steam-error-reporter-masquerade
Abuse of Valve's legitimate Steam Error Reporter (steamerrorreporter64.exe) — a signed MSVC C++ x64 binary — by repackaging it inside a 7-Zip SFX archive alongside encrypted companion files. The binary's authentic PDB path (c:\buildslave\steam_rel_client_hotfix_win64\...), Valve certificate, and runtime DLL imports (tier0_s64.dll, vstdlib_s64.dll) make it appear benign during superficial triage, while the actual malicious logic resides in an encrypted companion file decrypted at runtime.
Static Fingerprint
- PE32+ x64, MSVC compiled (typically Mar 2024)
- PDB path:
steamerrorreporter\win64\Release\steamerrorreporter64.pdb - Authenticode signed (CN = Valve Corporation)
- Imports: KERNEL32.dll (110), tier0_s64.dll (13), vstdlib_s64.dll (13), PSAPI.DLL (2), WININET.dll (11)
- No exports
- Resources: RT_ICON (9), RT_VERSION, RT_MANIFEST
Companion Files
The SFX archive typically bundles:
tier0_s64.dll,vstdlib_s64.dll— legitimate Valve runtime (for camouflage)msvcp_win.dll,ucrtbase.dll— Microsoft CRTnetwork-mon.map— large (6–7 MB), entropy ~0.99/8, encrypted payloadprocess.xml— smaller companion config, same encoding
Observed Samples
642ecaab(INUS.exe) — 7-Zip SFX wrapper, innerVect_P16.exe^[raw/analyses/642ecaab/report.md]9410374b— Confirmed twin of642ecaab: same inner payload (SHA-2560a0c0975...), same sidecar files (network-mon.map,process.xml), same Steam Error Reporter masquerade. Only the outer SFX wrapper differs. ^[/intel/analyses/9410374bb9ccfb1a8a15aac5a038202e1ce7fb841a5128edf4d348d82db760c3.html]