File name:

st-setup-1.8.16.exe

Full analysis: https://app.any.run/tasks/5afc862b-4c88-4dfa-972e-59a941ac5639
Verdict: Malicious activity
Analysis date: May 28, 2025, 13:56:44
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows, 9 sections
MD5:

9C42F5CCAE30AFC9C70C924D543924F8

SHA1:

4E3C555CFEE82D23ACFDDA4754C0870F455156E8

SHA256:

80B6573208F2179C97CE64FF731269E349A07A3969C1198BF5A9092C5A01555C

SSDEEP:

98304:J+dm8gYux7Ede4oqZSYVgnSoPV7dquc8GV+x7YjvyeSdRYTUhQ5WwwFPc7xqSG6i:PvI2akT6ZJJW6dEQK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • st-setup-1.8.16.exe (PID: 7732)
    • The process creates files with name similar to system file names

      • st-setup-1.8.16.exe (PID: 7732)
    • There is functionality for taking screenshot (YARA)

      • st-setup-1.8.16.exe (PID: 7732)
    • Uses ICACLS.EXE to modify access control lists

      • st-setup-1.8.16.exe (PID: 7732)
    • Creates a software uninstall entry

      • st-setup-1.8.16.exe (PID: 7732)
    • Executable content was dropped or overwritten

      • st-setup-1.8.16.exe (PID: 7732)
    • Explorer used for Indirect Command Execution

      • explorer.exe (PID: 7084)
    • Starts CMD.EXE for commands execution

      • explorer.exe (PID: 1764)
    • Process drops legitimate windows executable

      • st-setup-1.8.16.exe (PID: 7732)
    • Executing commands from a ".bat" file

      • explorer.exe (PID: 1764)
    • The process drops C-runtime libraries

      • st-setup-1.8.16.exe (PID: 7732)
  • INFO

    • Checks supported languages

      • st-setup-1.8.16.exe (PID: 7732)
      • SteamTools.exe (PID: 1452)
      • SteamTools.exe (PID: 5244)
      • SteamTools.exe (PID: 7224)
      • SteamTools.exe (PID: 7428)
      • SteamTools.exe (PID: 7708)
      • SteamTools.exe (PID: 7800)
      • SteamTools.exe (PID: 7600)
      • SteamTools.exe (PID: 7828)
      • SteamTools.exe (PID: 7996)
      • SteamTools.exe (PID: 7900)
      • SteamTools.exe (PID: 7936)
      • SteamTools.exe (PID: 3268)
      • SteamTools.exe (PID: 7568)
      • SteamTools.exe (PID: 6480)
      • SteamTools.exe (PID: 7908)
      • SteamTools.exe (PID: 7852)
      • SteamTools.exe (PID: 4692)
      • SteamTools.exe (PID: 8020)
      • SteamTools.exe (PID: 5360)
      • SteamTools.exe (PID: 8036)
      • SteamTools.exe (PID: 2552)
      • SteamTools.exe (PID: 3300)
      • SteamTools.exe (PID: 6576)
      • SteamTools.exe (PID: 3332)
      • SteamTools.exe (PID: 5740)
      • SteamTools.exe (PID: 1388)
      • SteamTools.exe (PID: 8184)
      • SteamTools.exe (PID: 6248)
      • SteamTools.exe (PID: 2644)
      • SteamTools.exe (PID: 4424)
      • SteamTools.exe (PID: 4736)
      • SteamTools.exe (PID: 7264)
      • SteamTools.exe (PID: 7292)
      • SteamTools.exe (PID: 6404)
      • SteamTools.exe (PID: 4528)
      • SteamTools.exe (PID: 5072)
      • SteamTools.exe (PID: 7396)
      • SteamTools.exe (PID: 4776)
      • SteamTools.exe (PID: 8152)
      • SteamTools.exe (PID: 8160)
      • SteamTools.exe (PID: 5324)
      • SteamTools.exe (PID: 6712)
    • Creates files in the program directory

      • st-setup-1.8.16.exe (PID: 7732)
    • Reads the computer name

      • st-setup-1.8.16.exe (PID: 7732)
      • SteamTools.exe (PID: 1452)
      • SteamTools.exe (PID: 5244)
    • Create files in a temporary directory

      • st-setup-1.8.16.exe (PID: 7732)
    • The sample compiled with english language support

      • st-setup-1.8.16.exe (PID: 7732)
    • Creates files or folders in the user directory

      • st-setup-1.8.16.exe (PID: 7732)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 1764)
    • Manual execution by a user

      • SteamTools.exe (PID: 7224)
      • SteamTools.exe (PID: 7800)
      • SteamTools.exe (PID: 7600)
      • SteamTools.exe (PID: 7428)
      • SteamTools.exe (PID: 7708)
      • SteamTools.exe (PID: 7568)
      • SteamTools.exe (PID: 5244)
      • SteamTools.exe (PID: 7828)
      • SteamTools.exe (PID: 5740)
      • SteamTools.exe (PID: 7996)
      • SteamTools.exe (PID: 7900)
      • SteamTools.exe (PID: 7936)
      • SteamTools.exe (PID: 3268)
      • SteamTools.exe (PID: 8020)
      • SteamTools.exe (PID: 6480)
      • SteamTools.exe (PID: 7908)
      • SteamTools.exe (PID: 7852)
      • SteamTools.exe (PID: 1388)
      • SteamTools.exe (PID: 5360)
      • SteamTools.exe (PID: 6576)
      • SteamTools.exe (PID: 2552)
      • SteamTools.exe (PID: 3332)
      • SteamTools.exe (PID: 4692)
      • SteamTools.exe (PID: 8036)
      • SteamTools.exe (PID: 3300)
      • SteamTools.exe (PID: 7264)
      • SteamTools.exe (PID: 6248)
      • SteamTools.exe (PID: 4736)
      • SteamTools.exe (PID: 7292)
      • SteamTools.exe (PID: 8184)
      • SteamTools.exe (PID: 6404)
      • SteamTools.exe (PID: 2644)
      • SteamTools.exe (PID: 4424)
      • SteamTools.exe (PID: 4776)
      • SteamTools.exe (PID: 4528)
      • SteamTools.exe (PID: 8152)
      • SteamTools.exe (PID: 8160)
      • SteamTools.exe (PID: 7396)
      • SteamTools.exe (PID: 5072)
      • SteamTools.exe (PID: 6712)
      • SteamTools.exe (PID: 4120)
      • SteamTools.exe (PID: 7244)
      • SteamTools.exe (PID: 920)
      • SteamTools.exe (PID: 5324)
      • SteamTools.exe (PID: 7520)
      • SteamTools.exe (PID: 4284)
      • SteamTools.exe (PID: 1180)
      • SteamTools.exe (PID: 8084)
      • SteamTools.exe (PID: 7560)
      • SteamTools.exe (PID: 1748)
      • SteamTools.exe (PID: 6208)
      • SteamTools.exe (PID: 2084)
      • SteamTools.exe (PID: 6228)
      • SteamTools.exe (PID: 7144)
      • SteamTools.exe (PID: 6416)
      • SteamTools.exe (PID: 4996)
    • Checks proxy server information

      • SteamTools.exe (PID: 1452)
      • SteamTools.exe (PID: 5244)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:02:08 08:30:59+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Large address aware, No debug
PEType: PE32+
LinkerVersion: 2.38
CodeSize: 36352
InitializedDataSize: 51200
UninitializedDataSize: 246784
EntryPoint: 0x4560
OSVersion: 5.1
ImageVersion: 6
SubsystemVersion: 5.1
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
200
Monitored processes
68
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start st-setup-1.8.16.exe icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs explorer.exe no specs explorer.exe no specs cmd.exe no specs conhost.exe no specs steamtools.exe steamtools.exe steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs slui.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs steamtools.exe no specs st-setup-1.8.16.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
920"C:\Program Files\SteamTools\SteamTools.exe" C:\Program Files\SteamTools\SteamTools.exeexplorer.exe
User:
admin
Company:
steamtools.net
Integrity Level:
MEDIUM
Description:
Steamtools
Exit code:
0
Version:
1.8.1.5
Modules
Images
c:\program files\steamtools\steamtools.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\program files\steamtools\qt5svg.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\gdi32full.dll
1180"C:\Program Files\SteamTools\SteamTools.exe" C:\Program Files\SteamTools\SteamTools.exeexplorer.exe
User:
admin
Company:
steamtools.net
Integrity Level:
MEDIUM
Description:
Steamtools
Exit code:
0
Version:
1.8.1.5
Modules
Images
c:\program files\steamtools\steamtools.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1388"C:\Program Files\SteamTools\SteamTools.exe" C:\Program Files\SteamTools\SteamTools.exeexplorer.exe
User:
admin
Company:
steamtools.net
Integrity Level:
MEDIUM
Description:
Steamtools
Exit code:
0
Version:
1.8.1.5
Modules
Images
c:\program files\steamtools\steamtools.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1452"C:\Program Files\SteamTools\SteamTools.exe" C:\Program Files\SteamTools\SteamTools.exe
cmd.exe
User:
admin
Company:
steamtools.net
Integrity Level:
MEDIUM
Description:
Steamtools
Version:
1.8.1.5
Modules
Images
c:\program files\steamtools\steamtools.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1748"C:\Program Files\SteamTools\SteamTools.exe" C:\Program Files\SteamTools\SteamTools.exeexplorer.exe
User:
admin
Company:
steamtools.net
Integrity Level:
MEDIUM
Description:
Steamtools
Exit code:
0
Version:
1.8.1.5
Modules
Images
c:\program files\steamtools\steamtools.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1764C:\WINDOWS\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -EmbeddingC:\Windows\explorer.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\twinapi.dll
2084"C:\Program Files\SteamTools\SteamTools.exe" C:\Program Files\SteamTools\SteamTools.exeexplorer.exe
User:
admin
Company:
steamtools.net
Integrity Level:
MEDIUM
Description:
Steamtools
Exit code:
0
Version:
1.8.1.5
Modules
Images
c:\program files\steamtools\steamtools.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\program files\steamtools\qt5svg.dll
c:\windows\system32\msvcp_win.dll
2552"C:\Program Files\SteamTools\SteamTools.exe" C:\Program Files\SteamTools\SteamTools.exeexplorer.exe
User:
admin
Company:
steamtools.net
Integrity Level:
MEDIUM
Description:
Steamtools
Exit code:
0
Version:
1.8.1.5
Modules
Images
c:\program files\steamtools\steamtools.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\program files\steamtools\qt5network.dll
2644"C:\Program Files\SteamTools\SteamTools.exe" C:\Program Files\SteamTools\SteamTools.exeexplorer.exe
User:
admin
Company:
steamtools.net
Integrity Level:
MEDIUM
Description:
Steamtools
Exit code:
0
Version:
1.8.1.5
Modules
Images
c:\program files\steamtools\steamtools.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3268"C:\Program Files\SteamTools\SteamTools.exe" C:\Program Files\SteamTools\SteamTools.exeexplorer.exe
User:
admin
Company:
steamtools.net
Integrity Level:
MEDIUM
Description:
Steamtools
Exit code:
0
Version:
1.8.1.5
Modules
Images
c:\program files\steamtools\steamtools.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
2 895
Read events
2 758
Write events
137
Delete events
0

Modification events

(PID) Process:(7732) st-setup-1.8.16.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteamTools
Operation:writeName:DisplayName
Value:
SteamTools
(PID) Process:(7732) st-setup-1.8.16.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteamTools
Operation:writeName:UninstallString
Value:
"C:\Program Files\SteamTools\Uninstall.exe"
(PID) Process:(7732) st-setup-1.8.16.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteamTools
Operation:writeName:QuietUninstallString
Value:
"C:\Program Files\SteamTools\Uninstall.exe" /S
(PID) Process:(7732) st-setup-1.8.16.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteamTools
Operation:writeName:InstallLocation
Value:
C:\Program Files\SteamTools
(PID) Process:(7732) st-setup-1.8.16.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteamTools
Operation:writeName:DisplayIcon
Value:
C:\Program Files\SteamTools\SteamTools.exe,0
(PID) Process:(7732) st-setup-1.8.16.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteamTools
Operation:writeName:NoModify
Value:
1
(PID) Process:(7732) st-setup-1.8.16.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteamTools
Operation:writeName:NoRepair
Value:
1
(PID) Process:(7732) st-setup-1.8.16.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\SteamTools
Operation:writeName:Language
Value:
1033
(PID) Process:(1764) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
(PID) Process:(1452) SteamTools.exeKey:HKEY_CURRENT_USER\SOFTWARE\Valve\Steamtools
Operation:writeName:fScreenIndex
Value:
0
Executable files
17
Suspicious files
0
Text files
3
Unknown types
3

Dropped files

PID
Process
Filename
Type
7732st-setup-1.8.16.exeC:\Program Files\SteamTools\platforms\qwindows.dllexecutable
MD5:4931FCD0E86C4D4F83128DC74E01EAAD
SHA256:3333BA244C97264E3BD19DB5953EFA80A6E47AACED9D337AC3287EC718162B85
7732st-setup-1.8.16.exeC:\Program Files\SteamTools\Qt5Gui.dllexecutable
MD5:47307A1E2E9987AB422F09771D590FF1
SHA256:5E7D2D41B8B92A880E83B8CC0CA173F5DA61218604186196787EE1600956BE1E
7732st-setup-1.8.16.exeC:\Program Files\SteamTools\Qt5Svg.dllexecutable
MD5:03761F923E52A7269A6E3A7452F6BE93
SHA256:7348CFC6444438B8845FB3F59381227325D40CA2187D463E82FC7B8E93E38DB5
7732st-setup-1.8.16.exeC:\Program Files\SteamTools\msvcp140_1.dllexecutable
MD5:18A6C1A3D630DFCBC227082D5B06681A
SHA256:AF589D441CD97638B1A0B9192A4014C52B64B35ECF5437CAA65F27B3583E07AA
7732st-setup-1.8.16.exeC:\Users\admin\AppData\Local\Temp\nsrC844.tmp
MD5:
SHA256:
7732st-setup-1.8.16.exeC:\Program Files\SteamTools\Qt5Widgets.dllexecutable
MD5:4CD1F8FDCD617932DB131C3688845EA8
SHA256:3788C669D4B645E5A576DE9FC77FCA776BF516D43C89143DC2CA28291BA14358
7732st-setup-1.8.16.exeC:\Users\admin\AppData\Local\Temp\nsrC845.tmp\modern-header.bmpimage
MD5:F1928D020EBD3BF2C54FB46B3253F2A9
SHA256:A928EDA70352B4BF7FE85EBEE91B1CA819AD78A4DBA4547B95A1A3FFF51F89DD
7732st-setup-1.8.16.exeC:\Program Files\SteamTools\Qt5Network.dllexecutable
MD5:3569693D5BAE82854DE1D88F86C33184
SHA256:4EF341AE9302E793878020F0740B09B0F31CB380408A697F75C69FDBD20FC7A1
7732st-setup-1.8.16.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SteamTools\SteamTools.lnklnk
MD5:36039238C6F00B831873956DD884CBB8
SHA256:6D604A62286F07E97455B26C23087C5BC7C1F0C6BDF054445AE0D5D1E30C0C81
7732st-setup-1.8.16.exeC:\Program Files\SteamTools\vcruntime140_1.dllexecutable
MD5:3B22B2EC303B0721827DD768C87DF6ED
SHA256:3B792DA47040C3B3E0804CDC5153EEF4E802B6975963029D8DC360CB824A7B62
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
20
DNS requests
14
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
8180
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
8180
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1452
SteamTools.exe
GET
302
119.167.249.58:80
http://new-service.biliapi.net/picture/chatres/update/version2.txt
unknown
unknown
5244
SteamTools.exe
GET
302
119.167.249.58:80
http://new-service.biliapi.net/picture/chatres/update/version2.txt
unknown
unknown
1452
SteamTools.exe
GET
200
8.133.135.83:80
http://stools.oss-cn-shanghai.aliyuncs.com/version2.txt
unknown
unknown
5244
SteamTools.exe
GET
200
8.133.135.83:80
http://stools.oss-cn-shanghai.aliyuncs.com/version2.txt
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.32.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
8180
SIHClient.exe
20.109.210.53:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
8180
SIHClient.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
8180
SIHClient.exe
40.69.42.241:443
fe3cr.delivery.mp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 40.126.32.68
  • 20.190.160.130
  • 40.126.32.72
  • 40.126.32.136
  • 20.190.160.64
  • 20.190.160.2
  • 40.126.32.133
  • 20.190.160.22
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
www.microsoft.com
  • 2.23.246.101
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted
steamtools.info
unknown
new-service.biliapi.net
  • 119.167.249.58
  • 116.153.3.100
  • 59.83.212.226
  • 122.188.45.51
  • 101.72.254.91
  • 60.221.17.73
  • 116.196.150.249
  • 122.188.44.51
  • 122.188.45.182
  • 60.221.17.61
  • 122.188.44.139
  • 122.188.45.140
unknown
stools.oss-cn-shanghai.aliyuncs.com
  • 8.133.135.83
unknown

Threats

PID
Process
Class
Message
1452
SteamTools.exe
Misc activity
INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0)
1452
SteamTools.exe
Misc activity
INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0)
2196
svchost.exe
Misc activity
ET INFO DNS Query to Alibaba Cloud CDN Domain (aliyuncs .com)
1452
SteamTools.exe
Misc activity
INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0)
1452
SteamTools.exe
Misc activity
INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0)
No debug info