| download: | /MWpIUDByWGY5cjArL0NWQUN1dHNBM1E1ZXdHcCtrWTdjMG9NUExwOHA0TExFaGFmQkxLdEhiK0I1MmdHbDVkL2t2QTdLe/EZNbWxValNHdnNYeUEvV1poWldMM2cxUjZ3aTBiTTNIT08zZ2FZZ1kxb0xKN2twclFwUGRSQVlIZ3lmVVduZnhpbnhxVz/dlaUJqdjRENnJPVDd0OGNibU9GcU1TaDhKWkdPYzZQM200bGl0NHJHN20zbjYyMWJzeWkwdWNMR2pMUkZ3UzNzemROUzE/zTUZJbHdraTNqLzNxUnZHbGFIVWNOVUErY2dCZDZncWNaUnhDR29WZVFxRkNLUkdoMkxDUHVVa2V1d1YxemlVVWtpL3Bw/NEJHbFVQTUErOTNEYWl3RVRHTjR0OUJiNjBldlFIeklORG1icWdya0RKMitkbEhmSzF6clhRVWd5dEd2ZmVMdFJFTUN2M/VNHaFZYOUduSSt2TDVqd3NUYnpQRVVpZGxrOWRmM3VVN0RWdWMwemFndDJFZUpvY2xqeTI1eHFqWXoyT3dPYUNVbU9lMX/Z4TmY0UDF1aDZxMTJSbEpxcEZSM3Arei9TRWNZSlFEYm15YTN2L2dseXVxMUI2Y1hrSUdXUDRJZVovM2FZSVhTb1dXL1F/OZmlrdjloSG1jVTZLQzZER2QvaTNEaFVCY0toQ0J6QXZGOUZTZ3JjZytTNTlMQW9tbFdZaElpVjEzblRQNm16VFhRPQ==/b24af86cfc60fe13 |
| Full analysis: | https://app.any.run/tasks/f0ec8eb6-f4d6-45fd-bc14-28edca3c62ae |
| Verdict: | Malicious activity |
| Analysis date: | December 02, 2023, 11:34:22 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 29A0D4F99B2AD92BC67D276C0C43D603 |
| SHA1: | 0308B646B70FA915C6FB1BC7DF5212940C7A938E |
| SHA256: | 874788B45DFC043289BA05387E83F27B4A046004A88A4C5EE7C073187FF65B9D |
| SSDEEP: | 24576:UDlF7nwnEfxR6faGpt9jE+JgTsjOa5vJI4xFauhIOhGHEuzZgoSjSoosl:UDLXL6CkbE+6ojOaJJlYEor2Sobl |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2016:07:25 02:55:51+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 25088 |
| InitializedDataSize: | 141824 |
| UninitializedDataSize: | 2048 |
| EntryPoint: | 0x33b6 |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.10.91.91 |
| ProductVersionNumber: | 2.10.91.91 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Bulgarian |
| CharacterSet: | Windows, Cyrillic |
| FileDescription: | Steam |
| FileVersion: | 2.10.91.91 |
| LegalCopyright: | © Valve Corporation |
| ProductName: | Steam |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 600 | "C:\Program Files\Steam\steam.exe" | C:\Program Files\Steam\Steam.exe | explorer.exe | ||||||||||||
User: admin Company: Valve Corporation Integrity Level: MEDIUM Description: Steam Client Bootstrapper Exit code: 0 Version: 06.35.19.37 Modules
| |||||||||||||||
| 1936 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2184 | "C:\Program Files\Steam\bin\steamservice.exe" /Install | C:\Program Files\Steam\bin\steamservice.exe | — | ns8D62.tmp | |||||||||||
User: admin Company: Valve Corporation Integrity Level: HIGH Description: Steam Client Service Exit code: 0 Version: 06.35.19.37 Modules
| |||||||||||||||
| 2620 | "C:\Users\admin\AppData\Local\Temp\nss6920.tmp\ns8D62.tmp" "C:\Program Files\Steam\bin\steamservice.exe" /Install | C:\Users\admin\AppData\Local\Temp\nss6920.tmp\ns8D62.tmp | — | b24af86cfc60fe13.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3048 | "C:\Users\admin\AppData\Local\Temp\b24af86cfc60fe13.exe" | C:\Users\admin\AppData\Local\Temp\b24af86cfc60fe13.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Steam Exit code: 0 Version: 2.10.91.91 Modules
| |||||||||||||||
| 3476 | "C:\Users\admin\AppData\Local\Temp\b24af86cfc60fe13.exe" | C:\Users\admin\AppData\Local\Temp\b24af86cfc60fe13.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Steam Exit code: 3221226540 Version: 2.10.91.91 Modules
| |||||||||||||||
| (PID) Process: | (2184) steamservice.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\Steam Client Service |
| Operation: | write | Name: | EventMessageFile |
Value: C:\Program Files\Common Files\Steam\SteamService.exe | |||
| (PID) Process: | (2184) steamservice.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\Steam Client Service |
| Operation: | write | Name: | TypesSupported |
Value: 7 | |||
| (PID) Process: | (2184) steamservice.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Steam |
| Operation: | write | Name: | InstallPath |
Value: C:\Program Files\Steam | |||
| (PID) Process: | (3048) b24af86cfc60fe13.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Steam |
| Operation: | write | Name: | InstallPath |
Value: C:\Program Files\Steam | |||
| (PID) Process: | (3048) b24af86cfc60fe13.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Valve\SteamService |
| Operation: | write | Name: | installpath_default |
Value: C:\Program Files\Steam | |||
| (PID) Process: | (600) Steam.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Steam |
| Operation: | write | Name: | SteamPID |
Value: 0 | |||
| (PID) Process: | (3048) b24af86cfc60fe13.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager |
| Operation: | write | Name: | PendingFileRenameOperations |
Value: \??\C:\Users\admin\AppData\Local\Temp\nss6920.tmp\nsProcess.dll | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3048 | b24af86cfc60fe13.exe | C:\Users\admin\AppData\Local\Temp\nss6920.tmp\System.dll | executable | |
MD5:A4DD044BCD94E9B3370CCF095B31F896 | SHA256:2E226715419A5882E2E14278940EE8EF0AA648A3EF7AF5B3DC252674111962BC | |||
| 3048 | b24af86cfc60fe13.exe | C:\Users\admin\AppData\Local\Temp\nss6920.tmp\modern-wizard.bmp | image | |
MD5:3614A4BE6B610F1DAF6C801574F161FE | SHA256:16E0EDC9F47E6E95A9BCAD15ADBDC46BE774FBCD045DD526FC16FC38FDC8D49B | |||
| 3048 | b24af86cfc60fe13.exe | C:\Users\admin\AppData\Local\Temp\nss6920.tmp\modern-header.bmp | image | |
MD5:DA3486D12BB4C8AEC16BD9E0D363D23F | SHA256:D93B76D51BD2214FA6E999C1BF70B4AFF5165A6542F9B9B2A92B5672601F4624 | |||
| 3048 | b24af86cfc60fe13.exe | C:\Program Files\Steam\bin\SteamService.exe | executable | |
MD5:E5E2E9ACF1483A87091221E00F0C534F | SHA256:BCFB4738253DEC31D7FB7A85F0AD8B0177DEAA2A7C6F3FD06A249177E4A65D5C | |||
| 3048 | b24af86cfc60fe13.exe | C:\Program Files\Steam\public\steambootstrapper_brazilian.txt | text | |
MD5:E1B0395FE69A012A6E573808FB600E24 | SHA256:CFB781BCA316850451FDA2163DA63715F7DB4FAAF1B3DE8CC2623D7AA0608925 | |||
| 3048 | b24af86cfc60fe13.exe | C:\Program Files\Steam\public\steambootstrapper_danish.txt | text | |
MD5:59AE5BE97B28CD16CD6970B7B26E78D4 | SHA256:B225151CF895541617E06A8C3A17386DCBE9B233A9F3DEB15E7FE6485A71089E | |||
| 3048 | b24af86cfc60fe13.exe | C:\Program Files\Steam\public\steambootstrapper_czech.txt | text | |
MD5:602A9B679F1E3320B9EAEE8646582BF6 | SHA256:F0C8E2DA7B2C58455A7CC5931E67D6B94956E1B7FE4763035BA925862FAA40E2 | |||
| 3048 | b24af86cfc60fe13.exe | C:\Program Files\Steam\public\steambootstrapper_finnish.txt | text | |
MD5:5455038252DDECCC5400B83F00ED5A01 | SHA256:5BB508DA6836273D0F0F10971A652380BADAD4EF1C790F3DF72B36FFC8EF847B | |||
| 3048 | b24af86cfc60fe13.exe | C:\Program Files\Steam\public\steambootstrapper_dutch.txt | text | |
MD5:F7A5553D4A03E1354708DB95B19DE909 | SHA256:06FEE861EEF6B7A88513FEBF2216EC3FE3274E548D327E7F81F0FD69222E46EC | |||
| 3048 | b24af86cfc60fe13.exe | C:\Program Files\Steam\public\steambootstrapper_english.txt | text | |
MD5:E2BC173918FE612294E01C51C1199616 | SHA256:8D02381A1EFBF26FFAB2C08A0E96C1E925CE9469241798A44F136961B5D4CFBE | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
600 | Steam.exe | GET | 200 | 193.108.153.14:80 | http://media.steampowered.com/client/steam_client_win32 | unknown | text | 4.34 Kb | unknown |
600 | Steam.exe | GET | 200 | 193.108.153.14:80 | http://media.steampowered.com/client/tenfoot_dicts_all.zip.3a6cb3db75398c509bdc6e389408b6951017494b | unknown | binary | 11.7 Mb | unknown |
600 | Steam.exe | GET | 200 | 193.108.153.14:80 | http://media.steampowered.com/client/tenfoot_misc_all.zip.a49df66ba6bd900ed2c58bb4a9a578752f73f511 | unknown | binary | 12.5 Mb | unknown |
600 | Steam.exe | GET | 200 | 193.108.153.14:80 | http://media.steampowered.com/client/tenfoot_fonts_all.zip.vz.e19674422bc376becd7bf4a73b4b52eefc34c7fe_12075477 | unknown | binary | 11.5 Mb | unknown |
600 | Steam.exe | GET | 200 | 193.108.153.14:80 | http://media.steampowered.com/client/tenfoot_sounds_all.zip.vz.3a674120cadd742865159e85dd3ec75b7dcc748c_1226636 | unknown | binary | 1.17 Mb | unknown |
600 | Steam.exe | GET | 200 | 193.108.153.14:80 | http://media.steampowered.com/client/tenfoot_ambientsounds_all.zip.c8342205c2cdfec5329ec8ec2905ddaa33be3cb8 | unknown | text | 7.60 Mb | unknown |
600 | Steam.exe | GET | — | 193.108.153.14:80 | http://media.steampowered.com/client/tenfoot_images_all.zip.vz.2bb2e0fd7778b60915d496578aa4722e1db8c58f_32706663 | unknown | — | — | unknown |
600 | Steam.exe | GET | 200 | 193.108.153.14:80 | http://media.steampowered.com/client/tenfoot_all.zip.vz.1fa19c9ff52876f8b9b9fa8cb4d5b210566dd699_2379523 | unknown | binary | 2.27 Mb | unknown |
600 | Steam.exe | GET | — | 193.108.153.14:80 | http://media.steampowered.com/client/steamui_websrc_all.zip.vz.142c9c94011dddaa0550ce0016d47a703fe6ffc3_23696493 | unknown | — | — | unknown |
600 | Steam.exe | GET | 200 | 193.108.153.14:80 | http://media.steampowered.com/client/resources_all.zip.vz.5b0960bde976b6339e7746a9d7d9e6bddb8ab6b1_2865754 | unknown | binary | 2.73 Mb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
600 | Steam.exe | 193.108.153.14:80 | media.steampowered.com | Akamai International B.V. | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
media.steampowered.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
600 | Steam.exe | Potential Corporate Privacy Violation | ET USER_AGENTS Steam HTTP Client User-Agent |