File name:

SteamSetup - Project Playtime.exe

Full analysis: https://app.any.run/tasks/3d0aea83-7148-4266-ac75-07e0ddbed68b
Verdict: Malicious activity
Analysis date: February 17, 2024, 22:32:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

70F3BC193DFA56B78F3E6E4F800F701F

SHA1:

1E5598F2DE49FED2E81F3DD8630C7346A2B89487

SHA256:

3B616CB0BEAACFFB53884B5BA0453312D2577DB598D2A877A3B251125FB281A1

SSDEEP:

49152:2DcHcEngZtNm1LQRHH4PTwZX6kg9hsf4lcszpyu7d/TC:rngZtNm1G4Pw6dJzZNTC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • SteamSetup - Project Playtime.exe (PID: 2848)
      • steamservice.exe (PID: 3428)
    • Changes the autorun value in the registry

      • SteamSetup - Project Playtime.exe (PID: 2848)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • SteamSetup - Project Playtime.exe (PID: 2848)
      • steamservice.exe (PID: 3428)
    • Creates a software uninstall entry

      • SteamSetup - Project Playtime.exe (PID: 2848)
    • The process creates files with name similar to system file names

      • SteamSetup - Project Playtime.exe (PID: 2848)
    • Reads the Internet Settings

      • Steam.exe (PID: 4004)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • SteamSetup - Project Playtime.exe (PID: 2848)
    • Starts application with an unusual extension

      • SteamSetup - Project Playtime.exe (PID: 2848)
  • INFO

    • Checks supported languages

      • SteamSetup - Project Playtime.exe (PID: 2848)
      • Steam.exe (PID: 4004)
      • steamservice.exe (PID: 3428)
      • ns1376.tmp (PID: 2304)
    • Create files in a temporary directory

      • SteamSetup - Project Playtime.exe (PID: 2848)
    • Reads the machine GUID from the registry

      • SteamSetup - Project Playtime.exe (PID: 2848)
    • Creates files in the program directory

      • steamservice.exe (PID: 3428)
      • SteamSetup - Project Playtime.exe (PID: 2848)
      • Steam.exe (PID: 4004)
    • Manual execution by a user

      • Steam.exe (PID: 4004)
      • taskmgr.exe (PID: 2348)
      • explorer.exe (PID: 956)
    • Reads the computer name

      • SteamSetup - Project Playtime.exe (PID: 2848)
      • Steam.exe (PID: 4004)
      • steamservice.exe (PID: 3428)
    • Reads CPU info

      • Steam.exe (PID: 4004)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:07:25 00:55:51+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 25088
InitializedDataSize: 141824
UninitializedDataSize: 2048
EntryPoint: 0x33b6
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.10.91.91
ProductVersionNumber: 2.10.91.91
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Bulgarian
CharacterSet: Windows, Cyrillic
FileDescription: Steam
FileVersion: 2.10.91.91
LegalCopyright: © Valve Corporation
ProductName: Steam
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
7
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start steamsetup - project playtime.exe ns1376.tmp no specs steamservice.exe steam.exe explorer.exe no specs taskmgr.exe no specs steamsetup - project playtime.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
956"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2304"C:\Users\admin\AppData\Local\Temp\nsnEEB7.tmp\ns1376.tmp" "C:\Program Files\Steam\bin\steamservice.exe" /InstallC:\Users\admin\AppData\Local\Temp\nsnEEB7.tmp\ns1376.tmpSteamSetup - Project Playtime.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsneeb7.tmp\ns1376.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2348"C:\Windows\system32\taskmgr.exe" /4C:\Windows\System32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2848"C:\Users\admin\AppData\Local\Temp\SteamSetup - Project Playtime.exe" C:\Users\admin\AppData\Local\Temp\SteamSetup - Project Playtime.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Steam
Exit code:
0
Version:
2.10.91.91
Modules
Images
c:\users\admin\appdata\local\temp\steamsetup - project playtime.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3428"C:\Program Files\Steam\bin\steamservice.exe" /InstallC:\Program Files\Steam\bin\steamservice.exe
ns1376.tmp
User:
admin
Company:
Valve Corporation
Integrity Level:
HIGH
Description:
Steam Client Service
Exit code:
0
Version:
07.15.03.72
Modules
Images
c:\program files\steam\bin\steamservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
4004"C:\Program Files\Steam\steam.exe" C:\Program Files\Steam\Steam.exe
explorer.exe
User:
admin
Company:
Valve Corporation
Integrity Level:
MEDIUM
Description:
Steam
Exit code:
0
Version:
07.15.03.72
Modules
Images
c:\program files\steam\steam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
4052"C:\Users\admin\AppData\Local\Temp\SteamSetup - Project Playtime.exe" C:\Users\admin\AppData\Local\Temp\SteamSetup - Project Playtime.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Steam
Exit code:
3221226540
Version:
2.10.91.91
Modules
Images
c:\users\admin\appdata\local\temp\steamsetup - project playtime.exe
c:\windows\system32\ntdll.dll
Total events
3 258
Read events
3 227
Write events
31
Delete events
0

Modification events

(PID) Process:(2848) SteamSetup - Project Playtime.exeKey:HKEY_CURRENT_USER\Software\Valve\Steam
Operation:writeName:Language
Value:
english
(PID) Process:(2848) SteamSetup - Project Playtime.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Steam
Operation:writeName:Language
Value:
english
(PID) Process:(2848) SteamSetup - Project Playtime.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Steam
Value:
"C:\Program Files\Steam\steam.exe" -silent
(PID) Process:(2848) SteamSetup - Project Playtime.exeKey:HKEY_CURRENT_USER\Software\Valve\Steam
Operation:writeName:SteamInstaller
Value:
SteamSetup - Project Playtime.exe
(PID) Process:(3428) steamservice.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Valve\SteamService
Operation:writeName:installpath_default
Value:
C:\Program Files\Steam
(PID) Process:(3428) steamservice.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\Steam Client Service
Operation:writeName:EventMessageFile
Value:
C:\Program Files\Steam\bin\steamservice.exe
(PID) Process:(3428) steamservice.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\Steam Client Service
Operation:writeName:TypesSupported
Value:
7
(PID) Process:(3428) steamservice.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Steam
Operation:writeName:InstallPath
Value:
C:\Program Files\Steam
(PID) Process:(3428) steamservice.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\steam
Operation:writeName:URL Protocol
Value:
(PID) Process:(3428) steamservice.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\steamlink
Operation:writeName:URL Protocol
Value:
Executable files
10
Suspicious files
28
Text files
3 484
Unknown types
15

Dropped files

PID
Process
Filename
Type
2848SteamSetup - Project Playtime.exeC:\Users\admin\AppData\Local\Temp\nsnEEB7.tmp\modern-header.bmpimage
MD5:DA3486D12BB4C8AEC16BD9E0D363D23F
SHA256:D93B76D51BD2214FA6E999C1BF70B4AFF5165A6542F9B9B2A92B5672601F4624
2848SteamSetup - Project Playtime.exeC:\Users\admin\AppData\Local\Temp\nsnEEB7.tmp\System.dllexecutable
MD5:A4DD044BCD94E9B3370CCF095B31F896
SHA256:2E226715419A5882E2E14278940EE8EF0AA648A3EF7AF5B3DC252674111962BC
2848SteamSetup - Project Playtime.exeC:\Program Files\Steam\public\steambootstrapper_french.txttext
MD5:DA69785DFBF494002F108DD73020183D
SHA256:8CCE22E7F13486F2BC612DCC8FA31D81038E6084A350FA10299D40C3A7F878C8
2848SteamSetup - Project Playtime.exeC:\Program Files\Steam\public\steambootstrapper_hungarian.txttext
MD5:18AAAF5FFCDD21B1B34291E812D83063
SHA256:1F45BB7BDFA01424F9237EEC60EBA35DC7F0DC4E8C2E193FE768FE96D3FF76D5
2848SteamSetup - Project Playtime.exeC:\Program Files\Steam\public\steambootstrapper_italian.txttext
MD5:8958371646901EAC40807EEB2F346382
SHA256:B01EC64D75FD1FBD00FBEB45A3FB39244911A8B22BB43DE4E0C03F205184F585
2848SteamSetup - Project Playtime.exeC:\Users\admin\AppData\Local\Temp\nsnEEB7.tmp\modern-wizard.bmpimage
MD5:3614A4BE6B610F1DAF6C801574F161FE
SHA256:16E0EDC9F47E6E95A9BCAD15ADBDC46BE774FBCD045DD526FC16FC38FDC8D49B
2848SteamSetup - Project Playtime.exeC:\Program Files\Steam\public\steambootstrapper_japanese.txttext
MD5:7E1D15FC9BA66A868C5C6CB1C2822F83
SHA256:FC74E26A8BAABBE4851109512D85173B75DBF7293D41EB3B92A1957A773C8265
2848SteamSetup - Project Playtime.exeC:\Program Files\Steam\public\steambootstrapper_danish.txttext
MD5:03B664BD98485425C21CDF83BC358703
SHA256:FDF7B42B3B027A12E1B79CB10AB9E6E34C668B04EB9E8A907D8611BA46473115
2848SteamSetup - Project Playtime.exeC:\Users\admin\AppData\Local\Temp\nsnEEB7.tmp\nsDialogs.dllexecutable
MD5:0D45588070CF728359055F776AF16EC4
SHA256:067C77D51DF034B4A614F83803140FBF4CD2F8684B88EA8C8ACDF163EDAD085A
2848SteamSetup - Project Playtime.exeC:\Program Files\Steam\Steam.exeexecutable
MD5:B4411620A3551834E4F699CC5A9B27E6
SHA256:3CAF4A246169B2D30C6BF18FA0B7A4A01BBE933CFB781F3DA4C6B3CB67B59D04
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
17
TCP/UDP connections
7
DNS requests
1
Threats
18

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4004
Steam.exe
GET
200
23.53.41.98:80
http://media.steampowered.com/client/steam_client_win32
unknown
text
3.63 Kb
unknown
4004
Steam.exe
GET
200
23.53.41.98:80
http://media.steampowered.com/client/resources_all.zip.vz.7b0b89dc9a451897160e0d1cdfcf6749dbf772cc_2858549
unknown
binary
2.73 Mb
unknown
4004
Steam.exe
GET
200
23.53.41.98:80
http://media.steampowered.com/client/steamui_websrc_all.zip.vz.83cdfb92d0b35c6f6716c814b4aaf3ce19b8c4a7_23814718
unknown
binary
22.7 Mb
unknown
4004
Steam.exe
GET
200
23.53.41.98:80
http://media.steampowered.com/client/resources_hidpi_all.zip.vz.3de815c3117712cb9eeb7ea4c8b275faf481dcfd_56342
unknown
binary
55.0 Kb
unknown
4004
Steam.exe
GET
200
23.53.41.98:80
http://media.steampowered.com/client/resources_misc_all.zip.vz.e86a975545f3ab21a77373870cb311ef93934b8c_2224876
unknown
binary
2.12 Mb
unknown
4004
Steam.exe
GET
200
23.53.41.98:80
http://media.steampowered.com/client/tenfoot_images_all.zip.vz.193cb8c4eb4446698ea2c0a9e8c4e6b6a623dac7_5572671
unknown
binary
5.31 Mb
unknown
4004
Steam.exe
GET
200
23.53.41.98:80
http://media.steampowered.com/client/strings_all.zip.vz.cebf0e5cbd6af51d25e4193c01f8f6e571c11571_1992788
unknown
binary
1.90 Mb
unknown
4004
Steam.exe
GET
200
23.53.41.98:80
http://media.steampowered.com/client/public_all.zip.vz.533cb1df66fe255772526698c830c2e2e6112579_12008096
unknown
binary
11.4 Mb
unknown
4004
Steam.exe
GET
200
23.53.41.98:80
http://media.steampowered.com/client/strings_en_all.zip.d58a1959149e8dd48d23a52052d3afa585a0416c
unknown
110 Kb
unknown
4004
Steam.exe
GET
200
23.53.41.98:80
http://media.steampowered.com/client/steamui_websrc_movies_all.zip.4d2183b0476852dfb695b8d70192a0ccece8c7d0
unknown
binary
7.17 Mb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4004
Steam.exe
23.53.41.98:80
media.steampowered.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
media.steampowered.com
  • 23.53.41.98
  • 23.53.41.97
whitelisted

Threats

PID
Process
Class
Message
4004
Steam.exe
Potential Corporate Privacy Violation
ET USER_AGENTS Steam HTTP Client User-Agent
17 ETPRO signatures available at the full report
No debug info