s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-9416c8be5f1f3156191f932b8eca2e0ef3cfce10ad78f41205719a2759cfeaaf high

📛 Threat Title

ConnectWise: ScreenConnect.ClientSetup.exe

Category: ConnectWise Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 5640552 bytes. Tags: ConnectWise, signed. Reporter: BlinkzSec. First seen: 2026-05-15 11:49:57.

Indicators of Compromise (5)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain screenconnect.clientsetup.exe VT: VT base fetch failed: SSLError: HTTPSConnectionPool(host='www.virustotal.com', port=443): Max retries exceeded with url: /api/v3/domains/screenconnect.clientsetup.exe (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate is not yet valid (_ssl.c:992)')))

IOC database

Type
domain
Value
screenconnect.clientsetup.exe
First seen
Last seen
Attached to this threat
Appears in
9 threats
Description
Extracted from Threat MB-efc4186e35021b6367b40de3f875038d045ea89b9e3408e2955fdc7c87d48595

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: SSLError: HTTPSConnectionPool(host='www.virustotal.com', port=443): Max retries exceeded with url: /api/v3/domains/screenconnect.clientsetup.exe (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate is not yet valid (_ssl.c:992)')))

hash_imphash 9771ee6344923fa220489ab01239bdfd

IOC database

Type
hash_imphash
Value
9771ee6344923fa220489ab01239bdfd
First seen
Last seen
Attached to this threat
Appears in
145 threats
Description
imphash of URLhaus payload 997a09b5cbbebd7e…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 9416c8be5f1f3156191f932b8eca2e0ef3cfce10ad78f41205719a2759cfeaaf VT 46 / 73 1 feed

IOC database

Type
hash_sha256
Value
9416c8be5f1f3156191f932b8eca2e0ef3cfce10ad78f41205719a2759cfeaaf
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Flagged by 46 of 73 VirusTotal vendors

VendorVerdictDetection
Alibaba malicious Trojan:Win32/ScreenConnect.9647dccd
ALYac malicious Application.Scam.SConnect.GenericKD.677
Antiy-AVL malicious Trojan/Win32.Qwexlafiba
Arcabit malicious Application.Scam.SConnect.Generic.677
Avast malicious Other:Malware-gen [Trj]
AVG malicious Other:Malware-gen [Trj]
Avira malicious TR/Malware
BitDefender malicious Application.Scam.SConnect.GenericKD.677
Bkav malicious W32.Malware.8D465F8C
CAT-QuickHeal malicious Trojan.Cobaltstrike
CTX malicious exe.trojan.connectwise
Cylance malicious Unsafe
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.Siggen29.64120
Elastic malicious malicious (high confidence)
Emsisoft malicious Application.Scam.SConnect.GenericKD.677 (B)
ESET-NOD32 malicious Win32/RemoteAdmin.ConnectWiseControl.E potentially unsafe application
F-Secure malicious Trojan.TR/Malware
Fortinet malicious Riskware/RemoteAdmin_ConnectWiseControl
Google malicious Detected
huorong malicious HackTool/ConnectWiseControl.i
Jiangmin malicious Trojan.Agent.edgo
K7AntiVirus malicious Unwanted-Program ( 005c6d501 )
K7GW malicious Unwanted-Program ( 005c6d501 )
Kingsoft malicious Win32.Troj.qwexlafiba.v
Lionic malicious Trojan.Win32.Scam.4!c
Malwarebytes malicious RiskWare.ConnectWise.Abused
MaxSecure malicious Trojan.Malware.300983.susgen
Microsoft malicious Trojan:Win32/Qwexlafiba!rfn
MicroWorld-eScan malicious Application.Scam.SConnect.GenericKD.677
NANO-Antivirus malicious Trojan.Win32.RemoteAdmin.lhhoup
Paloalto malicious generic.ml
Panda malicious Trj/PhxBzA.A
Rising malicious Hacktool.ConnectWiseControl!8.17790 (CLOUD)
Sangfor malicious Trojan.Win32.Save.a
SentinelOne malicious Static AI - Suspicious PE
Skyhigh malicious BehavesLike.Win32.ScreenConnect.tc
Symantec malicious ML.Attribute.HighConfidence
TrellixENS malicious ConnectWise
TrendMicro malicious TROJ_GEN.R06EC0DEI26
TrendMicro-HouseCall malicious TROJ_GEN.R06EC0DEI26
Varist malicious W32/ConnectWise.B.gen!Eldorado
VBA32 malicious BScope.Riskware.ConnectWise
VIPRE malicious Application.Scam.SConnect.GenericKD.677
Yandex malicious Riskware.RemoteAdmin!O4vT/8AeK2A
Zillya malicious Tool.Convagent.Win32.869

Details From VirusTotal

Basic Properties
MD57007c0a4dd2914a67bcf4d57f444a862
SHA-156e7bc97f237e55935b6b784372aa9fd21467c04
SHA-2569416c8be5f1f3156191f932b8eca2e0ef3cfce10ad78f41205719a2759cfeaaf
VHash056056655d15756az459z6tz
SSDEEP49152:EEEL5cx5xTkYJkGYYpT0+TFiH7efP8Q1yJJ4ZD1F5z97oL1YbGQ+okRPGHpRPqM5:NEs6efPNwJ4t1h0cG5FGJRPxow8OJ
TLSHT1F946F111B3DA95B9D47F0538D87A42A99A74BD048712C7EF53D4BE2D2D32BC04E323A6
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386, for MS Windows
File size5.4 MB
History
Creation date2022-11-18 20:10 UTC
First seen on VirusTotal2026-05-15 11:50 UTC
Last submission2026-05-19 18:44 UTC
Last analysis2026-06-22 11:28 UTC
Last modified on VirusTotal2026-06-22 13:30 UTC
Known Names
  • 22t3l6a16.exe
  • 9416c8be5f1f3156191f932b8eca2e0ef3cfce10ad78f41205719a2759cfeaaf.exe
  • ScreenConnect.ClientSetup.exe
  • _9416c8be5f1f3156191f932b8eca2e0ef3cfce10ad78f41205719a2759cfeaaf.exe
hash_sha1 56e7bc97f237e55935b6b784372aa9fd21467c04 VT 46 / 74 1 feed

IOC database

Type
hash_sha1
Value
56e7bc97f237e55935b6b784372aa9fd21467c04
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Flagged by 46 of 74 VirusTotal vendors

VendorVerdictDetection
Alibaba malicious Trojan:Win32/ScreenConnect.9647dccd
ALYac malicious Application.Scam.SConnect.GenericKD.677
Antiy-AVL malicious Trojan/Win32.Qwexlafiba
Arcabit malicious Application.Scam.SConnect.Generic.677
Avast malicious Other:Malware-gen [Trj]
AVG malicious Other:Malware-gen [Trj]
Avira malicious TR/Malware
BitDefender malicious Application.Scam.SConnect.GenericKD.677
Bkav malicious W32.Malware.8D465F8C
CAT-QuickHeal malicious Trojan.Cobaltstrike
CTX malicious exe.trojan.connectwise
Cylance malicious Unsafe
DrWeb malicious Trojan.Siggen29.64120
Elastic malicious malicious (high confidence)
Emsisoft malicious Application.Scam.SConnect.GenericKD.677 (B)
ESET-NOD32 malicious Win32/RemoteAdmin.ConnectWiseControl.E potentially unsafe application
F-Secure malicious Trojan.TR/Malware
Fortinet malicious Riskware/RemoteAdmin_ConnectWiseControl
GData malicious Win32.Riskware.SilentConwi.B
Google malicious Detected
huorong malicious HackTool/ConnectWiseControl.i
Jiangmin malicious Trojan.Agent.edgo
K7AntiVirus malicious Unwanted-Program ( 005c6d501 )
K7GW malicious Unwanted-Program ( 005c6d501 )
Kingsoft malicious Win32.Troj.qwexlafiba.v
Lionic malicious Trojan.Win32.Scam.4!c
Malwarebytes malicious RiskWare.ConnectWise.Abused
MaxSecure malicious Trojan.Malware.300983.susgen
Microsoft malicious Trojan:Win32/Qwexlafiba!rfn
MicroWorld-eScan malicious Application.Scam.SConnect.GenericKD.677
NANO-Antivirus malicious Trojan.Win32.RemoteAdmin.lhhoup
Paloalto malicious generic.ml
Panda malicious Trj/PhxBzA.A
Rising malicious Hacktool.ConnectWiseControl!8.17790 (CLOUD)
Sangfor malicious Trojan.Win32.Save.a
SentinelOne malicious Static AI - Malicious PE
Skyhigh malicious BehavesLike.Win32.ScreenConnect.tc
Symantec malicious ML.Attribute.HighConfidence
TrellixENS malicious ConnectWise
TrendMicro malicious TROJ_GEN.R06EC0DEI26
TrendMicro-HouseCall malicious TROJ_GEN.R06EC0DEI26
Varist malicious W32/ConnectWise.B.gen!Eldorado
VBA32 malicious BScope.Riskware.ConnectWise
VIPRE malicious Application.Scam.SConnect.GenericKD.677
Yandex malicious Riskware.RemoteAdmin!O4vT/8AeK2A
Zillya malicious Tool.Convagent.Win32.869

Details From VirusTotal

Basic Properties
MD57007c0a4dd2914a67bcf4d57f444a862
SHA-156e7bc97f237e55935b6b784372aa9fd21467c04
SHA-2569416c8be5f1f3156191f932b8eca2e0ef3cfce10ad78f41205719a2759cfeaaf
VHash056056655d15756az459z6tz
SSDEEP49152:EEEL5cx5xTkYJkGYYpT0+TFiH7efP8Q1yJJ4ZD1F5z97oL1YbGQ+okRPGHpRPqM5:NEs6efPNwJ4t1h0cG5FGJRPxow8OJ
TLSHT1F946F111B3DA95B9D47F0538D87A42A99A74BD048712C7EF53D4BE2D2D32BC04E323A6
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386, for MS Windows
File size5.4 MB
History
Creation date2022-11-18 20:10 UTC
First seen on VirusTotal2026-05-15 11:50 UTC
Last submission2026-05-19 18:44 UTC
Last analysis2026-07-23 11:20 UTC
Last modified on VirusTotal2026-07-23 13:22 UTC
Known Names
  • 22t3l6a16.exe
  • 9416c8be5f1f3156191f932b8eca2e0ef3cfce10ad78f41205719a2759cfeaaf.exe
  • ScreenConnect.ClientSetup.exe
  • _9416c8be5f1f3156191f932b8eca2e0ef3cfce10ad78f41205719a2759cfeaaf.exe
hash_md5 7007c0a4dd2914a67bcf4d57f444a862 1 feed

IOC database

Type
hash_md5
Value
7007c0a4dd2914a67bcf4d57f444a862
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 5640552 bytes. Tags: signed. Reporter: BlinkzSec. First seen: 2026-05-15 11:49:57.

Remediations (10)

  • web:cyberpress.org

    Escalate privileges to gain domain-level control Given the role of ScreenConnect in managed service provider (MSP) environments, exploitation could also enable supply chain-style attacks, impacting multiple downstream clients. Mitigation Deadlines and CISA Directive CISA has mandated that federal agencies remediate the vulnerability by May 12 ...

  • web:cybersecuritynews.com

    Attackers abuse ConnectWise ScreenConnect RMM tool via phishing, using fake IT alerts and invite links to gain stealthy access.

  • web:docs.connectwise.com

    Introduction After building an access agent installer, you will need run it one or more machines in order to connect to them from the Host page. This page will describe how to install a ScreenConnect™ access agent.

  • web:services.google.com

    Summary This document contains remediation and hardening recommendations for responding to critical vulnerabilites for the ConnectWise ScreenConnect application announced on February 19, 2024.

  • web:www.acronis.com

    Over the past months, Acronis TRU (Threat Research Unit) has identified multiple active and ongoing campaigns leveraging trojanized versions of ConnectWise ScreenConnect to gain initial access to victim networks and compromise target machines.

  • web:www.bleepingcomputer.com

    Threat actors are abusing the ConnectWise ScreenConnect installer to build signed remote access malware by modifying hidden settings within the client's Authenticode signature.

  • web:www.forcepoint.com

    ScreenConnect.ClientService.exe is a part of the ScreenConnect tool made by ConnectWise . It runs in the background and allows someone to remotely access or control your computer for support or meetings.

  • web:www.microsoft.com

    Signed malware backed by a stolen EV certificate deployed legitimate RMM tools to gain persistent access inside enterprise environments. Organizations must harden certificate controls and monitor RMM activity to reduce exposure.

  • web:www.reddit.com

    There are no Connectwise services, nothing in add/remove programs, no program files/data, and yet I still get the same message. I don't know the thumbprint of the original client install (was not documented by my predecessor).

  • web:www.screenconnect.com

    Each release is a full-server installation of ScreenConnect, which include client components. Mobile clients can be downloaded from the appropriate app store.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.