Summary | ZeroBOX

SteamWebHelper.exe

Malicious Library OS Processor Check PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6402 Oct. 8, 2021, 11:19 a.m. Oct. 8, 2021, 11:36 a.m.
Size 666.4KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 2db0b5a09292133e794322cb14639b2c
SHA256 fb4e1ee6f7fb1b22dd7b4f011ffadab81337cfe2d8171219b49df67e814ce5ef
CRC32 8EE72B7F
ssdeep 12288:8zxzTDWikLSb4NS7ET+tG1XbHaawAphVGc+rxanaDN7OjeQ1:6DWHSb4Nhh6iVGc+rxanSOyC
PDB Path D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • OS_Processor_Check_Zero - OS Processor Check
  • Malicious_Library_Zero - Malicious_Library

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

pdb_path D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb
section .didat
resource name PNG
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2236
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x734c2000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2236
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73203000
process_handle: 0xffffffff
1 0 0
file C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SteamWebHelper.exe
file C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SteamWebHelper.exe
section {u'size_of_data': u'0x0000e200', u'virtual_address': u'0x00063000', u'entropy': 6.802679828750322, u'name': u'.rsrc', u'virtual_size': u'0x0000e038'} entropy 6.80267982875 description A section with a high entropy has been found
file C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SteamWebHelper.exe
Bkav W32.AIDetect.malware2
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Razy.931651
FireEye Generic.mg.2db0b5a09292133e
ALYac Gen:Variant.Razy.931651
Zillya Trojan.Agent.Win32.2205396
Sangfor Suspicious.Win32.Save.a
Cybereason malicious.092921
Arcabit Trojan.Razy.DE3743
ESET-NOD32 a variant of Win32/GenKryptik.FKNU
APEX Malicious
Kaspersky VHO:Trojan-Banker.Win32.ClipBanker.gen
BitDefender Gen:Variant.Razy.931651
Sophos Generic ML PUA (PUA)
F-Secure Heuristic.HEUR/AGEN.1119113
McAfee-GW-Edition BehavesLike.Win32.Generic.jc
Emsisoft Gen:Variant.Razy.931651 (B)
SentinelOne Static AI - Malicious SFX
Avira HEUR/AGEN.1119113
Microsoft VirTool:Win32/Pucrpt.A!MTB
GData Gen:Variant.Razy.931651
Cynet Malicious (score: 100)
MAX malware (ai score=84)
VBA32 BScope.Trojan.Wacatac
eGambit Unsafe.AI_Score_91%
Fortinet W32/GenKryptik.FKJF!tr
BitDefenderTheta AI:Packer.E8B3264E1F