File name:

st-setup-1.8.16.exe

Full analysis: https://app.any.run/tasks/8f1c732b-44a3-4777-a4bf-f57165c6fdf8
Verdict: Malicious activity
Analysis date: May 18, 2025, 21:30:26
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows, 9 sections
MD5:

9C42F5CCAE30AFC9C70C924D543924F8

SHA1:

4E3C555CFEE82D23ACFDDA4754C0870F455156E8

SHA256:

80B6573208F2179C97CE64FF731269E349A07A3969C1198BF5A9092C5A01555C

SSDEEP:

98304:J+dm8gYux7Ede4oqZSYVgnSoPV7dquc8GV+x7YjvyeSdRYTUhQ5WwwFPc7xqSG6i:PvI2akT6ZJJW6dEQK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • st-setup-1.8.16.exe (PID: 516)
    • There is functionality for taking screenshot (YARA)

      • st-setup-1.8.16.exe (PID: 516)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • st-setup-1.8.16.exe (PID: 516)
    • The process creates files with name similar to system file names

      • st-setup-1.8.16.exe (PID: 516)
    • Process drops legitimate windows executable

      • st-setup-1.8.16.exe (PID: 516)
    • The process drops C-runtime libraries

      • st-setup-1.8.16.exe (PID: 516)
    • Uses ICACLS.EXE to modify access control lists

      • st-setup-1.8.16.exe (PID: 516)
    • Creates a software uninstall entry

      • st-setup-1.8.16.exe (PID: 516)
    • Explorer used for Indirect Command Execution

      • explorer.exe (PID: 6080)
    • Starts CMD.EXE for commands execution

      • explorer.exe (PID: 5720)
    • Executing commands from a ".bat" file

      • explorer.exe (PID: 5720)
  • INFO

    • Checks supported languages

      • st-setup-1.8.16.exe (PID: 516)
      • SteamTools.exe (PID: 920)
    • Create files in a temporary directory

      • st-setup-1.8.16.exe (PID: 516)
    • Reads the computer name

      • st-setup-1.8.16.exe (PID: 516)
      • SteamTools.exe (PID: 920)
    • Creates files in the program directory

      • st-setup-1.8.16.exe (PID: 516)
    • The sample compiled with english language support

      • st-setup-1.8.16.exe (PID: 516)
    • Creates files or folders in the user directory

      • st-setup-1.8.16.exe (PID: 516)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 5720)
    • Checks proxy server information

      • SteamTools.exe (PID: 920)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:02:08 08:30:59+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Large address aware, No debug
PEType: PE32+
LinkerVersion: 2.38
CodeSize: 36352
InitializedDataSize: 51200
UninitializedDataSize: 246784
EntryPoint: 0x4560
OSVersion: 5.1
ImageVersion: 6
SubsystemVersion: 5.1
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
147
Monitored processes
13
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start st-setup-1.8.16.exe sppextcomobj.exe no specs slui.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs explorer.exe no specs explorer.exe no specs cmd.exe no specs conhost.exe no specs steamtools.exe st-setup-1.8.16.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
516"C:\Users\admin\Downloads\st-setup-1.8.16.exe" C:\Users\admin\Downloads\st-setup-1.8.16.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\downloads\st-setup-1.8.16.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
920"C:\Program Files\SteamTools\SteamTools.exe" C:\Program Files\SteamTools\SteamTools.exe
cmd.exe
User:
admin
Company:
steamtools.net
Integrity Level:
MEDIUM
Description:
Steamtools
Version:
1.8.1.5
Modules
Images
c:\program files\steamtools\steamtools.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1272C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\SteamTools_launcher.bat" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cmdext.dll
c:\windows\system32\advapi32.dll
1628\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeicacls.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2240\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeicacls.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2420icacls "C:\Program Files\SteamTools\*.*" /grant:r "*S-1-5-32-545:(OI)(CI)F"C:\Windows\System32\icacls.exest-setup-1.8.16.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2516"C:\Users\admin\Downloads\st-setup-1.8.16.exe" C:\Users\admin\Downloads\st-setup-1.8.16.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\downloads\st-setup-1.8.16.exe
c:\windows\system32\ntdll.dll
3132icacls "C:\Program Files\SteamTools" /grant:r "*S-1-5-32-545:(OI)(CI)F" /TC:\Windows\System32\icacls.exest-setup-1.8.16.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
5072C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
5720C:\WINDOWS\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -EmbeddingC:\Windows\explorer.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shcore.dll
Total events
1 558
Read events
1 546
Write events
12
Delete events
0

Modification events

(PID) Process:(516) st-setup-1.8.16.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteamTools
Operation:writeName:DisplayName
Value:
SteamTools
(PID) Process:(516) st-setup-1.8.16.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteamTools
Operation:writeName:UninstallString
Value:
"C:\Program Files\SteamTools\Uninstall.exe"
(PID) Process:(516) st-setup-1.8.16.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteamTools
Operation:writeName:QuietUninstallString
Value:
"C:\Program Files\SteamTools\Uninstall.exe" /S
(PID) Process:(516) st-setup-1.8.16.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteamTools
Operation:writeName:InstallLocation
Value:
C:\Program Files\SteamTools
(PID) Process:(516) st-setup-1.8.16.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteamTools
Operation:writeName:DisplayIcon
Value:
C:\Program Files\SteamTools\SteamTools.exe,0
(PID) Process:(516) st-setup-1.8.16.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteamTools
Operation:writeName:NoModify
Value:
1
(PID) Process:(516) st-setup-1.8.16.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteamTools
Operation:writeName:NoRepair
Value:
1
(PID) Process:(516) st-setup-1.8.16.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\SteamTools
Operation:writeName:Language
Value:
1033
(PID) Process:(5720) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
(PID) Process:(920) SteamTools.exeKey:HKEY_CURRENT_USER\SOFTWARE\Valve\Steamtools
Operation:writeName:fScreenIndex
Value:
0
Executable files
17
Suspicious files
3
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
516st-setup-1.8.16.exeC:\Users\admin\AppData\Local\Temp\nstCCE9.tmp\modern-wizard.bmpimage
MD5:3614A4BE6B610F1DAF6C801574F161FE
SHA256:16E0EDC9F47E6E95A9BCAD15ADBDC46BE774FBCD045DD526FC16FC38FDC8D49B
516st-setup-1.8.16.exeC:\Users\admin\AppData\Local\Temp\nstCCE9.tmp\nsDialogs.dllexecutable
MD5:9CBB2C67258DF6CFC08E060BD8AB8309
SHA256:4AEC3A5A78295861C8AD96B70B0520C541EA4DF60651615802AD066780CE2296
516st-setup-1.8.16.exeC:\Users\admin\AppData\Local\Temp\nstCCE9.tmp\modern-header.bmpimage
MD5:F1928D020EBD3BF2C54FB46B3253F2A9
SHA256:A928EDA70352B4BF7FE85EBEE91B1CA819AD78A4DBA4547B95A1A3FFF51F89DD
516st-setup-1.8.16.exeC:\Program Files\SteamTools\vcruntime140.dllexecutable
MD5:0C583614EB8FFB4C8C2D9E9880220F1D
SHA256:6CADB4FEF773C23B511ACC8B715A084815C6E41DD8C694BC70090A97B3B03FB9
516st-setup-1.8.16.exeC:\Users\admin\AppData\Local\Temp\nstCCD8.tmp
MD5:
SHA256:
516st-setup-1.8.16.exeC:\Users\admin\Desktop\SteamTools.lnkbinary
MD5:DFA2991C6C96B8A68F5928F42324B371
SHA256:8796E3DEC576B6F8BB954407301293824141481209078AD25C5E1C8EDFF1BB51
516st-setup-1.8.16.exeC:\Program Files\SteamTools\msvcp140_1.dllexecutable
MD5:18A6C1A3D630DFCBC227082D5B06681A
SHA256:AF589D441CD97638B1A0B9192A4014C52B64B35ECF5437CAA65F27B3583E07AA
516st-setup-1.8.16.exeC:\Program Files\SteamTools\SteamTools.exeexecutable
MD5:E45BFB5EDCC03451A85BC505298FBC16
SHA256:7AFCB8D488F34E284DEEF1559DBC0D46D1BD68E226928E5B583169A1FD275842
516st-setup-1.8.16.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SteamTools\SteamTools.lnkbinary
MD5:613E266B9C82EA8E7FB225BF7656309C
SHA256:0B89805F6251ACF85B6FFF111CD6E70DE1797B9AC4DC1F4EA58F9C66BABC79B6
516st-setup-1.8.16.exeC:\Program Files\SteamTools\Qt5Widgets.dllexecutable
MD5:4CD1F8FDCD617932DB131C3688845EA8
SHA256:3788C669D4B645E5A576DE9FC77FCA776BF516D43C89143DC2CA28291BA14358
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
29
DNS requests
20
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
920
SteamTools.exe
GET
404
122.188.45.182:80
http://new-service.biliapi.net/picture/chatres/update/version2.txt
unknown
unknown
920
SteamTools.exe
GET
404
8.133.135.83:80
http://stools.oss-cn-shanghai.aliyuncs.com/version2.txt
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.31.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2112
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2104
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
920
SteamTools.exe
122.188.45.182:80
new-service.biliapi.net
CHINA UNICOM China169 Backbone
CN
unknown
920
SteamTools.exe
8.133.135.83:80
stools.oss-cn-shanghai.aliyuncs.com
Hangzhou Alibaba Advertising Co.,Ltd.
CN
unknown
2392
SIHClient.exe
4.175.87.197:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
google.com
  • 142.250.186.142
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 40.126.31.130
  • 20.190.159.68
  • 40.126.31.3
  • 20.190.159.2
  • 20.190.159.131
  • 20.190.159.73
  • 40.126.31.1
  • 40.126.31.128
whitelisted
steamtools.info
  • 49.13.77.253
unknown
new-service.biliapi.net
  • 122.188.45.182
  • 116.153.3.100
  • 122.188.45.51
  • 122.188.44.139
  • 59.83.212.226
  • 101.72.254.91
  • 116.196.150.249
  • 119.167.249.58
  • 122.188.44.51
  • 60.221.17.73
  • 122.188.45.140
  • 122.192.127.62
unknown
stools.oss-cn-shanghai.aliyuncs.com
  • 8.133.135.83
unknown
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
  • 2603:1030:800:5::bfee:a08d
whitelisted
171.39.242.20.in-addr.arpa
unknown

Threats

PID
Process
Class
Message
920
SteamTools.exe
Misc activity
INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0)
2196
svchost.exe
Misc activity
ET INFO DNS Query to Alibaba Cloud CDN Domain (aliyuncs .com)
920
SteamTools.exe
Misc activity
INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0)
No debug info