File verdict·Decided by the MT AI Engine
Our call

Suspicious

SteamSetup.exe is a signed Valve Corp. installer with zero engine detections and extensive clean history.

Verified · Valve Corp.
Trust score52Caution
SteamSetup.exe
2.3 MB
5d8d697707c89466cffc6a7d6321
Antivirus engines
0 of 74 flagged
Code signing
Signed by Valve Corp.
Age
First seen 2y ago
MT AI Engine · Verdict analysis

The reasoning behind this verdict

The MT AI Engine weighs every signal from this scan — antivirus detections, sandbox behaviour, code signing, prevalence and historical matches — to reach a single, evidence-based verdict.

90%Confidence
Very high
Reasoning

The complete absence of malicious detections across tier-1 and tier-2 engines combined with verified Valve Corp. signing and a prior safe RAG match on the same signer strongly indicates a legitimate Steam installer. Prevalence data shows thousands of prior submissions over nearly three years. While YARAify and some community comments raise noise, they are outweighed by the clean engine consensus, lack of malicious sandbox verdicts, and absence of malicious children or contacted hosts.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. engines: 0 malicious detections out of 74 total (12 tier-1 clean)

  2. signing.signer='Valve Corp.', verified=true, signerStats.safeRate=1

  3. similarHashes[0].verdict='safe' (matchKind=signer, reasonCode=ai:benign_signed_installer)

  4. prevalence.classification='common_old' (3701 sources, 12179 submissions)

  5. yaraify.ruleCount=3 but rules are 'NSIS_April_2024' and certificate-related (no malware family)

Points in its favour
  • Verified Valve Corp. signature
  • Zero engine detections across 65 reporting engines
  • Common_old prevalence with 12k+ submissions
  • Prior safe verdict on identical signer
Recommended action

Treat as legitimate Steam installer. Run only downloads obtained directly from steampowered.com.

What this file does

What it attempted when executed in an isolated sandbox

  • High concern: Tries to steal saved passwords and credentials from Windows.

  • High concern: Talks to a remote server to take commands or send out your data.

  • High concern: Downloads more malware onto your PC.

  • High concern: Encrypts your files and demands payment — ransomware behaviour.

  • High concern: Installs itself as a Windows service to stay running.

  • High concern: Sets itself to run automatically every time you start your PC.

  • High concern: Tries to disable or bypass your security software.

Translated from the file's technical behaviour during analysis. It never ran on your device.

What to do now

We couldn't fully clear this file. Treat it with caution.

  1. Don't run it unless you're certain it came from a source you trust.

  2. Check where you got it — an email attachment or a random download link is a red flag.

  3. If you're unsure, delete it. You can always re-download a clean copy from the official source.

  4. If you're still unsure, scan it again in a day or two — detections often catch up on newer files.

Threat family attribution

NSIS April 2024 corroborated by 1 source

  • 3 YARA rules
    NSIS_April_2024, PE_Digital_Certificate, PE_Potentially_Signed_Digital_Certificate
Sources disagree

1 contradiction resolved by the scoring engine

MT AI Engine read "safe", displayed verdict is "suspicious"
A ground-truth gate (admin override, MalwareBazaar, empty-file) or the low-confidence display rule shifted the final call.
Displayed verdict tracks the harder evidence.
Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
46

Adversary techniques mapped to the MITRE ATT&CK framework.

T1003· Credential theftT1010T1012T1014T1018T1027· Obfuscated codeT1027.002· Obfuscated codeT1033· Reads user infoT1036T1045T1057· Lists programsT1059· Runs commandsT1060T1070· Covers its tracksT1071· Remote server (C2)T1082· System reconT1083· Scans your filesT1096T1105· Downloads malwareT1112T1115T1125T1129· Loads modulesT1134+22 more
Spawned processes
15
$(unnamed)
"C:\Users\<USER>\AppData\Local\Temp\executable.exe"
$(unnamed)
"C:\Program Files (x86)\Steam\bin\steamservice.exe" /Install
$(unnamed)
C:\Windows\Explorer.EXE
$(unnamed)
"C:\Program Files (x86)\Steam\steam.exe"
$(unnamed)
"C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe" "-lang=en_US" "-cachedir=C:\Users\<USER>\AppData\Local\Steam\htmlcache" "-steampid=4008" "-buildid=1709846872" "-steamid=0" "-logdir=C:\Program Files (x86)\Steam\logs" "-…
$(unnamed)
"C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe" --type=crashpad-handler /prefetch:7 --max-uploads=5 --max-db-size=20 --max-db-age=5 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Program Files (x86)\St…
$(unnamed)
.\bin\gldriverquery64.exe
$(unnamed)
.\bin\vulkandriverquery64.exe
+7 more processes captured.
Network activity
23
IP addresses20
  • 204.79.197.203
  • 23.66.3.155
  • 23.66.3.150
  • 208.64.203.140
  • 23.66.3.149
  • 23.51.204.111
  • 155.133.253.50
  • 155.133.253.34
  • 162.254.193.74
  • 20.99.133.109
+10 more
URLs3
  • http://test.steampowered.com/204
  • http://apps.identrust.com/roots/dstrootcax3.p7c
  • http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
Persistence
1
Indicators1
  • Steam Client Service
Filesystem & mutexes
40
Files written15
  • C:\Program Files (x86)\Common Files\Steam\steamservice.exe
  • C:\Program Files (x86)\Steam\aom.dll
  • C:\Program Files (x86)\Steam\avif-16.dll
  • C:\Program Files (x86)\Steam\bin\audio.dll
  • C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\api-ms-win-core-console-l1-1-0.dll
+10 more
Files deleted15
  • C:\Users\<USER>\AppData\Local\Temp\nss3752.tmp
  • C:\Users\<USER>\AppData\Local\Temp\nsd37E1.tmp
  • C:\Users\<USER>\AppData\Local\Temp\nsd37E1.tmp\modern-header.bmp
  • C:\Users\<USER>\AppData\Local\Temp\nsd37E1.tmp\modern-wizard.bmp
  • C:\Users\<USER>\AppData\Local\Temp\nsd37E1.tmp\nsDialogs.dll
+10 more
Mutexes created10
  • SteamSingleInstance
  • Local\SM0:836:168:WilStaging_02
  • Local\SM0:836:64:WilError_03
  • Global\C::Users:Bruno:AppData:Local:Microsoft:Windows:Explorer:iconcache_idx.db!rwWriterMutex
  • Global\C::Users:Bruno:AppData:Local:Microsoft:Windows:Explorer:iconcache_16.db!dfMaintainer
+5 more
Dropped payload

Files this sample writes at runtime

This file drops 10 children at runtime. None are currently flagged malicious in our cache.

10 unseen
  • 1f45bb7bdfa01424f923ff76d5Never scanned
    never seen before
  • fdf7b42b3b027a12e1b7473115Never scanned
    never seen before
  • b01ec64d75fd1fbd00fb84f585Never scanned
    never seen before
  • fc74e26a8baabbe485113c8265Never scanned
    never seen before
  • 5e4f2de5ee98d5d76f5d3e66f6Never scanned
    never seen before
  • 3ef2d57118e6488b01631df04eNever scanned
    never seen before
  • 88eb0e145502e84cfb24bd7cd4Never scanned
    never seen before
  • 76a6bd74194efd819d33cfa6d9Never scanned
    never seen before
  • 7993f70d54d955e522e507a695Never scanned
    never seen before
  • 650a265dffdc5dc502001ff3f7Never scanned
    never seen before
External threat intelligence

1 corroborating signal from researcher-curated sources

YARAify HIT·3 community rules matchedView on YARAify
  • NSIS_April_2024by NDA0N
    Detects NSIS installers
  • PE_Digital_Certificateby albertzsigovits
  • PE_Potentially_Signed_Digital_Certificateby albertzsigovits
Cross-referenced against MalwareBazaar (abuse.ch), YARAify, and the CIRCL hashlookup reference DB.
Signature matches

YARA & heuristic rule matches

A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.

3 YARAify3 synthesis
MITRE ATT&CK profile
Persistence× 1Cred access× 1C2× 1
YARAify (community)
Researcher-authored rules via abuse.ch
  • NSIS_April_2024
  • PE_Digital_Certificate
  • PE_Potentially_Signed_Digital_Certificate
MalwareTips synthesis rules
Our own detection rules, applied to the scan data and sandbox behaviour
  • PersistenceScheduledTaskmedium

    Sandbox flagged persistence indicators (registry Run keys / services / scheduled tasks).

    Evidence
    Steam Client Service
  • CredentialDumpermedium

    MITRE T1003 (OS Credential Dumping) mapped by at least one sandbox run.

  • DirectIpC2medium

    Sample contacted 20 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.

    Evidence
    204.79.197.203 · 23.66.3.155 · 23.66.3.150
Antivirus engine breakdown

0 detections across 74 engines

0 malicious0 suspicious74 clean
Tier-117 engines
0flag
Top commercial AVs (low FP rate)
Tier-240 engines
0flag
Mainstream engines with mixed FP rates
Low-trust17 engines
0flag
Heuristic / generic-AI engines (high FP rate)
All 74 engines report this file as clean.
Hash 5d8d697707c8… cross-referenced against 74 AV engines via our AV network.
PE forensics

Section entropy & packers

Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.

ent 8.00Unpacked
Section entropy5 sections
.text
6.45
.rdata
5.16
.data
3.98
.ndata
0.00
.rsrc
6.24
0.0Packed threshold 7.28.0
Prevalence

How widely this file has been seen

Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.

Common & old
Unique uploaders
3,701
Hundreds of people have uploaded this — common.
Total submissions
12,179
Includes repeat uploads by the same source.
First seen
2y ago
Mar 6, 2024
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
here
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
3/6/2024, 1:34:42 PM
First seen (MalwareBazaar)
Last analysis (VT)
7/13/2026, 4:45:24 PM
Scanned here
7/21/2026, 2:13:06 AM
File name
SteamSetup.exe
Size
2.27 MB
MIME type
(unknown)
Detected type
Win32 EXE
SHA-256
5d8d697707c89466cfe203bde7e242680d020646bd5e49edaabd67fc6a7d6321
MD5
b1f4bc644f535c745341de0303631d9c
SHA-1
8d66e30416004cc2e98334a276c181ae1e67be55
PE imphash
4ea4df5d94204fc550be1874e1b77ea7
First seen (VT)
3/6/2024, 1:34:42 PM
Last analysis (VT)
7/13/2026, 4:45:24 PM
First scan (MalwareTips)
7/21/2026, 2:13:06 AM
Last scan (MalwareTips)
7/21/2026, 2:13:06 AM
Code signer
Valve Corp.verified
Community reputation
+64trusted
Behavior tags
signedpeexeoverlaypersistencedetect-debug-environment
Frequently asked

Safety FAQ

Common questions about SteamSetup.exe, answered from the scan data above.

  • SteamSetup.exe is suspicious — treat it as unsafe until you're sure. 0 of 74 antivirus engines flag it, which isn't a strong consensus but is enough to be cautious. Don't run it unless you fully trust where it came from, and prefer downloading the software fresh from its official site.
  • SteamSetup.exe is a Windows executable program, about 2.3 MB. We identify a file by its cryptographic hash rather than its name, because the same filename can be reused by completely different files — the hash below is the reliable fingerprint.
  • None — all 74 antivirus engines we queried report SteamSetup.exe as clean. That's reassuring, though brand-new malware can briefly evade detection before vendors add signatures, so we also weigh the file's behaviour and reputation.
  • Act quickly. 1) Disconnect the device from the internet to stop the malware communicating or spreading. 2) Run a full scan with reputable anti-malware software (such as Malwarebytes) and quarantine everything it finds. 3) Change your important passwords from a DIFFERENT, clean device — many threats log keystrokes or steal saved credentials. 4) If you bank or shop on this device, watch closely for fraud and alert your bank. 5) For a confirmed infection, the most reliable fix is to back up your personal files and reinstall the operating system for a clean start.
  • To remove SteamSetup.exe: 1) restart into Safe Mode (Safe Mode with Networking if you need to download a tool) so the malware doesn't auto-start. 2) Run a full scan with reputable anti-malware software and let it quarantine or delete the detections. 3) Delete the original SteamSetup.exe file and empty the Recycle Bin/Trash. 4) Check your browser extensions, startup items, and scheduled tasks for anything unfamiliar. 5) Reboot and scan again to confirm it's gone. If detections keep coming back, a clean operating-system reinstall is the most dependable cure.
  • Yes — SteamSetup.exe carries a valid digital signature from Valve Corp., which confirms the file hasn't been tampered with since that publisher signed it. A valid signature is a positive signal, but note that malware is occasionally signed with stolen or abused certificates, so it isn't proof of safety on its own.
  • The SHA-256 hash of SteamSetup.exe is 5d8d697707c89466cfe203bde7e242680d020646bd5e49edaabd67fc6a7d6321, and its MD5 is b1f4bc644f535c745341de0303631d9c. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
  • This report reflects the scan run on July 21, 2026. Because a file's hash never changes, the identity of SteamSetup.exe is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.