Taking out ConnectWise sites

https://rmhelp.top/

https://sehelp.top/

https://snhelp.top/

https://tchelp.top/

https://tdhelp.top/
https://uchelp.top/

https://uohelp.top/

https://uwhelp.top/ invitation only session

https://fuhelp.top/,
and,

https://ighelp.top/

https://iwhelp.top/

https://jnhelp.top/

https://johelp.top/

https://jxhelp.top/,
and,
https://kmhelp.top/

https://krhelp.top/?__cf_chl_tk=LBrH7oSBFgr5hHU7NqiJ2I7Mb7cXU7ayN4tWd8CO_Xo-1735428721-1.0.1.1-oiebLgbSrpxIks_qKg3XBbcijAQO1gLMcHu3cxuN1A4

Active today,
https://lehelp.top/
https://lwhelp.top/

https://mhhelp.top

https://mthelp.top,
and,
https://nmhelp.top

https://nphelp.top invitation only session, atm…
and,
https://oihelp.top/
https://oqhelp.top/,
and,
https://pfhelp.top/
https://pqhelp.top/

how do we shut them down ?

It’s very difficult to shut down as they come up with new sites all the time, but we are working on it, I’ll DM you some details.

https://qhhelp.top/,
https://qzhelp.top/,
https://fihelp.top/?__cf_chl_rt_tk=kMqb1iaSjzaygiVhhUJGaVJE3f.idCyWO8_j8WX8GCk-1735576545-1.0.1.1-ub9NfcT3pDFpeKAp11ArW7so6mLvpLn3j_eP3TEO7hw,
https://rmhelp.top/
https://sehelp.top/,
https://w4help.cc/

https://bqhelp.top/
https://brhelp.top/

This URL was in an email my elderly dad received and was supposedly a link to get his Social Security statement. He knows better than to click it and sent it to me. It leads to one of several URL’s and immediately issues a download called ā€œSSA.exeā€ which is actually ConnectWise. Here are the download URL’s I’ve found so far:

https://ssawebsecure.com/SSA/SSA.exe
https://away.vk.com/away.php?rh=869f04be-167b-439b-a5b4-21e8c68a3e37
https://away.vk.com/away.php?rh=444cd0cc-1517-46c1-850a-ab6e050bd012

I just did a (safe) test with SSA.exe in a VM using FakeNet and the sample reaches out to ziadversionfour.com.

Yeah, I just ran the same test and getting the error as well, but the SSA.EXE works and downloaded the ConnectWise.exe file, good link!

is connectwise like a rat ?

Yes, it’s exactly a rat!

https://zfhelp.top/,
and,
https://zghelp.top/ invitation only session atm.

care to DM me a lil more about it as well? I’m trying to write a script to extract the remote server where support.client.exe downloads the rest of it’s files (I assume it’s in there), maybe reporting those sites is more effective (the top sites barely shut down or are replaced really quick), thanks

01/02/25 jpcare.info 78.40.117.18 Alexhost/Namesilo
01/02/25 fxcebn2.top 37.221.64.108 Alexhost/Namesilo

https://www.afhelp.top/?__cf_chl_rt_tk=jWofVIDebR6ufALUI108zkOjo0ifNA6yF.Skh52.HaQ-1735855381-1.0.1.1-b.qZntxo1YORbx8ez4mMH2PpMD6RxTmUzAGtaEqyddk

https://tgvhelp.top/,
https://pklo.us/

01/06/25 as4care.help 37.221.64.202 Alexhost/Namesilo

Another - same IP

01/06/25 cesupport.help 37.221.64.202 Alexhost/Namesilo - 35303
01/06/25 ovasfa1.top 37.221.64.118 Alexhost/Namesilo

Appears to be a lot on that IP

https://coscare.help/,
https://jrsupport.help/

https://uchelp.top/?__cf_chl_tk=9VvtMom0EH3eDRD1Pn.QRq_O9NpsDdJWN3thfSq4wOg-1736188070-1.0.1.1-JLi09xh6hQhT_tZ1BST2phKvc_OyF3wstEn9MiIygow