File name:

SteamTools Setup New.exe

Full analysis: https://app.any.run/tasks/ce0335de-c492-4e01-86b1-3fa41fa4ecb0
Verdict: Malicious activity
Analysis date: May 17, 2025, 06:31:31
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows, 9 sections
MD5:

9C42F5CCAE30AFC9C70C924D543924F8

SHA1:

4E3C555CFEE82D23ACFDDA4754C0870F455156E8

SHA256:

80B6573208F2179C97CE64FF731269E349A07A3969C1198BF5A9092C5A01555C

SSDEEP:

98304:J+dm8gYux7Ede4oqZSYVgnSoPV7dquc8GV+x7YjvyeSdRYTUhQ5WwwFPc7xqSG6i:PvI2akT6ZJJW6dEQK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • SteamTools Setup New.exe (PID: 3896)
    • Starts CMD.EXE for commands execution

      • explorer.exe (PID: 1188)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • SteamTools Setup New.exe (PID: 3896)
      • SteamTools Setup New.exe (PID: 1072)
    • Executable content was dropped or overwritten

      • SteamTools Setup New.exe (PID: 3896)
      • SteamTools Setup New.exe (PID: 1072)
    • Process drops legitimate windows executable

      • SteamTools Setup New.exe (PID: 3896)
    • Uses ICACLS.EXE to modify access control lists

      • SteamTools Setup New.exe (PID: 3896)
    • Executing commands from a ".bat" file

      • explorer.exe (PID: 1188)
    • There is functionality for taking screenshot (YARA)

      • SteamTools.exe (PID: 5868)
    • Creates a software uninstall entry

      • SteamTools Setup New.exe (PID: 3896)
    • The process drops C-runtime libraries

      • SteamTools Setup New.exe (PID: 3896)
    • Explorer used for Indirect Command Execution

      • explorer.exe (PID: 6272)
  • INFO

    • Create files in a temporary directory

      • SteamTools Setup New.exe (PID: 3896)
    • Reads the computer name

      • SteamTools Setup New.exe (PID: 3896)
      • SteamTools.exe (PID: 5868)
    • Checks supported languages

      • SteamTools Setup New.exe (PID: 3896)
      • SteamTools.exe (PID: 5868)
      • SteamTools.exe (PID: 1328)
    • Creates files in the program directory

      • SteamTools Setup New.exe (PID: 3896)
    • Checks proxy server information

      • SteamTools.exe (PID: 5868)
    • Manual execution by a user

      • SteamTools.exe (PID: 1328)
      • SteamTools Setup New.exe (PID: 2332)
      • SteamTools Setup New.exe (PID: 1072)
    • Creates files or folders in the user directory

      • SteamTools Setup New.exe (PID: 3896)
    • The sample compiled with english language support

      • SteamTools Setup New.exe (PID: 3896)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 1188)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:02:08 08:30:59+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Large address aware, No debug
PEType: PE32+
LinkerVersion: 2.38
CodeSize: 36352
InitializedDataSize: 51200
UninitializedDataSize: 246784
EntryPoint: 0x4560
OSVersion: 5.1
ImageVersion: 6
SubsystemVersion: 5.1
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
155
Monitored processes
20
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start steamtools setup new.exe sppextcomobj.exe no specs slui.exe icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs explorer.exe no specs explorer.exe no specs cmd.exe no specs conhost.exe no specs steamtools.exe steamtools.exe no specs explorer.exe no specs COpenControlPanel no specs rundll32.exe no specs slui.exe steamtools setup new.exe no specs steamtools setup new.exe steamtools setup new.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
780C:\WINDOWS\explorer.exe /factory,{5BD95610-9434-43C2-886C-57852CC8A120} -EmbeddingC:\Windows\explorer.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shcore.dll
1072icacls "C:\Program Files\SteamTools" /grant:r "*S-1-5-32-545:(OI)(CI)F" /TC:\Windows\System32\icacls.exeSteamTools Setup New.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1072"C:\Users\admin\Desktop\SteamTools Setup New.exe" C:\Users\admin\Desktop\SteamTools Setup New.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\users\admin\desktop\steamtools setup new.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1188C:\WINDOWS\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -EmbeddingC:\Windows\explorer.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shcore.dll
1328"C:\Program Files\SteamTools\SteamTools.exe" C:\Program Files\SteamTools\SteamTools.exeexplorer.exe
User:
admin
Company:
steamtools.net
Integrity Level:
MEDIUM
Description:
Steamtools
Exit code:
0
Version:
1.8.1.5
Modules
Images
c:\program files\steamtools\steamtools.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\program files\steamtools\qt5network.dll
c:\windows\system32\gdi32full.dll
2332"C:\Users\admin\Desktop\SteamTools Setup New.exe" C:\Users\admin\Desktop\SteamTools Setup New.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\steamtools setup new.exe
c:\windows\system32\ntdll.dll
2692\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3896"C:\Users\admin\AppData\Local\Temp\SteamTools Setup New.exe" C:\Users\admin\AppData\Local\Temp\SteamTools Setup New.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\steamtools setup new.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4452icacls "C:\Program Files\SteamTools\*.*" /grant:r "*S-1-5-32-545:(OI)(CI)F"C:\Windows\System32\icacls.exeSteamTools Setup New.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4944C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
Total events
5 316
Read events
5 275
Write events
39
Delete events
2

Modification events

(PID) Process:(3896) SteamTools Setup New.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteamTools
Operation:writeName:DisplayName
Value:
SteamTools
(PID) Process:(3896) SteamTools Setup New.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteamTools
Operation:writeName:UninstallString
Value:
"C:\Program Files\SteamTools\Uninstall.exe"
(PID) Process:(3896) SteamTools Setup New.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteamTools
Operation:writeName:QuietUninstallString
Value:
"C:\Program Files\SteamTools\Uninstall.exe" /S
(PID) Process:(3896) SteamTools Setup New.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteamTools
Operation:writeName:InstallLocation
Value:
C:\Program Files\SteamTools
(PID) Process:(3896) SteamTools Setup New.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteamTools
Operation:writeName:DisplayIcon
Value:
C:\Program Files\SteamTools\SteamTools.exe,0
(PID) Process:(3896) SteamTools Setup New.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteamTools
Operation:writeName:NoModify
Value:
1
(PID) Process:(3896) SteamTools Setup New.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteamTools
Operation:writeName:NoRepair
Value:
1
(PID) Process:(3896) SteamTools Setup New.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\SteamTools
Operation:writeName:Language
Value:
1033
(PID) Process:(5868) SteamTools.exeKey:HKEY_CURRENT_USER\SOFTWARE\Valve\Steamtools
Operation:writeName:fScreenIndex
Value:
0
(PID) Process:(5868) SteamTools.exeKey:HKEY_CURRENT_USER\SOFTWARE\Valve\Steamtools
Operation:writeName:fPosition
Value:
@Point(610 100)
Executable files
19
Suspicious files
4
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
3896SteamTools Setup New.exeC:\Users\admin\AppData\Local\Temp\nsbB8C5.tmp\modern-header.bmpimage
MD5:F1928D020EBD3BF2C54FB46B3253F2A9
SHA256:A928EDA70352B4BF7FE85EBEE91B1CA819AD78A4DBA4547B95A1A3FFF51F89DD
3896SteamTools Setup New.exeC:\Users\admin\AppData\Local\Temp\nsbB8C5.tmp\System.dllexecutable
MD5:E74573CE106DD95B148BB8B1EF8E3418
SHA256:D12BC87BF84C51C13F0877949BCD719C5B90D9DF8658A2F8036DDC262CB0D87B
3896SteamTools Setup New.exeC:\Program Files\SteamTools\vcruntime140.dllexecutable
MD5:0C583614EB8FFB4C8C2D9E9880220F1D
SHA256:6CADB4FEF773C23B511ACC8B715A084815C6E41DD8C694BC70090A97B3B03FB9
3896SteamTools Setup New.exeC:\Program Files\SteamTools\SteamTools.exeexecutable
MD5:E45BFB5EDCC03451A85BC505298FBC16
SHA256:7AFCB8D488F34E284DEEF1559DBC0D46D1BD68E226928E5B583169A1FD275842
3896SteamTools Setup New.exeC:\Users\admin\AppData\Local\Temp\nslB8B4.tmp
MD5:
SHA256:
3896SteamTools Setup New.exeC:\Program Files\SteamTools\Core.dllexecutable
MD5:4BE563C65FF66351F94035D6B5624CC7
SHA256:C0EFDB388A3D1AAC1507B3DAABE63E7A3283AF81B1D1C04FDD1CA9F837882D51
3896SteamTools Setup New.exeC:\Program Files\SteamTools\Qt5Gui.dllexecutable
MD5:47307A1E2E9987AB422F09771D590FF1
SHA256:5E7D2D41B8B92A880E83B8CC0CA173F5DA61218604186196787EE1600956BE1E
3896SteamTools Setup New.exeC:\Program Files\SteamTools\Qt5Svg.dllexecutable
MD5:03761F923E52A7269A6E3A7452F6BE93
SHA256:7348CFC6444438B8845FB3F59381227325D40CA2187D463E82FC7B8E93E38DB5
3896SteamTools Setup New.exeC:\Program Files\SteamTools\Qt5Network.dllexecutable
MD5:3569693D5BAE82854DE1D88F86C33184
SHA256:4EF341AE9302E793878020F0740B09B0F31CB380408A697F75C69FDBD20FC7A1
3896SteamTools Setup New.exeC:\Program Files\SteamTools\Qt5Widgets.dllexecutable
MD5:4CD1F8FDCD617932DB131C3688845EA8
SHA256:3788C669D4B645E5A576DE9FC77FCA776BF516D43C89143DC2CA28291BA14358
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
37
DNS requests
23
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.30:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.216.77.30:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5868
SteamTools.exe
GET
302
119.188.174.58:80
http://new-service.biliapi.net/picture/chatres/update/version2.txt
unknown
unknown
5868
SteamTools.exe
GET
200
8.133.135.83:80
http://stools.oss-cn-shanghai.aliyuncs.com/version2.txt
unknown
unknown
780
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
780
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.30:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.216.77.30:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
5496
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.159.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 23.216.77.30
  • 23.216.77.18
  • 23.216.77.26
  • 23.216.77.38
  • 23.216.77.41
  • 23.216.77.35
  • 23.216.77.37
  • 23.216.77.29
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
google.com
  • 142.250.185.174
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 20.190.159.68
  • 20.190.159.4
  • 20.190.159.73
  • 40.126.31.67
  • 20.190.159.75
  • 40.126.31.2
  • 40.126.31.3
  • 20.190.159.128
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
steamtools.info
unknown
new-service.biliapi.net
  • 119.188.174.58
  • 59.83.212.226
  • 116.196.150.249
  • 122.188.45.51
  • 60.221.17.73
  • 122.188.44.139
  • 119.188.174.59
  • 202.97.231.78
  • 123.6.40.124
  • 101.72.254.91
  • 122.188.45.182
  • 122.188.45.140
unknown
stools.oss-cn-shanghai.aliyuncs.com
  • 8.133.135.83
unknown

Threats

PID
Process
Class
Message
5868
SteamTools.exe
Misc activity
INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0)
2196
svchost.exe
Misc activity
ET INFO DNS Query to Alibaba Cloud CDN Domain (aliyuncs .com)
5868
SteamTools.exe
Misc activity
INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0)
No debug info