File name: | SteamSetup.exe |
Full analysis: | https://app.any.run/tasks/6eed1b94-2192-4dc6-a6f7-be2c9598d66f |
Verdict: | Malicious activity |
Analysis date: | July 05, 2025, 21:27:27 |
OS: | Windows 10 Professional (build: 19044, 64 bit) |
Tags: | |
Indicators: | |
MIME: | application/vnd.microsoft.portable-executable |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections |
MD5: | 1B54B70BEEF8EB240DB31718E8F7EB5D |
SHA1: | DA5995070737EC655824C92622333C489EB6BCE4 |
SHA256: | 7D3654531C32D941B8CAE81C4137FC542172BFA9635F169CB392F245A0A12BCB |
SSDEEP: | 98304:S6RFwVoL8grR2bFl3BZmIsejD4m1DnSM3JeZ7FLoiPApPyDqwsd84+e0lLQbolhV:SAbrIo |
.exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
---|---|---|
.exe | | | Win64 Executable (generic) (37.3) |
.dll | | | Win32 Dynamic Link Library (generic) (8.8) |
.exe | | | Win32 Executable (generic) (6) |
.exe | | | Generic Win/DOS Executable (2.7) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2016:07:25 00:55:51+00:00 |
ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
PEType: | PE32 |
LinkerVersion: | 6 |
CodeSize: | 25088 |
InitializedDataSize: | 141824 |
UninitializedDataSize: | 2048 |
EntryPoint: | 0x33b6 |
OSVersion: | 4 |
ImageVersion: | 6 |
SubsystemVersion: | 4 |
Subsystem: | Windows GUI |
FileVersionNumber: | 2.10.91.91 |
ProductVersionNumber: | 2.10.91.91 |
FileFlagsMask: | 0x0000 |
FileFlags: | (none) |
FileOS: | Win32 |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | Bulgarian |
CharacterSet: | Windows, Cyrillic |
FileDescription: | Steam |
FileVersion: | 2.10.91.91 |
LegalCopyright: | © Valve Corporation |
ProductName: | Steam |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2076 | "C:\Users\admin\Desktop\SteamSetup.exe" | C:\Users\admin\Desktop\SteamSetup.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Steam Exit code: 0 Version: 2.10.91.91 Modules
| |||||||||||||||
3952 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
4412 | "C:\Users\admin\Desktop\SteamSetup.exe" | C:\Users\admin\Desktop\SteamSetup.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Steam Exit code: 3221226540 Version: 2.10.91.91 Modules
| |||||||||||||||
4920 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | SteamService.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
5548 | "C:\Program Files (x86)\Steam\steam.exe" -silent | C:\Program Files (x86)\Steam\Steam.exe | explorer.exe | ||||||||||||
User: admin Company: Valve Corporation Integrity Level: MEDIUM Description: Steam Version: 08.90.88.32 Modules
| |||||||||||||||
6304 | "C:\Program Files (x86)\Steam\steam.exe" | C:\Program Files (x86)\Steam\Steam.exe | — | explorer.exe | |||||||||||
User: admin Company: Valve Corporation Integrity Level: MEDIUM Description: Steam Exit code: 0 Version: 08.90.88.32 Modules
| |||||||||||||||
7136 | "C:\Program Files (x86)\Steam\bin\steamservice.exe" /Install | C:\Program Files (x86)\Steam\bin\SteamService.exe | SteamSetup.exe | ||||||||||||
User: admin Company: Valve Corporation Integrity Level: HIGH Description: Steam Client Service Exit code: 0 Version: 08.90.88.32 Modules
|
(PID) Process: | (7136) SteamService.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Valve\Steam |
Operation: | write | Name: | InstallPath |
Value: C:\Program Files (x86)\Steam | |||
(PID) Process: | (2076) SteamSetup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Steam |
Operation: | write | Name: | DisplayName |
Value: Steam | |||
(PID) Process: | (2076) SteamSetup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Steam |
Operation: | write | Name: | DisplayVersion |
Value: 2.10.91.91 | |||
(PID) Process: | (2076) SteamSetup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Valve\Steam |
Operation: | write | Name: | Language |
Value: english | |||
(PID) Process: | (2076) SteamSetup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Valve\Steam |
Operation: | write | Name: | Language |
Value: english | |||
(PID) Process: | (2076) SteamSetup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
Operation: | write | Name: | Steam |
Value: "C:\Program Files (x86)\Steam\steam.exe" -silent | |||
(PID) Process: | (2076) SteamSetup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Valve\Steam |
Operation: | write | Name: | SteamInstaller |
Value: SteamSetup.exe | |||
(PID) Process: | (7136) SteamService.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Valve\SteamService |
Operation: | write | Name: | installpath_default |
Value: C:\Program Files (x86)\Steam | |||
(PID) Process: | (7136) SteamService.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\steam |
Operation: | write | Name: | URL Protocol |
Value: | |||
(PID) Process: | (7136) SteamService.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\steamlink |
Operation: | write | Name: | URL Protocol |
Value: |
PID | Process | Filename | Type | |
---|---|---|---|---|
2076 | SteamSetup.exe | C:\Users\admin\AppData\Local\Temp\nsb5E8D.tmp\modern-header.bmp | image | |
MD5:DA3486D12BB4C8AEC16BD9E0D363D23F | SHA256:D93B76D51BD2214FA6E999C1BF70B4AFF5165A6542F9B9B2A92B5672601F4624 | |||
2076 | SteamSetup.exe | C:\Users\admin\AppData\Local\Temp\nsb5E8D.tmp\System.dll | executable | |
MD5:A36FBE922FFAC9CD85A845D7A813F391 | SHA256:FA367AE36BFBE7C989C24C7ABBB13482FC20BC35E7812DC377AA1C281EE14CC0 | |||
2076 | SteamSetup.exe | C:\Users\admin\AppData\Local\Temp\nsb5E8D.tmp\nsProcess.dll | executable | |
MD5:08072DC900CA0626E8C079B2C5BCFCF3 | SHA256:BB6CE83DDAAD4F530A66A1048FAC868DFC3B86F5E7B8E240D84D1633E385AEE8 | |||
2076 | SteamSetup.exe | C:\Program Files (x86)\Steam\bin\SteamService.exe | executable | |
MD5:BA0EA9249DA4AB8F62432617489AE5A6 | SHA256:CE177DC8CF42513FF819C7B8597C7BE290F9E98632A34ECD868DC76003421F0D | |||
2076 | SteamSetup.exe | C:\Users\admin\AppData\Local\Temp\nsb5E8D.tmp\nsDialogs.dll | executable | |
MD5:4E5BC4458AFA770636F2806EE0A1E999 | SHA256:91A484DC79BE64DD11BF5ACB62C893E57505FCD8809483AA92B04F10D81F9DE0 | |||
2076 | SteamSetup.exe | C:\Program Files (x86)\Steam\public\steambootstrapper_bulgarian.txt | text | |
MD5:4C81277A127E3D65FB5065F518FFE9C2 | SHA256:76A6BD74194EFD819D33802DECDFDDAAE893069D7000E44944DDA05022CFA6D9 | |||
2076 | SteamSetup.exe | C:\Program Files (x86)\Steam\public\steambootstrapper_brazilian.txt | text | |
MD5:0340D1A0BBDB8F3017D2326F4E351E0A | SHA256:0FCD7AE491B467858F2A8745C5ECDD55451399778C2119517EE686D1F264B544 | |||
2076 | SteamSetup.exe | C:\Program Files (x86)\Steam\public\steambootstrapper_greek.txt | text | |
MD5:189BA063D1481528CBD6E0C4AFC3ABAA | SHA256:C0A7A1DF442AC080668762DF795C72AA322E9D415C41BD0A4C676A4DC0551695 | |||
2076 | SteamSetup.exe | C:\Program Files (x86)\Steam\public\steambootstrapper_english.txt | text | |
MD5:DA6CD2483AD8A21E8356E63D036DF55B | SHA256:EBECECD3F691AC20E5B73E5C81861A01531203DF3CF2BAA9E1B6D004733A42A6 | |||
2076 | SteamSetup.exe | C:\Program Files (x86)\Steam\public\steambootstrapper_finnish.txt | text | |
MD5:9E62FC923C65BFC3F40AAF6EC4FD1010 | SHA256:8FF0F3CBDF28102FF037B9CDA90590E4B66E1E654B90F9AEA2CD5364494D02B7 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
1268 | svchost.exe | GET | 200 | 2.16.168.114:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | GET | 200 | 2.16.168.114:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
5876 | RUXIMICS.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 151.101.195.52:443 | https://cdn.steamstatic.com/client/steam_client_win32 | unknown | text | 8.12 Kb | whitelisted |
— | — | GET | 200 | 151.101.195.52:443 | https://cdn.steamstatic.com/client/tenfoot_images_all.zip.vz.193cb8c4eb4446698ea2c0a9e8c4e6b6a623dac7_5572671 | unknown | binary | 5.31 Mb | whitelisted |
— | — | GET | 200 | 151.101.67.52:443 | https://cdn.steamstatic.com/client/steamui_websrc_all.zip.vz.05bb3a83a2664fe30a6191908c1e08e43370113d_24467013 | unknown | binary | 23.3 Mb | whitelisted |
— | — | GET | 200 | 151.101.131.52:443 | https://cdn.steamstatic.com/client/resources_misc_all.zip.vz.e86a975545f3ab21a77373870cb311ef93934b8c_2224876 | unknown | binary | 2.12 Mb | whitelisted |
— | — | GET | 200 | 151.101.3.52:443 | https://cdn.steamstatic.com/client/resources_hidpi_all.zip.vz.3de815c3117712cb9eeb7ea4c8b275faf481dcfd_56342 | unknown | binary | 55.0 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1268 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5944 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5876 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1268 | svchost.exe | 2.16.168.114:80 | crl.microsoft.com | Akamai International B.V. | RU | whitelisted |
5944 | MoUsoCoreWorker.exe | 2.16.168.114:80 | crl.microsoft.com | Akamai International B.V. | RU | whitelisted |
1268 | svchost.exe | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
5944 | MoUsoCoreWorker.exe | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
5876 | RUXIMICS.exe | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
Domain | IP | Reputation |
---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
cdn.steamstatic.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |
x1.c.lencr.org |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
---|---|---|---|
— | — | Potential Corporate Privacy Violation | ET USER_AGENTS Steam HTTP Client User-Agent |