642ecaab44fc4a09fce541bc7c639e77a5f9aa5ef28ca87b595df3c87afb12f8642ecaab — 7-Zip SFX Dropper with Steam Error Reporter Masquerade
Build / RE
Outer wrapper is a 7-Zip SFX archive built with Oleg Scherbakov's modified SFX module v1.4.0 beta (7-Zip 9.15 beta, 27 Jun 2010). ^[file.txt] ^[binwalk.txt] ^[rabin2-info.txt] The SFX config block in .rsrc sets InstallPath="%TEMP%" and RunProgram="%%T\\Vect_P16.exe", causing silent extraction to the temp directory followed by execution of the inner payload. ^[strings.txt:370-382] ^[sfx-config.json]
The archive contains seven files:
Vect_P16.exe— PE32+ x64, compiled Wed Mar 6 20:27:29 2024, MSVC toolchain. ^[rabin2:Vect_P16.exe]tier0_s64.dll,vstdlib_s64.dll— Valve Steam runtime libraries (signed, same compile date). ^[rabin2:tier0_s64.dll]msvcp_win.dll,ucrtbase.dll— Microsoft CRT.network-mon.map— 6.7 MB companion file, entropy 0.99/8, no recognizable magic. Encrypted payload. ^[terminal:entropy-check]process.xml— 26 KB companion file, same obfuscation/encoding pattern.
Vect_P16.exe imports from KERNEL32.dll (110), tier0_s64.dll (13), vstdlib_s64.dll (13), PSAPI.DLL (2), and WININET.dll (11) — covering full HTTP client surface (open, connect, send, read, crack URL, query info, add headers). ^[terminal:imports] The binary reports signed: true per rabin2 and carries a PDB path pointing to c:\buildslave\steam_rel_client_hotfix_win64\build\src\steamerrorreporter\win64\Release\steamerrorreporter64.pdb, indicating it is the legitimate Valve Steam Error Reporter binary repurposed as a loader. ^[rabin2:Vect_P16.exe] RT_ICON (9 entries), RT_VERSION, and RT_MANIFEST resources are present. ^[terminal:resources]
No packing, no anti-debug, no VM detection in either layer. The threat is companion-file payload staging: the 6.7 MB network-mon.map is almost certainly an encrypted payload that the inner binary decrypts and executes at runtime.
capa.txt and floss.txt are unusable — both tools errored. ^[capa.txt] ^[floss.txt]
Deploy / ATT&CK
Static-only inference — CAPE skipped (no Windows guest). ^[dynamic-analysis.md]
| Technique | ID | Evidence |
|---|---|---|
| User Execution: Malicious File | T1204.002 | SFX social-engineering lure (INUS.exe) |
| Obfuscated Files or Information | T1027.002 | network-mon.map (entropy 0.99/8, no magic) |
| Hijack Execution Flow | T1574.001 / T1574.002 | Legitimate signed Steam Error Reporter loads encrypted companion payload |
| Application Layer Protocol: Web Protocols | T1071.001 | WININET.dll HTTP surface (11 imports) |
| Ingress Tool Transfer | T1105 | SFX self-extracts 7 files to %TEMP% |
Persistence: None observable statically.
C2: WININET HTTP client surface present, but no hardcoded URLs recovered from Vect_P16.exe strings. C2 config likely lives inside the encrypted network-mon.map or process.xml companion files.
Attribution: No linguistic or infrastructure clues. Steam Error Reporter masquerade (compile Mar 2024) and 7-Zip SFX packaging suggest a recent campaign. The OpenCTI labels cloud55file-cc, vidar, and snappyclient are contested for this sample — it does not match the Go-based ACR stealer / Vidar clusters (MSVC C++ x64, not Go; 7-Zip SFX, not signed PE dropper). Only the hijackloader label aligns with observed behavior.
IOCs
| Indicator | Value | Context |
|---|---|---|
| SHA-256 (outer) | 642ecaab44fc4a09fce541bc7c639e77a5f9aa5ef28ca87b595df3c87afb12f8 |
7-Zip SFX wrapper |
| SHA-256 (inner) | 0a0c09753b5103e86e32c2d8086dd1399f0d97a00e1525ec9c390067cdb242ba |
Vect_P16.exe |
| File size (outer) | 7,212,968 bytes | |
| SFX config | RunProgram="%%T\\Vect_P16.exe", InstallPath="%TEMP%" |
Silent extraction + execution |