ScreenConnect/Connectwise control client exe (marked as malicious)
-
PUP is an indicator for software that could be bad, but isn't. ALL remote access and monitoring can be used for malicious purposes. So it is often marked as PUP. Even if every tool ever made marked something as PUP, this would never give reason for concern unless you hadn't meant to install a remote access too. But you did, you knowingly installed ConnectWise, so you should be expecting PUP warnings from to time if you don't exclude it, just like all tools will do sometimes. Since you know that you installed it intentionally, you know that the PUP warning does not apply to you.
-
@scottalanmiller said in ScreenConnect/Connectwise control client exe (marked as malicious):
PUP is an indicator for software that could be bad, but isn't. ALL remote access and monitoring can be used for malicious purposes. So it is often marked as PUP. Even if every tool ever made marked something as PUP, this would never give reason for concern unless you hadn't meant to install a remote access too. But you did, you knowingly installed ConnectWise, so you should be expecting PUP warnings from to time if you don't exclude it, just like all tools will do sometimes. Since you know that you installed it intentionally, you know that the PUP warning does not apply to you.
We do get PUP alerts on our environment and most of them are ignored. In this case if you look at the results I shared, PUP is on just my AV, some others shows as Trojan
-
@scottalanmiller said in ScreenConnect/Connectwise control client exe (marked as malicious):
@dbeato no, just an online file by file virus scanner?
No, (although it should be for another thread) it gives you information about the file, file hash. or URL in question. Example below is the Itarian Remote Control application Executable:
It compares the has of the file to multiple AV and Technology companies to see if the hash has been flagged as malicious or not or if it is questionable.
-
@dbeato said in ScreenConnect/Connectwise control client exe (marked as malicious):
@scottalanmiller said in ScreenConnect/Connectwise control client exe (marked as malicious):
@dbeato no, just an online file by file virus scanner?
No, (although it should be for another thread) it gives you information about the file, file hash. or URL in question. Example below is the Itarian Remote Control application Executable:
It compares the has of the file to multiple AV and Technology companies to see if the hash has been flagged as malicious or not or if it is questionable.
How is that useful? The executable is rebuilt on every install for every group that it auto links to. that makes a hash useless.
-
@Ambarishrh said in ScreenConnect/Connectwise control client exe (marked as malicious):
We do get PUP alerts on our environment and most of them are ignored. In this case if you look at the results I shared, PUP is on just my AV, some others shows as Trojan
Then I'd be really wary of those. The problem is, what is a Trojan to one person is remote management to another. It's like a terrorist.... everyone's army is someone else's terrorist. It's all perspective.
-
@JaredBusch said in ScreenConnect/Connectwise control client exe (marked as malicious):
How is that useful? The executable is rebuilt on every install for every group that it auto links to. that makes a hash useless.
that's what I was expecting. If you deploy early, you get a new hash that no one has seen yet.
-
@scottalanmiller said in ScreenConnect/Connectwise control client exe (marked as malicious):
@JaredBusch said in ScreenConnect/Connectwise control client exe (marked as malicious):
How is that useful? The executable is rebuilt on every install for every group that it auto links to. that makes a hash useless.
that's what I was expecting. If you deploy early, you get a new hash that no one has seen yet.
You misunderstand. Every install will have a unique hash because the executable is BUILT by the system on the fly.
-
@JaredBusch said in ScreenConnect/Connectwise control client exe (marked as malicious):
@scottalanmiller said in ScreenConnect/Connectwise control client exe (marked as malicious):
@JaredBusch said in ScreenConnect/Connectwise control client exe (marked as malicious):
How is that useful? The executable is rebuilt on every install for every group that it auto links to. that makes a hash useless.
that's what I was expecting. If you deploy early, you get a new hash that no one has seen yet.
You misunderstand. Every install will have a unique hash because the executable is BUILT by the system on the fly.
Oh, right, duh. That too. That's way bigger as it is ONLY you ever submitting them.
-
@JaredBusch said in ScreenConnect/Connectwise control client exe (marked as malicious):
@dbeato said in ScreenConnect/Connectwise control client exe (marked as malicious):
@scottalanmiller said in ScreenConnect/Connectwise control client exe (marked as malicious):
@dbeato no, just an online file by file virus scanner?
No, (although it should be for another thread) it gives you information about the file, file hash. or URL in question. Example below is the Itarian Remote Control application Executable:
It compares the has of the file to multiple AV and Technology companies to see if the hash has been flagged as malicious or not or if it is questionable.
How is that useful? The executable is rebuilt on every install for every group that it auto links to. that makes a hash useless.
That might be true for ConnectWise but not all Executables create a new hash everytime.
-
@dbeato said in ScreenConnect/Connectwise control client exe (marked as malicious):
@JaredBusch said in ScreenConnect/Connectwise control client exe (marked as malicious):
@dbeato said in ScreenConnect/Connectwise control client exe (marked as malicious):
@scottalanmiller said in ScreenConnect/Connectwise control client exe (marked as malicious):
@dbeato no, just an online file by file virus scanner?
No, (although it should be for another thread) it gives you information about the file, file hash. or URL in question. Example below is the Itarian Remote Control application Executable:
It compares the has of the file to multiple AV and Technology companies to see if the hash has been flagged as malicious or not or if it is questionable.
How is that useful? The executable is rebuilt on every install for every group that it auto links to. that makes a hash useless.
That might be true for ConnectWise but not all Executables create a new hash everytime.
That is the entire point of this thread though.
-
@JaredBusch said in ScreenConnect/Connectwise control client exe (marked as malicious):
@dbeato said in ScreenConnect/Connectwise control client exe (marked as malicious):
@JaredBusch said in ScreenConnect/Connectwise control client exe (marked as malicious):
@dbeato said in ScreenConnect/Connectwise control client exe (marked as malicious):
@scottalanmiller said in ScreenConnect/Connectwise control client exe (marked as malicious):
@dbeato no, just an online file by file virus scanner?
No, (although it should be for another thread) it gives you information about the file, file hash. or URL in question. Example below is the Itarian Remote Control application Executable:
It compares the has of the file to multiple AV and Technology companies to see if the hash has been flagged as malicious or not or if it is questionable.
How is that useful? The executable is rebuilt on every install for every group that it auto links to. that makes a hash useless.
That might be true for ConnectWise but not all Executables create a new hash everytime.
That is the entire point of this thread though.
You are correct, that's why I wanted to move the portion of VirusTotal conversation out this thread.
-
@dbeato said in ScreenConnect/Connectwise control client exe (marked as malicious):
@JaredBusch said in ScreenConnect/Connectwise control client exe (marked as malicious):
@dbeato said in ScreenConnect/Connectwise control client exe (marked as malicious):
@JaredBusch said in ScreenConnect/Connectwise control client exe (marked as malicious):
@dbeato said in ScreenConnect/Connectwise control client exe (marked as malicious):
@scottalanmiller said in ScreenConnect/Connectwise control client exe (marked as malicious):
@dbeato no, just an online file by file virus scanner?
No, (although it should be for another thread) it gives you information about the file, file hash. or URL in question. Example below is the Itarian Remote Control application Executable:
It compares the has of the file to multiple AV and Technology companies to see if the hash has been flagged as malicious or not or if it is questionable.
How is that useful? The executable is rebuilt on every install for every group that it auto links to. that makes a hash useless.
That might be true for ConnectWise but not all Executables create a new hash everytime.
That is the entire point of this thread though.
You are correct, that's why I wanted to move the portion of VirusTotal conversation out this thread.
But that's the basis of his concern is that tools like that were identifying it. Take out that stuff, and there is no thread.
-
@dbeato said in ScreenConnect/Connectwise control client exe (marked as malicious):
@JaredBusch said in ScreenConnect/Connectwise control client exe (marked as malicious):
@dbeato said in ScreenConnect/Connectwise control client exe (marked as malicious):
@scottalanmiller said in ScreenConnect/Connectwise control client exe (marked as malicious):
@dbeato no, just an online file by file virus scanner?
No, (although it should be for another thread) it gives you information about the file, file hash. or URL in question. Example below is the Itarian Remote Control application Executable:
It compares the has of the file to multiple AV and Technology companies to see if the hash has been flagged as malicious or not or if it is questionable.
How is that useful? The executable is rebuilt on every install for every group that it auto links to. that makes a hash useless.
That might be true for ConnectWise but not all Executables create a new hash everytime.
And in those unrelated cases, lots of things flagging the would be more meaningful.