s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-79965a3946fc049ae7643e7afbab19611cc956948eba9ab2ae72714e8d437c2c high

📛 Threat Title

ConnectWise: ScreenConnect.ClientSetup.exe

Category: ConnectWise First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 11609936 bytes. Tags: ConnectWise, signed. Reporter: BlinkzSec. First seen: 2026-05-13 18:48:30.

Indicators of Compromise (5)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain screenconnect.clientsetup.exe VT: VT base fetch failed: SSLError: HTTPSConnectionPool(host='www.virustotal.com', port=443): Max retries exceeded with url: /api/v3/domains/screenconnect.clientsetup.exe (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate is not yet valid (_ssl.c:992)')))

IOC database

Type
domain
Value
screenconnect.clientsetup.exe
First seen
Last seen
Attached to this threat
Appears in
9 threats
Description
Extracted from Threat MB-efc4186e35021b6367b40de3f875038d045ea89b9e3408e2955fdc7c87d48595

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: SSLError: HTTPSConnectionPool(host='www.virustotal.com', port=443): Max retries exceeded with url: /api/v3/domains/screenconnect.clientsetup.exe (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate is not yet valid (_ssl.c:992)')))

hash_sha256 79965a3946fc049ae7643e7afbab19611cc956948eba9ab2ae72714e8d437c2c VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/79965a3946fc049ae7643e7afbab19611cc956948eba9ab2ae72714e8d437c2c
1 feed

IOC database

Type
hash_sha256
Value
79965a3946fc049ae7643e7afbab19611cc956948eba9ab2ae72714e8d437c2c
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
ConnectWise

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/79965a3946fc049ae7643e7afbab19611cc956948eba9ab2ae72714e8d437c2c

hash_sha1 cc9a52595c593f563a1b60461f95a25002bf3693 VT 38 / 74 2 feeds

IOC database

Type
hash_sha1
Value
cc9a52595c593f563a1b60461f95a25002bf3693
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Flagged by 38 of 74 VirusTotal vendors

VendorVerdictDetection
Alibaba malicious RiskWare:Win32/Screcwon.62baad8c
Antiy-AVL malicious RiskWare[RemoteAdmin]/Win32.ConnectWise
Arcabit malicious Adware.Generic.D3A4DC26
Avast malicious Win32:Evo-gen [Trj]
AVG malicious Win32:Evo-gen [Trj]
Avira malicious TR/W32.Evo
BitDefender malicious Adware.GenericKD.61135910
CTX malicious exe.adware.generic
Cylance malicious Unsafe
DeepInstinct malicious MALICIOUS
DrWeb malicious Adware.Downware.19741
Elastic malicious malicious (high confidence)
Emsisoft malicious Adware.GenericKD.61135910 (B)
ESET-NOD32 malicious Win32/RemoteAdmin.ConnectWiseControl.Q potentially unsafe application
F-Secure malicious Trojan.TR/W32.Evo
Fortinet malicious Riskware/RemoteAdmin_ConnectWiseControl
GData malicious Adware.GenericKD.61135910
Gridinsoft malicious Trojan.Win32.MultiInjector.dd!s1
Ikarus malicious PUA.ScreenConnect
Jiangmin malicious Trojan.Agent.edgo
K7AntiVirus malicious RemoteTool ( 005d29b61 )
K7GW malicious RemoteTool ( 005d29b61 )
Kaspersky malicious UDS:DangerousObject.Multi.Generic
Kingsoft malicious Win32.HACKTOOL.RemoteAdmin.v
Lionic malicious Hacktool.Win32.Generic.3!c
MaxSecure malicious Trojan.Malware.121218.susgen
McAfeeD malicious ti!79965A3946FC
Microsoft malicious Trojan:Win32/Wacatac.C!ml
MicroWorld-eScan malicious Adware.GenericKD.61135910
Paloalto malicious generic.ml
Panda malicious Trj/PhxBzA.A
Rising malicious Hacktool.ConnectWiseControl!8.17790 (CLOUD)
SentinelOne malicious Static AI - Suspicious PE
Sophos malicious Generic Reputation PUA (PUA)
Symantec malicious ML.Attribute.HighConfidence
TrellixENS malicious Artemis!C8E538539A24
VBA32 malicious BScope.Riskware.ConnectWise
Yandex malicious Riskware.RemoteAdmin!O4vT/8AeK2A

Details From VirusTotal

Basic Properties
MD5c8e538539a2426fe6ed8d19bc75a65ef
SHA-1cc9a52595c593f563a1b60461f95a25002bf3693
SHA-25679965a3946fc049ae7643e7afbab19611cc956948eba9ab2ae72714e8d437c2c
VHash017056655d15756az459z6tz
SSDEEP98304:nRDRs6efPwbpiTBNxNBWHTGS0h7276VpiTBNxNBWHbpiTBNxNBWHhpiTBNxNBWHE:nRdfefPwbK5eqyAK5sK5GK5WK5P
TLSHT125C61201B3DA49B9D5BF0A78E87A41549B35BC049B12C7AF53947D6D2D32BC08A323B7
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386, for MS Windows
File size11.1 MB
History
Creation date2022-11-18 20:10 UTC
First seen on VirusTotal2026-05-13 18:50 UTC
Last submission2026-05-15 01:42 UTC
Last analysis2026-05-15 10:12 UTC
Last modified on VirusTotal2026-05-21 21:30 UTC
Known Names
  • 79965a3946fc049ae7643e7afbab19611cc956948eba9ab2ae72714e8d437c2c.exe
  • hadu3.exe
  • ScreenConnect.ClientSetup.exe
  • _79965a3946fc049ae7643e7afbab19611cc956948eba9ab2ae72714e8d437c2c.exe
hash_md5 c8e538539a2426fe6ed8d19bc75a65ef VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/c8e538539a2426fe6ed8d19bc75a65ef
2 feeds

IOC database

Type
hash_md5
Value
c8e538539a2426fe6ed8d19bc75a65ef
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/c8e538539a2426fe6ed8d19bc75a65ef

hash_imphash 9771ee6344923fa220489ab01239bdfd

IOC database

Type
hash_imphash
Value
9771ee6344923fa220489ab01239bdfd
First seen
Last seen
Attached to this threat
Appears in
145 threats
Description
imphash of URLhaus payload 997a09b5cbbebd7e…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 11609936 bytes. Tags: ConnectWise, signed. Reporter: BlinkzSec. First seen: 2026-05-13 18:48:30.

Remediations (8)

  • web:cyberpress.org

    Escalate privileges to gain domain-level control Given the role of ScreenConnect in managed service provider (MSP) environments, exploitation could also enable supply chain-style attacks, impacting multiple downstream clients. Mitigation Deadlines and CISA Directive CISA has mandated that federal agencies remediate the vulnerability by May 12 ...

  • web:cybersecuritynews.com

    Attackers abuse ConnectWise ScreenConnect RMM tool via phishing, using fake IT alerts and invite links to gain stealthy access.

  • web:services.google.com

    Summary This document contains remediation and hardening recommendations for responding to critical vulnerabilites for the ConnectWise ScreenConnect application announced on February 19, 2024.

  • web:sunilgentyala.substack.com

    Upon execution, these installers instantiate ScreenConnect.ClientSetup.exe with command-line parameters directing connectivity toward adversary-controlled command-and-control infrastructure, immediately subordinating victim hosts to malicious ScreenConnect server instances.

  • web:www.acronis.com

    Over the past months, Acronis TRU (Threat Research Unit) has identified multiple active and ongoing campaigns leveraging trojanized versions of ConnectWise ScreenConnect to gain initial access to victim networks and compromise target machines.

  • web:www.connectwise.com

    To assist in the remediation and hardening process, we encourage partners to review and follow the ConnectWise ScreenConnect Remediation and Hardening Guide by Mandiant for additional protection.

  • web:www.forcepoint.com

    ScreenConnect.ClientService.exe is a part of the ScreenConnect tool made by ConnectWise . It runs in the background and allows someone to remotely access or control your computer for support or meetings.

  • web:www.microsoft.com

    Signed malware backed by a stolen EV certificate deployed legitimate RMM tools to gain persistent access inside enterprise environments. Organizations must harden certificate controls and monitor RMM activity to reduce exposure.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.