MB-c3a385fea4294dda9da4bcb3f3f15a6ea64fd66511985a52f8ecca248541e8ff
high
📛 Threat Title
ConnectWise: support.client.exe
Description
File type: exe. Size: 83184 bytes. Tags: ConnectWise, signed. Reporter: BlinkzSec. First seen: 2026-05-15 11:49:55.
Indicators of Compromise (5)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
support.client.exe
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/support.client.exe
IOC database
- Type
- domain
- Value
support.client.exe- First seen
- Last seen
- Attached to this threat
- Appears in
- 10 threats
- Description
- Extracted from Threat MB-d9fbcad42aaf846845c6c04550e5c010903112eedccd901c43c0a7a9be1bf2eb
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/support.client.exe
hash_sha256
c3a385fea4294dda9da4bcb3f3f15a6ea64fd66511985a52f8ecca248541e8ff
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/c3a385fea4294dda9da4bcb3f3f15a6ea64fd66511985a52f8ecca248541e8ff
1 feed
IOC database
- Type
- hash_sha256
- Value
c3a385fea4294dda9da4bcb3f3f15a6ea64fd66511985a52f8ecca248541e8ff- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Unknown
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/c3a385fea4294dda9da4bcb3f3f15a6ea64fd66511985a52f8ecca248541e8ff
hash_sha1
e7443e15af57fb225f3ddc9cda5955ad3bbcb517
1 feed
IOC database
- Type
- hash_sha1
- Value
e7443e15af57fb225f3ddc9cda5955ad3bbcb517- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
a9e2c397c9a018e3e64e5365d5b6fbe7
VT 40 / 75
1 feed
IOC database
- Type
- hash_md5
- Value
a9e2c397c9a018e3e64e5365d5b6fbe7- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 40 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Malware/Win.Generic.C5884423 |
| Alibaba | malicious | RiskWare:Win32/ConnectWise.440ded0a |
| ALYac | malicious | Application.Scam.SConnect.GenericKD.678 |
| Antiy-AVL | malicious | RiskWare[RemoteAdmin]/Win32.ConnectWise |
| Arcabit | malicious | Application.Scam.SConnect.Generic.678 |
| Avast | malicious | FileRepMalware [Misc] |
| AVG | malicious | FileRepMalware [Misc] |
| Avira | malicious | TR/Malware |
| BitDefender | malicious | Application.Scam.SConnect.GenericKD.678 |
| Bkav | malicious | W32.Malware.310305CB |
| CTX | malicious | exe.trojan.connectwise |
| Cynet | malicious | Malicious (score: 99) |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | Tool.ConnectWise.1 |
| Elastic | malicious | malicious (high confidence) |
| Emsisoft | malicious | Application.Scam.SConnect.GenericKD.678 (B) |
| F-Secure | malicious | Trojan.TR/Malware |
| Fortinet | malicious | Riskware/ScreenConnect |
| malicious | Detected |
|
| Ikarus | malicious | Trojan.Win32.Qwexlafiba |
| Jiangmin | malicious | RemoteAdmin.ConnectWise.m |
| K7AntiVirus | malicious | Riskware ( 00584baa1 ) |
| K7GW | malicious | Riskware ( 00584baa1 ) |
| Kaspersky | malicious | not-a-virus:HEUR:RemoteAdmin.Win32.ConnectWise.gen |
| Kingsoft | malicious | Win32.HACKTOOL.RemoteAdmin.v |
| Lionic | malicious | Riskware.Win32.ConnectWise.1!c |
| Malwarebytes | malicious | Generic.Malware/Suspicious |
| Microsoft | malicious | Trojan:Win32/Qwexlafiba!rfn |
| MicroWorld-eScan | malicious | Application.Scam.SConnect.GenericKD.678 |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/PhxBzA.A |
| Rising | malicious | Trojan.RemoteAdmin!8.D7F6 (TFE:5:S0IiEqXsGa) |
| Symantec | malicious | ML.Attribute.HighConfidence |
| Tencent | malicious | HackTool.Win32.ConnectWise.ha |
| TrellixENS | malicious | ScreenConnect |
| TrendMicro | malicious | TROJ_FRS.VSNTEI26 |
| TrendMicro-HouseCall | malicious | TROJ_FRS.VSNTEI26 |
| Varist | malicious | W32/ConnectWise.N.gen!Eldorado |
| VBA32 | malicious | BScope.Trojan.Wacatac |
| VIPRE | malicious | Application.Scam.SConnect.GenericKD.678 |
Details From VirusTotal
Basic Properties
| MD5 | a9e2c397c9a018e3e64e5365d5b6fbe7 |
| SHA-1 | e7443e15af57fb225f3ddc9cda5955ad3bbcb517 |
| SHA-256 | c3a385fea4294dda9da4bcb3f3f15a6ea64fd66511985a52f8ecca248541e8ff |
| VHash | 084056655d155565z92z44!z |
| SSDEEP | 1536:6xoG6KpY6Qi3yj2wyq4HwiMO10HVLCJRpsWr6cdaWPBJYYT77JU:IenkyfPAwiMq0RqRfbaWZJYYTxU |
| TLSH | T195836C43B5D18876E9720E3118B1D9B4593FBE110E648EAF7398422E0F351D19E3AE7B |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386, for MS Windows |
| File size | 81.2 KB |
History
| Creation date | 2024-10-28 17:41 UTC |
| First seen on VirusTotal | 2026-05-15 11:50 UTC |
| Last submission | 2026-05-15 11:50 UTC |
| Last analysis | 2026-05-20 07:27 UTC |
| Last modified on VirusTotal | 2026-05-20 10:37 UTC |
Known Names
support.client.exe_c3a385fea4294dda9da4bcb3f3f15a6ea64fd66511985a52f8ecca248541e8ff.exehnnnrsdlh.exe
hash_imphash
37d5c89163970dd3cc69230538a1b72b
IOC database
- Type
- hash_imphash
- Value
37d5c89163970dd3cc69230538a1b72b- First seen
- Last seen
- Attached to this threat
- Appears in
- 15 threats
- Description
- imphash of URLhaus payload b5903061132c7f84…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 83184 bytes. Tags: signed. Reporter: BlinkzSec. First seen: 2026-05-15 11:49:55.
Remediations (10)
-
web:blog.gdatasoftware.com
Since March 2025, there has been a noticeable increase in infections and fake applications using validly signed ConnectWise samples. We reveal how bad signing practices allow threat actors to abuse this legitimate software to build and distribute their own signed malware and what security vendors can do to detect them.
-
web:cybersecuritynews.com
Threat actors have been leveraging the legitimate Remote Monitoring and Management (RMM) tool, ScreenConnect, to establish persistence in their cyberattacks. This trend shows the evolving tactics of hackers who exploit trusted software to gain unauthorized access to systems. ScreenConnect, now known as ConnectWise Control, is a widely used RMM tool that allows IT teams to manage and monitor ...
-
web:services.google.com
Summary This document contains remediation and hardening recommendations for responding to critical vulnerabilites for the ConnectWise ScreenConnect application announced on February 19, 2024.
-
web:steveit.ca
Scam Remote In Hidden remote software with support.client.exe Had a few clients that got scammed for people to remote into their PC. Indication that its a scam is when they have a support.client.exe file in their download folder. What this does is installs ConnectWise screenconnect service.
-
web:threatchain.hashnode.dev
ConnectWise Sample Detected: support.client.exe A new ConnectWise sample was identified by threat intelligence feeds on 2026-04-29 10:01:20. This post breaks down what we know about the specific sample, how to recognize related activity on your network, and what to do if you or your organization might be affected.
-
web:www.connectwise.com
Remediation efforts for ConnectWise PSA™ are ongoing. In the meantime, we recommend using the web client instead of the thick client to reduce exposure risk Reports and Dashboards (formerly BrightGauge™), SmileBack™, ConnectWise CPQ™, ConnectWise Automate™, Asio™ platform, and security services are not directly impacted
-
web:www.cyberproof.com
ConnectWise ScreenConnect Attacks (Part 1): Continued Surge in RMM Tool Abuse CyberProof Research Team | June 4, 2025 | 13 minute read Contributors: Jacob James, Niranjan Jayanand, Madhuri Syamakala This blog is part of a (2) part series around our research finding on the ConnectWise ScreenConnect Attacks.
-
web:www.malwarebytes.com
Fake emails pretending to come from the US Social Security Administration (SSA) try to get targets to install ScreenConnect, a remote access tool. This campaign was flagged and investigated by the Malwarebytes Customer Support and Research teams. ScreenConnect, formerly known as ConnectWise Control, is a remote support and remote access platform widely used by businesses to facilitate IT ...
-
web:www.pcrisk.com
What is ScreenConnect ( ConnectWise ) Client scam? Fraudsters use all kinds of ways to extract information or money from people and distribute malicious programs via emails. This article describes cases where fraudsters use emails to trick recipients into installing ConnectWise (formerly known as ScreenConnect).
-
web:www.reddit.com
When inspecting the computer, I see a file named support.Client.exe as well as what looks like a full installation of Screen Connect within the app data folder. The installation time of Screen Connect appears to coincide with the time that my family member was in a call with the scammmers.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.