s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-0a87ca87a3d93286a61ae239db29c91a9d60430d1377d80603e2f77d60b2c2b8 high

📛 Threat Title

ConnectWise: support.client.exe

Category: ConnectWise First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 312568 bytes. Tags: ConnectWise, signed. Reporter: BlinkzSec. First seen: 2026-05-13 18:48:26.

Indicators of Compromise (5)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain support.client.exe VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/support.client.exe

IOC database

Type
domain
Value
support.client.exe
First seen
Last seen
Attached to this threat
Appears in
10 threats
Description
Extracted from Threat MB-d9fbcad42aaf846845c6c04550e5c010903112eedccd901c43c0a7a9be1bf2eb

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/support.client.exe

hash_sha256 0a87ca87a3d93286a61ae239db29c91a9d60430d1377d80603e2f77d60b2c2b8 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/0a87ca87a3d93286a61ae239db29c91a9d60430d1377d80603e2f77d60b2c2b8
1 feed

IOC database

Type
hash_sha256
Value
0a87ca87a3d93286a61ae239db29c91a9d60430d1377d80603e2f77d60b2c2b8
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
ConnectWise

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/0a87ca87a3d93286a61ae239db29c91a9d60430d1377d80603e2f77d60b2c2b8

hash_sha1 0152a542b34122a58d206c8d7abe5a7d6b756563 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/0152a542b34122a58d206c8d7abe5a7d6b756563
2 feeds

IOC database

Type
hash_sha1
Value
0152a542b34122a58d206c8d7abe5a7d6b756563
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/0152a542b34122a58d206c8d7abe5a7d6b756563

hash_md5 2d010c9664f9905a3cec8b0a605365e2 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/2d010c9664f9905a3cec8b0a605365e2
2 feeds

IOC database

Type
hash_md5
Value
2d010c9664f9905a3cec8b0a605365e2
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/2d010c9664f9905a3cec8b0a605365e2

hash_imphash c2fe6927e1db8cf00400dbef9e5d35be

IOC database

Type
hash_imphash
Value
c2fe6927e1db8cf00400dbef9e5d35be
First seen
Last seen
Attached to this threat
Appears in
118 threats
Description
imphash of URLhaus payload 75b337e70eed4a26…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 312568 bytes. Tags: ConnectWise, signed. Reporter: BlinkzSec. First seen: 2026-05-13 18:48:26.

Remediations (10)

  • web:blog.gdatasoftware.com

    Since March 2025, there has been a noticeable increase in infections and fake applications using validly signed ConnectWise samples. We reveal how bad signing practices allow threat actors to abuse this legitimate software to build and distribute their own signed malware and what security vendors can do to detect them.

  • web:cybersecuritynews.com

    Threat actors have been leveraging the legitimate Remote Monitoring and Management (RMM) tool, ScreenConnect, to establish persistence in their cyberattacks. This trend shows the evolving tactics of hackers who exploit trusted software to gain unauthorized access to systems. ScreenConnect, now known as ConnectWise Control, is a widely used RMM tool that allows IT teams to manage and monitor ...

  • web:services.google.com

    Summary This document contains remediation and hardening recommendations for responding to critical vulnerabilites for the ConnectWise ScreenConnect application announced on February 19, 2024.

  • web:steveit.ca

    Scam Remote In Hidden remote software with support.client.exe Had a few clients that got scammed for people to remote into their PC. Indication that its a scam is when they have a support.client.exe file in their download folder. What this does is installs ConnectWise screenconnect service.

  • web:threatchain.hashnode.dev

    Check for the filenamesupport.client.exe in recently downloaded files, email attachments, and installer bundles. Look for outbound connections to uncommon TLDs or newly registered domains — ConnectWise typically beacons to command-and-control infrastructure shortly after execution.

  • web:www.connectwise.com

    Remediation efforts for ConnectWise PSA™ are ongoing. In the meantime, we recommend using the web client instead of the thick client to reduce exposure risk Reports and Dashboards (formerly BrightGauge™), SmileBack™, ConnectWise CPQ™, ConnectWise Automate™, Asio™ platform, and security services are not directly impacted

  • web:www.cyberproof.com

    Further investigations led to collection of possible related IOCs, one is a malicious webpage [www.helpw8.top] impersonating customer support leading to download and execution of malicious dropper using file name Support.Client (1).exe.

  • web:www.malwarebytes.com

    Fake emails pretending to come from the US Social Security Administration (SSA) try to get targets to install ScreenConnect, a remote access tool. This campaign was flagged and investigated by the Malwarebytes Customer Support and Research teams. ScreenConnect, formerly known as ConnectWise Control, is a remote support and remote access platform widely used by businesses to facilitate IT ...

  • web:www.pcrisk.com

    What is ScreenConnect ( ConnectWise ) Client scam? Fraudsters use all kinds of ways to extract information or money from people and distribute malicious programs via emails. This article describes cases where fraudsters use emails to trick recipients into installing ConnectWise (formerly known as ScreenConnect).

  • web:www.reddit.com

    When inspecting the computer, I see a file named support.Client.exe as well as what looks like a full installation of Screen Connect within the app data folder. The installation time of Screen Connect appears to coincide with the time that my family member was in a call with the scammmers.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.