MB-9416c8be5f1f3156191f932b8eca2e0ef3cfce10ad78f41205719a2759cfeaaf
high
📛 Threat Title
ConnectWise: ScreenConnect.ClientSetup.exe
Description
File type: exe. Size: 5640552 bytes. Tags: ConnectWise, signed. Reporter: BlinkzSec. First seen: 2026-05-15 11:49:57.
Indicators of Compromise (5)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
screenconnect.clientsetup.exe
VT: VT base fetch failed: SSLError: HTTPSConnectionPool(host='www.virustotal.com', port=443): Max retries exceeded with url: /api/v3/domains/screenconnect.clientsetup.exe (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate is not yet valid (_ssl.c:992)')))
IOC database
- Type
- domain
- Value
screenconnect.clientsetup.exe- First seen
- Last seen
- Attached to this threat
- Appears in
- 9 threats
- Description
- Extracted from Threat MB-efc4186e35021b6367b40de3f875038d045ea89b9e3408e2955fdc7c87d48595
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: SSLError: HTTPSConnectionPool(host='www.virustotal.com', port=443): Max retries exceeded with url: /api/v3/domains/screenconnect.clientsetup.exe (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate is not yet valid (_ssl.c:992)')))
hash_imphash
9771ee6344923fa220489ab01239bdfd
IOC database
- Type
- hash_imphash
- Value
9771ee6344923fa220489ab01239bdfd- First seen
- Last seen
- Attached to this threat
- Appears in
- 145 threats
- Description
- imphash of URLhaus payload 997a09b5cbbebd7e…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
9416c8be5f1f3156191f932b8eca2e0ef3cfce10ad78f41205719a2759cfeaaf
VT 46 / 73
1 feed
IOC database
- Type
- hash_sha256
- Value
9416c8be5f1f3156191f932b8eca2e0ef3cfce10ad78f41205719a2759cfeaaf- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Unknown
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 46 of 73 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Alibaba | malicious | Trojan:Win32/ScreenConnect.9647dccd |
| ALYac | malicious | Application.Scam.SConnect.GenericKD.677 |
| Antiy-AVL | malicious | Trojan/Win32.Qwexlafiba |
| Arcabit | malicious | Application.Scam.SConnect.Generic.677 |
| Avast | malicious | Other:Malware-gen [Trj] |
| AVG | malicious | Other:Malware-gen [Trj] |
| Avira | malicious | TR/Malware |
| BitDefender | malicious | Application.Scam.SConnect.GenericKD.677 |
| Bkav | malicious | W32.Malware.8D465F8C |
| CAT-QuickHeal | malicious | Trojan.Cobaltstrike |
| CTX | malicious | exe.trojan.connectwise |
| Cylance | malicious | Unsafe |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | Trojan.Siggen29.64120 |
| Elastic | malicious | malicious (high confidence) |
| Emsisoft | malicious | Application.Scam.SConnect.GenericKD.677 (B) |
| ESET-NOD32 | malicious | Win32/RemoteAdmin.ConnectWiseControl.E potentially unsafe application |
| F-Secure | malicious | Trojan.TR/Malware |
| Fortinet | malicious | Riskware/RemoteAdmin_ConnectWiseControl |
| malicious | Detected |
|
| huorong | malicious | HackTool/ConnectWiseControl.i |
| Jiangmin | malicious | Trojan.Agent.edgo |
| K7AntiVirus | malicious | Unwanted-Program ( 005c6d501 ) |
| K7GW | malicious | Unwanted-Program ( 005c6d501 ) |
| Kingsoft | malicious | Win32.Troj.qwexlafiba.v |
| Lionic | malicious | Trojan.Win32.Scam.4!c |
| Malwarebytes | malicious | RiskWare.ConnectWise.Abused |
| MaxSecure | malicious | Trojan.Malware.300983.susgen |
| Microsoft | malicious | Trojan:Win32/Qwexlafiba!rfn |
| MicroWorld-eScan | malicious | Application.Scam.SConnect.GenericKD.677 |
| NANO-Antivirus | malicious | Trojan.Win32.RemoteAdmin.lhhoup |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/PhxBzA.A |
| Rising | malicious | Hacktool.ConnectWiseControl!8.17790 (CLOUD) |
| Sangfor | malicious | Trojan.Win32.Save.a |
| SentinelOne | malicious | Static AI - Suspicious PE |
| Skyhigh | malicious | BehavesLike.Win32.ScreenConnect.tc |
| Symantec | malicious | ML.Attribute.HighConfidence |
| TrellixENS | malicious | ConnectWise |
| TrendMicro | malicious | TROJ_GEN.R06EC0DEI26 |
| TrendMicro-HouseCall | malicious | TROJ_GEN.R06EC0DEI26 |
| Varist | malicious | W32/ConnectWise.B.gen!Eldorado |
| VBA32 | malicious | BScope.Riskware.ConnectWise |
| VIPRE | malicious | Application.Scam.SConnect.GenericKD.677 |
| Yandex | malicious | Riskware.RemoteAdmin!O4vT/8AeK2A |
| Zillya | malicious | Tool.Convagent.Win32.869 |
Details From VirusTotal
Basic Properties
| MD5 | 7007c0a4dd2914a67bcf4d57f444a862 |
| SHA-1 | 56e7bc97f237e55935b6b784372aa9fd21467c04 |
| SHA-256 | 9416c8be5f1f3156191f932b8eca2e0ef3cfce10ad78f41205719a2759cfeaaf |
| VHash | 056056655d15756az459z6tz |
| SSDEEP | 49152:EEEL5cx5xTkYJkGYYpT0+TFiH7efP8Q1yJJ4ZD1F5z97oL1YbGQ+okRPGHpRPqM5:NEs6efPNwJ4t1h0cG5FGJRPxow8OJ |
| TLSH | T1F946F111B3DA95B9D47F0538D87A42A99A74BD048712C7EF53D4BE2D2D32BC04E323A6 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386, for MS Windows |
| File size | 5.4 MB |
History
| Creation date | 2022-11-18 20:10 UTC |
| First seen on VirusTotal | 2026-05-15 11:50 UTC |
| Last submission | 2026-05-19 18:44 UTC |
| Last analysis | 2026-06-22 11:28 UTC |
| Last modified on VirusTotal | 2026-06-22 13:30 UTC |
Known Names
22t3l6a16.exe9416c8be5f1f3156191f932b8eca2e0ef3cfce10ad78f41205719a2759cfeaaf.exeScreenConnect.ClientSetup.exe_9416c8be5f1f3156191f932b8eca2e0ef3cfce10ad78f41205719a2759cfeaaf.exe
hash_sha1
56e7bc97f237e55935b6b784372aa9fd21467c04
VT 46 / 74
1 feed
IOC database
- Type
- hash_sha1
- Value
56e7bc97f237e55935b6b784372aa9fd21467c04- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 46 of 74 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Alibaba | malicious | Trojan:Win32/ScreenConnect.9647dccd |
| ALYac | malicious | Application.Scam.SConnect.GenericKD.677 |
| Antiy-AVL | malicious | Trojan/Win32.Qwexlafiba |
| Arcabit | malicious | Application.Scam.SConnect.Generic.677 |
| Avast | malicious | Other:Malware-gen [Trj] |
| AVG | malicious | Other:Malware-gen [Trj] |
| Avira | malicious | TR/Malware |
| BitDefender | malicious | Application.Scam.SConnect.GenericKD.677 |
| Bkav | malicious | W32.Malware.8D465F8C |
| CAT-QuickHeal | malicious | Trojan.Cobaltstrike |
| CTX | malicious | exe.trojan.connectwise |
| Cylance | malicious | Unsafe |
| DrWeb | malicious | Trojan.Siggen29.64120 |
| Elastic | malicious | malicious (high confidence) |
| Emsisoft | malicious | Application.Scam.SConnect.GenericKD.677 (B) |
| ESET-NOD32 | malicious | Win32/RemoteAdmin.ConnectWiseControl.E potentially unsafe application |
| F-Secure | malicious | Trojan.TR/Malware |
| Fortinet | malicious | Riskware/RemoteAdmin_ConnectWiseControl |
| GData | malicious | Win32.Riskware.SilentConwi.B |
| malicious | Detected |
|
| huorong | malicious | HackTool/ConnectWiseControl.i |
| Jiangmin | malicious | Trojan.Agent.edgo |
| K7AntiVirus | malicious | Unwanted-Program ( 005c6d501 ) |
| K7GW | malicious | Unwanted-Program ( 005c6d501 ) |
| Kingsoft | malicious | Win32.Troj.qwexlafiba.v |
| Lionic | malicious | Trojan.Win32.Scam.4!c |
| Malwarebytes | malicious | RiskWare.ConnectWise.Abused |
| MaxSecure | malicious | Trojan.Malware.300983.susgen |
| Microsoft | malicious | Trojan:Win32/Qwexlafiba!rfn |
| MicroWorld-eScan | malicious | Application.Scam.SConnect.GenericKD.677 |
| NANO-Antivirus | malicious | Trojan.Win32.RemoteAdmin.lhhoup |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/PhxBzA.A |
| Rising | malicious | Hacktool.ConnectWiseControl!8.17790 (CLOUD) |
| Sangfor | malicious | Trojan.Win32.Save.a |
| SentinelOne | malicious | Static AI - Malicious PE |
| Skyhigh | malicious | BehavesLike.Win32.ScreenConnect.tc |
| Symantec | malicious | ML.Attribute.HighConfidence |
| TrellixENS | malicious | ConnectWise |
| TrendMicro | malicious | TROJ_GEN.R06EC0DEI26 |
| TrendMicro-HouseCall | malicious | TROJ_GEN.R06EC0DEI26 |
| Varist | malicious | W32/ConnectWise.B.gen!Eldorado |
| VBA32 | malicious | BScope.Riskware.ConnectWise |
| VIPRE | malicious | Application.Scam.SConnect.GenericKD.677 |
| Yandex | malicious | Riskware.RemoteAdmin!O4vT/8AeK2A |
| Zillya | malicious | Tool.Convagent.Win32.869 |
Details From VirusTotal
Basic Properties
| MD5 | 7007c0a4dd2914a67bcf4d57f444a862 |
| SHA-1 | 56e7bc97f237e55935b6b784372aa9fd21467c04 |
| SHA-256 | 9416c8be5f1f3156191f932b8eca2e0ef3cfce10ad78f41205719a2759cfeaaf |
| VHash | 056056655d15756az459z6tz |
| SSDEEP | 49152:EEEL5cx5xTkYJkGYYpT0+TFiH7efP8Q1yJJ4ZD1F5z97oL1YbGQ+okRPGHpRPqM5:NEs6efPNwJ4t1h0cG5FGJRPxow8OJ |
| TLSH | T1F946F111B3DA95B9D47F0538D87A42A99A74BD048712C7EF53D4BE2D2D32BC04E323A6 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386, for MS Windows |
| File size | 5.4 MB |
History
| Creation date | 2022-11-18 20:10 UTC |
| First seen on VirusTotal | 2026-05-15 11:50 UTC |
| Last submission | 2026-05-19 18:44 UTC |
| Last analysis | 2026-07-23 11:20 UTC |
| Last modified on VirusTotal | 2026-07-23 13:22 UTC |
Known Names
22t3l6a16.exe9416c8be5f1f3156191f932b8eca2e0ef3cfce10ad78f41205719a2759cfeaaf.exeScreenConnect.ClientSetup.exe_9416c8be5f1f3156191f932b8eca2e0ef3cfce10ad78f41205719a2759cfeaaf.exe
hash_md5
7007c0a4dd2914a67bcf4d57f444a862
1 feed
IOC database
- Type
- hash_md5
- Value
7007c0a4dd2914a67bcf4d57f444a862- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 5640552 bytes. Tags: signed. Reporter: BlinkzSec. First seen: 2026-05-15 11:49:57.
Remediations (10)
-
web:cyberpress.org
Escalate privileges to gain domain-level control Given the role of ScreenConnect in managed service provider (MSP) environments, exploitation could also enable supply chain-style attacks, impacting multiple downstream clients. Mitigation Deadlines and CISA Directive CISA has mandated that federal agencies remediate the vulnerability by May 12 ...
-
web:cybersecuritynews.com
Attackers abuse ConnectWise ScreenConnect RMM tool via phishing, using fake IT alerts and invite links to gain stealthy access.
-
web:docs.connectwise.com
Introduction After building an access agent installer, you will need run it one or more machines in order to connect to them from the Host page. This page will describe how to install a ScreenConnect™ access agent.
-
web:services.google.com
Summary This document contains remediation and hardening recommendations for responding to critical vulnerabilites for the ConnectWise ScreenConnect application announced on February 19, 2024.
-
web:www.acronis.com
Over the past months, Acronis TRU (Threat Research Unit) has identified multiple active and ongoing campaigns leveraging trojanized versions of ConnectWise ScreenConnect to gain initial access to victim networks and compromise target machines.
-
web:www.bleepingcomputer.com
Threat actors are abusing the ConnectWise ScreenConnect installer to build signed remote access malware by modifying hidden settings within the client's Authenticode signature.
-
web:www.forcepoint.com
ScreenConnect.ClientService.exe is a part of the ScreenConnect tool made by ConnectWise . It runs in the background and allows someone to remotely access or control your computer for support or meetings.
-
web:www.microsoft.com
Signed malware backed by a stolen EV certificate deployed legitimate RMM tools to gain persistent access inside enterprise environments. Organizations must harden certificate controls and monitor RMM activity to reduce exposure.
-
web:www.reddit.com
There are no Connectwise services, nothing in add/remove programs, no program files/data, and yet I still get the same message. I don't know the thumbprint of the original client install (was not documented by my predecessor).
-
web:www.screenconnect.com
Each release is a full-server installation of ScreenConnect, which include client components. Mobile clients can be downloaded from the appropriate app store.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.