File name:

SteamSetup - Project Playtime.exe

Full analysis: https://app.any.run/tasks/3d0aea83-7148-4266-ac75-07e0ddbed68b
Verdict: Malicious activity
Analysis date: February 17, 2024, 22:32:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

70F3BC193DFA56B78F3E6E4F800F701F

SHA1:

1E5598F2DE49FED2E81F3DD8630C7346A2B89487

SHA256:

3B616CB0BEAACFFB53884B5BA0453312D2577DB598D2A877A3B251125FB281A1

SSDEEP:

49152:2DcHcEngZtNm1LQRHH4PTwZX6kg9hsf4lcszpyu7d/TC:rngZtNm1G4Pw6dJzZNTC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • SteamSetup - Project Playtime.exe (PID: 2848)
      • steamservice.exe (PID: 3428)
    • Changes the autorun value in the registry

      • SteamSetup - Project Playtime.exe (PID: 2848)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • SteamSetup - Project Playtime.exe (PID: 2848)
    • Starts application with an unusual extension

      • SteamSetup - Project Playtime.exe (PID: 2848)
    • Executable content was dropped or overwritten

      • steamservice.exe (PID: 3428)
      • SteamSetup - Project Playtime.exe (PID: 2848)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • SteamSetup - Project Playtime.exe (PID: 2848)
    • Reads the Internet Settings

      • Steam.exe (PID: 4004)
    • Creates a software uninstall entry

      • SteamSetup - Project Playtime.exe (PID: 2848)
  • INFO

    • Checks supported languages

      • SteamSetup - Project Playtime.exe (PID: 2848)
      • ns1376.tmp (PID: 2304)
      • steamservice.exe (PID: 3428)
      • Steam.exe (PID: 4004)
    • Reads the computer name

      • steamservice.exe (PID: 3428)
      • SteamSetup - Project Playtime.exe (PID: 2848)
      • Steam.exe (PID: 4004)
    • Create files in a temporary directory

      • SteamSetup - Project Playtime.exe (PID: 2848)
    • Manual execution by a user

      • Steam.exe (PID: 4004)
      • taskmgr.exe (PID: 2348)
      • explorer.exe (PID: 956)
    • Creates files in the program directory

      • SteamSetup - Project Playtime.exe (PID: 2848)
      • steamservice.exe (PID: 3428)
      • Steam.exe (PID: 4004)
    • Reads the machine GUID from the registry

      • SteamSetup - Project Playtime.exe (PID: 2848)
    • Reads CPU info

      • Steam.exe (PID: 4004)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:07:25 00:55:51+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 25088
InitializedDataSize: 141824
UninitializedDataSize: 2048
EntryPoint: 0x33b6
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.10.91.91
ProductVersionNumber: 2.10.91.91
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Bulgarian
CharacterSet: Windows, Cyrillic
FileDescription: Steam
FileVersion: 2.10.91.91
LegalCopyright: © Valve Corporation
ProductName: Steam
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
7
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start steamsetup - project playtime.exe ns1376.tmp no specs steamservice.exe steam.exe explorer.exe no specs taskmgr.exe no specs steamsetup - project playtime.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
956"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2304"C:\Users\admin\AppData\Local\Temp\nsnEEB7.tmp\ns1376.tmp" "C:\Program Files\Steam\bin\steamservice.exe" /InstallC:\Users\admin\AppData\Local\Temp\nsnEEB7.tmp\ns1376.tmpSteamSetup - Project Playtime.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsneeb7.tmp\ns1376.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2348"C:\Windows\system32\taskmgr.exe" /4C:\Windows\System32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2848"C:\Users\admin\AppData\Local\Temp\SteamSetup - Project Playtime.exe" C:\Users\admin\AppData\Local\Temp\SteamSetup - Project Playtime.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Steam
Exit code:
0
Version:
2.10.91.91
Modules
Images
c:\users\admin\appdata\local\temp\steamsetup - project playtime.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3428"C:\Program Files\Steam\bin\steamservice.exe" /InstallC:\Program Files\Steam\bin\steamservice.exe
ns1376.tmp
User:
admin
Company:
Valve Corporation
Integrity Level:
HIGH
Description:
Steam Client Service
Exit code:
0
Version:
07.15.03.72
Modules
Images
c:\program files\steam\bin\steamservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
4004"C:\Program Files\Steam\steam.exe" C:\Program Files\Steam\Steam.exe
explorer.exe
User:
admin
Company:
Valve Corporation
Integrity Level:
MEDIUM
Description:
Steam
Exit code:
0
Version:
07.15.03.72
Modules
Images
c:\program files\steam\steam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
4052"C:\Users\admin\AppData\Local\Temp\SteamSetup - Project Playtime.exe" C:\Users\admin\AppData\Local\Temp\SteamSetup - Project Playtime.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Steam
Exit code:
3221226540
Version:
2.10.91.91
Modules
Images
c:\users\admin\appdata\local\temp\steamsetup - project playtime.exe
c:\windows\system32\ntdll.dll
Total events
3 258
Read events
3 227
Write events
31
Delete events
0

Modification events

(PID) Process:(2848) SteamSetup - Project Playtime.exeKey:HKEY_CURRENT_USER\Software\Valve\Steam
Operation:writeName:Language
Value:
english
(PID) Process:(2848) SteamSetup - Project Playtime.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Steam
Operation:writeName:Language
Value:
english
(PID) Process:(2848) SteamSetup - Project Playtime.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Steam
Value:
"C:\Program Files\Steam\steam.exe" -silent
(PID) Process:(2848) SteamSetup - Project Playtime.exeKey:HKEY_CURRENT_USER\Software\Valve\Steam
Operation:writeName:SteamInstaller
Value:
SteamSetup - Project Playtime.exe
(PID) Process:(3428) steamservice.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Valve\SteamService
Operation:writeName:installpath_default
Value:
C:\Program Files\Steam
(PID) Process:(3428) steamservice.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\Steam Client Service
Operation:writeName:EventMessageFile
Value:
C:\Program Files\Steam\bin\steamservice.exe
(PID) Process:(3428) steamservice.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\Steam Client Service
Operation:writeName:TypesSupported
Value:
7
(PID) Process:(3428) steamservice.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Steam
Operation:writeName:InstallPath
Value:
C:\Program Files\Steam
(PID) Process:(3428) steamservice.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\steam
Operation:writeName:URL Protocol
Value:
(PID) Process:(3428) steamservice.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\steamlink
Operation:writeName:URL Protocol
Value:
Executable files
10
Suspicious files
28
Text files
3 484
Unknown types
15

Dropped files

PID
Process
Filename
Type
2848SteamSetup - Project Playtime.exeC:\Program Files\Steam\public\steambootstrapper_dutch.txttext
MD5:31A29061E51E245F74BB26D103C666AD
SHA256:56C8A86FA95EAB0D8F34F498E079B5516B96D2A2F1AD9C2A888555E50E47F192
2848SteamSetup - Project Playtime.exeC:\Program Files\Steam\public\steambootstrapper_bulgarian.txttext
MD5:239C03A3DC1C27993DA724736D086CEF
SHA256:B387E2FB971297D3438ACCA130C53DFDD202AE2CA5B52D6503333734CDA4FBFC
2848SteamSetup - Project Playtime.exeC:\Users\admin\AppData\Local\Temp\nsnEEB7.tmp\System.dllexecutable
MD5:A4DD044BCD94E9B3370CCF095B31F896
SHA256:2E226715419A5882E2E14278940EE8EF0AA648A3EF7AF5B3DC252674111962BC
2848SteamSetup - Project Playtime.exeC:\Program Files\Steam\public\steambootstrapper_finnish.txttext
MD5:594BE5B10D9F551E551CF20EAE0E6DFC
SHA256:E350CA62E777DA4DA6D25885BE96D48E7CE3ACF021A74F2A4902354A1BF03FBB
2848SteamSetup - Project Playtime.exeC:\Program Files\Steam\public\steambootstrapper_italian.txttext
MD5:8958371646901EAC40807EEB2F346382
SHA256:B01EC64D75FD1FBD00FBEB45A3FB39244911A8B22BB43DE4E0C03F205184F585
2848SteamSetup - Project Playtime.exeC:\Program Files\Steam\public\steambootstrapper_french.txttext
MD5:DA69785DFBF494002F108DD73020183D
SHA256:8CCE22E7F13486F2BC612DCC8FA31D81038E6084A350FA10299D40C3A7F878C8
2848SteamSetup - Project Playtime.exeC:\Users\admin\AppData\Local\Temp\nsnEEB7.tmp\modern-header.bmpimage
MD5:DA3486D12BB4C8AEC16BD9E0D363D23F
SHA256:D93B76D51BD2214FA6E999C1BF70B4AFF5165A6542F9B9B2A92B5672601F4624
2848SteamSetup - Project Playtime.exeC:\Program Files\Steam\public\steambootstrapper_greek.txttext
MD5:B9E30DF8CF272813B121133FCF259752
SHA256:88919D7BE26FB3E06401FC0254733D92FD743ECC56DA4177B41613E1F094C3E8
2848SteamSetup - Project Playtime.exeC:\Users\admin\AppData\Local\Temp\nsnEEB7.tmp\nsDialogs.dllexecutable
MD5:0D45588070CF728359055F776AF16EC4
SHA256:067C77D51DF034B4A614F83803140FBF4CD2F8684B88EA8C8ACDF163EDAD085A
2848SteamSetup - Project Playtime.exeC:\Program Files\Steam\public\steambootstrapper_danish.txttext
MD5:03B664BD98485425C21CDF83BC358703
SHA256:FDF7B42B3B027A12E1B79CB10AB9E6E34C668B04EB9E8A907D8611BA46473115
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
17
TCP/UDP connections
7
DNS requests
1
Threats
18

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4004
Steam.exe
GET
200
23.53.41.98:80
http://media.steampowered.com/client/resources_misc_all.zip.vz.e86a975545f3ab21a77373870cb311ef93934b8c_2224876
unknown
binary
2.12 Mb
unknown
4004
Steam.exe
GET
200
23.53.41.98:80
http://media.steampowered.com/client/steamui_websrc_all.zip.vz.83cdfb92d0b35c6f6716c814b4aaf3ce19b8c4a7_23814718
unknown
binary
22.7 Mb
unknown
4004
Steam.exe
GET
200
23.53.41.98:80
http://media.steampowered.com/client/tenfoot_images_all.zip.vz.193cb8c4eb4446698ea2c0a9e8c4e6b6a623dac7_5572671
unknown
binary
5.31 Mb
unknown
4004
Steam.exe
GET
200
23.53.41.98:80
http://media.steampowered.com/client/steam_client_win32
unknown
text
3.63 Kb
unknown
4004
Steam.exe
GET
200
23.53.41.98:80
http://media.steampowered.com/client/resources_all.zip.vz.7b0b89dc9a451897160e0d1cdfcf6749dbf772cc_2858549
unknown
binary
2.73 Mb
unknown
4004
Steam.exe
GET
200
23.53.41.98:80
http://media.steampowered.com/client/strings_all.zip.vz.cebf0e5cbd6af51d25e4193c01f8f6e571c11571_1992788
unknown
binary
1.90 Mb
unknown
4004
Steam.exe
GET
200
23.53.41.98:80
http://media.steampowered.com/client/strings_en_all.zip.d58a1959149e8dd48d23a52052d3afa585a0416c
unknown
110 Kb
unknown
4004
Steam.exe
GET
200
23.53.41.98:80
http://media.steampowered.com/client/steam_win32_steamrow.zip.vz.faf4890d78ff330fb327bc1392f733cf03e316ab_1806830
unknown
binary
1.72 Mb
unknown
4004
Steam.exe
GET
200
23.53.41.98:80
http://media.steampowered.com/client/steamui_websrc_movies_all.zip.4d2183b0476852dfb695b8d70192a0ccece8c7d0
unknown
binary
7.17 Mb
unknown
4004
Steam.exe
GET
200
23.53.41.98:80
http://media.steampowered.com/client/bins_cef_win32_win7.zip.vz.314ded663999d66f03023b3a12690d93d9d34974_66447549
unknown
binary
63.3 Mb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4004
Steam.exe
23.53.41.98:80
media.steampowered.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
media.steampowered.com
  • 23.53.41.98
  • 23.53.41.97
whitelisted

Threats

PID
Process
Class
Message
4004
Steam.exe
Potential Corporate Privacy Violation
ET USER_AGENTS Steam HTTP Client User-Agent
17 ETPRO signatures available at the full report
No debug info