familyhijackloaderconfidencelow
SHA-256: 642ecaab44fc4a09fce541bc7c639e77a5f9aa5ef28ca87b595df3c87afb12f8

642ecaab — 7-Zip SFX Dropper with Steam Error Reporter Masquerade

Build / RE

Outer wrapper is a 7-Zip SFX archive built with Oleg Scherbakov's modified SFX module v1.4.0 beta (7-Zip 9.15 beta, 27 Jun 2010). ^[file.txt] ^[binwalk.txt] ^[rabin2-info.txt] The SFX config block in .rsrc sets InstallPath="%TEMP%" and RunProgram="%%T\\Vect_P16.exe", causing silent extraction to the temp directory followed by execution of the inner payload. ^[strings.txt:370-382] ^[sfx-config.json]

The archive contains seven files:

  • Vect_P16.exe — PE32+ x64, compiled Wed Mar 6 20:27:29 2024, MSVC toolchain. ^[rabin2:Vect_P16.exe]
  • tier0_s64.dll, vstdlib_s64.dll — Valve Steam runtime libraries (signed, same compile date). ^[rabin2:tier0_s64.dll]
  • msvcp_win.dll, ucrtbase.dll — Microsoft CRT.
  • network-mon.map — 6.7 MB companion file, entropy 0.99/8, no recognizable magic. Encrypted payload. ^[terminal:entropy-check]
  • process.xml — 26 KB companion file, same obfuscation/encoding pattern.

Vect_P16.exe imports from KERNEL32.dll (110), tier0_s64.dll (13), vstdlib_s64.dll (13), PSAPI.DLL (2), and WININET.dll (11) — covering full HTTP client surface (open, connect, send, read, crack URL, query info, add headers). ^[terminal:imports] The binary reports signed: true per rabin2 and carries a PDB path pointing to c:\buildslave\steam_rel_client_hotfix_win64\build\src\steamerrorreporter\win64\Release\steamerrorreporter64.pdb, indicating it is the legitimate Valve Steam Error Reporter binary repurposed as a loader. ^[rabin2:Vect_P16.exe] RT_ICON (9 entries), RT_VERSION, and RT_MANIFEST resources are present. ^[terminal:resources]

No packing, no anti-debug, no VM detection in either layer. The threat is companion-file payload staging: the 6.7 MB network-mon.map is almost certainly an encrypted payload that the inner binary decrypts and executes at runtime.

capa.txt and floss.txt are unusable — both tools errored. ^[capa.txt] ^[floss.txt]

Deploy / ATT&CK

Static-only inference — CAPE skipped (no Windows guest). ^[dynamic-analysis.md]

Technique ID Evidence
User Execution: Malicious File T1204.002 SFX social-engineering lure (INUS.exe)
Obfuscated Files or Information T1027.002 network-mon.map (entropy 0.99/8, no magic)
Hijack Execution Flow T1574.001 / T1574.002 Legitimate signed Steam Error Reporter loads encrypted companion payload
Application Layer Protocol: Web Protocols T1071.001 WININET.dll HTTP surface (11 imports)
Ingress Tool Transfer T1105 SFX self-extracts 7 files to %TEMP%

Persistence: None observable statically.

C2: WININET HTTP client surface present, but no hardcoded URLs recovered from Vect_P16.exe strings. C2 config likely lives inside the encrypted network-mon.map or process.xml companion files.

Attribution: No linguistic or infrastructure clues. Steam Error Reporter masquerade (compile Mar 2024) and 7-Zip SFX packaging suggest a recent campaign. The OpenCTI labels cloud55file-cc, vidar, and snappyclient are contested for this sample — it does not match the Go-based ACR stealer / Vidar clusters (MSVC C++ x64, not Go; 7-Zip SFX, not signed PE dropper). Only the hijackloader label aligns with observed behavior.

IOCs

Indicator Value Context
SHA-256 (outer) 642ecaab44fc4a09fce541bc7c639e77a5f9aa5ef28ca87b595df3c87afb12f8 7-Zip SFX wrapper
SHA-256 (inner) 0a0c09753b5103e86e32c2d8086dd1399f0d97a00e1525ec9c390067cdb242ba Vect_P16.exe
File size (outer) 7,212,968 bytes
SFX config RunProgram="%%T\\Vect_P16.exe", InstallPath="%TEMP%" Silent extraction + execution