familyghostpulseconfidencehigh
SHA-256: 9410374bb9ccfb1a8a15aac5a038202e1ce7fb841a5128edf4d348d82db760c3

ghostpulse: 9410374b — Steam Error Reporter SFX twin (confirmed byte-identical inner payload to 642ecaab)

Executive Summary

7-Zip SFX dropper containing the legitimate Valve Steam Error Reporter (steamerrorreporter64.exe / Vect_P16.exe, MSVC 14.29, Mar 2024) bundled with encrypted companion files. The inner executable is byte-identical to the payload extracted from sample 642ecaab — confirmed by SHA-256 0a0c09753b5103e86e32c2d8086dd1399f0d97a00e1525ec9c390067cdb242ba. Only the outer 7-Zip SFX wrapper differs. The actual malicious logic is expected to reside in the 6.8 MB encrypted sidecar network-mon.map, decrypted at runtime by the carrier. Static-only analysis; CAPE skipped (no Windows guest). ^[dynamic-analysis.md]

What It Is

  • Outer wrapper: PE32 executable (GUI) Intel 80386, Oleg Scherbakov's 7-Zip SFX mod v1.4.0 beta (build 1795, Jun 27 2010), MSVC 8.0 linker. ^[file.txt] ^[exiftool.json] ^[rabin2-info.txt]
  • Archive: LZMA-compressed 7z solid archive at offset 0x2df47 (188,231 bytes into the file), BCJ filter, solid blocks. ^[binwalk.txt]
  • Inner payload: Vect_P16.exe — PE32+ x64, compiled Wed Mar 6 20:27:29 2024, MSVC 14.29 (VS 2019+), PDB path c:\buildslave\steam_rel_client_hotfix_win64\build\src\steamerrorreporter\win64\Release\steamerrorreporter64.pdb. ^[rabin2-info.txt:Vect_P16.exe]
  • Runtime DLLs: tier0_s64.dll (DigiCert-signed, CN=Valve Corporation), vstdlib_s64.dll, msvcp_win.dll, ucrtbase.dll — all standard Steam/Source Engine runtime. ^[terminal:file-verify]
  • Sidecar files: network-mon.map (6.8 MB, entropy 7.95/8, no recognizable magic — encrypted payload), process.xml (26.8 KB, same obfuscation). ^[terminal:entropy-check]
  • Signing: Outer SFX unsigned (signed: false). Inner Vect_P16.exe reports signed: true via rabin2, but the security directory raw bytes at offset 0x95800 do not contain a valid WIN_CERTIFICATE structure (length field 0x000c1a32, revision 0x0c32, type 0x000c — all garbage), indicating either certificate stripping or a corrupted/junk security overlay. tier0_s64.dll carries a valid DigiCert code-signing cert. ^[terminal:cert-parse] ^[rabin2-info.txt]

How It Works

  1. SFX extraction: 7-Zip SFX silently extracts to %TEMP% (InstallPath="%TEMP%", Progress="no", GUIFlags="8"). ^[strings.txt:371-373] ^[sfx-config.json]
  2. Execution: SFX config RunProgram="\"%%T\\Vect_P16.exe\"" launches the inner payload. ^[strings.txt:381] ^[sfx-config.json]
  3. Masquerade: Vect_P16.exe presents as Valve's crash reporter — VS_VERSIONINFO reads FileDescription: steamerrorreporter.exe, CompanyName: Valve Corporation, LegalCopyright: Copyright (C) 2010 Valve Corporation. ^[exiftool.json]
  4. Companion-file loading: The inner binary imports CreateFileW, ReadFile, MapViewOfFile, and full WININET.dll HTTP surface (11 imports: InternetOpenW, InternetConnectW, InternetReadFile, HttpOpenRequestW, HttpSendRequestW, etc.). ^[terminal:imports]
  5. Payload decryption: No static C2 URLs or payload decryption routines visible in Vect_P16.exe strings. The 6.8 MB network-mon.map is the only plausible payload source. The companion file begins with ASCII-like bytes (eiewiiekbteaeiha...) but no recognizable magic or XOR key recovered in static analysis. ^[terminal:sidecar-magic]

Decompiled Behavior

Ghidra / radare2 analysis of Vect_P16.exe (SHA-256 0a0c0975...) confirms it is a legitimate Valve Steam Error Reporter binary, not custom malware. Entry point 0x140008d40 initializes CRT (fcn.140008e9c), sets up exception handling, and enters the main reporter loop. There are no suspicious API resolutions, no VirtualAlloc/WriteProcessMemory patterns, and no process-injection stubs. The binary's only "malicious" behavior is its role as a carrier: it will read network-mon.map and process.xml from its working directory at runtime (standard behavior for Steam crash reporting — it reads crash dumps and config files), but in this distribution those files are attacker-controlled encrypted payloads. ^[r2:entry0]

This is a hijack-execution-flow technique (T1574) rather than a modified binary.

C2 Infrastructure

No static C2 recovered. The encrypted network-mon.map and process.xml sidecars are the only payload/config carriers. WININET HTTP imports suggest web-based C2 once decrypted. No hardcoded domains, IPs, mutex names, or pipes observed in the inner binary. ^[terminal:strings-network]

Interesting Tidbits

  • Confirmed twin: Inner Vect_P16.exe SHA-256 0a0c09753b5103e86e32c2d8086dd1399f0d97a00e1525ec9c390067cdb242ba is byte-identical to the payload from 642ecaab (INUS.exe). The builder is reusing the same inner carrier across multiple SFX wrappers. ^[terminal:sha256-verify]
  • Security directory anomaly: Vect_P16.exe reports signed: true but the certificate blob is invalid/corrupted. This may be an artefact of the repackaging process (SFX builder stripping or corrupting the security overlay). tier0_s64.dll retains its valid DigiCert signature.
  • Resource section: .rsrc in Vect_P16.exe is 302 KB (entropy 5.61) — legitimate Steam icons, manifests, and version info. No anomalous RT_RCDATA blobs.
  • capa/floss failure: Both tools errored during triage (missing signatures for capa, CLI parse error for floss). ^[capa.txt] ^[floss.txt]

How To Mess With It (Homelab Replication)

  1. Download the legitimate Steam Error Reporter from a Steam client install (path: Steam\bin\steamerrorreporter64.exe).
  2. Build a 7-Zip SFX archive with the 7-Zip SFX mod builder, adding the reporter + tier0_s64.dll + vstdlib_s64.dll + a large encrypted companion file.
  3. Configure RunProgram to launch the reporter post-extraction.
  4. The reporter will attempt to read companion files from its working directory — use this as a legitimate-appearing loader.
  5. For detection, hunt for the combination: 7-Zip SFX wrapper + steamerrorreporter64.exe inner payload + .map/.xml sidecars with entropy >7.9.

Deployable Signatures

YARA Rule

rule GhostPulse_SteamErrorReporter_SFX {
    meta:
        description = "GhostPulse cluster: 7-Zip SFX dropper with Steam Error Reporter inner payload"
        author = "PacketPursuit"
        reference = "/intel/analyses/9410374bb9ccfb1a8a15aac5a038202e1ce7fb841a5128edf4d348d82db760c3.html"
    strings:
        $sfx_1 = "7-Zip SFX" ascii wide
        $sfx_2 = "Oleg Scherbakov" ascii wide
        $sfx_3 = "RunProgram=\"%%T\\" ascii wide
        $steam_1 = "steamerrorreporter.exe" ascii wide
        $steam_2 = "Valve Corporation" ascii wide
        $steam_3 = "SteamErrorReporter process started" ascii wide
        $sidecar_1 = "network-mon.map" ascii wide
        $sidecar_2 = "process.xml" ascii wide
    condition:
        uint16(0) == 0x5a4d and
        filesize > 5MB and
        ($sfx_1 or $sfx_2) and
        2 of ($steam_*) and
        1 of ($sidecar_*)
}

Behavioral Hunt Query (Sigma-style)

title: GhostPulse Steam Error Reporter SFX Execution
detection:
    selection:
        - Image|endswith: '\\Vect_P16.exe'
        - CommandLine|contains: 'Vect_P16.exe'
    selection_sidecar:
        - TargetFilename|contains: 'network-mon.map'
        - TargetFilename|contains: 'process.xml'
    condition: selection or selection_sidecar

IOC List

Indicator Value Context
SHA-256 (outer) 9410374bb9ccfb1a8a15aac5a038202e1ce7fb841a5128edf4d348d82db760c3 7-Zip SFX wrapper
SHA-256 (inner) 0a0c09753b5103e86e32c2d8086dd1399f0d97a00e1525ec9c390067cdb242ba Vect_P16.exe / steamerrorreporter64.exe
SHA-256 (sidecar) c232a5d6699de18ecfe6cb98b0c49ab756022cc3ca3f9ba336841b191194e899 tier0_s64.dll (legitimate, signed)
SHA-256 (sidecar) 4bb95ee0a76b851410072d36e21364ac84bffd859ff2c49457a2e47dc078e212 vstdlib_s64.dll (legitimate)
File size (outer) 7,379,902 bytes
SFX config RunProgram="\"%%T\\Vect_P16.exe\"", InstallPath="%TEMP%" Silent extraction + execution
Inner PDB c:\buildslave\steam_rel_client_hotfix_win64\build\src\steamerrorreporter\win64\Release\steamerrorreporter64.pdb Valve build path

Behavioral Fingerprint

A 7-Zip SFX archive (Oleg Scherbakov mod, v1.4.0 beta) extracts to %TEMP% and launches Vect_P16.exe, which is the legitimate Valve Steam Error Reporter binary (PDB steamerrorreporter\win64\Release\steamerrorreporter64.pdb). The binary is accompanied by tier0_s64.dll, vstdlib_s64.dll, and two encrypted companion files: network-mon.map (~6.8 MB, entropy ~7.95) and process.xml (~26 KB). The inner binary imports WININET.dll HTTP APIs but carries no hardcoded C2 URLs. The actual malicious payload is expected to be decrypted from network-mon.map at runtime and executed via the carrier's standard file-reading behavior.

Detection Signatures (ATT&CK)

Technique ID Evidence
User Execution: Malicious File T1204.002 SFX social-engineering lure
Obfuscated Files or Information T1027.002 network-mon.map (entropy 7.95/8, no magic)
Hijack Execution Flow T1574.001 / T1574.002 Legitimate signed Steam Error Reporter loads encrypted companion payload
Application Layer Protocol: Web Protocols T1071.001 WININET.dll HTTP surface (11 imports)
Ingress Tool Transfer T1105 SFX self-extracts 7 files to %TEMP%

References

  • Sample 642ecaab — confirmed twin with identical inner payload and sidecar files. ^[/intel/analyses/642ecaab44fc4a09fce541bc7c639e77a5f9aa5ef28ca87b595df3c87afb12f8.html]
  • ghostpulse — entity page for family cluster
  • steam-error-reporter-masquerade — technique page for this masquerade pattern
  • companion-file-encrypted-payload — technique page for sidecar payload staging
  • 7z-sfx-dropper — technique page for the SFX dropper pattern

Provenance

  • Static analysis conducted on pp-hermes (Lab1BU, <lan>)
  • Tools: file (file.txt), exiftool (exiftool.json), pefile (pefile.txt), strings (strings.txt), rabin2 (rabin2-info.txt), 7z (archive extraction), openssl pkcs7 (certificate inspection), Python 3.11 with pefile and math (entropy calculation)
  • Inner payload extracted via 7z x at offset 188,231; verified SHA-256 against known twin 642ecaab
  • CAPE skipped — no Windows guest available. All behavior inferred from static artifacts. ^[dynamic-analysis.md]