File name:

steam.exe

Full analysis: https://app.any.run/tasks/51b3e352-a8d8-41ed-8d47-701c229cd66f
Verdict: Malicious activity
Analysis date: December 26, 2023, 16:32:40
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

90208E7B4C0FCB57088BEF5C255A31E2

SHA1:

B8730BA15A441C281D7D0E0BB0A7F4ACEE496A70

SHA256:

620BE7DA1140F212866C90BEB67E7E39021DA6FE3A880D0896A992739446384F

SSDEEP:

98304:xgs0Xq7DuPHiTXynE0JVbhVDBDV3Vx/zJZzwW2GB88Rm5HwaLZYk3UFm4MTIfP6J:xcWb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads settings of System Certificates

      • steam.exe (PID: 2184)
    • Reads the Internet Settings

      • steam.exe (PID: 2184)
    • Process uses IPCONFIG to discover network configuration

      • cmd.exe (PID: 1540)
  • INFO

    • Drops the executable file immediately after the start

      • steam.exe (PID: 2184)
    • Checks supported languages

      • steam.exe (PID: 2184)
    • Reads the computer name

      • steam.exe (PID: 2184)
    • Reads CPU info

      • steam.exe (PID: 2184)
    • Creates files or folders in the user directory

      • steam.exe (PID: 2184)
    • Reads the machine GUID from the registry

      • steam.exe (PID: 2184)
    • Manual execution by a user

      • cmd.exe (PID: 1540)
    • Create files in a temporary directory

      • steam.exe (PID: 2184)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:12:08 01:36:14+01:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 3020288
InitializedDataSize: 1353728
UninitializedDataSize: -
EntryPoint: 0x14da1d
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 8.56.38.63
ProductVersionNumber: 1.0.0.2
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
LegalCopyright: Copyright (C) 2021 Valve Corporation
InternalName: steam (buildbot_steam-relclient-win32-builder_steam_rel_client_win32@steam-relclient-win32-builder)
FileVersion: 08.56.38.63
CompanyName: Valve Corporation
ProductVersion: 01.00.00.02
FileDescription: Steam
SourceControlID: 8563863
OriginalFileName: steam.exe
ProductName: Steam
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start steam.exe Network Common Connections Ui no specs cmd.exe no specs ipconfig.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1316C:\Windows\system32\DllHost.exe /Processid:{7007ACD1-3202-11D1-AAD2-00805FC1270E}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1540"C:\Windows\system32\cmd.exe" C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2184"C:\Users\admin\AppData\Local\Temp\steam.exe" C:\Users\admin\AppData\Local\Temp\steam.exe
explorer.exe
User:
admin
Company:
Valve Corporation
Integrity Level:
MEDIUM
Description:
Steam
Exit code:
0
Version:
08.56.38.63
Modules
Images
c:\users\admin\appdata\local\temp\steam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2300ipconfig /allC:\Windows\System32\ipconfig.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
IP Configuration Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ipconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
Total events
5 066
Read events
5 040
Write events
26
Delete events
0

Modification events

(PID) Process:(2184) steam.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Steam
Operation:writeName:SteamPID
Value:
0
(PID) Process:(2184) steam.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1316) dllhost.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
0
Suspicious files
17
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2184steam.exeC:\Users\admin\AppData\Local\Temp\package\tenfoot_dicts_all.zip.3a6cb3db75398c509bdc6e389408b6951017494b
MD5:
SHA256:
2184steam.exeC:\Users\admin\AppData\Local\Temp\package\tenfoot_fonts_all.zip.vz.e19674422bc376becd7bf4a73b4b52eefc34c7fe_12075477
MD5:
SHA256:
2184steam.exeC:\Users\admin\AppData\Local\Temp\package\tenfoot_misc_all.zip.a49df66ba6bd900ed2c58bb4a9a578752f73f511
MD5:
SHA256:
2184steam.exeC:\Users\admin\AppData\Local\Temp\package\tenfoot_ambientsounds_all.zip.c8342205c2cdfec5329ec8ec2905ddaa33be3cb8
MD5:
SHA256:
2184steam.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
2184steam.exeC:\Users\admin\AppData\Local\Temp\TarFBF5.tmpcat
MD5:9C0C641C06238516F27941AA1166D427
SHA256:4276AF3669A141A59388BC56A87F6614D9A9BDDDF560636C264219A7EB11256F
2184steam.exeC:\Users\admin\AppData\Local\Temp\CabFBF4.tmpcompressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
2184steam.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C20769695407776ADAEAAD16A464C6D7binary
MD5:103E404999911B55A8937A242761FE88
SHA256:C933B08184ABA70D0B0583483AD6C808C12097B3C69BD62745FA35C90E2D316E
2184steam.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751der
MD5:60FE01DF86BE2E5331B0CDBE86165686
SHA256:C08CCBC876CD5A7CDFA9670F9637DA57F6A1282198A9BC71FC7D7247A6E5B7A8
2184steam.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C20769695407776ADAEAAD16A464C6D7binary
MD5:42C535B1CC7298A360F84886955615C8
SHA256:FC4BF12D6A8A8B07524A100C9EDF493CF20E1C800021F3F445C9EC0A53C1C898
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
11
DNS requests
5
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2184
steam.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?e5397fd9468ed318
unknown
compressed
4.66 Kb
unknown
2184
steam.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?f036be01d945f47e
unknown
compressed
65.2 Kb
unknown
2184
steam.exe
GET
200
23.192.153.142:80
http://x1.c.lencr.org/
unknown
binary
717 b
unknown
2184
steam.exe
GET
200
23.32.238.27:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgRr%2Fj98BpkXNF9O4e3CPpXkXA%3D%3D
unknown
binary
503 b
unknown
1080
svchost.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?57666a24cb959564
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2184
steam.exe
2.19.198.153:443
cdn.steamstatic.com
Akamai International B.V.
DE
unknown
2184
steam.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
2184
steam.exe
23.192.153.142:80
x1.c.lencr.org
AKAMAI-AS
GB
unknown
2184
steam.exe
23.32.238.27:80
r3.o.lencr.org
Akamai International B.V.
DE
unknown
1080
svchost.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted

DNS requests

Domain
IP
Reputation
cdn.steamstatic.com
  • 2.19.198.153
  • 2.19.198.123
unknown
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
x1.c.lencr.org
  • 23.192.153.142
whitelisted
r3.o.lencr.org
  • 23.32.238.27
  • 23.32.238.82
shared

Threats

No threats detected
No debug info