s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-c3a385fea4294dda9da4bcb3f3f15a6ea64fd66511985a52f8ecca248541e8ff high

📛 Threat Title

ConnectWise: support.client.exe

Category: ConnectWise Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 83184 bytes. Tags: ConnectWise, signed. Reporter: BlinkzSec. First seen: 2026-05-15 11:49:55.

Indicators of Compromise (5)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain support.client.exe VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/support.client.exe

IOC database

Type
domain
Value
support.client.exe
First seen
Last seen
Attached to this threat
Appears in
10 threats
Description
Extracted from Threat MB-d9fbcad42aaf846845c6c04550e5c010903112eedccd901c43c0a7a9be1bf2eb

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/support.client.exe

hash_sha256 c3a385fea4294dda9da4bcb3f3f15a6ea64fd66511985a52f8ecca248541e8ff VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/c3a385fea4294dda9da4bcb3f3f15a6ea64fd66511985a52f8ecca248541e8ff
1 feed

IOC database

Type
hash_sha256
Value
c3a385fea4294dda9da4bcb3f3f15a6ea64fd66511985a52f8ecca248541e8ff
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/c3a385fea4294dda9da4bcb3f3f15a6ea64fd66511985a52f8ecca248541e8ff

hash_sha1 e7443e15af57fb225f3ddc9cda5955ad3bbcb517 1 feed

IOC database

Type
hash_sha1
Value
e7443e15af57fb225f3ddc9cda5955ad3bbcb517
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 a9e2c397c9a018e3e64e5365d5b6fbe7 VT 40 / 75 1 feed

IOC database

Type
hash_md5
Value
a9e2c397c9a018e3e64e5365d5b6fbe7
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Flagged by 40 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Malware/Win.Generic.C5884423
Alibaba malicious RiskWare:Win32/ConnectWise.440ded0a
ALYac malicious Application.Scam.SConnect.GenericKD.678
Antiy-AVL malicious RiskWare[RemoteAdmin]/Win32.ConnectWise
Arcabit malicious Application.Scam.SConnect.Generic.678
Avast malicious FileRepMalware [Misc]
AVG malicious FileRepMalware [Misc]
Avira malicious TR/Malware
BitDefender malicious Application.Scam.SConnect.GenericKD.678
Bkav malicious W32.Malware.310305CB
CTX malicious exe.trojan.connectwise
Cynet malicious Malicious (score: 99)
DeepInstinct malicious MALICIOUS
DrWeb malicious Tool.ConnectWise.1
Elastic malicious malicious (high confidence)
Emsisoft malicious Application.Scam.SConnect.GenericKD.678 (B)
F-Secure malicious Trojan.TR/Malware
Fortinet malicious Riskware/ScreenConnect
Google malicious Detected
Ikarus malicious Trojan.Win32.Qwexlafiba
Jiangmin malicious RemoteAdmin.ConnectWise.m
K7AntiVirus malicious Riskware ( 00584baa1 )
K7GW malicious Riskware ( 00584baa1 )
Kaspersky malicious not-a-virus:HEUR:RemoteAdmin.Win32.ConnectWise.gen
Kingsoft malicious Win32.HACKTOOL.RemoteAdmin.v
Lionic malicious Riskware.Win32.ConnectWise.1!c
Malwarebytes malicious Generic.Malware/Suspicious
Microsoft malicious Trojan:Win32/Qwexlafiba!rfn
MicroWorld-eScan malicious Application.Scam.SConnect.GenericKD.678
Paloalto malicious generic.ml
Panda malicious Trj/PhxBzA.A
Rising malicious Trojan.RemoteAdmin!8.D7F6 (TFE:5:S0IiEqXsGa)
Symantec malicious ML.Attribute.HighConfidence
Tencent malicious HackTool.Win32.ConnectWise.ha
TrellixENS malicious ScreenConnect
TrendMicro malicious TROJ_FRS.VSNTEI26
TrendMicro-HouseCall malicious TROJ_FRS.VSNTEI26
Varist malicious W32/ConnectWise.N.gen!Eldorado
VBA32 malicious BScope.Trojan.Wacatac
VIPRE malicious Application.Scam.SConnect.GenericKD.678

Details From VirusTotal

Basic Properties
MD5a9e2c397c9a018e3e64e5365d5b6fbe7
SHA-1e7443e15af57fb225f3ddc9cda5955ad3bbcb517
SHA-256c3a385fea4294dda9da4bcb3f3f15a6ea64fd66511985a52f8ecca248541e8ff
VHash084056655d155565z92z44!z
SSDEEP1536:6xoG6KpY6Qi3yj2wyq4HwiMO10HVLCJRpsWr6cdaWPBJYYT77JU:IenkyfPAwiMq0RqRfbaWZJYYTxU
TLSHT195836C43B5D18876E9720E3118B1D9B4593FBE110E648EAF7398422E0F351D19E3AE7B
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386, for MS Windows
File size81.2 KB
History
Creation date2024-10-28 17:41 UTC
First seen on VirusTotal2026-05-15 11:50 UTC
Last submission2026-05-15 11:50 UTC
Last analysis2026-05-20 07:27 UTC
Last modified on VirusTotal2026-05-20 10:37 UTC
Known Names
  • support.client.exe
  • _c3a385fea4294dda9da4bcb3f3f15a6ea64fd66511985a52f8ecca248541e8ff.exe
  • hnnnrsdlh.exe
hash_imphash 37d5c89163970dd3cc69230538a1b72b

IOC database

Type
hash_imphash
Value
37d5c89163970dd3cc69230538a1b72b
First seen
Last seen
Attached to this threat
Appears in
15 threats
Description
imphash of URLhaus payload b5903061132c7f84…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 83184 bytes. Tags: signed. Reporter: BlinkzSec. First seen: 2026-05-15 11:49:55.

Remediations (10)

  • web:blog.gdatasoftware.com

    Since March 2025, there has been a noticeable increase in infections and fake applications using validly signed ConnectWise samples. We reveal how bad signing practices allow threat actors to abuse this legitimate software to build and distribute their own signed malware and what security vendors can do to detect them.

  • web:cybersecuritynews.com

    Threat actors have been leveraging the legitimate Remote Monitoring and Management (RMM) tool, ScreenConnect, to establish persistence in their cyberattacks. This trend shows the evolving tactics of hackers who exploit trusted software to gain unauthorized access to systems. ScreenConnect, now known as ConnectWise Control, is a widely used RMM tool that allows IT teams to manage and monitor ...

  • web:services.google.com

    Summary This document contains remediation and hardening recommendations for responding to critical vulnerabilites for the ConnectWise ScreenConnect application announced on February 19, 2024.

  • web:steveit.ca

    Scam Remote In Hidden remote software with support.client.exe Had a few clients that got scammed for people to remote into their PC. Indication that its a scam is when they have a support.client.exe file in their download folder. What this does is installs ConnectWise screenconnect service.

  • web:threatchain.hashnode.dev

    ConnectWise Sample Detected: support.client.exe A new ConnectWise sample was identified by threat intelligence feeds on 2026-04-29 10:01:20. This post breaks down what we know about the specific sample, how to recognize related activity on your network, and what to do if you or your organization might be affected.

  • web:www.connectwise.com

    Remediation efforts for ConnectWise PSA™ are ongoing. In the meantime, we recommend using the web client instead of the thick client to reduce exposure risk Reports and Dashboards (formerly BrightGauge™), SmileBack™, ConnectWise CPQ™, ConnectWise Automate™, Asio™ platform, and security services are not directly impacted

  • web:www.cyberproof.com

    ConnectWise ScreenConnect Attacks (Part 1): Continued Surge in RMM Tool Abuse CyberProof Research Team | June 4, 2025 | 13 minute read Contributors: Jacob James, Niranjan Jayanand, Madhuri Syamakala This blog is part of a (2) part series around our research finding on the ConnectWise ScreenConnect Attacks.

  • web:www.malwarebytes.com

    Fake emails pretending to come from the US Social Security Administration (SSA) try to get targets to install ScreenConnect, a remote access tool. This campaign was flagged and investigated by the Malwarebytes Customer Support and Research teams. ScreenConnect, formerly known as ConnectWise Control, is a remote support and remote access platform widely used by businesses to facilitate IT ...

  • web:www.pcrisk.com

    What is ScreenConnect ( ConnectWise ) Client scam? Fraudsters use all kinds of ways to extract information or money from people and distribute malicious programs via emails. This article describes cases where fraudsters use emails to trick recipients into installing ConnectWise (formerly known as ScreenConnect).

  • web:www.reddit.com

    When inspecting the computer, I see a file named support.Client.exe as well as what looks like a full installation of Screen Connect within the app data folder. The installation time of Screen Connect appears to coincide with the time that my family member was in a call with the scammmers.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.