aa116a6279aebc383ed7a9321d580f998436e34f06d07f2cb8ac2d7fd876ba60connectwise: aa116a62 — tenth confirmed sibling, new C2 193.26.115.231:8041, Oct 2024 cert timestamp
Executive Summary
Self-contained MSI-bundle variant of the ConnectWise ScreenConnect abuse cluster. PE32 wrapper compiled Nov 2022 (MSVC 14.33) embeds .NET 2.0 assemblies via mscoree!CorBindToRuntimeEx, then drives a full WiX-based MSI install registering services, credential providers, and an LSA authentication package. Valid Authenticode by ConnectWise, LLC. The hardcoded C2 endpoint 193.26.115.231:8041 is new to this cluster. Certificate timestamping signature is dated 2024-10-28 — roughly two years after compilation, suggesting either delayed signing or preserved build-time artefacts. Static-only; CAPE skipped (no Windows guest).
What It Is
| Field | Value |
|---|---|
| SHA-256 | aa116a6279aebc383ed7a9321d580f998436e34f06d07f2cb8ac2d7fd876ba60 |
| SHA-1 | e3565ac3b44d7223389e8182df4747b1f21db061 |
| MD5 | 8859c93067029a6515b293523db7d79b |
| Size | 5.64 MB (5,640,960 bytes) |
| Type | PE32 executable (GUI) Intel 80386, 5 sections ^[file.txt] |
| Compile time | Fri Nov 18 20:10:20 2022 UTC ^[pefile.txt:34] |
| Cert timestamp | 2024-10-28T17:44:14 UTC (PKCS#7 signingTime) ^[strings.txt:20139] |
| Signer | ConnectWise, LLC — DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA ^[strings.txt:20119] |
| Linker | MSVC 14.33 (Visual Studio 2019/2022) ^[exiftool.json:18] |
| Subsystem | Windows GUI ^[exiftool.json:26] |
| PDB | C:\Users\jmorgan\Source\cwcontrol\Custom\DotNetRunner\Release\DotNetRunner.pdb ^[strings.txt:125] |
| ProductCode | {B292C5EA-BF5F-4280-B056-1670FB10BB1D} ^[strings.txt:20084] |
| ScreenConnect version | 24.3.7.9067 ^[strings.txt:20083] |
This is the tenth confirmed sibling in the ConnectWise abuse cluster, joining the Nov 2022 MSI-bundle Variant A lineage (7145e8, b831f47e, 8c8e60af, 73a8126b). The compile timestamp, PDB path, ProductCode, and assembly version all match the Nov 2022 batch exactly; only the hardcoded C2 IP and the SHA-256 differ. ^[entities/connectwise.md]
How It Works
The outer PE32 is a C/C++ bootstrap stub (DotNetRunner) with a minimal import table (KERNEL32.dll, mscoree.dll, OLEAUT32.dll). On launch it calls CorBindToRuntimeEx to spin up the CLR, loads embedded .NET assemblies from the .rsrc section, and hands execution to the ScreenConnect client installer logic. ^[pefile.txt:239]
The .rsrc section (~5.4 MB, entropy 7.45) contains five named assembly streams: ^[pefile.txt:334-454]
SCREENCONNECT.CORE, VERSION=24.3.7.9067, CULTURE=NEUTRAL, PUBLICKEYTOKEN=4B14C015C87C1AD8SCREENCONNECT.WINDOWS, VERSION=24.3.7.9067, CULTURE=NEUTRAL, PUBLICKEYTOKEN=4B14C015C87C1AD8SCREENCONNECT.WINDOWSINSTALLER, VERSION=24.3.7.9067, CULTURE=NEUTRAL, PUBLICKEYTOKEN=4B14C015C87C1AD8_ENTRYPOINT_RESOLVER
binwalk identifies two Cabinet archives inside the resource blob (1.66 MB / 14 files at 0x25F54C, and 949 KB / 8 files at 0x41734C), consistent with a WiX-generated MSI payload. ^[binwalk.txt:23,25]
The MSI database tables observed in strings include ServiceInstall, Component, File, Registry, CustomAction, Upgrade, LaunchCondition, and FeatureComponents. ^[strings.txt:20083] Installation artefacts include:
- Windows service registration (
ScreenConnect.ClientService.exe) withSafeBoot\Networkpersistence - LSA Authentication Package registration (
ScreenConnect.WindowsAuthenticationPackage.dll) - Windows Credential Provider registration (
ScreenConnect.WindowsCredentialProvider.dll) - URL-scheme handler (
[URL_SCHEME]\shell\open\command→ScreenConnect.WindowsClient.exe)
Decompiled Behavior
radare2 analysis (level 2, 478 functions) shows a standard MSVC CRT entry-point at 0x004014ad. ^[rabin2-info.txt:9]
0x00401140 main
0x004014ad entry0
Decompilation of entry0 reveals boilerplate SEH setup (__security_init_cookie), CRT initialization (fcn.00401ba0 — likely __scrt_common_main_seh), and a call to main() at 0x0040140f. The main function itself is thin; the heavy lifting is delegated to mscoree!CorBindToRuntimeEx and subsequent .NET assembly resolution. ^[r2:entry0]
No anti-debug, anti-VM, or packing artefacts are present in the native stub. The evasion surface is entirely the valid Authenticode signature and the legitimate ScreenConnect installer logic.
C2 Infrastructure
- IP:
193.26.115.231 - Port:
8041 - Connection string:
?h=193.26.115.231&p=8041&k=BgIAAACkAABSU0ExAAgAAAEAAQAxPYeVPg7eE8YLDkwWCe89HblsflX/djko+4s8sQxc383azfZc1kIVrlBLF9Xpu1af+j0HkRhxK5LaobBLLp3qiqBsSbtErIRefMxFxCv/2Ttd+s7CrRSPxHy1k2CAL/GR0oSXiT+3HNb0FFgW8dgWCSn51u8PFlv6cxuCzaKyQ72y1NCA8O9YjPV8oIULjKGISfq87gXuZb6PPPpn5sbKv088rp0h0eoPNto9If2ftj88f/6REI6Rv3MVpCLvK2kIajMCFHUN6O98csL9PPjjSJ+Mneu1yRHmja+YaQiAaRU8KzSudMhEb2B9QSZ3I4b7EqectT3zA1bffGcdW3e7
The connection string appears twice in plaintext and once XML-escaped inside an embedded .config fragment. ^[strings.txt:20429,20430,21032] The k= parameter is a Base64-encoded RSA public key (spki format, 2048-bit) used for session encryption — consistent with ScreenConnect's standard client behaviour.
This is the fifth distinct C2 IP observed across the cluster. Prior IPs: 134.122.4.2, 104.236.198.16, 45.83.31.225, 84.54.33.84. ^[entities/connectwise.md]
Interesting Tidbits
- Certificate vs compile time gap. The PE was compiled in Nov 2022 but carries a DigiCert timestamp signature dated 2024-10-28. The simplest explanation is that the attackers retained stockpiled Nov 2022 builds and re-signed them with a fresh ConnectWise certificate when the old one expired or was revoked. ^[strings.txt:20139]
- Identical ProductCode. The MSI ProductCode
{B292C5EA-BF5F-4280-B056-1670FB10BB1D}matches prior Nov 2022 siblings, confirming a single WiX project template with parameterised C2. ^[strings.txt:20084] - No ClickOnce bootstrap. Unlike the Apr–May 2025 variants (
81adbf9a,050e5825, etc.), this sample does not importCertAddCertificateContextToStore,CertDeleteCertificateFromStore, ordfshim!ShOpenVerbApplicationW. The trust bootstrap is achieved by the valid Authenticode signature itself — Windows treats the installer as trusted software from a known publisher. ^[pefile.txt:229-333] - Zstandard compression. Strings reference
ZSTD_c_experimentalParam,ZSTD_compressStream2, andZSTD_btultra2, indicating the embedded assemblies use Zstandard for payload compression. ^[strings.txt:6997-7002]
How To Mess With It (Homelab Replication)
- Toolchain: Visual Studio 2019/2022 (MSVC 14.33), WiX Toolset v3.x, .NET Framework 2.0/4.0 targeting.
- Build a benign analogue: Create a C++ Win32 GUI project that calls
CorBindToRuntimeEx(L"v2.0.50727", NULL, 0, ...)and reflectively loads a C# assembly from an RT_RCDATA resource. Use WiX to bundle the output into an MSI withServiceInstallandRegistrytables. - Sign it: Obtain a code-signing certificate (self-signed OK for lab) and sign with
signtool.exe /tr http://timestamp.digicert.com /td sha256 /fd sha256. - Verification: On a Windows VM, double-click the signed MSI. SmartScreen should show the publisher name instead of "Unknown publisher." Observe the service registration in
services.msc.
Deployable Signatures
YARA rule
rule connectwise_screenconnect_msi_bundle : malware family connectwise {
meta:
description = "ConnectWise ScreenConnect MSI-bundle variant (self-contained installer with embedded .NET assemblies)"
author = "PacketPursuit"
date = "2026-08-09"
hash = "aa116a6279aebc383ed7a9321d580f998436e34f06d07f2cb8ac2d7fd876ba60"
reference = "https://wiki.packetpursuit/entities/connectwise"
strings:
$pdb = "cwcontrol\\Custom\\DotNetRunner\\Release\\DotNetRunner.pdb" ascii wide
$sc_core = "ScreenConnect.Core" ascii wide
$sc_win = "ScreenConnect.Windows" ascii wide
$sc_inst = "ScreenConnect.WindowsInstaller" ascii wide
$product_code = "ProductCode{B292C5EA-BF5F-4280-B056-1670FB10BB1D}" ascii wide
$auth_pkg = "ScreenConnect.WindowsAuthenticationPackage.dll" ascii wide
$cred_prov = "ScreenConnect.WindowsCredentialProvider.dll" ascii wide
$conn_tpl = "?h=" ascii wide
$conn_port = ":8041" ascii wide
$zstd1 = "ZSTD_compressStream2" ascii wide
$zstd2 = "ZSTD_btultra2" ascii wide
condition:
uint16(0) == 0x5A4D and
filesize > 3MB and filesize < 10MB and
(3 of ($sc_*) or $pdb) and
($auth_pkg or $cred_prov or $product_code) and
(1 of ($zstd*))
}
Sigma rule
title: ConnectWise ScreenConnect MSI Bundle Installer Execution
status: experimental
description: Detects execution of a known ConnectWise ScreenConnect MSI-bundle variant based on service image path and command-line arguments.
logsource:
category: process_creation
product: windows
detection:
selection:
- Image|endswith: 'ScreenConnect.WindowsClient.exe'
- Image|endswith: 'ScreenConnect.ClientService.exe'
- CommandLine|contains: 'ScreenConnect.WindowsClient.exe'
- CommandLine|contains: 'END_OF_INSTALL_CLIENT_LAUNCH_PARAMETERS'
condition: selection
falsepositives:
- Legitimate ScreenConnect installations in enterprise environments (validate against known-good hashes and publisher certificate thumbprints)
level: high
IOC list
| Indicator | Type | Note |
|---|---|---|
aa116a6279aebc383ed7a9321d580f998436e34f06d07f2cb8ac2d7fd876ba60 |
SHA-256 | This sample |
e3565ac3b44d7223389e8182df4747b1f21db061 |
SHA-1 | |
8859c93067029a6515b293523db7d79b |
MD5 | |
193.26.115.231:8041 |
IP:Port | Hardcoded C2 (new to cluster) |
?h=193.26.115.231&p=8041&k=BgIAAACkAABSU0ExAAgAAAEAAQAxPYeVPg7eE8Y... |
URL | Session bootstrap with RSA pubkey |
{B292C5EA-BF5F-4280-B056-1670FB10BB1D} |
MSI ProductCode | Shared across Nov 2022 siblings |
ScreenConnect.WindowsAuthenticationPackage.dll |
Filename | LSA auth package payload |
ScreenConnect.WindowsCredentialProvider.dll |
Filename | Credential provider payload |
C:\Users\jmorgan\Source\cwcontrol\Custom\DotNetRunner\Release\DotNetRunner.pdb |
PDB path | Build artefact |
Behavioral fingerprint
This binary is a 32-bit PE GUI executable with five sections, a high-entropy .rsrc (~5.4 MB), and a minimal native import table consisting only of KERNEL32.dll, mscoree.dll, and OLEAUT32.dll. It calls CorBindToRuntimeEx to bootstrap the .NET Framework 2.0 runtime, then loads embedded assemblies named ScreenConnect.Core, ScreenConnect.Windows, and ScreenConnect.WindowsInstaller from named RT_RCDATA resources. During installation it registers a Windows service (ScreenConnect.ClientService), adds an LSA authentication package, and installs a Windows Credential Provider DLL. Network traffic, if observed, targets TCP/8041 on a hardcoded IP with an HTTP GET carrying a Base64 RSA public-key parameter (?h=<ip>&p=8041&k=<key>).
Detection Signatures
| ATT&CK ID | Technique | Evidence |
|---|---|---|
| T1078 | Valid Accounts | Authenticode by ConnectWise, LLC ^[strings.txt:20119] |
| T1219 | Remote Access Software | Embedded ScreenConnect client assemblies and service ^[strings.txt:20083] |
| T1105 | Ingress Tool Transfer | MSI with embedded Cabinet archives in .rsrc ^[binwalk.txt:23,25] |
| T1543.003 | Create/Modify System Process: Windows Service | ServiceInstall table + SafeBoot\Network registry ^[strings.txt:20083] |
| T1003.001 | OS Credential Dumping: LSASS Memory | LSA Authentication Package registration ^[strings.txt:20083] |
| T1056.001 | Input Capture: Credential API Hooking | Credential Provider DLL registration ^[strings.txt:20083] |
| T1547.012 | Boot or Logon Autostart Execution: Print Processors | Credential provider CLSID registration ^[strings.txt:20083] |
| T1071.001 | Application Layer Protocol: Web Protocols | HTTP to 193.26.115.231:8041 with RSA key parameter ^[strings.txt:20429] |
Note: capa analysis failed (missing signatures directory); no capa-derived mappings available for this sample. ^[capa.txt]
References
- Artifact ID:
a71b726d-3b55-4d6f-bc57-6bab8a4d7531 - Source: OpenCTI (abuse.ch URLhaus connector), label
connectwise - Related wiki pages: connectwise, clickonce-certificate-trust-bootstrap, legitimate-remote-access-tool-abuse
Provenance
file.txt—filecommand (PE32, 5 sections)pefile.txt— Python pefile (headers, sections, imports, resources)exiftool.json— ExifTool (timestamp, linker version)rabin2-info.txt— radare2 binary info (lang=cil, signed=true, canary=true, nx=true)strings.txt—strings -n 6(all printable strings)binwalk.txt—binwalk -esignature scan (embedded PEs, Cabinet, zlib)capa.txt— Mandiant capa (failed — missing signatures)radare2— analysis level 2, entrypoint decompilation (entry0at0x004014ad)python3+cryptography/pefile— certificate extraction and timestamp parsing fromIMAGE_DIRECTORY_ENTRY_SECURITY