VBScript remediation
Audit mode is the default. The explicit /apply argument enables evidence-bound cleanup and quarantine.
Community incident remediation
This free Windows remediation targets the SPECIAL PARTY INVITATION chain associated with ScreenConnect instance fa12121053c2d7fe and relay relay.rupilure.top at 74.120.121.48:8041. It audits alternative connection and persistence paths, removes confirmed changes, and preserves evidence for review.
Community preview
Keep the VBScript and PowerShell audit engine in the same folder. Review the source and checksum before running it. The audit has been run end to end on a clean Windows 11 host; the /apply path is fail-closed by design but has not yet been exercised against a live infection, so try it on a disposable or backed-up system first. No audit output is sent to AlomSec or anywhere else, and the campaign relay is never resolved or contacted, so cleaning a host does not announce itself to the attacker. That is not the same as no network traffic: signature validation may retrieve certificate revocation data, and /apply starts Microsoft Defender, whose cloud protection may communicate with Microsoft. Both use services this computer is already configured to use. Test it in an isolated Windows system before organization-wide deployment.
Audit mode is the default. The explicit /apply argument enables evidence-bound cleanup and quarantine.
Collects current and historical connection evidence, persistence, accounts, remote-access state, signatures, hashes, and relevant Windows events.
Read the operating notes and compare every downloaded file with the published SHA-256 values.
Records processes, connections, listeners, DNS, services, tasks, autoruns, WMI, RDP, WinRM, OpenSSH, BITS, firewall state, accounts, Defender settings, recent executable content, and relevant event logs.
Confirmed payloads and target folders move beneath %ProgramData%\Argus-Omni-ScreenConnect-Remediation. Registry keys, scheduled tasks, autorun values, WMI subscriptions, firewall rules, and Defender exclusions are exported before removal.
Unknown remote-access software and suspicious persistence are ranked for human review. Automatic removal requires the exact incident identifiers or known hashes, so an approved deployment of the same product is reported rather than removed.
Isolate the affected host, preserve needed evidence, rotate credentials from a clean device, review identity and client-data access, run an offline scan, and rebuild when system integrity cannot be established.
Run locally as Administrator
cscript //nologo remediate_party_invitation_rat.vbs.%ProgramData%\Argus-Omni-ScreenConnect-Remediation\Audits.cscript //nologo remediate_party_invitation_rat.vbs /apply.