File name:

steam.exe

Full analysis: https://app.any.run/tasks/51b3e352-a8d8-41ed-8d47-701c229cd66f
Verdict: Malicious activity
Analysis date: December 26, 2023, 16:32:40
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

90208E7B4C0FCB57088BEF5C255A31E2

SHA1:

B8730BA15A441C281D7D0E0BB0A7F4ACEE496A70

SHA256:

620BE7DA1140F212866C90BEB67E7E39021DA6FE3A880D0896A992739446384F

SSDEEP:

98304:xgs0Xq7DuPHiTXynE0JVbhVDBDV3Vx/zJZzwW2GB88Rm5HwaLZYk3UFm4MTIfP6J:xcWb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads settings of System Certificates

      • steam.exe (PID: 2184)
    • Reads the Internet Settings

      • steam.exe (PID: 2184)
    • Process uses IPCONFIG to discover network configuration

      • cmd.exe (PID: 1540)
  • INFO

    • Checks supported languages

      • steam.exe (PID: 2184)
    • Reads the computer name

      • steam.exe (PID: 2184)
    • Drops the executable file immediately after the start

      • steam.exe (PID: 2184)
    • Reads the machine GUID from the registry

      • steam.exe (PID: 2184)
    • Creates files or folders in the user directory

      • steam.exe (PID: 2184)
    • Create files in a temporary directory

      • steam.exe (PID: 2184)
    • Manual execution by a user

      • cmd.exe (PID: 1540)
    • Reads CPU info

      • steam.exe (PID: 2184)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:12:08 01:36:14+01:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 3020288
InitializedDataSize: 1353728
UninitializedDataSize: -
EntryPoint: 0x14da1d
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 8.56.38.63
ProductVersionNumber: 1.0.0.2
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
LegalCopyright: Copyright (C) 2021 Valve Corporation
InternalName: steam (buildbot_steam-relclient-win32-builder_steam_rel_client_win32@steam-relclient-win32-builder)
FileVersion: 08.56.38.63
CompanyName: Valve Corporation
ProductVersion: 01.00.00.02
FileDescription: Steam
SourceControlID: 8563863
OriginalFileName: steam.exe
ProductName: Steam
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start steam.exe Network Common Connections Ui no specs cmd.exe no specs ipconfig.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1316C:\Windows\system32\DllHost.exe /Processid:{7007ACD1-3202-11D1-AAD2-00805FC1270E}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1540"C:\Windows\system32\cmd.exe" C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2184"C:\Users\admin\AppData\Local\Temp\steam.exe" C:\Users\admin\AppData\Local\Temp\steam.exe
explorer.exe
User:
admin
Company:
Valve Corporation
Integrity Level:
MEDIUM
Description:
Steam
Exit code:
0
Version:
08.56.38.63
Modules
Images
c:\users\admin\appdata\local\temp\steam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2300ipconfig /allC:\Windows\System32\ipconfig.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
IP Configuration Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ipconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
Total events
5 066
Read events
5 040
Write events
26
Delete events
0

Modification events

(PID) Process:(2184) steam.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Steam
Operation:writeName:SteamPID
Value:
0
(PID) Process:(2184) steam.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1316) dllhost.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
0
Suspicious files
17
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2184steam.exeC:\Users\admin\AppData\Local\Temp\package\tenfoot_dicts_all.zip.3a6cb3db75398c509bdc6e389408b6951017494b
MD5:
SHA256:
2184steam.exeC:\Users\admin\AppData\Local\Temp\package\tenfoot_fonts_all.zip.vz.e19674422bc376becd7bf4a73b4b52eefc34c7fe_12075477
MD5:
SHA256:
2184steam.exeC:\Users\admin\AppData\Local\Temp\package\tenfoot_misc_all.zip.a49df66ba6bd900ed2c58bb4a9a578752f73f511
MD5:
SHA256:
2184steam.exeC:\Users\admin\AppData\Local\Temp\package\tenfoot_ambientsounds_all.zip.c8342205c2cdfec5329ec8ec2905ddaa33be3cb8
MD5:
SHA256:
2184steam.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
2184steam.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:A83DBE7A8F56FC34B2A6C5A2EC2232A2
SHA256:70F6BB66ED9108C56D612685DDEB6BD3403E7EAA23A1DE25CAA75FD92E06950C
2184steam.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751der
MD5:60FE01DF86BE2E5331B0CDBE86165686
SHA256:C08CCBC876CD5A7CDFA9670F9637DA57F6A1282198A9BC71FC7D7247A6E5B7A8
2184steam.exeC:\Users\admin\AppData\Local\Temp\TarFBF5.tmpcat
MD5:9C0C641C06238516F27941AA1166D427
SHA256:4276AF3669A141A59388BC56A87F6614D9A9BDDDF560636C264219A7EB11256F
2184steam.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:CCE9F3A4B87F45CBAD88102C5F05CA29
SHA256:1C9A56066CBD0F6E990EE04638F5CD67AFA5B074529B3AE381E94CA4E855704A
2184steam.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751binary
MD5:DFB7CD18CE884E9F4C483B9B8E2E56F7
SHA256:00F28F645944070235ADAF6F19266B74553D1B223D29559BEE690C1CFA9DC4D7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
11
DNS requests
5
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2184
steam.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?e5397fd9468ed318
unknown
compressed
4.66 Kb
unknown
2184
steam.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?f036be01d945f47e
unknown
compressed
65.2 Kb
unknown
2184
steam.exe
GET
200
23.192.153.142:80
http://x1.c.lencr.org/
unknown
binary
717 b
unknown
2184
steam.exe
GET
200
23.32.238.27:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgRr%2Fj98BpkXNF9O4e3CPpXkXA%3D%3D
unknown
binary
503 b
unknown
1080
svchost.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?57666a24cb959564
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2184
steam.exe
2.19.198.153:443
cdn.steamstatic.com
Akamai International B.V.
DE
unknown
2184
steam.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
2184
steam.exe
23.192.153.142:80
x1.c.lencr.org
AKAMAI-AS
GB
unknown
2184
steam.exe
23.32.238.27:80
r3.o.lencr.org
Akamai International B.V.
DE
unknown
1080
svchost.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted

DNS requests

Domain
IP
Reputation
cdn.steamstatic.com
  • 2.19.198.153
  • 2.19.198.123
unknown
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
x1.c.lencr.org
  • 23.192.153.142
whitelisted
r3.o.lencr.org
  • 23.32.238.27
  • 23.32.238.82
shared

Threats

No threats detected
No debug info