Is ServiceExeWithService safe?
Multiple engines identify confirmed ConnectWise remote-administration tooling, while runtime service creation and defense-impairment techniques create substantial risk of unauthorized persistent access.
Nine of 74 engines flagged the executable, including corroborated ConnectWise Control hacktool labels and two tier-1 detections. A sandbox observed installation as a service and defense-impairment behavior; although this software can have legitimate administrative uses, it should not run unless its deployment is explicitly authorized.
c934cc868a7e985753…13e09c93142cb9Recommended next actions
Before opening
Do not open it. Delete this file from the device, then empty the Recycle Bin or Trash.
If you already opened it
Close it. If it opened links, requested credentials, or triggered unexpected behavior, disconnect from the internet and run a full device scan.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Nine of 74 engines flagged the executable, including corroborated ConnectWise Control hacktool labels and two tier-1 detections. A sandbox observed installation as a service and defense-impairment behavior; although this software can have legitimate administrative uses, it should not run unless its deployment is explicitly authorized.
The executable is consistently identified as ConnectWise Control or remote-administration software, with confirmed hacktool labeling from multiple engines. Nine of 74 engines flagged it, including two tier-1 engines, although no strong tier-1 family consensus formed. Runtime observation recorded service creation for screenconnect.clientservice.exe and techniques T1543.003 and T1562.001, which can provide persistent remote access and interfere with defenses. Five YARA rules matched, including a ScreenConnect-specific certificate indicator, while three related signer or imphash samples previously received suspicious remoteadmin assessments. No complete reputation check is available for the contacted IP addresses because contactedHosts is null, so those connections cannot be characterized as clean or confirmed malicious.
What We Detected
Nine of 74 antivirus engines flagged the executable. Huorong and Rising explicitly identified ConnectWise Control as a hacktool, DrWeb labeled it remote-administration software, and engines.hacktoolConfirmed=true establishes corroboration. Five YARA rules also matched, including INDICATOR_RMM_ConnectWise_ScreenConnect_CERT.
Threat Behavior
One completed sandbox run observed the ScreenConnect client service being created through sc create. The recorded techniques include T1543.003 for Windows service persistence and T1562.001 for impairing defenses. The sample contacted multiple IP addresses directly, but contactedHosts=null means no complete host-reputation result is available; none of those contacts should be described as clean or confirmed command-and-control from this evidence alone.
What To Do Now
Quarantine the executable and verify whether ConnectWise Control was intentionally deployed by an authorized administrator or support provider. If it was not authorized, isolate the endpoint, remove the created service using approved incident-response procedures, preserve logs, and investigate remote sessions and credential exposure while keeping endpoint protection enabled.
Where this verdict could be wrong5 caveats
- 15 of 17 tier-1 engines did not flag the sample, and engines.tier1FamilyConsensus.strong=false.
- behaviour.hasMaliciousSandboxVerdict=false, although the sandbox still observed T1543.003 and T1562.001.
- droppedChildren.hasMaliciousChild=false, but all three inspected children remained unclassified rather than affirmatively benign.
- The file is signed as 'Connectwise', but signing.verified=null, the certificate is tagged revoked, and signing.signerStats has only two samples with no established safe history.
- Several of the five YARA rules concern certificates or generic PE traits; the ScreenConnect-specific rule is the most relevant match.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 15 of 17 tier-1 engines did not flag the file
- behaviour.hasMaliciousSandboxVerdict=false
- droppedChildren.hasMaliciousChild=false
- brandMismatch was not detected
- peAnalysis.likelyPacked=false and peAnalysis.highEntropyCode=false
- engines.hacktoolConfirmed=true for ConnectWise Control
- 9/74 antivirus detections, including two tier-1 detections
- T1543.003 Windows service persistence observed at runtime
- T1562.001 defense-impairment technique observed at runtime
- Direct-IP network activity lacks a complete contacted-host reputation check
- File tags include revoked-cert and long-sleeps
Quarantine this executable unless its ConnectWise deployment is explicitly authorized and independently verified. For an unapproved installation, isolate the host and investigate persistence, remote access, and credentials while keeping endpoint protection enabled.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete9 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial14 runtime contacts were observed without a completed reputation cross-check.
YARA
Complete7 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 11MITRE ATT&CK techniques
- 11spawned processes
- 14network contacts
- 17filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Created or modified a system service, which can keep code running.
High concern: Attempted to impair or bypass security controls.
Moderate concern: Runs hidden system commands (script or shell).
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
Moderate concern: Checked the environment for virtualisation or analysis tools.
Note: Collects details about your system.
Note: Loads extra code modules while running.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Threat context
How hacktools are abused
This is a hacking or cracking tool — the kind used to bypass software licences, generate fake keys, or attack other systems. Even when the tool 'works', these downloads very often carry hidden malware.
Bottom line:Running one means trusting an anonymous author with full access to your PC — rarely worth the risk.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
ServiceExeWithService
c934cc868a7e985753ccaaef66d3e0714819be1d5549d600e113e09c93142cb9
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\<USER>\AppData\Local\Temp\screenconnect.clientservice.exe"
02Isolated runtime analysis - ProcessObserved
Observed process
%SAMPLEPATH%\screenconnect.clientservice.exe
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
Policies
C:\Program Files\Google\Policies
04Isolated runtime analysis - Written fileObserved
GUM448.tmp
C:\Program Files\Google\Temp\GUM448.tmp
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
20.99.186.246
Contact observed during runtime.
06Isolated runtime analysis - Contacted hostObserved
192.229.211.108
Contact observed during runtime.
07Isolated runtime analysis - +1 more recorded observation in Analyst mode
7 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 20.99.186.246
- 192.229.211.108
- 184.25.191.235
- 20.99.133.109
- 20.99.185.48
- 23.216.147.64
- 20.99.184.37
- 23.62.209.152
- 192.168.0.59
- 23.216.81.152
- C:\Program Files\Google\Policies
- C:\Program Files\Google\Temp\GUM448.tmp
- C:\Program Files\Google\Temp\GUMDCE9.tmp
- C:\Windows\System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser
- C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\screenconnect.clientservice.exe.log
- C:\Windows\System32\spp\store\2.0\cache\cache.dat
- %USERPROFILE%\AppData\Local\Microsoft\Windows\INetCache\IE\KLT1I0ZU\update50[1].xml
- C:\Program Files\Google\Temp\GUM448.tmp
- C:\Program Files\Google\Temp\GUMDCE9.tmp
- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\config\security.config.cch.1820.387817
- Global\CLR_CASOFF_MUTEX
- \BaseNamedObjects\Local\SM0:7664:168:WilStaging_02
Files this sample writes at runtime
This file drops 3 children at runtime. None are currently flagged malicious in our cache.
- d8988d672d6915b46946…cc146bNever scannednever seen before
- 596ccc911c1772735aac…43fa7bNever scannednever seen before
- d4a190004f7f17d17722…efacc7Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 7rule hits recorded
- 9 / 74engines flagged
- 24sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
5 high-confidence signature or behavior rules matched this file.
Verdict inputView chapterProvenanceObservedSourceSignature and behavior rulesObserved at - 02
9 of 74 antivirus engines flagged the file, including DrWeb and huorong.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 03
YARAify matched 5 researcher rules to this file.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: ServiceExeWithService — c934cc868a7e985753ccaaef66d3e0714819be1d5549d600e113e09c93142cb9
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\AppData\Local\Temp\screenconnect.clientservice.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — %SAMPLEPATH%\screenconnect.clientservice.exe
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: Policies — C:\Program Files\Google\Policies
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: GUM448.tmp — C:\Program Files\Google\Temp\GUM448.tmp
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: 20.99.186.246 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 10
Contacted host: 192.229.211.108 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
Category: hacktool
One or more independent reference databases matched this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
- DebuggerCheck__API
- INDICATOR_RMM_ConnectWise_ScreenConnect_CERT
- maldoc_find_kernel32_base_method_1
- PE_Digital_Certificate
- PE_Potentially_Signed_Digital_Certificate
Sample spawned schtasks / PowerShell scheduled-task cmdlets / sc create. Persistence mechanism.
EvidenceC:\Windows\SysWOW64\cmd.exe cmd /c sc create PHIKo binpath= "C:\Users\user\Desktop\screenconnect.clientservice.exe" >> C:\servicereg.log 2>&1The sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence20.99.186.246 · 192.229.211.108 · 184.25.191.235
9 of 74 engines flagged this file
View all 74 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- ServiceExeWithService
- Format
- Win32 EXE
- Code signing
- Signature not verified: Connectwise
- Size
- 93.3 KB
- Last analyzed
- Sep 23, 2026, 8:08 AM UTC
c934cc868a7e985753ccaaef66d3e0714819be1d5549d600e113e09c93142cb9Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file is dangerous. Treat it as harmful and remove it.
- Recovery step 01
Don't open this file. Delete this file from the device, then empty the Recycle Bin or Trash.
- Recovery step 02
If you already opened it, disconnect from the internet and start with a full antivirus scan or Microsoft Defender Offline scan. If compromise is suspected or the problem persists, use a reputable second-opinion scanner and follow incident-recovery or clean-reinstall guidance.
- Recovery step 03
If you typed any passwords while it was open, change them from a device you trust.
- Recovery step 04
Get a fresh copy from the original trusted source and verify its exact hash when possible.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is ServiceExeWithService malware?
What is ServiceExeWithService?
How many antivirus engines detected ServiceExeWithService?
I already downloaded and opened ServiceExeWithService — what should I do?
How do I remove ServiceExeWithService?
What kind of malware is ServiceExeWithService?
Is ServiceExeWithService digitally signed?
What is the SHA-256 hash of ServiceExeWithService?
How up to date is this analysis of ServiceExeWithService?
Community
Member reviews and reports for this exact file hash.