression. ^[strings.txt:6997-7002]

How To Mess With It (Homelab Replication)

  1. Toolchain: Visual Studio 2019/2022 (MSVC 14.33), WiX Toolset v3.x, .NET Framework 2.0/4.0 targeting.
  2. Build a benign analogue: Create a C++ Win32 GUI project that calls CorBindToRuntimeEx(L"v2.0.50727", NULL, 0, ...) and reflectively loads a C# assembly from an RT_RCDATA resource. Use WiX to bundle the output into an MSI with ServiceInstall and Registry tables.
  3. Sign it: Obtain a code-signing certificate (self-signed OK for lab) and sign with signtool.exe /tr http://timestamp.digicert.com /td sha256 /fd sha256.
  4. Verification: On a Windows VM, double-click the signed MSI. SmartScreen should show the publisher name instead of "Unknown publisher." Observe the service registration in services.msc.

Deployable Signatures

YARA rule

rule connectwise_screenconnect_msi_bundle : malware family connectwise {
    meta:
        description = "ConnectWise ScreenConnect MSI-bundle variant (self-contained installer with embedded .NET assemblies)"
        author = "PacketPursuit"
        date = "2026-08-09"
        hash = "aa116a6279aebc383ed7a9321d580f998436e34f06d07f2cb8ac2d7fd876ba60"
        reference = "https://wiki.packetpursuit/entities/connectwise"
    strings:
        $pdb = "cwcontrol\\Custom\\DotNetRunner\\Release\\DotNetRunner.pdb" ascii wide
        $sc_core = "ScreenConnect.Core" ascii wide
        $sc_win = "ScreenConnect.Windows" ascii wide
        $sc_inst = "ScreenConnect.WindowsInstaller" ascii wide
        $product_code = "ProductCode{B292C5EA-BF5F-4280-B056-1670FB10BB1D}" ascii wide
        $auth_pkg = "ScreenConnect.WindowsAuthenticationPackage.dll" ascii wide
        $cred_prov = "ScreenConnect.WindowsCredentialProvider.dll" ascii wide
        $conn_tpl = "?h=" ascii wide
        $conn_port = ":8041" ascii wide
        $zstd1 = "ZSTD_compressStream2" ascii wide
        $zstd2 = "ZSTD_btultra2" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        filesize > 3MB and filesize < 10MB and
        (3 of ($sc_*) or $pdb) and
        ($auth_pkg or $cred_prov or $product_code) and
        (1 of ($zstd*))
}

Sigma rule

title: ConnectWise ScreenConnect MSI Bundle Installer Execution
status: experimental
description: Detects execution of a known ConnectWise ScreenConnect MSI-bundle variant based on service image path and command-line arguments.
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        - Image|endswith: 'ScreenConnect.WindowsClient.exe'
        - Image|endswith: 'ScreenConnect.ClientService.exe'
        - CommandLine|contains: 'ScreenConnect.WindowsClient.exe'
        - CommandLine|contains: 'END_OF_INSTALL_CLIENT_LAUNCH_PARAMETERS'
    condition: selection
falsepositives:
    - Legitimate ScreenConnect installations in enterprise environments (validate against known-good hashes and publisher certificate thumbprints)
level: high

IOC list

Indicator Type Note
aa116a6279aebc383ed7a9321d580f998436e34f06d07f2cb8ac2d7fd876ba60 SHA-256 This sample
e3565ac3b44d7223389e8182df4747b1f21db061 SHA-1
8859c93067029a6515b293523db7d79b MD5
193.26.115.231:8041 IP:Port Hardcoded C2 (new to cluster)
?h=193.26.115.231&p=8041&k=BgIAAACkAABSU0ExAAgAAAEAAQAxPYeVPg7eE8Y... URL Session bootstrap with RSA pubkey
{B292C5EA-BF5F-4280-B056-1670FB10BB1D} MSI ProductCode Shared across Nov 2022 siblings
ScreenConnect.WindowsAuthenticationPackage.dll Filename LSA auth package payload
ScreenConnect.WindowsCredentialProvider.dll Filename Credential provider payload
C:\Users\jmorgan\Source\cwcontrol\Custom\DotNetRunner\Release\DotNetRunner.pdb PDB path Build artefact

Behavioral fingerprint

This binary is a 32-bit PE GUI executable with five sections, a high-entropy .rsrc (~5.4 MB), and a minimal native import table consisting only of KERNEL32.dll, mscoree.dll, and OLEAUT32.dll. It calls CorBindToRuntimeEx to bootstrap the .NET Framework 2.0 runtime, then loads embedded assemblies named ScreenConnect.Core, ScreenConnect.Windows, and ScreenConnect.WindowsInstaller from named RT_RCDATA resources. During installation it registers a Windows service (ScreenConnect.ClientService), adds an LSA authentication package, and installs a Windows Credential Provider DLL. Network traffic, if observed, targets TCP/8041 on a hardcoded IP with an HTTP GET carrying a Base64 RSA public-key parameter (?h=<ip>&p=8041&k=<key>).

Detection Signatures

ATT&CK ID Technique Evidence
T1078 Valid Accounts Authenticode by ConnectWise, LLC ^[strings.txt:20119]
T1219 Remote Access Software Embedded ScreenConnect client assemblies and service ^[strings.txt:20083]
T1105 Ingress Tool Transfer MSI with embedded Cabinet archives in .rsrc ^[binwalk.txt:23,25]
T1543.003 Create/Modify System Process: Windows Service ServiceInstall table + SafeBoot\Network registry ^[strings.txt:20083]
T1003.001 OS Credential Dumping: LSASS Memory LSA Authentication Package registration ^[strings.txt:20083]
T1056.001 Input Capture: Credential API Hooking Credential Provider DLL registration ^[strings.txt:20083]
T1547.012 Boot or Logon Autostart Execution: Print Processors Credential provider CLSID registration ^[strings.txt:20083]
T1071.001 Application Layer Protocol: Web Protocols HTTP to 193.26.115.231:8041 with RSA key parameter ^[strings.txt:20429]

Note: capa analysis failed (missing signatures directory); no capa-derived mappings available for this sample. ^[capa.txt]

References

Provenance

  • file.txt — file command (PE32, 5 sections)
  • pefile.txt — Python pefile (headers, sections, imports, resources)
  • exiftool.json — ExifTool (timestamp, linker version)
  • rabin2-info.txt — radare2 binary info (lang=cil, signed=true, canary=true, nx=true)
  • strings.txt — strings -n 6 (all printable strings)
  • binwalk.txt — binwalk -e signature scan (embedded PEs, Cabinet, zlib)
  • capa.txt — Mandiant capa (failed — missing signatures)
  • radare2 — analysis level 2, entrypoint decompilation (entry0 at 0x004014ad)
  • python3 + cryptography / pefile — certificate extraction and timestamp parsing from IMAGE_DIRECTORY_ENTRY_SECURITY