0b8484a08fd8ff651ec81a9980d2beee4bfaf6d056e686095b12c2f31762dcf2

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2022-Nov-18 20:10:20
Detected languages English - United States
Debug artifacts C:\Users\jmorgan\Source\cwcontrol\Custom\DotNetRunner\Release\DotNetRunner.pdb

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C# v7.0 / Basic .NET
.NET executable -> Microsoft
Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to system / monitoring tools:
  • rundll32.exe
Contains references to security software:
  • rshell.exe
May have dropper capabilities:
  • CurrentControlSet\Services
Contains another PE executable:
  • This program cannot be run in DOS mode.
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • cacerts.digicert.com
  • crl3.digicert.com
  • crl4.digicert.com
  • digicert.com
  • feedback.screenconnect.com
  • http://cacerts.digicert.com
  • http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
  • http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
  • http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
  • http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
  • http://crl3.digicert.com
  • http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
  • http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
  • http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
  • http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
  • http://crl4.digicert.com
  • http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0
  • http://ocsp.digicert.com0
  • http://ocsp.digicert.com0A
  • http://ocsp.digicert.com0C
  • http://ocsp.digicert.com0X
  • http://ocsp.digicert.com0\
  • http://www.digicert.com
  • http://www.digicert.com/CPS0
  • https://feedback.screenconnect.com
  • https://feedback.screenconnect.com/Feedback.axd
  • screenconnect.com
  • www.digicert.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to SHA256
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • LoadLibraryW
  • GetProcAddress
  • LoadLibraryExW
Malicious The PE is possibly a dropper. Resource SCREENCONNECT.CORE, VERSION=25.2.4.9229, CULTURE=NEUTRAL, PUBLICKEYTOKEN=4B14C015C87C1AD8 detected as a PE Executable.
Resource SCREENCONNECT.WINDOWS, VERSION=25.2.4.9229, CULTURE=NEUTRAL, PUBLICKEYTOKEN=4B14C015C87C1AD8 detected as a PE Executable.
Resource SCREENCONNECT.WINDOWSINSTALLER, VERSION=25.2.4.9229, CULTURE=NEUTRAL, PUBLICKEYTOKEN=4B14C015C87C1AD8 detected as a PE Executable.
Resource _ENTRYPOINT detected as a PE Executable.
Resource _RESOLVER detected as a PE Executable.
Resources amount for 96.9376% of the executable.
Info The PE is digitally signed. Signer: Connectwise
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
Malicious VirusTotal score: 20/72 (Scanned on 2025-06-02 14:34:03) CrowdStrike: win/grayware_confidence_70% (D)
Cylance: Unsafe
DeepInstinct: MALICIOUS
DrWeb: Trojan.MulDrop31.17564
ESET-NOD32: a variant of Win32/RemoteAdmin.ConnectWiseControl.E potentially unsafe
Fortinet: PossibleThreat.DU
Google: Detected
Gridinsoft: Trojan.Win32.MultiInjector.dd!s1
Jiangmin: Trojan.Agent.edgo
K7AntiVirus: Unwanted-Program ( 005c6d501 )
K7GW: Unwanted-Program ( 005c6d501 )
Kaspersky: not-a-virus:RemoteAdmin.MSIL.ConnectWise.b
MaxSecure: Trojan.Malware.121218.susgen
Rising: Hacktool.ConnectWise!8.13A88 (CLOUD)
SentinelOne: Static AI - Suspicious PE
Skyhigh: BehavesLike.Win32.ConnectWise.tc
Tencent: Pua:HackTool.Win32.Connectwise.16001881
VBA32: BScope.Riskware.ConnectWise
Varist: W32/ConnectWise.B.gen!Eldorado
Zillya: Tool.Convagent.Win32.869

Hashes

MD5 b6d7a7b950a61a37221033580a112af1 🔍
SHA1 92b8a5f2c2ea00eac5753acc6c85c7d3d9a963f5 🔍
SHA256 0b8484a08fd8ff651ec81a9980d2beee4bfaf6d056e686095b12c2f31762dcf2 🔍
SHA3 b5852981c0231dcc4dce7cbfeb7b92cd9a34de930af4503bf927d7dc4f8c7402 🔍
SSDeep 98304:gzIus6efPUIdoaxcp8wy5c3trGOlkQ5DUOgJ9zl:ghfefPtHxcp9ym3nltDUJV 🔍
Imports Hash 9771ee6344923fa220489ab01239bdfd 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2022-Nov-18 20:10:20
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 14.0
SizeOfCode 0xb200
SizeOfInitializedData 0x53f000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000014AD (Section: .text)
BaseOfCode 0x1000
BaseOfData 0xd000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.1
ImageVersion 0.0
SubsystemVersion 5.1
Win32VersionValue 0
SizeOfImage 0x54f000
SizeOfHeaders 0x400
Checksum 0x54d737
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 d9fa6da0baf4b869720be833223490cb 🔍
SHA1 b6978a757f7342839347eaf585473da8660a6996 🔍
SHA256 eaba38650152f8688eed3ed2c4383cebe5ccde8a3b5b746c50d1d4813d951597 🔍
SHA3 1813170b5d81291e0815ca0320d5741c141846868d1e4893819edb5a5c39fa92 🔍
VirtualSize 0xb1af
VirtualAddress 0x1000
SizeOfRawData 0xb200
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.59204

.rdata

MD5 8b45a1035c0de72f910a75db7749f735 🔍
SHA1 0642a66de21c204dda5ac19aacb0717068c12e72 🔍
SHA256 8d80004988f9a0ec5e1d00c2f0d1155bdbaf0fe0ee7c14237f572eace11dfa23 🔍
SHA3 111b251c78ec2250e45680281c5b13383a7e93e642cacfafe77f6f483d370006 🔍
VirtualSize 0x6078
VirtualAddress 0xd000
SizeOfRawData 0x6200
PointerToRawData 0xb600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.78662

.data

MD5 1f4cc86b6735a74429c9d1feb93e2871 🔍
SHA1 861fc35925471a609902d4fd925c68aad2a2d676 🔍
SHA256 84a7f490102ace5e46c847381c8d50860b646f72c6f6d454e9fd5943bf212ee6 🔍
SHA3 7a657ad1ea9679a4e12c24c5c173fddb959a56276907a6b55a2e227222d7b6ad 🔍
VirtualSize 0x11e4
VirtualAddress 0x14000
SizeOfRawData 0x800
PointerToRawData 0x11800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.26508

.rsrc

MD5 9132abaede5a6f7735817d13b4a57f49 🔍
SHA1 e5e4b5deb6434f43aecf1dcd966690b7ac04e6d7 🔍
SHA256 1a099cd9797ab991d394ad146eb16263627ad8160d7d8e918435440775ed4fd0 🔍
SHA3 46c87c2f0afce491265bff7dcc841dd3e0b0d1f020b5f499a5ffc575cf5783ad 🔍
VirtualSize 0x537474
VirtualAddress 0x16000
SizeOfRawData 0x537600
PointerToRawData 0x12000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.44993

.reloc

MD5 a93b0f39998e1e69e5944da8c5ff06b1 🔍
SHA1 dfde891879d0a61f960d47dcd6a9cc34c9ea70ba 🔍
SHA256 e98540b66036ea262721678c359478b46e58091f52b3dd902868763f629b7a2d 🔍
SHA3 af1d27a7c5c317da06a3cdaa8a7ee83d74ceb35ce0afdeb31b536d97ad6aa81d 🔍
VirtualSize 0xea8
VirtualAddress 0x54e000
SizeOfRawData 0x1000
PointerToRawData 0x549600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.30149

Imports

mscoree.dll CorBindToRuntimeEx
KERNEL32.dll GetModuleFileNameA
DecodePointer
SizeofResource
LockResource
LoadLibraryW
LoadResource
FindResourceW
GetProcAddress
WriteConsoleW
SetFilePointerEx
GetConsoleMode
GetConsoleCP
FlushFileBuffers
HeapReAlloc
HeapSize
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
RtlUnwind
GetLastError
SetLastError
EncodePointer
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
RaiseException
GetStdHandle
WriteFile
CreateFileW
MultiByteToWideChar
WideCharToMultiByte
ExitProcess
GetModuleHandleExW
GetACP
CloseHandle
HeapAlloc
HeapFree
FindClose
FindFirstFileExA
FindNextFileA
IsValidCodePage
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
LCMapStringW
SetStdHandle
GetFileType
GetStringTypeW
GetProcessHeap
OLEAUT32.dll VariantInit
SafeArrayUnaccessData
SafeArrayCreateVector
SafeArrayDestroy
VariantClear
SafeArrayAccessData

Delayed Imports

SCREENCONNECT.CORE, VERSION=25.2.4.9229, CULTURE=NEUTRAL, PUBLICKEYTOKEN=4B14C015C87C1AD8

Type FILES
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x86800
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.03377
Detected Filetype PE Executable
MD5 1db8b9fa0bdcbfaab807f715c288c19a 🔍
SHA1 fde73710ce063bbf1e377c02a1a8615cf4da1c08 🔍
SHA256 b8100e5ab07983cbf82d721cf719576ca3f60e352628dcaabd42d428011fdedf 🔍
SHA3 c5eb843629f73ec15acd1722a99fd91281ba32a1b9dfd2892e34a97cb3a074c8 🔍

SCREENCONNECT.WINDOWS, VERSION=25.2.4.9229, CULTURE=NEUTRAL, PUBLICKEYTOKEN=4B14C015C87C1AD8

Type FILES
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1a6200
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.64051
Detected Filetype PE Executable
MD5 94216eb90ca53fbb175f0ee6adbfb663 🔍
SHA1 48038f060a5042ff44a2d9a9be46368ecc8436fd 🔍
SHA256 da29455a64858fda773319c32c0a6cd40edbe8042ed005aa2befb8a4f0fb0522 🔍
SHA3 c0d0d35a90d19d6017cbb9f6dc944b3fb217ab8d4250312381fe5ea6ab260256 🔍

SCREENCONNECT.WINDOWSINSTALLER, VERSION=25.2.4.9229, CULTURE=NEUTRAL, PUBLICKEYTOKEN=4B14C015C87C1AD8

Type FILES
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1ac00
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.96255
Detected Filetype PE Executable
MD5 9de128d686e0979814b03bf08c68f4d9 🔍
SHA1 f865baae13625d58407beaf87b78a65f7167506f 🔍
SHA256 e84dfe0b660f1698d83b0ee959c1b228eb51e2d5cbee90fcc2fe987a6fe08441 🔍
SHA3 b8fbf3717f3faf5a2f3ff5ef2af41423938d89159301ab494bd97c85ae1b0578 🔍

_ENTRYPOINT

Type FILES
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2ee318
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.85897
Detected Filetype PE Executable
MD5 eee6046b7fd458287a02920189013df5 🔍
SHA1 59895908b51d11bb2b877550361add28749b8e54 🔍
SHA256 471f006f8fa65639c35f754bf173b5f7749e0e0bbc4c8e1a699c5358b995684c 🔍
SHA3 d14165127e35b1483659003623af78a10445b1e9fb6512fa1093881b7e05c8d8 🔍

_RESOLVER

Type FILES
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1600
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.8513
Detected Filetype PE Executable
MD5 5fb6074b08ac4709cf2f29fa5b49023e 🔍
SHA1 8bbb78a47c08867c50572f0bd2a27171f91e0454 🔍
SHA256 19ac323ca6eae2f8145cdc2bac865b32cd5a48ad6ff199d4ca7da214b056e1dc 🔍
SHA3 eb83af41dc4d6892c7cc83fb60c611dba627b071327701d962d5e5922dd0d815 🔍

1

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x188
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89623
MD5 b8e76ddb52d0eb41e972599ff3ca431b 🔍
SHA1 fc12d7ad112ddabfcd8f82f290d84e637a4d62f8 🔍
SHA256 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8 🔍
SHA3 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd 🔍

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2022-Nov-18 20:10:20
Version 0.0
SizeofData 103
AddressOfRawData 0x1214c
PointerToRawData 0x1074c
Referenced File C:\Users\jmorgan\Source\cwcontrol\Custom\DotNetRunner\Release\DotNetRunner.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2022-Nov-18 20:10:20
Version 0.0
SizeofData 20
AddressOfRawData 0x121b4
PointerToRawData 0x107b4

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2022-Nov-18 20:10:20
Version 0.0
SizeofData 752
AddressOfRawData 0x121c8
PointerToRawData 0x107c8

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2022-Nov-18 20:10:20
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

Load Configuration

Size 0xc0
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x414000
SEHandlerTable 0x41209c
SEHandlerCount 6

RICH Header

XOR Key 0xb6603e45
Unmarked objects 0
241 (40116) 10
243 (40116) 122
242 (40116) 24
C++ objects (VS2022 Update 3 (17.3.0) compiler 31616) 37
C objects (VS2022 Update 3 (17.3.0) compiler 31616) 17
ASM objects (VS2022 Update 3 (17.3.0) compiler 31616) 20
Imports (VS2008 SP1 build 30729) 4
Imports (VS2008 build 21022) 3
Total imports 96
C++ objects (LTCG) (VS2022 Update 3 (17.3.4-6) compiler 31630) 1
Resource objects (VS2022 Update 3 (17.3.4-6) compiler 31630) 1
Linker (VS2022 Update 3 (17.3.4-6) compiler 31630) 1

Errors

Leave a comment

No comments yet.