ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)
Attackers phish victims into running a signed ScreenConnect client that calls an attacker instance.
SANS ISC analyzed a phishing email that linked to ScreenConnect.ClientSetup.exe hosted on thelittlecupandsaucer.com.au. The file is a legitimate ConnectWise-signed ScreenConnect client preconfigured to relay to instance-v2e3e2-relay.screenconnect.com on port 443, using the attacker’s cloud instance rather than a tampered binary. The diary notes the Authenticode signature was intact and points defenders to the LOLRMM project, which tracks abused remote-management tools such as AnyDesk, TeamViewer, and NetSupport Manager.
- Phishing link delivered a ConnectWise-signed ScreenConnect client installer.
- Installer callbacks to attacker cloud instance v2e3e2 over port 443.
- Authenticode signature was intact with no post-sign tampering.
- Diary highlights widespread abuse of trusted RMM tools.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | instance-v2e3e2-relay.screenconnect.com | ation extracted from the PE file: Parameter Value Relay (h) instance-v2e3e2-relay.screenconnect.com Port (p) 443 Instance ID v2e3e2 (ConnectWise-hosted cloud) |
| domain | mejuri.com | s... I received a very simple phishing email: From: contact@mejuri[.]com To: <redacted> Subject: EFT Wire Transfer Paid Invoice Re |
| domain | thelittlecupandsaucer.com.au | 1(332)638474823 “Click here” is a link pointing to: hxxps://thelittlecupandsaucer[.]com[.]au/ScreenConnect.ClientSetup.exe This email passed all the |
| url | https://thelittlecupandsaucer[ | pport: +1(332)638474823 “Click here” is a link pointing to: hxxps://thelittlecupandsaucer[.]com[.]au/ScreenConnect.ClientSetup.exe This email passed a |
Full article337 words · extracted from isc.sans.edu · click to collapse
Threat Actors do not always use top-notch techniques or very complex malware to perform their attacks. Sometimes, they just abuse of existing applications...
I received a very simple phishing email:
From: contact@mejuri[.]com To: <redacted> Subject: EFT Wire Transfer Paid Invoice Receipt Dear Customer, Payment of $5745.65 was Received. Please click here to view your Order Information in PDF If this charge wasn't authorized by you, contact our customer service to cancel and receive an immediate refund. Digitally Yours, Customer Support: +1(332)638474823
“Click here” is a link pointing to:
hxxps://thelittlecupandsaucer[.]com[.]au/ScreenConnect.ClientSetup.exe
This email passed all the basic security controls. The link points to a real PE file. Today this attack vector will be blocked by browsers because downloaded an executable is suspicious!
The PE file was unknown on VT so I did a quick analysis of it. It’s a legit application: a ScreenConnect[1] client preconfigured to call-back a test account operated by the Attacker. Here is the configuration extracted from the PE file:

|
Parameter |
Value |
|
Relay (h) |
instance-v2e3e2-relay.screenconnect.com |
|
Port (p) |
443 |
|
Instance ID |
v2e3e2 (ConnectWise-hosted cloud) |
|
Instance key (k) |
RSA-2048 public key, blob SHA256 16b1cec1…9b00ead7 |
The PE is signed by ConnectWise, LLC (DigiCert G4 Code Signing CA1). The Authenticode digest matches the signed digest exactly. There's no overlay and nothing appended to or injected into the certificate table, so the signed-but-tampered config trick isn't used here.
Such tools are a gold mine for attackers because they are easy to deploy and trusted by most used! The list of “RMM” (Remote Monitoring and Management) tools is huge. Here is a brief list of the well-known ones;
- ScreenConnect
- AnyDesk
- TeamViewer
- LogMeIn
- Bomgar (BeyondTrust Remote Support)
- Zoho Assist
- Remote utilities like rutserv.exe
- NetSupport Manager
- SimpleHelp
If you want a better overview, check LOLRMM project [2] that maintains a list similar to the LOLBAS project!
[1] https://www.screenconnect.com
[2] https://lolrmm.io
Xavier Mertens (@xme)
Senior ISC Handler | SANS Principal Instructor | Freelance Consultant
Xameco | PGP Key