JWrapper ScreenConnect RAT Remediationn Toolkit v2.5.1
v2.5.1: Advanced Registry Purge & Relay Sinkholing
Description:
This release significantly expands the toolkit's capability to detect and eradicate deep-seated registry persistence and block active campaign relay infrastructure.
What's New:
- SideBySide Cache Purge: Added logic to dynamically scan and purge ScreenConnect artifacts hiding deep within the
HKEY_USERSSideBySide/ClickOnce deployment registry cache. - Tracing & Event Log Cleanup: Scans and removes
ControlSet001EventLog entries andWOW6432Node\Microsoft\Tracingartifacts left behind by malicious ScreenConnect executions. - Targeted Relay Sinkholing: Automatically adds Windows Hosts file blocks for known malicious ScreenConnect relay domains (
instance-fc5xev-relay.screenconnect.com,instance-sis2tc-relay.screenconnect.com) to prevent re-infection or beaconing. - Legitimate Software Whitelisting: Specifically excludes known, valid Line-of-Business applications (e.g., Furniture Wizard) from being flagged or blocked by the remediation sweeps.
- Enhanced Memory Detection:
system_check.ps1now cross-references running ScreenConnect command lines against known malicious relay identifiers to detect active, memory-resident staging.
Full Changelog: v2.5.0...v2.5.1