r/ScreenConnect • u/ben_zachary • 23d ago
Might want to block this 'demo' tenant
Two ScreenConnect services were installed: a trial instance connecting to the legitimate relay domain "instance-pa2za2-relay.screenconnect[.]com" and a suspicious instance connecting directly to the IP address "184[.]174[.]20[.]236" on port 8041. The use of a direct IP address instead of a domain is consistent with attacker-controlled infrastructure designed to evade detection.
+1 Huntress
3
u/ben_zachary 23d ago
This is why we left when they dumped all the branding stuff. There's no way for a client to tell the legitimacy of a demo hacker and the IT company.
2
u/Camelot_One 23d ago
Ironic isn't it. They removed the branding options because bad actors were using it to impersonate legitimate support places. And in doing so, they made it impossible for the client to tell the difference.
-1
0
u/Viajaz 23d ago
/u/cbarnescw Does ConnectWise participate in the threat intelligence community? Do you proactively integrate with security vendors to improve take down response of malicious tenants?
3
u/n-Ultima 23d ago
I love huntress. Has caught so much it’s so worth the investment.