NOTICE:
ASSOCIATED FILES:
2026-09-14 (MONDAY): BACKDOOR USING SCREENCONNECT FROM MALICIOUS EMAIL SOME OF THE EMAIL HEADERS: - Received: from allsecured[.]net (unknown [23.227.202[.]93]) by [information removed]; Sun, 13 Sep 2026 14:05:44 +0000 (UTC) - From: Social Security Administration (Information@allsecured[.]net) - Subject: Your Monthly SSA Electronic Statement is Available for Download - Date: 13 Sep 2026 14:05:42 +0000 - Message-ID: 20260913140542.71B0635A54B0E91F@allsecured[.]net LINK FROM EMAIL: - hxxps[:]//t[.]co/LPz3zzwREa FAKE SOCIAL SECURITY ADMINISTRATION PAGE AND FILE DOWNLOAD: - hxxps[:]//icci-sa[.]com/xgov - hxxps[:]//icci-sa[.]com/xgov/ - hxxps[:]//icci-sa[.]com/xgov/social_secur1tiy_administr3tion.php - hxxps[:]//icci-sa[.]com/xgov/social_secur1tiy_administr3tion.php?download=exe DOWNLOADED CUSTOMIZED SCREENCONNECT CLIENT INSTALLER: - SHA-256 hash: f1d103dd77d09697fa30fa14c4f39e394b0331a33ffd2ef5df2916dbe79e474b - File size: 12,828,216 bytes - File type: PE32 executable (GUI) Intel 80386, for MS Windows - File name: ScreenConnect.ClientSetup.exe POST-INFECTION SCREENCONNECT TRAFFIC: - tcp[:]//15.204.43.235[:]443 - instance-udppxf-relay.screenconnect.com - encoded/encrypted ScreenConnect traffic

Shown above: Screenshot of the email.

Shown above: Screenshot of the web page impersonating the Social Security Administration.

Shown above: Screenshot of the web page impersonating the Social Security Administration with the malicious download noted.

Shown above: Traffic from the infection filtered in Wireshark.
Click here to return to the main page.