ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    ScreenConnect/Connectwise control client exe (marked as malicious)

    IT Discussion
    connectwise screenconnect antivirus
    5
    27
    4.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JaredBuschJ
      JaredBusch @scottalanmiller
      last edited by

      @scottalanmiller said in ScreenConnect/Connectwise control client exe (marked as malicious):

      @JaredBusch said in ScreenConnect/Connectwise control client exe (marked as malicious):

      How is that useful? The executable is rebuilt on every install for every group that it auto links to. that makes a hash useless.

      that's what I was expecting. If you deploy early, you get a new hash that no one has seen yet.

      You misunderstand. Every install will have a unique hash because the executable is BUILT by the system on the fly.

      scottalanmillerS 1 Reply Last reply Reply Quote 1
      • scottalanmillerS
        scottalanmiller @JaredBusch
        last edited by

        @JaredBusch said in ScreenConnect/Connectwise control client exe (marked as malicious):

        @scottalanmiller said in ScreenConnect/Connectwise control client exe (marked as malicious):

        @JaredBusch said in ScreenConnect/Connectwise control client exe (marked as malicious):

        How is that useful? The executable is rebuilt on every install for every group that it auto links to. that makes a hash useless.

        that's what I was expecting. If you deploy early, you get a new hash that no one has seen yet.

        You misunderstand. Every install will have a unique hash because the executable is BUILT by the system on the fly.

        Oh, right, duh. That too. That's way bigger as it is ONLY you ever submitting them.

        1 Reply Last reply Reply Quote 0
        • dbeatoD
          dbeato @JaredBusch
          last edited by

          @JaredBusch said in ScreenConnect/Connectwise control client exe (marked as malicious):

          @dbeato said in ScreenConnect/Connectwise control client exe (marked as malicious):

          @scottalanmiller said in ScreenConnect/Connectwise control client exe (marked as malicious):

          @dbeato no, just an online file by file virus scanner?

          No, (although it should be for another thread) it gives you information about the file, file hash. or URL in question. Example below is the Itarian Remote Control application Executable:
          2019-04-23_0039.png

          It compares the has of the file to multiple AV and Technology companies to see if the hash has been flagged as malicious or not or if it is questionable.

          How is that useful? The executable is rebuilt on every install for every group that it auto links to. that makes a hash useless.

          That might be true for ConnectWise but not all Executables create a new hash everytime.

          JaredBuschJ scottalanmillerS 2 Replies Last reply Reply Quote 0
          • JaredBuschJ
            JaredBusch @dbeato
            last edited by

            @dbeato said in ScreenConnect/Connectwise control client exe (marked as malicious):

            @JaredBusch said in ScreenConnect/Connectwise control client exe (marked as malicious):

            @dbeato said in ScreenConnect/Connectwise control client exe (marked as malicious):

            @scottalanmiller said in ScreenConnect/Connectwise control client exe (marked as malicious):

            @dbeato no, just an online file by file virus scanner?

            No, (although it should be for another thread) it gives you information about the file, file hash. or URL in question. Example below is the Itarian Remote Control application Executable:
            2019-04-23_0039.png

            It compares the has of the file to multiple AV and Technology companies to see if the hash has been flagged as malicious or not or if it is questionable.

            How is that useful? The executable is rebuilt on every install for every group that it auto links to. that makes a hash useless.

            That might be true for ConnectWise but not all Executables create a new hash everytime.

            That is the entire point of this thread though.

            dbeatoD 1 Reply Last reply Reply Quote 1
            • dbeatoD
              dbeato @JaredBusch
              last edited by

              @JaredBusch said in ScreenConnect/Connectwise control client exe (marked as malicious):

              @dbeato said in ScreenConnect/Connectwise control client exe (marked as malicious):

              @JaredBusch said in ScreenConnect/Connectwise control client exe (marked as malicious):

              @dbeato said in ScreenConnect/Connectwise control client exe (marked as malicious):

              @scottalanmiller said in ScreenConnect/Connectwise control client exe (marked as malicious):

              @dbeato no, just an online file by file virus scanner?

              No, (although it should be for another thread) it gives you information about the file, file hash. or URL in question. Example below is the Itarian Remote Control application Executable:
              2019-04-23_0039.png

              It compares the has of the file to multiple AV and Technology companies to see if the hash has been flagged as malicious or not or if it is questionable.

              How is that useful? The executable is rebuilt on every install for every group that it auto links to. that makes a hash useless.

              That might be true for ConnectWise but not all Executables create a new hash everytime.

              That is the entire point of this thread though.

              You are correct, that's why I wanted to move the portion of VirusTotal conversation out this thread.

              scottalanmillerS 1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller @dbeato
                last edited by

                @dbeato said in ScreenConnect/Connectwise control client exe (marked as malicious):

                @JaredBusch said in ScreenConnect/Connectwise control client exe (marked as malicious):

                @dbeato said in ScreenConnect/Connectwise control client exe (marked as malicious):

                @JaredBusch said in ScreenConnect/Connectwise control client exe (marked as malicious):

                @dbeato said in ScreenConnect/Connectwise control client exe (marked as malicious):

                @scottalanmiller said in ScreenConnect/Connectwise control client exe (marked as malicious):

                @dbeato no, just an online file by file virus scanner?

                No, (although it should be for another thread) it gives you information about the file, file hash. or URL in question. Example below is the Itarian Remote Control application Executable:
                2019-04-23_0039.png

                It compares the has of the file to multiple AV and Technology companies to see if the hash has been flagged as malicious or not or if it is questionable.

                How is that useful? The executable is rebuilt on every install for every group that it auto links to. that makes a hash useless.

                That might be true for ConnectWise but not all Executables create a new hash everytime.

                That is the entire point of this thread though.

                You are correct, that's why I wanted to move the portion of VirusTotal conversation out this thread.

                But that's the basis of his concern is that tools like that were identifying it. Take out that stuff, and there is no thread.

                1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller @dbeato
                  last edited by

                  @dbeato said in ScreenConnect/Connectwise control client exe (marked as malicious):

                  @JaredBusch said in ScreenConnect/Connectwise control client exe (marked as malicious):

                  @dbeato said in ScreenConnect/Connectwise control client exe (marked as malicious):

                  @scottalanmiller said in ScreenConnect/Connectwise control client exe (marked as malicious):

                  @dbeato no, just an online file by file virus scanner?

                  No, (although it should be for another thread) it gives you information about the file, file hash. or URL in question. Example below is the Itarian Remote Control application Executable:
                  2019-04-23_0039.png

                  It compares the has of the file to multiple AV and Technology companies to see if the hash has been flagged as malicious or not or if it is questionable.

                  How is that useful? The executable is rebuilt on every install for every group that it auto links to. that makes a hash useless.

                  That might be true for ConnectWise but not all Executables create a new hash everytime.

                  And in those unrelated cases, lots of things flagging the would be more meaningful.

                  1 Reply Last reply Reply Quote 0
                  • 1
                  • 2
                  • 2 / 2
                  • First post
                    Last post