MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 48752c8ecb8ddbb0661bcde333109566836d8d0033ebfb9223e19b1a43748cde. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
ConnectWise
Vendor detections: 12
| SHA256 hash: | 48752c8ecb8ddbb0661bcde333109566836d8d0033ebfb9223e19b1a43748cde |
|---|---|
| SHA3-384 hash: | c3b5c503e66fed402c2dadc3434103b619425144c66d36a2788a8672fb44c7e34b78ea6a69c5cafb6c82d61961d57c6b |
| SHA1 hash: | 5974ba29b9b84fca2907b8d1e794dca2859ad2dc |
| MD5 hash: | fdd1bebcc1f0d9bc496ebc7d896893d0 |
| humanhash: | potato-march-spring-chicken |
| File name: | support.client.exe |
| Download: | download sample |
| Signature | ConnectWise |
| File size: | 312'552 bytes |
| First seen: | 2026-06-01 07:08:08 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | c2fe6927e1db8cf00400dbef9e5d35be (304 x ConnectWise) |
| ssdeep | 6144:KmlfAgiw7Op5ryNkS7Z12wvtGVG3iVt8eZ1u2J/xFji9:51iw7gryNkSV1hy1Z1u2JLu9 |
| TLSH | T136647D11B9C48432C673383147B4E2B28DBDB8301D655B8F57A81D7A9F741D0EA29B6F |
| TrID | 50.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13) 10.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 10.5% (.EXE) Win64 Executable (generic) (6522/11/2) 8.1% (.EXE) Win16 NE executable (generic) (5038/12/1) 7.2% (.EXE) Win32 Executable (generic) (4504/4/1) |
| Magika | pebin |
| Reporter | |
| Tags: | ConnectWise signed |
Code Signing Certificate
| Organisation: | Connectwise, LLC |
|---|---|
| Issuer: | DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 |
| Algorithm: | sha256WithRSAEncryption |
| Valid from: | 2022-08-17T00:00:00Z |
| Valid to: | 2025-08-15T23:59:59Z |
| Serial number: | 0b9360051bccf66642998998d5ba97ce |
| Intelligence: | 965 malware samples on MalwareBazaar are signed with this code signing certificate |
| Thumbprint Algorithm: | SHA256 |
| Thumbprint: | 82b4e7924d5bed84fb16ddf8391936eb301479cec707dc14e23bc22b8cdeae28 |
| Source: | This information was brought to you by ReversingLabs A1000 Malware Analysis Platform |