Suspicious
SteamSetup.exe is a signed Valve Corp. installer with zero engine detections and extensive clean history.
5d8d697707c89466cf…fc6a7d6321The reasoning behind this verdict
The MT AI Engine weighs every signal from this scan — antivirus detections, sandbox behaviour, code signing, prevalence and historical matches — to reach a single, evidence-based verdict.
The complete absence of malicious detections across tier-1 and tier-2 engines combined with verified Valve Corp. signing and a prior safe RAG match on the same signer strongly indicates a legitimate Steam installer. Prevalence data shows thousands of prior submissions over nearly three years. While YARAify and some community comments raise noise, they are outweighed by the clean engine consensus, lack of malicious sandbox verdicts, and absence of malicious children or contacted hosts.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines: 0 malicious detections out of 74 total (12 tier-1 clean)
signing.signer='Valve Corp.', verified=true, signerStats.safeRate=1
similarHashes[0].verdict='safe' (matchKind=signer, reasonCode=ai:benign_signed_installer)
prevalence.classification='common_old' (3701 sources, 12179 submissions)
yaraify.ruleCount=3 but rules are 'NSIS_April_2024' and certificate-related (no malware family)
- Verified Valve Corp. signature
- Zero engine detections across 65 reporting engines
- Common_old prevalence with 12k+ submissions
- Prior safe verdict on identical signer
Treat as legitimate Steam installer. Run only downloads obtained directly from steampowered.com.
What this file does
What it attempted when executed in an isolated sandbox
High concern: Tries to steal saved passwords and credentials from Windows.
High concern: Talks to a remote server to take commands or send out your data.
High concern: Downloads more malware onto your PC.
High concern: Encrypts your files and demands payment — ransomware behaviour.
High concern: Installs itself as a Windows service to stay running.
High concern: Sets itself to run automatically every time you start your PC.
High concern: Tries to disable or bypass your security software.
Translated from the file's technical behaviour during analysis. It never ran on your device.
What to do now
We couldn't fully clear this file. Treat it with caution.
Don't run it unless you're certain it came from a source you trust.
Check where you got it — an email attachment or a random download link is a red flag.
If you're unsure, delete it. You can always re-download a clean copy from the official source.
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
NSIS April 2024 corroborated by 1 source
- 3 YARA rulesNSIS_April_2024, PE_Digital_Certificate, PE_Potentially_Signed_Digital_Certificate
1 contradiction resolved by the scoring engine
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 204.79.197.203
- 23.66.3.155
- 23.66.3.150
- 208.64.203.140
- 23.66.3.149
- 23.51.204.111
- 155.133.253.50
- 155.133.253.34
- 162.254.193.74
- 20.99.133.109
- http://test.steampowered.com/204
- http://apps.identrust.com/roots/dstrootcax3.p7c
- http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
- Steam Client Service
- C:\Program Files (x86)\Common Files\Steam\steamservice.exe
- C:\Program Files (x86)\Steam\aom.dll
- C:\Program Files (x86)\Steam\avif-16.dll
- C:\Program Files (x86)\Steam\bin\audio.dll
- C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\api-ms-win-core-console-l1-1-0.dll
- C:\Users\<USER>\AppData\Local\Temp\nss3752.tmp
- C:\Users\<USER>\AppData\Local\Temp\nsd37E1.tmp
- C:\Users\<USER>\AppData\Local\Temp\nsd37E1.tmp\modern-header.bmp
- C:\Users\<USER>\AppData\Local\Temp\nsd37E1.tmp\modern-wizard.bmp
- C:\Users\<USER>\AppData\Local\Temp\nsd37E1.tmp\nsDialogs.dll
- SteamSingleInstance
- Local\SM0:836:168:WilStaging_02
- Local\SM0:836:64:WilError_03
- Global\C::Users:Bruno:AppData:Local:Microsoft:Windows:Explorer:iconcache_idx.db!rwWriterMutex
- Global\C::Users:Bruno:AppData:Local:Microsoft:Windows:Explorer:iconcache_16.db!dfMaintainer
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- 1f45bb7bdfa01424f923…ff76d5Never scannednever seen before
- fdf7b42b3b027a12e1b7…473115Never scannednever seen before
- b01ec64d75fd1fbd00fb…84f585Never scannednever seen before
- fc74e26a8baabbe48511…3c8265Never scannednever seen before
- 5e4f2de5ee98d5d76f5d…3e66f6Never scannednever seen before
- 3ef2d57118e6488b0163…1df04eNever scannednever seen before
- 88eb0e145502e84cfb24…bd7cd4Never scannednever seen before
- 76a6bd74194efd819d33…cfa6d9Never scannednever seen before
- 7993f70d54d955e522e5…07a695Never scannednever seen before
- 650a265dffdc5dc50200…1ff3f7Never scannednever seen before
1 corroborating signal from researcher-curated sources
- NSIS_April_2024by NDA0NDetects NSIS installers
- PE_Digital_Certificateby albertzsigovits
- PE_Potentially_Signed_Digital_Certificateby albertzsigovits
YARA & heuristic rule matches
A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.
- NSIS_April_2024
- PE_Digital_Certificate
- PE_Potentially_Signed_Digital_Certificate
Sandbox flagged persistence indicators (registry Run keys / services / scheduled tasks).
EvidenceSteam Client ServiceMITRE T1003 (OS Credential Dumping) mapped by at least one sandbox run.
Sample contacted 20 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence204.79.197.203 · 23.66.3.155 · 23.66.3.150
0 detections across 74 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Forensic fingerprint
- File name
- SteamSetup.exe
- Size
- 2.27 MB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- 5d8d697707c89466cfe203bde7e242680d020646bd5e49edaabd67fc6a7d6321
- MD5
- b1f4bc644f535c745341de0303631d9c
- SHA-1
- 8d66e30416004cc2e98334a276c181ae1e67be55
- PE imphash
- 4ea4df5d94204fc550be1874e1b77ea7
- First seen (VT)
- 3/6/2024, 1:34:42 PM
- Last analysis (VT)
- 7/13/2026, 4:45:24 PM
- First scan (MalwareTips)
- 7/21/2026, 2:13:06 AM
- Last scan (MalwareTips)
- 7/21/2026, 2:13:06 AM
- Code signer
- Valve Corp.verified
- Community reputation
- +64trusted
Safety FAQ
Common questions about SteamSetup.exe, answered from the scan data above.
- SteamSetup.exe is suspicious — treat it as unsafe until you're sure. 0 of 74 antivirus engines flag it, which isn't a strong consensus but is enough to be cautious. Don't run it unless you fully trust where it came from, and prefer downloading the software fresh from its official site.
- SteamSetup.exe is a Windows executable program, about 2.3 MB. We identify a file by its cryptographic hash rather than its name, because the same filename can be reused by completely different files — the hash below is the reliable fingerprint.
- None — all 74 antivirus engines we queried report SteamSetup.exe as clean. That's reassuring, though brand-new malware can briefly evade detection before vendors add signatures, so we also weigh the file's behaviour and reputation.
- Act quickly. 1) Disconnect the device from the internet to stop the malware communicating or spreading. 2) Run a full scan with reputable anti-malware software (such as Malwarebytes) and quarantine everything it finds. 3) Change your important passwords from a DIFFERENT, clean device — many threats log keystrokes or steal saved credentials. 4) If you bank or shop on this device, watch closely for fraud and alert your bank. 5) For a confirmed infection, the most reliable fix is to back up your personal files and reinstall the operating system for a clean start.
- To remove SteamSetup.exe: 1) restart into Safe Mode (Safe Mode with Networking if you need to download a tool) so the malware doesn't auto-start. 2) Run a full scan with reputable anti-malware software and let it quarantine or delete the detections. 3) Delete the original SteamSetup.exe file and empty the Recycle Bin/Trash. 4) Check your browser extensions, startup items, and scheduled tasks for anything unfamiliar. 5) Reboot and scan again to confirm it's gone. If detections keep coming back, a clean operating-system reinstall is the most dependable cure.
- Yes — SteamSetup.exe carries a valid digital signature from Valve Corp., which confirms the file hasn't been tampered with since that publisher signed it. A valid signature is a positive signal, but note that malware is occasionally signed with stolen or abused certificates, so it isn't proof of safety on its own.
- The SHA-256 hash of SteamSetup.exe is 5d8d697707c89466cfe203bde7e242680d020646bd5e49edaabd67fc6a7d6321, and its MD5 is b1f4bc644f535c745341de0303631d9c. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
- This report reflects the scan run on July 21, 2026. Because a file's hash never changes, the identity of SteamSetup.exe is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.