{"id":"d60faab06fd2a96468f60d9d03ddede2","title":"ScreenConnect — ScreenConnect · 远程访问工具(RMM) · PE32","md5":"d60faab06fd2a96468f60d9d03ddede2","sha256":"302f4b1ccf1808fa57fd30f4e8e2723b283fc8a1d4fa86267d7d11183ada2715","family":"ScreenConnect","apt":null,"verdict":null,"sample_type":"远程访问工具(RMM)","lang":"Rust","file_format":"PE32","compiler":"Rust","published_at":"2026-08-10T16:00:00.000Z","summary":"该样本为 ConnectWise ScreenConnect（原 ConnectWise Control）远程访问代理的 Rust 编译版本，内置 CLIENT_LAUNCH_PARAMETERS 启动参数指向云中继 instance-q0mttg-relay.screenconnect.com:443，内含 RSA 公钥 （BgIAAACkAABSU0Ex...）用于与中继建立加密会话。ScreenConnect 是合法的远程支持软件，但被 LockBit、BlackCat 等勒索软件团伙大规模滥用于初始访问与横向移动（RMM abuse）。样本经 Rust 编译（官方客户端为 C#），且出现在 MalwareBazaar 恶意样本库中，高度疑似被投递用于未经授权的远程访问。CAPA 检出 PEB 访问、反 Xen 虚拟机字符串、资源提取、嵌入 PE 文件等能力。","url":"https://zseceye.com/report/d60faab06fd2a96468f60d9d03ddede2","json_url":"https://zseceye.com/report/d60faab06fd2a96468f60d9d03ddede2.json","html_url":"https://zseceye.com/report/d60faab06fd2a96468f60d9d03ddede2","hash_urls":{"md5":"https://zseceye.com/hash/d60faab06fd2a96468f60d9d03ddede2","sha256":"https://zseceye.com/hash/302f4b1ccf1808fa57fd30f4e8e2723b283fc8a1d4fa86267d7d11183ada2715"},"search_urls":{"md5":"https://zseceye.com/?q=d60faab06fd2a96468f60d9d03ddede2","sha256":"https://zseceye.com/?q=302f4b1ccf1808fa57fd30f4e8e2723b283fc8a1d4fa86267d7d11183ada2715"},"sample_download_url":"https://zseceye.com/report/d60faab06fd2a96468f60d9d03ddede2/sample","sample_filename":"302f4b1c.zip","iocs":[],"ips":[]}