9410374bb9ccfb1a8a15aac5a038202e1ce7fb841a5128edf4d348d82db760c3ghostpulse: 9410374b — Steam Error Reporter SFX twin (confirmed byte-identical inner payload to 642ecaab)
Executive Summary
7-Zip SFX dropper containing the legitimate Valve Steam Error Reporter (steamerrorreporter64.exe / Vect_P16.exe, MSVC 14.29, Mar 2024) bundled with encrypted companion files. The inner executable is byte-identical to the payload extracted from sample 642ecaab — confirmed by SHA-256 0a0c09753b5103e86e32c2d8086dd1399f0d97a00e1525ec9c390067cdb242ba. Only the outer 7-Zip SFX wrapper differs. The actual malicious logic is expected to reside in the 6.8 MB encrypted sidecar network-mon.map, decrypted at runtime by the carrier. Static-only analysis; CAPE skipped (no Windows guest). ^[dynamic-analysis.md]
What It Is
- Outer wrapper: PE32 executable (GUI) Intel 80386, Oleg Scherbakov's 7-Zip SFX mod v1.4.0 beta (build 1795, Jun 27 2010), MSVC 8.0 linker. ^[file.txt] ^[exiftool.json] ^[rabin2-info.txt]
- Archive: LZMA-compressed 7z solid archive at offset
0x2df47(188,231 bytes into the file), BCJ filter, solid blocks. ^[binwalk.txt] - Inner payload:
Vect_P16.exe— PE32+ x64, compiled Wed Mar 6 20:27:29 2024, MSVC 14.29 (VS 2019+), PDB pathc:\buildslave\steam_rel_client_hotfix_win64\build\src\steamerrorreporter\win64\Release\steamerrorreporter64.pdb. ^[rabin2-info.txt:Vect_P16.exe] - Runtime DLLs:
tier0_s64.dll(DigiCert-signed, CN=Valve Corporation),vstdlib_s64.dll,msvcp_win.dll,ucrtbase.dll— all standard Steam/Source Engine runtime. ^[terminal:file-verify] - Sidecar files:
network-mon.map(6.8 MB, entropy 7.95/8, no recognizable magic — encrypted payload),process.xml(26.8 KB, same obfuscation). ^[terminal:entropy-check] - Signing: Outer SFX unsigned (
signed: false). InnerVect_P16.exereportssigned: truevia rabin2, but the security directory raw bytes at offset0x95800do not contain a valid WIN_CERTIFICATE structure (length field0x000c1a32, revision0x0c32, type0x000c— all garbage), indicating either certificate stripping or a corrupted/junk security overlay.tier0_s64.dllcarries a valid DigiCert code-signing cert. ^[terminal:cert-parse] ^[rabin2-info.txt]
How It Works
- SFX extraction: 7-Zip SFX silently extracts to
%TEMP%(InstallPath="%TEMP%",Progress="no",GUIFlags="8"). ^[strings.txt:371-373] ^[sfx-config.json] - Execution: SFX config
RunProgram="\"%%T\\Vect_P16.exe\""launches the inner payload. ^[strings.txt:381] ^[sfx-config.json] - Masquerade:
Vect_P16.exepresents as Valve's crash reporter — VS_VERSIONINFO readsFileDescription: steamerrorreporter.exe,CompanyName: Valve Corporation,LegalCopyright: Copyright (C) 2010 Valve Corporation. ^[exiftool.json] - Companion-file loading: The inner binary imports
CreateFileW,ReadFile,MapViewOfFile, and full WININET.dll HTTP surface (11 imports:InternetOpenW,InternetConnectW,InternetReadFile,HttpOpenRequestW,HttpSendRequestW, etc.). ^[terminal:imports] - Payload decryption: No static C2 URLs or payload decryption routines visible in
Vect_P16.exestrings. The 6.8 MBnetwork-mon.mapis the only plausible payload source. The companion file begins with ASCII-like bytes (eiewiiekbteaeiha...) but no recognizable magic or XOR key recovered in static analysis. ^[terminal:sidecar-magic]
Decompiled Behavior
Ghidra / radare2 analysis of Vect_P16.exe (SHA-256 0a0c0975...) confirms it is a legitimate Valve Steam Error Reporter binary, not custom malware. Entry point 0x140008d40 initializes CRT (fcn.140008e9c), sets up exception handling, and enters the main reporter loop. There are no suspicious API resolutions, no VirtualAlloc/WriteProcessMemory patterns, and no process-injection stubs. The binary's only "malicious" behavior is its role as a carrier: it will read network-mon.map and process.xml from its working directory at runtime (standard behavior for Steam crash reporting — it reads crash dumps and config files), but in this distribution those files are attacker-controlled encrypted payloads. ^[r2:entry0]
This is a hijack-execution-flow technique (T1574) rather than a modified binary.
C2 Infrastructure
No static C2 recovered. The encrypted network-mon.map and process.xml sidecars are the only payload/config carriers. WININET HTTP imports suggest web-based C2 once decrypted. No hardcoded domains, IPs, mutex names, or pipes observed in the inner binary. ^[terminal:strings-network]
Interesting Tidbits
- Confirmed twin: Inner
Vect_P16.exeSHA-2560a0c09753b5103e86e32c2d8086dd1399f0d97a00e1525ec9c390067cdb242bais byte-identical to the payload from642ecaab(INUS.exe). The builder is reusing the same inner carrier across multiple SFX wrappers. ^[terminal:sha256-verify] - Security directory anomaly:
Vect_P16.exereportssigned: truebut the certificate blob is invalid/corrupted. This may be an artefact of the repackaging process (SFX builder stripping or corrupting the security overlay).tier0_s64.dllretains its valid DigiCert signature. - Resource section:
.rsrcinVect_P16.exeis 302 KB (entropy 5.61) — legitimate Steam icons, manifests, and version info. No anomalous RT_RCDATA blobs. - capa/floss failure: Both tools errored during triage (missing signatures for capa, CLI parse error for floss). ^[capa.txt] ^[floss.txt]
How To Mess With It (Homelab Replication)
- Download the legitimate Steam Error Reporter from a Steam client install (path:
Steam\bin\steamerrorreporter64.exe). - Build a 7-Zip SFX archive with the 7-Zip SFX mod builder, adding the reporter +
tier0_s64.dll+vstdlib_s64.dll+ a large encrypted companion file. - Configure
RunProgramto launch the reporter post-extraction. - The reporter will attempt to read companion files from its working directory — use this as a legitimate-appearing loader.
- For detection, hunt for the combination: 7-Zip SFX wrapper +
steamerrorreporter64.exeinner payload +.map/.xmlsidecars with entropy >7.9.
Deployable Signatures
YARA Rule
rule GhostPulse_SteamErrorReporter_SFX {
meta:
description = "GhostPulse cluster: 7-Zip SFX dropper with Steam Error Reporter inner payload"
author = "PacketPursuit"
reference = "/intel/analyses/9410374bb9ccfb1a8a15aac5a038202e1ce7fb841a5128edf4d348d82db760c3.html"
strings:
$sfx_1 = "7-Zip SFX" ascii wide
$sfx_2 = "Oleg Scherbakov" ascii wide
$sfx_3 = "RunProgram=\"%%T\\" ascii wide
$steam_1 = "steamerrorreporter.exe" ascii wide
$steam_2 = "Valve Corporation" ascii wide
$steam_3 = "SteamErrorReporter process started" ascii wide
$sidecar_1 = "network-mon.map" ascii wide
$sidecar_2 = "process.xml" ascii wide
condition:
uint16(0) == 0x5a4d and
filesize > 5MB and
($sfx_1 or $sfx_2) and
2 of ($steam_*) and
1 of ($sidecar_*)
}
Behavioral Hunt Query (Sigma-style)
title: GhostPulse Steam Error Reporter SFX Execution
detection:
selection:
- Image|endswith: '\\Vect_P16.exe'
- CommandLine|contains: 'Vect_P16.exe'
selection_sidecar:
- TargetFilename|contains: 'network-mon.map'
- TargetFilename|contains: 'process.xml'
condition: selection or selection_sidecar
IOC List
| Indicator | Value | Context |
|---|---|---|
| SHA-256 (outer) | 9410374bb9ccfb1a8a15aac5a038202e1ce7fb841a5128edf4d348d82db760c3 |
7-Zip SFX wrapper |
| SHA-256 (inner) | 0a0c09753b5103e86e32c2d8086dd1399f0d97a00e1525ec9c390067cdb242ba |
Vect_P16.exe / steamerrorreporter64.exe |
| SHA-256 (sidecar) | c232a5d6699de18ecfe6cb98b0c49ab756022cc3ca3f9ba336841b191194e899 |
tier0_s64.dll (legitimate, signed) |
| SHA-256 (sidecar) | 4bb95ee0a76b851410072d36e21364ac84bffd859ff2c49457a2e47dc078e212 |
vstdlib_s64.dll (legitimate) |
| File size (outer) | 7,379,902 bytes | |
| SFX config | RunProgram="\"%%T\\Vect_P16.exe\"", InstallPath="%TEMP%" |
Silent extraction + execution |
| Inner PDB | c:\buildslave\steam_rel_client_hotfix_win64\build\src\steamerrorreporter\win64\Release\steamerrorreporter64.pdb |
Valve build path |
Behavioral Fingerprint
A 7-Zip SFX archive (Oleg Scherbakov mod, v1.4.0 beta) extracts to %TEMP% and launches Vect_P16.exe, which is the legitimate Valve Steam Error Reporter binary (PDB steamerrorreporter\win64\Release\steamerrorreporter64.pdb). The binary is accompanied by tier0_s64.dll, vstdlib_s64.dll, and two encrypted companion files: network-mon.map (~6.8 MB, entropy ~7.95) and process.xml (~26 KB). The inner binary imports WININET.dll HTTP APIs but carries no hardcoded C2 URLs. The actual malicious payload is expected to be decrypted from network-mon.map at runtime and executed via the carrier's standard file-reading behavior.
Detection Signatures (ATT&CK)
| Technique | ID | Evidence |
|---|---|---|
| User Execution: Malicious File | T1204.002 | SFX social-engineering lure |
| Obfuscated Files or Information | T1027.002 | network-mon.map (entropy 7.95/8, no magic) |
| Hijack Execution Flow | T1574.001 / T1574.002 | Legitimate signed Steam Error Reporter loads encrypted companion payload |
| Application Layer Protocol: Web Protocols | T1071.001 | WININET.dll HTTP surface (11 imports) |
| Ingress Tool Transfer | T1105 | SFX self-extracts 7 files to %TEMP% |
References
- Sample
642ecaab— confirmed twin with identical inner payload and sidecar files. ^[/intel/analyses/642ecaab44fc4a09fce541bc7c639e77a5f9aa5ef28ca87b595df3c87afb12f8.html] - ghostpulse — entity page for family cluster
- steam-error-reporter-masquerade — technique page for this masquerade pattern
- companion-file-encrypted-payload — technique page for sidecar payload staging
- 7z-sfx-dropper — technique page for the SFX dropper pattern
Provenance
- Static analysis conducted on
pp-hermes(Lab1BU, <lan>) - Tools:
file(file.txt),exiftool(exiftool.json),pefile(pefile.txt),strings(strings.txt),rabin2(rabin2-info.txt),7z(archive extraction),openssl pkcs7(certificate inspection), Python 3.11 withpefileandmath(entropy calculation) - Inner payload extracted via
7z xat offset 188,231; verified SHA-256 against known twin642ecaab - CAPE skipped — no Windows guest available. All behavior inferred from static artifacts. ^[dynamic-analysis.md]