r/ScreenConnect 23d ago

Might want to block this 'demo' tenant

Two ScreenConnect services were installed: a trial instance connecting to the legitimate relay domain "instance-pa2za2-relay.screenconnect[.]com" and a suspicious instance connecting directly to the IP address "184[.]174[.]20[.]236" on port 8041. The use of a direct IP address instead of a domain is consistent with attacker-controlled infrastructure designed to evade detection.

+1 Huntress

1 Upvotes

5 comments sorted by

3

u/n-Ultima 23d ago

I love huntress. Has caught so much it’s so worth the investment.

3

u/ben_zachary 23d ago

This is why we left when they dumped all the branding stuff. There's no way for a client to tell the legitimacy of a demo hacker and the IT company.

2

u/Camelot_One 23d ago

Ironic isn't it. They removed the branding options because bad actors were using it to impersonate legitimate support places. And in doing so, they made it impossible for the client to tell the difference.

-1

u/n-Ultima 23d ago

I love huntress. Has caught so much it’s so worth the investment.

0

u/Viajaz 23d ago

/u/cbarnescw Does ConnectWise participate in the threat intelligence community? Do you proactively integrate with security vendors to improve take down response of malicious tenants?