🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 db3cf6dae0646bbe3715d66efb5efdc0a42c96efbbe4166e043d890a1a74c2db. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ConnectWise


Vendor detections: 6


Intelligence 6 IOCs YARA 5 File information Comments

SHA256 hash: db3cf6dae0646bbe3715d66efb5efdc0a42c96efbbe4166e043d890a1a74c2db
SHA3-384 hash: a045d563fae2055eb162ac023e3c2310d25ffdb9631aac63f19f7a7372fc20467239711e48939868734843ca92962961
SHA1 hash: 5884cfe792a0797f5b96805f76a512f3ed168141
MD5 hash: 3790fe18ecb8f14747f133508421bbc0
humanhash: nevada-alanine-summer-sodium
File name:Installer.msi
Download: download sample
Signature ConnectWise
File size:14'725'120 bytes
First seen:2026-09-11 19:36:49 UTC
Last seen:Never
File type:Microsoft Software Installer (MSI) msi
MIME type:application/x-msi
ssdeep 196608:mHxcp9ym3nltDUJVeHxcp9ym3yHxcp9ym3DHxcp9ym3OHxcp9ym3dAHxcp9ym3d7:0GplpNGpAGptGpcGpduGpd/Gpdc
TLSH T156E623116BF89668F1F22A79E876A071A13B7C125D36D12E2324791E2C75EC0C9B3737
TrID 80.0% (.MSI) Microsoft Windows Installer (454500/1/170)
10.7% (.MST) Windows SDK Setup Transform script (61000/1/5)
7.8% (.MSP) Windows Installer Patch (44509/10/5)
1.4% (.) Generic OLE2 / Multistream Compound (8000/1)
Magika msi
Reporter BastianHein
Tags:ConnectWise msi

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
CL CL
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug anti-vm base64 CAB evasive expand expired-cert explorer fingerprint installer installer lolbin lolbin overlay packed packed reconnaissance rundll32
Verdict:
Unknown
File Type:
Msi
First seen:
2026-06-03T15:51:00Z UTC
Last seen:
2026-06-03T15:51:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
.Net CAB:COMPRESSION:LZX CAB:COMPRESSION:NONE Executable Managed .NET Office Document PDB Path PE (Portable Executable) PE File Layout PE Memory-Mapped (Dump) SOS: 0.21 SOS: 0.24 SOS: 0.25 SOS: 0.26 SOS: 0.27 SOS: 0.31 SOS: 0.32 SOS: 0.36 SOS: 0.39
Threat name:
ByteCode-MSIL.PUA.RAdminConnectWise
Status:
Malicious
First seen:
2026-05-13 04:05:40 UTC
File Type:
Binary (Archive)
Extracted files:
175
AV detection:
13 of 36 (36.11%)
Threat level:
  1/5
Verdict:
malicious
Label(s):
ADMINTOOL_ScreenConnect
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:INDICATOR_RMM_ConnectWise_ScreenConnect
Author:ditekSHen
Description:Detects ConnectWise Control (formerly ScreenConnect). Review RMM Inventory
Rule name:NET
Author:malware-lu
Rule name:RANSOMWARE
Author:ToroGuitar

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments