General Info

File name

SteamSetup.exe

Full analysis
https://app.any.run/tasks/08ec9de1-4407-4e83-b3da-0df78e800949
Verdict
Malicious activity
Analysis date
11/8/2019, 17:28:49
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5

81448c2e730b50b597bbd5e43007ce6a

SHA1

4b1b85ec2499a4ce07c89609b256923a4fc479e5

SHA256

3bc6942fe09f10ed3447bccdcf4a70ed369366fef6b2c7f43b541f1a3c5d1c51

SSDEEP

24576:QDliBd5TyliR0gWwOvTCU1z3zk51iq449nkU0/1COmcrOqpXzzE2YeshfLKB7:QD8tylwXoTCWi1iq1nkU09lRENhJLKB7

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Groove MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office IME (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office IME (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Language Pack 2010 - French/Français (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - German/Deutsch (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Italian/Italiano (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Japanese/日本語 (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Korean/한국어 (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Portuguese/Português (Brasil) (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Russian/русский (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Spanish/Español (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Turkish/Türkçe (14.0.4763.1013)
  • Microsoft Office O MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Arabic) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Basque) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Catalan) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Dutch) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Galician) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (German) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Proof (Ukrainian) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (French) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (German) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office SharePoint Designer MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office X MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 68.0.1 (x86 en-US) (68.0.1)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • SteamSetup.exe (PID: 784)
Application was dropped or rewritten from another process
  • steamservice.exe (PID: 2872)
  • nsF54A.tmp (PID: 1596)
  • steam.exe (PID: 3604)
Changes the autorun value in the registry
  • SteamSetup.exe (PID: 784)
Executable content was dropped or overwritten
  • SteamSetup.exe (PID: 784)
  • steamservice.exe (PID: 2872)
Starts application with an unusual extension
  • SteamSetup.exe (PID: 784)
Creates files in the program directory
  • steam.exe (PID: 3604)
  • SteamSetup.exe (PID: 784)
Modifies the open verb of a shell class
  • steamservice.exe (PID: 2872)
Creates a software uninstall entry
  • SteamSetup.exe (PID: 784)
Manual execution by user
  • steam.exe (PID: 3604)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable MS Visual C++ (generic) (42.2%)
.exe
|   Win64 Executable (generic) (37.3%)
.dll
|   Win32 Dynamic Link Library (generic) (8.8%)
.exe
|   Win32 Executable (generic) (6%)
.exe
|   Generic Win/DOS Executable (2.7%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2016:07:25 02:55:51+02:00
PEType:
PE32
LinkerVersion:
6
CodeSize:
25088
InitializedDataSize:
141824
UninitializedDataSize:
2048
EntryPoint:
0x33b6
OSVersion:
4
ImageVersion:
6
SubsystemVersion:
4
Subsystem:
Windows GUI
FileVersionNumber:
2.10.91.91
ProductVersionNumber:
2.10.91.91
FileFlagsMask:
0x0000
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
Bulgarian
CharacterSet:
Windows, Cyrillic
FileDescription:
Steam
FileVersion:
2.10.91.91
LegalCopyright:
© Valve Corporation
ProductName:
Steam
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
25-Jul-2016 00:55:51
Detected languages
Bulgarian - Bulgaria
Chinese - PRC
Chinese - Taiwan
Czech - Czech Republic
Danish - Denmark
Dutch - Netherlands
English - United States
Finnish - Finland
French - France
German - Germany
Greek - Greece
Hungarian - Hungary
Italian - Italy
Japanese - Japan
Korean - Korea
Norwegian - Norway (Bokmal)
Polish - Poland
Portuguese - Brazil
Portuguese - Portugal
Romanian - Romania
Russian - Russia
Spanish - Spain (Traditional sort)
Swedish - Sweden
Thai - Thailand
Turkish - Turkey
Ukrainian - Ukraine
FileDescription:
Steam
FileVersion:
2.10.91.91
LegalCopyright:
© Valve Corporation
ProductName:
Steam
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000C8
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
5
Time date stamp:
25-Jul-2016 00:55:51
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x0000615D 0x00006200 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.45023
.rdata 0x00008000 0x000013A4 0x00001400 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.163
.data 0x0000A000 0x00020338 0x00000600 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 3.9824
.ndata 0x0002B000 0x00036000 0x00000000 IMAGE_SCN_CNT_UNINITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.rsrc 0x00061000 0x00012868 0x00012A00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 6.2422
Resources
1

2

3

4

5

6

7

8

9

103

105

106

107

111

203

205

206

207

211

303

305

306

307

311

403

405

406

407

411

503

505

506

507

511

Imports
    KERNEL32.dll

    USER32.dll

    GDI32.dll

    SHELL32.dll

    ADVAPI32.dll

    COMCTL32.dll

    ole32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
43
Monitored processes
5
Malicious processes
2
Suspicious processes
2

Behavior graph

+
drop and start start steamsetup.exe no specs steamsetup.exe nsf54a.tmp no specs steamservice.exe steam.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2828
CMD
"C:\Users\admin\AppData\Local\Temp\SteamSetup.exe"
Path
C:\Users\admin\AppData\Local\Temp\SteamSetup.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Description
Steam
Version
2.10.91.91
Modules
Image
c:\users\admin\appdata\local\temp\steamsetup.exe
c:\systemroot\system32\ntdll.dll

PID
784
CMD
"C:\Users\admin\AppData\Local\Temp\SteamSetup.exe"
Path
C:\Users\admin\AppData\Local\Temp\SteamSetup.exe
Indicators
Parent process
––
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Steam
Version
2.10.91.91
Modules
Image
c:\users\admin\appdata\local\temp\steamsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\version.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\temp\nswaff3.tmp\system.dll
c:\windows\system32\riched20.dll
c:\users\admin\appdata\local\temp\nswaff3.tmp\nsdialogs.dll
c:\windows\system32\comdlg32.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\users\admin\appdata\local\temp\nswaff3.tmp\nsprocess.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\steam\steam.exe
c:\users\admin\appdata\local\temp\nswaff3.tmp\nsexec.dll
c:\users\admin\appdata\local\temp\nswaff3.tmp\nsf54a.tmp
c:\users\admin\appdata\local\temp\nswaff3.tmp\stdutils.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sxs.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\netutils.dll

PID
1596
CMD
"C:\Users\admin\AppData\Local\Temp\nswAFF3.tmp\nsF54A.tmp" "C:\Program Files\Steam\bin\steamservice.exe" /Install
Path
C:\Users\admin\AppData\Local\Temp\nswAFF3.tmp\nsF54A.tmp
Indicators
No indicators
Parent process
SteamSetup.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\nswaff3.tmp\nsf54a.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll
c:\program files\steam\bin\steamservice.exe

PID
2872
CMD
"C:\Program Files\Steam\bin\steamservice.exe" /Install
Path
C:\Program Files\Steam\bin\steamservice.exe
Indicators
Parent process
nsF54A.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Valve Corporation
Description
Steam Client Service
Version
04.52.21.91
Modules
Image
c:\program files\steam\bin\steamservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\version.dll
c:\windows\system32\psapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\firewallapi.dll

PID
3604
CMD
"C:\Program Files\Steam\steam.exe"
Path
C:\Program Files\Steam\steam.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Valve Corporation
Description
Steam Client Bootstrapper
Version
04.52.21.91
Modules
Image
c:\program files\steam\steam.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\version.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\psapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll

Registry activity

Total events
394
Read events
363
Write events
31
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
784
SteamSetup.exe
write
HKEY_CURRENT_USER\Software\Valve\Steam
Language
english
784
SteamSetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Steam
Language
english
784
SteamSetup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Steam
"C:\Program Files\Steam\steam.exe" -silent
784
SteamSetup.exe
write
HKEY_CURRENT_USER\Software\Valve\Steam
SteamInstaller
SteamSetup.exe
784
SteamSetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Steam\NSIS
Path
C:\Program Files\Steam
784
SteamSetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Steam
InstallPath
C:\Program Files\Steam
784
SteamSetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Steam
DisplayName
Steam
784
SteamSetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Steam
DisplayVersion
2.10.91.91
784
SteamSetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Steam
Publisher
Valve Corporation
784
SteamSetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Steam
URLInfoAbout
http://www.steampowered.com/
784
SteamSetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Steam
HelpLink
http://support.steampowered.com/
784
SteamSetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Steam
DisplayIcon
C:\Program Files\Steam\uninstall.exe
784
SteamSetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Steam
UninstallString
C:\Program Files\Steam\uninstall.exe
784
SteamSetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Steam
NoModify
1
784
SteamSetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Steam
NoRepair
1
784
SteamSetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Steam\NSIS
InstallerLanguage
1033
784
SteamSetup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
PendingFileRenameOperations
\??\C:\Users\admin\AppData\Local\Temp\nswAFF3.tmp\nsProcess.dll
2872
steamservice.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\Steam Client Service
EventMessageFile
C:\Program Files\Steam\bin\steamservice.exe
2872
steamservice.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\Steam Client Service
TypesSupported
7
2872
steamservice.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Steam
InstallPath
C:\Program Files\Steam
2872
steamservice.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\steam
URL:steam protocol
2872
steamservice.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\steam
URL Protocol
2872
steamservice.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\steam\DefaultIcon
steam.exe
2872
steamservice.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\steam\Shell\Open\Command
"C:\Program Files\Steam\steam.exe" "%1"
2872
steamservice.exe
write
HKEY_CLASSES_ROOT\steam
URL:steam protocol
2872
steamservice.exe
write
HKEY_CLASSES_ROOT\steam
URL Protocol
2872
steamservice.exe
write
HKEY_CLASSES_ROOT\steam\DefaultIcon
steam.exe
2872
steamservice.exe
write
HKEY_CLASSES_ROOT\steam\Shell\Open\Command
"C:\Program Files\Steam\steam.exe" "%1"
3604
steam.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Steam
SteamPID
3604
3604
steam.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Steam
TempAppCmdLine

Files activity

Executable files
10
Suspicious files
0
Text files
31
Unknown types
2

Dropped files

PID
Process
Filename
Type
784
SteamSetup.exe
C:\Users\admin\AppData\Local\Temp\nswAFF3.tmp\System.dll
executable
MD5: a4dd044bcd94e9b3370ccf095b31f896
SHA256: 2e226715419a5882e2e14278940ee8ef0aa648a3ef7af5b3dc252674111962bc
784
SteamSetup.exe
C:\Program Files\Steam\uninstall.exe
executable
MD5: 04ac66825466772809e5f5a7d6d66292
SHA256: 8f648df6a34445236155b2094905d1fb142e3f9cc314781c4361cf3c052e77f6
2872
steamservice.exe
C:\Program Files\Common Files\Steam\SteamService.exe
executable
MD5: 3e654318b9c1203beb7f4aefb2f6d839
SHA256: 2cdb8a21456df3dbc46c23460be079bf285b1352bd6b131f572d4cb52bacf252
784
SteamSetup.exe
C:\Users\admin\AppData\Local\Temp\nswAFF3.tmp\nsExec.dll
executable
MD5: c5b9fe538654a5a259cf64c2455c5426
SHA256: 7b51372117960e84d6f5eb3a26810cc044ff02283b3d656a0a456b0ab5cb8ea7
784
SteamSetup.exe
C:\Users\admin\AppData\Local\Temp\nswAFF3.tmp\nsF54A.tmp
executable
MD5: c1f54cb914ffa47fb0ad9984ecb9a3f3
SHA256: 503c52dbbb37c87d07a594a90dd2eea4e1f80c9578a9ea295e493171457aff5d
784
SteamSetup.exe
C:\Program Files\Steam\bin\SteamService.exe
executable
MD5: 3e654318b9c1203beb7f4aefb2f6d839
SHA256: 2cdb8a21456df3dbc46c23460be079bf285b1352bd6b131f572d4cb52bacf252
784
SteamSetup.exe
C:\Program Files\Steam\Steam.exe
executable
MD5: 565d90cdc73f2cbc03d5c184c70fc524
SHA256: 70bde9e88aa386aa5139cac0c8a78b5576f1bed9e5f719c4e620d5c0cf7d5cbf
784
SteamSetup.exe
C:\Users\admin\AppData\Local\Temp\nswAFF3.tmp\nsProcess.dll
executable
MD5: f0438a894f3a7e01a4aae8d1b5dd0289
SHA256: 30c6c3dd3cc7fcea6e6081ce821adc7b2888542dae30bf00e881c0a105eb4d11
784
SteamSetup.exe
C:\Users\admin\AppData\Local\Temp\nswAFF3.tmp\nsDialogs.dll
executable
MD5: 0d45588070cf728359055f776af16ec4
SHA256: 067c77d51df034b4a614f83803140fbf4cd2f8684b88ea8c8acdf163edad085a
784
SteamSetup.exe
C:\Users\admin\AppData\Local\Temp\nswAFF3.tmp\StdUtils.dll
executable
MD5: 98a4efba4e4b566dc3d93d2d9bfcab58
SHA256: e2ad7736209d62909a356248fce8e554093339b18ef3e6a989a3c278f177ad48
784
SteamSetup.exe
C:\Program Files\Steam\public\steambootstrapper_ukrainian.txt
text
MD5: f2ae05cc88dc6d7bc8e0e29a7622312e
SHA256: d1b6f19d7442784e3ea222e9506f0a45a9e981268a7035898d6c0e86932d3b9c
784
SteamSetup.exe
C:\Program Files\Steam\public\steambootstrapper_turkish.txt
text
MD5: cc1a9b06de02d14dc28b5cb12fb805ad
SHA256: 70ddc7e39868e07b3737e648e279888865e8942c5736e7208d77597f96d8182b
784
SteamSetup.exe
C:\Program Files\Steam\public\steambootstrapper_thai.txt
text
MD5: 1720daf2627ef4ad6626997665c74502
SHA256: 8eccfed053ba4881b6cd3ea518004ac98820eb6f049d9148fd74492d63d75095
784
SteamSetup.exe
C:\Program Files\Steam\public\steambootstrapper_tchinese.txt
text
MD5: b076ad87c690eeab567e54c0b8db299b
SHA256: ce35fcd84c8f2b288de110dc74e45544a9b61bef98d29612518a41a4ee7b6d30
784
SteamSetup.exe
C:\Program Files\Steam\public\steambootstrapper_japanese.txt
text
MD5: 9c00f0cf5f52c9b6e1288abed68219b2
SHA256: 3e3cd5b49164d7fbfb16e1b0896955f2a8c50e1b1a0264f5b542df5be60d22ed
784
SteamSetup.exe
C:\Program Files\Steam\public\steambootstrapper_norwegian.txt
text
MD5: 845a648a8042cbca41977824a4356feb
SHA256: 80ae7f593db16f9d5d33b75d19d43f3f3bbf0cfe017fdb0148c0eecb0aac0232
784
SteamSetup.exe
C:\Program Files\Steam\public\steambootstrapper_romanian.txt
text
MD5: 35f63d2eaf9c5031e0c38849e5e2846e
SHA256: c1ae90b2b0eb2b6c0bdd18ee480ad8a55d48973f70577c7c6b387330b3aec0aa
784
SteamSetup.exe
C:\Program Files\Steam\public\steambootstrapper_swedish.txt
text
MD5: 47ec6fb3d98e01976d7aa81658789f6e
SHA256: c8a63c827f343a5851a9ceb352e2cb9d3ffe16797390c132c0951c53be1a91ed
784
SteamSetup.exe
C:\Program Files\Steam\public\steambootstrapper_french.txt
text
MD5: 0182a05cf3aa48b0df12d899ee137ebd
SHA256: 46ce11c8add1fc89abe663b42a18e24c11ff8377a2ed2a4c35e835bb696701e1
784
SteamSetup.exe
C:\Program Files\Steam\public\steambootstrapper_hungarian.txt
text
MD5: 9f40b6b09785b41f1518c86e1101dcf3
SHA256: 82d9da0c4f4f1971ad133e61238c4dbd946b9a58e766efd36a949f975b96ed8d
784
SteamSetup.exe
C:\Program Files\Steam\public\steambootstrapper_spanish.txt
text
MD5: 3b5f0ab6990fb39fa4215c4b55f7d8fc
SHA256: 278eecab7d6d7c8639f0114c382343067f19288fe0cd2778bbc9b3cec50d7da3
784
SteamSetup.exe
C:\Program Files\Steam\public\steambootstrapper_polish.txt
text
MD5: d0d360beca051a6150c638c814111884
SHA256: 361fd526dee6c2f56084b6ca6079ca4ff1a52eea5878293d5dbcd8f7d6e9e2f1
784
SteamSetup.exe
C:\Program Files\Steam\public\steambootstrapper_russian.txt
text
MD5: 71ad4a77bc487de7bad27a795a1d1523
SHA256: 5afefcfa874796394cecf88dc82e6efbbb8c5d7c0337309b253494856c384659
784
SteamSetup.exe
C:\Program Files\Steam\public\steambootstrapper_koreana.txt
text
MD5: ee823b913cae33aace5bde417e748c47
SHA256: b2b890baf9241a1e49adf9ba78bc70870265dbbc87d9523b47fa82da5238304d
784
SteamSetup.exe
C:\Program Files\Steam\public\steambootstrapper_portuguese.txt
text
MD5: 4a32371d0b6a48d7a43e5c1dec5c4f6c
SHA256: cf9bbc83e6e80f288abce4b16f10d1bec89d7116695076a81150ee6578a53e37
784
SteamSetup.exe
C:\Program Files\Steam\public\steambootstrapper_schinese.txt
text
MD5: d8f7880a0ab573162d50fd41e7ede586
SHA256: dc70b1acce126b30f4dc246444e0e599aa3c5285136a62d9636514d4e2db479f
784
SteamSetup.exe
C:\Program Files\Steam\public\steambootstrapper_italian.txt
text
MD5: 153ab0f90e90e2db5d89d5223fa23d28
SHA256: f79ec156b7a205a8b34714fa32b1d5f7523cf738daf8b216100cb2cfe8489396
784
SteamSetup.exe
C:\Program Files\Steam\public\steambootstrapper_german.txt
text
MD5: 825465df8bd77c7e0aeb03736d1096c2
SHA256: 6925960062dce683a30621506b4da178054df17144fb18fff387230d561c46d1
784
SteamSetup.exe
C:\Program Files\Steam\public\steambootstrapper_korean.txt
text
MD5: ee823b913cae33aace5bde417e748c47
SHA256: b2b890baf9241a1e49adf9ba78bc70870265dbbc87d9523b47fa82da5238304d
784
SteamSetup.exe
C:\Program Files\Steam\public\steambootstrapper_greek.txt
text
MD5: 8bfaf948d2a968637202cfa810f6ff44
SHA256: 98205d4543eb8ea31dd97d6596d6d495b8b077c34ab3d2e525cdd3fd801f06be
784
SteamSetup.exe
C:\Program Files\Steam\public\steambootstrapper_finnish.txt
text
MD5: 537fd7e53fd7c2c0bb5a2b26a0bf8867
SHA256: fae3118f870c1adb564f641fee63ca1334a0f65213b16201511b343bbdaac544
784
SteamSetup.exe
C:\Program Files\Steam\public\steambootstrapper_czech.txt
text
MD5: b02ddd5e3b43e43ee9e51e13968b7a21
SHA256: 81a445a3ceb495564829cc7b0280fa993974b33476b85edcdf87f738ca82705b
784
SteamSetup.exe
C:\Program Files\Steam\public\steambootstrapper_dutch.txt
text
MD5: a24b4785c1da9b9838cca95099f973de
SHA256: 9c7b92b27cadcfe7ad1f47764cda4d6f5d9c64e30507463c277581e580858a43
784
SteamSetup.exe
C:\Program Files\Steam\public\steambootstrapper_bulgarian.txt
text
MD5: 84abaf1ca4bf7372acdc9f89d3b7592d
SHA256: 8dd4d81cb374750de3d3df6ffd0cc238ec5d1e3946dfef4b4c8380bdd832d0fd
784
SteamSetup.exe
C:\Program Files\Steam\public\steambootstrapper_brazilian.txt
text
MD5: 0fad7d2f29c625003ff68e645593f27e
SHA256: e4149f2d2e2fe362241717e161838e6177a1ccc522e1b95746fbd7d05bb0749f
784
SteamSetup.exe
C:\Program Files\Steam\public\steambootstrapper_danish.txt
text
MD5: d01a820b7be78e208952a7bdea47e2a8
SHA256: a6ce02cd2a342a2e2e60b42b18417b006c681cf233877b51b59db44aea0ed620
784
SteamSetup.exe
C:\Program Files\Steam\public\steambootstrapper_english.txt
text
MD5: 6df4e3ebc6d7c96fe41c4c5213f17efa
SHA256: 6387f9aff0226a5226d5d4f0fbe77ac80797ca621f0892034f38f0bf2370e4e1
3604
steam.exe
C:\Program Files\Steam\package\tenfoot_fonts_all.zip.vz.7673e4cd32b6752bc621d8bc1a7118a9af19b64a_12077027
––
MD5:  ––
SHA256:  ––
784
SteamSetup.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam\Steam Support Center.url
text
MD5: 4ab0d4d4ae6f708045d145fb6cc37fa9
SHA256: 799fd9fb48cff082c546921df263953c3868d721d1e69165db7a956ed2800a53
784
SteamSetup.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam\Steam.lnk
lnk
MD5: 4ff2422e594a497986e754aa109d24be
SHA256: afe934ca1f7854c907aea96ae84e8574123b534b676149ee75d60a1688acee7a
784
SteamSetup.exe
C:\Users\admin\AppData\Local\Temp\nswAFF3.tmp\modern-header.bmp
image
MD5: da3486d12bb4c8aec16bd9e0d363d23f
SHA256: d93b76d51bd2214fa6e999c1bf70b4aff5165a6542f9b9b2a92b5672601f4624
784
SteamSetup.exe
C:\Users\Public\Desktop\Steam.lnk
lnk
MD5: a86fbcf4602e96be771f133f9f3a67b1
SHA256: f10c02f9b0fba20c2de83a92327ca0fcfa8ca6cde895a98408ece988ff3b5a2f
784
SteamSetup.exe
C:\Users\admin\AppData\Local\Temp\nswAFF3.tmp\modern-wizard.bmp
image
MD5: 3614a4be6b610f1daf6c801574f161fe
SHA256: 16e0edc9f47e6e95a9bcad15adbdc46be774fbcd045dd526fc16fc38fdc8d49b
784
SteamSetup.exe
C:\Users\admin\AppData\Local\Temp\nswAFE3.tmp
––
MD5:  ––
SHA256:  ––

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
4
TCP/UDP connections
4
DNS requests
2
Threats
1

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
3604 steam.exe GET 302 155.133.250.108:80 http://client-download.steampowered.com/client/steam_client_win32 PE
––
––
suspicious
3604 steam.exe GET –– 2.16.186.59:80 http://media4.steampowered.com/client/tenfoot_dicts_all.zip.33245b7d523f68418283e93b0572508fa127ee8f unknown
––
––
whitelisted
3604 steam.exe GET 200 2.16.186.59:80 http://media4.steampowered.com/client/tenfoot_fonts_all.zip.vz.7673e4cd32b6752bc621d8bc1a7118a9af19b64a_12077027 unknown
binary
whitelisted
3604 steam.exe GET –– 2.16.186.59:80 http://media4.steampowered.com/client/tenfoot_ambientsounds_all.zip.89b80bcfdd11b2b99257ddbbdc374e2df54e2738 unknown
––
––
whitelisted

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
3604 steam.exe 155.133.250.108:80 PE suspicious
3604 steam.exe 2.16.186.59:80 Akamai International B.V. –– whitelisted

DNS requests

Domain IP Reputation
client-download.steampowered.com 155.133.250.108
155.133.250.76
155.133.250.107
155.133.250.75
suspicious
media4.steampowered.com 2.16.186.59
whitelisted

Threats

PID Process Class Message
3604 steam.exe Potential Corporate Privacy Violation ET USER_AGENTS Steam HTTP Client User-Agent

Debug output strings

No debug info.