MB-0a87ca87a3d93286a61ae239db29c91a9d60430d1377d80603e2f77d60b2c2b8
high
📛 Threat Title
ConnectWise: support.client.exe
Description
File type: exe. Size: 312568 bytes. Tags: ConnectWise, signed. Reporter: BlinkzSec. First seen: 2026-05-13 18:48:26.
Indicators of Compromise (5)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
support.client.exe
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/support.client.exe
IOC database
- Type
- domain
- Value
support.client.exe- First seen
- Last seen
- Attached to this threat
- Appears in
- 10 threats
- Description
- Extracted from Threat MB-d9fbcad42aaf846845c6c04550e5c010903112eedccd901c43c0a7a9be1bf2eb
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/support.client.exe
hash_sha256
0a87ca87a3d93286a61ae239db29c91a9d60430d1377d80603e2f77d60b2c2b8
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/0a87ca87a3d93286a61ae239db29c91a9d60430d1377d80603e2f77d60b2c2b8
1 feed
IOC database
- Type
- hash_sha256
- Value
0a87ca87a3d93286a61ae239db29c91a9d60430d1377d80603e2f77d60b2c2b8- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ConnectWise
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/0a87ca87a3d93286a61ae239db29c91a9d60430d1377d80603e2f77d60b2c2b8
hash_sha1
0152a542b34122a58d206c8d7abe5a7d6b756563
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/0152a542b34122a58d206c8d7abe5a7d6b756563
2 feeds
IOC database
- Type
- hash_sha1
- Value
0152a542b34122a58d206c8d7abe5a7d6b756563- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/0152a542b34122a58d206c8d7abe5a7d6b756563
hash_md5
2d010c9664f9905a3cec8b0a605365e2
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/2d010c9664f9905a3cec8b0a605365e2
2 feeds
IOC database
- Type
- hash_md5
- Value
2d010c9664f9905a3cec8b0a605365e2- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/2d010c9664f9905a3cec8b0a605365e2
hash_imphash
c2fe6927e1db8cf00400dbef9e5d35be
IOC database
- Type
- hash_imphash
- Value
c2fe6927e1db8cf00400dbef9e5d35be- First seen
- Last seen
- Attached to this threat
- Appears in
- 118 threats
- Description
- imphash of URLhaus payload 75b337e70eed4a26…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 312568 bytes. Tags: ConnectWise, signed. Reporter: BlinkzSec. First seen: 2026-05-13 18:48:26.
Remediations (10)
-
web:blog.gdatasoftware.com
Since March 2025, there has been a noticeable increase in infections and fake applications using validly signed ConnectWise samples. We reveal how bad signing practices allow threat actors to abuse this legitimate software to build and distribute their own signed malware and what security vendors can do to detect them.
-
web:cybersecuritynews.com
Threat actors have been leveraging the legitimate Remote Monitoring and Management (RMM) tool, ScreenConnect, to establish persistence in their cyberattacks. This trend shows the evolving tactics of hackers who exploit trusted software to gain unauthorized access to systems. ScreenConnect, now known as ConnectWise Control, is a widely used RMM tool that allows IT teams to manage and monitor ...
-
web:services.google.com
Summary This document contains remediation and hardening recommendations for responding to critical vulnerabilites for the ConnectWise ScreenConnect application announced on February 19, 2024.
-
web:steveit.ca
Scam Remote In Hidden remote software with support.client.exe Had a few clients that got scammed for people to remote into their PC. Indication that its a scam is when they have a support.client.exe file in their download folder. What this does is installs ConnectWise screenconnect service.
-
web:threatchain.hashnode.dev
Check for the filenamesupport.client.exe in recently downloaded files, email attachments, and installer bundles. Look for outbound connections to uncommon TLDs or newly registered domains — ConnectWise typically beacons to command-and-control infrastructure shortly after execution.
-
web:www.connectwise.com
Remediation efforts for ConnectWise PSA™ are ongoing. In the meantime, we recommend using the web client instead of the thick client to reduce exposure risk Reports and Dashboards (formerly BrightGauge™), SmileBack™, ConnectWise CPQ™, ConnectWise Automate™, Asio™ platform, and security services are not directly impacted
-
web:www.cyberproof.com
Further investigations led to collection of possible related IOCs, one is a malicious webpage [www.helpw8.top] impersonating customer support leading to download and execution of malicious dropper using file name Support.Client (1).exe.
-
web:www.malwarebytes.com
Fake emails pretending to come from the US Social Security Administration (SSA) try to get targets to install ScreenConnect, a remote access tool. This campaign was flagged and investigated by the Malwarebytes Customer Support and Research teams. ScreenConnect, formerly known as ConnectWise Control, is a remote support and remote access platform widely used by businesses to facilitate IT ...
-
web:www.pcrisk.com
What is ScreenConnect ( ConnectWise ) Client scam? Fraudsters use all kinds of ways to extract information or money from people and distribute malicious programs via emails. This article describes cases where fraudsters use emails to trick recipients into installing ConnectWise (formerly known as ScreenConnect).
-
web:www.reddit.com
When inspecting the computer, I see a file named support.Client.exe as well as what looks like a full installation of Screen Connect within the app data folder. The installation time of Screen Connect appears to coincide with the time that my family member was in a call with the scammmers.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.