Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
SteamSetup.exe

Overview

General Information

Sample name:SteamSetup.exe
Analysis ID:1558928
MD5:1b34108b77b984e227bbad718d89594a
SHA1:a75f5432e2ce39dc6c3f190d8d35ee2475a0ae6b
SHA256:3f27a1a005beb7b1032bf9aef9fe5128ee1cccc332de862717b42d0b7f9c1f34
Tags:exeuser-J_Jancelewicz
Infos:

Detection

Score:24
Range:0 - 100
Whitelisted:false
Confidence:20%

Signatures

Connects to many ports of the same IP (likely port scanning)
Yara detected Generic Downloader
Allocates memory with a write watch (potentially for evading sandboxes)
Binary contains a suspicious time stamp
Detected TCP or UDP traffic on non-standard ports
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
HTTP GET or POST without a user agent
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE file contains executable resources (Code or Archives)
PE file contains sections with non-standard names
PE file does not import any functions
Queries disk information (often used to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Stores files to the Windows start menu directory
Uses 32bit PE files

Classification

  • System is w10x64
  • SteamSetup.exe (PID: 7340 cmdline: "C:\Users\user\Desktop\SteamSetup.exe" MD5: 1B34108B77B984E227BBAD718D89594A)
    • SteamSetup.tmp (PID: 7360 cmdline: "C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp" /SL5="$10472,49358704,796160,C:\Users\user\Desktop\SteamSetup.exe" MD5: 5338593C8A3654FEF48E3EFD7FBBE890)
      • Steam2.exe (PID: 7640 cmdline: "C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exe" MD5: 24579F75EE35BDD8E4CCC5351295BD9D)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
C:\Users\user\AppData\Local\Programs\SteamClient\is-0A2IM.tmpJoeSecurity_GenericDownloader_1Yara detected Generic DownloaderJoe Security
    C:\Users\user\AppData\Local\Programs\SteamClient\is-H6DF9.tmpJoeSecurity_GenericDownloader_1Yara detected Generic DownloaderJoe Security
      C:\Users\user\AppData\Local\Programs\SteamClient\is-EL3N4.tmpJoeSecurity_GenericDownloader_1Yara detected Generic DownloaderJoe Security
        No Sigma rule has matched
        No Suricata rule has matched

        Click to jump to signature section

        Show All Signature Results
        Source: SteamSetup.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpRegistry value created: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{97C23183-77ED-457C-90C7-3FA73E699316}_is1Jump to behavior
        Source: unknownHTTPS traffic detected: 104.102.49.254:443 -> 192.168.2.4:52303 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 162.254.199.184:443 -> 192.168.2.4:52571 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 162.254.199.184:443 -> 192.168.2.4:52572 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 155.133.253.36:443 -> 192.168.2.4:52573 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 162.254.192.98:443 -> 192.168.2.4:52574 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 162.254.192.99:443 -> 192.168.2.4:52575 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 155.133.253.52:443 -> 192.168.2.4:52576 version: TLS 1.2
        Source: SteamSetup.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
        Source: Binary string: /_/artifacts/obj/WindowsFormsIntegration/x64/Release/net8.0/WindowsFormsIntegration.pdbRSDS source: SteamSetup.tmp, 00000001.00000003.1880994045.0000000005B6D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/System.Resources.Reader/Release/net8.0-windows/System.Resources.Reader.pdbSHA256 source: is-JT9R1.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Security.Cryptography.ProtectedData/Release/net8.0/System.Security.Cryptography.ProtectedData.pdb source: is-OL3NB.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\coreclr\windows.x64.Release\debug\createdump\createdump.pdb source: is-M7PK8.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Text.Json\Release\net8.0\System.Text.Json.pdb source: is-LFOPB.tmp.1.dr
        Source: Binary string: System.ComponentModel.ni.pdb source: is-RT9LP.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Xml.XmlSerializer\Release\net8.0\System.Xml.XmlSerializer.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.IO.Compression.ZipFile\Release\net8.0-windows\System.IO.Compression.ZipFile.pdb source: is-G8384.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Reflection.Metadata\Release\net8.0\System.Reflection.Metadata.pdb source: is-SELO9.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Reflection.Emit.Lightweight\Release\net8.0\System.Reflection.Emit.Lightweight.pdb source: is-8Q6ES.tmp.1.dr
        Source: Binary string: PresentationFramework.Luna.ni.pdb source: is-0QI8B.tmp.1.dr
        Source: Binary string: System.Threading.AccessControl.ni.pdb source: is-6E0AB.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/UIAutomationClientSideProviders/x64/Release/net8.0/UIAutomationClientSideProviders.pdbRSDS source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Runtime\Release\net8.0\System.Runtime.pdbSHA256 source: is-E704A.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Xml.XDocument\Release\net8.0\System.Xml.XDocument.pdbSHA256 source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/System.Globalization/Release/net8.0-windows/System.Globalization.pdbSHA256& source: is-J5Q53.tmp.1.dr
        Source: Binary string: System.Reflection.Metadata.ni.pdb source: is-SELO9.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Xml.Linq/Release/net8.0-windows/System.Xml.Linq.pdbSHA256 source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/System.Windows.Input.Manipulations/x64/Release/net8.0/System.Windows.Input.Manipulations.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000055F0000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/System.Data/Release/net8.0-windows/System.Data.pdbSHA256> source: is-C8Q0I.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Linq\Release\net8.0\System.Linq.pdb source: is-9VBVU.tmp.1.dr
        Source: Binary string: System.Windows.Input.Manipulations.ni.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000055F0000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Xml.XDocument\Release\net8.0\System.Xml.XDocument.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/System.Xml.XmlDocument/Release/net8.0-windows/System.Xml.XmlDocument.pdbSHA256 source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp, is-2TVF9.tmp.1.dr
        Source: Binary string: System.Xaml.ni.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.0000000005620000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/System.Web/Release/net8.0-windows/System.Web.pdb source: is-8SOAE.tmp.1.dr
        Source: Binary string: System.Text.Json.ni.pdb source: is-LFOPB.tmp.1.dr
        Source: Binary string: System.Linq.ni.pdb source: is-9VBVU.tmp.1.dr
        Source: Binary string: System.Formats.Tar.ni.pdb source: is-URA97.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/UIAutomationProvider/x64/Release/net8.0/UIAutomationProvider.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/System.Threading.AccessControl/Release/net8.0-windows/System.Threading.AccessControl.pdb source: is-6E0AB.tmp.1.dr
        Source: Binary string: System.Xml.XPath.XDocument.ni.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/System.Xml/Release/net8.0-windows/System.Xml.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Xml.ReaderWriter\Release\net8.0\System.Xml.ReaderWriter.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: WindowsBase.ni.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\Microsoft.CSharp\Release\net8.0-windows\Microsoft.CSharp.pdb source: is-U5CAB.tmp.1.dr
        Source: Binary string: System.Windows.Presentation.ni.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000055F0000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: System.Text.RegularExpressions.ni.pdb source: is-SNOP4.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Resources.Reader/Release/net8.0-windows/System.Resources.Reader.pdb source: is-JT9R1.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Windows/Release/net8.0-windows/System.Windows.pdbSHA256 source: is-7D57R.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Net.Requests\Release\net8.0-windows\System.Net.Requests.pdbSHA256@ source: is-IU0LQ.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Data/Release/net8.0-windows/System.Data.pdb source: is-C8Q0I.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Xml.ReaderWriter\Release\net8.0\System.Xml.ReaderWriter.pdbSHA256 source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.ComponentModel\Release\net8.0\System.ComponentModel.pdb source: is-RT9LP.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Memory\Release\net8.0\System.Memory.pdb source: is-219L9.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Data.DataSetExtensions/Release/net8.0-windows/System.Data.DataSetExtensions.pdbSHA256 source: is-5A8TQ.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Reflection.Emit.Lightweight\Release\net8.0\System.Reflection.Emit.Lightweight.pdbSHA256 source: is-8Q6ES.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Configuration.ConfigurationManager/Release/net8.0/System.Configuration.ConfigurationManager.pdb source: is-EVMTH.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\fxr\standalone\hostfxr.pdb source: is-21558.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Data.DataSetExtensions/Release/net8.0-windows/System.Data.DataSetExtensions.pdb source: is-5A8TQ.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/WindowsBase/x64/Release/net8.0/WindowsBase.pdbRSDS#F source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: UIAutomationProvider.ni.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/System.Xml.Serialization/Release/net8.0-windows/System.Xml.Serialization.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Net.Requests\Release\net8.0-windows\System.Net.Requests.pdb source: is-IU0LQ.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Runtime.InteropServices\Release\net8.0\System.Runtime.InteropServices.pdb source: is-3DQQ4.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Numerics/Release/net8.0-windows/System.Numerics.pdb source: is-G9TVR.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Windows/Release/net8.0-windows/System.Windows.pdb source: is-7D57R.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Xml/Release/net8.0-windows/System.Xml.pdbSHA256 source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/PresentationFramework.Luna/x64/Release/net8.0/PresentationFramework.Luna.pdb source: is-0QI8B.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\coreclr\windows.x64.Release\debug\createdump\createdump.pdb===GCTL source: is-M7PK8.tmp.1.dr
        Source: Binary string: Microsoft.CSharp.ni.pdb source: is-U5CAB.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Windows.Presentation/x64/Release/net8.0/System.Windows.Presentation.pdbRSDS source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000055F0000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: System.Net.WebProxy.ni.pdb source: is-3U4SF.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Globalization/Release/net8.0-windows/System.Globalization.pdb source: is-J5Q53.tmp.1.dr
        Source: Binary string: UIAutomationClient.ni.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Formats.Tar\Release\net8.0-windows\System.Formats.Tar.pdb source: is-URA97.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/WindowsBase/x64/Release/net8.0/WindowsBase.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: System.IO.Compression.ZipFile.ni.pdb source: is-G8384.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Numerics/Release/net8.0-windows/System.Numerics.pdbSHA256s# source: is-G9TVR.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdbGCTL source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/System.Configuration/Release/net8.0-windows/System.Configuration.pdb source: is-KSMQT.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Console\Release\net8.0-windows\System.Console.pdb source: is-QLJJ1.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Design.Facade/Release/net8.0/System.Design.pdb source: is-7IP4F.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Xml.Linq/Release/net8.0-windows/System.Xml.Linq.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Xml.XmlSerializer\Release\net8.0\System.Xml.XmlSerializer.pdbSHA256 source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/System.Configuration.ConfigurationManager/Release/net8.0/System.Configuration.ConfigurationManager.pdbSHA256 source: is-EVMTH.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/WindowsFormsIntegration/x64/Release/net8.0/WindowsFormsIntegration.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.0000000005B6D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb source: Steam2.exe, 00000003.00000000.1879341006.00007FF69F827000.00000002.00000001.01000000.00000009.sdmp
        Source: Binary string: UIAutomationClientSideProviders.ni.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\coreclr\windows.x64.Release\dlls\mscorrc\mscorrc.pdb source: is-G721R.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Xaml/x64/Release/net8.0/System.Xaml.pdbRSDS source: SteamSetup.tmp, 00000001.00000003.1880994045.0000000005620000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: System.Memory.ni.pdb source: is-219L9.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Core/Release/net8.0-windows/System.Core.pdb source: is-N6T5R.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Xml.XPath.XDocument\Release\net8.0\System.Xml.XPath.XDocument.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Xml.XPath\Release\net8.0\System.Xml.XPath.pdbSHA256] source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\bin\wpfgfx\x64\Release\wpfgfx_cor3.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.0000000005B6D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/System.Web/Release/net8.0-windows/System.Web.pdbSHA256 source: is-8SOAE.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Net.WebProxy\Release\net8.0\System.Net.WebProxy.pdb source: is-3U4SF.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Data.Common\Release\net8.0\System.Data.Common.pdb source: is-S7M74.tmp.1.dr
        Source: Binary string: System.Net.Requests.ni.pdb source: is-IU0LQ.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Xml.Serialization/Release/net8.0-windows/System.Xml.Serialization.pdbSHA256 source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/System.Xaml/x64/Release/net8.0/System.Xaml.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.0000000005620000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: System.Runtime.InteropServices.ni.pdb source: is-3DQQ4.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/UIAutomationTypes/x64/Release/net8.0/UIAutomationTypes.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\fxr\standalone\hostfxr.pdbxxxGCTL source: is-21558.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Xml.XmlDocument/Release/net8.0-windows/System.Xml.XmlDocument.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp, is-2TVF9.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Configuration/Release/net8.0-windows/System.Configuration.pdbSHA256l8 source: is-KSMQT.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.IO.Packaging/Release/net8.0/System.IO.Packaging.pdb source: is-O2VS5.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/UIAutomationClientSideProviders/x64/Release/net8.0/UIAutomationClientSideProviders.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Linq\Release\net8.0\System.Linq.pdbSHA256 source: is-9VBVU.tmp.1.dr
        Source: Binary string: UIAutomationTypes.ni.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: System.Configuration.ConfigurationManager.ni.pdb source: is-EVMTH.tmp.1.dr
        Source: Binary string: System.Console.ni.pdb source: is-QLJJ1.tmp.1.dr
        Source: Binary string: System.Security.Cryptography.ProtectedData.ni.pdb source: is-OL3NB.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Xml.XPath\Release\net8.0\System.Xml.XPath.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/System.Core/Release/net8.0-windows/System.Core.pdbSHA2564- source: is-N6T5R.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Runtime\Release\net8.0\System.Runtime.pdb source: is-E704A.tmp.1.dr
        Source: Binary string: WindowsFormsIntegration.ni.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.0000000005B6D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdbmmmGCTL source: Steam2.exe, 00000003.00000000.1879341006.00007FF69F827000.00000002.00000001.01000000.00000009.sdmp
        Source: Binary string: System.Data.Common.ni.pdb source: is-S7M74.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Windows.Presentation/x64/Release/net8.0/System.Windows.Presentation.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000055F0000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/UIAutomationClient/x64/Release/net8.0/UIAutomationClient.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Text.RegularExpressions\Release\net8.0\System.Text.RegularExpressions.pdb source: is-SNOP4.tmp.1.dr
        Source: Binary string: System.IO.Packaging.ni.pdb source: is-O2VS5.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Net.WebProxy\Release\net8.0\System.Net.WebProxy.pdbSHA256 source: is-3U4SF.tmp.1.dr

        Networking

        barindex
        Source: global trafficTCP traffic: 162.254.199.165 ports 27018,0,1,2,7,8
        Source: Yara matchFile source: C:\Users\user\AppData\Local\Programs\SteamClient\is-0A2IM.tmp, type: DROPPED
        Source: Yara matchFile source: C:\Users\user\AppData\Local\Programs\SteamClient\is-H6DF9.tmp, type: DROPPED
        Source: Yara matchFile source: C:\Users\user\AppData\Local\Programs\SteamClient\is-EL3N4.tmp, type: DROPPED
        Source: global trafficTCP traffic: 192.168.2.4:52304 -> 162.254.199.165:27018
        Source: global trafficHTTP traffic detected: GET /cmsocket/ HTTP/1.1Host: cmp2-atl3.steamserver.netConnection: UpgradeUpgrade: websocketSec-WebSocket-Key: SX1pmJICoUOgvcAEWO04Yg==Sec-WebSocket-Version: 13
        Source: global trafficHTTP traffic detected: GET /cmsocket/ HTTP/1.1Host: cmp1-dfw1.steamserver.netConnection: UpgradeUpgrade: websocketSec-WebSocket-Key: 8pAM8HKoEEa2SDwRfJv7Yw==Sec-WebSocket-Version: 13
        Source: global trafficHTTP traffic detected: GET /cmsocket/ HTTP/1.1Host: cmp1-iad1.steamserver.netConnection: UpgradeUpgrade: websocketSec-WebSocket-Key: 4Mzn+oyKNEOPx/VMky/HWA==Sec-WebSocket-Version: 13
        Source: global trafficHTTP traffic detected: GET /cmsocket/ HTTP/1.1Host: cmp2-iad1.steamserver.netConnection: UpgradeUpgrade: websocketSec-WebSocket-Key: 9SfrCnjzD0+vkNHqMYQEtw==Sec-WebSocket-Version: 13
        Source: global trafficHTTP traffic detected: GET /cmsocket/ HTTP/1.1Host: cmp2-dfw1.steamserver.netConnection: UpgradeUpgrade: websocketSec-WebSocket-Key: gct+FU7dl0WK9aM8K5/MdQ==Sec-WebSocket-Version: 13
        Source: Joe Sandbox ViewIP Address: 104.102.49.254 104.102.49.254
        Source: Joe Sandbox ViewJA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: global trafficHTTP traffic detected: GET /ISteamDirectory/GetCMListForConnect/v1/?format=vdf&cellid=0 HTTP/1.1Host: api.steampowered.comUser-Agent: SteamKit/3.0.0
        Source: global trafficHTTP traffic detected: GET /cmsocket/ HTTP/1.1Host: cmp2-atl3.steamserver.netConnection: UpgradeUpgrade: websocketSec-WebSocket-Key: SX1pmJICoUOgvcAEWO04Yg==Sec-WebSocket-Version: 13
        Source: global trafficHTTP traffic detected: GET /cmsocket/ HTTP/1.1Host: cmp1-dfw1.steamserver.netConnection: UpgradeUpgrade: websocketSec-WebSocket-Key: 8pAM8HKoEEa2SDwRfJv7Yw==Sec-WebSocket-Version: 13
        Source: global trafficHTTP traffic detected: GET /cmsocket/ HTTP/1.1Host: cmp1-iad1.steamserver.netConnection: UpgradeUpgrade: websocketSec-WebSocket-Key: 4Mzn+oyKNEOPx/VMky/HWA==Sec-WebSocket-Version: 13
        Source: global trafficHTTP traffic detected: GET /cmsocket/ HTTP/1.1Host: cmp2-iad1.steamserver.netConnection: UpgradeUpgrade: websocketSec-WebSocket-Key: 9SfrCnjzD0+vkNHqMYQEtw==Sec-WebSocket-Version: 13
        Source: global trafficHTTP traffic detected: GET /cmsocket/ HTTP/1.1Host: cmp2-dfw1.steamserver.netConnection: UpgradeUpgrade: websocketSec-WebSocket-Key: gct+FU7dl0WK9aM8K5/MdQ==Sec-WebSocket-Version: 13
        Source: global trafficDNS traffic detected: DNS query: 198.187.3.20.in-addr.arpa
        Source: global trafficDNS traffic detected: DNS query: api.steampowered.com
        Source: global trafficDNS traffic detected: DNS query: cmp1-atl3.steamserver.net
        Source: global trafficDNS traffic detected: DNS query: cmp2-atl3.steamserver.net
        Source: global trafficDNS traffic detected: DNS query: cmp1-dfw1.steamserver.net
        Source: global trafficDNS traffic detected: DNS query: cmp1-iad1.steamserver.net
        Source: global trafficDNS traffic detected: DNS query: cmp2-iad1.steamserver.net
        Source: global trafficDNS traffic detected: DNS query: cmp2-dfw1.steamserver.net
        Source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://uri.etsi.org/01903/v1.2.2#SSOFTWARE
        Source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://uri.etsi.org/01903/v1.2.2#SignedProperties
        Source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://uri.etsi.org/01903/v1.2.2#bhttp://uri.etsi.org/01903/v1.2.2#SignedProperties
        Source: is-EVMTH.tmp.1.dr, is-O2VS5.tmp.1.dr, is-SELO9.tmp.1.drString found in binary or memory: https://aka.ms/binaryformatter
        Source: Steam2.exe, 00000003.00000000.1879341006.00007FF69F827000.00000002.00000001.01000000.00000009.sdmpString found in binary or memory: https://aka.ms/dotnet-core-applaunch?
        Source: Steam2.exe, 00000003.00000000.1879341006.00007FF69F827000.00000002.00000001.01000000.00000009.sdmpString found in binary or memory: https://aka.ms/dotnet-core-applaunch?Architecture:
        Source: is-21558.tmp.1.drString found in binary or memory: https://aka.ms/dotnet-core-applaunch?framework=&framework_version=missing_runtime=true&arch=&rid=&os
        Source: is-IU0LQ.tmp.1.drString found in binary or memory: https://aka.ms/dotnet-warnings/
        Source: Steam2.exe, 00000003.00000000.1879341006.00007FF69F827000.00000002.00000001.01000000.00000009.sdmp, is-21558.tmp.1.drString found in binary or memory: https://aka.ms/dotnet/app-launch-failed
        Source: is-21558.tmp.1.drString found in binary or memory: https://aka.ms/dotnet/download
        Source: is-21558.tmp.1.drString found in binary or memory: https://aka.ms/dotnet/downloadUsage:
        Source: is-21558.tmp.1.drString found in binary or memory: https://aka.ms/dotnet/info
        Source: is-21558.tmp.1.drString found in binary or memory: https://aka.ms/dotnet/sdk-not-foundFailed
        Source: is-EVMTH.tmp.1.dr, is-O2VS5.tmp.1.dr, is-S7M74.tmp.1.dr, is-SELO9.tmp.1.drString found in binary or memory: https://aka.ms/serializationformat-binary-obsolete
        Source: is-SNOP4.tmp.1.drString found in binary or memory: https://github.com/dotnet/linker/issues/2715.
        Source: is-5A8TQ.tmp.1.dr, is-9VBVU.tmp.1.dr, is-3U4SF.tmp.1.dr, is-N6T5R.tmp.1.dr, is-SNOP4.tmp.1.dr, is-3DQQ4.tmp.1.dr, is-EVMTH.tmp.1.dr, is-2TVF9.tmp.1.dr, is-KSMQT.tmp.1.dr, is-LFOPB.tmp.1.dr, is-8Q6ES.tmp.1.dr, is-J5Q53.tmp.1.dr, is-8SOAE.tmp.1.dr, is-O2VS5.tmp.1.dr, is-C8Q0I.tmp.1.dr, is-S7M74.tmp.1.dr, is-7D57R.tmp.1.dr, is-SELO9.tmp.1.dr, is-U5CAB.tmp.1.dr, is-IU0LQ.tmp.1.dr, is-URA97.tmp.1.drString found in binary or memory: https://github.com/dotnet/runtime
        Source: is-JT9R1.tmp.1.drString found in binary or memory: https://github.com/dotnet/runtime0
        Source: is-KSMQT.tmp.1.drString found in binary or memory: https://github.com/dotnet/runtime;
        Source: is-8SOAE.tmp.1.drString found in binary or memory: https://github.com/dotnet/runtimeH
        Source: is-J5Q53.tmp.1.drString found in binary or memory: https://github.com/dotnet/runtimer
        Source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/dotnet/runtimezX
        Source: SteamSetup.tmp, 00000001.00000003.1880994045.0000000005B6D000.00000004.00001000.00020000.00000000.sdmp, is-7IP4F.tmp.1.drString found in binary or memory: https://github.com/dotnet/winforms
        Source: SteamSetup.tmp, 00000001.00000003.1880994045.0000000005B6D000.00000004.00001000.00020000.00000000.sdmp, SteamSetup.tmp, 00000001.00000003.1880994045.00000000055F0000.00000004.00001000.00020000.00000000.sdmp, SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp, SteamSetup.tmp, 00000001.00000003.1880994045.0000000005620000.00000004.00001000.00020000.00000000.sdmp, is-0QI8B.tmp.1.drString found in binary or memory: https://github.com/dotnet/wpf
        Source: SteamSetup.tmp, 00000001.00000003.1880994045.0000000005B6D000.00000004.00001000.00020000.00000000.sdmp, SteamSetup.tmp, 00000001.00000003.1880994045.00000000055F0000.00000004.00001000.00020000.00000000.sdmp, SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp, SteamSetup.tmp, 00000001.00000003.1880994045.0000000005620000.00000004.00001000.00020000.00000000.sdmp, is-0QI8B.tmp.1.drString found in binary or memory: https://github.com/dotnet/wpf4
        Source: is-S7M74.tmp.1.drString found in binary or memory: https://github.com/mono/linker/issues/1187
        Source: is-U5CAB.tmp.1.drString found in binary or memory: https://github.com/mono/linker/issues/1416.
        Source: is-U5CAB.tmp.1.drString found in binary or memory: https://github.com/mono/linker/issues/1906.
        Source: is-S7M74.tmp.1.drString found in binary or memory: https://github.com/mono/linker/issues/1981
        Source: SteamSetup.exeString found in binary or memory: https://jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU
        Source: SteamSetup.exe, 00000000.00000003.1688166005.000000007FB50000.00000004.00001000.00020000.00000000.sdmp, SteamSetup.exe, 00000000.00000003.1687407738.0000000002690000.00000004.00001000.00020000.00000000.sdmp, SteamSetup.tmp, 00000001.00000000.1689708207.0000000000401000.00000020.00000001.01000000.00000004.sdmp, is-46PES.tmp.1.drString found in binary or memory: https://www.innosetup.com/
        Source: SteamSetup.exe, 00000000.00000003.1688166005.000000007FB50000.00000004.00001000.00020000.00000000.sdmp, SteamSetup.exe, 00000000.00000003.1687407738.0000000002690000.00000004.00001000.00020000.00000000.sdmp, SteamSetup.tmp, 00000001.00000000.1689708207.0000000000401000.00000020.00000001.01000000.00000004.sdmp, is-46PES.tmp.1.drString found in binary or memory: https://www.remobjects.com/ps
        Source: SteamSetup.tmp, 00000001.00000003.1692507487.00000000035B0000.00000004.00001000.00020000.00000000.sdmp, SteamSetup.tmp, 00000001.00000003.1887946566.000000000250C000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.steam.com/
        Source: SteamSetup.exe, 00000000.00000003.1903609511.0000000002433000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.steam.com/Q6C
        Source: SteamSetup.tmp, 00000001.00000003.1887946566.000000000250C000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.steam.com/Q9Q
        Source: unknownNetwork traffic detected: HTTP traffic on port 52303 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 52571 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 52572 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52574
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52575
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52572
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52573
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52303
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52576
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52571
        Source: unknownNetwork traffic detected: HTTP traffic on port 52574 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 52573 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 52575 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 52576 -> 443
        Source: unknownHTTPS traffic detected: 104.102.49.254:443 -> 192.168.2.4:52303 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 162.254.199.184:443 -> 192.168.2.4:52571 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 162.254.199.184:443 -> 192.168.2.4:52572 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 155.133.253.36:443 -> 192.168.2.4:52573 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 162.254.192.98:443 -> 192.168.2.4:52574 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 162.254.192.99:443 -> 192.168.2.4:52575 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 155.133.253.52:443 -> 192.168.2.4:52576 version: TLS 1.2
        Source: SteamSetup.tmp.0.drStatic PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
        Source: is-HTHBE.tmp.1.drStatic PE information: No import functions for PE file found
        Source: is-UCH6K.tmp.1.drStatic PE information: No import functions for PE file found
        Source: is-9VBVU.tmp.1.drStatic PE information: No import functions for PE file found
        Source: is-BV18A.tmp.1.drStatic PE information: No import functions for PE file found
        Source: is-O2VS5.tmp.1.drStatic PE information: No import functions for PE file found
        Source: is-V92IG.tmp.1.drStatic PE information: No import functions for PE file found
        Source: is-KPNTM.tmp.1.drStatic PE information: No import functions for PE file found
        Source: is-IOHDI.tmp.1.drStatic PE information: No import functions for PE file found
        Source: SteamSetup.exe, 00000000.00000003.1688166005.000000007FE36000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFileName vs SteamSetup.exe
        Source: SteamSetup.exe, 00000000.00000003.1903609511.00000000023F8000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFilenamekernel32j% vs SteamSetup.exe
        Source: SteamSetup.exe, 00000000.00000003.1687407738.000000000277A000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFileName vs SteamSetup.exe
        Source: SteamSetup.exe, 00000000.00000000.1685924822.00000000004C6000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFileName vs SteamSetup.exe
        Source: SteamSetup.exeBinary or memory string: OriginalFileName vs SteamSetup.exe
        Source: SteamSetup.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
        Source: is-IOHDI.tmp.1.dr, PipeStream.csTask registration methods: 'RegisterForCancellation'
        Source: is-IOHDI.tmp.1.dr, PipeSecurity.csSecurity API names: System.IO.Pipes.PipeSecurity.GetAccessControlSectionsFromChanges()
        Source: is-IOHDI.tmp.1.dr, PipeSecurity.csSecurity API names: ((CommonObjectSecurity)this).AddAccessRule
        Source: is-IOHDI.tmp.1.dr, PipeSecurity.csSecurity API names: System.Security.AccessControl.CommonObjectSecurity.GetAccessRules(bool, bool, System.Type)
        Source: is-IOHDI.tmp.1.dr, NamedPipeServerStream.csSecurity API names: System.IO.Pipes.PipeSecurity.AddAccessRule(System.IO.Pipes.PipeAccessRule)
        Source: is-IOHDI.tmp.1.dr, NamedPipeServerStream.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
        Source: is-IOHDI.tmp.1.dr, NamedPipeClientStream.csSecurity API names: System.IO.Pipes.PipeStream.GetAccessControl()
        Source: is-IOHDI.tmp.1.dr, NamedPipeClientStream.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
        Source: is-UCH6K.tmp.1.dr, Helper.csSecurity API names: System.IO.FileSystemAclExtensions.SetAccessControl(System.IO.DirectoryInfo, System.Security.AccessControl.DirectorySecurity)
        Source: is-UCH6K.tmp.1.dr, Helper.csSecurity API names: System.Security.AccessControl.FileSystemSecurity.AddAccessRule(System.Security.AccessControl.FileSystemAccessRule)
        Source: classification engineClassification label: sus24.troj.winEXE@5/496@8/7
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\ProgramsJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeMutant created: NULL
        Source: C:\Users\user\Desktop\SteamSetup.exeFile created: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmpJump to behavior
        Source: C:\Users\user\Desktop\SteamSetup.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
        Source: C:\Users\user\Desktop\SteamSetup.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile read: C:\Users\desktop.iniJump to behavior
        Source: C:\Users\user\Desktop\SteamSetup.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganizationJump to behavior
        Source: SteamSetup.exeString found in binary or memory: /LOADINF="filename"
        Source: C:\Users\user\Desktop\SteamSetup.exeFile read: C:\Users\user\Desktop\SteamSetup.exeJump to behavior
        Source: unknownProcess created: C:\Users\user\Desktop\SteamSetup.exe "C:\Users\user\Desktop\SteamSetup.exe"
        Source: C:\Users\user\Desktop\SteamSetup.exeProcess created: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp "C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp" /SL5="$10472,49358704,796160,C:\Users\user\Desktop\SteamSetup.exe"
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpProcess created: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exe "C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exe"
        Source: C:\Users\user\Desktop\SteamSetup.exeProcess created: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp "C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp" /SL5="$10472,49358704,796160,C:\Users\user\Desktop\SteamSetup.exe" Jump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpProcess created: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exe "C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exe"Jump to behavior
        Source: C:\Users\user\Desktop\SteamSetup.exeSection loaded: version.dllJump to behavior
        Source: C:\Users\user\Desktop\SteamSetup.exeSection loaded: netapi32.dllJump to behavior
        Source: C:\Users\user\Desktop\SteamSetup.exeSection loaded: netutils.dllJump to behavior
        Source: C:\Users\user\Desktop\SteamSetup.exeSection loaded: uxtheme.dllJump to behavior
        Source: C:\Users\user\Desktop\SteamSetup.exeSection loaded: apphelp.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: mpr.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: version.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: netapi32.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: winhttp.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: netutils.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: uxtheme.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: kernel.appcore.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: iconcodecservice.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: windowscodecs.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: wtsapi32.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: winsta.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: textinputframework.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: coreuicomponents.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: coremessaging.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: ntmarta.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: coremessaging.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: wintypes.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: wintypes.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: wintypes.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: windows.storage.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: wldp.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: profapi.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: shfolder.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: rstrtmgr.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: ncrypt.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: ntasn1.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: textshaping.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: dwmapi.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: sspicli.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: explorerframe.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: sfc.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: sfc_os.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: propsys.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: linkinfo.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: ntshrui.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: srvcli.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: cscapi.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpSection loaded: apphelp.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: apphelp.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: kernel.appcore.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: uxtheme.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: dwrite.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: icu.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: urlmon.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: iertutil.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: srvcli.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: netutils.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: d3dcompiler_47_cor3.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: windowscodecs.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: dwmapi.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: d3d9.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: windows.storage.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: wldp.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: d3d10warp.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: wtsapi32.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: winsta.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: powrprof.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: umpdc.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: dataexchange.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: d3d11.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: dcomp.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: dxgi.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: twinapi.appcore.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: textshaping.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: resourcepolicyclient.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: dxcore.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: textinputframework.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: coreuicomponents.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: coremessaging.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: ntmarta.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: coremessaging.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: wintypes.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: wintypes.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: wintypes.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: msctfui.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: uiautomationcore.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: propsys.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: winmm.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: iphlpapi.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: dhcpcsvc6.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: dhcpcsvc.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: dnsapi.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: winnsi.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: winhttp.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: mswsock.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: wshunix.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: winrnr.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: rasadhlp.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: nlaapi.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: wshbth.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: devobj.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: pnrpnsp.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: napinsp.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: fwpuclnt.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: sspicli.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: schannel.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: mskeyprotect.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: ntasn1.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: ncrypt.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: ncryptsslp.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: msasn1.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: cryptsp.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: rsaenh.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: cryptbase.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeSection loaded: gpapi.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{00BB2765-6A77-11D0-A535-00C04FD7D062}\InProcServer32Jump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwnerJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpWindow found: window name: TMainFormJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpAutomated click: Next
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpAutomated click: Install
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpAutomated click: Next
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpAutomated click: Next
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpAutomated click: Next
        Source: Window RecorderWindow detected: More than 3 window changes detected
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpRegistry value created: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{97C23183-77ED-457C-90C7-3FA73E699316}_is1Jump to behavior
        Source: SteamSetup.exeStatic file information: File size 50219482 > 1048576
        Source: SteamSetup.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
        Source: Binary string: /_/artifacts/obj/WindowsFormsIntegration/x64/Release/net8.0/WindowsFormsIntegration.pdbRSDS source: SteamSetup.tmp, 00000001.00000003.1880994045.0000000005B6D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/System.Resources.Reader/Release/net8.0-windows/System.Resources.Reader.pdbSHA256 source: is-JT9R1.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Security.Cryptography.ProtectedData/Release/net8.0/System.Security.Cryptography.ProtectedData.pdb source: is-OL3NB.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\coreclr\windows.x64.Release\debug\createdump\createdump.pdb source: is-M7PK8.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Text.Json\Release\net8.0\System.Text.Json.pdb source: is-LFOPB.tmp.1.dr
        Source: Binary string: System.ComponentModel.ni.pdb source: is-RT9LP.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Xml.XmlSerializer\Release\net8.0\System.Xml.XmlSerializer.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.IO.Compression.ZipFile\Release\net8.0-windows\System.IO.Compression.ZipFile.pdb source: is-G8384.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Reflection.Metadata\Release\net8.0\System.Reflection.Metadata.pdb source: is-SELO9.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Reflection.Emit.Lightweight\Release\net8.0\System.Reflection.Emit.Lightweight.pdb source: is-8Q6ES.tmp.1.dr
        Source: Binary string: PresentationFramework.Luna.ni.pdb source: is-0QI8B.tmp.1.dr
        Source: Binary string: System.Threading.AccessControl.ni.pdb source: is-6E0AB.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/UIAutomationClientSideProviders/x64/Release/net8.0/UIAutomationClientSideProviders.pdbRSDS source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Runtime\Release\net8.0\System.Runtime.pdbSHA256 source: is-E704A.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Xml.XDocument\Release\net8.0\System.Xml.XDocument.pdbSHA256 source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/System.Globalization/Release/net8.0-windows/System.Globalization.pdbSHA256& source: is-J5Q53.tmp.1.dr
        Source: Binary string: System.Reflection.Metadata.ni.pdb source: is-SELO9.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Xml.Linq/Release/net8.0-windows/System.Xml.Linq.pdbSHA256 source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/System.Windows.Input.Manipulations/x64/Release/net8.0/System.Windows.Input.Manipulations.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000055F0000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/System.Data/Release/net8.0-windows/System.Data.pdbSHA256> source: is-C8Q0I.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Linq\Release\net8.0\System.Linq.pdb source: is-9VBVU.tmp.1.dr
        Source: Binary string: System.Windows.Input.Manipulations.ni.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000055F0000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Xml.XDocument\Release\net8.0\System.Xml.XDocument.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/System.Xml.XmlDocument/Release/net8.0-windows/System.Xml.XmlDocument.pdbSHA256 source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp, is-2TVF9.tmp.1.dr
        Source: Binary string: System.Xaml.ni.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.0000000005620000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/System.Web/Release/net8.0-windows/System.Web.pdb source: is-8SOAE.tmp.1.dr
        Source: Binary string: System.Text.Json.ni.pdb source: is-LFOPB.tmp.1.dr
        Source: Binary string: System.Linq.ni.pdb source: is-9VBVU.tmp.1.dr
        Source: Binary string: System.Formats.Tar.ni.pdb source: is-URA97.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/UIAutomationProvider/x64/Release/net8.0/UIAutomationProvider.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/System.Threading.AccessControl/Release/net8.0-windows/System.Threading.AccessControl.pdb source: is-6E0AB.tmp.1.dr
        Source: Binary string: System.Xml.XPath.XDocument.ni.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/System.Xml/Release/net8.0-windows/System.Xml.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Xml.ReaderWriter\Release\net8.0\System.Xml.ReaderWriter.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: WindowsBase.ni.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\Microsoft.CSharp\Release\net8.0-windows\Microsoft.CSharp.pdb source: is-U5CAB.tmp.1.dr
        Source: Binary string: System.Windows.Presentation.ni.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000055F0000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: System.Text.RegularExpressions.ni.pdb source: is-SNOP4.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Resources.Reader/Release/net8.0-windows/System.Resources.Reader.pdb source: is-JT9R1.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Windows/Release/net8.0-windows/System.Windows.pdbSHA256 source: is-7D57R.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Net.Requests\Release\net8.0-windows\System.Net.Requests.pdbSHA256@ source: is-IU0LQ.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Data/Release/net8.0-windows/System.Data.pdb source: is-C8Q0I.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Xml.ReaderWriter\Release\net8.0\System.Xml.ReaderWriter.pdbSHA256 source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.ComponentModel\Release\net8.0\System.ComponentModel.pdb source: is-RT9LP.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Memory\Release\net8.0\System.Memory.pdb source: is-219L9.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Data.DataSetExtensions/Release/net8.0-windows/System.Data.DataSetExtensions.pdbSHA256 source: is-5A8TQ.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Reflection.Emit.Lightweight\Release\net8.0\System.Reflection.Emit.Lightweight.pdbSHA256 source: is-8Q6ES.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Configuration.ConfigurationManager/Release/net8.0/System.Configuration.ConfigurationManager.pdb source: is-EVMTH.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\fxr\standalone\hostfxr.pdb source: is-21558.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Data.DataSetExtensions/Release/net8.0-windows/System.Data.DataSetExtensions.pdb source: is-5A8TQ.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/WindowsBase/x64/Release/net8.0/WindowsBase.pdbRSDS#F source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: UIAutomationProvider.ni.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/System.Xml.Serialization/Release/net8.0-windows/System.Xml.Serialization.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Net.Requests\Release\net8.0-windows\System.Net.Requests.pdb source: is-IU0LQ.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Runtime.InteropServices\Release\net8.0\System.Runtime.InteropServices.pdb source: is-3DQQ4.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Numerics/Release/net8.0-windows/System.Numerics.pdb source: is-G9TVR.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Windows/Release/net8.0-windows/System.Windows.pdb source: is-7D57R.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Xml/Release/net8.0-windows/System.Xml.pdbSHA256 source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/PresentationFramework.Luna/x64/Release/net8.0/PresentationFramework.Luna.pdb source: is-0QI8B.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\coreclr\windows.x64.Release\debug\createdump\createdump.pdb===GCTL source: is-M7PK8.tmp.1.dr
        Source: Binary string: Microsoft.CSharp.ni.pdb source: is-U5CAB.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Windows.Presentation/x64/Release/net8.0/System.Windows.Presentation.pdbRSDS source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000055F0000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: System.Net.WebProxy.ni.pdb source: is-3U4SF.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Globalization/Release/net8.0-windows/System.Globalization.pdb source: is-J5Q53.tmp.1.dr
        Source: Binary string: UIAutomationClient.ni.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Formats.Tar\Release\net8.0-windows\System.Formats.Tar.pdb source: is-URA97.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/WindowsBase/x64/Release/net8.0/WindowsBase.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: System.IO.Compression.ZipFile.ni.pdb source: is-G8384.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Numerics/Release/net8.0-windows/System.Numerics.pdbSHA256s# source: is-G9TVR.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdbGCTL source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/System.Configuration/Release/net8.0-windows/System.Configuration.pdb source: is-KSMQT.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Console\Release\net8.0-windows\System.Console.pdb source: is-QLJJ1.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Design.Facade/Release/net8.0/System.Design.pdb source: is-7IP4F.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Xml.Linq/Release/net8.0-windows/System.Xml.Linq.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Xml.XmlSerializer\Release\net8.0\System.Xml.XmlSerializer.pdbSHA256 source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/System.Configuration.ConfigurationManager/Release/net8.0/System.Configuration.ConfigurationManager.pdbSHA256 source: is-EVMTH.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/WindowsFormsIntegration/x64/Release/net8.0/WindowsFormsIntegration.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.0000000005B6D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb source: Steam2.exe, 00000003.00000000.1879341006.00007FF69F827000.00000002.00000001.01000000.00000009.sdmp
        Source: Binary string: UIAutomationClientSideProviders.ni.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\coreclr\windows.x64.Release\dlls\mscorrc\mscorrc.pdb source: is-G721R.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Xaml/x64/Release/net8.0/System.Xaml.pdbRSDS source: SteamSetup.tmp, 00000001.00000003.1880994045.0000000005620000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: System.Memory.ni.pdb source: is-219L9.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Core/Release/net8.0-windows/System.Core.pdb source: is-N6T5R.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Xml.XPath.XDocument\Release\net8.0\System.Xml.XPath.XDocument.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Xml.XPath\Release\net8.0\System.Xml.XPath.pdbSHA256] source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\bin\wpfgfx\x64\Release\wpfgfx_cor3.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.0000000005B6D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/System.Web/Release/net8.0-windows/System.Web.pdbSHA256 source: is-8SOAE.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Net.WebProxy\Release\net8.0\System.Net.WebProxy.pdb source: is-3U4SF.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Data.Common\Release\net8.0\System.Data.Common.pdb source: is-S7M74.tmp.1.dr
        Source: Binary string: System.Net.Requests.ni.pdb source: is-IU0LQ.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Xml.Serialization/Release/net8.0-windows/System.Xml.Serialization.pdbSHA256 source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/System.Xaml/x64/Release/net8.0/System.Xaml.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.0000000005620000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: System.Runtime.InteropServices.ni.pdb source: is-3DQQ4.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/UIAutomationTypes/x64/Release/net8.0/UIAutomationTypes.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\fxr\standalone\hostfxr.pdbxxxGCTL source: is-21558.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Xml.XmlDocument/Release/net8.0-windows/System.Xml.XmlDocument.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp, is-2TVF9.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Configuration/Release/net8.0-windows/System.Configuration.pdbSHA256l8 source: is-KSMQT.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.IO.Packaging/Release/net8.0/System.IO.Packaging.pdb source: is-O2VS5.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/UIAutomationClientSideProviders/x64/Release/net8.0/UIAutomationClientSideProviders.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Linq\Release\net8.0\System.Linq.pdbSHA256 source: is-9VBVU.tmp.1.dr
        Source: Binary string: UIAutomationTypes.ni.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: System.Configuration.ConfigurationManager.ni.pdb source: is-EVMTH.tmp.1.dr
        Source: Binary string: System.Console.ni.pdb source: is-QLJJ1.tmp.1.dr
        Source: Binary string: System.Security.Cryptography.ProtectedData.ni.pdb source: is-OL3NB.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Xml.XPath\Release\net8.0\System.Xml.XPath.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/System.Core/Release/net8.0-windows/System.Core.pdbSHA2564- source: is-N6T5R.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Runtime\Release\net8.0\System.Runtime.pdb source: is-E704A.tmp.1.dr
        Source: Binary string: WindowsFormsIntegration.ni.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.0000000005B6D000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdbmmmGCTL source: Steam2.exe, 00000003.00000000.1879341006.00007FF69F827000.00000002.00000001.01000000.00000009.sdmp
        Source: Binary string: System.Data.Common.ni.pdb source: is-S7M74.tmp.1.dr
        Source: Binary string: /_/artifacts/obj/System.Windows.Presentation/x64/Release/net8.0/System.Windows.Presentation.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000055F0000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: /_/artifacts/obj/UIAutomationClient/x64/Release/net8.0/UIAutomationClient.pdb source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Text.RegularExpressions\Release\net8.0\System.Text.RegularExpressions.pdb source: is-SNOP4.tmp.1.dr
        Source: Binary string: System.IO.Packaging.ni.pdb source: is-O2VS5.tmp.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Net.WebProxy\Release\net8.0\System.Net.WebProxy.pdbSHA256 source: is-3U4SF.tmp.1.dr
        Source: is-BV18A.tmp.1.drStatic PE information: 0x82AF122D [Fri Jun 24 06:58:53 2039 UTC]
        Source: SteamSetup.exeStatic PE information: section name: .didata
        Source: SteamSetup.tmp.0.drStatic PE information: section name: .didata
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Text.Json.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-IU0LQ.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Cryptography.Primitives.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Reflection.Primitives.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.InteropServices.RuntimeInformation.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-FFGT1.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework-SystemData.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-J5A62.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-OHS2U.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-5UA7J.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Cryptography.Xml.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-03T8C.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Cryptography.Encoding.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-NMQB8.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-P1CEB.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-NI148.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\Microsoft.Win32.Primitives.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-N6T5R.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-9GBK7.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationUI.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-21558.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-3T158.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\Microsoft.Win32.Registry.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Cryptography.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-GOJFJ.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.PerformanceCounter.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-FER0U.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Windows.Forms.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Threading.Thread.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exe (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.Hashing.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Resources.ResourceManager.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\createdump.exe (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-FGBU1.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\Microsoft.Win32.Registry.AccessControl.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-E537O.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-FPFGC.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-TC3UL.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.Compression.Native.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.Serialization.Formatters.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-B4T90.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Collections.Concurrent.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-393CK.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-2ACL7.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\protobuf-net.Core.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.Security.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\mscordaccore.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Transactions.Local.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.DiagnosticSource.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Xml.Serialization.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-OFR4B.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Xml.XmlDocument.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-RQKJN.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Private.Xml.Linq.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.CodeDom.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Reflection.Emit.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-6FLE2.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.EventLog.Messages.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Web.HttpUtility.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-CB3FM.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-LMELL.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-3NS6I.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-3CV6V.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Reflection.DispatchProxy.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-353H2.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-0QI8B.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-D583Q.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-PR1SN.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\Microsoft.DiaSymReader.Native.amd64.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-L7DHN.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-0ED3E.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-4IO64.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-4JUH3.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Text.Encodings.Web.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Resources.Writer.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Configuration.ConfigurationManager.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-OL3NB.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework.Royale.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Windows.Forms.Primitives.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.InteropServices.JavaScript.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.Compression.Brotli.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-SELO9.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-RMN2A.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-S7M74.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-PCJI1.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-175RN.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\mscorlib.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationNative_cor3.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-R29DJ.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-23N9N.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-0TTDC.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Resources.Extensions.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Transactions.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-2E66P.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-NH22G.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-842D2.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Cryptography.Csp.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Private.CoreLib.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-PP8SL.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-TAUBR.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\Microsoft.Win32.SystemEvents.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-URA97.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.Tracing.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-K613I.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-V1K2R.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-G5ANC.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-0KAJQ.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-G9TVR.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework-SystemXmlLinq.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-6E0AB.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-3DQQ4.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-SG76T.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\D3DCompiler_47_cor3.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.Serialization.Json.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.NameResolution.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-7V7V0.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Dynamic.Runtime.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework.Aero.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.IsolatedStorage.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-8SOAE.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework-SystemXml.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.Sockets.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-O2VS5.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Linq.Queryable.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-U5R7O.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-B0N4M.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.CompilerServices.VisualC.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-AJ60V.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.AccessControl.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Console.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-IBGJR.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-FUODR.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-1P5NQ.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\WindowsFormsIntegration.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-PJDI3.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework-SystemCore.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-O5P26.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Text.RegularExpressions.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-OMU5T.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-ISS47.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.Packaging.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.Serialization.Primitives.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-C1TIS.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Cryptography.Pkcs.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Threading.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Windows.Input.Manipulations.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.Pipes.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.Intrinsics.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-BRU3O.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Windows.Controls.Ribbon.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-ERNCA.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.WebSockets.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-41G2F.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.TextWriterTraceListener.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationCore.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Windows.Forms.Design.Editors.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-NK6GU.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\PenImc_cor3.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-7JPAQ.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-M7PK8.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-GK1S4.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-6KRKJ.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Cryptography.Cng.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-OD7NK.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\hostpolicy.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-V92IG.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.Tools.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.Ping.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-VE7BR.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\wpfgfx_cor3.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-7F6KI.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-NGLMS.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Threading.AccessControl.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-3II23.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-ICB9T.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-JIDK5.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Web.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-H3VRF.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-1SION.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-5A8TQ.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-MJMLB.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Principal.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Cryptography.X509Certificates.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Threading.Timer.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-IOHDI.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Data.Common.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Xml.XPath.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.ComponentModel.Annotations.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-V5O72.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Reflection.Metadata.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\UIAutomationProvider.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Formats.Asn1.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.Numerics.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Collections.Specialized.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-O9S7G.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-SHJIR.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-SA04C.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-1GT60.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Xml.Linq.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Private.Uri.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Reflection.Emit.ILGeneration.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-G721R.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-MT7MH.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Printing.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.Quic.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.ServiceProcess.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-EPD79.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-PS2Q9.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-NBGUE.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-4O1SG.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-KTNL3.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-06ALL.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.Serialization.Xml.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\coreclr.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-7D57R.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\Microsoft.VisualBasic.Forms.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.ValueTuple.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.FileSystem.Watcher.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-KSMQT.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\Microsoft.VisualBasic.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-621DK.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-KPNTM.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-3J2EH.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-46PES.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.TraceSource.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Globalization.Extensions.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\vcruntime140_cor3.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework.Luna.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-QLJJ1.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-7PK1K.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-3GH17.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework.Classic.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-U5CAB.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\SteamKit2.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Core.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-TK2A2.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework.AeroLite.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Xml.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.Pipes.AccessControl.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Reflection.TypeExtensions.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-8Q6ES.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-JS4JU.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.AppContext.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-E704A.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Buffers.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\UIAutomationClientSideProviders.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-C4PDK.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.Http.Json.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Collections.Immutable.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.FileSystem.AccessControl.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-JT9R1.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-F7HS6.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-E52FV.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-J5Q53.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-RPC5P.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Drawing.Design.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-BPLBO.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-VBC6I.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\DirectWriteForwarder.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-C0NRL.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-LFOPB.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Design.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.Compression.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Text.Encoding.Extensions.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.WebClient.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Collections.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-IIQJM.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-FVIIK.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.Http.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-82OGO.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-C6SPK.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-FHTIL.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\protobuf-net.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\mscordaccore_amd64_amd64_8.0.824.36612.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-KM93B.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Threading.Tasks.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.ComponentModel.TypeConverter.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\clrjit.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-E917C.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-TH0C6.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Reflection.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Text.Encoding.CodePages.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.Compression.FileSystem.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-2UHB1.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Threading.Tasks.Dataflow.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-0A2IM.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.SecureString.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\msquic.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Windows.Presentation.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.Mail.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Numerics.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-OF9H5.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Xaml.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-E88LT.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.Extensions.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-QQFQ0.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\WindowsBase.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-9VBVU.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-FQLAJ.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Threading.Channels.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-S9H2V.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Linq.Parallel.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.NetworkInformation.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Private.Xml.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.WebHeaderCollection.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.HttpListener.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-0BV5K.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-G8384.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\netstandard.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-RH90K.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-BMK4J.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.WebProxy.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.DirectoryServices.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-NOPIK.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-LKC3R.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-HUU3F.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-DE47S.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-CTNSH.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Xml.XmlSerializer.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.UnmanagedMemoryStream.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-8JNSQ.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-RT9LP.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-BV18A.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\UIAutomationTypes.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-IKSD2.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-L9IRH.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\clrgc.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-C4VI1.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-IDQQK.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-HT29O.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Drawing.Primitives.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Xml.ReaderWriter.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Numerics.Vectors.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-UCH6K.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.Primitives.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-0R6D5.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Private.DataContractSerialization.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.InteropServices.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Xml.XPath.XDocument.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-NES76.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Claims.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-D5RPK.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.Loader.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.ServiceModel.Web.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\UIAutomationClient.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-EVMTH.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-BSKQN.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-FUJRK.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-I9KME.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-IM89D.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-DN9A9.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-8O1SP.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-0I40G.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-EL3N4.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-9A0PH.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Principal.Windows.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-QB0O9.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\Microsoft.VisualBasic.Core.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Threading.Tasks.Extensions.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\mscordbi.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-54V5Q.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-QQMQ0.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-J5UVU.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Formats.Tar.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.FileSystem.Primitives.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Reflection.Extensions.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Threading.ThreadPool.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework.Aero2.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Data.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-0R4RR.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-IJCCG.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Linq.Expressions.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-9K5SP.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-T2AEF.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Collections.NonGeneric.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.EventLog.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-C1QE8.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Configuration.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-OMLDU.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-624HU.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.CompilerServices.Unsafe.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-2VB07.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-N0JVU.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-6UJNJ.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\hostfxr.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-LB3BN.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Windows.Extensions.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.Compression.ZipFile.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-07LBE.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Memory.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-J4F54.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.Serialization.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-M1IBB.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.MemoryMappedFiles.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.FileSystem.DriveInfo.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework-SystemDrawing.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-2TVF9.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-5I1AN.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-OEM2B.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Cryptography.ProtectedData.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-MQN3F.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\mscorrc.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\ReachFramework.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Cryptography.OpenSsl.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.Requests.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.ComponentModel.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-HKSM3.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.Debug.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-H6DF9.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-CG1VF.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.dll (copy)Jump to dropped file
        Source: C:\Users\user\Desktop\SteamSetup.exeFile created: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-S9871.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-83U1I.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Permissions.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-SNOP4.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.Contracts.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.WebSockets.Client.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.ObjectModel.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-160D2.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-0CFKI.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Drawing.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-0AA2H.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-6UT8P.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Xml.XDocument.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Globalization.Calendars.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-CDVC3.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Drawing.Common.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-80BQ8.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-RUGAU.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Windows.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-HQ8MG.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Temp\is-457S0.tmp\_isetup\_setup64.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.ServicePoint.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.FileSystem.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-M0K5L.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-VC35U.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\Accessibility.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Globalization.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.StackTrace.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.Handles.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\unins000.exe (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Text.Encoding.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-OLKB5.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.ComponentModel.EventBasedAsync.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-MQH5V.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-BGSNO.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-RNA4A.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-5R65M.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-6A3I2.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-OS7F4.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-NMQLB.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-7IP4F.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-C8Q0I.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.Process.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Resources.Reader.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-9H3PC.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-HTHBE.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-R4HMS.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-NA0P8.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-219L9.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-T8PJ7.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-HVE4F.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-CO8N6.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-M4HRH.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Threading.Overlapped.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.ComponentModel.Primitives.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Data.DataSetExtensions.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Linq.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-J1ACH.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\clretwrc.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-85E29.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Cryptography.Algorithms.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-322AN.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Reflection.Emit.Lightweight.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.ComponentModel.DataAnnotations.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-4RNUS.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\Microsoft.CSharp.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-3U4SF.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-16F0N.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.FileVersionInfo.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Threading.Tasks.Parallel.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-85LFJ.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\System.Windows.Forms.Design.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-1274N.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Local\Programs\SteamClient\is-HF7IL.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam.lnkJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRootJump to behavior
        Source: C:\Users\user\Desktop\SteamSetup.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeMemory allocated: 2CD65900000 memory reserve | memory write watchJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeWindow / User API: threadDelayed 392Jump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeWindow / User API: threadDelayed 924Jump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeWindow / User API: threadDelayed 457Jump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeWindow / User API: threadDelayed 6609Jump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Text.Json.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Cryptography.Primitives.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-IU0LQ.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.InteropServices.RuntimeInformation.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Reflection.Primitives.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-FFGT1.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework-SystemData.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-OHS2U.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-J5A62.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Cryptography.Xml.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-5UA7J.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-03T8C.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Cryptography.Encoding.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-NMQB8.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-P1CEB.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-NI148.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\Microsoft.Win32.Primitives.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-N6T5R.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-9GBK7.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationUI.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-21558.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-3T158.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\Microsoft.Win32.Registry.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Cryptography.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-GOJFJ.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.PerformanceCounter.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-FER0U.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Windows.Forms.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Threading.Thread.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.Hashing.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Resources.ResourceManager.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\createdump.exe (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-FGBU1.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\Microsoft.Win32.Registry.AccessControl.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-E537O.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-FPFGC.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-TC3UL.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.Serialization.Formatters.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.Compression.Native.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-B4T90.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Collections.Concurrent.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-393CK.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-2ACL7.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\protobuf-net.Core.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.Security.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\mscordaccore.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Transactions.Local.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.DiagnosticSource.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Xml.Serialization.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-OFR4B.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Xml.XmlDocument.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-RQKJN.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Private.Xml.Linq.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.CodeDom.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Reflection.Emit.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-6FLE2.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.EventLog.Messages.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Web.HttpUtility.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-CB3FM.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-LMELL.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-3NS6I.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Reflection.DispatchProxy.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-3CV6V.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-353H2.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-0QI8B.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-D583Q.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-PR1SN.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\Microsoft.DiaSymReader.Native.amd64.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-L7DHN.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-0ED3E.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-4IO64.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-4JUH3.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Text.Encodings.Web.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Resources.Writer.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Configuration.ConfigurationManager.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework.Royale.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Windows.Forms.Primitives.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-OL3NB.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.InteropServices.JavaScript.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.Compression.Brotli.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-SELO9.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-RMN2A.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-S7M74.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-PCJI1.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationNative_cor3.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\mscorlib.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-175RN.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-R29DJ.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-0TTDC.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-23N9N.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Transactions.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Resources.Extensions.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-2E66P.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-NH22G.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-842D2.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Cryptography.Csp.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Private.CoreLib.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-PP8SL.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-TAUBR.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\Microsoft.Win32.SystemEvents.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-URA97.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.Tracing.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-K613I.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-G5ANC.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-V1K2R.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-0KAJQ.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-G9TVR.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework-SystemXmlLinq.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-6E0AB.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-3DQQ4.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-SG76T.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.Serialization.Json.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.NameResolution.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Dynamic.Runtime.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-7V7V0.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework.Aero.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.IsolatedStorage.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-8SOAE.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework-SystemXml.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.Sockets.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-O2VS5.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Linq.Queryable.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-B0N4M.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-U5R7O.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.CompilerServices.VisualC.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-AJ60V.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.AccessControl.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-IBGJR.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Console.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-FUODR.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-1P5NQ.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\WindowsFormsIntegration.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-PJDI3.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework-SystemCore.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-O5P26.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Text.RegularExpressions.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-OMU5T.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-ISS47.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.Packaging.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.Serialization.Primitives.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-C1TIS.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Cryptography.Pkcs.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Threading.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Windows.Input.Manipulations.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.Pipes.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.Intrinsics.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-BRU3O.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Windows.Controls.Ribbon.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-ERNCA.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.WebSockets.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-41G2F.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.TextWriterTraceListener.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationCore.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Windows.Forms.Design.Editors.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\PenImc_cor3.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-NK6GU.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-7JPAQ.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-M7PK8.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-GK1S4.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-6KRKJ.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Cryptography.Cng.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-OD7NK.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\hostpolicy.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-V92IG.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.Ping.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.Tools.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\wpfgfx_cor3.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-VE7BR.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-7F6KI.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-NGLMS.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Threading.AccessControl.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-3II23.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-ICB9T.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-JIDK5.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Web.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-H3VRF.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-1SION.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-5A8TQ.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-MJMLB.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Principal.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Cryptography.X509Certificates.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Threading.Timer.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Data.Common.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-IOHDI.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Xml.XPath.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.ComponentModel.Annotations.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Reflection.Metadata.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\UIAutomationProvider.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-V5O72.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Formats.Asn1.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.Numerics.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Collections.Specialized.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-O9S7G.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-SA04C.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-SHJIR.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-1GT60.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Xml.Linq.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Private.Uri.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Reflection.Emit.ILGeneration.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-G721R.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-MT7MH.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Printing.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.Quic.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.ServiceProcess.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-EPD79.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-PS2Q9.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-NBGUE.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-4O1SG.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-KTNL3.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.Serialization.Xml.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-06ALL.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\coreclr.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-7D57R.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\Microsoft.VisualBasic.Forms.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.ValueTuple.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.FileSystem.Watcher.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-KSMQT.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\Microsoft.VisualBasic.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-621DK.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-KPNTM.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-3J2EH.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-46PES.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.TraceSource.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Globalization.Extensions.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\vcruntime140_cor3.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework.Luna.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-QLJJ1.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-7PK1K.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework.Classic.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-3GH17.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\SteamKit2.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-U5CAB.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Core.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-TK2A2.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework.AeroLite.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Xml.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.Pipes.AccessControl.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Reflection.TypeExtensions.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-8Q6ES.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-JS4JU.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.AppContext.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-E704A.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\UIAutomationClientSideProviders.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Buffers.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-C4PDK.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.Http.Json.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Collections.Immutable.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.FileSystem.AccessControl.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-JT9R1.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-F7HS6.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-E52FV.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-J5Q53.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-RPC5P.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Drawing.Design.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-BPLBO.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\DirectWriteForwarder.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-VBC6I.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-C0NRL.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-LFOPB.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Design.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.Compression.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Text.Encoding.Extensions.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.WebClient.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Collections.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-FVIIK.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-IIQJM.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.Http.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-C6SPK.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-82OGO.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-FHTIL.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\mscordaccore_amd64_amd64_8.0.824.36612.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\protobuf-net.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-KM93B.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Threading.Tasks.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.ComponentModel.TypeConverter.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\clrjit.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-E917C.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Reflection.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-TH0C6.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Text.Encoding.CodePages.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.Compression.FileSystem.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-2UHB1.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Threading.Tasks.Dataflow.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-0A2IM.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.SecureString.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Windows.Presentation.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\msquic.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.Mail.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Numerics.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-OF9H5.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Xaml.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.Extensions.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-E88LT.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-QQFQ0.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\WindowsBase.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-9VBVU.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-FQLAJ.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Threading.Channels.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-S9H2V.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Linq.Parallel.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.NetworkInformation.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Private.Xml.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.WebHeaderCollection.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.HttpListener.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-0BV5K.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-G8384.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\netstandard.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-RH90K.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-BMK4J.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.WebProxy.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.DirectoryServices.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-NOPIK.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-LKC3R.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-HUU3F.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-DE47S.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-CTNSH.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Xml.XmlSerializer.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.UnmanagedMemoryStream.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-8JNSQ.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-RT9LP.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\UIAutomationTypes.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-BV18A.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-IKSD2.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-L9IRH.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\clrgc.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-C4VI1.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-IDQQK.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-HT29O.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Drawing.Primitives.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Xml.ReaderWriter.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Numerics.Vectors.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-UCH6K.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.Primitives.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-0R6D5.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Private.DataContractSerialization.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.InteropServices.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Xml.XPath.XDocument.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Claims.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-NES76.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-D5RPK.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.Loader.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.ServiceModel.Web.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\UIAutomationClient.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-BSKQN.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-EVMTH.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-FUJRK.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-I9KME.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-IM89D.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-DN9A9.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-8O1SP.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-0I40G.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-EL3N4.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-9A0PH.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Principal.Windows.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-QB0O9.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\Microsoft.VisualBasic.Core.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Threading.Tasks.Extensions.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\mscordbi.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-54V5Q.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-QQMQ0.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-J5UVU.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Formats.Tar.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.FileSystem.Primitives.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Reflection.Extensions.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Threading.ThreadPool.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Data.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework.Aero2.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-0R4RR.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Linq.Expressions.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-IJCCG.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-9K5SP.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-T2AEF.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.EventLog.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Collections.NonGeneric.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Configuration.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-C1QE8.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-OMLDU.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-624HU.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.CompilerServices.Unsafe.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-2VB07.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-N0JVU.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-6UJNJ.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\hostfxr.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-LB3BN.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Windows.Extensions.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.Compression.ZipFile.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Memory.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-07LBE.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-J4F54.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.Serialization.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-M1IBB.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.MemoryMappedFiles.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.FileSystem.DriveInfo.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework-SystemDrawing.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-2TVF9.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Cryptography.ProtectedData.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-5I1AN.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-OEM2B.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-MQN3F.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\mscorrc.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Cryptography.OpenSsl.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\ReachFramework.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.Requests.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.ComponentModel.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.Debug.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-HKSM3.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-CG1VF.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-H6DF9.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-S9871.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Permissions.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-SNOP4.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.Contracts.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.ObjectModel.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.WebSockets.Client.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-160D2.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Drawing.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-0CFKI.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-0AA2H.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-6UT8P.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Xml.XDocument.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Globalization.Calendars.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-CDVC3.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Drawing.Common.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-RUGAU.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-80BQ8.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Windows.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-HQ8MG.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-457S0.tmp\_isetup\_setup64.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Net.ServicePoint.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.FileSystem.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-M0K5L.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-VC35U.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\Accessibility.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Globalization.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.StackTrace.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Runtime.Handles.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\unins000.exe (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Text.Encoding.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-OLKB5.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.ComponentModel.EventBasedAsync.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-MQH5V.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-BGSNO.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-5R65M.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-RNA4A.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-6A3I2.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-OS7F4.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-NMQLB.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-7IP4F.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-C8Q0I.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Resources.Reader.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.Process.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-9H3PC.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-HTHBE.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-R4HMS.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-NA0P8.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-219L9.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-T8PJ7.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-HVE4F.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-CO8N6.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-M4HRH.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Threading.Overlapped.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.ComponentModel.Primitives.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Data.DataSetExtensions.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Linq.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-J1ACH.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\clretwrc.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-85E29.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Security.Cryptography.Algorithms.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-322AN.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Reflection.Emit.Lightweight.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.ComponentModel.DataAnnotations.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-4RNUS.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\Microsoft.CSharp.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-16F0N.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-3U4SF.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.FileVersionInfo.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Threading.Tasks.Parallel.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\System.Windows.Forms.Design.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-85LFJ.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-1274N.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Programs\SteamClient\is-HF7IL.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeFile opened: PhysicalDrive0Jump to behavior
        Source: SteamSetup.tmp, 00000001.00000003.1890591391.0000000000911000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpProcess information queried: ProcessInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeProcess token adjusted: DebugJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeMemory allocated: page read and write | page guardJump to behavior
        Source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: _hwndProgman
        Source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: Shell_TrayWnd
        Source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: Progman
        Source: SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: IsProgmanWindow
        Source: C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmpQueries volume information: C:\ VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
        ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
        Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
        Command and Scripting Interpreter
        1
        Windows Service
        1
        Windows Service
        1
        Masquerading
        OS Credential Dumping1
        Query Registry
        Remote ServicesData from Local System1
        Encrypted Channel
        Exfiltration Over Other Network MediumAbuse Accessibility Features
        CredentialsDomainsDefault Accounts1
        Scheduled Task/Job
        1
        Scheduled Task/Job
        2
        Process Injection
        2
        Virtualization/Sandbox Evasion
        LSASS Memory11
        Security Software Discovery
        Remote Desktop ProtocolData from Removable Media1
        Non-Standard Port
        Exfiltration Over BluetoothNetwork Denial of Service
        Email AddressesDNS ServerDomain AccountsAt1
        Registry Run Keys / Startup Folder
        1
        Scheduled Task/Job
        1
        Disable or Modify Tools
        Security Account Manager2
        Virtualization/Sandbox Evasion
        SMB/Windows Admin SharesData from Network Shared Drive1
        Ingress Tool Transfer
        Automated ExfiltrationData Encrypted for Impact
        Employee NamesVirtual Private ServerLocal AccountsCron1
        DLL Side-Loading
        1
        Registry Run Keys / Startup Folder
        2
        Process Injection
        NTDS2
        Process Discovery
        Distributed Component Object ModelInput Capture2
        Non-Application Layer Protocol
        Traffic DuplicationData Destruction
        Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon Script1
        DLL Side-Loading
        1
        Timestomp
        LSA Secrets1
        Application Window Discovery
        SSHKeylogging3
        Application Layer Protocol
        Scheduled TransferData Encrypted for Impact
        Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
        DLL Side-Loading
        Cached Domain Credentials2
        System Owner/User Discovery
        VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
        DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup ItemsCompile After DeliveryDCSync1
        File and Directory Discovery
        Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
        Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/JobIndicator Removal from ToolsProc Filesystem22
        System Information Discovery
        Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Is Windows Process
        • Number of created Registry Values
        • Number of created Files
        • Visual Basic
        • Delphi
        • Java
        • .Net C# or VB.NET
        • C, C++ or other language
        • Is malicious
        • Internet

        This section contains all screenshots as thumbnails, including those not shown in the slideshow.


        windows-stand
        SourceDetectionScannerLabelLink
        SteamSetup.exe0%ReversingLabs
        SourceDetectionScannerLabelLink
        C:\Users\user\AppData\Local\Programs\SteamClient\Accessibility.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\D3DCompiler_47_cor3.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\DirectWriteForwarder.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\Microsoft.CSharp.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\Microsoft.DiaSymReader.Native.amd64.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\Microsoft.VisualBasic.Core.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\Microsoft.VisualBasic.Forms.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\Microsoft.VisualBasic.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\Microsoft.Win32.Primitives.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\Microsoft.Win32.Registry.AccessControl.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\Microsoft.Win32.Registry.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\Microsoft.Win32.SystemEvents.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\PenImc_cor3.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\PresentationCore.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework-SystemCore.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework-SystemData.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework-SystemDrawing.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework-SystemXml.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework-SystemXmlLinq.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework.Aero.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework.Aero2.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework.AeroLite.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework.Classic.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework.Luna.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework.Royale.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\PresentationFramework.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\PresentationNative_cor3.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\PresentationUI.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\ReachFramework.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exe (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\SteamKit2.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.AppContext.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Buffers.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.CodeDom.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Collections.Concurrent.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Collections.Immutable.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Collections.NonGeneric.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Collections.Specialized.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Collections.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.ComponentModel.Annotations.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.ComponentModel.DataAnnotations.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.ComponentModel.EventBasedAsync.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.ComponentModel.Primitives.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.ComponentModel.TypeConverter.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.ComponentModel.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Configuration.ConfigurationManager.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Configuration.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Console.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Core.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Data.Common.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Data.DataSetExtensions.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Data.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Design.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.Contracts.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.Debug.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.DiagnosticSource.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.EventLog.Messages.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.EventLog.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.FileVersionInfo.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.PerformanceCounter.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.Process.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.StackTrace.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.TextWriterTraceListener.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.Tools.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.TraceSource.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Diagnostics.Tracing.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.DirectoryServices.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Drawing.Common.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Drawing.Design.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Drawing.Primitives.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Drawing.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Dynamic.Runtime.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Formats.Asn1.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Formats.Tar.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Globalization.Calendars.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Globalization.Extensions.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.Globalization.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.Compression.Brotli.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.Compression.FileSystem.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.Compression.Native.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.Compression.ZipFile.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.Compression.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.FileSystem.AccessControl.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.FileSystem.DriveInfo.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.FileSystem.Primitives.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.FileSystem.Watcher.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.FileSystem.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.Hashing.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.IsolatedStorage.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.MemoryMappedFiles.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.Packaging.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Programs\SteamClient\System.IO.Pipes.AccessControl.dll (copy)0%ReversingLabs
        No Antivirus matches
        No Antivirus matches
        SourceDetectionScannerLabelLink
        http://uri.etsi.org/01903/v1.2.2#SSOFTWARE0%Avira URL Cloudsafe
        https://www.steam.com/Q6C0%Avira URL Cloudsafe
        https://www.steam.com/Q9Q0%Avira URL Cloudsafe
        http://uri.etsi.org/01903/v1.2.2#bhttp://uri.etsi.org/01903/v1.2.2#SignedProperties0%Avira URL Cloudsafe
        https://www.steam.com/0%Avira URL Cloudsafe
        http://uri.etsi.org/01903/v1.2.2#SignedProperties0%Avira URL Cloudsafe
        NameIPActiveMaliciousAntivirus DetectionReputation
        cmp1-atl3.steamserver.net
        162.254.199.165
        truefalse
          high
          api.steampowered.com
          104.102.49.254
          truefalse
            high
            cmp2-iad1.steamserver.net
            162.254.192.99
            truefalse
              high
              cmp1-dfw1.steamserver.net
              155.133.253.36
              truefalse
                high
                cmp2-atl3.steamserver.net
                162.254.199.184
                truefalse
                  high
                  cmp2-dfw1.steamserver.net
                  155.133.253.52
                  truefalse
                    high
                    cmp1-iad1.steamserver.net
                    162.254.192.98
                    truefalse
                      high
                      198.187.3.20.in-addr.arpa
                      unknown
                      unknownfalse
                        high
                        NameMaliciousAntivirus DetectionReputation
                        https://cmp1-iad1.steamserver.net/cmsocket/false
                          high
                          https://cmp2-dfw1.steamserver.net/cmsocket/false
                            high
                            https://cmp2-iad1.steamserver.net/cmsocket/false
                              high
                              https://cmp2-atl3.steamserver.net/cmsocket/false
                                high
                                https://api.steampowered.com/ISteamDirectory/GetCMListForConnect/v1/?format=vdf&cellid=0false
                                  high
                                  https://cmp1-dfw1.steamserver.net/cmsocket/false
                                    high
                                    NameSourceMaliciousAntivirus DetectionReputation
                                    https://github.com/dotnet/runtime;is-KSMQT.tmp.1.drfalse
                                      high
                                      https://jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupUSteamSetup.exefalse
                                        high
                                        https://www.steam.com/Q6CSteamSetup.exe, 00000000.00000003.1903609511.0000000002433000.00000004.00001000.00020000.00000000.sdmpfalse
                                        • Avira URL Cloud: safe
                                        unknown
                                        https://aka.ms/dotnet/infois-21558.tmp.1.drfalse
                                          high
                                          https://github.com/dotnet/wpfSteamSetup.tmp, 00000001.00000003.1880994045.0000000005B6D000.00000004.00001000.00020000.00000000.sdmp, SteamSetup.tmp, 00000001.00000003.1880994045.00000000055F0000.00000004.00001000.00020000.00000000.sdmp, SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp, SteamSetup.tmp, 00000001.00000003.1880994045.0000000005620000.00000004.00001000.00020000.00000000.sdmp, is-0QI8B.tmp.1.drfalse
                                            high
                                            https://github.com/mono/linker/issues/1416.is-U5CAB.tmp.1.drfalse
                                              high
                                              https://aka.ms/dotnet-core-applaunch?Architecture:Steam2.exe, 00000003.00000000.1879341006.00007FF69F827000.00000002.00000001.01000000.00000009.sdmpfalse
                                                high
                                                https://aka.ms/dotnet/app-launch-failedSteam2.exe, 00000003.00000000.1879341006.00007FF69F827000.00000002.00000001.01000000.00000009.sdmp, is-21558.tmp.1.drfalse
                                                  high
                                                  http://uri.etsi.org/01903/v1.2.2#bhttp://uri.etsi.org/01903/v1.2.2#SignedPropertiesSteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmpfalse
                                                  • Avira URL Cloud: safe
                                                  unknown
                                                  https://aka.ms/dotnet/sdk-not-foundFailedis-21558.tmp.1.drfalse
                                                    high
                                                    https://aka.ms/dotnet-core-applaunch?Steam2.exe, 00000003.00000000.1879341006.00007FF69F827000.00000002.00000001.01000000.00000009.sdmpfalse
                                                      high
                                                      https://github.com/dotnet/runtime0is-JT9R1.tmp.1.drfalse
                                                        high
                                                        https://aka.ms/dotnet/downloadUsage:is-21558.tmp.1.drfalse
                                                          high
                                                          https://github.com/dotnet/runtimeis-5A8TQ.tmp.1.dr, is-9VBVU.tmp.1.dr, is-3U4SF.tmp.1.dr, is-N6T5R.tmp.1.dr, is-SNOP4.tmp.1.dr, is-3DQQ4.tmp.1.dr, is-EVMTH.tmp.1.dr, is-2TVF9.tmp.1.dr, is-KSMQT.tmp.1.dr, is-LFOPB.tmp.1.dr, is-8Q6ES.tmp.1.dr, is-J5Q53.tmp.1.dr, is-8SOAE.tmp.1.dr, is-O2VS5.tmp.1.dr, is-C8Q0I.tmp.1.dr, is-S7M74.tmp.1.dr, is-7D57R.tmp.1.dr, is-SELO9.tmp.1.dr, is-U5CAB.tmp.1.dr, is-IU0LQ.tmp.1.dr, is-URA97.tmp.1.drfalse
                                                            high
                                                            https://github.com/dotnet/runtimeris-J5Q53.tmp.1.drfalse
                                                              high
                                                              http://uri.etsi.org/01903/v1.2.2#SignedPropertiesSteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmpfalse
                                                              • Avira URL Cloud: safe
                                                              unknown
                                                              https://github.com/dotnet/runtimezXSteamSetup.tmp, 00000001.00000003.1880994045.000000000576D000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                high
                                                                https://github.com/mono/linker/issues/1981is-S7M74.tmp.1.drfalse
                                                                  high
                                                                  https://aka.ms/dotnet-core-applaunch?framework=&framework_version=missing_runtime=true&arch=&rid=&osis-21558.tmp.1.drfalse
                                                                    high
                                                                    http://uri.etsi.org/01903/v1.2.2#SSOFTWARESteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                    • Avira URL Cloud: safe
                                                                    unknown
                                                                    https://aka.ms/dotnet-warnings/is-IU0LQ.tmp.1.drfalse
                                                                      high
                                                                      https://github.com/dotnet/winformsSteamSetup.tmp, 00000001.00000003.1880994045.0000000005B6D000.00000004.00001000.00020000.00000000.sdmp, is-7IP4F.tmp.1.drfalse
                                                                        high
                                                                        https://github.com/dotnet/wpf4SteamSetup.tmp, 00000001.00000003.1880994045.0000000005B6D000.00000004.00001000.00020000.00000000.sdmp, SteamSetup.tmp, 00000001.00000003.1880994045.00000000055F0000.00000004.00001000.00020000.00000000.sdmp, SteamSetup.tmp, 00000001.00000003.1880994045.00000000057A6000.00000004.00001000.00020000.00000000.sdmp, SteamSetup.tmp, 00000001.00000003.1880994045.0000000005620000.00000004.00001000.00020000.00000000.sdmp, is-0QI8B.tmp.1.drfalse
                                                                          high
                                                                          https://www.remobjects.com/psSteamSetup.exe, 00000000.00000003.1688166005.000000007FB50000.00000004.00001000.00020000.00000000.sdmp, SteamSetup.exe, 00000000.00000003.1687407738.0000000002690000.00000004.00001000.00020000.00000000.sdmp, SteamSetup.tmp, 00000001.00000000.1689708207.0000000000401000.00000020.00000001.01000000.00000004.sdmp, is-46PES.tmp.1.drfalse
                                                                            high
                                                                            https://github.com/mono/linker/issues/1906.is-U5CAB.tmp.1.drfalse
                                                                              high
                                                                              https://aka.ms/serializationformat-binary-obsoleteis-EVMTH.tmp.1.dr, is-O2VS5.tmp.1.dr, is-S7M74.tmp.1.dr, is-SELO9.tmp.1.drfalse
                                                                                high
                                                                                https://www.innosetup.com/SteamSetup.exe, 00000000.00000003.1688166005.000000007FB50000.00000004.00001000.00020000.00000000.sdmp, SteamSetup.exe, 00000000.00000003.1687407738.0000000002690000.00000004.00001000.00020000.00000000.sdmp, SteamSetup.tmp, 00000001.00000000.1689708207.0000000000401000.00000020.00000001.01000000.00000004.sdmp, is-46PES.tmp.1.drfalse
                                                                                  high
                                                                                  https://aka.ms/binaryformatteris-EVMTH.tmp.1.dr, is-O2VS5.tmp.1.dr, is-SELO9.tmp.1.drfalse
                                                                                    high
                                                                                    https://github.com/dotnet/linker/issues/2715.is-SNOP4.tmp.1.drfalse
                                                                                      high
                                                                                      https://github.com/dotnet/runtimeHis-8SOAE.tmp.1.drfalse
                                                                                        high
                                                                                        https://aka.ms/dotnet/downloadis-21558.tmp.1.drfalse
                                                                                          high
                                                                                          https://github.com/mono/linker/issues/1187is-S7M74.tmp.1.drfalse
                                                                                            high
                                                                                            https://www.steam.com/SteamSetup.tmp, 00000001.00000003.1692507487.00000000035B0000.00000004.00001000.00020000.00000000.sdmp, SteamSetup.tmp, 00000001.00000003.1887946566.000000000250C000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                            • Avira URL Cloud: safe
                                                                                            unknown
                                                                                            https://www.steam.com/Q9QSteamSetup.tmp, 00000001.00000003.1887946566.000000000250C000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                            • Avira URL Cloud: safe
                                                                                            unknown
                                                                                            • No. of IPs < 25%
                                                                                            • 25% < No. of IPs < 50%
                                                                                            • 50% < No. of IPs < 75%
                                                                                            • 75% < No. of IPs
                                                                                            IPDomainCountryFlagASNASN NameMalicious
                                                                                            162.254.199.165
                                                                                            cmp1-atl3.steamserver.netUnited States
                                                                                            32590VALVE-CORPORATIONUSfalse
                                                                                            155.133.253.52
                                                                                            cmp2-dfw1.steamserver.netGermany
                                                                                            32590VALVE-CORPORATIONUSfalse
                                                                                            162.254.199.184
                                                                                            cmp2-atl3.steamserver.netUnited States
                                                                                            32590VALVE-CORPORATIONUSfalse
                                                                                            104.102.49.254
                                                                                            api.steampowered.comUnited States
                                                                                            16625AKAMAI-ASUSfalse
                                                                                            155.133.253.36
                                                                                            cmp1-dfw1.steamserver.netGermany
                                                                                            32590VALVE-CORPORATIONUSfalse
                                                                                            162.254.192.98
                                                                                            cmp1-iad1.steamserver.netUnited States
                                                                                            32590VALVE-CORPORATIONUSfalse
                                                                                            162.254.192.99
                                                                                            cmp2-iad1.steamserver.netUnited States
                                                                                            32590VALVE-CORPORATIONUSfalse
                                                                                            Joe Sandbox version:41.0.0 Charoite
                                                                                            Analysis ID:1558928
                                                                                            Start date and time:2024-11-19 23:59:11 +01:00
                                                                                            Joe Sandbox product:CloudBasic
                                                                                            Overall analysis duration:0h 8m 9s
                                                                                            Hypervisor based Inspection enabled:false
                                                                                            Report type:full
                                                                                            Cookbook file name:default.jbs
                                                                                            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                                            Number of analysed new started processes analysed:9
                                                                                            Number of new started drivers analysed:0
                                                                                            Number of existing processes analysed:0
                                                                                            Number of existing drivers analysed:0
                                                                                            Number of injected processes analysed:0
                                                                                            Technologies:
                                                                                            • HCA enabled
                                                                                            • EGA enabled
                                                                                            • AMSI enabled
                                                                                            Analysis Mode:default
                                                                                            Analysis stop reason:Timeout
                                                                                            Sample name:SteamSetup.exe
                                                                                            Detection:SUS
                                                                                            Classification:sus24.troj.winEXE@5/496@8/7
                                                                                            EGA Information:Failed
                                                                                            HCA Information:
                                                                                            • Successful, ratio: 100%
                                                                                            • Number of executed functions: 0
                                                                                            • Number of non-executed functions: 0
                                                                                            Cookbook Comments:
                                                                                            • Found application associated with file extension: .exe
                                                                                            • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                                                                                            • Excluded domains from analysis (whitelisted): fs.microsoft.com, ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                                                                                            • Not all processes where analyzed, report is missing behavior information
                                                                                            • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                                                                                            • Report size getting too big, too many NtOpenKeyEx calls found.
                                                                                            • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                                                                            • Report size getting too big, too many NtQueryValueKey calls found.
                                                                                            • VT rate limit hit for: SteamSetup.exe
                                                                                            No simulations
                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                            104.102.49.254http://gtm-cn-j4g3qqvf603.steamproxy1.com/Get hashmaliciousUnknownBrowse
                                                                                            • www.valvesoftware.com/legal.htm
                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                            api.steampowered.comhttps://steamcommunlty-gifts.com/s/HRABGet hashmaliciousUnknownBrowse
                                                                                            • 104.102.49.254
                                                                                            https://steamcommunity-success.com/gift-card/9376695162Get hashmaliciousUnknownBrowse
                                                                                            • 104.102.49.254
                                                                                            https://steamcommunlty-gifts.com/s/HRABGet hashmaliciousUnknownBrowse
                                                                                            • 104.102.49.254
                                                                                            https://steamcommunlty-gifts.com/s/HRABGet hashmaliciousUnknownBrowse
                                                                                            • 104.102.49.254
                                                                                            https://sneamcomnnumnlty.com/h474823487284/geting/activeGet hashmaliciousUnknownBrowse
                                                                                            • 104.102.49.254
                                                                                            https://sneamcomnnumnlty.com/f78493482943/geting/gameGet hashmaliciousUnknownBrowse
                                                                                            • 104.102.49.254
                                                                                            https://sneamcomnnumnlty.com/hfjf748934924/geting/putGet hashmaliciousUnknownBrowse
                                                                                            • 104.102.49.254
                                                                                            https://sneamcomnnumnlty.com/jfh8893040282949023/here/putGet hashmaliciousUnknownBrowse
                                                                                            • 104.102.49.254
                                                                                            https://steamcommunrutty.com/gift/actlvation=Mor85Fhn6w4Get hashmaliciousUnknownBrowse
                                                                                            • 104.102.49.254
                                                                                            http://sneamcomnnumnlty.com/fact/actual/getGet hashmaliciousUnknownBrowse
                                                                                            • 92.122.104.90
                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                            VALVE-CORPORATIONUSIWnUKXop2x.elfGet hashmaliciousMirai, OkiruBrowse
                                                                                            • 103.28.54.20
                                                                                            mirai.arm7.elfGet hashmaliciousMiraiBrowse
                                                                                            • 162.254.195.132
                                                                                            SecuriteInfo.com.Linux.Siggen.9999.16484.11734Get hashmaliciousUnknownBrowse
                                                                                            • 155.133.238.98
                                                                                            zZMmONZWnO.dllGet hashmaliciousWannacryBrowse
                                                                                            • 155.133.248.7
                                                                                            SteamSetup.exeGet hashmaliciousUnknownBrowse
                                                                                            • 205.196.6.229
                                                                                            steam.exeGet hashmaliciousUnknownBrowse
                                                                                            • 205.196.6.226
                                                                                            VALVE-CORPORATIONUSIWnUKXop2x.elfGet hashmaliciousMirai, OkiruBrowse
                                                                                            • 103.28.54.20
                                                                                            mirai.arm7.elfGet hashmaliciousMiraiBrowse
                                                                                            • 162.254.195.132
                                                                                            SecuriteInfo.com.Linux.Siggen.9999.16484.11734Get hashmaliciousUnknownBrowse
                                                                                            • 155.133.238.98
                                                                                            zZMmONZWnO.dllGet hashmaliciousWannacryBrowse
                                                                                            • 155.133.248.7
                                                                                            SteamSetup.exeGet hashmaliciousUnknownBrowse
                                                                                            • 205.196.6.229
                                                                                            steam.exeGet hashmaliciousUnknownBrowse
                                                                                            • 205.196.6.226
                                                                                            AKAMAI-ASUSQuarantineMessage.zipGet hashmaliciousUnknownBrowse
                                                                                            • 23.217.172.185
                                                                                            Benefit Enrollment -wZ5nusm.pdfGet hashmaliciousUnknownBrowse
                                                                                            • 23.203.104.175
                                                                                            Customer forms.pdfGet hashmaliciousUnknownBrowse
                                                                                            • 104.78.188.188
                                                                                            Benefit Enrollment -eGz8VNb.pdfGet hashmaliciousUnknownBrowse
                                                                                            • 23.203.104.175
                                                                                            Integration.pdf www.skype.com.lnkGet hashmaliciousUnknownBrowse
                                                                                            • 96.17.64.171
                                                                                            b.pdfGet hashmaliciousUnknownBrowse
                                                                                            • 23.217.172.185
                                                                                            https://www.bing.com/ck/a?!&&p=5ceef533778c3decJmltdHM9MTcyMzQyMDgwMCZpZ3VpZD0zNjRmNjVlOC1lNTZjLTYxOWQtMTI1Ny03MTNlZTQyYTYwMTImaW5zaWQ9NTE0MA&ptn=3&ver=2&hsh=3&fclid=364f65e8-e56c-619d-1257-713ee42a6012&u=a1aHR0cHM6Ly9sZXhpbnZhcmlhbnQuY29tLw#aHR0cHM6Ly9HMTAuZHpwdndvYnIucnUvdkd5c2dQdC8=Get hashmaliciousUnknownBrowse
                                                                                            • 92.122.18.57
                                                                                            file.exeGet hashmaliciousLummaC, Amadey, Stealc, VidarBrowse
                                                                                            • 23.200.88.15
                                                                                            https://nam.dcv.ms/WLtyQ3priBGet hashmaliciousHTMLPhisherBrowse
                                                                                            • 2.18.121.138
                                                                                            V6QED2Q1WBYVOPEGet hashmaliciousUnknownBrowse
                                                                                            • 23.195.93.152
                                                                                            VALVE-CORPORATIONUSIWnUKXop2x.elfGet hashmaliciousMirai, OkiruBrowse
                                                                                            • 103.28.54.20
                                                                                            mirai.arm7.elfGet hashmaliciousMiraiBrowse
                                                                                            • 162.254.195.132
                                                                                            SecuriteInfo.com.Linux.Siggen.9999.16484.11734Get hashmaliciousUnknownBrowse
                                                                                            • 155.133.238.98
                                                                                            zZMmONZWnO.dllGet hashmaliciousWannacryBrowse
                                                                                            • 155.133.248.7
                                                                                            SteamSetup.exeGet hashmaliciousUnknownBrowse
                                                                                            • 205.196.6.229
                                                                                            steam.exeGet hashmaliciousUnknownBrowse
                                                                                            • 205.196.6.226
                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                            3b5074b1b5d032e5620f69f9f700ff0ehttps://s.id/sharedocumentGet hashmaliciousUnknownBrowse
                                                                                            • 155.133.253.52
                                                                                            • 162.254.199.184
                                                                                            • 104.102.49.254
                                                                                            • 155.133.253.36
                                                                                            • 162.254.192.98
                                                                                            • 162.254.192.99
                                                                                            https://trackru.top/usGet hashmaliciousUnknownBrowse
                                                                                            • 155.133.253.52
                                                                                            • 162.254.199.184
                                                                                            • 104.102.49.254
                                                                                            • 155.133.253.36
                                                                                            • 162.254.192.98
                                                                                            • 162.254.192.99
                                                                                            https://www.google.ie/url?q=queryy8px(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3D&sa=t&url=amp%2ftranscabrera.com%2fyaya%2f37w6telbuncxaji5ywvxeooxd1ok88ou67nhi/bWFyay5tY2tlbnppZUBtYWdlbGxhbmxwLmNvbQ==$?Get hashmaliciousHTMLPhisherBrowse
                                                                                            • 155.133.253.52
                                                                                            • 162.254.199.184
                                                                                            • 104.102.49.254
                                                                                            • 155.133.253.36
                                                                                            • 162.254.192.98
                                                                                            • 162.254.192.99
                                                                                            https://s.id/nelsiGet hashmaliciousHTMLPhisherBrowse
                                                                                            • 155.133.253.52
                                                                                            • 162.254.199.184
                                                                                            • 104.102.49.254
                                                                                            • 155.133.253.36
                                                                                            • 162.254.192.98
                                                                                            • 162.254.192.99
                                                                                            https://www.google.ie/url?q=querymmjx(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3D&sa=t&url=amp%2fsafrareal.com.br%2fyoya%2fgrcbea7q6lbvpmruhnx3bojhvb2k6ojxdnvuw/Y3doaXRlQHdvcmxkZHJ5ZXIuY29t$?Get hashmaliciousUnknownBrowse
                                                                                            • 155.133.253.52
                                                                                            • 162.254.199.184
                                                                                            • 104.102.49.254
                                                                                            • 155.133.253.36
                                                                                            • 162.254.192.98
                                                                                            • 162.254.192.99
                                                                                            https://ledger-checks.s3.us-east-1.amazonaws.com/index.htmlGet hashmaliciousUnknownBrowse
                                                                                            • 155.133.253.52
                                                                                            • 162.254.199.184
                                                                                            • 104.102.49.254
                                                                                            • 155.133.253.36
                                                                                            • 162.254.192.98
                                                                                            • 162.254.192.99
                                                                                            https://t.ly/9nPygGet hashmaliciousUnknownBrowse
                                                                                            • 155.133.253.52
                                                                                            • 162.254.199.184
                                                                                            • 104.102.49.254
                                                                                            • 155.133.253.36
                                                                                            • 162.254.192.98
                                                                                            • 162.254.192.99
                                                                                            Nota1893.exeGet hashmaliciousUnknownBrowse
                                                                                            • 155.133.253.52
                                                                                            • 162.254.199.184
                                                                                            • 104.102.49.254
                                                                                            • 155.133.253.36
                                                                                            • 162.254.192.98
                                                                                            • 162.254.192.99
                                                                                            Requerimento.exeGet hashmaliciousUnknownBrowse
                                                                                            • 155.133.253.52
                                                                                            • 162.254.199.184
                                                                                            • 104.102.49.254
                                                                                            • 155.133.253.36
                                                                                            • 162.254.192.98
                                                                                            • 162.254.192.99
                                                                                            Nota1893.exeGet hashmaliciousUnknownBrowse
                                                                                            • 155.133.253.52
                                                                                            • 162.254.199.184
                                                                                            • 104.102.49.254
                                                                                            • 155.133.253.36
                                                                                            • 162.254.192.98
                                                                                            • 162.254.192.99
                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                            C:\Users\user\AppData\Local\Programs\SteamClient\D3DCompiler_47_cor3.dll (copy)https://investors.spotify.com.sg.misteri.us.kg/Get hashmaliciousUnknownBrowse
                                                                                              SecuriteInfo.com.FileRepMalware.32268.950.exeGet hashmaliciousUnknownBrowse
                                                                                                https://wavebrowser.co/Get hashmaliciousUnknownBrowse
                                                                                                  https://github.com/GPSBabel/gpsbabel/releases/download/Continuous-Windows/GPSBabel-20240815T1150Z-e9b2084-Setup.exeGet hashmaliciousUnknownBrowse
                                                                                                    https://viture.com/windowsGet hashmaliciousUnknownBrowse
                                                                                                      https://www.plexim.com/sites/default/files/packages/plecs-standalone-4-8-4_win64.exeGet hashmaliciousUnknownBrowse
                                                                                                        YoutubePlaylistDownloader.exeGet hashmaliciousUnknownBrowse
                                                                                                          https://developers.yubico.com/yubikey-manager-qt/Releases/yubikey-manager-qt-1.2.6-win64.exeGet hashmaliciousUnknownBrowse
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):21168
                                                                                                            Entropy (8bit):6.542009642868284
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:KBmy0h6gSGR5OcHivWt/WbX6HRN7KtHNsAR9zF0H:bSyOcHLgWwts89zmH
                                                                                                            MD5:3A293D421E4A853F569C2E7B5BF27775
                                                                                                            SHA1:64BE26396D3569E2A32FFE25A3A5B3F30D8EB67C
                                                                                                            SHA-256:F59C6ACF3ABA059DAD7414BA0046E0EA0646FA54036827C2A611CE8843232463
                                                                                                            SHA-512:8D9636E69105DCF5B3A5A07191E7C993A5A49B64869A9D2E8801FA31ACC1778C53E850E1286B0CD45F1111D8CC54CC8409C4C493B0601C68B92C980661AF4C30
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Reputation:low
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......f...........!..... ...........?... ...@....... ..............................ld....@..................................>..O....@...............*...(...`....................................................... ............... ..H............text........ ... .................. ..`.rsrc........@......."..............@..@.reloc.......`.......(..............@..B.................>......H........ ......................P ......................................H!j*.......8M..{.c....BD.l.....EVt.RL..*.8.c...Q...w....2..E..W...U..c..m..d&GA.,..rND...I>.v.......Ea...r..2..]..&.Fk.!...sTBSJB............v4.0.30319......l...,...#~..........#Strings............#US. .......#GUID...0.......#Blob...........W.........%3........!...........7...................t...3..................................... ...............^.?...y.r...........?...............-.....D.....d.....
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):4916840
                                                                                                            Entropy (8bit):6.398149817011711
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:49152:FCZnRO4XyM53Rkq4ypQqdoRpmruVNYvkaRwvpiD0N+YEzI4og/RfzHLeHTRhFRNS:EG2QCwmHXnog/pzHAo/A2L
                                                                                                            MD5:A7349236212B0E5CEC2978F2CFA49A1A
                                                                                                            SHA1:5ABB08949162FD1985B89FFAD40AAF5FC769017E
                                                                                                            SHA-256:A05D04A270F68C8C6D6EA2D23BEBF8CD1D5453B26B5442FA54965F90F1C62082
                                                                                                            SHA-512:C7FF4F9146FEFEDC199360AA04236294349C881B3865EBC58C5646AD6B3F83FCA309DE1173F5EBF823A14BA65E5ADA77B46F20286D1EA62C37E17ADBC9A82D02
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Joe Sandbox View:
                                                                                                            • Filename: , Detection: malicious, Browse
                                                                                                            • Filename: SecuriteInfo.com.FileRepMalware.32268.950.exe, Detection: malicious, Browse
                                                                                                            • Filename: , Detection: malicious, Browse
                                                                                                            • Filename: , Detection: malicious, Browse
                                                                                                            • Filename: , Detection: malicious, Browse
                                                                                                            • Filename: , Detection: malicious, Browse
                                                                                                            • Filename: YoutubePlaylistDownloader.exe, Detection: malicious, Browse
                                                                                                            • Filename: , Detection: malicious, Browse
                                                                                                            Reputation:moderate, very likely benign file
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........|3..]...]...]..e\...]...\.5.]..e...]..wX...]..wY...]..e^...]..eX.y.]..eY...]..e]...]..eU./.]..e....]..e_...].Rich..].................PE..d................." ......8..........<).......................................K.....B.K...`A........................................`%G.x....(G.P.....J.@.....H.......J.h&....J.....p.D.p....................S<.(...pR<.@............S<.(............................text.....8.......8................. ..`.rdata...F....8..P....8.............@..@.data...`....@G......@G.............@....pdata........H......@H.............@..@.rsrc...@.....J......@J.............@..@.reloc........J......PJ.............@..B........................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):497824
                                                                                                            Entropy (8bit):6.7965571379271275
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:sSla/DmFHF4oPOOLrBO0th7QT29h9Yfl1yl1gJj0qVbn95n3pcsa0Q:sdDmFHay6ehnO10Abn9d3pXRQ
                                                                                                            MD5:6F5A7B47BF1D61C9B84276A99121BBF4
                                                                                                            SHA1:2A806A697397FAFEC4E9B333251963F43285A085
                                                                                                            SHA-256:391042279B8C582DEDEAEE0CE82B211DB4020B07EDEDD0FF44B6225A702665D7
                                                                                                            SHA-512:9D873B9935BA153EF43B398FB5B11E7CDED24A4885C219D66DC4E48DF1C6E690EA61AFAE2EF95B95EEF761743387DCC2C7CC85D0DCC107C271771FC4700378A6
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Reputation:low
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....-.f.........." ..... ...@...............................................p.......#....`...@......@............... .......................................o..H$...p...(...`.. ...0%..................................................................H............text...w........ .................. ..`.data...B*...0...0...0..............@....reloc.. ....`.......`..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1005832
                                                                                                            Entropy (8bit):6.717630206703801
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:24576:Wuz94uYWl+9whtbSp1HVu9yH+sChDUD3IX+:v54uZ++tbQHVu9yHugrH
                                                                                                            MD5:AC45B05C090E28DDE2BDD3E6D460330F
                                                                                                            SHA1:54A64B5C41A365E4F03974E620D9227582E0B6B1
                                                                                                            SHA-256:FBA4224E5DEABCCD781BD7E0371C16A9765F7BE0EA165F8BB499F5D62F4531BF
                                                                                                            SHA-512:6DCDB591E85C9F2C241ED2BCFAFA214B7F1B75E6D681BB40F76CC3B121FCE41CE9455FA3C44D455A4E4F2FF4BA4F159F0DE51C0EA74FFC73837B342794AB7389
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Reputation:low
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...o............" ..... ...................................................0............`...@......@............... ..................................`....*..TQ...0...)...........;..p...........................................................`...H............text............ .................. ..`.data........0.......0..............@....reloc........... ..................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):2309152
                                                                                                            Entropy (8bit):6.414576855139372
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:49152:jH+fGgFyzuNiG6H0n8D1gkrz/OAyFAopdrq/c/:+GgFQq8DT/ZyFDN0c
                                                                                                            MD5:A71CD05C01F0FC603C0BD782516F806D
                                                                                                            SHA1:C15E261D5E7318875D324D28AB70A883CD434C81
                                                                                                            SHA-256:7F8DCF37D9D66EAE14C48A79FA2FCD447BD0F38A21BE0203A9C4A89398AACF28
                                                                                                            SHA-512:CE53F6DC1F02889ED6FB1F8DF226F9BADBB039F79505CDBD599A00A32B6617DA5E19F2AD7F76BB8134B3CCAD39FAB2209ED8EC6AE42CD30402C4E450FC19FA88
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......Wq0...^...^...^.Xh]...^.Xh[..^.XhZ...^..]...^..Z.'.^.Xh_...^..._...^..[.m.^..W...^..^...^......^.......^..\...^.Rich..^.........................PE..d....ZY..........." ...(.....\...... 0........................................#......)$...`A.........................................Z!.p....[!.P....P#.......!..W....#. (...`#..>.....p.......................(....U..@...................0Y!.`....................text............................... ..`.rdata...Y.......Z..................@..@.data....a...p!......^!.............@....pdata...W....!..X...t!.............@..@.didat..p....@#.......".............@....rsrc........P#.......".............@..@.reloc...>...`#..@....".............@..B................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1247520
                                                                                                            Entropy (8bit):6.749192841590639
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:24576:NsvtzOPj/l89Sk2f+/eOUCxRepC36Rk3i+XFqUn:NsvtzOP7ymf+/TZd3ie
                                                                                                            MD5:5A0F40B6899F9BD7E43A5425DA58DE25
                                                                                                            SHA1:BDFF3CBF31FA86709309D92667C285F9F2C6D40B
                                                                                                            SHA-256:EEA806D40BE4C2FB909072DF32DE259EC476E9A7CC749C37447994FFC340F1AD
                                                                                                            SHA-512:F99971B7C6B3F3A02F99FD40DA655326D6BCF1060FFB2E5E49A6BDA6E09C05557B15F0951C1560E1ACDB4B2CDF0B63ECEF45E6745C1D562AE286AA3D53529850
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....Q............" .................................................................^....`...@......@............... ..........................................d_...... )...........>..p...............................................................H............text............................... ..`.data...............................@....reloc........... ..................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):247968
                                                                                                            Entropy (8bit):6.37445921548819
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:L/Ko6Z6pKRRO48OkdzAbCbDme2+zi2bQTFh:Liyp4SdGKru2ETFh
                                                                                                            MD5:6D96BA9C49ABCA46C4E5E6DB1A83561C
                                                                                                            SHA1:B0CC05C727A0AA4F7E2149427E3E434A1D2D372B
                                                                                                            SHA-256:232CFFB26231A28F7B7884ADFCB9C49CF23C5F8289E0BA9D90F4644BA7C9C312
                                                                                                            SHA-512:DC68E50B2168513E12B29E3CAA3ADC69C18F30FB99E7EB19056C556E75E1B73EC95671343133C1FB6B2D3A0C6747A984F73A37F456CA0B4183BDBFE65874E76C
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." ..... ...p............................................................`...@......@............... .......................................[...........(...........#..p...............................................................H............text............ .................. ..`.data...NX...0...`...0..............@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):19104
                                                                                                            Entropy (8bit):6.5215263611516
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:jGgfnShxL2GoOoxWmHe9QdWVYA6VFHRN72k6R9zdL:jpn6lZoQRFCl2k29zt
                                                                                                            MD5:38D24ABC45135A87E515790906D7724A
                                                                                                            SHA1:BFFBDB01EC108FC45C29202AE814C13D55A4C79A
                                                                                                            SHA-256:C6DCA08937792CD14E10F7B9794377FE698C3A97C9958D90B397CB6BDEB1F0C8
                                                                                                            SHA-512:674C8B1B5454143F7D6767919FDE88FC478F4A80DC24C70F6CE398AF526A7F065BF38FA3030E3CBF28204313BE2EA92FA19F1F3F014216A0E6D7BF130D58AC24
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...|............" ..0.............n7... ...@....... ....................................`..................................7..O....@..............."...(...`......t6..8............................................ ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`....... ..............@..B................O7......H.......P .......................5......................................BSJB............v4.0.30319......l...H...#~..........#Strings....4.......#US.8.......#GUID...H...\...#Blob......................3................................x.............................%.........*.....C.......(.....(...E.(.....(...`.(...}.(...,.(.....(...<.(...q.......0...........................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y...............................#.....+.5...3.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15640
                                                                                                            Entropy (8bit):6.836441141207769
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:kiGp+xfkPWhhpWvpWsWxNzx95jmHnhWgN7acWYH8AgfcMbnoQNpX01k9z3AZs88o:ki2EIWhhpWv4zX6HRN7v8/7R9z56
                                                                                                            MD5:D3BAAD7A5DB953DE71AA459841CC37DB
                                                                                                            SHA1:CB94AD1EA3706C7346CEB305ABB6B47436671636
                                                                                                            SHA-256:A682B72F9D80BC517F197A0FF85CD2858EB743D8CB6E8453C946E413BD10C0E1
                                                                                                            SHA-512:7680F910655B9BDC99DDA93D62F936FCF2C57931D7A324316D53571E2F069F691EAEEA2FE30AF1F08CC24E07D188692EB46D9A8CF6AB21CC7FB3FC391346DE2C
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....q..........."!..0..............)... ........@.. ...............................C....`..................................)..Z....@...................)...`.......(..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H........ ......................P ........................................g~W..<.ah...>]~KNh.n*...=.t,.'....Z.h,.*&...B|....d.F..i.o.....>~.8........W...I.........qnk.6..P'../.K.!..<.t"..{BSJB............v4.0.30319......`.......#~..(.......#Strings............#GUID... .......#Blob......................3................................................"...........;.l.........f.....!.E.....E.....>.................E...[.E.....E.....E.....E...B.E...O.E...v.............
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):34976
                                                                                                            Entropy (8bit):4.6401763861103875
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:XWFBrWvK8kH6cKRbOEnYA6VFHRN7v2BHR9zJVEb3:Y6S6vRbOSFClv29zMb3
                                                                                                            MD5:F8BCC72E3315CA75D42B83090D1DE38E
                                                                                                            SHA1:7DBDA01CE3F9F6ACE4E42A7A5FC1D2DB22B3EED8
                                                                                                            SHA-256:3E3FFC9A7F24222A811A0394BD7E72DF11DBC466B10DEB6F669A8E1D79C77E2C
                                                                                                            SHA-512:8377537479DC150A47F6D8DEFECF371052CABBB6AEC85143C9E8F931743910066CD8AF31EC8B54B87450AA0684A219DBAF27C82895CD53B547A31760EB632954
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...z............." .....0... ...............................................`......PA....`...@......@............... ..........................................0....`...(...P..........p...............................................................H............text...p&.......0.................. ..`.data........@.......@..............@....reloc.......P.......P..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):120992
                                                                                                            Entropy (8bit):6.141095686333107
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:HY1NwrxWkbGKzcNqJSvEVcULVii1i81SFUt:Dl6KYqJSvEVz7/iO
                                                                                                            MD5:4FD4616455D07E7252B50B565A2E75C5
                                                                                                            SHA1:CD6DB5A8DCA0D94AA5E48717E32F3EC3E1B17998
                                                                                                            SHA-256:853DA3E1E5BA29DECFC91A39FA1B70955BDC63E18F034AE119635DF53704E9D9
                                                                                                            SHA-512:1E37902F3B4AFCC08ACD7C8450E72DE11CA16D1D338B8E076BF4940BDE832866D410900ED6513B1D6BA67E7FCF579336998D7B2A2AC9483404B3FA2C6866EE2D
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...M.)..........." .....p...0......................................................NX....`...@......@............... .......................................4...........(..........0...p...............................................................H............text...Kh.......p.................. ..`.data...a........ ..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):96528
                                                                                                            Entropy (8bit):6.256005340484751
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:8c+vV+l6Q2jM+HHdKCl2/4IGrAsDkjvSpJniknzDi:8vv8l6jjNHkQIGr4jsJnlnS
                                                                                                            MD5:58B452E9A001CDF96C84AFDEB3FC7D0B
                                                                                                            SHA1:2E7828151F39F5A2D3DCC88FD0CF53527C89BFFD
                                                                                                            SHA-256:E030C7EB334F13D261A22E2608A78455C34877D39884E3DAA4E5324C00B56E15
                                                                                                            SHA-512:5C1135DCF20B21778CD9DE86C276E887CCFF3CFC900734D5DD2B86770B5B220D1D557780D17A04D56D732BB5C99CAA8A0C6801F4479AF4A4019C473FE55EBEB2
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...^............." ..... ... ...............................................P............`...@......@............... ..................................`....(.......P...)...@..8...0...p...........................................................`...H............text...F........ .................. ..`.data........0.......0..............@....reloc..8....@.......@..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):157856
                                                                                                            Entropy (8bit):6.1575669495933445
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:urdsza/NXpFSGeVdEgUxnI3iJ05uE2alATZ+k/OKY4US2+:wsza13Sxy5SiJUuE2vXPZ
                                                                                                            MD5:4D4ED1ABBB92E818A6E2CD9C91AE5FAC
                                                                                                            SHA1:5F70C569120724DCBD9839B16503517FCDB09D9B
                                                                                                            SHA-256:4128EF96ED97A3393082335768F85E118148A7EDF13777B2B1368DA88CB21276
                                                                                                            SHA-512:6E90EC4EEF42D669FB9D9C7E7B52F87E711C3FC46491E2409AB7037E68817E2E32E5F29BE02E97F951204E0136E20562568DAE7223A33380FCAA0944B93C25DE
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......ym.h=..;=..;=..;4tY;7..;-..:4..;-..:6..;-..:...;)g.:>..;)g.:2..;=..;...;P..:0..;P..:<..;P.5;<..;=.];<..;P..:<..;Rich=..;................PE..d....-.f.........." ...).H..........p!....................................................`A.........................................................P...,...0..8....@...(......8.......p.......................(...`...@............p..h............................text...,D.......F.................. ..`.orpc........`.......J.............. ..`.rdata......p.......L..............@..@.data...............................@....pdata..8....0......................@..@.rsrc....,...P......................@..@.reloc..8............:..............@..B................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):8542368
                                                                                                            Entropy (8bit):6.777702600079919
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:98304:HmsdFJMKLTfQUtV5sIexZwO1oHy7xAz+BianSJhw36pbIy6Py99:zJMKx6BxZr1manSJhw36+y6A9
                                                                                                            MD5:EB08E99C6FCF641A2D936D4E16160408
                                                                                                            SHA1:B0C22D6F0049629BD3575430FEF188F13E593906
                                                                                                            SHA-256:C325EC0006A3A743CBF2DF266E6C57A3B07BD0865938467204AF1F36992C8A3C
                                                                                                            SHA-512:3BAB6873F737CED3CC8700EF953355DB4F7B9DE3706EF35BF87516A3C4ECF3A9FAC77EF047266B3C4BDA3DFF146CAE329A8ACAF5B9E6B5D27D86152A64B679E1
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...h.2..........." .....p{..................................................0......IN....`...@......@............... ..................................L...l...h9...0...(..........x..T...........................................................P...H............text....i{......p{................. ..`.data...w.....{.. ....{.............@....reloc.............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):39072
                                                                                                            Entropy (8bit):5.152976144651618
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:fWtXILG8kxsuQ7JfADw7fmlE8QMnYA6VFHRN7WVtHNsAR9zRY:iX2GHxsuQ7JH7fOVFCluts89zS
                                                                                                            MD5:289320F577443CF8FB301A730E2E0577
                                                                                                            SHA1:9C4EEA8D1D7B3800E63FD1D455DFA2AC516B5842
                                                                                                            SHA-256:B77EC004EABCD8759B0991E923F200FF107A5110861B49238873F475998119F0
                                                                                                            SHA-512:DCB3E2A02910C1C8CF01EF95E7A0F7A006B95A6DFA2A6247EFD33E99C83348DC9B7E19682A83D2C14194C2D778AF1323ACCEE214BE5775F15D7CF898AC0B37B2
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....SE..........." .....@... ...............................................p............`...@......@............... ...............................................p...(...`..|.......T...............................................................H............text....7.......@.................. ..`.data........P.......P..............@....reloc..|....`.......`..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):34992
                                                                                                            Entropy (8bit):5.06686826259634
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:cWd+b6tYf7uMk5Rxo5ka2mXT9FIX6HRN77HtHNsAR9zRWj:nO6tYf710A9eWBts89z4j
                                                                                                            MD5:F1714233138A49F3EE33521D4DBDB63F
                                                                                                            SHA1:42403E139F8EFA7B8FD93643EAB246ABCC52A3E8
                                                                                                            SHA-256:13458987C56DC1E3E4147E3AF9758BEDD02620F776D0A0457234599AA6908674
                                                                                                            SHA-512:23BDA66FD2BD332586F717AA921372711AED61D89A0B1C7EF1654DB74DC72316E7F91078D5027A5CFFF0F308AC71B68E2F3B435E83AE9AB5932688F5DC5B182F
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....gO..........." .....0... ...............................................`......-.....`...@......@............... ...............................................`...(...P..|.......T...............................................................H............text....*.......0.................. ..`.data...c....@.......@..............@....reloc..|....P.......P..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):34976
                                                                                                            Entropy (8bit):4.86447641958981
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:hWArL6BLzBGcr6K9mN9ABN8YA6VFHRN756R9zekg:1n6zMO8FCl529zE
                                                                                                            MD5:29AADEB003680D153EE1FBFA4F13007D
                                                                                                            SHA1:DA596E2EF94DFE6DD9DE4174496E9DAC95DB4C9E
                                                                                                            SHA-256:8225F2F463DFD22409BF35D68A186B3CF4D4E2BFB3D06E970C2AFFC8911347CE
                                                                                                            SHA-512:AF3F5D7C88D65EBD89CC28DC1FC823E9ECB3AE32867E849D70B414AED7F104763D092AEDDA062168CB24D744729666BF9EFB25FAF15D5FC8DB258E0C168E3B7B
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................" .....0... ...............................................`............`...@......@............... ......................................l........`...(...P..t.......T...............................................................H............text...7&.......0.................. ..`.data........@.......@..............@....reloc..t....P.......P..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):34976
                                                                                                            Entropy (8bit):5.07371888821369
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:3WE8CO6PzDix+GtH6fDonYqHT4CjeYA6VFHRN7kfNFu49R9zFlK:X26PzOKkn/T4xFClkFFu69zq
                                                                                                            MD5:C8694E9CD42C325CB3AE356CC4DFF7FE
                                                                                                            SHA1:636986A78005DD775C632EB7AB1314471AF7CC0F
                                                                                                            SHA-256:E266AA3D2EDE9B36C8C0F4A3C256E1C553101312EAF5BB71A5AF32F168ACB282
                                                                                                            SHA-512:6EEF36D795E206A1AC543ED731C53751429BC715AF8BA77DBCCF6FE2ECE5495BE4A42B1E78D8D53486CBC963BEE9BDEC67444306EBFBF7A24415E93DE8DB448C
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .....0... ...............................................`.......(....`...@......@............... ...............................................`...(...P..\...x...T...............................................................H............text....+.......0.................. ..`.data........@.......@..............@....reloc..\....P.......P..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):30896
                                                                                                            Entropy (8bit):4.671392181687111
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:gWQvA1blqixkPVHulGwgjX6HRN7vDX+iR9zXoK41:6vmpqixoVPwOWvDuO9z4K41
                                                                                                            MD5:4443643BBA915CC3E79936F70A126AA1
                                                                                                            SHA1:33440C787A52D4C4CEC825B083AECC7D6E619BBA
                                                                                                            SHA-256:BC907F0FB61F2139B333DD22D90A18991190E56AE1B8E5F7F6544DBCA166A9C4
                                                                                                            SHA-512:EC4FD6F0417A4DDE8A4A88B30765FEF695E9A2C2A5C64C256E2DEC900C4F7DE7D50EB58117F07D137D13711391F9A4434119BB444C84D80EE5A63F6BC2011EF2
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....X............" ..... ... ...............................................P.......\....`...@......@............... ......................................t...H....P...(...@..$.......T...............................................................H............text............ .................. ..`.data...2....0.......0..............@....reloc..$....@.......@..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):444576
                                                                                                            Entropy (8bit):6.440833272545049
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:wNPuxxnrOCMgPaisoAAnzQ9km0OsSVPtfwUh:wAznrO+PavoAAn89kmQSPwUh
                                                                                                            MD5:234B4CDFA3C0E3F92A8A8B6D023D475B
                                                                                                            SHA1:99777FE5D31FD9F22FA264BEC205DFCEA9B59341
                                                                                                            SHA-256:1EC111968837EB9B3D110680ED6B3F55CE2208C458F42350EBE8BFDDAFBB3850
                                                                                                            SHA-512:59246448DAEE1E880925E0D58C44DF44BE3FFFDFB907650F8BF9D04E1119F0A2F0E622CB4AD779D9B44F3AB9AF0954856431AD8C49DC404C153D171AD83379B7
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....[X..........." .....P...@......................................................hj....`...@......@............... .......................................`...........(......L...x...T...............................................................H............text...QE.......P.................. ..`.data....(...`...0...`..............@....reloc..L...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):448672
                                                                                                            Entropy (8bit):6.474085434530271
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:lrZkP7nVEPMrK7u2aAc8tU9kmMxKoVPtfwrfAX:lr+P7neErK75aAc8O9km5oPwrfY
                                                                                                            MD5:B07A911B77E9C6BFB40BEE9EDBB30003
                                                                                                            SHA1:CEE3FA050CEB5C9F91E927B0A7F59F7B244BCB40
                                                                                                            SHA-256:6D380E65B7C9F95B4AC9FBD92DA35CE7ED95E4E3170154AD9405461DEBBE2150
                                                                                                            SHA-512:975DD732BA4B84759314E30031FEB921699DA75311C46CB28FE5E453594FBEEE0780F2D08E971474EFC431359863B1F44D5F260CB78ED678A11DE65C4C44934D
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....H..........." .....`...@.......................................................W....`...@......@............... .......................................`...........(......L...x...T...............................................................H............text....].......`.................. ..`.data....(...p...0...p..............@....reloc..L...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):239776
                                                                                                            Entropy (8bit):6.273420553853626
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:oP05HdISwFh/zzfClS5/zm7Y9EqS3StS3fM+bj:Q0JdIN7EqSitS3Zn
                                                                                                            MD5:986799438340C732BB482628FFFBB2F7
                                                                                                            SHA1:1AE12FD48B575E4A6FA7EF20C8FFAE43B9AEE019
                                                                                                            SHA-256:03CB4DCB63A2388368F04E3C542865D46D445F44359BAAC2A78CC6143FF7C5CE
                                                                                                            SHA-512:07D8858FA934AB98BD1A4DCA59CA7D4A9EB7A889FB2B5363A40E19E2A3BE9A7C178BF26E7ED702533C26C3311EE3F0540ABB18A61E00CAD96B6CAE539D927158
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...;P!..........." .....@...0.......................................................9....`...@......@............... ......................................,+...........(...p..T...X...T...............................................................H............text....1.......@.................. ..`.data...7....P... ...P..............@....reloc..T....p.......p..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):272544
                                                                                                            Entropy (8bit):6.427109808525276
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:gbFX7U01FlqnpLMjwFMi8m7zd1XVSaos5gU+NTB4dOVGkK1:oFLU0PonpHFdlSDs5gD34qXS
                                                                                                            MD5:A315F2B9A4D56A36B35758AFBFB2E9E7
                                                                                                            SHA1:21AB6249AD343F43697A740068BDFFBE8019590A
                                                                                                            SHA-256:291AD602E68F54502BF4414BD0585981E605DA41B3A9C8CDE7AF57555A0E96C1
                                                                                                            SHA-512:141D9D36A2353A839FCC85D237DFD53BA03595159E420147D1F16848A22B2401D90B3C2B59243F09E34D824BA7288C2362C5DAB9C707C23097122B873C37118B
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...%m(..........." .........0......................................................P.....`...@......@............... ......................................|4...........(..........h...T...............................................................H............text...u........................... ..`.data............ ..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):669856
                                                                                                            Entropy (8bit):6.432051743565
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:BlTaMaSzOKy2r7SPNjB2aL9/aMolZSL7+:BluMaSSKy2/SPNVDJilA7+
                                                                                                            MD5:80DCD2DEE00526FA95ABFB1C0A7C8B57
                                                                                                            SHA1:F440EFE6A737E073F8FD920C8CCD30DEBE4AB09A
                                                                                                            SHA-256:55206C2904F12D0856EEFD722E17DF8F685276C4CBB772CC775618D2DB57A0B6
                                                                                                            SHA-512:E9801F9DDA7DB199AE357DCC84E53A9F13870D7452FBAC7A05B013642D3F383923E1CA3E9A8016419F8045A26734024DF9687BCA5DBDC61B66CC3C8F8A63F7A7
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....V............" .........@......................................................<.....`...@......@............... .......................................R...........(..............T...............................................................H............text.............................. ..`.data...j%.......0..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):334000
                                                                                                            Entropy (8bit):6.389483256864205
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:eJ+s+kfIPvH96Xcfb81vFdqE3vex1/16k9dfuL3ofjm4v70yYZ1384BokKX:qlInd6Xcfg9UceZ7pv7aDfBRS
                                                                                                            MD5:30EA2AC0A36970CB801B8F164B370767
                                                                                                            SHA1:E142030CBDEFCFCAA6538D6C1C6362944940958A
                                                                                                            SHA-256:1E3C574533A854EA1AA537A34B12211F5D1FB99D7ACC266E464DBF990DF599D6
                                                                                                            SHA-512:4E3AF4B1B62E607B0BD47DB61D8765154C1862434BBB37B2F05880084C0C3009486B62F07B851CC7B3D00FABE8D181814CDA5C41D9CB2AA116D45FE03DA57AFA
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....c..........." .........@.......................................................7....`...@......@............... ......................................dI...........(......P.......T...............................................................H............text............................... ..`.data.... .......0..................@....reloc..P...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16124064
                                                                                                            Entropy (8bit):6.814489484370051
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:196608:YffCqPQVBYD+IsWs7Y5gIeLHOdwzLPlT+AJ0ysEKvqg:YffCq4ptWP5gIeLHOdwzblT43Jvr
                                                                                                            MD5:FCE0527DCEA85FB4F9256C2D398BE500
                                                                                                            SHA1:A3E485D52C82461129D317B06B252CBB64FCFD3A
                                                                                                            SHA-256:B903285A81535D3F7D394E284FD8BAFF2DF2001CFF2D590B63BF159D6435E5F7
                                                                                                            SHA-512:A3F202A35AF1FF36E371588B5D2EEC57718D94028A1AF8388453F7467F1A20502197376A2A1F02E4486CF8D91E773868018554F8F82AC6971195F7C93E7F9F51
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....cC..........." ................................................................7.....`...@......@............... ..................................l........$.......(......./...j..T...........................................................p...H............text...^........................... ..`.data....... ....... ..............@....reloc.../.......0..................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1237280
                                                                                                            Entropy (8bit):6.162110099362256
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:24576:N3mF1Kl1KS1OGTUQ8I6cXYA/fozjXu79SgKUNndau7YxZDlHTGLgvXC6irLdLUf0:BQKl17OGTUQ8wozjq9SZGndauiDC6iZ
                                                                                                            MD5:1B7E26A5178D7E80EF9B5D1BF0C53763
                                                                                                            SHA1:F3CACDE5660E6DB3B96A19032707326434C4A1DA
                                                                                                            SHA-256:66E5D8D49F9645FD67C12324E0E947B8646779B502A3BC475E3A3AEB650E20BB
                                                                                                            SHA-512:BEE9C66DBCE0E9AB4AC06B5AA3A01E4FD33475A1BE74D92DC9A75C2A3CED6B441F8A76747F3CF09913E38BEAE055FA277C55267353CDA97ABD018146E7355B89
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......cC.l'".?'".?'".?.ZE?-".?7..>.".?7..>-".?7..>.".?3I.>(".?'".?H".?J..>.".?J..>&".?J.)?&".?'"A?%".?J..>&".?Rich'".?........................PE..d...~..f.........." ...)............0................................................e....`A............................................\...,...................`....... )..........`...p........................... ...@...............8............................text............................... ..`.rdata..............................@..@.data... ...........................@....pdata..`...........................@..@.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1288352
                                                                                                            Entropy (8bit):6.742211790346322
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:24576:Br2JFGlyXQfoVGd3HAS0gZZ3xhRToFP9x:BzZzZZmFr
                                                                                                            MD5:191F203634A63CEF1542DD95BEB5C4C0
                                                                                                            SHA1:B12F2314A6A5A7E9899DCF7E43789D2FA19A177E
                                                                                                            SHA-256:0F9B35AA4326DCB6B8E3EBB610C5ED6AD3A116A24A97A6CEBB6CF14C80B75FEB
                                                                                                            SHA-512:9AEEB8424F87E9D993AE2FDAA3FCBE4C30E6F04D3EEF20B848083FC8531C001A8EE1319B73A35B700FDA57868B39C5DCE1DA89F86E96BFC3232F4E1C5533763D
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....j..........." .....`...........................................................g....`...@......@............... ..................................<........B.......(...`..L....<..T...........................................................@...H............text...a\.......`.................. ..`.data........p.......p..............@....reloc..L....`... ...`..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1603760
                                                                                                            Entropy (8bit):6.680950208426245
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:24576:49f8aQsCuaY+QtQ3+ACMaylTIDDCPmZbxhT6LRquiPx:6lhCuza3+ACMasTIDOMxhTX
                                                                                                            MD5:FEAE8157F5E6A7425B47AF947AFEF9F5
                                                                                                            SHA1:6ECAF7F7A8EC4E7A0034576B46D9B045C7A5E8D5
                                                                                                            SHA-256:91B09A9DB441B99D14D4160A98D935A736B66802CFC2ADA80C7482D0AEDD2C02
                                                                                                            SHA-512:E52CB5F1C5070D2F9CF3D1208C24CE6EF566DB1DF745A67FA7FD45C3A0371D158E5B6498FDA264E67D5561EDA8CA0CFD4BE4575879A412F2EF27E853490292BC
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...".'..........." .........................................................P......f.....`...@......@............... ..................................<...........P...(...0.......j..T...........................................................@...H............text............................... ..`.data...Mg.......p..................@....reloc.......0... ...0..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):153600
                                                                                                            Entropy (8bit):7.110434070329448
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:gd5NVzHUHXe6F6e2zHX8D5VFcB3rqC3rsG3ThNSHoNOb3ThNSHoNOF:EAXkrsdV2ZGC7syfT2fT
                                                                                                            MD5:E17923870064DF5200CD84F4B60AFED6
                                                                                                            SHA1:BC5F5E3573868896505E3B743C5626EE10292DF6
                                                                                                            SHA-256:405B6D4EBA43D561DC8914A44AB6A2D70088FC0B18C2909E3B403B1F7871D6CD
                                                                                                            SHA-512:BC3D0F7B9F7D94E4A8A4355033D45C91A265118CF518253C6A5411C63F01DDD349497FFDEDC8308AE61D6BC37558D80A04C25A132EA36F15E50AA73F5F3370EF
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...{.<..........."...0......T........... .....@..... ....................................`...@......@............... ...............................@...S.........................., ..T............................................................ ..H............text........ ...................... ..`.rsrc....S...@...T..................@..@........................................H.......|L..XY.............Xz..........................................J.r...p.s....(....*Js....%o....o....&*..( ...*..(!....(.....{....r%..p.r[..p("...o#...*>.o$...-..(%...*..0..$........{....,.*..}....rc..p.s.......(&...*.0..C...............+1..t....}....*..t....}.....{...........s'...o(...*..}....*R.(!....(......(....*.0...........r...p()...-..r...p()...:.....r...p()...-j*.{....r...ps*...s+...o,....{.....o-....{.....{....o....o/....{....r9..po#....{....ry..po0....{.....o1...*.{..
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):158720
                                                                                                            Entropy (8bit):6.3954432817313664
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:CjK4UGDHXrQ8hy7qgpHulWD9ZvZ5Pf3Ca10xuZ04ntfOshBul3ThNSHoNO/:CjK4TDUqgpqWDLZ5H+xuZ04fhA9fT
                                                                                                            MD5:24579F75EE35BDD8E4CCC5351295BD9D
                                                                                                            SHA1:ABA441303C3B421DC246EADC469CA05F00DD006F
                                                                                                            SHA-256:0B5D62717704AFE1282A9D6ADE9104FE40E1C6EE855E4DB66E8EF68F68C57CFF
                                                                                                            SHA-512:3494565C8F75122F1204339BBDB3D90A4C2BB28405F98F5869D94775D9EB855FA19733C036B27E7BD3B6532A0AAEDE94ED427BE3AC41D66EFE7050073C6490D0
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........G6..)e..)e..)elR*d..)elR-d..)elR,d..)e...e..)e.(d..)e..(ef.)e.U d..)e.U+d..)eRich..)e........................PE..d......f.........."....(.Z..........@..........@..........................................`..........................................................`...S...0..\............P..(.......T.......................(...P...@............p...............................text...lY.......Z.................. ..`.rdata.......p.......^..............@..@.data...............................@....pdata..\....0......................@..@.reloc..(....P......................@..B.rsrc....S...`...T..................@..@................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):6191616
                                                                                                            Entropy (8bit):5.95806780252613
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:98304:xJD6MnOWZkv2poIbYF9ICqeBPI6hNQ8QY5LR+qXTlx:xJ2wOWloj9HZ9Q8QY
                                                                                                            MD5:720365C78A7334C8E567F826B5888E30
                                                                                                            SHA1:B37FFA349205DF4EBBC04E8CEBBE27AC95D5E4DC
                                                                                                            SHA-256:15449032C0877608ADBE17A82CEBB3F8118D7B850CE1A1E799ED738089F75349
                                                                                                            SHA-512:59BC16886CC14E1FDE12424B314A9190126926AB88F2FA05F3A306F03443723EDA41A008AF583F0B1B9DF71386C3CF9CFD23AE84E473A49D17B5E917EF553002
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....T............" ..0..p^.........>.^.. ....^...... ........................^.....y._...`..................................^.O.....^.<.....................^......^.T............................................ ............... ..H............text....n^.. ...p^................. ..`.rsrc...<.....^......r^.............@..@.reloc........^......x^.............@..B..................^.....H........T...4L.................d.^......................................0...........(e....r...p}f.....}g...~....(h....~....}i....s....}j....sk...%rK..p......ol...%rO..p......ol...%rY..p......ol...(m..........%.rK..p.%.rO..p.%.rY..p.}n.....}o...*.s.........*...0...........(e....ri..p}f.....}g...~....(h....~....}i....s....}j....sk...%rK..p......ol...%r...p......ol...%r...p......ol...%r...p......ol...(m..........%.rK..p.%.r...p.%.r...p.%.r...p.}n.....}o...*.s.........*..0......
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                            Category:dropped
                                                                                                            Size (bytes):525261
                                                                                                            Entropy (8bit):4.608916738911991
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:QdKci/CH1EcBdEjjjYEjQLw8SyteN1KaYEYF8+teM:2EM
                                                                                                            MD5:91A7F728567604FAB6ABEA623554EE11
                                                                                                            SHA1:8945E3296D8B60230B6E615329F362AEEB551511
                                                                                                            SHA-256:A6258E5296FD7457A827038B7C89F8AB25F573345C536D0A8DC892681A8942A2
                                                                                                            SHA-512:F4023B1C4C2929A8F6885DCFFA9613F997B78CC08E45C57AED892E6E3009337CA3916B8DC8FB662C86EBE98B6911DE9171766BF985749B8A9A61EC91039AA315
                                                                                                            Malicious:false
                                                                                                            Preview:<?xml version="1.0"?>..<doc>.. <assembly>.. <name>SteamKit2</name>.. </assembly>.. <members>.. <member name="T:SteamKit2.ClientMsgProtobuf">.. <summary>.. Represents a protobuf backed client message. Only contains the header information... </summary>.. </member>.. <member name="P:SteamKit2.ClientMsgProtobuf.IsProto">.. <summary>.. Gets a value indicating whether this client message is protobuf backed... Client messages of this type are always protobuf backed... </summary>.. <value>.. .<c>true</c> if this instance is protobuf backed; otherwise, <c>false</c>... </value>.. </member>.. <member name="P:SteamKit2.ClientMsgProtobuf.MsgType">.. <summary>.. Gets the network message type of this client message... </summary>.. <value>.. The network message type... </value>.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15520
                                                                                                            Entropy (8bit):6.73836549241893
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:XkWrBaWi7WvaYA6VFHRN7JQDX+iR9zwYiQ:XkWd2KaFClJQDuO9zh
                                                                                                            MD5:36B89A91AA27942AA5948EE349CAB75E
                                                                                                            SHA1:89656249ED33686F86533A0ED8DC8CBEA81ECBAA
                                                                                                            SHA-256:E0ED6218EB92190388E554288C0794CF3E85018F85EB753D1D6EE90167628D99
                                                                                                            SHA-512:9A26A9B94231FADE42E9DC4F57A21D52ADD215D3D6A416A371BFFAF91085EE0866E4341D1C7D10707CC617E08297D7E1F69A32CDC062A02421355B3E08D79425
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...D.K..........." ..0..............(... ...@....... ..............................Kb....`..................................(..O....@..d................(...`.......'..T............................................ ............... ..H............text........ ...................... ..`.rsrc...d....@......................@..@.reloc.......`......................@..B.................(......H.......P ......................('......................................BSJB............v4.0.30319......l.......#~......<...#Strings....H.......#US.L.......#GUID...\...|...#Blob......................3......................................................x.....3...........^.................I....._.................w.................G...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15536
                                                                                                            Entropy (8bit):6.73756934231282
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:38lEdg8Wj2WvQlWxNzx95jmHnhWgN7awWHBm+0U8X01k9z3AH5Q:3C0Wj2WvQGX6HRN76Bmo8R9zYG
                                                                                                            MD5:B2F03EA9F7B56D26733B2A1C9224A397
                                                                                                            SHA1:6C49E77764E38C99E092B4D74B8D22954723289A
                                                                                                            SHA-256:236910220ECDC4F1E7B0A6EFFBED8A9177AEE6BCB090F16807E83368F17563DB
                                                                                                            SHA-512:A1F2B9BAF03DF6D68DE01DF6D33970819668A46138CE38925426437E63A8A4A075DC0D4B6890A1C06DD40A95D6FC8657C8D6F791F356F68DD729A7B7CF7BB5DB
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..............(... ...@....... ....................................`..................................(..O....@..T................(...`.......'..T............................................ ............... ..H............text........ ...................... ..`.rsrc...T....@......................@..@.reloc.......`......................@..B.................(......H.......P ......................('......................................BSJB............v4.0.30319......l.......#~......@...#Strings....L.......#US.P.......#GUID...`...x...#Blob......................3............................................................?.....!.....j.....%...........U.....k.....:.......................!.....S...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):489632
                                                                                                            Entropy (8bit):6.5425586567283025
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:vCh91rqxP6PRc4Uo8wv8K+RpB8Cw93gozY+OSTMo:OBcMpgQY+OSYo
                                                                                                            MD5:78E0E6A45F064CB22F500D0ACB85A1D0
                                                                                                            SHA1:4D5259F6777ABF2AC666B07325B6F5246FC2F762
                                                                                                            SHA-256:2E1BA52621FCD31507BF08F9537154DB7A216CBA70C941B24A425B7F28F5F19E
                                                                                                            SHA-512:772CEAF937953A1447A2B34B659AC3B8DEBB49C0E7B02749BA523F99F5263A8D046F4D5E9744E989E22B845D841D408FC9C231DC575066FF137248A76FEF1976
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .........................................................P.......8....`...@......@............... ..........................................E...P...(...@.......2..p...............................................................H............text...I........................... ..`.data.../k.......p..................@....reloc.......@.......@..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):276744
                                                                                                            Entropy (8bit):6.735103537020919
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:zH8+KHhcm1xa3ZvGFehyhyO28ibc8wXD6GK:zPChcm1xachD2PbVE+GK
                                                                                                            MD5:34E8718BED9FFCB954586F833672F548
                                                                                                            SHA1:EE3D827879373D2AE7708D90C6916EFDE84B98BD
                                                                                                            SHA-256:635D3192EBC262DCEAFB679C30D63A06375D686E9E9BAD9E43B1914B4ACE483E
                                                                                                            SHA-512:A406540C34C699BDC6EA69635047EA206E295CB1E6C2EF80EC9C0374B74F2FE4C3754B309ADB2BD173D8F4D6261DB6BE6570B518A7FD7D2CBBC4304921A38923
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...d6(..........." .........P............................................................`...@......@............... .......................................n...........)..............p...............................................................H............text.............................. ..`.data...h=.......@..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):837896
                                                                                                            Entropy (8bit):6.723078162409922
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:crJR+uRoPwK6eN8/98vTU4dQEE3k0T9YLVgHr4lucvMgllgg9n:w+uM8abw+CMlFDll/n
                                                                                                            MD5:E8D86E48D55490F58ACC8DDDCEF458CC
                                                                                                            SHA1:DCDB9C0D60B300467962E58602A82BBE6EC77AAC
                                                                                                            SHA-256:FC48AA677A344F912C1A9160115DAFD396B4F69EEDD27F4B53B14C2B512E92D2
                                                                                                            SHA-512:18F993F4C7899856AA0C6AD200863D2444FDFA4745ED4CB961AA38DB9F7E6DCB5576665CC1D487A9D1EA7C3B526A95710734AA65049410CBC2E58FD7C3DEFD15
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...f............." .....@...P...........................................................`...@......@............... ..........................................Hr.......)..........( ..p...............................................................H............text...P0.......@.................. ..`.data...L$...P...0...P..............@....reloc........... ..................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):104712
                                                                                                            Entropy (8bit):5.9531643262406995
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:4QoktJ1UcLZmsYAZwmkXjhXVrMZREnZWzUdhiszMO:4jk9vZ7I1GZKZPHoO
                                                                                                            MD5:7DFE9C0A526E8BE845FDF94C77A40215
                                                                                                            SHA1:C3C84D477A91F553167C88D7DC77EC77723138B4
                                                                                                            SHA-256:4F96E191302A84C970545AADB2FC53FA9B5455B1DE54187A5373E0E3B5C90991
                                                                                                            SHA-512:61971E48894E92832ED76967B06E0D8AB57B8748096159852BF2F6AD8C74F8B6DC759EC3FA868AE91F1F08D4F9ECB15CC3A8DF697452DD17972A96715B0C73A3
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....n............" .....0...0...............................................p............`...@......@............... ......................................@0.......p...)...`..........p...............................................................H............text...*+.......0.................. ..`.data........@... ...@..............@....reloc.......`.......`..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):104608
                                                                                                            Entropy (8bit):6.019621325219264
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:Nx/tht+6AWhqlJH5MC+W06201CTBUsqEiONocgw50ad01IODi0zmG:Nx/Q6AqiT+WFPaiONocgwaaOhDzl
                                                                                                            MD5:7B967ABA7A1321AF17A04576DE32CC50
                                                                                                            SHA1:DC2F05B710D21733BEFB5066FA99BFB3AE1B7C4F
                                                                                                            SHA-256:C3D7055A0C71A9E8641C7883DBBDFFEBDBB27D2350DE43BA925D947662533DAF
                                                                                                            SHA-512:4B8ABBE1101EA2CB7B257198E2DCB353CCA151C4BEBD4697A128FFD69D27E1DE64FE19FCBDC79636414B01B15B7848E2C16E6B9BDE24688D1794A7334AEAA9A4
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...!............." .....0...0...............................................p......}e....`...@......@............... ......................................p1.......p...(...`......8...p...............................................................H............text...!).......0.................. ..`.data........@... ...@..............@....reloc.......`.......`..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):260272
                                                                                                            Entropy (8bit):6.618737529882049
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:nXiJoXLKgtvcp1M5eRWAbQW0ryS1woXh3m3x:XYCKgtEzweMiD0rGqJmB
                                                                                                            MD5:C755E2D819F1462687BA99F28D7FB638
                                                                                                            SHA1:1758E9E47D46C3B1D4F71520D09F3FA80E40C9D6
                                                                                                            SHA-256:7EE67CDC969F5BD5BA1A4E99A17ED8A67C2DD835537A982CB41A7EBE3AD025FE
                                                                                                            SHA-512:060610E7C30AB2625C85315E0AC105E08888BD2B37A9ABCFA33566565C632E7397FC5DB5EDF03054FECA2B2F46CB73F54E2CDB258CCD470D1947A27BC7DE997D
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...77............" .....p...P.......................................................e....`...@......@............... ..................................p....Z..8........(..............p...........................................................p...H............text....g.......p.................. ..`.data....>.......@..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):203024
                                                                                                            Entropy (8bit):6.207298456243025
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:ADzcvTHdJdCe4dCLLe+Yfn3gwmMWQArD5/oE5bF65eUV/uuTG:AQT9WDvgwzWQArHUV/uui
                                                                                                            MD5:2B2EBCE91DD24647BA64032AFF474EEA
                                                                                                            SHA1:633B37C3F8ED3E2E036A6301E3A99AE2382F9BE6
                                                                                                            SHA-256:CE51C0A016E0D830BB2325B917DE3B959E42DF82C47A681287C97F0C27846AF4
                                                                                                            SHA-512:9718A8E686CA2F7E27DB887AB94E0C5578CDA23170C27E97BEA1D0F95A30F29A4D742BDBC791C1E2F91D9AD5D2BE383701DBBA3D0AD054DA06D30863CD5DA1F4
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .........P............................................................`...@......@............... ......................................0I..p........)......L....!..p...............................................................H............text............................... ..`.data...M9.......@..................@....reloc..L...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):17072
                                                                                                            Entropy (8bit):6.659738769823181
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:zpmblJeIeGXxV7wl+W+XWvIX6HRN7ckABmo8R9zYRHI2jW:zLSWIWcVmoQ9zsBW
                                                                                                            MD5:1C22BAF0E27D88F5BCD119256DAE3CFD
                                                                                                            SHA1:B6A788DC9E55A276998EFE47C21D9F655AD6842B
                                                                                                            SHA-256:0816FEBC2BA00D8CC16C843A5D629ADC4648A36EB45082DE8F0A29ACD5AEAD45
                                                                                                            SHA-512:A14BA425BBB69F11D6F264CDE110034B6DC8CAA13DDB85F9E6C223C0D5176D168D8DAFDAEF3BDE86803CCFEB99614D1F9DE2D981DBC8E19225748A7C1891FAA7
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....>..........." ..0.................. ...@....... .............................."i....`.....................................O....@...................(...`.......-..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B........................H.......P ...................... -......................................BSJB............v4.0.30319......l.......#~..l.......#Strings....,.......#US.0.......#GUID...@.......#Blob......................3................................+.....S...........................3.......9...O.............}.........}...........$.....A.....d.........................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):47368
                                                                                                            Entropy (8bit):5.343676854529679
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:+W+wWvLfT+rudWBj/DbodqYfhKnVsL9WkS89KJKfCvDXxO88+aEZ4jIwVsBvzN42:eRLkYoYkaBv688IVO/X8FCltxf9z56g
                                                                                                            MD5:CF4ADD9E2E8C056C75B770CA9E4B64B8
                                                                                                            SHA1:B8EE4E78731D0D65E3EDEAF9C263BF703873AD7E
                                                                                                            SHA-256:A28CE11CFA6608760F22E102423BFCD6AC33B693287C1F15AFBCDABD3EBAAECB
                                                                                                            SHA-512:D72DEEC88359E38454FC783B82FF7C36CE0A50FB76DBFB74E469F7BA262457105474E80F9DAA09B04A10CAA70A45860D83926ED80EFCE8D685FE1961599B057C
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d..............." .....`... ......................................................7M....`...@......@............... ...................................................)..............p...............................................................H............text....W.......`.................. ..`.data........p.......p..............@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):80032
                                                                                                            Entropy (8bit):5.840306606911554
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:PH4czT4Vhd+Cv8A/oqZvD2olsyrbktai3zY:PV49+S85qxD2omyr3sE
                                                                                                            MD5:A862087E377CB4E1CED00DFA23160CB3
                                                                                                            SHA1:65198639EFED63E4EB19839876453E6DC3C1D957
                                                                                                            SHA-256:7F450304CD7FF566C745EA2C776160865DB400D42A2EDC206020D8735C7B233F
                                                                                                            SHA-512:136ADC24E973984D67227E66FCB6BDB3002C23D9883D20F111D78448B6DCB667DA0A32E30292D669AC55AE35B2106FE754D8C262505AE5EDE9058D750E74B50F
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....S............" ......... ......................................................C.....`...@......@............... ......................................4&..X........(..........p...p...............................................................H............text............................... ..`.data...............................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):743696
                                                                                                            Entropy (8bit):6.6621018055827355
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:EwTQLZPFIwJ04TS1jMoubC+hfzF89TwM/BiXtDaCPzFPaOL8j0ecA:TTQd9IwJ0B1jMoubC+hbO9TwM/BiwCPE
                                                                                                            MD5:E10561CCC3B6C7D0AC9705A411803DEA
                                                                                                            SHA1:558A8054F0ED9F680DD20561FD9811F3C818B716
                                                                                                            SHA-256:E5D98E1ABE75C19B49952C9D5D4E28B54D336A73B9C14773FB4E7197BAE00E3A
                                                                                                            SHA-512:77C60173B7037A9E3AC714AAF5778281BDC4AFCA9166314051D4784E53000AA33FAE46E90B4DD56701AC8C28558C252E0C04564CB5C8704F09BC6D3F3A732041
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....q..........." .....@...................................................0............`...@......@............... ...........................................X...0...)... ......`<..p...............................................................H............text....<.......@.................. ..`.data........P.......P..............@....reloc....... ....... ..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):30880
                                                                                                            Entropy (8bit):4.305226325250858
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:jWe1Wv4QqU2+30cM5YA6VFHRN7kuiHR9z0vD+z/:N03eFClkt9zaD+z/
                                                                                                            MD5:F0A9C1F351FD248118EEE637D9B404D6
                                                                                                            SHA1:25596AC1293D92EB144261BADFA3E76D51413E65
                                                                                                            SHA-256:A3E2FE9700B643FCCCE0628540A846F45714F51A9DA17C0FFE56BDC4C739046F
                                                                                                            SHA-512:0F05B14C36907A33A13EAD741F48C6679D06F42D667AA517CB31C8B06642499558D985C2955335CB3F426B63410B84B9E21E27A84546CC6EC8BAE84116058321
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." ..... ... ...............................................P.......I....`...@......@............... ..........................................0....P...(...@......0...p...............................................................H............text...1........ .................. ..`.data........0.......0..............@....reloc.......@.......@..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1075360
                                                                                                            Entropy (8bit):6.616695520960553
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:yPiP0JcnrfOsdV0Z8oApKK1sPTdokGH5OTNWLOdN2XyhtAVv5d6wGGDSxw0aY1ne:yLmnuuy/6TlGGD6zaIn16O9LH1unv
                                                                                                            MD5:29DC8A1515153483DC01004EBFF4EA6F
                                                                                                            SHA1:5981CDA980A00577D8B0D4777315417B12730256
                                                                                                            SHA-256:3C65989CF6C67DE98E21CE52A607F2A49F335BB465937AA9BA994B0F8C86E541
                                                                                                            SHA-512:BD71C0C1BBCDE7F540AA25BD03A39301A8704F63D33E1FBD7CB98C9D3117CA68A4447DD43FB78B8D26B98727408DA02CFC2435B0296543DF8886B7456D4C6346
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .....P...................................................@............`...@......@............... ...............................................@...(... .......K..p........................................................... ...H............text....B.......P.................. ..`.data........`.......`..............@....reloc....... ... ... ..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):19616
                                                                                                            Entropy (8bit):6.475079017005305
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:cMXTSv/fUNRvGZYdf3zyP/we9+uH5WdNWvFYA6VFHRN7Iz8u/6fR9znQQD:fQ9gcFFClIgl9zJ
                                                                                                            MD5:CA0B1BEED7162550FB7FA2389A6B94E8
                                                                                                            SHA1:11B6A2A0A81A67270A152391D2D8863B42FD388A
                                                                                                            SHA-256:D88BB22EC1FF049550D1DD13B8B9C27B094822FBF73D034BDB4F5546F1AEC579
                                                                                                            SHA-512:1068AF9F03FB8CAFA236F2D720F5C01C30D90E5B67EA03B54C9C42406B680945A6E808ACC31A57E11F9B788DD007E029CE114A919564E53FC6B9C0B97577C260
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...'............." ..0.............v8... ...@....... ...............................i....`.................................!8..O....@...............$...(...`......87..T............................................ ............... ..H............text...|.... ...................... ..`.rsrc........@......................@..@.reloc.......`......."..............@..B................U8......H.......P ..h....................6......................................BSJB............v4.0.30319......l...h...#~..........#Strings............#US.........#GUID...........#Blob......................3................................h.................2...%.2.........R.......b.....U.....U.....,.....U.....U.....U.....U...3.U.....U.....U.................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.C...+.Y...3.o...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):174240
                                                                                                            Entropy (8bit):6.276884758080206
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:ioeEmXYzdfd6+Vfz5mDVVdwF6xARZvcKZzxuR1BB1GwRV:Ve1X4fd6qwVdC6x2ZvcK14B73
                                                                                                            MD5:60BE3B0FE0CE54306E547728C541616F
                                                                                                            SHA1:505519153734F9B58FB37DC4E86740FF7D057896
                                                                                                            SHA-256:577D62369B948EC8DAC8D01403987007EDEF6409A8FAE7DF733FBBC068086A75
                                                                                                            SHA-512:AB770C4882396808EA49D216367853D0041A63F20CEE3F6BB64A06417D7A5AF07FC1C19BB60948B04D411D0B27B45B1B3C5C316F1D06E623A34B54E79512D055
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...<r............" .....0...@......................................................H:....`...@......@............... ..................................P....<...........(...p......X...p...........................................................P...H............text...}!.......0.................. ..`.data...."...@...0...@..............@....reloc.......p.......p..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):23840
                                                                                                            Entropy (8bit):6.309945960737407
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:hS9H4Ay0l9Jr3OzFPhoact/iKMePLexkrW1rU1ZXt8+EFWc2WvDcrX6HRN7HVyNf:E9H4Ay0l9Jr34FPhoact/iKMePLAxiA8
                                                                                                            MD5:7690C569AA58A3BB3D19D8B45D37DF15
                                                                                                            SHA1:EF1D0FC539EC8B943B58C02C7E9B78415BFF599F
                                                                                                            SHA-256:3735702159E6D3D1EACA9BB7A9763D1CE58F84A4ED246066EF1780F6AEC67F63
                                                                                                            SHA-512:3E9CD45453CA82616BE8FD97092E6741CC2AAE98E0B710282674806D2C9C7E6782F89B580F241D00584173A68642643E64F70AE9FBCD25FAEF3A1D46D3A1393A
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..*...........H... ...`....... ..............................5.....`.................................sH..O....`..4............4.. )...........G..T............................................ ............... ..H............text....(... ...*.................. ..`.rsrc...4....`.......,..............@..@.reloc...............2..............@..B.................H......H.......P ...&...................G......................................BSJB............v4.0.30319......l...<...#~..........#Strings.....$......#US..$......#GUID....$......#Blob......................3......................................................i.......G...........................:.n...J.t.....t...P.................C.....`...............................................).....1.....9.....A.....Q... .Y.....a.....i.....q.....y.....................I.....R.....q...#.z...+.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):2861216
                                                                                                            Entropy (8bit):6.795350514221502
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:49152:/LlMm2mf+ncGZUm3k+mywJOHPxIyiNMZ62YGkO3egTxiZsc5hBhB0X1v:DOOQZYyZ62YGkO3egTxiZs209
                                                                                                            MD5:D9A6328A389DAD8E4A5C9BF9EFD8FA77
                                                                                                            SHA1:05C93E421CFA10B7504E867E8EDEB3E68C4EBE8D
                                                                                                            SHA-256:1BB6848E76A1AC2966515EE04B80FFF63A1566CC086F267B184040E9F681E808
                                                                                                            SHA-512:052CF47E55E025A03E7E0B92FFE49B8131BF7E7A0E46A4244598077601AD01B72D4060A393E8214CC4045435D930F9516B740D0DB666FF1207D7D0E7BCCC50A6
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....a..........." .....@)..0................................................+.....0.+...`...@......@............... ..................................p.............+..(...P+..-.....p...........................................................p...H............text....8)......@)................. ..`.data........P)......P).............@....reloc...-...P+..0...P+.............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.654808513658327
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:wowweWm7WviYA6VFHRN7FUe3/6fR9znQfNzn:woEKiFClFUeA9z2
                                                                                                            MD5:4F3162B9B035A7B978BC88F73F77A4DD
                                                                                                            SHA1:EF3EE0BC3C8525D34FB1B3BC14ED6A11759DAE02
                                                                                                            SHA-256:61BD0CBD9C8C85A1B6C783EEBD1568B40923D2EBF4C0967418D6202371CE36ED
                                                                                                            SHA-512:CB586CA8F80BC4BF51CC3F032842FE9C0B987BE8742670BAD2C2A549C724B3770761175F3BF088A8C242BF1C37C5302352F9212C4FCACB2F8A8BB0ABDEAD5EA5
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....N..........." ..0..............*... ...@....... ..............................d.....`..................................)..O....@...................(...`.......(..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H.......P ......................8(......................................BSJB............v4.0.30319......l...0...#~......@...#Strings............#US.........#GUID...........#Blob......................3................................................E.............|...............i.)...'.).....".....)...~.).....).....).....)...e.).....).....E...........v.....v.....v...).v...1.v...9.v...A.v...I.v...Q.v...Y.v...a.v...i.v...q.v...y.v.......:.....C.....b...#.k...+.....+.....3.....;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):25376
                                                                                                            Entropy (8bit):6.287661962300747
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384://AAaFiTCmM82SuxDJQE3W8FWvmGX6HRN7FNbZR9zLVq:3paFiTCm0DJQoEmWWFFT9zk
                                                                                                            MD5:F6FD1153DDA80799A04EE9351FBC223F
                                                                                                            SHA1:107E1B848C215F30569BFBC200637AFAF60D8C06
                                                                                                            SHA-256:A4D48F2C0F6C22731A57D1336C82EBDCE6E5BA3EE7E13BFD4893979E53132FE7
                                                                                                            SHA-512:1F588633E055FB992DE7B17072A5829E08AEF4A1A0DB6201CC966B7258D342531ABA5A81514BDFA84E41EE0A734848F175064B5C0D2BEC369AA66F9601EB1E09
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....A............" ..0..0...........O... ...`....... ..............................,.....`..................................O..O....`..4............:.. )...........N..T............................................ ............... ..H............text..../... ...0.................. ..`.rsrc...4....`.......2..............@..@.reloc...............8..............@..B.................O......H.......P ...-..................HN......................................BSJB............v4.0.30319......l...T...#~...... ...#Strings.....+......#US..+......#GUID....+......#Blob......................3................................<.....H.........~.......................).r.........;.................Y.......................B....._...................#...........................).....1.....9.....A.....Q... .Y.....a.....i.....q.....y.....................R.....[.....z...#.....+.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):22176
                                                                                                            Entropy (8bit):6.387333708399484
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:5UuzLRrw/cSmWtGA+bH7S3W1HWNYA6VFHRN7xBmo8R9zYj:5UunRrwPtGA+LOi2FClLmoQ9zO
                                                                                                            MD5:3D282B70FE068939C3EB9854ACE54354
                                                                                                            SHA1:E37211642E776F03E9F45C3C0C19A0A71C5150E0
                                                                                                            SHA-256:F19F1E7B9BEFA1E1F4F8CD12232AE3A94ACCE6D0F6662C195527204B65B0486C
                                                                                                            SHA-512:6AC990C8FCEC3597C2885228C5775A995B4AFEE21DADDAA35B689880636F789770A11925CABACD91098D5F0AD89D795D4D50895C12E93A7CD3E69C3F517F8B61
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................" ..0..$...........C... ...`....... ..............................J.....`.................................cC..O....`..D................(...........B..8............................................ ............... ..H............text....#... ...$.................. ..`.rsrc...D....`.......&..............@..@.reloc...............,..............@..B.................C......H.......P ...!..................LB......................................BSJB............v4.0.30319......l...P...#~..........#Strings............#US.........#GUID.......\...#Blob......................3......................................:.........E.a.....a...^.A.......................P.....P...~.P...(.P.....P.....P...e.P...r.P...".P...<...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y...............................#.....+.>...3.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16648
                                                                                                            Entropy (8bit):6.674662538277605
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:HaTGqLWl2Wv4MYA6VFHRN7paxMR9zGV5wwgTp:HaiqeX4MFClpp9zTTp
                                                                                                            MD5:9D85EDC5D0EFA8F803820E3D40FCFA23
                                                                                                            SHA1:73E9BFB4AC2B7B9424B7DBD5D257DF1E04945A32
                                                                                                            SHA-256:560E53DE0E025CDE566C2C30080DA83E3DA28D592D5BCFFBA78CCC6198F2B2A8
                                                                                                            SHA-512:BD15EA96737C7AE62C75218BADD5C979656252BC30DE81718EC07A0C177B2A268157A82EEDAB838EA2B4690D8AD609297DC518200F377878DF986BB5910772C1
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....]..........."!..0..............+... ........@.. ...............................@....`..................................+..N....@...................)...`.......*..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................+......H........ ......................P ............................................6...(~s1..(IE.?.>.1..1....~4...#.m..9.5{.....pz.j..eU...~.Lf../W.c.\Sf..].@.O..........x..%......pi..g...z5.+...*.8.HBSJB............v4.0.30319......`.......#~......H...#Strings....4.......#GUID...D.......#Blob......................3......................................Z.........9.........................,...5.............{.........F.............................#.....p.........................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16136
                                                                                                            Entropy (8bit):6.738272740252956
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:xEKxAG+HWRmWv1pWjA6Kr4PFHnhWgN7acW9aN6AgfcMbnoQNpX01k9z3AZs8g7D9:j4WRmWv1YA6VFHRN74a0/7R9z59DyM
                                                                                                            MD5:30BF6C4EF92AED34FC143A9724F3CEDD
                                                                                                            SHA1:1BB4BBA6801925D9B9BBD7DBBCCF1A8F522B4087
                                                                                                            SHA-256:40E5813EAB9D7FA7A1914DBBD8E452C04F9FF053C5A4E5BE494DC85AC4BD9246
                                                                                                            SHA-512:BE5E7104F3635D000D7246832AC54C9E32512DF678CD4B4BAFFE81EE3A1178BCD0028989AF71C2617FCF849A316F67A3F7D790C901B1D35CCBD08F16C24BA592
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...6............." ..0..............*... ...@....... ...................................`..................................*..O....@...................)...`.......)..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................*......H.......P ......................$)......................................BSJB............v4.0.30319......l...H...#~..........#Strings....<.......#US.@.......#GUID...P.......#Blob......................3..................................................W...R.W...g.D...w...........0.....w.......................>...........................................>.....>.....>...).>...1.>...9.>...A.>...I.>...Q.>...Y.>...a.>...i.>...q.>...y.>.......................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):415904
                                                                                                            Entropy (8bit):6.6490929239322965
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:zsUTEcoc/FGzasNt2l4ru2jKw6xtQ7/tvjETqeZ03EdoUj4MKD/6:oUTf/FGGsNtM4q2jStgjH+4Me/6
                                                                                                            MD5:19296608F2A3075C08B531122BC525BC
                                                                                                            SHA1:1F07C37BAEE61A8C4C7590F35B36721758F08D9A
                                                                                                            SHA-256:9A8F55961A23B981F489AE6F7FBC7B5919A60CC181CAAD9B9C248D3E3E542D43
                                                                                                            SHA-512:2F4BDE70E85ED6320CE94C5D64DB5247A052992648042785CCCA0A73E186825F98CAC9EB4EA9B126F2DC0A773053F763CC6539D12BC30209AEB65DB6527E7221
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....q..........." .........................................................0............`...@......@............... ...........................................)...0...(... ...... )..p...............................................................H............text............................... ..`.data...............................@....reloc....... ....... ..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):800928
                                                                                                            Entropy (8bit):1.7782280660549779
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:9Nira5KkDpWjA6Kr4PFHnhWgN7awWLCjVi6KrIX01k9z3AszW7szwL:9IrOYA6VFHRN7g49R9zri7sw
                                                                                                            MD5:B945BB71515F3597C3B3A58D2F1E3B54
                                                                                                            SHA1:E37EE014E86DC82A3FFA30BD1BE29BF6C4914673
                                                                                                            SHA-256:EC2086DEB616AF11A27BDBD0668638254A835303CD922211F5CD669FAA195F54
                                                                                                            SHA-512:373BED1C64322AB222967C73DF3FEBD1F53D227A5BC33B7E9E14DCBA43CFFC76D390D03ADD117160EDD4022A34500D0DD3170574469D3CF8AE1A26B3C49A0823
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....)=..........." ..0.............&)... ...@....... ..............................,@....`..................................(..O....@..l................(...`.......'..T............................................ ............... ..H............text...,.... ...................... ..`.rsrc...l....@......................@..@.reloc.......`......................@..B.................)......H.......P ......................H'......................................BSJB............v4.0.30319......l.......#~..........#Strings............#US.........#GUID.......`...#Blob......................3..............................................-.....-...0.....M.................R.................h.....7...........[.....x...........D...................................).....1.....9.....I... .Q.....Y.....a.....i.....q.....y...............................#.....#.....+.....3.X...
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):387248
                                                                                                            Entropy (8bit):6.555993554831254
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:PTjRRbvaPik9w6VSMAc15k8H5iGD7x/v9a4w45N5WkaGhLWukVTRW2e:Pfo9w6V3oa2vsNLWuWle
                                                                                                            MD5:6807A5F492DD8EA805BF55A64A754868
                                                                                                            SHA1:D6D2707F2A55F13B96196BD4182347AD41C876EB
                                                                                                            SHA-256:CA18410D83DA120038813EDEBE4086CCB94F6AAE6DB194F594D7207695223E0E
                                                                                                            SHA-512:B9AEEE86CFB836F3BDAB0D8E4453F8D65A7899B11260E40340A56D7377AE17BC239E4FB212FD42F07DDBE7C0ADE5F5F26773E297CFCA1FE80B1410C4D3C36C03
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...~............" .....P...`......................................................H.....`...@......@............... ...........................................%.......(......@....&..p...............................................................H............text....D.......P.................. ..`.data....H...`...P...`..............@....reloc..@...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):47384
                                                                                                            Entropy (8bit):5.385545715496689
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:768:QMGgXwsP/QEBuk3bqUghjhyCKPivxbzY17tvALj0fjW7F9zC:QCXwsP/QEBuk3bqUghjwCKPipb017tvB
                                                                                                            MD5:BA98951D775757104E005E5F4E209C3E
                                                                                                            SHA1:6A59BD6130172B72FB97C35CADBD0F5D9E549732
                                                                                                            SHA-256:7D3347F76557D5655A5BBDAD0477F5DA12E337FC77E86B1B91E269A3B3A023B5
                                                                                                            SHA-512:6D4EF736011D50D140932DD54DC2A5E40C574AFFB9F0FAE202C32C9568CCFFCBC12770ECF33A2A2C3BD76F5238AE360694D5FE44BD993F8A51AF330C0DB7E719
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....J............" .....`... .......................................................)....`...@......@............... ...................................................)......H...`...p...............................................................H............text....X.......`.................. ..`.data........p.......p..............@....reloc..H...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):288928
                                                                                                            Entropy (8bit):6.5444388161484195
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:5n7+Xf7eNhl3tukQB0mVgGLknb6bQSBj/Fx:5SXDe3F8kbXOkGbd/X
                                                                                                            MD5:07B65047D965B216881DBEA41FE6195B
                                                                                                            SHA1:55B9DEF720100000E115C4DD0EE887F76AF547EF
                                                                                                            SHA-256:FCBB8213C0E39D76C251588A9D6DF23B956559CE18FB38C1E7E036E822B14934
                                                                                                            SHA-512:B83292085F1C38F9B0C4F7CABF217C5B18FA5F27804CE736EAE6AB257FCB0535F6EA6BEAC88357F779A428ABFC9A3068B57609076B4F14F99C7B9EDCD6C8BE1E
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .........P...............................................@............`...@......@............... .......................................l.......@...(...0.. ....!..p...............................................................H............text...D........................... ..`.data....;.......@..................@....reloc.. ....0.......0..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):338080
                                                                                                            Entropy (8bit):6.5467859190265045
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:KXlZtqaP75HL9eEIdkh+T9jb3b41PlmF6YZTdiX2JWb:KXlZtqweDdmMy8Wb
                                                                                                            MD5:A19AEDFEB37A15AFCCE8BCC5D4D78EC3
                                                                                                            SHA1:E0805A04BC3F3B6AF99DCB066A49940E64F2F2E7
                                                                                                            SHA-256:3468B4717F086423052FCBD305CD3151CC555EF0045B9269D43CCEDCA838E47A
                                                                                                            SHA-512:C2D939074F5EA4C28770556CEA5C5DCD2A173BC6D0A0BFBA43A7A29965DCB907B2390C1D0DAF74F07BDBBD572DAEB55A85FA15C87A81730AC84ED151526660EB
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .........p.......................................................^....`...@......@............... .......................................w...".......(...........%..p...............................................................H............text...+s.......................... ..`.data....S.......`..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):47264
                                                                                                            Entropy (8bit):5.383416201972765
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:768:NB+D3qmLYSzA+DUnFT08vkFY4mPFsNEFClDm9zw:NzmLYSz1DUnFvc64miNwiDyzw
                                                                                                            MD5:1E16A3F143BBC16769EDB8E90FEF330B
                                                                                                            SHA1:CAE5E3C1186E4C6631FA3A607FB09627E60CA6E2
                                                                                                            SHA-256:D10AB35B57C343C006F982473D98ED2D2125D6D311B131390113011BC96D820E
                                                                                                            SHA-512:05A5FE0E8488D28A691824119F0B3FA03D493D91CEBED9977112A40C1BE7AB69E34ADCD49595386F231CBF756AA2CE0469867FD398642AB107B3D6449A6B9A99
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...=............." .....`... ......................................................0.....`...@......@............... ..........................................8........(..............p...............................................................H............text....V.......`.................. ..`.data........p.......p..............@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):67848
                                                                                                            Entropy (8bit):6.069064583177759
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:768:2jOHMffs25VU9QbAoqxfxGSC0e+LRnugRxFjyGw3/slSdoF31s7YiNZ/OSkk9ZP+:2lM2EoLmpsFZZwiMzQQ
                                                                                                            MD5:7C78865F32AED5CB2BED0B3240AEC113
                                                                                                            SHA1:4CCBE9AFF7D5D86D401981106C5A85FDAB5DC5FE
                                                                                                            SHA-256:5468BBB816B4A21AF610388C9AA8CC2DF47A581E9AEBF81EEA985C8D1EEA80B1
                                                                                                            SHA-512:25C7070CEB9CC1BD3815C497E4012FB951D989592D39021E7381DE93D884467A63673459CD302513C086A8088BCD6D8355E0986582844083283645FD9CC952B8
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." ......... ............................................................`...@......@............... ..................................0...4(...........)......0.......p...........................................................0...H............text............................... ..`.data...............................@....reloc..0...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15648
                                                                                                            Entropy (8bit):6.812729868383133
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:aATqxAOjfFWhUWv8VWxNzx95jmHnhWgN7agWCvwKDUX01k9z3AWipfx:awwBWhUWv82X6HRN7UpR9zvox
                                                                                                            MD5:6E5EF37CC93928F186A03F70E18D2E06
                                                                                                            SHA1:45415524ADDEF2322609C9A99B661711D4D83AF0
                                                                                                            SHA-256:8C6B948D52A18E77B796E5AE43139E155E52362075B9D3F94929BD2E1C20D3C0
                                                                                                            SHA-512:4C777BE5C8F211F448364A007BB28A45F8575B03D42B0CCAE057F0EB0EB9204CE2681AA0EDAA1A46D441B072F8188BC6361D85BF0D32A843D0F883065576D681
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...et..........." ..0..............)... ...@....... ....................................`.................................Q)..O....@.................. )...`......`(..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H.......P .......................'......................................BSJB............v4.0.30319......l.......#~..(.......#Strings............#US.........#GUID...........#Blob......................3................................................F.h.....h.....U.................%...(.%...........%.....%.....%.....%.....%...f.%.....%.................O.....O.....O...).O...1.O...9.O...A.O...I.O...Q.O...Y.O...a.O...i.O...q.O...y.O.......................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):145680
                                                                                                            Entropy (8bit):6.213889260140082
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:HXvuCBgDTeY0dpwQn60x7cftbgZyeI7XT5DFEj3C:xBgOY6aQn60x7cftbgfalCjy
                                                                                                            MD5:B5B5534716E8115775DAE499811D0AA4
                                                                                                            SHA1:A34F5CB79DCA9F2821E276979A72BE3A093764CA
                                                                                                            SHA-256:0F2701EA7067203F84D6E8D3E5E6D45C00434B41175C3CF4F7ADD5B17D7F437A
                                                                                                            SHA-512:BDBBAD128B3464B3C80C777560BA53E3297145309F53778D12A9285D469B4D79216F9BE07096F8F884251BBFA91274944F4E6E2345FE92A274F526013F637E75
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................" .........0......................................................:p....`...@......@............... .......................................B...........)......|.......p...............................................................H............text...g........................... ..`.data............ ..................@....reloc..|...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16656
                                                                                                            Entropy (8bit):6.729692051834912
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:IK6DDj+yVx/bWXDWv1pWjA6Kr4PFHnhWgN7agWz3KDUX01k9z3AWipv0t:I5+yfzWXDWv1YA6VFHRN7IpR9zv82
                                                                                                            MD5:AF34F0A70120DD8DB41F8DEC70280B5E
                                                                                                            SHA1:3C568BF4CA5D852279C54F93350385BEE5666529
                                                                                                            SHA-256:F0B69FBDB0540A52A66E7A7B5C11476E29FB9ADEB2DC7D5FF88EA12D36843D5B
                                                                                                            SHA-512:54B6A9549E13BC52CFFE199FD07D9C57EBB2F3BE4C8000FC8DC2B9D824F527379697DBB41B8371562C55082C6E0B0EFD9ACFB375AD45964A4E8C25A46834A854
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................."!..0.............n-... ........@.. ..............................x,....`..................................-..Z....@...................)...`.......,..T............................................ ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................P-......H........ ..H...................P ..........................................`j..@.e..R]?..m$...|j....3.m.~....&....fG.....UW...q.....4z...`.(.W_N.3.6.....#.'Q...}iG...............%JB}K...~..Y..BSJB............v4.0.30319......`...x...#~..........#Strings............#GUID...........#Blob......................3................................ .....................O.......................c....._...........}...........6...........B...........................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1046704
                                                                                                            Entropy (8bit):6.686390581958359
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:TQ/6mjCDrmDrvfhuginX9KO2YP2cTER5LvBWFsAtvrZogoLKpUHk04mrJNq3cca2:p4yM7SIOZ2x/Lv4djSK65rJY3iwW64w
                                                                                                            MD5:156B21AFD15DB03BA63FC8B8C3D6A62C
                                                                                                            SHA1:A66EC9D0B19374F2D5AF7E75D804C822D91F2E8B
                                                                                                            SHA-256:CCDA7C8E27CFB2C6381F0EC1A92A1A73A85255F5F69A18DFFC9067BDC12DD912
                                                                                                            SHA-512:90A03D5C4E1A7EABC21A8417C1081B7DFEC30F0639B6C3712B1BF252AD60DA70FA4D2A7C226C4806959B2410A2FAD09DF286CCA654BA6D95E7F89B605F779BCB
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .................................................................A....`...@......@............... ..................................x.......$f.......(...........G..p...........................................................x...H............text...9........................... ..`.data........ ....... ..............@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1530016
                                                                                                            Entropy (8bit):6.604389115791053
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:24576:js+K3mAKW1QUvE5k9fqzGgBBg/NGidXkOJxPSqQRJzAJO:js+NAKV5k9fqzpBg/NBdXkOJY
                                                                                                            MD5:ACF93F1D6F7AAB7CBCC26DFBC12348F2
                                                                                                            SHA1:A1A49DD8B6607E4D382DDC95A04528EAA98804A1
                                                                                                            SHA-256:3446ED6793FD49E51580FDBB047A8F15F81950D0039C2181396E3A9CC327774D
                                                                                                            SHA-512:FDC14BCAB8815987A320D9618872D978A314F3C0A3048D00EF408CBFCEE8DE67BFBE2197AE15675B813D8BC084DF33115E101F63B297E2C548E96E3200EF6A23
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." ..... ...................................................0............`...@......@............... ......................................$...p....0...(..........(...p...............................................................H............text............ .................. ..`.data...g....0.......0..............@....reloc........... ..................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15520
                                                                                                            Entropy (8bit):6.7942931270446705
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:NJ7sZxM0YDFW9BW5pWjA6Kr4PFHnhWgN7akW6/9xu3O6YX01k9z3AnIs9E:P7sDM0YDFW9BW5YA6VFHRN7fZR9zKIsC
                                                                                                            MD5:11350FC493C0939339C3327398288226
                                                                                                            SHA1:D595D0E78A90CDA3D21419A05CD8A9F42385E385
                                                                                                            SHA-256:02D8DA4B3EB2B1ABD79CABC927898DCDE50E53964078B903EA3BADC91268A2CF
                                                                                                            SHA-512:78E7C03299DDB72479BAFA4FBF1945215950360BDA662B7EF1FCD6FAE556D7D80895642664453DD6629E06DDA513D80DC1FEF7FD2C5D71C6A169B8887A2A03F5
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...3v6..........." ..0..............)... ...@....... ...............................d....`..................................)..O....@...................(...`.......(..8............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H.......P ......................h(......................................BSJB............v4.0.30319......l...$...#~..........#Strings............#US.........#GUID.......d...#Blob......................3................................................5...........U.........................&.....&...n.&.....&.....&.....&...U.&...i.&.....&...3...................8.....8.....8...).8...1.8...9.8...A.8...I.8...Q.8...Y.8...a.8...i.8...q.8...y.8.....8.......................#.....+.>...3.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):133392
                                                                                                            Entropy (8bit):6.080206645595261
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:LQz5724yeP4Sy2vmH00N6no5WkCIJJoRc0onc:y57O6mpMSoZB
                                                                                                            MD5:4E55F8E2CD309634892AC4E34D78D1C7
                                                                                                            SHA1:B96BF1860E415BDB99BCD94AF0973F31D0CCAD7A
                                                                                                            SHA-256:E8A06462CDFB428C9ACFC5ACA4BB97AB6D2C715E8029A6CD8FD5760F831A3D92
                                                                                                            SHA-512:C4F154AFA33991A3F2494F92AE0A0F2866A21C55DBC86DFD789DB143A72C241589553E433B8C86B8EBC2FDA8A756E20AE4BD59FE368200A5F094C29208DC81F9
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....D..........." .........0......................................................Rn....`...@......@............... .......................................-...........)......<...@...p...............................................................H............text............................... ..`.data............ ..................@....reloc..<...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):21664
                                                                                                            Entropy (8bit):6.343171564299715
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:4lkzkXBQ+RGP7RYpYOOT/460+WBvWctWqYA6VFHRN7dBmo8R9zY5a:y234/FClfmoQ9zp
                                                                                                            MD5:2A96C7F99E34759656F05BD0A0E327E4
                                                                                                            SHA1:1D8E9E6E179EE1271853790F99247FEBC7EB3D6A
                                                                                                            SHA-256:09BC14AA546F826EF2B834A909B7036DDD86F93ED4F1A275A9FF95A78CD61F04
                                                                                                            SHA-512:754B19268A23BE3C93B3B751F3B3888B23BB922367007DA9E155CF8B26C505B2B86DB329FC54015476305F3D81D619E447B9721DBB04C65059BCCFFA952F8271
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....5..........." ..0.."...........@... ...`....... ....................................`.................................U@..O....`..T............,...(...........?..8............................................ ............... ..H............text.... ... ...".................. ..`.rsrc...T....`.......$..............@..@.reloc...............*..............@..B.................@......H.......P ......................<?......................................BSJB............v4.0.30319......l.......#~..<...4...#Strings....p.......#US.t.......#GUID.......h...#Blob......................3..................................................................&.....".:...;.:...............'...........X.....u...........................................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y...............................#.....+.G...3.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16648
                                                                                                            Entropy (8bit):6.6812317734380064
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:lmh7op9/MWbCWvCYA6VFHRN75l3VXC4deR9zVjTTC:lm5op9ZjCFClnVXC4dC9zVjTG
                                                                                                            MD5:6DD949F6AA63BB8FE19BBF6B6B076083
                                                                                                            SHA1:FAD97047B28D631D1DDBFE4DA79E2D4E624FDFAA
                                                                                                            SHA-256:45886BE34B3B81717B4913564361B12D7AE3B9926BC85F80DF64026C4EE9B4D7
                                                                                                            SHA-512:B62404B9AF3077DF8318E3CF8C7D9A3E97070EAAD07F5F6AB3E9E7C8F1763C14966298B7ABC41BE0AD96A07E3DCA2B2620C234ECFEEC6E020762CFCF6156FE4E
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....Z............" ..0..............,... ...@....... ....................................`.................................a,..O....@...................)...`......t+..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................,......H.......P .......................*......................................BSJB............v4.0.30319......l...<...#~......h...#Strings............#US.........#GUID...$.......#Blob......................3......................................&.........W.............................j.Z...9.Z.....A.....Z.....Z.....Z.....Z.....Z...w.Z.....Z.....#...........................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):243872
                                                                                                            Entropy (8bit):6.50591783119501
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:mfSRUsXJHsqVpPq+Pu1Nr7tXAjsEpN0Qif+j7kgiuG4krZAuZAt0/+JvyQ4UjIPl:27s5Hsq7Pq+67qjhp+QifuvtzJ4TwM
                                                                                                            MD5:2AB51F750E3B9C69CC2EBC9ABE2EF369
                                                                                                            SHA1:3D19ABE16F55A9366780C2056210B87E9A78838D
                                                                                                            SHA-256:D563C1EAF08DFDA8FD1860BF00FCAB903C85C91A299379D6EF73C3AECA2B7A9A
                                                                                                            SHA-512:13633EDFE2C14117BB77AC7D94D3A2E27C19660F73A8E751F9D73B75C6AACD066954E7EBCD7B11F39A627EA9FD2F2B3455FF90947156AAA1DC664D5387699947
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................" .....@...@......................................................d.....`...@......@............... .......................................P...........(......h.... ..p...............................................................H............text....=.......@.................. ..`.data....*...P...0...P..............@....reloc..h...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):272544
                                                                                                            Entropy (8bit):6.50562073982023
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:9q6gkJLdnAwEqvTlz1aYqsOMBFK0rkir51KYb8FK3MEIS3PQnZg28aq/xv642ucw:0dkJLN5EqvpzTC01anZ0/H2NfFgzFIS
                                                                                                            MD5:3D7131BF95378643004211E17DF764AC
                                                                                                            SHA1:5A4C0F7C5AE61FED16345B693E5CEFE2C3CB728C
                                                                                                            SHA-256:B649BBE057F0C5B5EEFEF65087AFB3EA54EE2DBDE1BB03C532A0D894E783C031
                                                                                                            SHA-512:1C730C3BD483223D0B8E622EE649C838F0DA6F97E25F5050F9A629A1B0271A8B8E10741D101A5A0645D7C4166E2FD7F53982506EBF10A4A17F7EC65A6394317C
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...P............." .........p......................................................v'....`...@......@............... ..................................p....f...........(......L....%..p...........................................................p...H............text....|.......................... ..`.data....V.......`..................@....reloc..L...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.74478738201605
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:geMRqXWDRquRqm0Rq7Wv0YA6VFHRN7utHNsAR9zF09RGZ1:/GqKq0qmuqK0FClMts89zm9RG7
                                                                                                            MD5:8E55387B87036298850351AB1C4E6473
                                                                                                            SHA1:F17FF8CD1DF79360702FD7EC6B14F4E5351B9653
                                                                                                            SHA-256:B6B0E4CFAA7C085A4854B80327052A0ADA77CBD8D6242C73316AFF391A14EE56
                                                                                                            SHA-512:8EF76D0448570A217BFCFEF2185E1A910386285FC3F640E2BE9337289D5CE46DC23BE15F2F453DCB49F1EC3EE8FA56F0009AC1AB1848B3727B23F3CAF8368C70
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....7............" ..0.............:+... ...@....... ..............................z~....`..................................*..O....@...................(...`.......)..T............................................ ............... ..H............text...@.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................+......H.......P ......................h)......................................BSJB............v4.0.30319......l...p...#~..........#Strings....|.......#US.........#GUID...........#Blob......................3..................................................;...x.;...3.(...[.....^.................I....._.................w.................G..................."....."....."...)."...1."...9."...A."...I."...Q."...Y."...a."...i."...q."...y.".......................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15648
                                                                                                            Entropy (8bit):6.828509514457341
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:icRPWYRZRp0RjWvUfX6HRN7UJRFDR9zzKKDmP:iWNvpuiUfWCzl9zs
                                                                                                            MD5:7BE96ACC4C7DD6DAF7D374CD907E9E69
                                                                                                            SHA1:32A66E89D313C03054DB64C0E2817B377D395B88
                                                                                                            SHA-256:41D02C060070592CB1E75C25E1F052823DE17DE692F65C53A0050E292156B4C8
                                                                                                            SHA-512:2891F08E8CA1321E555841CA8C8A831CB4C1090DEF9FCDDFFA5973E2FFBA3694C53F52861F92D41C146A51F3FE1EA96FED99609C84A35C8378AFE8D4B7630B00
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...;............" ..0..............)... ...@....... ....................................`.................................k)..O....@.................. )...`......l(..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H.......P .......................'......................................BSJB............v4.0.30319......l.......#~..4.......#Strings............#US.........#GUID...........#Blob......................3..................................................8...x.8...3.%...X.....^.................I....._.................w.................G...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16160
                                                                                                            Entropy (8bit):6.70432965142328
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:rWQRLWdRoRA0RHWvFSX6HRN72OFDR9zzKUVx:rWi06AuGFaW2Gl9zDx
                                                                                                            MD5:202E1D4882ADC18706D82E39A66BC8B1
                                                                                                            SHA1:C9CF5CF0AE8377E7D19FFBAF194127F7937B6CEB
                                                                                                            SHA-256:AF0431593029BE941368EEB132DC9BDD8666A1E4735E5F7209B2B998A50B25AF
                                                                                                            SHA-512:EDAFA2FF6BB5E229FD3CD44B0AC3E65F021C0BE53B98D5EBCD0E4E4691369B9AA0055BF3769E45CC7700B81E7C4FD51492B4C2E949B99FDC98DF975F32E90684
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....0............" ..0.............v*... ...@....... ..............................ka....`.................................!*..O....@.................. )...`......8)..T............................................ ............... ..H............text...|.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................U*......H.......P ..h....................(......................................BSJB............v4.0.30319......l...T...#~..........#Strings............#US.........#GUID...........#Blob......................3............................................................D...........o.....*...........Z.....p.....?.......................&.....X...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):84128
                                                                                                            Entropy (8bit):5.872675308344579
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:TqgxVcA9+/PACL3jTuDw9wbnEiZE+eU6p3ikzg1O:Tqg/f+3AiXu8ebnu+P6N/8s
                                                                                                            MD5:4528413D622621E35856F07EA263CD1B
                                                                                                            SHA1:5BB25492DD02CC7E9490CF6CFBCF28A248636DD4
                                                                                                            SHA-256:A298995294C59D04947F91290FB7030ACDC4DB3C5B6B1981FBC8C0136CD1B25C
                                                                                                            SHA-512:4CF1CB3A615C431080842CDB5BF3E3C322737BDC6719AC061898ADCF38E47E1A24C0B72238E30BAD0BABC91DFCC7F6BA5148195E1D43A3CC595E1CBC5D93EEE0
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...:+>..........." .........0............................................... ......d,....`...@......@............... ......................................t(..L.... ...(..........8...p...............................................................H............text............................... ..`.data............ ..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15520
                                                                                                            Entropy (8bit):6.736585195684987
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:YfFQWJmWvMYA6VFHRN7YgJtHNsAR9zF0TYZbv:6FHHMFClLts89zmTM
                                                                                                            MD5:80BCD0CC0FED45B44F8AE08E6C55ABE4
                                                                                                            SHA1:21C2FFCC9848ACC81BAF04B7BAC62978549E1D87
                                                                                                            SHA-256:1F3F7EB23DE0768F8BBE4F043EC8818E42AD66D7438A60991B2CED69F67A94F5
                                                                                                            SHA-512:394EF89DFFC287C0CF2E9BC76A4D88AF4277DD0B34CABFC8BE9747F79A6BFECD69F8A56EF3D5B17D64C9B1AD291C9681260B5D4B5FAD4497CE691F565BA04FA5
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..............)... ...@....... ....................................`..................................(..O....@...................(...`.......'..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................(......H.......P ......................,'......................................BSJB............v4.0.30319......l.......#~..,.......#Strings............#US.........#GUID...........#Blob......................3..................................................U.....U...Q.B...u.....|.....7.*.....*...g.....}.*...L.*.....*.....*.....*...3.*...e.*.................<.....<.....<...).<...1.<...9.<...A.<...I.<...Q.<...Y.<...a.<...i.<...q.<...y.<.......C.....L.....k...#.t...+.....+.....3.....;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):831240
                                                                                                            Entropy (8bit):6.118745272820205
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:cAw//Ot2fD+T5pdHnbAHhlyZ8OXTw05nmZfRTlnL:cAw/D+ZbAPlAmZfRJnL
                                                                                                            MD5:80F809C49EF92211D8D604ACDE19B734
                                                                                                            SHA1:FE38C548F62C9686451D7ED3BB56AD0C4014E097
                                                                                                            SHA-256:6E9365E60F9060B3E492F489E1C13EC07BD1F368FFCC5BA24D98530BDCD2D468
                                                                                                            SHA-512:303A5C5C8DB412A93BCB933A63733C532A23A2207531D2460670BBB125042985ABAAD7BADE42F8C88E835DD74895AF7B75AF5930EF623A285EB14EED869BDCA2
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......j..u..&..&..&.q.'&.&.q.'$.&.q.'..&'..&".&e..'-.&..&o.&>v.'..&>v.'/.&>v}&/.&>v.'/.&Rich..&........................PE..d.....f.........." ...(............P................................................I....`A.........................................^.......`..x...............d........)..........0,..p............................*..@............................................text............................... ..`.rdata..Lg.......h..................@..@.data...l....p.......\..............@....pdata..d............`..............@..@.rsrc................~..............@..@.reloc..............................@..B................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):55456
                                                                                                            Entropy (8bit):5.787077196786641
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:768:RZtyjfZsPdcoZZtWjbOQSW3sfy91AxQSvv3XvPHlfe2FCl1DuO9zr:RX0s1dZ4jNSW3s6cQSvv3XvPHBBi9zr
                                                                                                            MD5:FB43BE837BF3B54DAA6CA9DBB875AABC
                                                                                                            SHA1:D891C123A71A6C458DAE3BFBCADF0CB6D4472F06
                                                                                                            SHA-256:1729EE8E1CF5FC6EF86CF9AEF5BD2F689C0AEA02055963BEFE23ABE4C49F701C
                                                                                                            SHA-512:F949B1C09F7A6521282EDC49EF1162046F8E6F33298C4B6ADD25B3B0A9ECD646270DD60865C7CCE882FAD2E0DDF81300874B410AC246BF5995E50732BA5DB755
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....p..........." ......... .......................................................\....`...@......@............... .......................................!...........(..............p...............................................................H............text...(y.......................... ..`.data...A...........................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):264472
                                                                                                            Entropy (8bit):6.565006382155934
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:B14BmTBMCV3tgcWf/e9wYxn1Wc/od4pFFm4n2C:/GCV3CfqpFFgC
                                                                                                            MD5:DB981290B935938AA7FCD85B332E370F
                                                                                                            SHA1:21E754B0DBBC323F6444D38E551AD4237C1E3CF5
                                                                                                            SHA-256:D57CFCF89FDFAFC8B5F86B7DA586B72AFF6B1997AE7896A17323993BF1741389
                                                                                                            SHA-512:45EE7D549EAC2990B17F15AA326DF1CAC57825C5E5EA2E1F854C9EED352FA03102687FD8FAC041F2CBCCAC4CD690EBF609B7AC4EEF5F97859079974BEA20DF02
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.... 8..........." .........P.......................................................K....`...@......@............... .......................................f...........)..........X%..p...............................................................H............text...5........................... ..`.data...2;.......@..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):104608
                                                                                                            Entropy (8bit):6.03720418323957
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:eE8AlMvSLSjaab0PihEzfQHl9I+CAvpYhLKPyf9DKiVzm4G:eEjGKWKAuf+af9DKCy
                                                                                                            MD5:3760E66ADE87F95A0AF203D73335570E
                                                                                                            SHA1:81D2896860642BFD22384D01F3EAAC123BA8E8BC
                                                                                                            SHA-256:3F9B710E88C21089D7D7ED538B4612527A2BC5C160A41C148B872A8C84FBA756
                                                                                                            SHA-512:79AE5F2801E2498EF13C756F4CA3162F612146D5875081D85EB94EAAE15339F3D20E208E2803DEFD42C6917ED7E7F3B1606D7EAD04035007BA77FA9068BFE405
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....%i..........." .....0...0...............................................p.......@....`...@......@............... ......................................H-.......p...(...`......x...p...............................................................H............text...{ .......0.................. ..`.data........@... ...@..............@....reloc.......`.......`..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):55568
                                                                                                            Entropy (8bit):5.419488526897619
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:768:+TUsLf/NM8/u0koRo21g1PCYh0UskMFClYRFT9zQ:+QmNMH0ko71g1aYOUskIiSTzQ
                                                                                                            MD5:7815CF4E3103FB75B16B322B82CA0A92
                                                                                                            SHA1:1904D409EF775FECBFD81195B44F85BFDD097AC7
                                                                                                            SHA-256:EC73EF6B6BE1C451C5222C593E7178DAD79C8E61292BFBE44CD1292D5BF6D9BC
                                                                                                            SHA-512:E6900B2B1A2D6BEA175DA8D2453BBDC6432E20EE28CEA1156B1644CD02945B3886337C620C9EEA9A6FCEA7EAA68F23CC46E3D70BF9641DAA1F6393A8308A1D7B
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...}.<..........." ......... ............................................................`...@......@............... ...................................................)..........X...p...............................................................H............text....p.......................... ..`.data...E...........................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15632
                                                                                                            Entropy (8bit):6.823933557530997
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:Z1PXcWQqWvxYA6VFHRN7bih7RxB+R9z0o:Z1PW7xFClG7Rxw9zf
                                                                                                            MD5:0D8AAF01FC45951BFFF5FE30ED082863
                                                                                                            SHA1:DC29F5AA8215EB09E48953871554BDDA54F1540B
                                                                                                            SHA-256:57304750022F054C5AA0097450C54D20484BF3AA564BCB1E97847FBF6C2E1E21
                                                                                                            SHA-512:04886F62BC6656B18F2CD7077EEFABEE2A8F64953CA37E71BAA758D57D8375DE7A91C56E3E3E7B8B41643A5CC0568982E0AFDB4875B4FCE53C2625B4E7C204E6
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....t............" ..0..............)... ...@....... ....................................`.................................g)..O....@...................)...`......h(..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H.......P .......................'......................................BSJB............v4.0.30319......l.......#~..D.......#Strings............#US.........#GUID...........#Blob......................3................................................!.2.....2..._.....R...........E...........u...........Z.......................A.....s...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):88336
                                                                                                            Entropy (8bit):5.879093770998518
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:1fNv1C2lUQAOT1sJu0Z33qpE3JZr4GBo333333333333AQ3Hkkk33kLHtSaiOpTe:11dVl5Apu0ZqpmDr4G6333333333333g
                                                                                                            MD5:401E2BCACEA756C5452E02FB3BDF39A1
                                                                                                            SHA1:E4EFD4116196365376EC8082E16DE95B6FA7BD7D
                                                                                                            SHA-256:61865DD41C1516623E403109118DDFA7645FD95121CBAC0583BA1CA2D541E556
                                                                                                            SHA-512:0BB32643A9D86D047EF359D91C60634823F7220473C53CA22AE9A92B6A68A60CA60C383290846107828EC39CA52A16566A3879A3047211AFC0D7E5466F1A19A0
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....r..........." .........0...............................................0............`...@......@............... ......................................h).......0...)... ......X...p...............................................................H............text............................... ..`.data............ ..................@....reloc....... ....... ..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.713782816724895
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:yzRHy1MW92WvNYA6VFHRN7hUtHNsAR9zF06Im:yzRS13XNFClMts89zm6J
                                                                                                            MD5:14C84085F431CE7FBA0F91AEC4448847
                                                                                                            SHA1:97FADEBD3354FFCCBE81BF2B0B29F7FEC60AFAC1
                                                                                                            SHA-256:432AB703B7DFA567EC4E9C4717DFD2B9BB0EC8F373DBDA0771C10A5897E08D9D
                                                                                                            SHA-512:5CA5F10ECBC7575F6C022BB1B45498F0F8D0417CB5CF4B5F647971C439E216FFA51526BCFA2FB39997D3C01F0F129228A2A3401C164AD756D1F1D807D1BD112B
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...Xmn..........." ..0..............+... ...@....... ..............................._....`..................................*..O....@...................(...`.......)..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................*......H.......P ......................L)......................................BSJB............v4.0.30319......l.......#~......p...#Strings....h.......#US.l.......#GUID...|.......#Blob......................3....................................../.........h...................................J.......a...............-.............................../...........................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):55560
                                                                                                            Entropy (8bit):6.584918050714321
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:OayNEwaeXqJMkhw8Vb6TVpm2wkdxpim9zTfi:Oowa0qJE8Vb6TVpm2wkdxv9vfi
                                                                                                            MD5:3D19AC5866E193231AAB0888EAC74A56
                                                                                                            SHA1:CF3A6E805498201A1D21BC87067F058C89DC31B2
                                                                                                            SHA-256:53726755857B538B3676CABC39989874BE072028FD5B39360A7580D73A14E562
                                                                                                            SHA-512:681B24EF94B6F4E39F21532D67ED61DC693F5F0BAB16AAAAC76149C79D17C43118C69157D86D951714DEEB9EC2238468D9F0C1A99673B54CFE805989D4FB81AB
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....n..........." ..0.............N.... ........... ....................... ......5&....`.....................................O.......T................).......... ...T............................................ ............... ..H............text........ ...................... ..`.rsrc...T...........................@..@.reloc..............................@..B................/.......H.......p^..HS...........................................................s&...z.~....*...0..........(....,..*..(.....o'......&...*...................0...........(.......((...-..,..*.*.(....,.r...p......%...%...()...*..(*...*.(....,.r...p......%...%...%...()...*...(+...*.(....,!r...p......%...%...%...%...()...*....(,...*..,&(....,..r...pr...p.()...(-...*..(....*.*.(....,.r...p......%...%...()...*...(/...*.(....,.r...p......%...%...%...()...*....(0...*.(....,"r...p......%...%..
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):92440
                                                                                                            Entropy (8bit):5.817248773055368
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:0fohJcqhNwo3SjZw4gGv7+J+lNxhh5h+WcziX:0Ancqhio3SjZw4gGD+J+lNxb+ze
                                                                                                            MD5:65C30C4B56E172195C803385B3542743
                                                                                                            SHA1:9DA75B8C3CB5C87EEB1E2A99589B11F048A8073A
                                                                                                            SHA-256:A3FE636D2E150BBA7692E47E891E5E81501060D3E136CC7DF45AEC21429B202B
                                                                                                            SHA-512:C3ECF3DFA558872A5352FC829A644B7E67561F2A96B99A5A027F9C972398EDD47BEE91CF2E4973334B31470C51B296DAA73B1C5BF94340A27446B55DF8EBB2A4
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...?sE..........." .........0...............................................@............`...@......@............... .......................................*.......@...)...0..........p...............................................................H............text...]........................... ..`.data............ ..................@....reloc.......0.......0..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):84128
                                                                                                            Entropy (8bit):5.795749731518867
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:yIx5ebzfb/qs7in9eq7Zb8GJZe/c9G97kA6tirmVzO:yIxeD/q99vb8G2/e6kA8L6
                                                                                                            MD5:55BB40A1BC70FA96FBCD33B65AEB709E
                                                                                                            SHA1:E34EBB648AC89C41C8F53E6831E3B707096F8004
                                                                                                            SHA-256:2A5CE27B0E82264E6FA09504680B32B0014BE188FEF4AEDFE86D3392C3190477
                                                                                                            SHA-512:D0349F16BFAD2BB35738ABDB336C9B852A1316EFFF11095BF219753A61AEB926F620A928321FFB97B2E24CA7DBEFCF6592A516636C2DF2638572C2B364CE3D42
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....b..........." .........0............................................... ......B.....`...@......@............... .......................................%..|.... ...(......<.......p...............................................................H............text............................... ..`.data...`........ ..................@....reloc..<...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):288928
                                                                                                            Entropy (8bit):6.3565468587913
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:A4CftCb7K5nZsY8H6y1KmUc13znPwEDDOz4hJ0/8oFyS63ZUybmglHY2/YO/hUSo:qftCX6lu6gqyBDDOzHUddlttpUR
                                                                                                            MD5:C5B20B04C09A5A9E56E695016D5D52C9
                                                                                                            SHA1:507E9ACDC223A8DF9EC446158121F59BE73CE1C3
                                                                                                            SHA-256:1033977B422496B3B5F008979BE89CF9A06743581A36B6408CB4DED628D714A4
                                                                                                            SHA-512:BC608F0128ED30E40BD16F13E1C749EE86ECDCBC615184E59096697B04E3C69D879999DC9A14B4E047DD20DBD2CF81297E748F8F32AE92AD121A033813C269B9
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....g..........." .........`...............................................@............`...@......@............... .......................................`.......@...(...0..`...0$..p...............................................................H............text............................... ..`.data...6M.......P..................@....reloc..`....0.......0..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16672
                                                                                                            Entropy (8bit):6.749834751700326
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:cARUY7xW2WGPWv7srWxNzx95jmHnhWgN7agWYLrp0KBQfX01k9z3AlC+1ZIVpdt:cYdVfWGPWv7jX6HRN7XRxB+R9z0DZIL
                                                                                                            MD5:AD19CF1AEE37E575B7417387272ACFDB
                                                                                                            SHA1:A268235CD212375CDB20176B499AA154EF3FB145
                                                                                                            SHA-256:E7DB86F2176EC876DE7AF4BECD8B7C4EEA60E133F4866FC014403F318928CD24
                                                                                                            SHA-512:F9D853ECC9ABF4D505794C1E41AE9C0D25078ADE7B861F86E69E4D6D0C586CE0B7AD5168F172DE2C9C901BF3EB76B98EBCC7C92D5920814D19396BDEAD8BE51B
                                                                                                            Malicious:false
                                                                                                            Antivirus:
                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...:.y..........."!..0..............,... ........@.. ....................................`.................................c,..X....@.................. )...`......\+..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................,......H........"..t...........P ......h"...........................................<linker>.. <assembly fullname="System.IO.Pipes.AccessControl" feature="System.Resources.UseSystemResourceKeys" featurevalue="true">.. System.Resources.UseSystemResourceKeys removes resource strings and instead uses the resource key as the exception message -->.. <resource name="FxResources.System.IO.Pipes.AccessControl.SR.resources" action="remove" />.. <type fullname="System.SR">..
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):166048
                                                                                                            Entropy (8bit):6.346422693533479
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:oqlaVz+We9hgsXZyPTA8pLtx1k82pq1L8p9X8f/F:tAVzeosXZf8pL0p9X8fd
                                                                                                            MD5:E6115534751BE304966019E057F40DE2
                                                                                                            SHA1:671416A123E8ED8243A0F352520CDB25D999AB17
                                                                                                            SHA-256:7C2A4EAD45C9BACD5AE24BDF7C1D2481F1A06F75088E7F884974AA0257E798FA
                                                                                                            SHA-512:B8834D7F4CA23F4954C0D2FF351215FD522F53055A9751EE4CEA5F965B169A29EADCA7E9376A0F24B2AAB0A72D8C5286032AA42C4958A98B0FBADB776523A341
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...m+............" .........@...............................................`............`...@......@............... ..................................P...t@..X....`...(...P......@...p...........................................................P...H............text............................... ..`.data...6/... ...0... ..............@....reloc.......P.......P..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15632
                                                                                                            Entropy (8bit):6.8277201917102674
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:H9jw4pWw+WvLYA6VFHRN7htvR2IR9zXRq:H9jw4dPLFClhtvgU9zw
                                                                                                            MD5:DEB54D7C28DC4BAF320D8E762CD3906D
                                                                                                            SHA1:28D9096B448B0C8611302D7E27A6667050252682
                                                                                                            SHA-256:7800B0FD6AAC7979CAC550E1BAAE3AFAC15CFA8081FC186B27553BF7CBA7A0A3
                                                                                                            SHA-512:F748B155577DCEE8141C15E0684EF79FD6197891B5B1215074EFA7299539A38F7AD54EA97AFAB41F4DC42AC0F8904F36BE791494EFBF4E0EE0D1257185B2A538
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..............)... ...@....... ...............................u....`..................................)..O....@...................)...`.......(..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H.......P .......................(......................................BSJB............v4.0.30319......l.......#~..D.......#Strings............#US.........#GUID...(.......#Blob......................3................................................$...........=.n.........h.....#.>.....>...x.7.................>...].>.....>.....>.....>...D.>...Q.>.................h.....h.....h...).h...1.h...9.h...A.h...Q.h. .Y.h...a.h...i.h...q.h...y.h.....h.....h.......................#.....+.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.665072159776856
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:OzN83OxAhRo4HWabWvFpWjA6Kr4PFHnhWgN7akW2huxu3O6YX01k9z3AneMC:SN8302oCWabWvFYA6VFHRN7pyR9zKeN
                                                                                                            MD5:79563DE651295283F15CA4BCE8E98841
                                                                                                            SHA1:4D6ACA5801A92B02BBA687F7B6BC7E6EC59FDE13
                                                                                                            SHA-256:A58420178170177F772551C4AA7E4807B2672A8655F828600D47A3958CC40F7C
                                                                                                            SHA-512:77CD8D3D9A1AE5DE6A1A49C114FF4316C02E1F696430DE173D89632F96B958CB9B9010DE7B89930E15D177A5BE6E470D358B6330A968EA8ECADA44F7F43225CC
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....'............" ..0..............*... ...@....... ..............................YU....`.................................7*..O....@..$................(...`......d)..T............................................ ............... ..H............text........ ...................... ..`.rsrc...$....@......................@..@.reloc.......`......................@..B................k*......H.......P .......................(......................................BSJB............v4.0.30319......l.......#~...... ...#Strings............#US.........#GUID... ...t...#Blob......................3............................................................=...........h.....#...........S.....i.....8.............................Q...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):3676336
                                                                                                            Entropy (8bit):6.684594575848001
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:49152:h6S6FKfOBPKD5EUsp4Zq2daW7L2+K06Fs4sZ39SuMsFIW/pR:HOBiOmbp8uMsFIW/pR
                                                                                                            MD5:C3C16C39F19ED16A1AB42EF8DE7AE641
                                                                                                            SHA1:F072B19500679A70D1D6DD113B55921C6F963CBA
                                                                                                            SHA-256:10E4BC750F17578252293AAF7192E24E72A330D3EDC0146BE9245E9586CAC19D
                                                                                                            SHA-512:89307D4FDCF1DE91C6A0DD8C0807E56863856B803322C33AA845D90C0EEB6988F97ED70CA2754601FB61A739C0C364F2D8ADC7A28869F4921D6D5CF358FB0D2C
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....y............" .....P1...................................................7.......8...`...@......@............... ..........................................`.....7..(....7.,f...b..p...............................................................H............text...dK1......P1................. ..`.data........`1.. ...`1.............@....reloc..,f....7..p....7.............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):805152
                                                                                                            Entropy (8bit):6.7416805748123725
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:nbwydNnBKT9DzuU4/sKE5QmSfc+1yQgdY5wDG00eK0CszcyYl:nbzpKT9PuO5QmaryQgdYai0ZK03k
                                                                                                            MD5:19464109760AF17AE6CD8DBA5D222722
                                                                                                            SHA1:9DA4FA8D3C740182134C3D2B2977DCF0E0FAB669
                                                                                                            SHA-256:A4E353C60F26EAC3140F493C270320302BFB2E5FFCC1D4131682EA3E4C02D244
                                                                                                            SHA-512:47397137669BAB558BBFDB42B9AABC24A6301F8671253B0BC4632A975AD4AA0BAB87C9472AB4553A526132634CCD93A88BC09C4B8353E7FAB14DE0E2F498B7AD
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." ......................................................... ......i{....`...@......@............... ......................................p....d... .. )......T.......p...............................................................H............text............................... ..`.data....U.......`..................@....reloc..T........ ..................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):174352
                                                                                                            Entropy (8bit):6.296291995805638
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:i3adgejQmgA0o3eXZI6e07fww49JKotL3aZv0Tl:EadgQuA0/pI6eufww49F3aJ0J
                                                                                                            MD5:B58CC7032740F5EEC429E8414737B9EC
                                                                                                            SHA1:A18595EAD4A4F6ACE6F03B94248ED8E1BC1E599C
                                                                                                            SHA-256:59656C67991255D19B868DC1F48D1AD10BC8D8B6C667F792C2C9AFFBF69E47EF
                                                                                                            SHA-512:4382B3227139F6D15CBC4E2E25D4DB33B591FCC56E28E4B02D1FFD91F485CE908F0FCA236ED214B974483D856B92F348C48A06A7C1036CCB716DD20E7E69DCCD
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................" .........p............................................................`...@......@............... .......................................+...........)...p..........p...............................................................H............text............................... ..`.data....V.......`..................@....reloc.......p.......p..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):542880
                                                                                                            Entropy (8bit):6.739097833229294
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:fFcC4bb3czSgsrusOv38qA0s4WfufbFHJMb3xqHYYzLhMxjCUoTclQ:K7b38crusO/yEvuhsSWmQ
                                                                                                            MD5:DDF4958F47A5D0A7ED06832880DA1BFE
                                                                                                            SHA1:40FA6F2D97DE7504770B37153F4EEBF79A069535
                                                                                                            SHA-256:BDCF09BBA6A4DE7D73FEAA0DBA8802BE86738B3DE4E3E8D0EC79E2809F0F7E17
                                                                                                            SHA-512:1D54CA464CFD1ADB8B78C1226954F2C4FB66EC3CB51980BDE613A25A18A938BB536C7C6695CAF139EAE1F8A15AAB33B53B0BF9D1DC9BFDA948007BD6DE3EC0F2
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...uWB..........." .....@................................................... ......|4....`...@......@............... ..................................0........J... ...(......H.......p...........................................................0...H............text....1.......@.................. ..`.data........P.......P..............@....reloc..H...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):157960
                                                                                                            Entropy (8bit):6.47315446775413
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:Vm98N/j+0sbFbqX63vwZuIBo7M5F896ToYdBCBuqmwLhtTihdUmXD:88Cb6oIBo7q2GBCBuwhzmT
                                                                                                            MD5:11C346045E8C17C82C66B33E1E200DD8
                                                                                                            SHA1:64E08782D5CA2ACB2AC2C88B2D8F0323F43E3295
                                                                                                            SHA-256:344C7A232249C2ACE65D2CC03D62C356FE3F56AD46A0CC4603A36EC7D0F5587F
                                                                                                            SHA-512:294F1F8DEF433238DE0E98754BD44BF0614490D8A1086759924F548B91E219E223380601F16B987B27C9D0D67FE80393827A30580CFA096C49F5B2834E73FB88
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....Q............" .........@...............................................@............`...@......@............... ..................................@....6.......@...)...0..........p...........................................................@...H............text............................... ..`.data....".......0..................@....reloc.......0.......0..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):129184
                                                                                                            Entropy (8bit):6.196981583264401
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:4YBSzjfI+HAOaaRH8/OhcRRY4beMDSZkXs3pMGudO:ifIcJxRHMOhO+Zkcyz0
                                                                                                            MD5:AD794A89E1FB0BFD63D31E0BA44A9690
                                                                                                            SHA1:38636C92963BADC5F01B4A3AFCCEA17BE099C4DD
                                                                                                            SHA-256:7CE9E667B76C9F647E7124755BF25F56115C5CEB3A68DBDFB0254CE16AECF19E
                                                                                                            SHA-512:5D48755E0C03D7554E5924DAFF35C1505987664E5C5BAC4F4CFB3B2DF7AC74AE214DC6B1D7D778FF04579360EAC86111A56467A0B4C86552669B109145972679
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....i............" .....p...P......................................................<.....`...@......@............... .......................................4..<........(......l...0...p...............................................................H............text...Qe.......p.................. ..`.data....8.......@..................@....reloc..l...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1730848
                                                                                                            Entropy (8bit):6.692369218509377
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:24576:mycmIjdj8GrJnZLDflJjD2TRSKIP616WF1IMx:amIjdjFrJnZLDfz/aSs
                                                                                                            MD5:564C9A5BBE41D6CAACB1FA1993CC8AAC
                                                                                                            SHA1:34079090BC4D48F0351673BE7B255C52FA5B6369
                                                                                                            SHA-256:B760CCED33549528F6E101C491A0CAC4064F644EF3E829AE127FD3F09A33FBFF
                                                                                                            SHA-512:1A5D4F000EAB595E7DCA508C94EEAD23AD83C9856C57B9CB18DAF43D5B795FFE4C093A063B99142D2961AAAD33987BCC7DBEA5EC901DFFFF10C57A90D7A685B6
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...@............." ......... ...............................................@............`...@......@............... ..................................P....J......@.. )... ......Xo..p...........................................................P...H............text...}........................... ..`.data........ ....... ..............@....reloc....... ... ... ..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):551184
                                                                                                            Entropy (8bit):6.571055787933049
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:KmIFBDqpp+4F/B7VRZ3KYNB0hZJ6c7fkDNRd2B/eBl3EWZg0gG/qikXOG4drks:veip+4F/BJNuZJZx++WZgoQOzrks
                                                                                                            MD5:57905BE512F822BCF59258FBF2448DF8
                                                                                                            SHA1:27828B211218F240CE1ED73997BFC7B0A04527D8
                                                                                                            SHA-256:CDAD57CC4B992A6BBE2BB79BACD6DD28D248694BF089731BB474BEC682CA77C6
                                                                                                            SHA-512:9B2044A712E59FE7F6BDAD8420FD21451E5679D7AECD7B4479341C7AA27ADA290967CB32F898A899BF6E344A88F1FB7285EB214A98792C760BD374EBCBDE02B5
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...%............" .........................................................@.......O....`...@......@............... ......................................T...0*...@...)...0.......,..p...............................................................H............text....s.......................... ..`.data..............................@....reloc.......0.......0..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):432416
                                                                                                            Entropy (8bit):6.566108898209545
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:K+cqnJGnQkW6a+Sdjoe9k7u0GeFowoR5axLmqRSxnJ8kks1GL0q3+lL4A:l6aFP9f0NokSxOL0AEX
                                                                                                            MD5:29A059AB9999BD953C0AEC0B2C78E9A1
                                                                                                            SHA1:C41DB5BB3EF1CB499898698E3A87B83925F9BC36
                                                                                                            SHA-256:E1743ACD71086BB1AA689AACCC9485AEC04B2A7C2C15586ECDD5685AD881B7A5
                                                                                                            SHA-512:5431C58174273A5795D40DF4AA988D6049E0402F04379E84B80A9E02AE819A73BD5FBFF17109EFF0C341171A56BC28807D8B3B55DA03E7304552993DB89EA220
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....|..........." .........................................................p............`...@......@............... ..................................P........)...p.. )...`.......*..p...........................................................P...H............text............................... ..`.data...mr..........................@....reloc.......`.......`..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):112800
                                                                                                            Entropy (8bit):6.132923222586611
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:NUgJ8nlSAIFIpp8oXAcRKdRObZDFduWF8XwYJiAzk:Nx8nMAc2p8qRgAVDVF8Acjg
                                                                                                            MD5:397EB70F9DE2A7676B5DA94FF7CF11BF
                                                                                                            SHA1:88424878A779059002622F22315C1E0050FF4251
                                                                                                            SHA-256:E2A5AB5B077CBE3B7CDB0622EAE9363E8D9C591DDAB2CE87FCE6777A510767A6
                                                                                                            SHA-512:0E4836D6AB91BDACBB49EF71290256A7DCF4CBCA23B9C329C2E05CF00966BF0FABE9748092A579843BC211D4612D94CF8BB655207A3D40C46D11DCC663BFE544
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....64..........." .....@...@...........................................................`...@......@............... ......................................`1...........(..............p...............................................................H............text....7.......@.................. ..`.data...B$...P...0...P..............@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):157856
                                                                                                            Entropy (8bit):6.292306263911845
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:O1TeXCmzdST4L7rGE5RtqbqeQGwpncU/SLVXyVMnA9kmeBgo:WGCwdu4SsRQbIfqZm0H
                                                                                                            MD5:3874C63BA167BA4D4B815BAD86016CF4
                                                                                                            SHA1:72AB7DE57994DBAD6133FA9DDA1F2943E9F3122E
                                                                                                            SHA-256:9F9CF0B569F370DF63BE323844009718090B6D4FD4E21EC8D4DD6B6CC2FFE8CF
                                                                                                            SHA-512:17DC16864394CB6F0D52724606EBA24735A86DD62719264635265CED7DB0C36333FF0A3328222B6638DA16DD23FA6159E5F9B5EBA4499F62BABB1524587EEF2B
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....v..........." .........@...............................................@.......-....`...@......@............... .......................................9..8....@...(...0......(...p...............................................................H............text............................... ..`.data...T&.......0..................@....reloc.......0.......0..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):96432
                                                                                                            Entropy (8bit):6.098459980747934
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:Y6cypC971fwwSZy9hswibRSsYwlFb7R/gJR7SSNNJkZphyNVdWvmVzS:YUC971fZgy9hswZsYcN76JR7SAfuphyI
                                                                                                            MD5:E039ACA6E9900CEADCFBDBCF094D3A14
                                                                                                            SHA1:E38CEE576F881D512D4217629AB09B795FB520E9
                                                                                                            SHA-256:FAFDAAF0437E2C10B8343E5B1B2C744977B88CAB7585FD27DCC12071B27F46F5
                                                                                                            SHA-512:02D4550D30E3B9FBBE73243BCE8161E9117BBE67610117F11158A2B02DED148BE3A88C99CD6F60BD4DACB704F87E137E488F07CCA48BAD622CEB8F74D418F011
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...Uz............" .........0...............................................P......6.....`...@......@............... ..................................P....,.......P...(...@..(.......p...........................................................P...H............text............................... ..`.data...,.... ... ... ..............@....reloc..(....@.......@..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):231696
                                                                                                            Entropy (8bit):6.473831853357629
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:LaO7AQhsFgOZrgy5HSchuzeQ4X1VjK6uJQ+Y6MFot9R9loV2O1w6D/:77AQhsFgOZrBccgeQxRJNtngV2YTL
                                                                                                            MD5:5C34FE0079268AE7F3F22811FE9495FB
                                                                                                            SHA1:DE25943AE52E36BC6DD686790A7F56D5AA5C7591
                                                                                                            SHA-256:D609294406B894BC0F60D10FB62AD7A819E3BCBA3691A1825E4250364E23A7F1
                                                                                                            SHA-512:46A330540F64EAA5A7BC8D097DADFAFB5D054282F44FC2FB57F59494E5A1E6136C98DD8B6D08DFAABCB29B8121112405A86946C27F854151B443E18968F531AD
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....r(..........." .........P...............................................`............`...@......@............... ......................................xU.......`...)...P......x ..p...............................................................H............text............................... ..`.data....7.......@..................@....reloc.......P.......P..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):280840
                                                                                                            Entropy (8bit):6.504374684121034
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:6T5mQ9WRSfuurvHljMR4WGTSttIqq+xM8cSA7ljZZ2uy:W5/9WRSfuMHljCxMkA7lNZ2uy
                                                                                                            MD5:D351D8F0647E32577C3F03481B85A225
                                                                                                            SHA1:611C0862E644752153C74E81E6603EC0711F7BF8
                                                                                                            SHA-256:32409E5B1F753B13850D2C88CCBA73CB9CC4678D41F11A6B30C020AF3B787054
                                                                                                            SHA-512:A4AA5C66899B9E7FAF6B30E84826AF4F2CAC4C8A0EEED0B4292B30642FAC53AD20C42E401D9448195B78AC88A2D2F8F0D5AF28A9484E6B0D85570C15C7EA296F
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...2uJ..........." .........p............................................... ............`...@......@............... ..................................P....b....... ...)..........p!..p...........................................................P...H............text............................... ..`.data....U.......`..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):346272
                                                                                                            Entropy (8bit):6.521387641131273
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:+f/JWsKEin0hypPmFjQMt5e15XxGGIDvdDp3k+fc3CU1S2Du:6JW7EincF9QEe0THQCU1HDu
                                                                                                            MD5:44E2EFFD739146A1EDE87973AE254B2A
                                                                                                            SHA1:E342395ED09EF148F5848EDD1D79C3DC201A9738
                                                                                                            SHA-256:3FA27A91DAA93BD98F0EC6943DCB08531D799327B3E08E87EBC1BC9FCADF1CB8
                                                                                                            SHA-512:13507AD994D29D7DB8DBCF460819DBC2D7343FF9001426167361688DEFD3191051D233D71FCDAC51E0C16AE44CFAC5BB5A2F2A42D8389C32A51A533647977911
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...9..........." ......................................................... ......ik....`...@......@............... ..................................p...h....#... ...(......H...H)..p...........................................................p...H............text...Z........................... ..`.data...=n.......p..................@....reloc..H...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):669856
                                                                                                            Entropy (8bit):6.738177589721567
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:WauvNG3LGljZ0W5Yk0ZdmNtAj0mhIPLboapg1i6k90QdsAYcNCYq:WagNGbG2vBx093n6MVS7cZq
                                                                                                            MD5:621801207C70925E83F806DBD9954A4F
                                                                                                            SHA1:AC257BE3308F039A09E0439C4111F7FAFAED12DC
                                                                                                            SHA-256:4B1C1C6254C0F73E5CC110F3BB3E342D11EFF16ECA5F0F678E5158E896DC67BC
                                                                                                            SHA-512:82C842AB166058DAAA31CCED435D29BC996ECE3E7295C0F934541AB1B1969F2A9221612573BB3CD85412A98AE1780A9A2C5E38F3E34E2385300F5EA56D622F74
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....1..........." ..... ................................................................`...@......@............... ..................................p...`....7.......(..........0+..p...........................................................p...H............text............ .................. ..`.data...h....0.......0..............@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):47368
                                                                                                            Entropy (8bit):5.313584058986443
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:768:DEOyP3H1ppKzS/Y7Fzq7roiIJPMuFCl20VXC4dC9zVjTQ:D9yP3H1ppKO6FzqYi2i5C4dezFTQ
                                                                                                            MD5:D38BBF660F3694B32D26AEB7A4113BCB
                                                                                                            SHA1:D1FB7DA85BBF49A937D233BEF2E329CDB9B68241
                                                                                                            SHA-256:C85BA2F97897AC62919E6367E4FC05D166B3A4D13E5757E21998883312C52294
                                                                                                            SHA-512:0C7B9ACF7D318E705BD2F9785AF3892BF4BACA9247EBBEA96A294DA32C62B9D912BFD2D4E1FB5B2693DBAD8F3084AAA3382C690BBBA82AB7456BD00512CAFC52
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....H............" .....`... ......................................................._....`...@......@............... ...................................................)..........P...p...............................................................H............text...8U.......`.................. ..`.data........p.......p..............@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):547088
                                                                                                            Entropy (8bit):6.626088648642838
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:BZmV75OO7txaGNUL2Sdr5Nzv0SAu9FWc1sPHE/0NY05:BZm95FtxaGDSzxAu9IpEsN5
                                                                                                            MD5:FFC0A29CFB99461BBD61BAB8A455BED6
                                                                                                            SHA1:75577F5B1ADC70877BC39830968B605CC175A8C4
                                                                                                            SHA-256:91CD06310E6DA6966A37C073F4FA4FEBB896BD09EE8658F308EB1709B335EB07
                                                                                                            SHA-512:3BF93B46BE1626636BFE133E2899218649C17F05AC1294B7940A2BBEDF01161E597D0DDE047A1672B6712444F8C5807BA8157B6A2EF50E4A25F3C46501100E3A
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .........................................................0............`...@......@............... ..................................p.......|8...0...)... .......4..p...........................................................p...H............text...8........................... ..`.data...az..........................@....reloc....... ....... ..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):170144
                                                                                                            Entropy (8bit):6.427166919417408
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:Hza6IfDI6Q8nqNIJ55jypCTpAY3ykJ9rialFpR/fTu:T9t6vn8IJySpxFHfi
                                                                                                            MD5:53AB5080DEEE5C08F664C6329DB1CF45
                                                                                                            SHA1:F800510D0212425220BC0DFBAADC9FBD979DDFB6
                                                                                                            SHA-256:EBB450E89DE674B20C93E0108123FF1C1D2F217CF9CDF2E51609A84E76708687
                                                                                                            SHA-512:DC321BB7693ECF188C148DF5ABE942F2DD6D2FCA6F681876BC9C066A1356C7E3562846E5E1D91B759AFAC9F1872D9516FCE81270E1AEEA4FFD608899A4EF9772
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .........P...............................................p......?.....`...@......@............... ......................................\K.......p...(...`......8...p...............................................................H............text............................... ..`.data....8... ...@... ..............@....reloc.......`.......`..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):67872
                                                                                                            Entropy (8bit):5.7806499699132505
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:tWTDQdpxYexI0Yx82s88krahmqOwA83qJKAFE6WHKV6q6G22N7XK6RH4wqYXYsY/:tWTD2px7DYx82s88krahmqOwA83qJKAk
                                                                                                            MD5:48EFC108D7EF7817BCD9BAFAE557436F
                                                                                                            SHA1:5A017C66B16266A7C34CEBB7DFF531AB5068DF34
                                                                                                            SHA-256:9C4D605934307CFC9ED37ACB1210368C8ACC5C88B816931E7D022F8AE917CDCA
                                                                                                            SHA-512:E7FB663FF470121B72A2B6621A362DAE7C8899536FAFEDF70BE69016630604C7C7027BBE9509ECBCEE558631B07535E03F3FA5815518BBFEE6B1417A0B2324E1
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...1.+..........." ......... .......................................................b....`...@......@............... .......................................!.......... )..............p...............................................................H............text...:........................... ..`.data...............................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):43184
                                                                                                            Entropy (8bit):5.444316993596802
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:C23WkwWvOJtQnkEun+JBTeZDeRbOkKsfJbCLv+CToLfyOQEi066gaiGgX6HRN7jp:C23ROJ+pKEJSO7o6ji3W99zdD
                                                                                                            MD5:090FCCE165FED5E5ED5332C11CC31B3B
                                                                                                            SHA1:77D98026A8A7F6307655B54E34B4CD15C903DC23
                                                                                                            SHA-256:D2EAC1736D03EF60DA6775105B7AC6D8E0C9855CA2437CF108B1DCBEBF05CBF0
                                                                                                            SHA-512:E09CC8EFE62E0EBA06596BBCBFEAC0839EA9B31A355F4F24DAB0A85238EE62241029DA79D51805DB29D1232EA769C236DE961D5DA5B17E045098523E3DDAEABD
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....f............" .....P... ............................................................`...@......@............... ..................................p................(...p..........p...........................................................p...H............text... L.......P.................. ..`.data...=....`.......`..............@....reloc.......p.......p..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):100632
                                                                                                            Entropy (8bit):6.038277233896664
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:Xl4Xlu9IUefYv9AfOWog+qBWO7bBjLLEORWNzrT:Xl4XlDl89Bg+uV7bBjLLEOR2fT
                                                                                                            MD5:4F6F32BEE2BC12E8C6087488D856AF5D
                                                                                                            SHA1:AFE5F7581CB31B6934F31C9410AF4D08EE5934A2
                                                                                                            SHA-256:8971C704C33BAFE87445FD4B8E5417E2824F8F878052B11BED2AD02F7DE31DA0
                                                                                                            SHA-512:EC0416BF1B814CA94A6FAAD2B97A605BA01BBE4D62697088C665908A6EFCABFA9834E4A7C45FD4BD5DA34E59616E49607D11C9F8335946B30DB01E76AB2EA0D3
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................" .........@...............................................`......D.....`...@......@............... .......................................,..<....`...)...P..x.......p...............................................................H............text...[........................... ..`.data...s!... ...0... ..............@....reloc..x....P.......P..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):190752
                                                                                                            Entropy (8bit):6.3691331105031095
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:tOEp0tsypJKO0BYnjbpL8DqJVyR3IUQeu0IeW+1omEAa9NYLbkbmvh0dksI8mt/R:fpKsnRnYQzIeW+1odmvhSR7mtxrX
                                                                                                            MD5:3C9FDD9789791E468453B420FA39CEC5
                                                                                                            SHA1:92386B6677D421CD2EFEC73F67D66975A41017E7
                                                                                                            SHA-256:7CD51A14E2E1D4231FA85440AFB3047B65AB4F397BFF37C91F50ED20DEF9A800
                                                                                                            SHA-512:B74F822E016E468C15B70274797944F8444A38BE9E68F6B83BA42B30A02FCA892E3EEC0E4E177AD267DBE90DF0D8FEB1B999EB2A866489E0B2B659E6282BF1F0
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...[.v..........." .....`...P.......................................................a....`...@......@............... .......................................L.......... )......d.......p...............................................................H............text....Q.......`.................. ..`.data...O7...p...@...p..............@....reloc..d...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):17568
                                                                                                            Entropy (8bit):6.601523102100865
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:4hubcrkpKZyS3YxAstDhWVVaWvipWjA6Kr4PFHnhWgN7akW98xu3O6YX01k9z3Aj:S3132LFhWVVaWviYA6VFHRN7FR9zKj
                                                                                                            MD5:A0260D173E91A0BA02B39CB673986BFA
                                                                                                            SHA1:AFCD7A4EF3B64B6112F67C568DE61E2599D5E3F9
                                                                                                            SHA-256:2E28BCA4C04A512CE8B481B7FA8FA93A342406A5E554B9D9075F9BA20060701E
                                                                                                            SHA-512:62BC5F23C77674916D2B552B397E7C3891B276D5304FC9AB6C48A70F60190EAEBB1A06B10023A820EB9E58069A9C81B1E7D7B73951F69839B0A8BF5E6A5DAC06
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....x..........." ..0..............1... ...@....... ....................................`..................................0..O....@..4................(...`......./..T............................................ ............... ..H............text... .... ...................... ..`.rsrc...4....@......................@..@.reloc.......`......................@..B.................0......H.......P .. ...................p/......................................BSJB............v4.0.30319......l.......#~..|.......#Strings............#US.........#GUID.......|...#Blob......................3................................6.....x.........................../.......L.................................p...........................................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.C...+.Y...3.o...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.698265155355934
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:OL9+i8wxVLWIBWvrVpWjA6Kr4PFHnhWgN7awWyHSZCjVi6KrIX01k9z3AszWmCL:29iuxWIBWvhYA6VFHRN7xyZ49R9zrim+
                                                                                                            MD5:C79FBAB0FBE63D539F5808D867319DED
                                                                                                            SHA1:6AB319EA399E61322A41F059743E3C8C66C4D184
                                                                                                            SHA-256:759C6E9C3EEE3344F73EE6FA8016F27816C2615BB079D1DE9CD97EDA35ADAF24
                                                                                                            SHA-512:83DC117256500B347751D30AB390B3C4F4C371D8053986B44CEE732FA5E540EF60A8CB78BEE73D1A93984B4EDF65782E86424735F58094C259793A7EF91697F7
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...cL............"!..0.............n*... ........@.. ....................................`..................................*..P....@...................(...`......()..T............................................ ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................P*......H........ ..X...................P .......................................N;#?D.a...]..v...!.1CnF..).d..n...!..d.j.Y...J..|.8}....G=L....V....[..W.M..A...*V......2aR.E3".....bou.tc.:...{..Y..*.BSJB............v4.0.30319......`...8...#~..........#Strings............#GUID...........#Blob......................3......................................D.........]...........v.................\.r.....r.....`...8.....0.......r.....r.....r.....r.....r...}.r.....r...........6.....
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15520
                                                                                                            Entropy (8bit):6.724762605096555
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:bF7xXs50WANWvqGMpWjA6Kr4PFHnhWgN7awWmCjVi6KrIX01k9z3AszWTA1MCu:J1XWANWvRMYA6VFHRN7549R9zriU1MCu
                                                                                                            MD5:4CE41C17B5695E5A862531C9CF10049C
                                                                                                            SHA1:2647BCC625BA83DC830827B97063A7CAD92F48AC
                                                                                                            SHA-256:7EF9E8E2D7E8BCF66C0A1A22D6709D4732B4CCDC61F395A364DA9591FBFDA5A4
                                                                                                            SHA-512:9C3725C5C94620C08A5489BA186DCD42BD4262398FB64356ACF93E087E1865EBB72536A4730F97F540DE36F114ABA1E70E1F2490F894DD33B1625F18B5817C7B
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....p..........." ..0.............Z)... ...@....... ..............................{!....`..................................)..O....@..T................(...`......((..T............................................ ............... ..H............text...`.... ...................... ..`.rsrc...T....@......................@..@.reloc.......`......................@..B................;)......H.......P ..X....................'......................................BSJB............v4.0.30319......l...8...#~..........#Strings....\.......#US.`.......#GUID...p.......#Blob......................3................................................'.f.....f...e.S...............K...........{...........`.......................G.....y.......-...........%.....%.....%...).%...1.%...9.%...A.%...I.%...Q.%...Y.%...a.%...i.%...q.%...y.%.......:.....C.....b...#.k...+.....+.....3.....;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):80144
                                                                                                            Entropy (8bit):5.803230831022685
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:Gdq4De0RKXrgcCGfNiQSstWrHG73Vii33zTT:GY0MrqQN4rHG7FiQ3r
                                                                                                            MD5:95C0763C84097068062150DE68644010
                                                                                                            SHA1:87480BBCFD5D3D5CCB062470DA0E3EE6043216AD
                                                                                                            SHA-256:EC4EA965B4BDC6886EF9EBB234BD568543ED9846CD6FA32E4EB33B5529841A38
                                                                                                            SHA-512:56CE8D3E416158D356B54174A6D5968EE3556A593E2AABF884126163EE14C9264F5E624B0528058BD586C4433FE6D54D7CC6F781BEA429FEBE98DEE809030FA2
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...+.$..........." .........0......................................................'a....`...@......@............... ..................................p...\%...........)......T.......p...........................................................p...H............text...o........................... ..`.data............ ..................@....reloc..T...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):964768
                                                                                                            Entropy (8bit):6.564122188888795
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:L63NP3HfSVnK8rt8/gOdudIC0kPWWkTnpH3emGfbtTbW:evQK8regqxWk1XwfbdW
                                                                                                            MD5:8EF1D146E723F4F6DA9B6DC4A679D3F2
                                                                                                            SHA1:5BB1E673C4922E9A88AE7EDF5B1C1BD88A78EC02
                                                                                                            SHA-256:AAD5595E9D7DE9D99A700313AF2DE75AA8BD271246066F9700FDD39A69AA6555
                                                                                                            SHA-512:2BB0BB482C2DDD8494846FF4FDED55A627BF921C2E2165A11CD056517143426AF126324C93AF45C99B483FADDBE80262EDA2EFBD1F48E4B06C6CE6CD52245E2D
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...$..f.........." ......................................................................`...@......@............... ..........................................(w.......(...p..@....C..p...............................................................H............text...P........................... ..`.data...P...........................@....reloc..@....p... ...p..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):13170968
                                                                                                            Entropy (8bit):6.844875656043683
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:98304:3fWVGoCY0Os5SYWxv4Ac7JnQj6OUN9v4AS0C9C4fKp7kHeAi:6mY015SYWxvdcNQ2OUN9vDCEp7kej
                                                                                                            MD5:A2EA4D0A864DC1F7C7A4EA4D3930011A
                                                                                                            SHA1:0C0EE0F265387C64D8B9F0BB29E7D9320F394C65
                                                                                                            SHA-256:60AB682B551CC4E94E2DE432149E032FD63AC0B6D15397DECC4D8BE87C6BE1AB
                                                                                                            SHA-512:90EF986AE72D4713AAEA1E86F185EC709F4726095BED25598073B0AF988D8F941B0CB345F05BC1832936B9D0F2B9DB477D97A9AFD83CBC6552281FD9E5553997
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....BW..........." ...............................................................4.....`...@......@............... .......................................p..d........)... ..8...(...p...............................................................H............text............................. ..`.data............ ..................@....reloc..8.... ....... ..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):2082976
                                                                                                            Entropy (8bit):6.703393423935663
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:49152:lEOFavlNDjaq8s+3kOCP8tOEFxOouLsY2DLzv6EI6P7:lE8a2kdUy6P7
                                                                                                            MD5:219492E04A852A3AD7A112EDC2559480
                                                                                                            SHA1:6AE74ADDD7165FDBDB7E038AC9BD2C2B9522ACF2
                                                                                                            SHA-256:29C546097FF7E5AC94202E71311EF2BCBAE2D7DDEA6BF8E951F1FB3BC942DE75
                                                                                                            SHA-512:994A2C824539DA7C966A57CBB4B58B4A89F283BF4293C27AE33B9A6B0EE267F8DCDB644B96ED80080D449615A6EA672552EB16250EBCC8AE1220A3DB5F3F2F0C
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....Zi..........." ................................................................k.....`...@......@............... .................................. ....[...........(...p...'.. v..p........................................................... ...H............text...+........................... ..`.data...X...........................@....reloc...'...p...0...p..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):260376
                                                                                                            Entropy (8bit):6.615511865069277
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:wfAevHZGInBPKCeDc6CK9MG3bMeVmtG0FsGu6Myw0M:XyIDc6MG3wamtG0fuVMM
                                                                                                            MD5:22647404E842F5177DEC97B960B98501
                                                                                                            SHA1:5E5DECC395401901278F2B4727ED6539CE28A51C
                                                                                                            SHA-256:F289BC9873AE0BD99DB74E00F480C931CA94F3785251132C04699AB01893604B
                                                                                                            SHA-512:3EF4F8141B680EF0922C24284E7B5D5F7B006C0E718E69D6E2F0446B58B271099FE599398C1814C8698B8460A5A6062BAFAA12D2F7FFED5123A86DCA46BDB340
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....S..........." .........@............................................................`...@......@............... ..................................p...PS..x........)......8.......p...........................................................p...H............text....{.......................... ..`.data....$.......0..................@....reloc..8...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):403616
                                                                                                            Entropy (8bit):6.600068240160654
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:QxxBCAdWeda9F5g7yB4cPIm1OwpXQgQbTCtYnzrZjzEOdlIZJ4aU:QDBZHU9F5Rv7/QnCSnz1fQZyaU
                                                                                                            MD5:CE7139BB6444A47C86FAF3780F4D561B
                                                                                                            SHA1:32538812CF09B179760E17148E95AD84581AD8AC
                                                                                                            SHA-256:A113BB3BD9E8C13B1EAF126C3EC614A08C3193A51F52C277B3BD5F4DC00D08FB
                                                                                                            SHA-512:F2F1CEA8ED59D7DF0BE03279FDAF2A1764D2E8C00C975BFB60C81BB838FCA0B210AE7BE2A6D1B2ABDAA2A8AB9799D2D5BD568F9A6F59DB95E37C736A9B55D092
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................" .....p................................................................`...@......@............... ...........................................-.......(...........)..p...............................................................H............text...fb.......p.................. ..`.data...Sd.......p..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):7989512
                                                                                                            Entropy (8bit):6.799190907572347
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:49152:xgKjbhmQzKo84xxpBR2ZPQ3DtqDTXNaVC8v4aYzqNmKG82o4AgcKVLDSvdEAzsfr:xlRDDnVul2QSvdEhYw2gfW5WUFH5chT
                                                                                                            MD5:1B47420D8AD2071CDED2C944E3F6C984
                                                                                                            SHA1:157CD6B1DC208BAFCCA11282FB3B6259D9D5DCED
                                                                                                            SHA-256:CFB4DBA4AC73773F5EAC02006F0FE7E6399CD67F5A12B4CE26C9F0F406A7EDED
                                                                                                            SHA-512:4ECE5BE567CAC3751FFFBA31FE00F73458E205F658A3C55AC42271D00E43CEDA2ACE6C0D59272B527B36A83EC1C340A1FB7EBD9B041FCF841BADB0B6B92FC80A
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...X............." ......s...................................................y.....Z.z...`...@......@............... ..................................p............y..)...Py..h.....p...........................................................p...H............text.....s.......s................. ..`.data....Z....s..`....s.............@....reloc...h...Py..p...Py.............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):75936
                                                                                                            Entropy (8bit):5.93517438959376
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:4PYWVA8CWZpWNv6zIMuSxRlHJ5ZYoqtTJogirzK:4gX8CWZpWNv6txRl+Nt7E2
                                                                                                            MD5:F714AC64710C190EEB50638803184D4C
                                                                                                            SHA1:49548E940524ADD22AD2F6CBFADDCB1D819F81E6
                                                                                                            SHA-256:7D1417C97CF840F4AEBBD50A7179026BF78A099F6FA4304FFD8262342B965A3C
                                                                                                            SHA-512:E142D3A048B2115DA4FA1F4D119643BA8E84A4ABFC867D28E67879EFF3195F44DE08138A3C764A26A1BE80C88C4D471E6D8AA10B48F30EE5677B8E7257A4D31F
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .........0.......................................................)....`...@......@............... .......................................$..|........(......P.......p...............................................................H............text.............................. ..`.data............ ..................@....reloc..P...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16136
                                                                                                            Entropy (8bit):6.746130186809866
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:VWqx+7wWEUWvFpWjA6Kr4PFHnhWgN7acWHx6RMySX01k9z3AhV5JC4qRH:8wawWEUWvFYA6VFHRN7nMR9zGV5wbRH
                                                                                                            MD5:DF0207D04392D91A07047F9309B5DB3D
                                                                                                            SHA1:AC61281D2717E1DC8E78BAC27BC84DAAFF4DB1BF
                                                                                                            SHA-256:80C531B9CEE91C4B770264ADD3788E7C55E168DAB69A880616E25C288C1AFD1B
                                                                                                            SHA-512:BBD5A9BD24630787E99A806DF0CD178F604398043F0CF65D4CC7191C052B427EB2DD50D86F455D02D04373E7C73C319B079DBE47AA9F2F05726C6CD5F2B02BEC
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...U.o..........."!..0..............*... ........@.. ....................................`.................................;*..P....@...................)...`......0)..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................p*......H........ ..`...................P ...................................... k.}A...<........H.y.;...J.2O..\.. ./.)J....5H..G...b.G.S......>......N.....QKm7a....B.)dn..".)..u...;O..~....{../c.w..i..aBSJB............v4.0.30319......`.......#~..l...D...#Strings............#GUID...........#Blob......................3................................................"...........;...........f.....!.b.....b.....7.................b...[.b.....b.....b.....b...B.b...O.b...v.............
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.7044983638513145
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:DuEW1VJWvrLYA6VFHRN7MDX+iR9zw8td4:DutYnFClMDuO9z3d4
                                                                                                            MD5:CE6B3D7D2E3BF3E35BC49F0905A0947E
                                                                                                            SHA1:5F075D3E596CFF0670AEE7E1BB1C6C2FA6AB1089
                                                                                                            SHA-256:253E1C6A59ACB96DB9EA8E4BE48EA4E8040F885D602349B2B44753234709D49D
                                                                                                            SHA-512:D53C00B4C26540D36464501A64A0AB3E7FE175256F47F44BBA53D25ECAB6255C51570EA4A7FBD6E2FAC171967A9CB876E2C7FD5A961554EB5C49222620E31BD1
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................"!..0..............*... ........@.. ..............................+.....`..................................)..V....@...................(...`.......(..T............................................ ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................*......H........ ......................P ......................................Wsa.....ky`w...q.FB....O.Z.......\........j.....K.N...]M.~.'.@?O.=d.r].N\.~.BE...p.9..e4....D.&..S..7.j........H:...+nT_...`BSJB............v4.0.30319......`.......#~..4.......#Strings....<.......#GUID...L.......#Blob......................3................................................0...........I.k.........t...../.E.....E.....>.....~.....~.....E...i.E.....E.....E.....E...P.E...].E.................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):129184
                                                                                                            Entropy (8bit):6.114698747717757
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:6Z54JKiEAYbKatyLJSsVkrc00EBR7yxcuk:B/fSessuaRxhk
                                                                                                            MD5:2E6C7A183AD043850BFA731550D43F51
                                                                                                            SHA1:3F6818E1FD9564D38223367DBE03D257FA394D83
                                                                                                            SHA-256:88DFA993884C1277A3ADCBC55EF44B4A38C55EC4F0F8C7768862377BEAE76DBC
                                                                                                            SHA-512:C8D3013E7C9171ADE3C49782394CDCE172DEC85EAC96A84CFAE7C1936666EB4093D7A518CF955D30B3E1189C0C72319A6E58D85731F83020E59DDFEA5D44F743
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .........0............................................................`...@......@............... .......................................+..l........(..........(...p...............................................................H............text............................... ..`.data...Y........ ..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15648
                                                                                                            Entropy (8bit):6.804728776210739
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:Gv8XzaxAQy8W1WWvoiWxNzx95jmHnhWgN7agW8jNOghHssDX01k9z3AeKDJA:GEDAxW1WWvoxX6HRN7BjNOgFDR9zzKlA
                                                                                                            MD5:00346A61DDEAFB150D595887D6ACA36F
                                                                                                            SHA1:735B7CD1B62787861BAF51EC0D02C66C294962F0
                                                                                                            SHA-256:AFACE1464DF1D31BD96CC897F4D47C6B5A855707CBBFC954E624E68F3AC16372
                                                                                                            SHA-512:60395D751677C3728C3CD7763A36B1950E329D8407649C97CA7B049D8FCF8117943D1618B06087F376D6FAFE4EAE1ABE64BF0CE2D5FEC39C68FDED69687FC02A
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...k............" ..0.............z)... ...@....... ..............................9?....`.................................%)..O....@.................. )...`......,(..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................Y)......H.......P ..\....................'......................................BSJB............v4.0.30319......l.......#~..(.......#Strings............#US.........#GUID...........#Blob......................3......................................................x.....3.....4.....^.................I....._.................w.................G...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1116320
                                                                                                            Entropy (8bit):6.6439477896792
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:43e0ziO6AJ8+utVRA8WDlLeO9om5EoU/mSdWKURfeGWTbrWnoDzgVdkn:43e0BlJ8TRocOWmc/DamGWTbwIn
                                                                                                            MD5:496F077B5C7B487EBF3E6222A53783EB
                                                                                                            SHA1:EEADF861F1EC14A8FAC957ADC2191B252E609FCE
                                                                                                            SHA-256:F8DC3E1AFC09A8C21B5C4C7AFB17C520AFE0263CCE8366CF57471D1D203728ED
                                                                                                            SHA-512:DDD0BA22E2BC0F76DA573EA6CD4AEC89A0F3CC1D32223938C963850F2348D1C8086C508E06F4076F3820A1A2B35A47D0497C4CA5E211CAF5BAC18BBA4F53185B
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....3............" .................................................................Y....`...@......@............... ......................................@...........(...........W..p...............................................................H............text............................... ..`.data...A...........................@....reloc........... ..................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.754858406085234
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:FsiCLx+eWl+WvXpWjA6Kr4PFHnhWgN7agWfiC7L4xxu3O6YX01k9z3AnUGj:fWPWl+WvXYA6VFHRN7AnY1R9zK5
                                                                                                            MD5:5A0D5E375A4568CEA219B700365A3C5D
                                                                                                            SHA1:2EF3BDF476C9EDA2992A2FFC13FBE467D6630803
                                                                                                            SHA-256:B14DA399FCF67C895F70F3B609937E28E7CB1CB7FE46EEC51181F1CB5F8C6D6A
                                                                                                            SHA-512:2DDB829370CAAFD3298CFDEC06A067CF6EEAADB3A88CA7F7EBEE61ACB2747744B78DF4BDC43304427D135CD73CBF907D000DF6DEE42F18C05B8C9EF537DD2BC8
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...P............"!..0..............+... ........@.. ..............................<.....`.................................5+..V....@...................(...`......8*..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................p+......H........ ..h...................P ......................................F..b3...X[N....0..Rl.e,.3...L|..V......$...R.Gg.....B@..>0.[_..x8.i...L...W..Qq:..H..-M..p...@..a....j.....x....9.!g....KBSJB............v4.0.30319......`.......#~..........#Strings............#GUID...........#Blob......................3......................................3.........@...........Y.................?.g.....g.....`.................g...y.g.....g.....g.....g...`.g...m.g.................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):43168
                                                                                                            Entropy (8bit):5.182597235608364
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:iWJeWvhx1Yc6PuTNtyVC0a+SKODVt9jR3YA6VFHRN7dBWkBmo8R9zYU:NvbGc6WTUK+jOZVFClGCmoQ9zp
                                                                                                            MD5:1679D883CB813D80B1257AF4ADC0AD77
                                                                                                            SHA1:F8573165E89592339B18FE392C0FC004405BBD74
                                                                                                            SHA-256:9784CA5F49D11E8A112D39FF3EB1105502A20FD2331EA1523CD2F491A5E8208B
                                                                                                            SHA-512:8D80120B954C338AF0BC3C17EE113028921EBC66A4A2F061BAA32CD6F21D163F125600CF3209948D1890952F4E5EB2A480C888F18563DD2FD4C149AF80E34E48
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....C..........." .....P... .......................................................!....`...@......@............... ...................................................(...p..........p...............................................................H............text....G.......P.................. ..`.data........`.......`..............@....reloc.......p.......p..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16672
                                                                                                            Entropy (8bit):6.688841643360067
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:MuCkGQKyxAyCWCCWv3g0yWxNzx95jmHnhWgN7agWF7qT8RwX01k9z3AhStpK6/Ta:M2F4WCCWv3pBX6HRN7u2T9R9zUspFO
                                                                                                            MD5:63BAE6DF058D6F3D630713CA52343D29
                                                                                                            SHA1:96A8411BA0786BE08E54B62CA8EAE6998CE57644
                                                                                                            SHA-256:1B6B873F4C5F5985E7C3E6BA5693D1C676FE0773C9335003F97807712EDEDCE7
                                                                                                            SHA-512:EC8892A9A1451C76D6CCA4835BBF242EAE417EC4120C69EBD47D484763583C1AC5D0BF73D28871B31F133C061BD9EB88E4695BC2E6E59C509C809E5478652205
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...N.K..........." ..0..............,... ...@....... ..............................0.....`..................................,..O....@..d............... )...`.......+..T............................................ ............... ..H............text........ ...................... ..`.rsrc...d....@......................@..@.reloc.......`......................@..B.................,......H.......P ......................4+......................................BSJB............v4.0.30319......l...l...#~......|...#Strings....T.......#US.X.......#GUID...h...|...#Blob......................3................................"...............M.............................q.6.../.6...........6.....6.....6.....6.....6...m.6.....6.................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):137392
                                                                                                            Entropy (8bit):6.141873621571383
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:hJ4+cFoEaEKuh23IIBbL61G26uREGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGV:E+cF+Ezk3b0AJ0EGGGGGGGGGGGGGGGGA
                                                                                                            MD5:AACAA4C6CF82CC31170B35E85088BAEE
                                                                                                            SHA1:729F82BDA28D082F6E50DC92A8FD3CA535F51F8A
                                                                                                            SHA-256:7A758A27E1EE75D4434332984FA37875A723DA0E6BF31D9160C8986B0315C4D6
                                                                                                            SHA-512:CD92A09D0F89AA4A5C3C06D079FED08B4804562CA89FD2798630520D07DC1752295BD7ADBFD6DC23BA8C6BE6FF3409C2EEEF33EA98F0C861EEDFA7BBC4597A0C
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....<..........." .........0......................................................;o....`...@......@............... ..................................P...D5...........(..............p...........................................................P...H............text............................... ..`.data............ ..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15536
                                                                                                            Entropy (8bit):6.762522427444249
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:3hDixAXGWI3WvxNWxNzx95jmHnhWgN7awWJpccpBm+0U8X01k9z3AH50:eZWI3WvQX6HRN7CpcsBmo8R9zY2
                                                                                                            MD5:6467861CB0D9DEA2AEC7DE8BE11739B5
                                                                                                            SHA1:72EC68876D3115A13BAB42C9039613012AF2F82B
                                                                                                            SHA-256:EF8A510D31E84CDB66278C00B62CCC92658C128026422A227A6774A2E8A727CC
                                                                                                            SHA-512:FB2D0B89B8268BC3A29213B101FD6577612B2104FB1F16147F3C0551F28403E7BB91CE04328A0F65EB3164A3D186F1C3088BE051334FDA4346F745CBC18C95E9
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..............)... ...@....... ..............................p%....`..................................(..O....@...................(...`.......'..T............................................ ............... ..H............text... .... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................(......H.......P ......................X'......................................BSJB............v4.0.30319......l.......#~......h...#Strings....t.......#US.x.......#GUID...........#Blob......................3..................................................%...x.%...3.....V.....^.................I....._.................w.................G...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16136
                                                                                                            Entropy (8bit):6.714372309412333
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:GeawQgWZzWvPYA6VFHRN7sUCMR9zGV5wfK:Ge/QHyPFClsUF9zm
                                                                                                            MD5:A0BEA80A62152978E32251FA63A0ACB8
                                                                                                            SHA1:3F4F646C98CB8628314924B463BAAD197D039BBF
                                                                                                            SHA-256:9A3E5D6D51AE86A91D2EC90B2A2BE5DC2210F032C140C349F04256DE6ED441D5
                                                                                                            SHA-512:4E8B600E1D59CEEE3411AF54758556B9792519C396EC9DF997DD58AF66B5505A4A86BB8F165391AC75F1CF0F092038B059C1C1D074E291B8C320D14A9695960E
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................" ..0.............n*... ...@....... ...............................W....`..................................*..O....@...................)...`.......)..T............................................ ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................M*......H.......P ..H....................(......................................BSJB............v4.0.30319......l.......#~..|...,...#Strings............#US.........#GUID...........#Blob......................3................................................9...........U...................A.....A...........A...r.A.....A.....A.....A...Y.A...i.A.................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):51376
                                                                                                            Entropy (8bit):5.749601750476796
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:768:5UG932Xb+i171RsnV73v2/PL04IWWkmoQ9zItF:5PGr+871q7/2b0QWkmVzmF
                                                                                                            MD5:E87C3E51080C7BB65E611B485A599ABD
                                                                                                            SHA1:B9B02227ED6C0E3DA2D19FC6DE018E559D532E70
                                                                                                            SHA-256:8974918F0BA83548BAFA900918F93B35770A64D8DBC7A104188CD6FFC8D0F157
                                                                                                            SHA-512:3CF5541C5080A5774477A5077CB88006F7548F94E74D08D0FF33505B89C10B26E87162CCCB19CBE9C290371E3C83FD5AEE8A79637C251AD11EB6E6AACE1C57F2
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....>............" .....p... ............................................................`...@......@............... ...................................................(..............p...............................................................H............text....j.......p.................. ..`.data...............................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15632
                                                                                                            Entropy (8bit):6.801183385142263
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:GzxAe+rIH5WL2WvAApWjA6Kr4PFHnhWgN7agWyZLrp0KBQfX01k9z3AlC+V/C:AAgWL2WvtYA6VFHRN73ZRxB+R9z0W
                                                                                                            MD5:C1CBD3AEC800C18949C8E91853BBE2B3
                                                                                                            SHA1:1002548B57C17FACAAB39960B0E6764D063A9E8D
                                                                                                            SHA-256:BC700629D14BC36FE3FB97F28B9E0ECA8C59312F85E3844749E738B374CFEE7F
                                                                                                            SHA-512:54B6407EA7772F2834ABAF1791FAAF6B7D56141B097D7D03346054D89844287062EA9FA6045654A7954562F00994CCFE94942DF2E36CB90C5B6AD8377816D764
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0.............F)... ...@....... ....................................`..................................(..O....@...................)...`.......'..T............................................ ............... ..H............text...L.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................%)......H.......P ......................d'......................................BSJB............v4.0.30319......l.......#~......d...#Strings....p.......#US.t.......#GUID...........#Blob......................3..................................................4.....4...Z.!...T...........@...........p...........U.......................<.....n...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):30880
                                                                                                            Entropy (8bit):4.644629646041882
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:bWoLWvBn5oNBVVp+YA6VFHRN7KBmo8R9zYJF:faBiBVmFClomoQ9zK
                                                                                                            MD5:460684B262DE49F8A3C771B47C993EA3
                                                                                                            SHA1:15B760439D2C0A0B39EEC012EDA53D67078D0FA8
                                                                                                            SHA-256:2D796A9138318AC5BCFE96970F3C5920F8307856C1BEE5F9D5BEAEF0369AE319
                                                                                                            SHA-512:41CF1EA52BBF2ADEB8A066533FE9647B67E9FEEDBF45DC4E517D61EB31A35B8944062DE7B59476AE8E533E99CDC5E06270957652A1467F94157264F53258ECBD
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...e............." ..... ... ...............................................P............`...@......@............... ...............................................P...(...@..........p...............................................................H............text...~........ .................. ..`.data........0.......0..............@....reloc.......@.......@..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):18192
                                                                                                            Entropy (8bit):6.55554414057899
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:AYSj5rt9x+uicWKNWv9YA6VFHRN7s2IR9zXRv:ATj1t71c9FClPU9zl
                                                                                                            MD5:76436C13BBA8732978A08454FD284D23
                                                                                                            SHA1:359A7A36E8DF9517450BFF786C07C68ABC004C9A
                                                                                                            SHA-256:AD4C4C92BAD3D1BE04793A39377129A42C45C227FE404113FB9F9BEBDA3C4B06
                                                                                                            SHA-512:23DCEF122EE3DA9E0D3A40BCBAE1673DC5EF84103207D56FE5B3823E8D20D5B15124BC83DE0E6DD60AC06BDE8F0EE6527E7D70A654956DB68F4AF97FC4102A6E
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....4............" ..0.............22... ...@....... ..............................kK....`..................................1..O....@...................)...`.......0..T............................................ ............... ..H............text...8.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................2......H.......P ......................l0......................................BSJB............v4.0.30319......l.......#~..........#Strings............#US.........#GUID...........#Blob......................3................................I.....3...................................................i.v.........N...........%.....B.....5.........................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15632
                                                                                                            Entropy (8bit):6.8214166952315685
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:kKfpo0MNnIWbmWv+YA6VFHRN7DRxB+R9z0d:DBo0MLH+FClDRxw9zC
                                                                                                            MD5:3AB302DE13AB2C008D41B4BC381F5C45
                                                                                                            SHA1:DA82EF01893EC54D6AB9371EA93B398270923323
                                                                                                            SHA-256:0D269D39F04173829F9686CFFBD8AF33030D2D6BBE42BF090FD35FB86DA6FCF3
                                                                                                            SHA-512:E313ACA9F9805B7CF98BB855E843D88F5E0585B86F132B788D58A593A0017C18521ACBC1F842421B50D2FCB56B62ECFD3CF0C87BD7DA7129D56BD2CBB5150488
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...u.i..........." ..0..............)... ...@....... ..............................k.....`..................................)..O....@...................)...`.......(..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H.......P .......................(......................................BSJB............v4.0.30319......l.......#~..D.......#Strings....0.......#US.4.......#GUID...D.......#Blob......................3................................................(.`.....`...f.................L...........|...........a.......................H.....z...................(.....(.....(...).(...1.(...9.(...A.(...I.(...Q.(...Y.(...a.(...i.(...q.(...y.(.......................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):51464
                                                                                                            Entropy (8bit):4.966231479839345
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:qOwMiFMwIImR3GwWxUezVsPkDb6i5DC4dezFTa:qpdm5GwYxEkDb6KFIta
                                                                                                            MD5:3CF7102500300B05DA0684577ED54202
                                                                                                            SHA1:7DBD4086C08A45C405AD38338E1D0B4306671B09
                                                                                                            SHA-256:64889EC4D820F87797894D0DBCE86240830F8DEC085A3C1DC6E21250F512E34E
                                                                                                            SHA-512:C7AE087E7E30DD14315DC4AA4C70E4A7C94F272C41BB49D3041F18474240D895371DF0ED2373AE92FB561004324565D52237C21607F7C0BA3DAD33CD61DA7DD2
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...0.'..........." .....p... .......................................................#....`...@......@............... .................................. ................)..............p........................................................... ...H............text...Zg.......p.................. ..`.data...............................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15520
                                                                                                            Entropy (8bit):6.831239516010608
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:q7e1eTxASTWyUWvqPpWjA6Kr4PFHnhWgN7awWr4I8HNsAX01k9z3Aa30ah1A:qCUNVWyUWvcYA6VFHRN7LtHNsAR9zF0x
                                                                                                            MD5:FA3EC6DB4842FE658F04CF3789CD7209
                                                                                                            SHA1:8E471D546C18604F20AC6F4EB4C242B887CA0689
                                                                                                            SHA-256:B7EF3589E7F793D9780FA32EFB2595C91A85D92E6E0FF62B5187142114F1707C
                                                                                                            SHA-512:337ABA8011D756C69BBA57C2517487FCDFFB0A5D22362669047776D28D789EABA286E867E15196736F83346466B63AF0DA412E283E6BC3884F5C7819085F97CA
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....h..........." ..0..............)... ...@....... ..............................U.....`.................................{)..O....@..d................(...`......X(..T............................................ ............... ..H............text........ ...................... ..`.rsrc...d....@......................@..@.reloc.......`......................@..B.................)......H.......P .......................'......................................BSJB............v4.0.30319......l.......#~..(.......#Strings............#US.........#GUID...........#Blob......................3............................................................@.O.........k.....&.7.....7...V.....l.7...;.7.....7.....7.....7...".7...T.7.................I.....I.....I...).I...1.I...9.I...A.I...I.I...Q.I...Y.I...a.I...i.I...q.I...y.I.......................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):96528
                                                                                                            Entropy (8bit):6.024769249295685
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:BOryyBJoyJyGXe5CtLey6+67NVpnSPM+l5+tkmVgKmH6iRnzDDn:BPyJO5CtiXdSPM+r6kmud6KnTn
                                                                                                            MD5:1BA98C8A3C7D903ABFF78D01E081D64C
                                                                                                            SHA1:15EF718B9F1EEC435C7AEE8A59B41562D88934A4
                                                                                                            SHA-256:69DE6AB16DFBA66224B37E4FCD5E62AFDF45F75C9F5C78BFD6CBFA09142390C8
                                                                                                            SHA-512:FB194521D9964012CBCA456505A9858B49F36009A6E9DCE9F9EC6126693990750285F57DB2831048606336EB9F28193D6073B3E6CACEF337D7323A3967FF3846
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...;.=..........." .........0...............................................P............`...@......@............... .......................................(..\....P...)...@......X...p...............................................................H............text............................... ..`.data........ ... ... ..............@....reloc.......@.......@..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):17056
                                                                                                            Entropy (8bit):6.59164397370935
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:DnA37W6LWv2qYA6VFHRN74G/6fR9znQJ0:Dnka2qFCl4t9z9
                                                                                                            MD5:5B8D61FE9D1525A7F1479001B5ADFA91
                                                                                                            SHA1:92A41489B496F19730C99AC70A3F4B85AA9A4024
                                                                                                            SHA-256:7AF94B0D91DE391BE95AB3DC816EAD7072CB2354199773FBB05C2D3AC1C3F871
                                                                                                            SHA-512:B9D843B6501E304D971CCC8C3B579E4430E4D7C05A2122EE28DDEBB017C5A0EC1A348BEE7D1C6E1DB11EEC01FCE6F11909284ECABE079ADA742800D94F34F235
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................."!..0.............~/... ........@.. ....................................`.................................#/..X....@...................(...`......,...T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................`/......H........ ..\...................P ........................................J......#.}1..T\>..M.].WQN...I...)0.!.Zc..........9....;{*.z...K=J...6.c.Dr.!...q..^E.e<B.....tM.!.^.\....+....^c.p...J.`.BSJB............v4.0.30319......`.......#~..P...d...#Strings............#GUID...........#Blob......................3................................M.....I.........B.$.....$...[.....D...........A.............k........."...........{.......................b.....o.......$...........
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16144
                                                                                                            Entropy (8bit):6.745282705194393
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:qjMTlhAxYPWuGWvlpWjA6Kr4PFHnhWgN7agWFdYPKDUX01k9z3AWipYNX:qjMTlMyWuGWvlYA6VFHRN79pR9zvHV
                                                                                                            MD5:9CCB06FECC5F840F88BBE8E7C9797CAC
                                                                                                            SHA1:75D00AF394B6E8406C5DFA3E7F96A68363368FC7
                                                                                                            SHA-256:C160277C510E5A535B2369A7B12135E2E790EDD1F34EC2B1E2FC80ED8DE475C8
                                                                                                            SHA-512:064B5AE4FAA13A3C68627F1CFC88E9B883179CF64FF14110DEE4AEE49F278DD66402BDA29B78ECBB9F3368A5A52A35C647C79D8EF7903B15BFE9725B5C5FB883
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................."!..0..............*... ........@.. ....................................`..................................*..X....@...................)...`.......)..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................*......H........ ......................P ........................................-*f;..??..`.~5c+)q5.b.[.....?q0........G.&...r<p....N.b.I[e..u,......fu....e.d....&G. ..?_t.[/...e..!..4.,6../.]|.G..K.%.H..BSJB............v4.0.30319......`...(...#~..........#Strings....0.......#GUID...@.......#Blob......................3..................................................P...X.P...p.....p.......v...V.....z.....).......1.....1...?...........>...............................P...........
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):329888
                                                                                                            Entropy (8bit):6.652393975318632
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:x17UgKhUflT6tEFs8Sx/mPueNpQV587It9diIKc1yCC:x17SeflT6tK8UQV58kt9diUsD
                                                                                                            MD5:721811312D3F000E40A403983E60F6B7
                                                                                                            SHA1:DC9E6186A10ADF2419F8DAAC6DBBB11472A3BBB5
                                                                                                            SHA-256:39562DC738F28E2994CEE74207BEE53C833231EC68B2885E403DC3D9C43B6821
                                                                                                            SHA-512:E25E51E6ECAB823691F2E5296EBD257D15521639FBB2994B625433921445F8BE14A4FBB6D4A19A0925B0D7FC07031EE16B48B7DC4396B4A4916626D673B4EFC3
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....X..........." .........@............................................................`...@......@............... ......................................`n.. ........(......p...P ..p...............................................................H............text.............................. ..`.data...-#.......0..................@....reloc..p...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):309536
                                                                                                            Entropy (8bit):6.56574804790244
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:nzv7WOXu33WPEei5EZNqHRk5XDiio9gZbzZYNAgk74dzzKX22zRrRBKZ+FhJDwwz:J2WR1BpLDRcnFIB2ahm97z/+
                                                                                                            MD5:B0A85005B5AAC68913092BEBEE39F34B
                                                                                                            SHA1:4E747E19165BB28054F5895A36ACA213E3B6A115
                                                                                                            SHA-256:984ED1D9AC926AB13FBBD8712CDF3CA5A7701E57C1A22B684541E46ECFBA9979
                                                                                                            SHA-512:86991DC81D38E14F19B7F1C1155F7DDFBA2FC2ABB5E5843C238984C876D5BF01E6F6613F022372226B589056E1ACDA0B7227937939DABAF33311CCCCF583FB0C
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...v.b..........." ..... ...`............................................................`...@......@............... .......................................i..`....... )...........#..p...............................................................H............text............ .................. ..`.data...'N...0...P...0..............@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16152
                                                                                                            Entropy (8bit):6.7495299582867805
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:UVhg/xiIqHVWbodB5WvgWcWxNzx95jmHnhWgN7acWnqAgfcMbnoQNpX01k9z3AZl:UV0fYVWbodB5WvtjX6HRN7Eq/7R9z5iR
                                                                                                            MD5:083C2972E3414380BD45BC621EB5295D
                                                                                                            SHA1:1F3ECEF2865EC4C45E513A9846258DC6A280B3E8
                                                                                                            SHA-256:17AD1F1709F3A153FA0DBD43D4DD46D2477D090949AE86E7E88953D8C19A83F0
                                                                                                            SHA-512:7F3E0AFC520CB9C6C7D8DEDF3E97B4AEDB8D44EFC2BDD1CBAF27CA02A0DB5E09BDC6FCF6894E22A548575BF523AE1A6895838BB816A5DE1323EBAC87C0A3DDAB
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....0..........."!..0..............*... ........@.. ....................................`.................................S*..X....@...................)...`......L)..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................*......H........ ..|...................P ......................................j.u..j..y..p...C....+........4.n...Y..\0$c.....?^BV6...LR.mF^..8...P.....c..}.:Ac..W.5_.c6r.}.db...8>...?{....eq$>..-...<..pBSJB............v4.0.30319......`.......#~..x...d...#Strings............#GUID...........#Blob......................3............................................................3...........^.......O.....O...a.....w.O.....O.....O...w.O.....O.....O...G.O...I.........................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):39200
                                                                                                            Entropy (8bit):5.1532257055006365
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:gHWF8JBrWvXsWHkhzHE0ue4q+k+ars69R9pnUkO2akIGt6HHDZax1IJhXcKX6HRy:gq8JB6cBXDsw9pns77EiWE6D9zIl
                                                                                                            MD5:5E78166E97851B13B4087A54EF712D8C
                                                                                                            SHA1:5228E45D993D397B7355191C2A50F03334851A00
                                                                                                            SHA-256:E91D3502B52775C240CC81B9D3BF36E503CE9C2640B45D1614BB667AA5C1849B
                                                                                                            SHA-512:67D6194F6975110C67C3966F0AE994AF433780239E9270C47903A1AF0851D44443885A6573271767CA85B1DD795B7D441A8A4CCE15966985E5A352280D7F4006
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....f..........." .....@... ...............................................p......s.....`...@......@............... ...............................................p.. )...`..,.......p...............................................................H............text....=.......@.................. ..`.data........P.......P..............@....reloc..,....`.......`..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):17184
                                                                                                            Entropy (8bit):6.676772135546476
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:ckrZI8N3bMWsUBBgWvBgEX6HRN7x9R9zUsp/:ckrZI8N3biUBBBBgMW59zzp/
                                                                                                            MD5:FB2252EE905F33760D6D40FF4E5A37A7
                                                                                                            SHA1:C93E55DF5AFC58809BF4099EF62F739F089525EE
                                                                                                            SHA-256:3F91EEC7FDF494D6C223B093024ACA3B6F16444F89D1D7A26B2F4F289BC8F830
                                                                                                            SHA-512:38200EE479F480C34A94822C563A6862A124493F14F786FFD63249215F5047389DCC3E95CB6ED1CB729DDF89BDC23F0A25845677F19C47212403B8D1995CA20A
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....M............"!..0.................. ........@.. ...................................`.................................M...N....@.................. )...`......H-..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B........................H........ ..x...................P .......................................C.J.O.S.lE{..k.@.[..:1..%qiF6.6.L....w...g..d'..p.-..8.s.&..-{...w5e._k...!v....'p.T.7_o.T@..)*.I/...))...<....F....BSJB............v4.0.30319......`.......#~..........#Strings............#GUID...........#Blob......................3................................"...........................W.a...............=.............Q.........R.......................9.....k.....m...................A.....
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):17160
                                                                                                            Entropy (8bit):6.688880877671809
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:p6Xu2tNCj8NMbLWgV4BHWvPYA6VFHRN7wVKau2R9zGN0u:MXNtNCj8NmPV4BGPFClwAauK9zI0u
                                                                                                            MD5:C173858DDAECFEB532221BC0714655E9
                                                                                                            SHA1:E6C6812A3562369FD0DEAC4A58573D278FE61E65
                                                                                                            SHA-256:3FF4F2C5A52617AC51B1B030FA1C77D5BCE4CB39C173BB78EFBBBC2A7C84BF66
                                                                                                            SHA-512:A0825419C6C6C118D37D11276E079EF64D94321E97AD880CAECB8AF41129E19CDF769AC3A762637E108443AEF7CBD171C4ECEA0369C515752911B5AA36F9B6A5
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...v.D..........." ..0............../... ...@....... ...............................j....`.................................u/..O....@...................)...`......|...T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................./......H.......P .......................-......................................BSJB............v4.0.30319......l...d...#~..........#Strings............#US.........#GUID...........#Blob......................3..................................................~...<.~.....S...........Z...a.;...{.;.........#.;.....;...0.;.....;.....;.....;.....;.................3.....3.....3...).3...1.3...9.3...A.3...I.3...Q.3...Y.3...a.3...i.3...q.3...y.3.......:.....C.....b...#.k...+.....+.....3.....;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):43680
                                                                                                            Entropy (8bit):5.842163683540018
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:768:C+1fsSED2vCeDQvRzXB3gWql6375IVxedktN7xPBhwsR/JG39QRoNvsh2JcfoDLf:2B/LuYdy50b4b7RSHnbOiKmVzvP
                                                                                                            MD5:EA2E0866F900117135C1771D85281303
                                                                                                            SHA1:EC58A506017621DB3233D1513D28727EA2FA7C7A
                                                                                                            SHA-256:819E11FE3C456DFD56377233B2BAE5BC11FEF41FA3A8816ED30FAFFF74A2090F
                                                                                                            SHA-512:4FAE0463DD343E74D73401E9724E17F044699CCCCEE3873467A0171360FA1F0AF080178A71AD7DDC7878218C9069ECCD9B7B85557E699FAC0CDAAA28BAE0C40A
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...3............."!..0..x.............. ........@.. ..............................{.....`.....................................Z.......T................(..............T............................................ ............... ..H............text....w... ...x.................. ..`.rsrc...T............z..............@..@.reloc..............................@..B.......................H........ ...u..................P .......................................n.-9..0...l..3./?Z<WL*.c7..+h.(.......m.!e....}..u.:. I.G..#>.DMl.g.t^.!.OF.X.(..&.$......3.p......'q%W..k9...=...|.s.IBSJB............v4.0.30319......`....2..#~...2..T@..#Strings....<s......#GUID...Ls......#Blob......................3................................{......#...........6..`..6....m6..(7....4.. .....%.....%....m#.....6...!.6..&..%.....%.....%..s..%.....%.....%.....%.....6..........
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):231688
                                                                                                            Entropy (8bit):6.4927538353537635
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:QTJLDgw9ow9j0rKu8bmb3KD/L8V8/6Xe9QF+wVkjox7rtefYGA/+PXuXUGL:mgw9ow9A4bmrA/mt7jWfuka
                                                                                                            MD5:01187D21FC09DD04F699064387D5E27C
                                                                                                            SHA1:F6B7086AAABAB39E2AB7A2FC5B130BC2150FC1C5
                                                                                                            SHA-256:BC1F295790C53358899C6721E0CED2F33F695C2421B2BB97FAB18F9DFFDD0198
                                                                                                            SHA-512:185FFE28CDFF7738DA5E278616B374DF79D0B1486B3D4B218266E1C408003DB509AEACF9D5C10D3F84EADED3BB9BD2A1A55F1156F9CB1C320384D62B05009410
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...4............." .........@...............................................`...........`...@......@............... .......................................U..t....`...)...P..H...P ..p...............................................................H............text...S........................... ..`.data....$... ...0... ..............@....reloc..H....P.......P..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):100616
                                                                                                            Entropy (8bit):5.964892851536555
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:yQAG0KzKsXnTOShX+bX5SHuDQp6O/U/xOQwQ7rzUU3q2bP6NLrSjlV4i7Ep4za/e:ywRXSSV+bJSHu6cgXSJV4QXUe
                                                                                                            MD5:82BB53A6347A98BC441E26C6EFBB6EE7
                                                                                                            SHA1:94FFF378394772F8F6B37A66A3C7DAE43F3848E3
                                                                                                            SHA-256:D407C1380C52E1A04E554C0B134D9BC4699C7225290003ACE8E988E4AEEDBB25
                                                                                                            SHA-512:4BC1BFEF668F6843F85FBCC28B886E66BB886D30903C8DC8CBE3CCA8417AFB6130856C73FFF0686E3022ACEF8D26994DB4CF296ECF788EBA9D59B8E21EA74E58
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .....0... ...............................................`......K.....`...@......@............... ......................................p+.......`...)...P..8...@...p...............................................................H............text...|#.......0.................. ..`.data...{....@.......@..............@....reloc..8....P.......P..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):17568
                                                                                                            Entropy (8bit):6.594046728282668
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:j63EqCxAvK2WIBWv59pWjA6Kr4PFHnhWgN7awWneCjVi6KrIX01k9z3AszWInEn6:20qIOWIBWv3YA6VFHRN7R49R9zriJ6
                                                                                                            MD5:3D57375A1B2FB9E988E522F05125C445
                                                                                                            SHA1:B11D29EED40A5F27A20186C8A31F97098B54CB37
                                                                                                            SHA-256:3BB8895B734D1967615845BD34FE9A3BB7AEC23546D1E55C16678697B92E466D
                                                                                                            SHA-512:C31248443035E571CCBD87996DDA2F2898EBB5665EAF99B8799A046D7C6F6D4FBB1B2DE1F5B87BE56D8A6B4181EDFBDCA8D0C873AE0856F1EB0E801349DC07F1
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....H-..........." ..0.............R0... ...@....... ...............................P....`................................../..O....@...................(...`..........T............................................ ............... ..H............text...X.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................30......H.......P .. ...................p.......................................BSJB............v4.0.30319......l.......#~..t.......#Strings....|.......#US.........#GUID...........#Blob......................3................................>...........................?.....6.....j.....%.d.....d...U.M...k.d...:.d.....d.....d.....d...!.d...S.d.....H...........................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16656
                                                                                                            Entropy (8bit):6.715593579536355
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:OvV8AxNaHvxAPADWZfWvT4pWjA6Kr4PFHnhWgN7agWkzKDUX01k9z3AWipd6T4:+EHZjWZfWvsYA6VFHRN7rpR9zv6
                                                                                                            MD5:A52D0E2B5EDA30DA599AB9EF536EE43F
                                                                                                            SHA1:C2CA58894F9B26B27E090BAB6D483546C1F83F56
                                                                                                            SHA-256:F45FBB7D188FEF81BEBFC32F177335FCCB6CE9E9BC014CBB99752D8F085CEEFC
                                                                                                            SHA-512:4C9FF15E1BE5B968990726BE10C2A910187E368AA6E9AA55F9235438F036F50B3D04B40DD6C9BC3EFC2AC2C275F2183A750E033AD359646A20A6AF6045E07719
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.... ..........." ..0..............,... ...@....... ....................................`..................................,..O....@...................)...`.......+..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................,......H.......P ...................... +......................................BSJB............v4.0.30319......l...<...#~..........#Strings....0.......#US.4.......#GUID...D.......#Blob......................3......................................d.........J.!.....!.........A.......J...n.....,.........................................j.........................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16152
                                                                                                            Entropy (8bit):6.795893683417245
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:bTbUikV/AvcaTAFC2xArKWJtWvjWkWxNzx95jmHnhWgN7acW6swKUWX01k9z3AdF:PbUVJWJtWvCLX6HRN75t2R9zGFP
                                                                                                            MD5:A6C3B858EE0CA8E265219DBDD692DA96
                                                                                                            SHA1:1A6C76B404ED9ACC793A7C1DAC68FB664FAE0718
                                                                                                            SHA-256:44BFFA0D3D0C59AFCB6205071167B52D6AE5DB3E8F167C955FBC5592EE422510
                                                                                                            SHA-512:6D466C9A8C5DF820DDFECDCEA511DF858CD7B26958A629D7F0463C0441DA1AE9B1F929C2B19B0B63D1F494C4338855AF2B333FD57E01AAEB99B0E35FDED3FBD8
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...d............" ..0..............+... ...@....... ...............................p....`.................................}+..O....@...................)...`......|*..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................+......H.......P .......................)......................................BSJB............v4.0.30319......l.......#~..........#Strings............#US.........#GUID... .......#Blob......................3......................................................x.....3.n.........^.................I....._.................w.................G...................h.....h.....h...).h...1.h...9.h...A.h...I.h...Q.h...Y.h...a.h...i.h...q.h...y.h.......................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.7285494674641
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:0zox6WeWWvYYA6VFHRN7IL/6fR9znQ2BDi:0zoxq3YFCl19zpDi
                                                                                                            MD5:11867901021083A68FA4D1FF345F477A
                                                                                                            SHA1:FF0889F05B3161F7D27CCC5FE2DF7F9A430D9E1C
                                                                                                            SHA-256:CF9436FF6A04184E6049CCBC5C27D638DFE5DE134640C35A4D5873FAA010FCC9
                                                                                                            SHA-512:D2B42520FDB3F83C8648047AE1D4E6350F81BDF3D8286C4AF01221DD2DD9B018B5DAA390927170FE49CF4ACB01DFBE63D45CCC4AAF6B451BAF9AA22B239CC2A0
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...Mpv..........." ..0..............*... ...@....... ....................................`.................................s*..O....@...................(...`......h)..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................*......H.......P .......................(......................................BSJB............v4.0.30319......l...L...#~......<...#Strings............#US.........#GUID...........#Blob......................3................................................ ...........^.................D.d.....d...t.7.....d...Y.d.....d.....d.....d...@.d...r.d.................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15536
                                                                                                            Entropy (8bit):6.831442459723241
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:oz3xAn1e9WABijRWvtWxNzx95jmHnhWgN7awWChD/DoSJj+iX01k9z3AjFDk:i79WABijRWvuX6HRN7v9/DX+iR9zwW
                                                                                                            MD5:4C8CC0E429ED432A088EFACAEC656770
                                                                                                            SHA1:590F274CA3075533293AD01E6088B473E604602C
                                                                                                            SHA-256:738F70CFAC6A793F518DB6E3586F2740BBA663DAABC07672CE2A4918A9EF5580
                                                                                                            SHA-512:7C1BA5A2B9B4433C728462928FBA4A3E5C42E3E63EB202F4DAE90C129B31FBB5CA0DB3522ADAAEB29AB2D0D67D4AC476C9EC6959A5AE771DE19AA7016627FE98
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....}............" ..0..............)... ...@....... ....................................`..................................)..O....@...................(...`.......(..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H.......P .......................(......................................BSJB............v4.0.30319......l.......#~..X.......#Strings.... .......#US.$.......#GUID...4.......#Blob......................3..................................................|.....|...E.i.........p.....+.Q.....Q...[.J...q.Q...@.Q.....Q.....Q.....Q...'.Q...Y.Q.................c.....c.....c...).c...1.c...9.c...A.c...I.c...Q.c...Y.c...a.c...i.c...q.c...y.c.......................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):759968
                                                                                                            Entropy (8bit):6.636461086910098
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:UxoB+nhcBfFBUnQi70v8uEJh5UOSDxGcmptxF7VWG2tObhE4K5:yHQu/0EueexGcUtxF7VWG2tOlE95
                                                                                                            MD5:8D2B652263E5884FC82ABC73A210BA2A
                                                                                                            SHA1:4AD1E5DB2033EF1579E3B7BC3D6BEA638C2E56E2
                                                                                                            SHA-256:BC0E941D59F7BF9DBC240EF83DEB8D1EE63B3595DD098967C1E733D90260F851
                                                                                                            SHA-512:91DC26606D5E37A3E2A09EF614BFA0FF561F851AA81DBDA30EBE59E58B846DD6C1E5B2CFA2B0AF8D6A7BA537BCA7D59B895736A590E0AF06F3075DAF0D68472E
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...pVt..........." .........................................................p............`...@......@............... ...........................................;...p...(...`.......:..p...............................................................H............text...2........................... ..`.data..............................@....reloc.......`.......`..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16136
                                                                                                            Entropy (8bit):6.7781584154919665
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:ifO9v9WY3WvbYA6VFHRN70zwVXC4deR9zVjTTDS:OOFZ2bFCl0cVXC4dC9zVjTnS
                                                                                                            MD5:8B04C9FB125B99DA5BFC0381692A5FD3
                                                                                                            SHA1:19746B26152A1A83A0A5B3A736A131CB59287779
                                                                                                            SHA-256:825A454E5B4595CA7F105A308288873A9A28F02EEA1A524D395AED224DBD57A2
                                                                                                            SHA-512:15F30712C990050A455708CBCF2AF2B18F1FDC4581E5F0A2A3E7992F3AFC8C59FE110273AF9D7FFA9E0D0D7F7844D5C0AD1CD6950C9F235BEC7389B6B5D5C27A
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....4..........." ..0.............v+... ...@....... ..............................%.....`.................................#+..O....@...................)...`.......*..T............................................ ............... ..H............text...|.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................W+......H.......P ..D....................)......................................BSJB............v4.0.30319......l.......#~..........#Strings............#US.........#GUID...........#Blob......................3................................................4...........r.................X.............(.........m.......................T.........................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):55456
                                                                                                            Entropy (8bit):5.600389797972162
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:768:WeKDjiacl7ACvmx7FKI+ptTD9Wg7k57n2eJqFCl/wDuO9z4KB:WDya0cCveFG75Wr2eAi+z4KB
                                                                                                            MD5:320327E2A99304156AE3B0EC3F134270
                                                                                                            SHA1:71AC532EA74B4310DA58BA9F0529DACC0C19F1AB
                                                                                                            SHA-256:0D4095AA5E0373F21F0D046E0EFD3304624156D36ADEAE2996E7652A222AE4BF
                                                                                                            SHA-512:EBC7C767F5F0E3A1B070D1D4BF4FA939A5FBD4183F9BF0003FF2EFCB68ACAC84F4B7B5983334455F7A21ED9230560AC33A4E3B3A741B5FDD8D6EE6498B70EF3C
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....4............" ......... ............................................................`...@......@............... ..................................$................(......d...h...p...........................................................(...H............text....v.......................... ..`.data...............................@....reloc..d...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):17168
                                                                                                            Entropy (8bit):6.744985038171994
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:2Hzoc2l9WWfWv7YA6VFHRN70ORxB+R9z0AG:4zovlru7FCl0ORxw9zXG
                                                                                                            MD5:D671EFA2A023A61CCA5729BC5696B4FA
                                                                                                            SHA1:B26DFFC059655C32092CFF62F6C6D074C4F2B186
                                                                                                            SHA-256:02C67B42BD1C6E8D8954F96C3AB7C00575E7FAAAACCD58A8F60CD20CD74A2D43
                                                                                                            SHA-512:0EDA02115C25C6BE1F48D5EF85C87C2889F9ADEACE939F17320EE25EE27BDCE741E18289D7E36E2B1634C2C56AD1EE38C6B1DDE05A735E2CBF910DF4060F0AF3
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....c..........." ..0............../... ...@....... ...............................y....`.................................s/..O....@..D................)...`......X...T............................................ ............... ..H............text........ ...................... ..`.rsrc...D....@......................@..@.reloc.......`......................@..B................./......H.......P .......................-......................................BSJB............v4.0.30319......l.......#~......T...#Strings............#US.........#GUID...........#Blob......................3................................-.....r...............'...................X.....k.....k...........k.....k...i.k...&.k...C.k.....k.....k.................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):456864
                                                                                                            Entropy (8bit):6.54420536200444
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:KHcXqG6bINOxPS5n7aGTh6npadBcV85eu:K3GjOdY7wBu
                                                                                                            MD5:3C8EA9AD233098B980F254A5CB0A01A8
                                                                                                            SHA1:B95600708DE3949EEEA51E27868988B1B66F867C
                                                                                                            SHA-256:1D391B2A96A07D45236778B81FE80CAD479B194FEE464900B5C551E896AA2F53
                                                                                                            SHA-512:3ABB1EA3C626922BB677A97B109CEDCF349FB23E87CB14DF1037F08E2DA333FA5A8BF156FEEC87E25776C4D24D0423C2B4FDBBA406866BD84998F9778129259B
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .....P...p............................................................`...@......@............... ..................................h........(.......(......p...p;..p...........................................................h&..H............text....B.......P.................. ..`.data....[...`...`...`..............@....reloc..p...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):2050208
                                                                                                            Entropy (8bit):6.677577580791444
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:49152:HUy8hZ9wf3V7i9KAgmJE2Jjd/mxObmVw6Q41x:HU4QRgeL41x
                                                                                                            MD5:814F7E26E5AEECCEC424393D142FEA98
                                                                                                            SHA1:A9F8B6CB03EBE4E64E2B17FB4E57C17D24B7B00A
                                                                                                            SHA-256:60F3B82345E2812DCFDEF98642B2CA707B34C51D917D86615DF309714EF1E9D8
                                                                                                            SHA-512:46FF8137B77EF79BF5C8CEDBC35F263AB671641B50E0C16D705B744A9E902E1D6349D58570D3BBF4532CCCDD8DAAFBB30C2173C52E02734B589303516ACB43E4
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .....`................................................... ......c.....`...@......@............... ..........................................d.... ...(..........H...p...............................................................H............text....U.......`.................. ..`.data.......p.......p..............@....reloc........... ..................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):186544
                                                                                                            Entropy (8bit):5.9668644667656325
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:kuNLd2rZAzaoZdXEooSgEooVEooYEooeTlVXBIg0WPgE2uU7:f6r+zlpEooSgEooVEooYEooefXag0eg7
                                                                                                            MD5:297784722000D8F6C1DCC6272CB93C54
                                                                                                            SHA1:7CCBAC742B6338CFA8F6ECBED8804C6445D966F7
                                                                                                            SHA-256:7172998EC636B80C3251F7F26AE11190C11A7767D3489B356D82B96CEF0E9A2B
                                                                                                            SHA-512:C25E408C610F645C0CAB5626B1D6FBB0DD97DAE683AEC729BFE9519C24CB01EAF4319EE96B01B7289B563E79B4107ECDED56ADE0895C812A7BF89AC91DDEC5C6
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....j............" ......... ......................................................zJ....`...@......@............... ......................................85..@>.......(...........)..p...............................................................H............text....}.......................... ..`.data...............................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):186528
                                                                                                            Entropy (8bit):6.415230610741847
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:pSw4kXyyyLNMWWqfY8SJYrjXQori1RqU2TOK1xguZunS:VCyyKSA86YrkorvU2rfj0S
                                                                                                            MD5:287EDFA9B689281780A9475A99A587CC
                                                                                                            SHA1:B29E4F6C62D1C1FC83BD4DD9F73405F8173FD28D
                                                                                                            SHA-256:FA4952DF244AC5DD6D5D36B62E25B2CD0BF844453196D29838638518CB6944B6
                                                                                                            SHA-512:7D2BB2334D641E4831C3F2A4A304AB82DAE11B5F06718524B479D27C5B151212692E97A114FA40B7BB8610DB8FEBDE4B2BC2EC8A4C555197D295AF057B636C08
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....T..........." .....`...@.......................................................~....`...@......@............... .......................................N...........(..........h...p...............................................................H............text....T.......`.................. ..`.data....&...p...0...p..............@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15640
                                                                                                            Entropy (8bit):6.801577686636654
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:kB0LPxAb0OOi3jWVMfWvVWIWxNzx95jmHnhWgN7acWnwKUWX01k9z3Ad7eTowl5:dL5+WKfWv0nX6HRN7Z2R9zGAl5
                                                                                                            MD5:D5AB3127B17D4E08CE04CFD5CC3DB2DA
                                                                                                            SHA1:D40032C264C94D084ACC129FD4B467AEA550936F
                                                                                                            SHA-256:5F45B771954E4B7DC4213F1E808AA1C01971384F314E17A804595604FA272735
                                                                                                            SHA-512:347977CD08F6C7242D8F1557C36340D617E06F2CABBFF8452F16BDA1E57DE105F72C016846717F317357071EA6F874D60CD8F3E552C58EE4B4DD3C0478BCCF86
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....j..........." ..0.............j)... ...@....... ..............................:.....`..................................)..O....@...................)...`......$(..T............................................ ............... ..H............text...p.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................K)......H.......P ..T....................'......................................BSJB............v4.0.30319......l.......#~..4.......#Strings............#US.........#GUID...........#Blob......................3..................................................=...x.=...3.*...].....^.................I....._.................w.................G...................$.....$.....$...).$...1.$...9.$...A.$...I.$...Q.$...Y.$...a.$...i.$...q.$...y.$.......................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15648
                                                                                                            Entropy (8bit):6.831749206420305
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:4FMYodxAanD/YHWl3WvM2WxNzx95jmHnhWgN7agWGhHssDX01k9z3AeKD++zEA:41mVDQHWl3WvM9X6HRN7pFDR9zzKaM
                                                                                                            MD5:B815AFF49D8A185341D31ABAB43F4DB0
                                                                                                            SHA1:BF661D387D2FB9FF3BBD51B5412B4B395A76EA01
                                                                                                            SHA-256:D788B912A2FCADA28A9A1E2D221AACA429D20A420B05315F173A5A5365BF3D5E
                                                                                                            SHA-512:BC07CA500FCDD762032D5911C303DBC28B1E720D32A91129B3C1C07A8B01CDF73DB82E69D5C02571001E06D83C2589B40EFA23CE1820029DD0156A6098403762
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....I............" ..0..............)... ...@....... ..............................3x....`..................................)..O....@.................. )...`.......(..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H.......P .......................(......................................BSJB............v4.0.30319......l.......#~..D.......#Strings............#US.........#GUID...$.......#Blob......................3............................................................3.Z.........^.......B.....B...n.;.....m.....m.....B...S.B.....B...w.B.....B...:.B...G.B.................T.....T.....T...).T...1.T...9.T...A.T...Q.T. .Y.T...a.T...i.T...q.T...y.T.....T.....T.......................#.....+.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):18592
                                                                                                            Entropy (8bit):6.50782634151712
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:uW7XHkE3jDvupZFiVyJjxA7A63WwDWvtpWjA6Kr4PFHnhWgN7akWWKIjwX01k9za:5If+3WwDWvtYA6VFHRN7EHR9z0A27ELu
                                                                                                            MD5:042B64BA15515B5ACC1B53D31076EADD
                                                                                                            SHA1:C8D810607D642B7D63C4F0A70FC5D891CD0C4D83
                                                                                                            SHA-256:5CD2E42D0C8C3BEAD4B8BD993750A3D5D266039DAA52506F7BFC27783990226E
                                                                                                            SHA-512:E624E89ED367F0C91D8B597CB351A030ECD6FC0CBE45AE5AD5F48A45D76C0C3F28EF8A4BFDFD32D37E51A7555E7FFC74B0CCE5E751FF0CAE6F8C7E8A90F9953E
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...~............." ..0..............4... ...@....... ...............................J....`..................................3..O....@..T............ ...(...`.......2..T............................................ ............... ..H............text........ ...................... ..`.rsrc...T....@......................@..@.reloc.......`......................@..B.................3......H.......P ......................P2......................................BSJB............v4.0.30319......l...H...#~..........#Strings....h.......#US.l.......#GUID...|.......#Blob......................3................................O.....................0...........3.......x..... ..... ........... ..... ...r. ..... ...*. ..... ..... .................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.C...+.Y...3.o...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):17056
                                                                                                            Entropy (8bit):6.6307312364714805
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:P4n7palYIWo5WvLpWjA6Kr4PFHnhWgN7aIW3k+2NowcLK+X01k9z3AcjTvGY:OmWo5WvLYA6VFHRN7gk+2N6R9zdTGY
                                                                                                            MD5:17B940218F1B5A16BC7576F345C3CA04
                                                                                                            SHA1:CC64810DED8E394421DA7B9521CF5E4EBE977D59
                                                                                                            SHA-256:BE6B73071C8E8BD1EF4702CFE2A5AF73A926D64996479DF2A6E296F942C4DD3C
                                                                                                            SHA-512:3B323281E07A6A207AA23B255AAF1D4E958C8844627CBEAF8413A9B3B234A88B12593E2E0F33AED0EEF10A4D17D384513A1034E85D9FB3ED7969C6B83C68C9B6
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0.................. ...@....... ....................................`.................................7...O....@...................(...`......H-..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................k.......H.......P ..x....................,......................................BSJB............v4.0.30319......l.......#~..8.......#Strings............#US.........#GUID...........#Blob......................3................................&.....................?.................%.].....................&.................>.....[...................{...........................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.C...+.Y...3.o...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.742653380857255
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:2h/pWnylpFWvcYA6VFHRN7z1649R9zri8a2:2hXqcFClA69zX1
                                                                                                            MD5:B690D3E96E11B84ED793FC571EA0A78F
                                                                                                            SHA1:9D9090E5A702750F4CAC744D1D7651BBA6BCBE7A
                                                                                                            SHA-256:7BB1C84D14EFCCBCB84A1F075CC00814757DF752E80A6FC472A1A4FAC9E0C97E
                                                                                                            SHA-512:CB0971C76761455A6D226227442B2A28339C939381D26AF38C91DA23E38883915E712F2966FEEEF090A9996A993A45633C14AA2BBF6C94092245FA9553F38F0A
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[y=..........." ..0..............+... ...@....... ....................................`.................................;+..O....@...................(...`......P*..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................o+......H.......P .......................)......................................BSJB............v4.0.30319......l.......#~..........#Strings............#US.........#GUID...........#Blob......................3......................................!.........f...........\.....:...........B.^...H.^.....;.....^.....^...+.^.....^.....^.....^...p.^.................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.C...+.Y...3.o...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):862368
                                                                                                            Entropy (8bit):7.456874615261393
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:5f7xn7kZQ6kliVreJIHHr0tRYbKr2KtG9VKABC6rPQYBKgTWeUAm:5D9km6k/IwRYbiBeKGCHYTy/Am
                                                                                                            MD5:BD45A5557BDB95B90A2B51CE1C82E868
                                                                                                            SHA1:576C6EC24EA8DAA10FB7C8360B867C26A78CD9FB
                                                                                                            SHA-256:F22C997008FDA321A85557778F5BF95F369AE6DB161A52D4BB08CEA6991215A2
                                                                                                            SHA-512:989CB3A5B896644775CF5874E99E8DFDA3654AF6D7E8AEA7B38769078B67CF2B87B475A0D494D1717E83C4CA7A11B15895B01BD0C16D122F101E1FC46EC05F00
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....+............" .........@.......................................................O....`...@......@............... .......................................B..p........(......<...8...p...............................................................H............text............................... ..`.data...`!.......0..................@....reloc..<...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.712115863132619
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:9CAmXhpuwx9HlWgJWvJpWjA6Kr4PFHnhWgN7agWtYJxu3O6YX01k9z3AnE9:9qxvrWgJWvJYA6VFHRN74YdR9zKE9
                                                                                                            MD5:8DC6E3FB54FAA14613CE7A90722569E4
                                                                                                            SHA1:87F0EDB5AEE1326917F74586B8985C06C4246E60
                                                                                                            SHA-256:08E5A63DEB24F9F9DF1AA4128F2020644A86EDC8CC42D23D3E5E4E00A4A1F52A
                                                                                                            SHA-512:B29AF1804677F24B4E2A9EFBA474C66580F530C09B001E747D9E6676762FD0025D23B6CA2A400F2EA7B09ED7469F160DC32D79856DF30031FC55204EB8C9B936
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...s.$..........."!..0.............N*... ........@.. ..............................#T....`..................................)..L....@...................(...`.......(..T............................................ ............... ..H............text...T.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................0*......H........ ..,...................P ......................................5.Q.....Q...s..Wc....N.f%.........}.8........vB......o.b..3.R...J......2.ED...hg.x..&.F....5...6.xD_^../..G. ...l`,..[.\BSJB............v4.0.30319......`.......#~..`... ...#Strings............#GUID...........#Blob......................3......................................O........."...........;...........f.!...!.z.....z.....s.........;.......z...[.z.....z.....z.....z...B.z...O.z...v.............
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.7004639534089705
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:puw2W9NWv5YA6VFHRN77vhk7vDX+iR9zwB6:puoc5FCl7pEDuO9zR
                                                                                                            MD5:B68AD44BDAF4F427A9E17E58326AC076
                                                                                                            SHA1:6274AB86C6F1F2A0BC2C13C541BA970AB7B7090A
                                                                                                            SHA-256:5A33C014C9AD5C8A60E889F80F1D9E4B3D36DD10FAB49BD1D2538325E7B6EDAB
                                                                                                            SHA-512:1911C839E162A8FE4ED80A5CADCB9019D74E07CFEDFD68AE151A66D0B38A9A601CFE458EA1FB79B608A799618C454EC70C971A5F3EE92C96E35BCE77C3604907
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..............*... ...@....... ...................................`.................................a*..O....@...................(...`......x)..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................*......H.......P .......................(......................................BSJB............v4.0.30319......l...T...#~......T...#Strings............#US.........#GUID...(.......#Blob......................3......................................M...............x.....3.....7.....^.......m.....m...I.f..._.m.....m.....m...w.m.....m.....m...G.m.................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):133280
                                                                                                            Entropy (8bit):6.118931111888508
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:7mTuj37yym3E5T+zpq5D3lhjdPTp8K76+d05Hzdy+NXMBpm4+SqUNiNxCzQd:7mTuq33E16qvZ5N77uLLN8BkSqUNACkd
                                                                                                            MD5:1829B95B9A2AB17DA9612B1529D5DF0C
                                                                                                            SHA1:C6B08686B182940D659D9E12251D8CBB02602BAE
                                                                                                            SHA-256:E73E129E5AED0F39F9147CD1FF2E047B01227AA791943D69A1DE4785B9598FB4
                                                                                                            SHA-512:FF687A80F9DF35DE0CA2A606763631D21D3558F9702028C2E50E20FA46FF4401DCE4585D69222E64988EF7221276363B264C1CFEDA2F67F9FB132839FA7C8E39
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....S..........." ......... ...........................................................`...@......@............... ......................................|-..X........(.......... ...p...............................................................H............text.............................. ..`.data...}...........................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1501456
                                                                                                            Entropy (8bit):6.703064329512441
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:24576:iNDUuuRgw5xH6D9+YFVCwIbvRz6ySHAJcEVAvM8UbUJnBpK95:8vmTH6DMYTCwIlzPScp8UJ
                                                                                                            MD5:44E63A84FC57C49E4F2FA313CF651CBF
                                                                                                            SHA1:65240A270AFB9C06B65BB08ABF2CB8C1FD44EE97
                                                                                                            SHA-256:DC8B1118B266EC750AF5B4480869E01A97751A2F55352AC6908CEFB4A59499D1
                                                                                                            SHA-512:A0078A0FE7C8A092E71841287543E276643A0B469DA77D11B78F7857A6D5A1099FF6E4CE67A7B9992B60D97184922EA118AFD378EF4A357943D054A796456491
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....%..........." .....0................................................................`...@......@............... ...................................... ............)...........R..p...............................................................H............text....&.......0.................. ..`.data...\Q...@...`...@..............@....reloc........... ..................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1022128
                                                                                                            Entropy (8bit):6.821588247611613
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:24576:7PNtms1Go9Fz7KPTT8inDiv67tA2ehjEnQKL:N1G457KLTRivKehjg7
                                                                                                            MD5:66FEE2E52A143A1227E062E88F4C3C19
                                                                                                            SHA1:65F5B79A84F89C820DE6273D0F7F323189C81FF4
                                                                                                            SHA-256:B9FE1181B9C0504D97940331B47DA8817BE5C202A0D57C2B92FE6909972F2012
                                                                                                            SHA-512:36E1CDB8C5AD2064F46BC30FF2F3742DE94D057C0D7ECCC1B1AFE1416EAD3128673CF35768396289FD34249324AE2958B0EF9C1E06298D533FCE7B40EBECD1A2
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....mL..........." .........P...............................................p.......q....`...@......@............... ...........................................G...p...(...P......h...p...............................................................H............text............................... ..`.data....)... ...0... ..............@....reloc.......P... ...P..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):84144
                                                                                                            Entropy (8bit):6.01559741196385
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:4cj1LAKJSc+9NVY3qX7/6T6vGccWysg1D+LMWbzm4Z:4+1LAJc8NVj7/FGx5D+LM0/
                                                                                                            MD5:CF4DFE3880F9DB4476A840637E5558AE
                                                                                                            SHA1:30F1C9CA1A9E6B89D11B541368CF605BC4E76BEE
                                                                                                            SHA-256:C787901537E0BC1E6E4A686FB341294223DFD9B91277341DFCE0DAEA946ABF80
                                                                                                            SHA-512:1D681FCFA1ED9B7F74A69E6BAE6501959C9982F75895F5AAD55DE88544085EE24093330D5A96AB57AFD7D66856997EF3270D7B87CA171F8EC4F40535B30B5C36
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...(............" ......... ............................................... ......9.....`...@......@............... .......................................$..T.... ...(......(.......p...............................................................H............text............................... ..`.data...;...........................@....reloc..(...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):133400
                                                                                                            Entropy (8bit):6.277895373459539
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:Zj3t+/k1S+F3g2vlsEjd2fzs6FlsdJQ/WoioIa3cBPdzcWxRC4dezFTDkn:Zj3tYkwQQQmEjd2ZFli6/riY5avItDkn
                                                                                                            MD5:4D0F0F9563809C92DD1A38DEB4E24F33
                                                                                                            SHA1:03D2328EFB08D1E86686F8876595A162753BE374
                                                                                                            SHA-256:20DDABA930EE090B47FA38722EB0D5D23C9F860E45B3A2C1F03CDB4EA1B69C53
                                                                                                            SHA-512:DCDE9B8BEA8DD1111B2908FF89C96FD8CAD0812881E359EAB59BDF13451F5FF1DD50EADFC2FA2489B8B60A90926DBADC9D4641196974C65442006B0F142B5ABA
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...7.<..........." .........@............................................................`...@......@............... ......................................L7...........)..............p...............................................................H............text.............................. ..`.data....#.......0..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16160
                                                                                                            Entropy (8bit):6.742004031944957
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:PHYCHwcH9H8HzW8HWvdBX6HRN7YRxB+R9z0xfb+:KfGdJWYRxw9z9
                                                                                                            MD5:0F9296306DE9D1BCCE253FC647D1E8D6
                                                                                                            SHA1:2ECA5248F203D94813F3428A3C3A82CAFE973635
                                                                                                            SHA-256:D6AB3875C8FEAF7D6FD9B1EFD18B1FFD10FE46B2FF3A2F24D7FA5D16F927EC0F
                                                                                                            SHA-512:C2A5F479BFEA3357BE02E3C1340C303DD4D20CF3F6A78A6092FB2ED9E3315863F9F8A8673BE7927FF7B9FCF1210C50B90BA6123CAF1F845033EDB7276ACE33BD
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....VT..........."!..0..............*... ........@.. ....................................`.................................;*..P....@.................. )...`......@)..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................p*......H........ ..p...................P ......................................).....Q..$.?o&p]...0.~%.0*s{&;....[.=...A|>.k..9EQ.jH.n....D 4........g./...T...6..SO..CD.V..........UK..bg. q..3.?.tY...v.9BSJB............v4.0.30319......`.......#~..p...H...#Strings............#GUID...........#Blob......................3......................................................4...........7.......c...{.....V.............c...t.....}.................9.....................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):489752
                                                                                                            Entropy (8bit):6.715559969531241
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:X/ZX6ZS+34JkIT8tA7nPgNK4pFI6yB5v3Jx45WX9gLP:XV+Icur4vi5v5x4IX9gLP
                                                                                                            MD5:902DE8298523A79CF1F6E013E4CDE766
                                                                                                            SHA1:0D797B0D06D107A8DE21F72C2ECB6292E5E0F0ED
                                                                                                            SHA-256:E383DE92AA93F424FAEED789CDA2B920699D4A6EC805E5FD46833DAC9CD319A6
                                                                                                            SHA-512:4C0A192E7D6E9BDE627546ECE7287D41184E4FD91AE0DC87D660B5894BF210C27F3E8B1F3E8F5B568ECEF6C29D8AC2980970575EC2ACB6E696391AD88FA9D666
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .........................................................P.......?....`...@......@............... ..................................h......,1...P...)...@......`"..p...........................................................h...H............text...*|.......................... ..`.data...M...........................@....reloc.......@.......@..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16048
                                                                                                            Entropy (8bit):6.76076698039701
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:RCVT05B091ncmYdJfFWCXWvL4X6HRN7N49R9zriD:8VAMopWL4WN69zu
                                                                                                            MD5:1748BB8AE9ADB170599FBBF94B472B8C
                                                                                                            SHA1:A8C8C75A96743945325B9FF652FC99F3037EBC4C
                                                                                                            SHA-256:578E16D2A7B2C1647F925A611962CF256D8915121B86B5A9EDDEA82A9B3C012F
                                                                                                            SHA-512:08A8E6F71445C2D84075111B889618B7935D70312A33E165525210DD96EE9DE5287118443A87EBE6811CBB0334F574762EC2CCFB8A63E625D3173559EB959EE4
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0.............V+... ...@....... ..............................J.....`..................................+..O....@...................(...`.......*..T............................................ ............... ..H............text...\.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................7+......H.......P ..0....................)......................................BSJB............v4.0.30319......l...d...#~..........#Strings............#US.........#GUID...........#Blob......................3......................................s...............1...........A.......O.................................W...........1...................p...........................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):133296
                                                                                                            Entropy (8bit):6.342375712378606
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:UzCkkW0glfG6WVKdrhYnS+5On3kg9dE8rVP9kiTL:0kWxI6WVKVhjg8rVPOif
                                                                                                            MD5:8B391D187DB389BE181E700081C81906
                                                                                                            SHA1:EE3E0803D217FC947EFA6BA2D51CF196337EA4F6
                                                                                                            SHA-256:C44D73E3582228CAE2CDBFE74F6A60D11B4E1B4FCBD7343FA52F3C3C12AEA770
                                                                                                            SHA-512:0D89BEC917A2E82D39EDB089E8AF23C9732FA67205391709608DD0AA826DF5C9FAA9FEC4C265F7ED6AB8D109D620C878AD97F4F9EC8DD6D3CD1E6222DF007DBE
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...r............." .........@............................................................`...@......@............... ......................................44...........(..........@...p...............................................................H............text............................... ..`.data....$.......0..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):17056
                                                                                                            Entropy (8bit):6.608161458975255
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:4af4fk3CB2oqr9z9W7zWvCYA6VFHRN7Ki7Bmo8R9zYqgg:4af4B8ozyCFClKOmoQ9zqg
                                                                                                            MD5:B252E2C17A4297DBB90BFCE9C66DB845
                                                                                                            SHA1:2BABEE3632DE7471E338A95796E19596DEB1CBE8
                                                                                                            SHA-256:35890B7AF3C51962D8342BD17DF24289438459971C0972DDC67E47534C78B790
                                                                                                            SHA-512:31E6AEEDACEDF07EBF9BA7E26F40779005CBC11AAAFB86559F50652EAE5A1C7948706642F7D034AB6358DDB8A9E9CF952840F6DAF61C87E912C1A2FBE456FD59
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....2..........." ..0..............-... ...@....... ..............................(-....`..................................-..O....@...................(...`.......,..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................-......H.......P ......................<,......................................BSJB............v4.0.30319......l.......#~......H...#Strings....X.......#US.\.......#GUID...l.......#Blob......................3................................&.................o...w.o...2.\.........].................H.....^.....-...........v.................F...................V.....V.....V...).V...1.V...9.V...A.V...I.V...Q.V...Y.V...a.V...i.V...q.V...y.V.......................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.750565769577352
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:qBz2EM0u8ZWI7WvtYA6VFHRN7ptHNsAR9zF0+T:qlE2KtFClXts89zmU
                                                                                                            MD5:A1A92B8791B4D56C7B6E335483E38135
                                                                                                            SHA1:8C9D7FC7B452C7993313D349722A2C25283BB53B
                                                                                                            SHA-256:9B1F4F2C7FC17D2CD4F49FECDD6B8D71C77998F54509EF1B28F2910DC9A6B618
                                                                                                            SHA-512:B03148C8FB0F67F5D1C2ACBFF7BE34C8E5D9E17B4FDF60C85AF3437815AACC69DE8DD3E693B44C7E40EA8228EA1E3399849646666046E218972F2CAB8B15CB29
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................."!..0.............^+... ........@.. ..............................(v....`..................................+..T....@...................(...`.......*..T............................................ ............... ..H............text...d.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................@+......H........ ..D...................P ......................................,......#...>....'._D.Xf..........jgO...e....(.."..e......)>. ..rn.Q...2......i$)..>gC..=.a.f.u...H.].p../5...O..../3..BSJB............v4.0.30319......`...|...#~..........#Strings............#GUID...........#Blob......................3......................................].........U.@.....@...n.....`...........T.............y...0.!...9.!.................................u.............@...........
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16160
                                                                                                            Entropy (8bit):6.725064482931626
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:Ji92Uc6uQWcvWvdEX6HRN7fDRxB+R9z0W0S:JWL+dMWrRxw9zD0S
                                                                                                            MD5:0C62633F770757272D10CABB6C8BC0D0
                                                                                                            SHA1:378122B24AA5B589CE11B3EFC9CBDF3F5BEEE148
                                                                                                            SHA-256:7A22A638C6A751B85D112D9A1E929E7FDC2658856A4FE08B9F1DE2019757717F
                                                                                                            SHA-512:487244ED650E0039B3425F6C1E56F59694503BD418A3D0C2A8F57464AE06F7CC06AC917DD92C00D032EE330D8A49909BD5E8B269A8D93D4094B27BB92C2EB9BD
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....~o..........."!..0.............N*... ........@.. ....................................`..................................)..X....@.................. )...`.......(..T............................................ ............... ..H............text...T.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................0*......H........ ..(...................P ......................................Q+....+....N[.z....u^....G.D.^.Y...w.1..Hoe....+f.?V~........4.AU3...._4..T...K...4^s...n.......u.t...H./S...u%.g..|'...jBSJB............v4.0.30319......`.......#~..`... ...#Strings............#GUID...........#Blob......................3......................................P.........7...........P...........{.....6...................................p.......................W.....d...................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15640
                                                                                                            Entropy (8bit):6.779164699458774
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:VRF6PxAdql7SNMWbCWvY7WxNzx95jmHnhWgN7agWLgj3LwKUWX01k9z3Ad7vvp:TF65oqRSNMWbCWvYUX6HRN7KgM2R9zGN
                                                                                                            MD5:38366E6D059554EFAAB623EF614C3357
                                                                                                            SHA1:DB0D245CC6F0442B2851EFCA589F84AF1111E07C
                                                                                                            SHA-256:8AD0AB3216F296F993EB9FB0D911B202E0D3B435A63D35E3133B191DBCBDC8C9
                                                                                                            SHA-512:12CFA64DF5B3D7D407AC1B3DFF2AB0E1ED22C38505B6A7FE51741B3E8692E416ACCE744AD4600CFE0BE2522FF5011C4EE656C9200D6DBC267D48217F6E4FD8D7
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L..............." ..0.............")... ...@....... ..............................!.....`..................................(..O....@...................)...`.......'..T............................................ ............... ..H............text...(.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H.......P ......................`'......................................BSJB............v4.0.30319......l.......#~......d...#Strings....|.......#US.........#GUID...........#Blob......................3..................................................3...x.3...3. ...S.....^.................I....._.................w.................G...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):84128
                                                                                                            Entropy (8bit):5.965475930237355
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:rRgoICPT0eXImrmODZcUBeZ8j0qEHawde3qGRm3LGgmi5zS:rRgo9PpYFtZ8j0qEHawdezRYGgmGW
                                                                                                            MD5:2552D8702CCE0128057F347BF760AD72
                                                                                                            SHA1:F32D9D8051C0820CF92D6D326D7CD65226850A75
                                                                                                            SHA-256:5F4184FD0607DCB2E3006118B618AAC3417B9C52E51C6D58C9C396A1F6AF9720
                                                                                                            SHA-512:F25554ECCED6E7FF8FA370C8A2D526A204BA7139AA944E4B42F010F30A199DD7C0D434A187DB9CD97CCFB054B9810E059BD3A50C5E0C2B40594C741F289B2DFD
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." ......... ............................................... .......@....`...@......@............... ..................................`....'....... ...(......T...`...p...........................................................`...H............text............................... ..`.data...............................@....reloc..T...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):661664
                                                                                                            Entropy (8bit):6.673728367333183
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:4J5UP48Vd00bmWIQf2VQIhS3dzGpepguWC4bVUl6lJlD2EL66zP0ARZ9dn3/sx1w:5PJddbmWnf2VQ9bgnzVTFD2S6isx91o3
                                                                                                            MD5:537F45E761B7BF2593E86778B1AAC461
                                                                                                            SHA1:36F5AF91AC751FF1DDAC5297E0835388335706C0
                                                                                                            SHA-256:A5E3E04CA99F4B82C761370508EBE6E1DC7FE6B9463E904BA408AFDBC16D5272
                                                                                                            SHA-512:32D9A9C892422CACC9A7554719076DAD65AF3B31C8402247804CC5B66216ACBBE8D773AEB540DC98421E43659BE284E41F60DEEDBF4FE0928302A0CB4997AF49
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...g............" .....@..........................................................S.....`...@......@............... ......................................`...hI.......(...........4..p...............................................................H............text....5.......@.................. ..`.data.......P.......P..............@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16656
                                                                                                            Entropy (8bit):6.71053707165234
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:jmw3RJOW0iWvJYA6VFHRN7pORxB+R9z0LLZ:jn3RSDJFClpORxw9zC
                                                                                                            MD5:08BFE95432A413747BB05DB5AFE50AE7
                                                                                                            SHA1:1D937A7A2B29061B0A52AC4B659ADDFBB4DC2030
                                                                                                            SHA-256:8FF2322E5F56AE15E026EE299C3E437EF9FB581AB50C688E2870C9DC55C90411
                                                                                                            SHA-512:6784366CA92DCF063898E43B48538909FFD9DD5F4F8A70DAD7007A21BCC50B24899849439E33AE01DBE81C7AC3F2E48A69B499B116918F3F8AACD238994D005C
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....:............" ..0..............-... ...@....... ...............................7....`..................................-..O....@..t................)...`.......,..T............................................ ............... ..H............text........ ...................... ..`.rsrc...t....@......................@..@.reloc.......`......................@..B.................-......H.......P ......................<,......................................BSJB............v4.0.30319......l.......#~..........#Strings............#US.........#GUID...........#Blob......................3................................$.....3.........0...........D...........o.....*.1.....1.....K.....1...i.1.....1.....1.....1...P.1...X.1.................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........C.....L.....k...#.t...+.....+.....3.....;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15520
                                                                                                            Entropy (8bit):6.796904916610158
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:P/hssWCGWveYA6VFHRN78ZpIyqDX+iR9zwf:PZ/neFCl8PkDuO9zC
                                                                                                            MD5:A3E2E4ED94A51EDB3C95A3E50B448D0E
                                                                                                            SHA1:CE3C27BD57BDEE41D509C1E7C4BD15EB9EEDE7C2
                                                                                                            SHA-256:ACC824E034064DEE4A74C3F2C1CAB36C1FFB07773405168AA5FD1EA5026CEFDC
                                                                                                            SHA-512:554727273BBAF9B740653223560E851451CAC889F013D42F23F4D7321D31BC86F231A08DCCB715B081FB0F2908E95D037399CF5CF8A4A2FE7F3AD493083FD519
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....J..........." ..0..............)... ...@....... ....................................`..................................)..O....@..d................(...`.......(..T............................................ ............... ..H............text........ ...................... ..`.rsrc...d....@......................@..@.reloc.......`......................@..B.................)......H.......P ......................D(......................................BSJB............v4.0.30319......l...,...#~..........#Strings....d.......#US.h.......#GUID...x...|...#Blob......................3......................................E.......................z...........+.....b...Q.b.....[.....b.....b...4.b.....b.....b.....b.....b.....i...........t.....t.....t...).t...1.t...9.t...A.t...I.t...Q.t...Y.t...a.t...i.t...q.t...y.t.......................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):59672
                                                                                                            Entropy (8bit):5.885523824307154
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:rn/dGA98odbfSYCDVgHvwkcm7WwvCwmEWGzR:rnrq7KHoTeWSNtF
                                                                                                            MD5:EB5B2FB46C0F5AB93ECA0C5DB054FFE0
                                                                                                            SHA1:E1AA25DDD2C359FB08B260180B8AE3A651953A33
                                                                                                            SHA-256:77B8748C3ECDA6E06BFFAFE34F14840185E2AE2FB3ABE3A4F6B577323C23EE62
                                                                                                            SHA-512:EB9128389C0C3F36D832118EF706761A08D9AE33789AFE190023B3170D2ED11C7E8EC704D45544B775AC94F46CC673C09D582AC6927E8445747851D747DC9875
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................" ......... ............................................................`...@......@............... ......................................< ...........)..........H...p...............................................................H............text............................... ..`.data...............................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15632
                                                                                                            Entropy (8bit):6.740344128283329
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:6GqxAsOUWoo9WvDpWjA6Kr4PFHnhWgN7agWH4/KfKUSIX01k9z3AGoi7GtK:4LhWoo9WvDYA6VFHRN744o2IR9zXR7GY
                                                                                                            MD5:EFACD5C037B280E814A636B399BA51F2
                                                                                                            SHA1:FF434841129277A5F37E4D9F2B373D17376A9F62
                                                                                                            SHA-256:7F2AEBB25BBC9B473D639AD55BA2470EBC50A805C89BDB7FF3CE47A92DF1FFDE
                                                                                                            SHA-512:E161A026358E520A2494C05676DD9C658184388A33EA12F0441C34B7F7D6D75F18D814B24132381B6D4C9199BB916C9F06C33E919D2F8750EC19399891025A38
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..............(... ...@....... ..............................m.....`..................................(..O....@..4................)...`.......'..T............................................ ............... ..H............text........ ...................... ..`.rsrc...4....@......................@..@.reloc.......`......................@..B.................(......H.......P ......................D'......................................BSJB............v4.0.30319......l.......#~.. ...D...#Strings....d.......#US.h.......#GUID...x...|...#Blob......................3............................................................>...........i.....$...........T.....j.....9....................... .....R...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.C...+.Y...3.o...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1452192
                                                                                                            Entropy (8bit):6.692930879882557
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:24576:s9tKjFlRYS616HJ6cC/X3pqNRPP0AjFAdgGPD6+a0Yre:PlyS616HJ6c+ZQntKnaE
                                                                                                            MD5:E54F1341C9288EFFE1A21BCC372CFC68
                                                                                                            SHA1:AB8DC7991A47FD33051CB7D403DFDE31BCF6493D
                                                                                                            SHA-256:1236B218A205E8114EA578F8A3F19023A1A8FA2D01BA96E89F4182D84F41FB68
                                                                                                            SHA-512:7B33899C861ECB8C2A8D68081B31AD811C2E41D525ABC9967E64639E2CCD3C000E24D6F4377C8B295352FAA33637B3263D6D1D7F484A9BC48742E56DD2899B2C
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................" .........@.......................................................m....`...@......@............... ......................................LW...........(..........HS..T...............................................................H............text............................... ..`.data............ ..................@....reloc........... ..................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):116912
                                                                                                            Entropy (8bit):6.0097243228568145
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:b1krGkVsbV41aq4I/tT8AP43x/oLsTac3L5rgYYq+X7aVFvTbTTqZlWCzb:bcix4gq4IJ8AegLs+G55Yfaj6Zl9n
                                                                                                            MD5:515E56514CF3D123E4C6AD33E15CA2F6
                                                                                                            SHA1:8FC1C94371ADA70930EEBB7C7360D40DECCC4A8F
                                                                                                            SHA-256:A8DA3B8B3AC71775E27777652AF247AEC30F4D275D6E85F1490462EA042056C1
                                                                                                            SHA-512:7F2D7B69935D9D78F1924AEBBA46F9FD8089E34D71FB0691E9E88635365A0EF2F5376064328DD39290BBF02E3552238E2EC39C4D2FF180A5C8BA3EC801EF6A86
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .....`...0......................................................'.....`...@......@............... .......................................+...........(..............p...............................................................H............text....^.......`.................. ..`.data........p... ...p..............@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16664
                                                                                                            Entropy (8bit):6.680561869198979
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:28zn7Dxl7W7BWHW1WxNzx95jmHnhWgN7acWHPRlGfAgfcMbnoQNpX01k9z3AfjMM:vzn7dl7W7BW2WX6HRN7K6/7R9zgMqdd9
                                                                                                            MD5:8E8686D4BBD1BA7229E2E54A3B8CAC1B
                                                                                                            SHA1:9CB6BCC1C3F98E11A8F9F4BE5AE4F94245DA548E
                                                                                                            SHA-256:98B57636E6D5BA40C425E85B78C531A860694E7DE6488CD661044FA91170C8A1
                                                                                                            SHA-512:D6BC42F3869C748DE35383A5E55CD5B3B451975518D80B4E0910068B50E1F24C572F6A4A435CC18B28099A70219A31D12B728D87049472D4851EDE79CA529C63
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....c0..........." ..0.............n,... ...@....... ....................................`..................................,..O....@...................)...`......T+..8............................................ ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................M,......H.......P .......................*......................................BSJB............v4.0.30319......l... ...#~......p...#Strings............#US.........#GUID.......t...#Blob......................3................................................S...........s.........................~.....~.....~...6.~.....~.....~...s.~.....~...7.~...Q...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y...............................#.....+.>...3.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):5564592
                                                                                                            Entropy (8bit):5.9838147426391055
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:49152:eFXznRh41kiAVUkJawXhoIPgkLQ4jhXlNXKU/kg48YD9YCT2JZelq:cznE1kjJaw1xxkWbz
                                                                                                            MD5:95648A2FA7627D161B9D1FDD1D0459F5
                                                                                                            SHA1:444C386A91A4EE72AE4253C18BF910004AA4F5FC
                                                                                                            SHA-256:F9AE092A343964DBE400BA59D7C7AAC6B17BD027B92E196C11B71EC3C7434BCF
                                                                                                            SHA-512:9617D46F4A7EA6DBB19CB35257DEEE93C4E0461BE7A274547A3B18AFFD9657E5D6EB2F70EDEB101682896231E81DFCE8DF057EC143302E8F5860AB74BF47B5F7
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....g............" ......Q.. ................................................T......nU...`...@......@............... ......................................$...t0....T..(....T..>..p...p...............................................................H............text...%.Q.......Q................. ..`.data.........Q.......Q.............@....reloc...>....T..@....T.............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):3012784
                                                                                                            Entropy (8bit):6.435982980274157
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:24576:P/T7ddSgSigMFn5Q20T9/vysyyLnCXwh0KFDe9z/9GCCH/PLvlvKJdnFLvwLIlc1:yligmnsWyLnGCH/PLvlvKJh7SRR
                                                                                                            MD5:08880F1B35619BC6C3EBF07B0DD4B696
                                                                                                            SHA1:9E29833B7A533D5C4186EB3D3878561D8A3769B6
                                                                                                            SHA-256:4889CD8D7ACBEF74600B80D2261C51CADF08A6B268166CEF0CBF8066FF6CF71A
                                                                                                            SHA-512:0702F63E2196B5E3CA7AF5B1A8CACCD70E39854B435194053FA3F1D2150EF70B5AAD4B77093DE11FCEB66DBBD801CA1E78DD74784528160EFBBAAAFC7DF53C6D
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................" .....@,...................................................-.....j.....`...@......@............... ......................................@...T;....-..(....-.,......p...............................................................H............text...U9,......@,................. ..`.data....^...P,..`...P,.............@....reloc..,.....-.. ....-.............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):13564064
                                                                                                            Entropy (8bit):6.473811993244613
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:98304:1EOVu5/pZoar/RZhFM3fxqbyRitP7AXfDPWkOSiQM/:1EOVUvRZhy32EitP7AXfDnOSB4
                                                                                                            MD5:CEB0075D090BC07B793D886B0F47D596
                                                                                                            SHA1:A18E0A3E872B6BF9B392A933136A219AE27C77B8
                                                                                                            SHA-256:215C333D7279D35CF60197EA4DAE1DA9FDD125404EF5A3BC9478D27EF237A8B3
                                                                                                            SHA-512:5CE4628D87203A27F6D4C3CB74C5C4CF94876415B4E33F0F1C3EC04E2885520A27BA3CB6ECC7921A8CCE115DA186EFA378712ABED071E72991EA214AECB5A647
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .....`...`............................................................`...@......@............... .......................................P...........(...@..p....^..p...............................................................H............text...kP.......`.................. ..`.data...N....p.......p..............@....reloc..p....@.......@..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):137376
                                                                                                            Entropy (8bit):6.275208849412791
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:vfoPuayYTnyCWulExt5qLkKkuWH/6V+937:30uanTFWumWkRuWf6o9r
                                                                                                            MD5:D631DB8DBEE0555534672D63369D484B
                                                                                                            SHA1:57CE3A34BFB747D53033BB1FD6923D093FCFBB6E
                                                                                                            SHA-256:9819A338F2CC06AFF2C1172DDFC98D942EF86435DF4ED4109E893B61AEB4EBF9
                                                                                                            SHA-512:8E4DEF62C695F856FC96CE8BBD25451A2696740F3455C8DE41B2E66F41F6174863281F888E29C387E2CF3BF23230A53C2C0DECA72BA52472E970BBFD6C84ABC5
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.... ............" .........0.......................................................~....`...@......@............... ......................................d3...........(..............T...............................................................H............text...}........................... ..`.data............ ..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):30880
                                                                                                            Entropy (8bit):4.7224621314296105
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:9WIhhNwZVjB6ZDDrRvYA6VFHRN7v2/6fR9zjOih:ZhkCDDrxFCll9zjP
                                                                                                            MD5:467E4E772261148FCEFD8620401BD521
                                                                                                            SHA1:AA888D911A45CDCEC352E44776CE3E328D39CE51
                                                                                                            SHA-256:038FF7CF6B72F7F861F75346C6108939F21C792FB689712F7BC7FD42AAE248AC
                                                                                                            SHA-512:18D895E02C5D56031F3406815A8A7D7FBAADBF1752DF3F73741BA04B5472A54CF021AC3ECF4FCB1C6BBD6BCC0B4998BEF67EE2BDEBC8A41A400FC0BAAA8B1A7A
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...-............." ..... ... ...............................................P...........`...@......@............... ......................................d...l....P...(...@..(...H...T...............................................................H............text............ .................. ..`.data...J....0.......0..............@....reloc..(....@.......@..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16136
                                                                                                            Entropy (8bit):6.7201571212077225
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:XUnaHtGxAeWyixDWDSWvmpWjA6Kr4PFHnhWgN7acWPoAgfcMbnoQNpX01k9z3AZ+:eaHtsviRWDSWvmYA6VFHRN7uo/7R9z5z
                                                                                                            MD5:F038E35B176485760C5D92877E33EE0C
                                                                                                            SHA1:62974D42DFC93E87ABAA78EFC0E13F73667C380D
                                                                                                            SHA-256:15E3C48D3C693F7182221BF369A528B33C99EE00C2E3840ED35F600FECDAB77D
                                                                                                            SHA-512:2AC72E17F2ED3120130383FD1FEDF34329E53D19F5CA922796B7DD9561DCBF1E4246DE481677E51884C785215A684A4EAD29066504DA35EBC6B810DD3AF6F446
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...%.h..........." ..0..............*... ...@....... ....................................`.................................M*..O....@..T................)...`......p)..T............................................ ............... ..H............text........ ...................... ..`.rsrc...T....@......................@..@.reloc.......`......................@..B.................*......H.......P .......................(......................................BSJB............v4.0.30319......l...$...#~..........#Strings............#US.........#GUID...(...x...#Blob......................3......................................X.........U.............................y.....7.......k.................................u............. ...........................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1419424
                                                                                                            Entropy (8bit):6.68633763415658
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:24576:9V+eIoWov6n9R1CNbtBh+I6hMqa1GIrsCbQt8dq1ZZo:vNWov6n9R1C9tBMW4QQ1A
                                                                                                            MD5:87605F39616FA8F05F32EA9087681CBE
                                                                                                            SHA1:1B971B72C32B1CB2D0C3E1C9000B7BF14F5B0122
                                                                                                            SHA-256:6EFE4C56C90455A4A5DCD11DE881DDDFBFCF343D523EDFEE30BC318B4622EBC3
                                                                                                            SHA-512:DB7071F23469D0B69197C69DC2258F221EC966E5FFD92767031CC095296EE0B1ABFC024738C47AC11C30E2146DEF634B267355518D1F1D979B7BA7E6CF39DD49
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....V............" .................................................................T....`...@......@............... ...................................................(...`......p`..T........................................................... ...H............text............................... ..`.data....^.......`..................@....reloc.......`... ...`..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.684545508308997
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:+t1KdJWg4WvvQYA6VFHRN7N3GtHNsAR9zF0T:+tMdtJIFClNEts89zmT
                                                                                                            MD5:AAD69625CA4EA9ED2176D8E11DB56E2C
                                                                                                            SHA1:3F3D9E94B07D40135DFB0A294002BA00BF866E6B
                                                                                                            SHA-256:97C5A3EA6CC5086323EACE63B8DA07DA484055CEDA72856B98BDD507A6080B02
                                                                                                            SHA-512:7C7614D77604B4E94E1C7AF45F0642DB8C8553D8AB2ECCD166EA4BADCB23802D191B59466E3C1F3DBC29B1CAEFFB2C666BDD1C9082613CFBB8FCFEE70D1FCF24
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0.............>+... ...@....... ....................................`..................................*..O....@..T................(...`.......*..T............................................ ............... ..H............text...D.... ...................... ..`.rsrc...T....@......................@..@.reloc.......`......................@..B.................+......H.......P ..<....................)......................................BSJB............v4.0.30319......l...$...#~..........#Strings....@.......#US.D.......#GUID...T.......#Blob......................3................................................L.............................p.@.....@.....,.....@.....@.....@.....@.....@...l.@.....@.................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........:.....C.....b...#.k...+.....+.....3.....;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):22296
                                                                                                            Entropy (8bit):6.376173260415304
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:IT1G5qkxK67ex4FCh0eWYAWvlvX6HRN7aEw4R9zE8J:IJ6LS0YhBWajk9zJ
                                                                                                            MD5:E08002B259471A203FB54A3142617115
                                                                                                            SHA1:FB0EDC0F656F850EC49740479C78251A8FEEF35C
                                                                                                            SHA-256:1A10820BEED89FE0A72D2D6A9E849001590B35625006EF53F67EC4981964B231
                                                                                                            SHA-512:ACF5C0A39460A24F0687D84BE6B435B1E57BB90D77A13DA712CEAAE4B8409960FF21509F3E857D489ABD6827D8FAA635EDB4FEDF4141C7BFB858AAB4EC6D4C1E
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................."!..0..$...........B... ........@.. ....................................`.................................wB..T....`...................)...........A..T............................................ ............... ..H............text...."... ...$.................. ..`.rsrc........`.......&..............@..@.reloc...............,..............@..B.................B......H........ ... ..................P .........................................Tz...7c...a....l..iDj<U.....s..k....T_.83..AAY...R.S.I~!...q.|.....".,..m...0.=..#...Kk+M.g...q.....jkM..M.....$.mIBSJB............v4.0.30319......`...|...#~......8...#Strings............#GUID...$.......#Blob......................3............................................................G..... .......b...-.....f.......i.......................................[...............................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16544
                                                                                                            Entropy (8bit):6.621378907680227
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:s0WLW7yEqHWvWYA6VFHRN7i3tHNsAR9zF0RGRv:s0WkyEqGWFClkts89zmRGRv
                                                                                                            MD5:065469DFC7A55B2575D432CC2EB20B75
                                                                                                            SHA1:26C4271164F9A0D5F02C6EB79BF1A95E77D715F6
                                                                                                            SHA-256:54C25CDE74F7FA7C164E5E8C90BBBDB1A4F84ECD4B3C6F542560A6CC8BC55E4D
                                                                                                            SHA-512:BCAAA07A1DEC59A5B64D2034D30741EED9C00159EF4AE42C79896709C65B5982053074BC7621B818523B608B663845C853790B3AD6A484109696CF4690533685
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0.............N,... ...@....... ....................................`..................................+..O....@...................(...`.......+..T............................................ ............... ..H............text...T.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................-,......H.......P ..8....................*......................................BSJB............v4.0.30319......l...4...#~..........#Strings....4.......#US.8.......#GUID...H.......#Blob......................3......................................".....................X.................*._....._...B.?....._...'._...Y._....._...3._....._...l._.................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........:.....C.....b...#.k...+.....+.....3.....;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.760114531130961
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:KLIiUA/xzgWddWvBpWjA6Kr4PFHnhWgN7akWMgtUtxu3O6YX01k9z3AnQQO:KLjJ8WddWvBYA6VFHRN71JR9zKQQO
                                                                                                            MD5:F5C6679493D864440EE6A19B508D21C4
                                                                                                            SHA1:8D34E56F84ED52F3AEAC4E074505D2BCED16A189
                                                                                                            SHA-256:52FD1A9D7666DB207E9F447A2F0C530C43539370633F1A8DA4CB930B9F62B420
                                                                                                            SHA-512:5082DC05D0B99449F2B5231614FA988A990313DEE7F96A49600C2CBBAE50EA1AF453C77EA018156413849541129836AFBCDDD1D6053D94A00C3D2D51FCCD3419
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................."!..0..............+... ........@.. ...............................n....`.................................m+..N....@...................(...`.......*..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................+......H........ ......................P .......................................&.H.....y.V!.. hs..p/M$..HQ.....Y.<.k/.q.&.9.....m.R...f.BgH.WL....c...:7..N#..[...5cxJ.t@.?...Z>e........~x.......`6).BSJB............v4.0.30319......`.......#~..d.......#Strings............#GUID...$.......#Blob......................3................................................L.............................p.L.....L.....8.....L.....L.....L.....L.....L...l.L.....L.............................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):30896
                                                                                                            Entropy (8bit):4.273248077657323
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:JWHeWv4UpNUVBZu4xVXY7mWWxNzx95jmHnhWgN7agWGKIjwX01k9z3ABC/XO+R:JWHeWv4UpNJWC7AX6HRN7uHR9z0C/XOO
                                                                                                            MD5:77D0B6E9DB4FE2D47149541ABB658C2C
                                                                                                            SHA1:2D9349D25164FE01369B12FBBE392E5602F4FE5A
                                                                                                            SHA-256:E8F7DE93A7F5F6AD2A909B4B849C594EB872498D1F491DCF2EEBFC740EDE56A0
                                                                                                            SHA-512:47DE7B112EAE0F6AF383CBAC202DBF1417A3EDD6C3C0EAFC136E99E871AC819D5DC0D5507CE570F371B41D8B6E651960B09BF36E230F056982922CF16D3E0244
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....."..........." ..... ... ...............................................P......b.....`...@......@............... ...............................................P...(...@......h...p...............................................................H............text...3........ .................. ..`.data.../....0.......0..............@....reloc.......@.......@..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.7207100865383165
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:cCA6iA+GWZvWvZYA6VFHRN7zr49R9zriC:qs+R+ZFClzr69zZ
                                                                                                            MD5:F0366F13E8A05F94B99A8CF97734C0CC
                                                                                                            SHA1:9AFFFAF9AA03E4B982662A951C6704DBDD4D82D2
                                                                                                            SHA-256:468A023FAE4823A00132B0D91EF77CD783A474B8AB16441AB5C879CB022397F4
                                                                                                            SHA-512:AA4D08B1101F0F2D54E5C48199671674B2AFBF7A1B7F8E22752984CAA684931E1BA5D361EFE3585A1E66F7625ABB22F63415B9F69F9DC6EF4B7E697DE459B688
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...C.t..........."!..0..............*... ........@.. ....................................`..................................*..N....@..d................(...`.......)..T............................................ ............... ..H............text........ ...................... ..`.rsrc...d....@......................@..@.reloc.......`......................@..B.................*......H........ ......................P .......................................8.e+...&.......x.zX{.0{.O.<...c.d.p....p......H..XT-~.c_N.;....3B....I.........Mc...W.P....h..3...z.qo.*J..=...).E..fBSJB............v4.0.30319......`.......#~......\...#Strings....P.......#GUID...`.......#Blob......................3......................................'.........C.............................g.{...%.{.....d.....{...|.{.....{.....{.....{...c.{.....{.............................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16136
                                                                                                            Entropy (8bit):6.763250939574308
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:DYlxlKxAdKXZ14WAsnPUWvTbpWjA6Kr4PFHnhWgN7agW6kxwVIX01k9z3A7OMsNo:ITQocZiWrsWvTbYA6VFHRN7UR9zEOMio
                                                                                                            MD5:B8C780077D3BE36CC8F8A85C5B056393
                                                                                                            SHA1:E269FE3AE47536E5583749987D15867680091BEC
                                                                                                            SHA-256:6CA75DE642BFB7D7E4654161EE0A7FFAAC4775406073D5BD6588D8FBA9CE937F
                                                                                                            SHA-512:6565880E5E6CCAD9FE6A2B3787FBE92F51306BB13D6A91389C4616D58B1EE2B8CFAF89CB748836C6BD8F0B09D8208BFF4CAB6D7B01A9A805E46E573647AC0159
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..............+... ...@....... ..............................Uc....`.................................A+..O....@...................)...`......T*..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................u+......H.......P .......................)......................................BSJB............v4.0.30319......l.......#~..8.......#Strings............#US.........#GUID...........#Blob......................3................................................P.................<...........g.~...2.~.....1.....~.....~.....~.....~.....~...p.~.....~.................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):18192
                                                                                                            Entropy (8bit):6.625640713703575
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:bvu3anBNTYxDHn+WBvWvdpWjA6Kr4PFHnhWgN7agWv6KDUX01k9z3AWipVl:Lu3af2L+WBvWvdYA6VFHRN7m6pR9zvwl
                                                                                                            MD5:BB348D3A59DB204B4F6357758D950D7B
                                                                                                            SHA1:401FE3743A40BD85F06C5074454080E7F6895540
                                                                                                            SHA-256:EF29DFAAEBC33486376625E22BDBC96597785E99859A96E7DFDDAD0211AB6643
                                                                                                            SHA-512:ED8611B8EA3F164DAD3FD6A98337AA9076AC6EE9D00606C59DFB5AF19E7EC799E35FF580A1BF8FB74E23376D8780B068E030753BD6B56CFE17F438DCB6BD43AA
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....K..........."!..0.............N3... ........@.. ...............................&....`..................................2..V....@...................)...`.......2..T............................................ ............... ..H............text...T.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................03......H........ ..0...................P ......................................I.(b...R.c.l....i.$%'...3.q.*...\..N..J..y..Bc.K.....r........8...D...A...%.y.Nq.....rym..Q$...G.C.W..Kx...\..&.T....p.9BSJB............v4.0.30319......`.......#~.. ...p...#Strings............#GUID...........#Blob......................3................................J.................................+.....F.....H.....N...............................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):23712
                                                                                                            Entropy (8bit):6.267200741035943
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:c58Ieq5ufyw8bcB8yGn70WzjsWvyYA6VFHRN7x6R9zdS:c58IeWv39yFClx29zA
                                                                                                            MD5:4512B147B8F78C18047A105F2BB1A429
                                                                                                            SHA1:C0BCB9C44F2DED879855E86FBC1CA9F755DEE78D
                                                                                                            SHA-256:4A23D5325BA071AB2AE359F524062C6CAE2454A75DDAAB206022CE877E3AA13B
                                                                                                            SHA-512:72ADAB86F3457653380BBA8775D4477A5DA20AB08BF55897EB6F53CF27D2CABBBDCA259DCE23E0080C3CA9DE6C8A29BF00689D6B9B58A317616E1A73BB8D9CB6
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....Q..........." ..0..*...........I... ...`....... ...............................y....`..................................H..O....`..4............4...(...........H..T............................................ ............... ..H............text...4)... ...*.................. ..`.rsrc...4....`.......,..............@..@.reloc...............2..............@..B.................I......H.......P ..4'...................G......................................BSJB............v4.0.30319......l...x...#~......X...#Strings....<%......#US.@%......#GUID...P%......#Blob......................3..................................................................S.....:.y...<.....O...................................................................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........:.....C.....b...#.k...+.....+.....3.....;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):50336
                                                                                                            Entropy (8bit):5.748159627893803
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:768:+RlKhT46UA2Zi5wRNH5JVb0U502zq1TntuaaNFCl+69zsc:Ku6Zi5i5jzCkaaiRzsc
                                                                                                            MD5:C251E9C5E68F8234ECEE5A332FA890EB
                                                                                                            SHA1:D0FB802214E6641387B55270089300ADF52C9A48
                                                                                                            SHA-256:36E9F61DA6BF4B6AEF5073DD639BB6174397A53573E3B0EE754AC5A997268070
                                                                                                            SHA-512:289805F4BA063A5BE984810F7504E85B3F33659492EB3509CFEB314C7AE4D8EE8E207DBCA4F354D17F3D2A359E5B83D881F6E6A3380FA9C49701FEA7AA4B0352
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...b............." ..0................. ........... ...............................w....`.....................................O........................(..............T............................................ ............... ..H............text....... ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H.......P .....................4.......................................BSJB............v4.0.30319......l....:..#~..d;..dR..#Strings...........#US........#GUID..........#Blob......................3............................-......................=..\..=.....=...=............; ..2.; ..T.M.....m=....m=....; ..9.; ....; ....; ....; .. .; ..P.; ................};....};....};..).};..1.};..9.};..A.};..Q.}; .Y.};..a.};..i.};..q.};..y.};....};....};......[.....d.........#.....+.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):415904
                                                                                                            Entropy (8bit):6.537421933056359
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:KqsPcEZnG2usAMctT0i6KTHIJZamhPrwgE08sr1VEZRE95p1wSHovYvZK51/0y7P:KqgE2uZztIi3ywgt8NOBHovicP
                                                                                                            MD5:BA75D597D43C856BDC6D4A2707EE58B5
                                                                                                            SHA1:489F2F6836332BCD15EADE770C7E46131F074DB4
                                                                                                            SHA-256:90F73C2DECCD7139D9948C8F5D5B874A2D5DC9FA43D36A4190F6F60ADE792433
                                                                                                            SHA-512:60BAC2F126A72A389A891E318D476353AC40E1542E0C5F4997DC4B9EE1E0790CAEA0B6882BA95079DCE2E907E42E18BC39F28E32361938F120ADD3DC4664EF6A
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....)............" .........p...............................................0......PX....`...@......@............... ..................................\.......,...0...(... ......`(..T...........................................................`...H............text...g........................... ..`.data....\.......`..................@....reloc....... ....... ..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):870560
                                                                                                            Entropy (8bit):6.698604415601525
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:e0nJfitube+UKtRjkFIRVYZvOQ0109+mkXE/dPZWfl+U:nRUWFkOU+HE/xZKsU
                                                                                                            MD5:9C5ABEE2F1E122E307DDBA43D2BC1574
                                                                                                            SHA1:C21842857E4452DD6C67E4B72F8CD417486C239C
                                                                                                            SHA-256:CA6E09B43631E90070E141714BDCC3124FD9301BE14C9C663C04EF92A0A951CD
                                                                                                            SHA-512:0E26B9C4BFDBCA6916B43C064D188547673DBB7A121A4B2BC05C672F5A3EB5223344352D8C5F844511DAF6EF85F2BFDD3A1E1422B11482CE591CDFD686BD6FDA
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....W..........." .....`................................................... ............`...@......@............... ...................................... ...@b... ...(......P....>..T...............................................................H............text....[.......`.................. ..`.data...e....p.......p..............@....reloc..P...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):59552
                                                                                                            Entropy (8bit):5.257260939720961
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:NWpN/Po1PdD8nvXct+B62EOI57wDhtaMaycXJe5LxmI2liZWZPQIjDZBv0gAxSXl:YBQ1VPuCwDh24xFrDYYcFClz9zgv
                                                                                                            MD5:DE79B443EEBCE1B83464224287780FC3
                                                                                                            SHA1:B16F794A7C87C766840B1D42E2E079F957A93312
                                                                                                            SHA-256:DA253533149EE5152D36CD4C20AE4FBAB8A2AB2D3D93067A9765BDA230088165
                                                                                                            SHA-512:76A4C90F50CD86534A481501C1AD774D40EC1A963387CA79DE20FC747D61578890DEF6EAC12519CC5ADD1CBCFA8B842B301A1EF21177B3EB491B9D7EE1D5A812
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....]..........." ......... .......................................................;....`...@......@............... ..................................l.......\........(......|.......T...........................................................p...H............text...k........................... ..`.data...n...........................@....reloc..|...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):313520
                                                                                                            Entropy (8bit):6.026328145716465
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:Lwz2fFD31yI6tnfKKEjXowPpcpys8+Lehz2rlp:UCfFD4IeWxy0mLekp
                                                                                                            MD5:8978AC101696167F58CC1692BBE8B66B
                                                                                                            SHA1:C5ECD066C1527D2309CF79E42B984F8B9E358DC2
                                                                                                            SHA-256:15F86E2E660BAB9293C737BDED22A5F0A49776B48371E76DFA57C89850E72768
                                                                                                            SHA-512:60620A67348C33B1D7A1456B8041484DD51D2AA1AE5A4DC9A384E5F3016BA574AE2C7F0E7D366DA25DBE24BCF832ACA50E2A9F029E5BA05F951F90C8EAD4BA63
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .....P...@......................................................>.....`...@......@............... ..................................L...(;...........(..........(...T...........................................................P...H............text...`F.......P.................. ..`.data....'...`...0...`..............@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):2255024
                                                                                                            Entropy (8bit):6.594152174912454
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:49152:BSSZ/3BjajYVeLQo2P6AjRIOuoU82S1VGG2hFGYYB45gkQdh:YSlR6A6oU82S1VGG2hFGYmh
                                                                                                            MD5:3A905AF6B4A0C8431E438B35E8E0AFAC
                                                                                                            SHA1:7F33226B0501ABBB4A8E685F752A172F4A486987
                                                                                                            SHA-256:56799A464AB74E86F00104D3CB39DDEB6FCA2E9DA8CF063B660CE67C47A2979A
                                                                                                            SHA-512:AE69AB68318DD3F4931F657A95231E8BEC5D6EFF007A29C17A1FE22448E1F5A5D06B0C5FE76E614AA5EE71CB546C74451904911FD8C415DA5C360FF1AAE8F2A1
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...j............." .....@ ..................................................@"......."...`...@......@............... ......................................tj..<....@"..(...."..%......T........................................................... ...H............text....7 ......@ ................. ..`.data........P ......P .............@....reloc...%...."..0....".............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):211120
                                                                                                            Entropy (8bit):6.371401919540868
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:JVj+vjFiZoYqqcgVPCmU82iYwBpIUG2pQBd5eVJm495kCl5qf0B9iKCDQc1MSmsH:/pnjPU8AKpG2xkby51lc3n
                                                                                                            MD5:0F11173A55103D5AC405DD5E8083E6DF
                                                                                                            SHA1:F41120F21511CBA636DC8CE428306B3321FFA5F0
                                                                                                            SHA-256:85F28B33B26119D03AAEDCB55A62972832DCA2E4010DFCBD38DBB78FF40CB5A5
                                                                                                            SHA-512:BB45C4EB036D79A9210558CB842C7DB5D532AF8FF7FE89EDF415688FFF50C0D65984FE78F8D8886C2FEC6B1CF17DB38EC81843B32CBAFABB93B5DCA17AA990A9
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....f............" .........`......................................................f ....`...@......@............... ..................................|....J..x........(......L.......T...............................................................H............text............................... ..`.data....O.......P..................@....reloc..L...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):311056
                                                                                                            Entropy (8bit):4.240184363331846
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:SE9XK6chFa5y9sh33X+QIa7rGgtfqYZdLqt:xq0FfqYZdLk
                                                                                                            MD5:433E16EF5493F3056333B527F1E2DD60
                                                                                                            SHA1:FE62C578F0186E2184EC45F2DAD74BB541949B07
                                                                                                            SHA-256:C78605F3D54C17048715442A67E02C104EDF16BA63845E76E5C58EA39F3EAB5D
                                                                                                            SHA-512:1D6D372A802A99383BDBA8788E96417D60CA19F072CB471BF36622190F44A34260C3F0F823C378091474FBA3082EB062D9560AE30A62966AB2B4925B51111262
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......%%=.aDS.aDS.aDS.q...`DS.q.Q.`DS.RichaDS.PE..d......f.........." ...(.............................................................R....`.......................................................... ...................)..............T............................................................................rdata..X...........................@..@.rsrc........ ......................@..@.......f........l...l...l..........f...........................f........l...................................RSDS.".7(.BH...w".......D:\a\_work\1\s\artifacts\obj\coreclr\windows.x64.Release\dlls\clretwrc\clretwrc.pdb.............................T....rdata..T........rdata$voltmd...l........rdata$zzzdbg.... .......rsrc$01.....!......rsrc$02....................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):668448
                                                                                                            Entropy (8bit):6.597025509314607
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:6lUe0bQZSn84GFMN5mSVv8pg8OWFODaunfRSzPg9HRfAWbsxLTjjTVSAAbijTwxt:6ZZo8JaN5z+dufRS6xrgSAXTCWon
                                                                                                            MD5:C72941B29791828AFBF0D431CC7FBA35
                                                                                                            SHA1:B6DA4DFA2DFC390069FE838D3841DCCF6D48ABAA
                                                                                                            SHA-256:CCF2823C73204A39DC0A1DE9E9B948B87BB9243F710AB53A6E0DF4C159BEF7D4
                                                                                                            SHA-512:992183DEA27FDA359E475D937063C8679F47C53872180DF8AAA667C2F220ED6A5D09E87B30C0FB6CBCBA2F52B395A7FBFB230C9DF10036E5DD6CD3800AFE8CCB
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........O...!]..!]..!].]..!].. \..!].. ]..!]9w"\..!]9w%\..!]9w$\..!].p(\..!].p!\..!].p.]..!].p#\..!]Rich..!]........PE..d......f.........." ...(............@.....................................................`A........................................p...d......................\F...... )...........+..p............................*..@............................................text............................... ..`.rdata..............................@..@.data...............................@....pdata..\F.......H..................@..@.rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1785096
                                                                                                            Entropy (8bit):6.549282182275219
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:49152:u/m1kU6fimCAYAOwJlfRyraVXxwHkye4asWnwZMN8f:uKAYzolImViHTe4avuf
                                                                                                            MD5:00949AA1FCE3C881929ADB781077D8C0
                                                                                                            SHA1:FF75673FD2492EC8D09458E2000CCE68565EFF26
                                                                                                            SHA-256:91A91D35EB8D85293DFF960E8431963114AEFB9B62B0C261C0012ED040A2FE44
                                                                                                            SHA-512:3FCE596DC69C4335EC5403171F5A044DC7E5E3DE8BFFE56777444E33DBED91D3647E74EDA936C2CE0117F5B9D5C2D28A522C26F8E54B4B1BE2E1ADBB4F1159CB
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........O....z..z..z.V...z..V{..z..{...z.a.y..z.a.~..z.a....z.t...z.z..z....z.x..z.Rich..z.........PE..d......f.........." ...(.4..........`C.......................................p............`A........................................p................@.......P..h........)...P.......@..p.......................(....?..@............P..p............................text....3.......4.................. ..`.rdata.......P.......8..............@..@.data....h.......@..................@....pdata..h....P......................@..@.rsrc........@......................@..@.reloc.......P......................@..B................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):5044488
                                                                                                            Entropy (8bit):6.559243918969336
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:49152:SFznQSUNeMW/3Pz42WuxpWNbIotHsErN3ocWErFMzHRGNTJc5fnzn7M4Fdpi9Zdo:dexpWNbIotUcsA9FbNF0DcxQ
                                                                                                            MD5:059FC7A9CEAD83069D5147DD4DD75AE5
                                                                                                            SHA1:EF7754EE10708C753E6A64C5F3B122CEF94A6166
                                                                                                            SHA-256:DB1D6DEB3B4A74769DB761EEDF669142AB2D759EBA324672DE2649EF3D88E7F0
                                                                                                            SHA-512:1656BD914B308F1FFBCCED00A53C96AB4BCFD411CA6AA0E98FD8F4768A2F94A4096D6858E4AA0E6A1DBF068F1D1A1E2D3D560592AFB09DA1EBBB27B8F9E7F903
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........N... .. .. .... ...$.. ...!.. ..!... .T.#.. .T.$.. .T.%.. ..#.. ....]. .. .. ..... ..... ..".. .Rich.. .........PE..d......f.........." ...(..;..N................................................N.......M...`A.........................................$H.|...<&H.,.....N.......I.......L..)... N.p_..p.=.p.....................>.(...`.<.@.............;.....|"H.`....................text...B.;.......;................. ..`.CLR_UEF\.....;.......;............. ..`.rdata...[....;..\....;.............@..@.data........PH..:...*H.............@....pdata........I......dH.............@..@.didat..8.....L......0K.............@...Section.......L......2K.............@..._RDATA...2....L..4...4K.............@..@.rsrc.........N......hL.............@..@.reloc..p_... N..`...pL.............@..B........................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):61752
                                                                                                            Entropy (8bit):6.3493073551414625
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:768:+hwLsWpGD774wTlENE9Kb8lS8BE3EqG01Ekks3uN2wP2QpTLFClk9z/:+hwLsWpG4Ntb8l4mD28liMz/
                                                                                                            MD5:03EC12EEAF45EF8E1747862CE905F51A
                                                                                                            SHA1:E4A47D35C7689C884B9F0AA491D8F824DA0DD469
                                                                                                            SHA-256:4B82AFBE3419EDA1B9C9742F55CA2A2692CDF9C5C23B61068313494B3164925B
                                                                                                            SHA-512:4A86B4BE9D521AC4F7D93E1E5F826D8D560750D97240BCA83D4982E8718186CF0BF23F61EB059C77B95C9B7719F64F00D6AE318798B7C0D76A2BF1F8E14D9263
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...............................e.......e.......e................................t.....................Rich....................PE..d......f.........."....(.r...Z......@/.........@....................................wD....`.............................................................................8)......t......T...............................@............................................text....p.......r.................. ..`.rdata...=.......>...v..............@..@.data...`...........................@....pdata..............................@..@.rsrc...............................@..@.reloc..t...........................@..B........................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):350472
                                                                                                            Entropy (8bit):6.298019612811869
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:s3oCq7D6qYvWzxP5tsWaag28fxfIUmtd3+:9+1Wzbtsftvmdu
                                                                                                            MD5:D078EA59CAE2F77F8794A632DD0809BC
                                                                                                            SHA1:843A780E62B4F2C85E17DE2E87B2C3CF233D9571
                                                                                                            SHA-256:F451A4839BD27A10FD03E751C843F2389E71E76A2F7BF418A650A53844D21D1F
                                                                                                            SHA-512:A9B9B223286170CADCFCA8F2E125791B817301B6464F0EC839990696D743986634563E2CE8080D540CDACC0FD725C0FA17C40CF6668A8A59FFC2DF17FBEDC7B9
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........%...D.L.D.L.D.LA..M.D.LA..M.D.LA..M.D.L.<uL.D.L.<.M.D.L.D.L=D.L...M.D.L...M.D.L...L.D.L...M.D.LRich.D.L........................PE..d...z..f.........." ...(.............8.......................................p......F.....`A................................................L........P....... ...+...0...)...`.......z..p....................}..(....y..@...............`............................text............................... ..`.rdata...L.......N..................@..@.data...H...........................@....pdata...+... ...,..................@..@.rsrc........P.......$..............@..@.reloc.......`.......*..............@..B................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):393488
                                                                                                            Entropy (8bit):6.332083868536635
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:8LsyeU2urknHxoHs+n1wg1xhDrLj5OAS0+QB02u7FksfEX7RPzfUz:ysyN2urknCHsAwgtrsA6Qu2v7dcz
                                                                                                            MD5:4DF8367F195394E23720173C751CF159
                                                                                                            SHA1:E215CF52164D4180605D5C16F873691649F4C32E
                                                                                                            SHA-256:29BCB525992E2BF1DC2C66918450ADE3B36E88226B1CEAB18A8C110A0E0DA0DC
                                                                                                            SHA-512:FD5DB356CB08578B731C62AFE3A98D57FDE6889ED1664038F01FBEF00FE06C83BC93365CFE94B8D23906990BFF5DA437A97C684C69CB61812E46C627C55CDD34
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........Q...?..?..?.Qb<..?.Qb;..?.Qb:...?....?..>..?..>.Q.?.e6..?.e?..?.e...?.e=..?.Rich..?.........PE..d......f.........." ...(.8..........P........................................ ............`A............................................ ...0...........x........2.......)..............p.......................(.......@............P...............................text...\7.......8.................. ..`.rdata..(N...P...P...<..............@..@.data...............................@....pdata...2.......4..................@..@.rsrc...x...........................@..@.reloc..............................@..B................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):17072
                                                                                                            Entropy (8bit):6.659738769823181
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:zpmblJeIeGXxV7wl+W+XWvIX6HRN7ckABmo8R9zYRHI2jW:zLSWIWcVmoQ9zsBW
                                                                                                            MD5:1C22BAF0E27D88F5BCD119256DAE3CFD
                                                                                                            SHA1:B6A788DC9E55A276998EFE47C21D9F655AD6842B
                                                                                                            SHA-256:0816FEBC2BA00D8CC16C843A5D629ADC4648A36EB45082DE8F0A29ACD5AEAD45
                                                                                                            SHA-512:A14BA425BBB69F11D6F264CDE110034B6DC8CAA13DDB85F9E6C223C0D5176D168D8DAFDAEF3BDE86803CCFEB99614D1F9DE2D981DBC8E19225748A7C1891FAA7
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....>..........." ..0.................. ...@....... .............................."i....`.....................................O....@...................(...`.......-..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B........................H.......P ...................... -......................................BSJB............v4.0.30319......l.......#~..l.......#Strings....,.......#US.0.......#GUID...@.......#Blob......................3................................+.....S...........................3.......9...O.............}.........}...........$.....A.....d.........................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1338400
                                                                                                            Entropy (8bit):6.358098724993395
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:cABsjnIunobZ5eGiBSk7uf9xg9Y/ydKEPXoRyingNLi0/rqsaoGSZNrWVgi00szd:cjIuG4Sk7ug9Y/ytNe4rqsa0njGzQD
                                                                                                            MD5:05D4804E5EA5509E19A3388B46A363E2
                                                                                                            SHA1:31EA1248542D2914FC76179E5731126DFCCDBFA0
                                                                                                            SHA-256:61350E7EE96E614900D641B4ECC3F35271AA2BA72C0455AE0D021E20C95F9A3E
                                                                                                            SHA-512:6DBD79B065E8C0D3B042DA7615ABC0EF7DC7522E86AEB3DF9707080AFE113077A894F5CB963D2B0A179B5755296011798B24F7102AE9A5274CCD5C0FF9959EDA
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........=I.nI.nI.n@.-nC.n.l.oC.n.l.oF.n.l.oc.n...oM.n...oB.nI.n..nYk.o..nYk.oH.nYkAnH.nYk.oH.nRichI.n........PE..d.....f.........." ...(.b..........................................................R.....`A.........................................g..p...Pi.......`..........<....F.. &...p..........p.......................(...@...@............................................text...`a.......b.................. ..`.rdata...............f..............@..@.data................^..............@....pdata..<............l..............@..@.rsrc........`.......$..............@..@.reloc.......p.......*..............@..B........................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):547088
                                                                                                            Entropy (8bit):6.626088648642838
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:BZmV75OO7txaGNUL2Sdr5Nzv0SAu9FWc1sPHE/0NY05:BZm95FtxaGDSzxAu9IpEsN5
                                                                                                            MD5:FFC0A29CFB99461BBD61BAB8A455BED6
                                                                                                            SHA1:75577F5B1ADC70877BC39830968B605CC175A8C4
                                                                                                            SHA-256:91CD06310E6DA6966A37C073F4FA4FEBB896BD09EE8658F308EB1709B335EB07
                                                                                                            SHA-512:3BF93B46BE1626636BFE133E2899218649C17F05AC1294B7940A2BBEDF01161E597D0DDE047A1672B6712444F8C5807BA8157B6A2EF50E4A25F3C46501100E3A
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .........................................................0............`...@......@............... ..................................p.......|8...0...)... .......4..p...........................................................p...H............text...8........................... ..`.data...az..........................@....reloc....... ....... ..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):50336
                                                                                                            Entropy (8bit):5.748159627893803
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:768:+RlKhT46UA2Zi5wRNH5JVb0U502zq1TntuaaNFCl+69zsc:Ku6Zi5i5jzCkaaiRzsc
                                                                                                            MD5:C251E9C5E68F8234ECEE5A332FA890EB
                                                                                                            SHA1:D0FB802214E6641387B55270089300ADF52C9A48
                                                                                                            SHA-256:36E9F61DA6BF4B6AEF5073DD639BB6174397A53573E3B0EE754AC5A997268070
                                                                                                            SHA-512:289805F4BA063A5BE984810F7504E85B3F33659492EB3509CFEB314C7AE4D8EE8E207DBCA4F354D17F3D2A359E5B83D881F6E6A3380FA9C49701FEA7AA4B0352
                                                                                                            Malicious:true
                                                                                                            Yara Hits:
                                                                                                            • Rule: JoeSecurity_GenericDownloader_1, Description: Yara detected Generic Downloader, Source: C:\Users\user\AppData\Local\Programs\SteamClient\is-0A2IM.tmp, Author: Joe Security
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...b............." ..0................. ........... ...............................w....`.....................................O........................(..............T............................................ ............... ..H............text....... ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H.......P .....................4.......................................BSJB............v4.0.30319......l....:..#~..d;..dR..#Strings...........#US........#GUID..........#Blob......................3............................-......................=..\..=.....=...=............; ..2.; ..T.M.....m=....m=....; ..9.; ....; ....; ....; .. .; ..P.; ................};....};....};..).};..1.};..9.};..A.};..Q.}; .Y.};..a.};..i.};..q.};..y.};....};....};......[.....d.........#.....+.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):415904
                                                                                                            Entropy (8bit):6.6490929239322965
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:zsUTEcoc/FGzasNt2l4ru2jKw6xtQ7/tvjETqeZ03EdoUj4MKD/6:oUTf/FGGsNtM4q2jStgjH+4Me/6
                                                                                                            MD5:19296608F2A3075C08B531122BC525BC
                                                                                                            SHA1:1F07C37BAEE61A8C4C7590F35B36721758F08D9A
                                                                                                            SHA-256:9A8F55961A23B981F489AE6F7FBC7B5919A60CC181CAAD9B9C248D3E3E542D43
                                                                                                            SHA-512:2F4BDE70E85ED6320CE94C5D64DB5247A052992648042785CCCA0A73E186825F98CAC9EB4EA9B126F2DC0A773053F763CC6539D12BC30209AEB65DB6527E7221
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....q..........." .........................................................0............`...@......@............... ...........................................)...0...(... ...... )..p...............................................................H............text............................... ..`.data...............................@....reloc....... ....... ..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):133280
                                                                                                            Entropy (8bit):6.118931111888508
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:7mTuj37yym3E5T+zpq5D3lhjdPTp8K76+d05Hzdy+NXMBpm4+SqUNiNxCzQd:7mTuq33E16qvZ5N77uLLN8BkSqUNACkd
                                                                                                            MD5:1829B95B9A2AB17DA9612B1529D5DF0C
                                                                                                            SHA1:C6B08686B182940D659D9E12251D8CBB02602BAE
                                                                                                            SHA-256:E73E129E5AED0F39F9147CD1FF2E047B01227AA791943D69A1DE4785B9598FB4
                                                                                                            SHA-512:FF687A80F9DF35DE0CA2A606763631D21D3558F9702028C2E50E20FA46FF4401DCE4585D69222E64988EF7221276363B264C1CFEDA2F67F9FB132839FA7C8E39
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....S..........." ......... ...........................................................`...@......@............... ......................................|-..X........(.......... ...p...............................................................H............text.............................. ..`.data...}...........................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16160
                                                                                                            Entropy (8bit):6.725064482931626
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:Ji92Uc6uQWcvWvdEX6HRN7fDRxB+R9z0W0S:JWL+dMWrRxw9zD0S
                                                                                                            MD5:0C62633F770757272D10CABB6C8BC0D0
                                                                                                            SHA1:378122B24AA5B589CE11B3EFC9CBDF3F5BEEE148
                                                                                                            SHA-256:7A22A638C6A751B85D112D9A1E929E7FDC2658856A4FE08B9F1DE2019757717F
                                                                                                            SHA-512:487244ED650E0039B3425F6C1E56F59694503BD418A3D0C2A8F57464AE06F7CC06AC917DD92C00D032EE330D8A49909BD5E8B269A8D93D4094B27BB92C2EB9BD
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....~o..........."!..0.............N*... ........@.. ....................................`..................................)..X....@.................. )...`.......(..T............................................ ............... ..H............text...T.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................0*......H........ ..(...................P ......................................Q+....+....N[.z....u^....G.D.^.Y...w.1..Hoe....+f.?V~........4.AU3...._4..T...K...4^s...n.......u.t...H./S...u%.g..|'...jBSJB............v4.0.30319......`.......#~..`... ...#Strings............#GUID...........#Blob......................3......................................P.........7...........P...........{.....6...................................p.......................W.....d...................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):116912
                                                                                                            Entropy (8bit):6.0097243228568145
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:b1krGkVsbV41aq4I/tT8AP43x/oLsTac3L5rgYYq+X7aVFvTbTTqZlWCzb:bcix4gq4IJ8AegLs+G55Yfaj6Zl9n
                                                                                                            MD5:515E56514CF3D123E4C6AD33E15CA2F6
                                                                                                            SHA1:8FC1C94371ADA70930EEBB7C7360D40DECCC4A8F
                                                                                                            SHA-256:A8DA3B8B3AC71775E27777652AF247AEC30F4D275D6E85F1490462EA042056C1
                                                                                                            SHA-512:7F2D7B69935D9D78F1924AEBBA46F9FD8089E34D71FB0691E9E88635365A0EF2F5376064328DD39290BBF02E3552238E2EC39C4D2FF180A5C8BA3EC801EF6A86
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .....`...0......................................................'.....`...@......@............... .......................................+...........(..............p...............................................................H............text....^.......`.................. ..`.data........p... ...p..............@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):5044488
                                                                                                            Entropy (8bit):6.559243918969336
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:49152:SFznQSUNeMW/3Pz42WuxpWNbIotHsErN3ocWErFMzHRGNTJc5fnzn7M4Fdpi9Zdo:dexpWNbIotUcsA9FbNF0DcxQ
                                                                                                            MD5:059FC7A9CEAD83069D5147DD4DD75AE5
                                                                                                            SHA1:EF7754EE10708C753E6A64C5F3B122CEF94A6166
                                                                                                            SHA-256:DB1D6DEB3B4A74769DB761EEDF669142AB2D759EBA324672DE2649EF3D88E7F0
                                                                                                            SHA-512:1656BD914B308F1FFBCCED00A53C96AB4BCFD411CA6AA0E98FD8F4768A2F94A4096D6858E4AA0E6A1DBF068F1D1A1E2D3D560592AFB09DA1EBBB27B8F9E7F903
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........N... .. .. .... ...$.. ...!.. ..!... .T.#.. .T.$.. .T.%.. ..#.. ....]. .. .. ..... ..... ..".. .Rich.. .........PE..d......f.........." ...(..;..N................................................N.......M...`A.........................................$H.|...<&H.,.....N.......I.......L..)... N.p_..p.=.p.....................>.(...`.<.@.............;.....|"H.`....................text...B.;.......;................. ..`.CLR_UEF\.....;.......;............. ..`.rdata...[....;..\....;.............@..@.data........PH..:...*H.............@....pdata........I......dH.............@..@.didat..8.....L......0K.............@...Section.......L......2K.............@..._RDATA...2....L..4...4K.............@..@.rsrc.........N......hL.............@..@.reloc..p_... N..`...pL.............@..B........................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):96528
                                                                                                            Entropy (8bit):6.256005340484751
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:8c+vV+l6Q2jM+HHdKCl2/4IGrAsDkjvSpJniknzDi:8vv8l6jjNHkQIGr4jsJnlnS
                                                                                                            MD5:58B452E9A001CDF96C84AFDEB3FC7D0B
                                                                                                            SHA1:2E7828151F39F5A2D3DCC88FD0CF53527C89BFFD
                                                                                                            SHA-256:E030C7EB334F13D261A22E2608A78455C34877D39884E3DAA4E5324C00B56E15
                                                                                                            SHA-512:5C1135DCF20B21778CD9DE86C276E887CCFF3CFC900734D5DD2B86770B5B220D1D557780D17A04D56D732BB5C99CAA8A0C6801F4479AF4A4019C473FE55EBEB2
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...^............." ..... ... ...............................................P............`...@......@............... ..................................`....(.......P...)...@..8...0...p...........................................................`...H............text...F........ .................. ..`.data........0.......0..............@....reloc..8....@.......@..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):669856
                                                                                                            Entropy (8bit):6.432051743565
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:BlTaMaSzOKy2r7SPNjB2aL9/aMolZSL7+:BluMaSSKy2/SPNVDJilA7+
                                                                                                            MD5:80DCD2DEE00526FA95ABFB1C0A7C8B57
                                                                                                            SHA1:F440EFE6A737E073F8FD920C8CCD30DEBE4AB09A
                                                                                                            SHA-256:55206C2904F12D0856EEFD722E17DF8F685276C4CBB772CC775618D2DB57A0B6
                                                                                                            SHA-512:E9801F9DDA7DB199AE357DCC84E53A9F13870D7452FBAC7A05B013642D3F383923E1CA3E9A8016419F8045A26734024DF9687BCA5DBDC61B66CC3C8F8A63F7A7
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....V............" .........@......................................................<.....`...@......@............... .......................................R...........(..............T...............................................................H............text.............................. ..`.data...j%.......0..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1046704
                                                                                                            Entropy (8bit):6.686390581958359
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:TQ/6mjCDrmDrvfhuginX9KO2YP2cTER5LvBWFsAtvrZogoLKpUHk04mrJNq3cca2:p4yM7SIOZ2x/Lv4djSK65rJY3iwW64w
                                                                                                            MD5:156B21AFD15DB03BA63FC8B8C3D6A62C
                                                                                                            SHA1:A66EC9D0B19374F2D5AF7E75D804C822D91F2E8B
                                                                                                            SHA-256:CCDA7C8E27CFB2C6381F0EC1A92A1A73A85255F5F69A18DFFC9067BDC12DD912
                                                                                                            SHA-512:90A03D5C4E1A7EABC21A8417C1081B7DFEC30F0639B6C3712B1BF252AD60DA70FA4D2A7C226C4806959B2410A2FAD09DF286CCA654BA6D95E7F89B605F779BCB
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .................................................................A....`...@......@............... ..................................x.......$f.......(...........G..p...........................................................x...H............text...9........................... ..`.data........ ....... ..............@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1247520
                                                                                                            Entropy (8bit):6.749192841590639
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:24576:NsvtzOPj/l89Sk2f+/eOUCxRepC36Rk3i+XFqUn:NsvtzOP7ymf+/TZd3ie
                                                                                                            MD5:5A0F40B6899F9BD7E43A5425DA58DE25
                                                                                                            SHA1:BDFF3CBF31FA86709309D92667C285F9F2C6D40B
                                                                                                            SHA-256:EEA806D40BE4C2FB909072DF32DE259EC476E9A7CC749C37447994FFC340F1AD
                                                                                                            SHA-512:F99971B7C6B3F3A02F99FD40DA655326D6BCF1060FFB2E5E49A6BDA6E09C05557B15F0951C1560E1ACDB4B2CDF0B63ECEF45E6745C1D562AE286AA3D53529850
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....Q............" .................................................................^....`...@......@............... ..........................................d_...... )...........>..p...............................................................H............text............................... ..`.data...............................@....reloc........... ..................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1237280
                                                                                                            Entropy (8bit):6.162110099362256
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:24576:N3mF1Kl1KS1OGTUQ8I6cXYA/fozjXu79SgKUNndau7YxZDlHTGLgvXC6irLdLUf0:BQKl17OGTUQ8wozjq9SZGndauiDC6iZ
                                                                                                            MD5:1B7E26A5178D7E80EF9B5D1BF0C53763
                                                                                                            SHA1:F3CACDE5660E6DB3B96A19032707326434C4A1DA
                                                                                                            SHA-256:66E5D8D49F9645FD67C12324E0E947B8646779B502A3BC475E3A3AEB650E20BB
                                                                                                            SHA-512:BEE9C66DBCE0E9AB4AC06B5AA3A01E4FD33475A1BE74D92DC9A75C2A3CED6B441F8A76747F3CF09913E38BEAE055FA277C55267353CDA97ABD018146E7355B89
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......cC.l'".?'".?'".?.ZE?-".?7..>.".?7..>-".?7..>.".?3I.>(".?'".?H".?J..>.".?J..>&".?J.)?&".?'"A?%".?J..>&".?Rich'".?........................PE..d...~..f.........." ...)............0................................................e....`A............................................\...,...................`....... )..........`...p........................... ...@...............8............................text............................... ..`.rdata..............................@..@.data... ...........................@....pdata..`...........................@..@.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15520
                                                                                                            Entropy (8bit):6.7942931270446705
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:NJ7sZxM0YDFW9BW5pWjA6Kr4PFHnhWgN7akW6/9xu3O6YX01k9z3AnIs9E:P7sDM0YDFW9BW5YA6VFHRN7fZR9zKIsC
                                                                                                            MD5:11350FC493C0939339C3327398288226
                                                                                                            SHA1:D595D0E78A90CDA3D21419A05CD8A9F42385E385
                                                                                                            SHA-256:02D8DA4B3EB2B1ABD79CABC927898DCDE50E53964078B903EA3BADC91268A2CF
                                                                                                            SHA-512:78E7C03299DDB72479BAFA4FBF1945215950360BDA662B7EF1FCD6FAE556D7D80895642664453DD6629E06DDA513D80DC1FEF7FD2C5D71C6A169B8887A2A03F5
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...3v6..........." ..0..............)... ...@....... ...............................d....`..................................)..O....@...................(...`.......(..8............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H.......P ......................h(......................................BSJB............v4.0.30319......l...$...#~..........#Strings............#US.........#GUID.......d...#Blob......................3................................................5...........U.........................&.....&...n.&.....&.....&.....&...U.&...i.&.....&...3...................8.....8.....8...).8...1.8...9.8...A.8...I.8...Q.8...Y.8...a.8...i.8...q.8...y.8.....8.......................#.....+.>...3.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15520
                                                                                                            Entropy (8bit):6.796904916610158
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:P/hssWCGWveYA6VFHRN78ZpIyqDX+iR9zwf:PZ/neFCl8PkDuO9zC
                                                                                                            MD5:A3E2E4ED94A51EDB3C95A3E50B448D0E
                                                                                                            SHA1:CE3C27BD57BDEE41D509C1E7C4BD15EB9EEDE7C2
                                                                                                            SHA-256:ACC824E034064DEE4A74C3F2C1CAB36C1FFB07773405168AA5FD1EA5026CEFDC
                                                                                                            SHA-512:554727273BBAF9B740653223560E851451CAC889F013D42F23F4D7321D31BC86F231A08DCCB715B081FB0F2908E95D037399CF5CF8A4A2FE7F3AD493083FD519
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....J..........." ..0..............)... ...@....... ....................................`..................................)..O....@..d................(...`.......(..T............................................ ............... ..H............text........ ...................... ..`.rsrc...d....@......................@..@.reloc.......`......................@..B.................)......H.......P ......................D(......................................BSJB............v4.0.30319......l...,...#~..........#Strings....d.......#US.h.......#GUID...x...|...#Blob......................3......................................E.......................z...........+.....b...Q.b.....[.....b.....b...4.b.....b.....b.....b.....b.....i...........t.....t.....t...).t...1.t...9.t...A.t...I.t...Q.t...Y.t...a.t...i.t...q.t...y.t.......................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):21664
                                                                                                            Entropy (8bit):6.343171564299715
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:4lkzkXBQ+RGP7RYpYOOT/460+WBvWctWqYA6VFHRN7dBmo8R9zY5a:y234/FClfmoQ9zp
                                                                                                            MD5:2A96C7F99E34759656F05BD0A0E327E4
                                                                                                            SHA1:1D8E9E6E179EE1271853790F99247FEBC7EB3D6A
                                                                                                            SHA-256:09BC14AA546F826EF2B834A909B7036DDD86F93ED4F1A275A9FF95A78CD61F04
                                                                                                            SHA-512:754B19268A23BE3C93B3B751F3B3888B23BB922367007DA9E155CF8B26C505B2B86DB329FC54015476305F3D81D619E447B9721DBB04C65059BCCFFA952F8271
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....5..........." ..0.."...........@... ...`....... ....................................`.................................U@..O....`..T............,...(...........?..8............................................ ............... ..H............text.... ... ...".................. ..`.rsrc...T....`.......$..............@..@.reloc...............*..............@..B.................@......H.......P ......................<?......................................BSJB............v4.0.30319......l.......#~..<...4...#Strings....p.......#US.t.......#GUID.......h...#Blob......................3..................................................................&.....".:...;.:...............'...........X.....u...........................................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y...............................#.....+.G...3.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):743696
                                                                                                            Entropy (8bit):6.6621018055827355
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:EwTQLZPFIwJ04TS1jMoubC+hfzF89TwM/BiXtDaCPzFPaOL8j0ecA:TTQd9IwJ0B1jMoubC+hbO9TwM/BiwCPE
                                                                                                            MD5:E10561CCC3B6C7D0AC9705A411803DEA
                                                                                                            SHA1:558A8054F0ED9F680DD20561FD9811F3C818B716
                                                                                                            SHA-256:E5D98E1ABE75C19B49952C9D5D4E28B54D336A73B9C14773FB4E7197BAE00E3A
                                                                                                            SHA-512:77C60173B7037A9E3AC714AAF5778281BDC4AFCA9166314051D4784E53000AA33FAE46E90B4DD56701AC8C28558C252E0C04564CB5C8704F09BC6D3F3A732041
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....q..........." .....@...................................................0............`...@......@............... ...........................................X...0...)... ......`<..p...............................................................H............text....<.......@.................. ..`.data........P.......P..............@....reloc....... ....... ..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):6191616
                                                                                                            Entropy (8bit):5.95806780252613
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:98304:xJD6MnOWZkv2poIbYF9ICqeBPI6hNQ8QY5LR+qXTlx:xJ2wOWloj9HZ9Q8QY
                                                                                                            MD5:720365C78A7334C8E567F826B5888E30
                                                                                                            SHA1:B37FFA349205DF4EBBC04E8CEBBE27AC95D5E4DC
                                                                                                            SHA-256:15449032C0877608ADBE17A82CEBB3F8118D7B850CE1A1E799ED738089F75349
                                                                                                            SHA-512:59BC16886CC14E1FDE12424B314A9190126926AB88F2FA05F3A306F03443723EDA41A008AF583F0B1B9DF71386C3CF9CFD23AE84E473A49D17B5E917EF553002
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....T............" ..0..p^.........>.^.. ....^...... ........................^.....y._...`..................................^.O.....^.<.....................^......^.T............................................ ............... ..H............text....n^.. ...p^................. ..`.rsrc...<.....^......r^.............@..@.reloc........^......x^.............@..B..................^.....H........T...4L.................d.^......................................0...........(e....r...p}f.....}g...~....(h....~....}i....s....}j....sk...%rK..p......ol...%rO..p......ol...%rY..p......ol...(m..........%.rK..p.%.rO..p.%.rY..p.}n.....}o...*.s.........*...0...........(e....ri..p}f.....}g...~....(h....~....}i....s....}j....sk...%rK..p......ol...%r...p......ol...%r...p......ol...%r...p......ol...(m..........%.rK..p.%.r...p.%.r...p.%.r...p.}n.....}o...*.s.........*..0......
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):3012784
                                                                                                            Entropy (8bit):6.435982980274157
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:24576:P/T7ddSgSigMFn5Q20T9/vysyyLnCXwh0KFDe9z/9GCCH/PLvlvKJdnFLvwLIlc1:yligmnsWyLnGCH/PLvlvKJh7SRR
                                                                                                            MD5:08880F1B35619BC6C3EBF07B0DD4B696
                                                                                                            SHA1:9E29833B7A533D5C4186EB3D3878561D8A3769B6
                                                                                                            SHA-256:4889CD8D7ACBEF74600B80D2261C51CADF08A6B268166CEF0CBF8066FF6CF71A
                                                                                                            SHA-512:0702F63E2196B5E3CA7AF5B1A8CACCD70E39854B435194053FA3F1D2150EF70B5AAD4B77093DE11FCEB66DBBD801CA1E78DD74784528160EFBBAAAFC7DF53C6D
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................" .....@,...................................................-.....j.....`...@......@............... ......................................@...T;....-..(....-.,......p...............................................................H............text...U9,......@,................. ..`.data....^...P,..`...P,.............@....reloc..,.....-.. ....-.............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):67872
                                                                                                            Entropy (8bit):5.7806499699132505
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:tWTDQdpxYexI0Yx82s88krahmqOwA83qJKAFE6WHKV6q6G22N7XK6RH4wqYXYsY/:tWTD2px7DYx82s88krahmqOwA83qJKAk
                                                                                                            MD5:48EFC108D7EF7817BCD9BAFAE557436F
                                                                                                            SHA1:5A017C66B16266A7C34CEBB7DFF531AB5068DF34
                                                                                                            SHA-256:9C4D605934307CFC9ED37ACB1210368C8ACC5C88B816931E7D022F8AE917CDCA
                                                                                                            SHA-512:E7FB663FF470121B72A2B6621A362DAE7C8899536FAFEDF70BE69016630604C7C7027BBE9509ECBCEE558631B07535E03F3FA5815518BBFEE6B1417A0B2324E1
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...1.+..........." ......... .......................................................b....`...@......@............... .......................................!.......... )..............p...............................................................H............text...:........................... ..`.data...............................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):350472
                                                                                                            Entropy (8bit):6.298019612811869
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:s3oCq7D6qYvWzxP5tsWaag28fxfIUmtd3+:9+1Wzbtsftvmdu
                                                                                                            MD5:D078EA59CAE2F77F8794A632DD0809BC
                                                                                                            SHA1:843A780E62B4F2C85E17DE2E87B2C3CF233D9571
                                                                                                            SHA-256:F451A4839BD27A10FD03E751C843F2389E71E76A2F7BF418A650A53844D21D1F
                                                                                                            SHA-512:A9B9B223286170CADCFCA8F2E125791B817301B6464F0EC839990696D743986634563E2CE8080D540CDACC0FD725C0FA17C40CF6668A8A59FFC2DF17FBEDC7B9
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........%...D.L.D.L.D.LA..M.D.LA..M.D.LA..M.D.L.<uL.D.L.<.M.D.L.D.L=D.L...M.D.L...M.D.L...L.D.L...M.D.LRich.D.L........................PE..d...z..f.........." ...(.............8.......................................p......F.....`A................................................L........P....... ...+...0...)...`.......z..p....................}..(....y..@...............`............................text............................... ..`.rdata...L.......N..................@..@.data...H...........................@....pdata...+... ...,..................@..@.rsrc........P.......$..............@..@.reloc.......`.......*..............@..B................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):157960
                                                                                                            Entropy (8bit):6.47315446775413
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:Vm98N/j+0sbFbqX63vwZuIBo7M5F896ToYdBCBuqmwLhtTihdUmXD:88Cb6oIBo7q2GBCBuwhzmT
                                                                                                            MD5:11C346045E8C17C82C66B33E1E200DD8
                                                                                                            SHA1:64E08782D5CA2ACB2AC2C88B2D8F0323F43E3295
                                                                                                            SHA-256:344C7A232249C2ACE65D2CC03D62C356FE3F56AD46A0CC4603A36EC7D0F5587F
                                                                                                            SHA-512:294F1F8DEF433238DE0E98754BD44BF0614490D8A1086759924F548B91E219E223380601F16B987B27C9D0D67FE80393827A30580CFA096C49F5B2834E73FB88
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....Q............" .........@...............................................@............`...@......@............... ..................................@....6.......@...)...0..........p...........................................................@...H............text............................... ..`.data....".......0..................@....reloc.......0.......0..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16544
                                                                                                            Entropy (8bit):6.621378907680227
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:s0WLW7yEqHWvWYA6VFHRN7i3tHNsAR9zF0RGRv:s0WkyEqGWFClkts89zmRGRv
                                                                                                            MD5:065469DFC7A55B2575D432CC2EB20B75
                                                                                                            SHA1:26C4271164F9A0D5F02C6EB79BF1A95E77D715F6
                                                                                                            SHA-256:54C25CDE74F7FA7C164E5E8C90BBBDB1A4F84ECD4B3C6F542560A6CC8BC55E4D
                                                                                                            SHA-512:BCAAA07A1DEC59A5B64D2034D30741EED9C00159EF4AE42C79896709C65B5982053074BC7621B818523B608B663845C853790B3AD6A484109696CF4690533685
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0.............N,... ...@....... ....................................`..................................+..O....@...................(...`.......+..T............................................ ............... ..H............text...T.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................-,......H.......P ..8....................*......................................BSJB............v4.0.30319......l...4...#~..........#Strings....4.......#US.8.......#GUID...H.......#Blob......................3......................................".....................X.................*._....._...B.?....._...'._...Y._....._...3._....._...l._.................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........:.....C.....b...#.k...+.....+.....3.....;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):668448
                                                                                                            Entropy (8bit):6.597025509314607
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:6lUe0bQZSn84GFMN5mSVv8pg8OWFODaunfRSzPg9HRfAWbsxLTjjTVSAAbijTwxt:6ZZo8JaN5z+dufRS6xrgSAXTCWon
                                                                                                            MD5:C72941B29791828AFBF0D431CC7FBA35
                                                                                                            SHA1:B6DA4DFA2DFC390069FE838D3841DCCF6D48ABAA
                                                                                                            SHA-256:CCF2823C73204A39DC0A1DE9E9B948B87BB9243F710AB53A6E0DF4C159BEF7D4
                                                                                                            SHA-512:992183DEA27FDA359E475D937063C8679F47C53872180DF8AAA667C2F220ED6A5D09E87B30C0FB6CBCBA2F52B395A7FBFB230C9DF10036E5DD6CD3800AFE8CCB
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........O...!]..!]..!].]..!].. \..!].. ]..!]9w"\..!]9w%\..!]9w$\..!].p(\..!].p!\..!].p.]..!].p#\..!]Rich..!]........PE..d......f.........." ...(............@.....................................................`A........................................p...d......................\F...... )...........+..p............................*..@............................................text............................... ..`.rdata..............................@..@.data...............................@....pdata..\F.......H..................@..@.rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):800928
                                                                                                            Entropy (8bit):1.7782280660549779
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:9Nira5KkDpWjA6Kr4PFHnhWgN7awWLCjVi6KrIX01k9z3AszW7szwL:9IrOYA6VFHRN7g49R9zri7sw
                                                                                                            MD5:B945BB71515F3597C3B3A58D2F1E3B54
                                                                                                            SHA1:E37EE014E86DC82A3FFA30BD1BE29BF6C4914673
                                                                                                            SHA-256:EC2086DEB616AF11A27BDBD0668638254A835303CD922211F5CD669FAA195F54
                                                                                                            SHA-512:373BED1C64322AB222967C73DF3FEBD1F53D227A5BC33B7E9E14DCBA43CFFC76D390D03ADD117160EDD4022A34500D0DD3170574469D3CF8AE1A26B3C49A0823
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....)=..........." ..0.............&)... ...@....... ..............................,@....`..................................(..O....@..l................(...`.......'..T............................................ ............... ..H............text...,.... ...................... ..`.rsrc...l....@......................@..@.reloc.......`......................@..B.................)......H.......P ......................H'......................................BSJB............v4.0.30319......l.......#~..........#Strings............#US.........#GUID.......`...#Blob......................3..............................................-.....-...0.....M.................R.................h.....7...........[.....x...........D...................................).....1.....9.....I... .Q.....Y.....a.....i.....q.....y...............................#.....#.....+.....3.X...
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16136
                                                                                                            Entropy (8bit):6.763250939574308
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:DYlxlKxAdKXZ14WAsnPUWvTbpWjA6Kr4PFHnhWgN7agW6kxwVIX01k9z3A7OMsNo:ITQocZiWrsWvTbYA6VFHRN7UR9zEOMio
                                                                                                            MD5:B8C780077D3BE36CC8F8A85C5B056393
                                                                                                            SHA1:E269FE3AE47536E5583749987D15867680091BEC
                                                                                                            SHA-256:6CA75DE642BFB7D7E4654161EE0A7FFAAC4775406073D5BD6588D8FBA9CE937F
                                                                                                            SHA-512:6565880E5E6CCAD9FE6A2B3787FBE92F51306BB13D6A91389C4616D58B1EE2B8CFAF89CB748836C6BD8F0B09D8208BFF4CAB6D7B01A9A805E46E573647AC0159
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..............+... ...@....... ..............................Uc....`.................................A+..O....@...................)...`......T*..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................u+......H.......P .......................)......................................BSJB............v4.0.30319......l.......#~..8.......#Strings............#US.........#GUID...........#Blob......................3................................................P.................<...........g.~...2.~.....1.....~.....~.....~.....~.....~...p.~.....~.................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):59552
                                                                                                            Entropy (8bit):5.257260939720961
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:NWpN/Po1PdD8nvXct+B62EOI57wDhtaMaycXJe5LxmI2liZWZPQIjDZBv0gAxSXl:YBQ1VPuCwDh24xFrDYYcFClz9zgv
                                                                                                            MD5:DE79B443EEBCE1B83464224287780FC3
                                                                                                            SHA1:B16F794A7C87C766840B1D42E2E079F957A93312
                                                                                                            SHA-256:DA253533149EE5152D36CD4C20AE4FBAB8A2AB2D3D93067A9765BDA230088165
                                                                                                            SHA-512:76A4C90F50CD86534A481501C1AD774D40EC1A963387CA79DE20FC747D61578890DEF6EAC12519CC5ADD1CBCFA8B842B301A1EF21177B3EB491B9D7EE1D5A812
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....]..........." ......... .......................................................;....`...@......@............... ..................................l.......\........(......|.......T...........................................................p...H............text...k........................... ..`.data...n...........................@....reloc..|...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):231696
                                                                                                            Entropy (8bit):6.473831853357629
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:LaO7AQhsFgOZrgy5HSchuzeQ4X1VjK6uJQ+Y6MFot9R9loV2O1w6D/:77AQhsFgOZrBccgeQxRJNtngV2YTL
                                                                                                            MD5:5C34FE0079268AE7F3F22811FE9495FB
                                                                                                            SHA1:DE25943AE52E36BC6DD686790A7F56D5AA5C7591
                                                                                                            SHA-256:D609294406B894BC0F60D10FB62AD7A819E3BCBA3691A1825E4250364E23A7F1
                                                                                                            SHA-512:46A330540F64EAA5A7BC8D097DADFAFB5D054282F44FC2FB57F59494E5A1E6136C98DD8B6D08DFAABCB29B8121112405A86946C27F854151B443E18968F531AD
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....r(..........." .........P...............................................`............`...@......@............... ......................................xU.......`...)...P......x ..p...............................................................H............text............................... ..`.data....7.......@..................@....reloc.......P.......P..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16656
                                                                                                            Entropy (8bit):6.729692051834912
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:IK6DDj+yVx/bWXDWv1pWjA6Kr4PFHnhWgN7agWz3KDUX01k9z3AWipv0t:I5+yfzWXDWv1YA6VFHRN7IpR9zv82
                                                                                                            MD5:AF34F0A70120DD8DB41F8DEC70280B5E
                                                                                                            SHA1:3C568BF4CA5D852279C54F93350385BEE5666529
                                                                                                            SHA-256:F0B69FBDB0540A52A66E7A7B5C11476E29FB9ADEB2DC7D5FF88EA12D36843D5B
                                                                                                            SHA-512:54B6A9549E13BC52CFFE199FD07D9C57EBB2F3BE4C8000FC8DC2B9D824F527379697DBB41B8371562C55082C6E0B0EFD9ACFB375AD45964A4E8C25A46834A854
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................."!..0.............n-... ........@.. ..............................x,....`..................................-..Z....@...................)...`.......,..T............................................ ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................P-......H........ ..H...................P ..........................................`j..@.e..R]?..m$...|j....3.m.~....&....fG.....UW...q.....4z...`.(.W_N.3.6.....#.'Q...}iG...............%JB}K...~..Y..BSJB............v4.0.30319......`...x...#~..........#Strings............#GUID...........#Blob......................3................................ .....................O.......................c....._...........}...........6...........B...........................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):51376
                                                                                                            Entropy (8bit):5.749601750476796
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:768:5UG932Xb+i171RsnV73v2/PL04IWWkmoQ9zItF:5PGr+871q7/2b0QWkmVzmF
                                                                                                            MD5:E87C3E51080C7BB65E611B485A599ABD
                                                                                                            SHA1:B9B02227ED6C0E3DA2D19FC6DE018E559D532E70
                                                                                                            SHA-256:8974918F0BA83548BAFA900918F93B35770A64D8DBC7A104188CD6FFC8D0F157
                                                                                                            SHA-512:3CF5541C5080A5774477A5077CB88006F7548F94E74D08D0FF33505B89C10B26E87162CCCB19CBE9C290371E3C83FD5AEE8A79637C251AD11EB6E6AACE1C57F2
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....>............" .....p... ............................................................`...@......@............... ...................................................(..............p...............................................................H............text....j.......p.................. ..`.data...............................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15648
                                                                                                            Entropy (8bit):6.831749206420305
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:4FMYodxAanD/YHWl3WvM2WxNzx95jmHnhWgN7agWGhHssDX01k9z3AeKD++zEA:41mVDQHWl3WvM9X6HRN7pFDR9zzKaM
                                                                                                            MD5:B815AFF49D8A185341D31ABAB43F4DB0
                                                                                                            SHA1:BF661D387D2FB9FF3BBD51B5412B4B395A76EA01
                                                                                                            SHA-256:D788B912A2FCADA28A9A1E2D221AACA429D20A420B05315F173A5A5365BF3D5E
                                                                                                            SHA-512:BC07CA500FCDD762032D5911C303DBC28B1E720D32A91129B3C1C07A8B01CDF73DB82E69D5C02571001E06D83C2589B40EFA23CE1820029DD0156A6098403762
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....I............" ..0..............)... ...@....... ..............................3x....`..................................)..O....@.................. )...`.......(..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H.......P .......................(......................................BSJB............v4.0.30319......l.......#~..D.......#Strings............#US.........#GUID...$.......#Blob......................3............................................................3.Z.........^.......B.....B...n.;.....m.....m.....B...S.B.....B...w.B.....B...:.B...G.B.................T.....T.....T...).T...1.T...9.T...A.T...Q.T. .Y.T...a.T...i.T...q.T...y.T.....T.....T.......................#.....+.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.742653380857255
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:2h/pWnylpFWvcYA6VFHRN7z1649R9zri8a2:2hXqcFClA69zX1
                                                                                                            MD5:B690D3E96E11B84ED793FC571EA0A78F
                                                                                                            SHA1:9D9090E5A702750F4CAC744D1D7651BBA6BCBE7A
                                                                                                            SHA-256:7BB1C84D14EFCCBCB84A1F075CC00814757DF752E80A6FC472A1A4FAC9E0C97E
                                                                                                            SHA-512:CB0971C76761455A6D226227442B2A28339C939381D26AF38C91DA23E38883915E712F2966FEEEF090A9996A993A45633C14AA2BBF6C94092245FA9553F38F0A
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[y=..........." ..0..............+... ...@....... ....................................`.................................;+..O....@...................(...`......P*..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................o+......H.......P .......................)......................................BSJB............v4.0.30319......l.......#~..........#Strings............#US.........#GUID...........#Blob......................3......................................!.........f...........\.....:...........B.^...H.^.....;.....^.....^...+.^.....^.....^.....^...p.^.................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.C...+.Y...3.o...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):96528
                                                                                                            Entropy (8bit):6.024769249295685
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:BOryyBJoyJyGXe5CtLey6+67NVpnSPM+l5+tkmVgKmH6iRnzDDn:BPyJO5CtiXdSPM+r6kmud6KnTn
                                                                                                            MD5:1BA98C8A3C7D903ABFF78D01E081D64C
                                                                                                            SHA1:15EF718B9F1EEC435C7AEE8A59B41562D88934A4
                                                                                                            SHA-256:69DE6AB16DFBA66224B37E4FCD5E62AFDF45F75C9F5C78BFD6CBFA09142390C8
                                                                                                            SHA-512:FB194521D9964012CBCA456505A9858B49F36009A6E9DCE9F9EC6126693990750285F57DB2831048606336EB9F28193D6073B3E6CACEF337D7323A3967FF3846
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...;.=..........." .........0...............................................P............`...@......@............... .......................................(..\....P...)...@......X...p...............................................................H............text............................... ..`.data........ ... ... ..............@....reloc.......@.......@..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):432416
                                                                                                            Entropy (8bit):6.566108898209545
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:K+cqnJGnQkW6a+Sdjoe9k7u0GeFowoR5axLmqRSxnJ8kks1GL0q3+lL4A:l6aFP9f0NokSxOL0AEX
                                                                                                            MD5:29A059AB9999BD953C0AEC0B2C78E9A1
                                                                                                            SHA1:C41DB5BB3EF1CB499898698E3A87B83925F9BC36
                                                                                                            SHA-256:E1743ACD71086BB1AA689AACCC9485AEC04B2A7C2C15586ECDD5685AD881B7A5
                                                                                                            SHA-512:5431C58174273A5795D40DF4AA988D6049E0402F04379E84B80A9E02AE819A73BD5FBFF17109EFF0C341171A56BC28807D8B3B55DA03E7304552993DB89EA220
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....|..........." .........................................................p............`...@......@............... ..................................P........)...p.. )...`.......*..p...........................................................P...H............text............................... ..`.data...mr..........................@....reloc.......`.......`..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.754858406085234
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:FsiCLx+eWl+WvXpWjA6Kr4PFHnhWgN7agWfiC7L4xxu3O6YX01k9z3AnUGj:fWPWl+WvXYA6VFHRN7AnY1R9zK5
                                                                                                            MD5:5A0D5E375A4568CEA219B700365A3C5D
                                                                                                            SHA1:2EF3BDF476C9EDA2992A2FFC13FBE467D6630803
                                                                                                            SHA-256:B14DA399FCF67C895F70F3B609937E28E7CB1CB7FE46EEC51181F1CB5F8C6D6A
                                                                                                            SHA-512:2DDB829370CAAFD3298CFDEC06A067CF6EEAADB3A88CA7F7EBEE61ACB2747744B78DF4BDC43304427D135CD73CBF907D000DF6DEE42F18C05B8C9EF537DD2BC8
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...P............"!..0..............+... ........@.. ..............................<.....`.................................5+..V....@...................(...`......8*..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................p+......H........ ..h...................P ......................................F..b3...X[N....0..Rl.e,.3...L|..V......$...R.Gg.....B@..>0.[_..x8.i...L...W..Qq:..H..-M..p...@..a....j.....x....9.!g....KBSJB............v4.0.30319......`.......#~..........#Strings............#GUID...........#Blob......................3......................................3.........@...........Y.................?.g.....g.....`.................g...y.g.....g.....g.....g...`.g...m.g.................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):59552
                                                                                                            Entropy (8bit):5.643119448166663
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:768:lt51EDMpCUoqFY66Gw17oqZn/TEHmyrchswz6EEZcYf5o4ba2yGlG1QeY48lCi5m:ltFcC3ZcYf5o4bZyGc1A4c53iPmVz8n
                                                                                                            MD5:67972D6AF44F5E08E9F3EACC31D302AC
                                                                                                            SHA1:976D10328572171E8122FA1AA765E92AB54CEC45
                                                                                                            SHA-256:217BC7C04BE852B4FCF8104F8BA8F673F1B177D2D8C5CAF455E7A18E6BBE2097
                                                                                                            SHA-512:BE2B63E849A046A0D786EB25958F423A088BDE3431800FA4CB6667D5FA4147D1FD363AD2D7E3E4FE9EB8BCF03A0DCCBE5A23FA4252AA228D8EA1A380597AEC57
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0.................. ........... ....................... ............`.................................q...O.......$................(..............T............................................ ............... ..H............text....... ...................... ..`.rsrc...$...........................@..@.reloc..............................@..B........................H.......P ..................... .......................................BSJB............v4.0.30319......l...$O..#~...O..(b..#Strings............#US.........#GUID..........#Blob......................3................................e.....b/........L%.O...).O....RO..EP.......+..:.:4..J$:4...&S0...+.O...%.O...(:4...&:4...":4....:4....:4..U&:4....:4.................N.....N.....N..)..N..1..N..9..N..A..N..Q..N .Y..N..a..N..i..N..q..N..y..N.....N.....N......R.....[.....z...#.....+.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):22296
                                                                                                            Entropy (8bit):6.376173260415304
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:IT1G5qkxK67ex4FCh0eWYAWvlvX6HRN7aEw4R9zE8J:IJ6LS0YhBWajk9zJ
                                                                                                            MD5:E08002B259471A203FB54A3142617115
                                                                                                            SHA1:FB0EDC0F656F850EC49740479C78251A8FEEF35C
                                                                                                            SHA-256:1A10820BEED89FE0A72D2D6A9E849001590B35625006EF53F67EC4981964B231
                                                                                                            SHA-512:ACF5C0A39460A24F0687D84BE6B435B1E57BB90D77A13DA712CEAAE4B8409960FF21509F3E857D489ABD6827D8FAA635EDB4FEDF4141C7BFB858AAB4EC6D4C1E
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................."!..0..$...........B... ........@.. ....................................`.................................wB..T....`...................)...........A..T............................................ ............... ..H............text...."... ...$.................. ..`.rsrc........`.......&..............@..@.reloc...............,..............@..B.................B......H........ ... ..................P .........................................Tz...7c...a....l..iDj<U.....s..k....T_.83..AAY...R.S.I~!...q.|.....".,..m...0.=..#...Kk+M.g...q.....jkM..M.....$.mIBSJB............v4.0.30319......`...|...#~......8...#Strings............#GUID...$.......#Blob......................3............................................................G..... .......b...-.....f.......i.......................................[...............................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):260376
                                                                                                            Entropy (8bit):6.615511865069277
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:wfAevHZGInBPKCeDc6CK9MG3bMeVmtG0FsGu6Myw0M:XyIDc6MG3wamtG0fuVMM
                                                                                                            MD5:22647404E842F5177DEC97B960B98501
                                                                                                            SHA1:5E5DECC395401901278F2B4727ED6539CE28A51C
                                                                                                            SHA-256:F289BC9873AE0BD99DB74E00F480C931CA94F3785251132C04699AB01893604B
                                                                                                            SHA-512:3EF4F8141B680EF0922C24284E7B5D5F7B006C0E718E69D6E2F0446B58B271099FE599398C1814C8698B8460A5A6062BAFAA12D2F7FFED5123A86DCA46BDB340
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....S..........." .........@............................................................`...@......@............... ..................................p...PS..x........)......8.......p...........................................................p...H............text....{.......................... ..`.data....$.......0..................@....reloc..8...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):43184
                                                                                                            Entropy (8bit):5.444316993596802
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:C23WkwWvOJtQnkEun+JBTeZDeRbOkKsfJbCLv+CToLfyOQEi066gaiGgX6HRN7jp:C23ROJ+pKEJSO7o6ji3W99zdD
                                                                                                            MD5:090FCCE165FED5E5ED5332C11CC31B3B
                                                                                                            SHA1:77D98026A8A7F6307655B54E34B4CD15C903DC23
                                                                                                            SHA-256:D2EAC1736D03EF60DA6775105B7AC6D8E0C9855CA2437CF108B1DCBEBF05CBF0
                                                                                                            SHA-512:E09CC8EFE62E0EBA06596BBCBFEAC0839EA9B31A355F4F24DAB0A85238EE62241029DA79D51805DB29D1232EA769C236DE961D5DA5B17E045098523E3DDAEABD
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....f............" .....P... ............................................................`...@......@............... ..................................p................(...p..........p...........................................................p...H............text... L.......P.................. ..`.data...=....`.......`..............@....reloc.......p.......p..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16672
                                                                                                            Entropy (8bit):6.688841643360067
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:MuCkGQKyxAyCWCCWv3g0yWxNzx95jmHnhWgN7agWF7qT8RwX01k9z3AhStpK6/Ta:M2F4WCCWv3pBX6HRN7u2T9R9zUspFO
                                                                                                            MD5:63BAE6DF058D6F3D630713CA52343D29
                                                                                                            SHA1:96A8411BA0786BE08E54B62CA8EAE6998CE57644
                                                                                                            SHA-256:1B6B873F4C5F5985E7C3E6BA5693D1C676FE0773C9335003F97807712EDEDCE7
                                                                                                            SHA-512:EC8892A9A1451C76D6CCA4835BBF242EAE417EC4120C69EBD47D484763583C1AC5D0BF73D28871B31F133C061BD9EB88E4695BC2E6E59C509C809E5478652205
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...N.K..........." ..0..............,... ...@....... ..............................0.....`..................................,..O....@..d............... )...`.......+..T............................................ ............... ..H............text........ ...................... ..`.rsrc...d....@......................@..@.reloc.......`......................@..B.................,......H.......P ......................4+......................................BSJB............v4.0.30319......l...l...#~......|...#Strings....T.......#US.X.......#GUID...h...|...#Blob......................3................................"...............M.............................q.6.../.6...........6.....6.....6.....6.....6...m.6.....6.................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):3156541
                                                                                                            Entropy (8bit):6.3749448508652815
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:49152:1WGtLBcXqFpBR6SVb8kq4pgquLMMji4NYxtJpkxhGjIHTbd333sx:vtLutqgwh4NYxtJpkxhGq333s
                                                                                                            MD5:FB8F887F569CECF50AF68290EE751386
                                                                                                            SHA1:95D34DBD4B472707BD7073B559E51C1E61020952
                                                                                                            SHA-256:C339A2F77F23B7E371DBD0560E8993535666B8E6B55FD8194188D7F3DA04325B
                                                                                                            SHA-512:12217CCDE00A204FCB32FB37DAF98F8EDEA8D26F01D231DCCB95E04F29C5C75E32064190B9251E6EA4576130DAB4BF3A4D4E7A32C40A3691307D4BC05343DCA7
                                                                                                            Malicious:false
                                                                                                            Preview:MZP.....................@.......................InUn....................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L......c.................L,..|......hf,......p,...@...........................0...........@......@....................-.......-..9...................................................................................-.......-......................text.... ,......",................. ..`.itext...(...@,..*...&,............. ..`.data...X....p,......P,.............@....bss.....y....-..........................idata...9....-..:....,.............@....didata.......-.......-.............@....edata........-......*-.............@..@.tls....L.....-..........................rdata..]............,-.............@..@.rsrc.................-.............@..@..............1.......0.............@..@........................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):4916840
                                                                                                            Entropy (8bit):6.398149817011711
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:49152:FCZnRO4XyM53Rkq4ypQqdoRpmruVNYvkaRwvpiD0N+YEzI4og/RfzHLeHTRhFRNS:EG2QCwmHXnog/pzHAo/A2L
                                                                                                            MD5:A7349236212B0E5CEC2978F2CFA49A1A
                                                                                                            SHA1:5ABB08949162FD1985B89FFAD40AAF5FC769017E
                                                                                                            SHA-256:A05D04A270F68C8C6D6EA2D23BEBF8CD1D5453B26B5442FA54965F90F1C62082
                                                                                                            SHA-512:C7FF4F9146FEFEDC199360AA04236294349C881B3865EBC58C5646AD6B3F83FCA309DE1173F5EBF823A14BA65E5ADA77B46F20286D1EA62C37E17ADBC9A82D02
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........|3..]...]...]..e\...]...\.5.]..e...]..wX...]..wY...]..e^...]..eX.y.]..eY...]..e]...]..eU./.]..e....]..e_...].Rich..].................PE..d................." ......8..........<).......................................K.....B.K...`A........................................`%G.x....(G.P.....J.@.....H.......J.h&....J.....p.D.p....................S<.(...pR<.@............S<.(............................text.....8.......8................. ..`.rdata...F....8..P....8.............@..@.data...`....@G......@G.............@....pdata........H......@H.............@..@.rsrc...@.....J......@J.............@..@.reloc........J......PJ.............@..B........................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):18192
                                                                                                            Entropy (8bit):6.625640713703575
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:bvu3anBNTYxDHn+WBvWvdpWjA6Kr4PFHnhWgN7agWv6KDUX01k9z3AWipVl:Lu3af2L+WBvWvdYA6VFHRN7m6pR9zvwl
                                                                                                            MD5:BB348D3A59DB204B4F6357758D950D7B
                                                                                                            SHA1:401FE3743A40BD85F06C5074454080E7F6895540
                                                                                                            SHA-256:EF29DFAAEBC33486376625E22BDBC96597785E99859A96E7DFDDAD0211AB6643
                                                                                                            SHA-512:ED8611B8EA3F164DAD3FD6A98337AA9076AC6EE9D00606C59DFB5AF19E7EC799E35FF580A1BF8FB74E23376D8780B068E030753BD6B56CFE17F438DCB6BD43AA
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....K..........."!..0.............N3... ........@.. ...............................&....`..................................2..V....@...................)...`.......2..T............................................ ............... ..H............text...T.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................03......H........ ..0...................P ......................................I.(b...R.c.l....i.$%'...3.q.*...\..N..J..y..Bc.K.....r........8...D...A...%.y.Nq.....rym..Q$...G.C.W..Kx...\..&.T....p.9BSJB............v4.0.30319......`.......#~.. ...p...#Strings............#GUID...........#Blob......................3................................J.................................+.....F.....H.....N...............................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.7285494674641
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:0zox6WeWWvYYA6VFHRN7IL/6fR9znQ2BDi:0zoxq3YFCl19zpDi
                                                                                                            MD5:11867901021083A68FA4D1FF345F477A
                                                                                                            SHA1:FF0889F05B3161F7D27CCC5FE2DF7F9A430D9E1C
                                                                                                            SHA-256:CF9436FF6A04184E6049CCBC5C27D638DFE5DE134640C35A4D5873FAA010FCC9
                                                                                                            SHA-512:D2B42520FDB3F83C8648047AE1D4E6350F81BDF3D8286C4AF01221DD2DD9B018B5DAA390927170FE49CF4ACB01DFBE63D45CCC4AAF6B451BAF9AA22B239CC2A0
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...Mpv..........." ..0..............*... ...@....... ....................................`.................................s*..O....@...................(...`......h)..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................*......H.......P .......................(......................................BSJB............v4.0.30319......l...L...#~......<...#Strings............#US.........#GUID...........#Blob......................3................................................ ...........^.................D.d.....d...t.7.....d...Y.d.....d.....d.....d...@.d...r.d.................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):67848
                                                                                                            Entropy (8bit):6.069064583177759
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:768:2jOHMffs25VU9QbAoqxfxGSC0e+LRnugRxFjyGw3/slSdoF31s7YiNZ/OSkk9ZP+:2lM2EoLmpsFZZwiMzQQ
                                                                                                            MD5:7C78865F32AED5CB2BED0B3240AEC113
                                                                                                            SHA1:4CCBE9AFF7D5D86D401981106C5A85FDAB5DC5FE
                                                                                                            SHA-256:5468BBB816B4A21AF610388C9AA8CC2DF47A581E9AEBF81EEA985C8D1EEA80B1
                                                                                                            SHA-512:25C7070CEB9CC1BD3815C497E4012FB951D989592D39021E7381DE93D884467A63673459CD302513C086A8088BCD6D8355E0986582844083283645FD9CC952B8
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." ......... ............................................................`...@......@............... ..................................0...4(...........)......0.......p...........................................................0...H............text............................... ..`.data...............................@....reloc..0...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):17056
                                                                                                            Entropy (8bit):6.6307312364714805
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:P4n7palYIWo5WvLpWjA6Kr4PFHnhWgN7aIW3k+2NowcLK+X01k9z3AcjTvGY:OmWo5WvLYA6VFHRN7gk+2N6R9zdTGY
                                                                                                            MD5:17B940218F1B5A16BC7576F345C3CA04
                                                                                                            SHA1:CC64810DED8E394421DA7B9521CF5E4EBE977D59
                                                                                                            SHA-256:BE6B73071C8E8BD1EF4702CFE2A5AF73A926D64996479DF2A6E296F942C4DD3C
                                                                                                            SHA-512:3B323281E07A6A207AA23B255AAF1D4E958C8844627CBEAF8413A9B3B234A88B12593E2E0F33AED0EEF10A4D17D384513A1034E85D9FB3ED7969C6B83C68C9B6
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0.................. ...@....... ....................................`.................................7...O....@...................(...`......H-..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................k.......H.......P ..x....................,......................................BSJB............v4.0.30319......l.......#~..8.......#Strings............#US.........#GUID...........#Blob......................3................................&.....................?.................%.].....................&.................>.....[...................{...........................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.C...+.Y...3.o...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.654808513658327
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:wowweWm7WviYA6VFHRN7FUe3/6fR9znQfNzn:woEKiFClFUeA9z2
                                                                                                            MD5:4F3162B9B035A7B978BC88F73F77A4DD
                                                                                                            SHA1:EF3EE0BC3C8525D34FB1B3BC14ED6A11759DAE02
                                                                                                            SHA-256:61BD0CBD9C8C85A1B6C783EEBD1568B40923D2EBF4C0967418D6202371CE36ED
                                                                                                            SHA-512:CB586CA8F80BC4BF51CC3F032842FE9C0B987BE8742670BAD2C2A549C724B3770761175F3BF088A8C242BF1C37C5302352F9212C4FCACB2F8A8BB0ABDEAD5EA5
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....N..........." ..0..............*... ...@....... ..............................d.....`..................................)..O....@...................(...`.......(..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H.......P ......................8(......................................BSJB............v4.0.30319......l...0...#~......@...#Strings............#US.........#GUID...........#Blob......................3................................................E.............|...............i.)...'.).....".....)...~.).....).....).....)...e.).....).....E...........v.....v.....v...).v...1.v...9.v...A.v...I.v...Q.v...Y.v...a.v...i.v...q.v...y.v.......:.....C.....b...#.k...+.....+.....3.....;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):30880
                                                                                                            Entropy (8bit):4.644629646041882
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:bWoLWvBn5oNBVVp+YA6VFHRN7KBmo8R9zYJF:faBiBVmFClomoQ9zK
                                                                                                            MD5:460684B262DE49F8A3C771B47C993EA3
                                                                                                            SHA1:15B760439D2C0A0B39EEC012EDA53D67078D0FA8
                                                                                                            SHA-256:2D796A9138318AC5BCFE96970F3C5920F8307856C1BEE5F9D5BEAEF0369AE319
                                                                                                            SHA-512:41CF1EA52BBF2ADEB8A066533FE9647B67E9FEEDBF45DC4E517D61EB31A35B8944062DE7B59476AE8E533E99CDC5E06270957652A1467F94157264F53258ECBD
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...e............." ..... ... ...............................................P............`...@......@............... ...............................................P...(...@..........p...............................................................H............text...~........ .................. ..`.data........0.......0..............@....reloc.......@.......@..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):17056
                                                                                                            Entropy (8bit):6.608161458975255
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:4af4fk3CB2oqr9z9W7zWvCYA6VFHRN7Ki7Bmo8R9zYqgg:4af4B8ozyCFClKOmoQ9zqg
                                                                                                            MD5:B252E2C17A4297DBB90BFCE9C66DB845
                                                                                                            SHA1:2BABEE3632DE7471E338A95796E19596DEB1CBE8
                                                                                                            SHA-256:35890B7AF3C51962D8342BD17DF24289438459971C0972DDC67E47534C78B790
                                                                                                            SHA-512:31E6AEEDACEDF07EBF9BA7E26F40779005CBC11AAAFB86559F50652EAE5A1C7948706642F7D034AB6358DDB8A9E9CF952840F6DAF61C87E912C1A2FBE456FD59
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....2..........." ..0..............-... ...@....... ..............................(-....`..................................-..O....@...................(...`.......,..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................-......H.......P ......................<,......................................BSJB............v4.0.30319......l.......#~......H...#Strings....X.......#US.\.......#GUID...l.......#Blob......................3................................&.................o...w.o...2.\.........].................H.....^.....-...........v.................F...................V.....V.....V...).V...1.V...9.V...A.V...I.V...Q.V...Y.V...a.V...i.V...q.V...y.V.......................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):157856
                                                                                                            Entropy (8bit):6.1575669495933445
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:urdsza/NXpFSGeVdEgUxnI3iJ05uE2alATZ+k/OKY4US2+:wsza13Sxy5SiJUuE2vXPZ
                                                                                                            MD5:4D4ED1ABBB92E818A6E2CD9C91AE5FAC
                                                                                                            SHA1:5F70C569120724DCBD9839B16503517FCDB09D9B
                                                                                                            SHA-256:4128EF96ED97A3393082335768F85E118148A7EDF13777B2B1368DA88CB21276
                                                                                                            SHA-512:6E90EC4EEF42D669FB9D9C7E7B52F87E711C3FC46491E2409AB7037E68817E2E32E5F29BE02E97F951204E0136E20562568DAE7223A33380FCAA0944B93C25DE
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......ym.h=..;=..;=..;4tY;7..;-..:4..;-..:6..;-..:...;)g.:>..;)g.:2..;=..;...;P..:0..;P..:<..;P.5;<..;=.];<..;P..:<..;Rich=..;................PE..d....-.f.........." ...).H..........p!....................................................`A.........................................................P...,...0..8....@...(......8.......p.......................(...`...@............p..h............................text...,D.......F.................. ..`.orpc........`.......J.............. ..`.rdata......p.......L..............@..@.data...............................@....pdata..8....0......................@..@.rsrc....,...P......................@..@.reloc..8............:..............@..B................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):870560
                                                                                                            Entropy (8bit):6.698604415601525
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:e0nJfitube+UKtRjkFIRVYZvOQ0109+mkXE/dPZWfl+U:nRUWFkOU+HE/xZKsU
                                                                                                            MD5:9C5ABEE2F1E122E307DDBA43D2BC1574
                                                                                                            SHA1:C21842857E4452DD6C67E4B72F8CD417486C239C
                                                                                                            SHA-256:CA6E09B43631E90070E141714BDCC3124FD9301BE14C9C663C04EF92A0A951CD
                                                                                                            SHA-512:0E26B9C4BFDBCA6916B43C064D188547673DBB7A121A4B2BC05C672F5A3EB5223344352D8C5F844511DAF6EF85F2BFDD3A1E1422B11482CE591CDFD686BD6FDA
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....W..........." .....`................................................... ............`...@......@............... ...................................... ...@b... ...(......P....>..T...............................................................H............text....[.......`.................. ..`.data...e....p.......p..............@....reloc..P...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1603760
                                                                                                            Entropy (8bit):6.680950208426245
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:24576:49f8aQsCuaY+QtQ3+ACMaylTIDDCPmZbxhT6LRquiPx:6lhCuza3+ACMasTIDOMxhTX
                                                                                                            MD5:FEAE8157F5E6A7425B47AF947AFEF9F5
                                                                                                            SHA1:6ECAF7F7A8EC4E7A0034576B46D9B045C7A5E8D5
                                                                                                            SHA-256:91B09A9DB441B99D14D4160A98D935A736B66802CFC2ADA80C7482D0AEDD2C02
                                                                                                            SHA-512:E52CB5F1C5070D2F9CF3D1208C24CE6EF566DB1DF745A67FA7FD45C3A0371D158E5B6498FDA264E67D5561EDA8CA0CFD4BE4575879A412F2EF27E853490292BC
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...".'..........." .........................................................P......f.....`...@......@............... ..................................<...........P...(...0.......j..T...........................................................@...H............text............................... ..`.data...Mg.......p..................@....reloc.......0... ...0..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):47384
                                                                                                            Entropy (8bit):5.385545715496689
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:768:QMGgXwsP/QEBuk3bqUghjhyCKPivxbzY17tvALj0fjW7F9zC:QCXwsP/QEBuk3bqUghjwCKPipb017tvB
                                                                                                            MD5:BA98951D775757104E005E5F4E209C3E
                                                                                                            SHA1:6A59BD6130172B72FB97C35CADBD0F5D9E549732
                                                                                                            SHA-256:7D3347F76557D5655A5BBDAD0477F5DA12E337FC77E86B1B91E269A3B3A023B5
                                                                                                            SHA-512:6D4EF736011D50D140932DD54DC2A5E40C574AFFB9F0FAE202C32C9568CCFFCBC12770ECF33A2A2C3BD76F5238AE360694D5FE44BD993F8A51AF330C0DB7E719
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....J............" .....`... .......................................................)....`...@......@............... ...................................................)......H...`...p...............................................................H............text....X.......`.................. ..`.data........p.......p..............@....reloc..H...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):84144
                                                                                                            Entropy (8bit):6.01559741196385
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:4cj1LAKJSc+9NVY3qX7/6T6vGccWysg1D+LMWbzm4Z:4+1LAJc8NVj7/FGx5D+LM0/
                                                                                                            MD5:CF4DFE3880F9DB4476A840637E5558AE
                                                                                                            SHA1:30F1C9CA1A9E6B89D11B541368CF605BC4E76BEE
                                                                                                            SHA-256:C787901537E0BC1E6E4A686FB341294223DFD9B91277341DFCE0DAEA946ABF80
                                                                                                            SHA-512:1D681FCFA1ED9B7F74A69E6BAE6501959C9982F75895F5AAD55DE88544085EE24093330D5A96AB57AFD7D66856997EF3270D7B87CA171F8EC4F40535B30B5C36
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...(............" ......... ............................................... ......9.....`...@......@............... .......................................$..T.... ...(......(.......p...............................................................H............text............................... ..`.data...;...........................@....reloc..(...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):100616
                                                                                                            Entropy (8bit):5.964892851536555
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:yQAG0KzKsXnTOShX+bX5SHuDQp6O/U/xOQwQ7rzUU3q2bP6NLrSjlV4i7Ep4za/e:ywRXSSV+bJSHu6cgXSJV4QXUe
                                                                                                            MD5:82BB53A6347A98BC441E26C6EFBB6EE7
                                                                                                            SHA1:94FFF378394772F8F6B37A66A3C7DAE43F3848E3
                                                                                                            SHA-256:D407C1380C52E1A04E554C0B134D9BC4699C7225290003ACE8E988E4AEEDBB25
                                                                                                            SHA-512:4BC1BFEF668F6843F85FBCC28B886E66BB886D30903C8DC8CBE3CCA8417AFB6130856C73FFF0686E3022ACEF8D26994DB4CF296ECF788EBA9D59B8E21EA74E58
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .....0... ...............................................`......K.....`...@......@............... ......................................p+.......`...)...P..8...@...p...............................................................H............text...|#.......0.................. ..`.data...{....@.......@..............@....reloc..8....P.......P..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):170144
                                                                                                            Entropy (8bit):6.427166919417408
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:Hza6IfDI6Q8nqNIJ55jypCTpAY3ykJ9rialFpR/fTu:T9t6vn8IJySpxFHfi
                                                                                                            MD5:53AB5080DEEE5C08F664C6329DB1CF45
                                                                                                            SHA1:F800510D0212425220BC0DFBAADC9FBD979DDFB6
                                                                                                            SHA-256:EBB450E89DE674B20C93E0108123FF1C1D2F217CF9CDF2E51609A84E76708687
                                                                                                            SHA-512:DC321BB7693ECF188C148DF5ABE942F2DD6D2FCA6F681876BC9C066A1356C7E3562846E5E1D91B759AFAC9F1872D9516FCE81270E1AEEA4FFD608899A4EF9772
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .........P...............................................p......?.....`...@......@............... ......................................\K.......p...(...`......8...p...............................................................H............text............................... ..`.data....8... ...@... ..............@....reloc.......`.......`..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):831240
                                                                                                            Entropy (8bit):6.118745272820205
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:cAw//Ot2fD+T5pdHnbAHhlyZ8OXTw05nmZfRTlnL:cAw/D+ZbAPlAmZfRJnL
                                                                                                            MD5:80F809C49EF92211D8D604ACDE19B734
                                                                                                            SHA1:FE38C548F62C9686451D7ED3BB56AD0C4014E097
                                                                                                            SHA-256:6E9365E60F9060B3E492F489E1C13EC07BD1F368FFCC5BA24D98530BDCD2D468
                                                                                                            SHA-512:303A5C5C8DB412A93BCB933A63733C532A23A2207531D2460670BBB125042985ABAAD7BADE42F8C88E835DD74895AF7B75AF5930EF623A285EB14EED869BDCA2
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......j..u..&..&..&.q.'&.&.q.'$.&.q.'..&'..&".&e..'-.&..&o.&>v.'..&>v.'/.&>v}&/.&>v.'/.&Rich..&........................PE..d.....f.........." ...(............P................................................I....`A.........................................^.......`..x...............d........)..........0,..p............................*..@............................................text............................... ..`.rdata..Lg.......h..................@..@.data...l....p.......\..............@....pdata..d............`..............@..@.rsrc................~..............@..@.reloc..............................@..B................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16656
                                                                                                            Entropy (8bit):6.71053707165234
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:jmw3RJOW0iWvJYA6VFHRN7pORxB+R9z0LLZ:jn3RSDJFClpORxw9zC
                                                                                                            MD5:08BFE95432A413747BB05DB5AFE50AE7
                                                                                                            SHA1:1D937A7A2B29061B0A52AC4B659ADDFBB4DC2030
                                                                                                            SHA-256:8FF2322E5F56AE15E026EE299C3E437EF9FB581AB50C688E2870C9DC55C90411
                                                                                                            SHA-512:6784366CA92DCF063898E43B48538909FFD9DD5F4F8A70DAD7007A21BCC50B24899849439E33AE01DBE81C7AC3F2E48A69B499B116918F3F8AACD238994D005C
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....:............" ..0..............-... ...@....... ...............................7....`..................................-..O....@..t................)...`.......,..T............................................ ............... ..H............text........ ...................... ..`.rsrc...t....@......................@..@.reloc.......`......................@..B.................-......H.......P ......................<,......................................BSJB............v4.0.30319......l.......#~..........#Strings............#US.........#GUID...........#Blob......................3................................$.....3.........0...........D...........o.....*.1.....1.....K.....1...i.1.....1.....1.....1...P.1...X.1.................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........C.....L.....k...#.t...+.....+.....3.....;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16136
                                                                                                            Entropy (8bit):6.7201571212077225
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:XUnaHtGxAeWyixDWDSWvmpWjA6Kr4PFHnhWgN7acWPoAgfcMbnoQNpX01k9z3AZ+:eaHtsviRWDSWvmYA6VFHRN7uo/7R9z5z
                                                                                                            MD5:F038E35B176485760C5D92877E33EE0C
                                                                                                            SHA1:62974D42DFC93E87ABAA78EFC0E13F73667C380D
                                                                                                            SHA-256:15E3C48D3C693F7182221BF369A528B33C99EE00C2E3840ED35F600FECDAB77D
                                                                                                            SHA-512:2AC72E17F2ED3120130383FD1FEDF34329E53D19F5CA922796B7DD9561DCBF1E4246DE481677E51884C785215A684A4EAD29066504DA35EBC6B810DD3AF6F446
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...%.h..........." ..0..............*... ...@....... ....................................`.................................M*..O....@..T................)...`......p)..T............................................ ............... ..H............text........ ...................... ..`.rsrc...T....@......................@..@.reloc.......`......................@..B.................*......H.......P .......................(......................................BSJB............v4.0.30319......l...$...#~..........#Strings............#US.........#GUID...(...x...#Blob......................3......................................X.........U.............................y.....7.......k.................................u............. ...........................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16664
                                                                                                            Entropy (8bit):6.680561869198979
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:28zn7Dxl7W7BWHW1WxNzx95jmHnhWgN7acWHPRlGfAgfcMbnoQNpX01k9z3AfjMM:vzn7dl7W7BW2WX6HRN7K6/7R9zgMqdd9
                                                                                                            MD5:8E8686D4BBD1BA7229E2E54A3B8CAC1B
                                                                                                            SHA1:9CB6BCC1C3F98E11A8F9F4BE5AE4F94245DA548E
                                                                                                            SHA-256:98B57636E6D5BA40C425E85B78C531A860694E7DE6488CD661044FA91170C8A1
                                                                                                            SHA-512:D6BC42F3869C748DE35383A5E55CD5B3B451975518D80B4E0910068B50E1F24C572F6A4A435CC18B28099A70219A31D12B728D87049472D4851EDE79CA529C63
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....c0..........." ..0.............n,... ...@....... ....................................`..................................,..O....@...................)...`......T+..8............................................ ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................M,......H.......P .......................*......................................BSJB............v4.0.30319......l... ...#~......p...#Strings............#US.........#GUID.......t...#Blob......................3................................................S...........s.........................~.....~.....~...6.~.....~.....~...s.~.....~...7.~...Q...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y...............................#.....+.>...3.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):22176
                                                                                                            Entropy (8bit):6.387333708399484
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:5UuzLRrw/cSmWtGA+bH7S3W1HWNYA6VFHRN7xBmo8R9zYj:5UunRrwPtGA+LOi2FClLmoQ9zO
                                                                                                            MD5:3D282B70FE068939C3EB9854ACE54354
                                                                                                            SHA1:E37211642E776F03E9F45C3C0C19A0A71C5150E0
                                                                                                            SHA-256:F19F1E7B9BEFA1E1F4F8CD12232AE3A94ACCE6D0F6662C195527204B65B0486C
                                                                                                            SHA-512:6AC990C8FCEC3597C2885228C5775A995B4AFEE21DADDAA35B689880636F789770A11925CABACD91098D5F0AD89D795D4D50895C12E93A7CD3E69C3F517F8B61
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................" ..0..$...........C... ...`....... ..............................J.....`.................................cC..O....`..D................(...........B..8............................................ ............... ..H............text....#... ...$.................. ..`.rsrc...D....`.......&..............@..@.reloc...............,..............@..B.................C......H.......P ...!..................LB......................................BSJB............v4.0.30319......l...P...#~..........#Strings............#US.........#GUID.......\...#Blob......................3......................................:.........E.a.....a...^.A.......................P.....P...~.P...(.P.....P.....P...e.P...r.P...".P...<...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y...............................#.....+.>...3.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16136
                                                                                                            Entropy (8bit):6.714372309412333
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:GeawQgWZzWvPYA6VFHRN7sUCMR9zGV5wfK:Ge/QHyPFClsUF9zm
                                                                                                            MD5:A0BEA80A62152978E32251FA63A0ACB8
                                                                                                            SHA1:3F4F646C98CB8628314924B463BAAD197D039BBF
                                                                                                            SHA-256:9A3E5D6D51AE86A91D2EC90B2A2BE5DC2210F032C140C349F04256DE6ED441D5
                                                                                                            SHA-512:4E8B600E1D59CEEE3411AF54758556B9792519C396EC9DF997DD58AF66B5505A4A86BB8F165391AC75F1CF0F092038B059C1C1D074E291B8C320D14A9695960E
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................" ..0.............n*... ...@....... ...............................W....`..................................*..O....@...................)...`.......)..T............................................ ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................M*......H.......P ..H....................(......................................BSJB............v4.0.30319......l.......#~..|...,...#Strings............#US.........#GUID...........#Blob......................3................................................9...........U...................A.....A...........A...r.A.....A.....A.....A...Y.A...i.A.................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16136
                                                                                                            Entropy (8bit):6.738272740252956
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:xEKxAG+HWRmWv1pWjA6Kr4PFHnhWgN7acW9aN6AgfcMbnoQNpX01k9z3AZs8g7D9:j4WRmWv1YA6VFHRN74a0/7R9z59DyM
                                                                                                            MD5:30BF6C4EF92AED34FC143A9724F3CEDD
                                                                                                            SHA1:1BB4BBA6801925D9B9BBD7DBBCCF1A8F522B4087
                                                                                                            SHA-256:40E5813EAB9D7FA7A1914DBBD8E452C04F9FF053C5A4E5BE494DC85AC4BD9246
                                                                                                            SHA-512:BE5E7104F3635D000D7246832AC54C9E32512DF678CD4B4BAFFE81EE3A1178BCD0028989AF71C2617FCF849A316F67A3F7D790C901B1D35CCBD08F16C24BA592
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...6............." ..0..............*... ...@....... ...................................`..................................*..O....@...................)...`.......)..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................*......H.......P ......................$)......................................BSJB............v4.0.30319......l...H...#~..........#Strings....<.......#US.@.......#GUID...P.......#Blob......................3..................................................W...R.W...g.D...w...........0.....w.......................>...........................................>.....>.....>...).>...1.>...9.>...A.>...I.>...Q.>...Y.>...a.>...i.>...q.>...y.>.......................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):13170968
                                                                                                            Entropy (8bit):6.844875656043683
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:98304:3fWVGoCY0Os5SYWxv4Ac7JnQj6OUN9v4AS0C9C4fKp7kHeAi:6mY015SYWxvdcNQ2OUN9vDCEp7kej
                                                                                                            MD5:A2EA4D0A864DC1F7C7A4EA4D3930011A
                                                                                                            SHA1:0C0EE0F265387C64D8B9F0BB29E7D9320F394C65
                                                                                                            SHA-256:60AB682B551CC4E94E2DE432149E032FD63AC0B6D15397DECC4D8BE87C6BE1AB
                                                                                                            SHA-512:90EF986AE72D4713AAEA1E86F185EC709F4726095BED25598073B0AF988D8F941B0CB345F05BC1832936B9D0F2B9DB477D97A9AFD83CBC6552281FD9E5553997
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....BW..........." ...............................................................4.....`...@......@............... .......................................p..d........)... ..8...(...p...............................................................H............text............................. ..`.data............ ..................@....reloc..8.... ....... ..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):112800
                                                                                                            Entropy (8bit):6.132923222586611
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:NUgJ8nlSAIFIpp8oXAcRKdRObZDFduWF8XwYJiAzk:Nx8nMAc2p8qRgAVDVF8Acjg
                                                                                                            MD5:397EB70F9DE2A7676B5DA94FF7CF11BF
                                                                                                            SHA1:88424878A779059002622F22315C1E0050FF4251
                                                                                                            SHA-256:E2A5AB5B077CBE3B7CDB0622EAE9363E8D9C591DDAB2CE87FCE6777A510767A6
                                                                                                            SHA-512:0E4836D6AB91BDACBB49EF71290256A7DCF4CBCA23B9C329C2E05CF00966BF0FABE9748092A579843BC211D4612D94CF8BB655207A3D40C46D11DCC663BFE544
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....64..........." .....@...@...........................................................`...@......@............... ......................................`1...........(..............p...............................................................H............text....7.......@.................. ..`.data...B$...P...0...P..............@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):157856
                                                                                                            Entropy (8bit):6.292306263911845
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:O1TeXCmzdST4L7rGE5RtqbqeQGwpncU/SLVXyVMnA9kmeBgo:WGCwdu4SsRQbIfqZm0H
                                                                                                            MD5:3874C63BA167BA4D4B815BAD86016CF4
                                                                                                            SHA1:72AB7DE57994DBAD6133FA9DDA1F2943E9F3122E
                                                                                                            SHA-256:9F9CF0B569F370DF63BE323844009718090B6D4FD4E21EC8D4DD6B6CC2FFE8CF
                                                                                                            SHA-512:17DC16864394CB6F0D52724606EBA24735A86DD62719264635265CED7DB0C36333FF0A3328222B6638DA16DD23FA6159E5F9B5EBA4499F62BABB1524587EEF2B
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....v..........." .........@...............................................@.......-....`...@......@............... .......................................9..8....@...(...0......(...p...............................................................H............text............................... ..`.data...T&.......0..................@....reloc.......0.......0..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):158720
                                                                                                            Entropy (8bit):6.3954432817313664
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:CjK4UGDHXrQ8hy7qgpHulWD9ZvZ5Pf3Ca10xuZ04ntfOshBul3ThNSHoNO/:CjK4TDUqgpqWDLZ5H+xuZ04fhA9fT
                                                                                                            MD5:24579F75EE35BDD8E4CCC5351295BD9D
                                                                                                            SHA1:ABA441303C3B421DC246EADC469CA05F00DD006F
                                                                                                            SHA-256:0B5D62717704AFE1282A9D6ADE9104FE40E1C6EE855E4DB66E8EF68F68C57CFF
                                                                                                            SHA-512:3494565C8F75122F1204339BBDB3D90A4C2BB28405F98F5869D94775D9EB855FA19733C036B27E7BD3B6532A0AAEDE94ED427BE3AC41D66EFE7050073C6490D0
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........G6..)e..)e..)elR*d..)elR-d..)elR,d..)e...e..)e.(d..)e..(ef.)e.U d..)e.U+d..)eRich..)e........................PE..d......f.........."....(.Z..........@..........@..........................................`..........................................................`...S...0..\............P..(.......T.......................(...P...@............p...............................text...lY.......Z.................. ..`.rdata.......p.......^..............@..@.data...............................@....pdata..\....0......................@..@.reloc..(....P......................@..B.rsrc....S...`...T..................@..@................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15640
                                                                                                            Entropy (8bit):6.779164699458774
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:VRF6PxAdql7SNMWbCWvY7WxNzx95jmHnhWgN7agWLgj3LwKUWX01k9z3Ad7vvp:TF65oqRSNMWbCWvYUX6HRN7KgM2R9zGN
                                                                                                            MD5:38366E6D059554EFAAB623EF614C3357
                                                                                                            SHA1:DB0D245CC6F0442B2851EFCA589F84AF1111E07C
                                                                                                            SHA-256:8AD0AB3216F296F993EB9FB0D911B202E0D3B435A63D35E3133B191DBCBDC8C9
                                                                                                            SHA-512:12CFA64DF5B3D7D407AC1B3DFF2AB0E1ED22C38505B6A7FE51741B3E8692E416ACCE744AD4600CFE0BE2522FF5011C4EE656C9200D6DBC267D48217F6E4FD8D7
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L..............." ..0.............")... ...@....... ..............................!.....`..................................(..O....@...................)...`.......'..T............................................ ............... ..H............text...(.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H.......P ......................`'......................................BSJB............v4.0.30319......l.......#~......d...#Strings....|.......#US.........#GUID...........#Blob......................3..................................................3...x.3...3. ...S.....^.................I....._.................w.................G...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):313520
                                                                                                            Entropy (8bit):6.026328145716465
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:Lwz2fFD31yI6tnfKKEjXowPpcpys8+Lehz2rlp:UCfFD4IeWxy0mLekp
                                                                                                            MD5:8978AC101696167F58CC1692BBE8B66B
                                                                                                            SHA1:C5ECD066C1527D2309CF79E42B984F8B9E358DC2
                                                                                                            SHA-256:15F86E2E660BAB9293C737BDED22A5F0A49776B48371E76DFA57C89850E72768
                                                                                                            SHA-512:60620A67348C33B1D7A1456B8041484DD51D2AA1AE5A4DC9A384E5F3016BA574AE2C7F0E7D366DA25DBE24BCF832ACA50E2A9F029E5BA05F951F90C8EAD4BA63
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .....P...@......................................................>.....`...@......@............... ..................................L...(;...........(..........(...T...........................................................P...H............text...`F.......P.................. ..`.data....'...`...0...`..............@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):415904
                                                                                                            Entropy (8bit):6.537421933056359
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:KqsPcEZnG2usAMctT0i6KTHIJZamhPrwgE08sr1VEZRE95p1wSHovYvZK51/0y7P:KqgE2uZztIi3ywgt8NOBHovicP
                                                                                                            MD5:BA75D597D43C856BDC6D4A2707EE58B5
                                                                                                            SHA1:489F2F6836332BCD15EADE770C7E46131F074DB4
                                                                                                            SHA-256:90F73C2DECCD7139D9948C8F5D5B874A2D5DC9FA43D36A4190F6F60ADE792433
                                                                                                            SHA-512:60BAC2F126A72A389A891E318D476353AC40E1542E0C5F4997DC4B9EE1E0790CAEA0B6882BA95079DCE2E907E42E18BC39F28E32361938F120ADD3DC4664EF6A
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....)............" .........p...............................................0......PX....`...@......@............... ..................................\.......,...0...(... ......`(..T...........................................................`...H............text...g........................... ..`.data....\.......`..................@....reloc....... ....... ..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16160
                                                                                                            Entropy (8bit):6.742004031944957
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:PHYCHwcH9H8HzW8HWvdBX6HRN7YRxB+R9z0xfb+:KfGdJWYRxw9z9
                                                                                                            MD5:0F9296306DE9D1BCCE253FC647D1E8D6
                                                                                                            SHA1:2ECA5248F203D94813F3428A3C3A82CAFE973635
                                                                                                            SHA-256:D6AB3875C8FEAF7D6FD9B1EFD18B1FFD10FE46B2FF3A2F24D7FA5D16F927EC0F
                                                                                                            SHA-512:C2A5F479BFEA3357BE02E3C1340C303DD4D20CF3F6A78A6092FB2ED9E3315863F9F8A8673BE7927FF7B9FCF1210C50B90BA6123CAF1F845033EDB7276ACE33BD
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....VT..........."!..0..............*... ........@.. ....................................`.................................;*..P....@.................. )...`......@)..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................p*......H........ ..p...................P ......................................).....Q..$.?o&p]...0.~%.0*s{&;....[.=...A|>.k..9EQ.jH.n....D 4........g./...T...6..SO..CD.V..........UK..bg. q..3.?.tY...v.9BSJB............v4.0.30319......`.......#~..p...H...#Strings............#GUID...........#Blob......................3......................................................4...........7.......c...{.....V.............c...t.....}.................9.....................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):489632
                                                                                                            Entropy (8bit):6.5425586567283025
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:vCh91rqxP6PRc4Uo8wv8K+RpB8Cw93gozY+OSTMo:OBcMpgQY+OSYo
                                                                                                            MD5:78E0E6A45F064CB22F500D0ACB85A1D0
                                                                                                            SHA1:4D5259F6777ABF2AC666B07325B6F5246FC2F762
                                                                                                            SHA-256:2E1BA52621FCD31507BF08F9537154DB7A216CBA70C941B24A425B7F28F5F19E
                                                                                                            SHA-512:772CEAF937953A1447A2B34B659AC3B8DEBB49C0E7B02749BA523F99F5263A8D046F4D5E9744E989E22B845D841D408FC9C231DC575066FF137248A76FEF1976
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .........................................................P.......8....`...@......@............... ..........................................E...P...(...@.......2..p...............................................................H............text...I........................... ..`.data.../k.......p..................@....reloc.......@.......@..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.7044983638513145
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:DuEW1VJWvrLYA6VFHRN7MDX+iR9zw8td4:DutYnFClMDuO9z3d4
                                                                                                            MD5:CE6B3D7D2E3BF3E35BC49F0905A0947E
                                                                                                            SHA1:5F075D3E596CFF0670AEE7E1BB1C6C2FA6AB1089
                                                                                                            SHA-256:253E1C6A59ACB96DB9EA8E4BE48EA4E8040F885D602349B2B44753234709D49D
                                                                                                            SHA-512:D53C00B4C26540D36464501A64A0AB3E7FE175256F47F44BBA53D25ECAB6255C51570EA4A7FBD6E2FAC171967A9CB876E2C7FD5A961554EB5C49222620E31BD1
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................"!..0..............*... ........@.. ..............................+.....`..................................)..V....@...................(...`.......(..T............................................ ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................*......H........ ......................P ......................................Wsa.....ky`w...q.FB....O.Z.......\........j.....K.N...]M.~.'.@?O.=d.r].N\.~.BE...p.9..e4....D.&..S..7.j........H:...+nT_...`BSJB............v4.0.30319......`.......#~..4.......#Strings....<.......#GUID...L.......#Blob......................3................................................0...........I.k.........t...../.E.....E.....>.....~.....~.....E...i.E.....E.....E.....E...P.E...].E.................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15632
                                                                                                            Entropy (8bit):6.740344128283329
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:6GqxAsOUWoo9WvDpWjA6Kr4PFHnhWgN7agWH4/KfKUSIX01k9z3AGoi7GtK:4LhWoo9WvDYA6VFHRN744o2IR9zXR7GY
                                                                                                            MD5:EFACD5C037B280E814A636B399BA51F2
                                                                                                            SHA1:FF434841129277A5F37E4D9F2B373D17376A9F62
                                                                                                            SHA-256:7F2AEBB25BBC9B473D639AD55BA2470EBC50A805C89BDB7FF3CE47A92DF1FFDE
                                                                                                            SHA-512:E161A026358E520A2494C05676DD9C658184388A33EA12F0441C34B7F7D6D75F18D814B24132381B6D4C9199BB916C9F06C33E919D2F8750EC19399891025A38
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..............(... ...@....... ..............................m.....`..................................(..O....@..4................)...`.......'..T............................................ ............... ..H............text........ ...................... ..`.rsrc...4....@......................@..@.reloc.......`......................@..B.................(......H.......P ......................D'......................................BSJB............v4.0.30319......l.......#~.. ...D...#Strings....d.......#US.h.......#GUID...x...|...#Blob......................3............................................................>...........i.....$...........T.....j.....9....................... .....R...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.C...+.Y...3.o...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):19104
                                                                                                            Entropy (8bit):6.5215263611516
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:jGgfnShxL2GoOoxWmHe9QdWVYA6VFHRN72k6R9zdL:jpn6lZoQRFCl2k29zt
                                                                                                            MD5:38D24ABC45135A87E515790906D7724A
                                                                                                            SHA1:BFFBDB01EC108FC45C29202AE814C13D55A4C79A
                                                                                                            SHA-256:C6DCA08937792CD14E10F7B9794377FE698C3A97C9958D90B397CB6BDEB1F0C8
                                                                                                            SHA-512:674C8B1B5454143F7D6767919FDE88FC478F4A80DC24C70F6CE398AF526A7F065BF38FA3030E3CBF28204313BE2EA92FA19F1F3F014216A0E6D7BF130D58AC24
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...|............" ..0.............n7... ...@....... ....................................`..................................7..O....@..............."...(...`......t6..8............................................ ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`....... ..............@..B................O7......H.......P .......................5......................................BSJB............v4.0.30319......l...H...#~..........#Strings....4.......#US.8.......#GUID...H...\...#Blob......................3................................x.............................%.........*.....C.......(.....(...E.(.....(...`.(...}.(...,.(.....(...<.(...q.......0...........................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y...............................#.....+.5...3.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1785096
                                                                                                            Entropy (8bit):6.549282182275219
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:49152:u/m1kU6fimCAYAOwJlfRyraVXxwHkye4asWnwZMN8f:uKAYzolImViHTe4avuf
                                                                                                            MD5:00949AA1FCE3C881929ADB781077D8C0
                                                                                                            SHA1:FF75673FD2492EC8D09458E2000CCE68565EFF26
                                                                                                            SHA-256:91A91D35EB8D85293DFF960E8431963114AEFB9B62B0C261C0012ED040A2FE44
                                                                                                            SHA-512:3FCE596DC69C4335EC5403171F5A044DC7E5E3DE8BFFE56777444E33DBED91D3647E74EDA936C2CE0117F5B9D5C2D28A522C26F8E54B4B1BE2E1ADBB4F1159CB
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........O....z..z..z.V...z..V{..z..{...z.a.y..z.a.~..z.a....z.t...z.z..z....z.x..z.Rich..z.........PE..d......f.........." ...(.4..........`C.......................................p............`A........................................p................@.......P..h........)...P.......@..p.......................(....?..@............P..p............................text....3.......4.................. ..`.rdata.......P.......8..............@..@.data....h.......@..................@....pdata..h....P......................@..@.rsrc........@......................@..@.reloc.......P......................@..B................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):387248
                                                                                                            Entropy (8bit):6.555993554831254
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:PTjRRbvaPik9w6VSMAc15k8H5iGD7x/v9a4w45N5WkaGhLWukVTRW2e:Pfo9w6V3oa2vsNLWuWle
                                                                                                            MD5:6807A5F492DD8EA805BF55A64A754868
                                                                                                            SHA1:D6D2707F2A55F13B96196BD4182347AD41C876EB
                                                                                                            SHA-256:CA18410D83DA120038813EDEBE4086CCB94F6AAE6DB194F594D7207695223E0E
                                                                                                            SHA-512:B9AEEE86CFB836F3BDAB0D8E4453F8D65A7899B11260E40340A56D7377AE17BC239E4FB212FD42F07DDBE7C0ADE5F5F26773E297CFCA1FE80B1410C4D3C36C03
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...~............" .....P...`......................................................H.....`...@......@............... ...........................................%.......(......@....&..p...............................................................H............text....D.......P.................. ..`.data....H...`...P...`..............@....reloc..@...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):104608
                                                                                                            Entropy (8bit):6.019621325219264
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:Nx/tht+6AWhqlJH5MC+W06201CTBUsqEiONocgw50ad01IODi0zmG:Nx/Q6AqiT+WFPaiONocgwaaOhDzl
                                                                                                            MD5:7B967ABA7A1321AF17A04576DE32CC50
                                                                                                            SHA1:DC2F05B710D21733BEFB5066FA99BFB3AE1B7C4F
                                                                                                            SHA-256:C3D7055A0C71A9E8641C7883DBBDFFEBDBB27D2350DE43BA925D947662533DAF
                                                                                                            SHA-512:4B8ABBE1101EA2CB7B257198E2DCB353CCA151C4BEBD4697A128FFD69D27E1DE64FE19FCBDC79636414B01B15B7848E2C16E6B9BDE24688D1794A7334AEAA9A4
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...!............." .....0...0...............................................p......}e....`...@......@............... ......................................p1.......p...(...`......8...p...............................................................H............text...!).......0.................. ..`.data........@... ...@..............@....reloc.......`.......`..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):542880
                                                                                                            Entropy (8bit):6.739097833229294
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:fFcC4bb3czSgsrusOv38qA0s4WfufbFHJMb3xqHYYzLhMxjCUoTclQ:K7b38crusO/yEvuhsSWmQ
                                                                                                            MD5:DDF4958F47A5D0A7ED06832880DA1BFE
                                                                                                            SHA1:40FA6F2D97DE7504770B37153F4EEBF79A069535
                                                                                                            SHA-256:BDCF09BBA6A4DE7D73FEAA0DBA8802BE86738B3DE4E3E8D0EC79E2809F0F7E17
                                                                                                            SHA-512:1D54CA464CFD1ADB8B78C1226954F2C4FB66EC3CB51980BDE613A25A18A938BB536C7C6695CAF139EAE1F8A15AAB33B53B0BF9D1DC9BFDA948007BD6DE3EC0F2
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...uWB..........." .....@................................................... ......|4....`...@......@............... ..................................0........J... ...(......H.......p...........................................................0...H............text....1.......@.................. ..`.data........P.......P..............@....reloc..H...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):145680
                                                                                                            Entropy (8bit):6.213889260140082
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:HXvuCBgDTeY0dpwQn60x7cftbgZyeI7XT5DFEj3C:xBgOY6aQn60x7cftbgfalCjy
                                                                                                            MD5:B5B5534716E8115775DAE499811D0AA4
                                                                                                            SHA1:A34F5CB79DCA9F2821E276979A72BE3A093764CA
                                                                                                            SHA-256:0F2701EA7067203F84D6E8D3E5E6D45C00434B41175C3CF4F7ADD5B17D7F437A
                                                                                                            SHA-512:BDBBAD128B3464B3C80C777560BA53E3297145309F53778D12A9285D469B4D79216F9BE07096F8F884251BBFA91274944F4E6E2345FE92A274F526013F637E75
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................" .........0......................................................:p....`...@......@............... .......................................B...........)......|.......p...............................................................H............text...g........................... ..`.data............ ..................@....reloc..|...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15632
                                                                                                            Entropy (8bit):6.823933557530997
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:Z1PXcWQqWvxYA6VFHRN7bih7RxB+R9z0o:Z1PW7xFClG7Rxw9zf
                                                                                                            MD5:0D8AAF01FC45951BFFF5FE30ED082863
                                                                                                            SHA1:DC29F5AA8215EB09E48953871554BDDA54F1540B
                                                                                                            SHA-256:57304750022F054C5AA0097450C54D20484BF3AA564BCB1E97847FBF6C2E1E21
                                                                                                            SHA-512:04886F62BC6656B18F2CD7077EEFABEE2A8F64953CA37E71BAA758D57D8375DE7A91C56E3E3E7B8B41643A5CC0568982E0AFDB4875B4FCE53C2625B4E7C204E6
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....t............" ..0..............)... ...@....... ....................................`.................................g)..O....@...................)...`......h(..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H.......P .......................'......................................BSJB............v4.0.30319......l.......#~..D.......#Strings............#US.........#GUID...........#Blob......................3................................................!.2.....2..._.....R...........E...........u...........Z.......................A.....s...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):243872
                                                                                                            Entropy (8bit):6.50591783119501
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:mfSRUsXJHsqVpPq+Pu1Nr7tXAjsEpN0Qif+j7kgiuG4krZAuZAt0/+JvyQ4UjIPl:27s5Hsq7Pq+67qjhp+QifuvtzJ4TwM
                                                                                                            MD5:2AB51F750E3B9C69CC2EBC9ABE2EF369
                                                                                                            SHA1:3D19ABE16F55A9366780C2056210B87E9A78838D
                                                                                                            SHA-256:D563C1EAF08DFDA8FD1860BF00FCAB903C85C91A299379D6EF73C3AECA2B7A9A
                                                                                                            SHA-512:13633EDFE2C14117BB77AC7D94D3A2E27C19660F73A8E751F9D73B75C6AACD066954E7EBCD7B11F39A627EA9FD2F2B3455FF90947156AAA1DC664D5387699947
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................" .....@...@......................................................d.....`...@......@............... .......................................P...........(......h.... ..p...............................................................H............text....=.......@.................. ..`.data....*...P...0...P..............@....reloc..h...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):489752
                                                                                                            Entropy (8bit):6.715559969531241
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:X/ZX6ZS+34JkIT8tA7nPgNK4pFI6yB5v3Jx45WX9gLP:XV+Icur4vi5v5x4IX9gLP
                                                                                                            MD5:902DE8298523A79CF1F6E013E4CDE766
                                                                                                            SHA1:0D797B0D06D107A8DE21F72C2ECB6292E5E0F0ED
                                                                                                            SHA-256:E383DE92AA93F424FAEED789CDA2B920699D4A6EC805E5FD46833DAC9CD319A6
                                                                                                            SHA-512:4C0A192E7D6E9BDE627546ECE7287D41184E4FD91AE0DC87D660B5894BF210C27F3E8B1F3E8F5B568ECEF6C29D8AC2980970575EC2ACB6E696391AD88FA9D666
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .........................................................P.......?....`...@......@............... ..................................h......,1...P...)...@......`"..p...........................................................h...H............text...*|.......................... ..`.data...M...........................@....reloc.......@.......@..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):329888
                                                                                                            Entropy (8bit):6.652393975318632
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:x17UgKhUflT6tEFs8Sx/mPueNpQV587It9diIKc1yCC:x17SeflT6tK8UQV58kt9diUsD
                                                                                                            MD5:721811312D3F000E40A403983E60F6B7
                                                                                                            SHA1:DC9E6186A10ADF2419F8DAAC6DBBB11472A3BBB5
                                                                                                            SHA-256:39562DC738F28E2994CEE74207BEE53C833231EC68B2885E403DC3D9C43B6821
                                                                                                            SHA-512:E25E51E6ECAB823691F2E5296EBD257D15521639FBB2994B625433921445F8BE14A4FBB6D4A19A0925B0D7FC07031EE16B48B7DC4396B4A4916626D673B4EFC3
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....X..........." .........@............................................................`...@......@............... ......................................`n.. ........(......p...P ..p...............................................................H............text.............................. ..`.data...-#.......0..................@....reloc..p...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):497824
                                                                                                            Entropy (8bit):6.7965571379271275
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:sSla/DmFHF4oPOOLrBO0th7QT29h9Yfl1yl1gJj0qVbn95n3pcsa0Q:sdDmFHay6ehnO10Abn9d3pXRQ
                                                                                                            MD5:6F5A7B47BF1D61C9B84276A99121BBF4
                                                                                                            SHA1:2A806A697397FAFEC4E9B333251963F43285A085
                                                                                                            SHA-256:391042279B8C582DEDEAEE0CE82B211DB4020B07EDEDD0FF44B6225A702665D7
                                                                                                            SHA-512:9D873B9935BA153EF43B398FB5B11E7CDED24A4885C219D66DC4E48DF1C6E690EA61AFAE2EF95B95EEF761743387DCC2C7CC85D0DCC107C271771FC4700378A6
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....-.f.........." ..... ...@...............................................p.......#....`...@......@............... .......................................o..H$...p...(...`.. ...0%..................................................................H............text...w........ .................. ..`.data...B*...0...0...0..............@....reloc.. ....`.......`..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):129184
                                                                                                            Entropy (8bit):6.114698747717757
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:6Z54JKiEAYbKatyLJSsVkrc00EBR7yxcuk:B/fSessuaRxhk
                                                                                                            MD5:2E6C7A183AD043850BFA731550D43F51
                                                                                                            SHA1:3F6818E1FD9564D38223367DBE03D257FA394D83
                                                                                                            SHA-256:88DFA993884C1277A3ADCBC55EF44B4A38C55EC4F0F8C7768862377BEAE76DBC
                                                                                                            SHA-512:C8D3013E7C9171ADE3C49782394CDCE172DEC85EAC96A84CFAE7C1936666EB4093D7A518CF955D30B3E1189C0C72319A6E58D85731F83020E59DDFEA5D44F743
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .........0............................................................`...@......@............... .......................................+..l........(..........(...p...............................................................H............text............................... ..`.data...Y........ ..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):309536
                                                                                                            Entropy (8bit):6.56574804790244
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:nzv7WOXu33WPEei5EZNqHRk5XDiio9gZbzZYNAgk74dzzKX22zRrRBKZ+FhJDwwz:J2WR1BpLDRcnFIB2ahm97z/+
                                                                                                            MD5:B0A85005B5AAC68913092BEBEE39F34B
                                                                                                            SHA1:4E747E19165BB28054F5895A36ACA213E3B6A115
                                                                                                            SHA-256:984ED1D9AC926AB13FBBD8712CDF3CA5A7701E57C1A22B684541E46ECFBA9979
                                                                                                            SHA-512:86991DC81D38E14F19B7F1C1155F7DDFBA2FC2ABB5E5843C238984C876D5BF01E6F6613F022372226B589056E1ACDA0B7227937939DABAF33311CCCCF583FB0C
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...v.b..........." ..... ...`............................................................`...@......@............... .......................................i..`....... )...........#..p...............................................................H............text............ .................. ..`.data...'N...0...P...0..............@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):30880
                                                                                                            Entropy (8bit):4.7224621314296105
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:9WIhhNwZVjB6ZDDrRvYA6VFHRN7v2/6fR9zjOih:ZhkCDDrxFCll9zjP
                                                                                                            MD5:467E4E772261148FCEFD8620401BD521
                                                                                                            SHA1:AA888D911A45CDCEC352E44776CE3E328D39CE51
                                                                                                            SHA-256:038FF7CF6B72F7F861F75346C6108939F21C792FB689712F7BC7FD42AAE248AC
                                                                                                            SHA-512:18D895E02C5D56031F3406815A8A7D7FBAADBF1752DF3F73741BA04B5472A54CF021AC3ECF4FCB1C6BBD6BCC0B4998BEF67EE2BDEBC8A41A400FC0BAAA8B1A7A
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...-............." ..... ... ...............................................P...........`...@......@............... ......................................d...l....P...(...@..(...H...T...............................................................H............text............ .................. ..`.data...J....0.......0..............@....reloc..(....@.......@..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):334000
                                                                                                            Entropy (8bit):6.389483256864205
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:eJ+s+kfIPvH96Xcfb81vFdqE3vex1/16k9dfuL3ofjm4v70yYZ1384BokKX:qlInd6Xcfg9UceZ7pv7aDfBRS
                                                                                                            MD5:30EA2AC0A36970CB801B8F164B370767
                                                                                                            SHA1:E142030CBDEFCFCAA6538D6C1C6362944940958A
                                                                                                            SHA-256:1E3C574533A854EA1AA537A34B12211F5D1FB99D7ACC266E464DBF990DF599D6
                                                                                                            SHA-512:4E3AF4B1B62E607B0BD47DB61D8765154C1862434BBB37B2F05880084C0C3009486B62F07B851CC7B3D00FABE8D181814CDA5C41D9CB2AA116D45FE03DA57AFA
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....c..........." .........@.......................................................7....`...@......@............... ......................................dI...........(......P.......T...............................................................H............text............................... ..`.data.... .......0..................@....reloc..P...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):964768
                                                                                                            Entropy (8bit):6.564122188888795
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:L63NP3HfSVnK8rt8/gOdudIC0kPWWkTnpH3emGfbtTbW:evQK8regqxWk1XwfbdW
                                                                                                            MD5:8EF1D146E723F4F6DA9B6DC4A679D3F2
                                                                                                            SHA1:5BB1E673C4922E9A88AE7EDF5B1C1BD88A78EC02
                                                                                                            SHA-256:AAD5595E9D7DE9D99A700313AF2DE75AA8BD271246066F9700FDD39A69AA6555
                                                                                                            SHA-512:2BB0BB482C2DDD8494846FF4FDED55A627BF921C2E2165A11CD056517143426AF126324C93AF45C99B483FADDBE80262EDA2EFBD1F48E4B06C6CE6CD52245E2D
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...$..f.........." ......................................................................`...@......@............... ..........................................(w.......(...p..@....C..p...............................................................H............text...P........................... ..`.data...P...........................@....reloc..@....p... ...p..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):39200
                                                                                                            Entropy (8bit):5.1532257055006365
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:gHWF8JBrWvXsWHkhzHE0ue4q+k+ars69R9pnUkO2akIGt6HHDZax1IJhXcKX6HRy:gq8JB6cBXDsw9pns77EiWE6D9zIl
                                                                                                            MD5:5E78166E97851B13B4087A54EF712D8C
                                                                                                            SHA1:5228E45D993D397B7355191C2A50F03334851A00
                                                                                                            SHA-256:E91D3502B52775C240CC81B9D3BF36E503CE9C2640B45D1614BB667AA5C1849B
                                                                                                            SHA-512:67D6194F6975110C67C3966F0AE994AF433780239E9270C47903A1AF0851D44443885A6573271767CA85B1DD795B7D441A8A4CCE15966985E5A352280D7F4006
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....f..........." .....@... ...............................................p......s.....`...@......@............... ...............................................p.. )...`..,.......p...............................................................H............text....=.......@.................. ..`.data........P.......P..............@....reloc..,....`.......`..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1730848
                                                                                                            Entropy (8bit):6.692369218509377
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:24576:mycmIjdj8GrJnZLDflJjD2TRSKIP616WF1IMx:amIjdjFrJnZLDfz/aSs
                                                                                                            MD5:564C9A5BBE41D6CAACB1FA1993CC8AAC
                                                                                                            SHA1:34079090BC4D48F0351673BE7B255C52FA5B6369
                                                                                                            SHA-256:B760CCED33549528F6E101C491A0CAC4064F644EF3E829AE127FD3F09A33FBFF
                                                                                                            SHA-512:1A5D4F000EAB595E7DCA508C94EEAD23AD83C9856C57B9CB18DAF43D5B795FFE4C093A063B99142D2961AAAD33987BCC7DBEA5EC901DFFFF10C57A90D7A685B6
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...@............." ......... ...............................................@............`...@......@............... ..................................P....J......@.. )... ......Xo..p...........................................................P...H............text...}........................... ..`.data........ ....... ..............@....reloc....... ... ... ..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):34992
                                                                                                            Entropy (8bit):5.06686826259634
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:cWd+b6tYf7uMk5Rxo5ka2mXT9FIX6HRN77HtHNsAR9zRWj:nO6tYf710A9eWBts89z4j
                                                                                                            MD5:F1714233138A49F3EE33521D4DBDB63F
                                                                                                            SHA1:42403E139F8EFA7B8FD93643EAB246ABCC52A3E8
                                                                                                            SHA-256:13458987C56DC1E3E4147E3AF9758BEDD02620F776D0A0457234599AA6908674
                                                                                                            SHA-512:23BDA66FD2BD332586F717AA921372711AED61D89A0B1C7EF1654DB74DC72316E7F91078D5027A5CFFF0F308AC71B68E2F3B435E83AE9AB5932688F5DC5B182F
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....gO..........." .....0... ...............................................`......-.....`...@......@............... ...............................................`...(...P..|.......T...............................................................H............text....*.......0.................. ..`.data...c....@.......@..............@....reloc..|....P.......P..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):661664
                                                                                                            Entropy (8bit):6.673728367333183
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:4J5UP48Vd00bmWIQf2VQIhS3dzGpepguWC4bVUl6lJlD2EL66zP0ARZ9dn3/sx1w:5PJddbmWnf2VQ9bgnzVTFD2S6isx91o3
                                                                                                            MD5:537F45E761B7BF2593E86778B1AAC461
                                                                                                            SHA1:36F5AF91AC751FF1DDAC5297E0835388335706C0
                                                                                                            SHA-256:A5E3E04CA99F4B82C761370508EBE6E1DC7FE6B9463E904BA408AFDBC16D5272
                                                                                                            SHA-512:32D9A9C892422CACC9A7554719076DAD65AF3B31C8402247804CC5B66216ACBBE8D773AEB540DC98421E43659BE284E41F60DEEDBF4FE0928302A0CB4997AF49
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...g............" .....@..........................................................S.....`...@......@............... ......................................`...hI.......(...........4..p...............................................................H............text....5.......@.................. ..`.data.......P.......P..............@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):25376
                                                                                                            Entropy (8bit):6.287661962300747
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384://AAaFiTCmM82SuxDJQE3W8FWvmGX6HRN7FNbZR9zLVq:3paFiTCm0DJQoEmWWFFT9zk
                                                                                                            MD5:F6FD1153DDA80799A04EE9351FBC223F
                                                                                                            SHA1:107E1B848C215F30569BFBC200637AFAF60D8C06
                                                                                                            SHA-256:A4D48F2C0F6C22731A57D1336C82EBDCE6E5BA3EE7E13BFD4893979E53132FE7
                                                                                                            SHA-512:1F588633E055FB992DE7B17072A5829E08AEF4A1A0DB6201CC966B7258D342531ABA5A81514BDFA84E41EE0A734848F175064B5C0D2BEC369AA66F9601EB1E09
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....A............" ..0..0...........O... ...`....... ..............................,.....`..................................O..O....`..4............:.. )...........N..T............................................ ............... ..H............text..../... ...0.................. ..`.rsrc...4....`.......2..............@..@.reloc...............8..............@..B.................O......H.......P ...-..................HN......................................BSJB............v4.0.30319......l...T...#~...... ...#Strings.....+......#US..+......#GUID....+......#Blob......................3................................<.....H.........~.......................).r.........;.................Y.......................B....._...................#...........................).....1.....9.....A.....Q... .Y.....a.....i.....q.....y.....................R.....[.....z...#.....+.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):538136
                                                                                                            Entropy (8bit):6.299714405457925
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:q5YDDKStgzRK093ertSfiOMVAXUYYJJOb:qmDxSP6OaLYYJC
                                                                                                            MD5:027854570A4412624BECEE78A10395C1
                                                                                                            SHA1:6B0E6BC0CD97F2CAC1B962BE868FC7CB621D77F8
                                                                                                            SHA-256:2D67E87859ECAEB15C4DD621B0983F1A9AD3E2AA9B11624C018A43E6D6B06BEC
                                                                                                            SHA-512:8593D309434C7954AA42E5BD63F76A5BAE783C8F2130798EA285032C71F890C4C1783614597EE2BA3DA3294A68CE636EA2A9DCB21A858A840C8D8F6316928D65
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~...:..:..:..:..;..<U..%..<U..1..<U..*..3......q...?..:.....q...8..TU.....TU..;..TUj.;..:...8..TU..;..Rich:..................PE..d......e.........." ...&.@...................................................p......7.....`A.........................................|..h....|..h........@.......:.......(...`......0...T..............................@............P..h............................text...q>.......@.................. ..`.rdata...C...P...D...D..............@..@.data...............................@....pdata...:.......<..................@..@_RDATA..............................@..@.rsrc....@.......B..................@..@.reloc.......`......................@..B........................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.665072159776856
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:OzN83OxAhRo4HWabWvFpWjA6Kr4PFHnhWgN7akW2huxu3O6YX01k9z3AneMC:SN8302oCWabWvFYA6VFHRN7pyR9zKeN
                                                                                                            MD5:79563DE651295283F15CA4BCE8E98841
                                                                                                            SHA1:4D6ACA5801A92B02BBA687F7B6BC7E6EC59FDE13
                                                                                                            SHA-256:A58420178170177F772551C4AA7E4807B2672A8655F828600D47A3958CC40F7C
                                                                                                            SHA-512:77CD8D3D9A1AE5DE6A1A49C114FF4316C02E1F696430DE173D89632F96B958CB9B9010DE7B89930E15D177A5BE6E470D358B6330A968EA8ECADA44F7F43225CC
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....'............" ..0..............*... ...@....... ..............................YU....`.................................7*..O....@..$................(...`......d)..T............................................ ............... ..H............text........ ...................... ..`.rsrc...$....@......................@..@.reloc.......`......................@..B................k*......H.......P .......................(......................................BSJB............v4.0.30319......l.......#~...... ...#Strings............#US.........#GUID... ...t...#Blob......................3............................................................=...........h.....#...........S.....i.....8.............................Q...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):96432
                                                                                                            Entropy (8bit):6.098459980747934
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:Y6cypC971fwwSZy9hswibRSsYwlFb7R/gJR7SSNNJkZphyNVdWvmVzS:YUC971fZgy9hswZsYcN76JR7SAfuphyI
                                                                                                            MD5:E039ACA6E9900CEADCFBDBCF094D3A14
                                                                                                            SHA1:E38CEE576F881D512D4217629AB09B795FB520E9
                                                                                                            SHA-256:FAFDAAF0437E2C10B8343E5B1B2C744977B88CAB7585FD27DCC12071B27F46F5
                                                                                                            SHA-512:02D4550D30E3B9FBBE73243BCE8161E9117BBE67610117F11158A2B02DED148BE3A88C99CD6F60BD4DACB704F87E137E488F07CCA48BAD622CEB8F74D418F011
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...Uz............" .........0...............................................P......6.....`...@......@............... ..................................P....,.......P...(...@..(.......p...........................................................P...H............text............................... ..`.data...,.... ... ... ..............@....reloc..(....@.......@..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.698265155355934
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:OL9+i8wxVLWIBWvrVpWjA6Kr4PFHnhWgN7awWyHSZCjVi6KrIX01k9z3AszWmCL:29iuxWIBWvhYA6VFHRN7xyZ49R9zrim+
                                                                                                            MD5:C79FBAB0FBE63D539F5808D867319DED
                                                                                                            SHA1:6AB319EA399E61322A41F059743E3C8C66C4D184
                                                                                                            SHA-256:759C6E9C3EEE3344F73EE6FA8016F27816C2615BB079D1DE9CD97EDA35ADAF24
                                                                                                            SHA-512:83DC117256500B347751D30AB390B3C4F4C371D8053986B44CEE732FA5E540EF60A8CB78BEE73D1A93984B4EDF65782E86424735F58094C259793A7EF91697F7
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...cL............"!..0.............n*... ........@.. ....................................`..................................*..P....@...................(...`......()..T............................................ ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................P*......H........ ..X...................P .......................................N;#?D.a...]..v...!.1CnF..).d..n...!..d.j.Y...J..|.8}....G=L....V....[..W.M..A...*V......2aR.E3".....bou.tc.:...{..Y..*.BSJB............v4.0.30319......`...8...#~..........#Strings............#GUID...........#Blob......................3......................................D.........]...........v.................\.r.....r.....`...8.....0.......r.....r.....r.....r.....r...}.r.....r...........6.....
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15640
                                                                                                            Entropy (8bit):6.836441141207769
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:kiGp+xfkPWhhpWvpWsWxNzx95jmHnhWgN7acWYH8AgfcMbnoQNpX01k9z3AZs88o:ki2EIWhhpWv4zX6HRN7v8/7R9z56
                                                                                                            MD5:D3BAAD7A5DB953DE71AA459841CC37DB
                                                                                                            SHA1:CB94AD1EA3706C7346CEB305ABB6B47436671636
                                                                                                            SHA-256:A682B72F9D80BC517F197A0FF85CD2858EB743D8CB6E8453C946E413BD10C0E1
                                                                                                            SHA-512:7680F910655B9BDC99DDA93D62F936FCF2C57931D7A324316D53571E2F069F691EAEEA2FE30AF1F08CC24E07D188692EB46D9A8CF6AB21CC7FB3FC391346DE2C
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....q..........."!..0..............)... ........@.. ...............................C....`..................................)..Z....@...................)...`.......(..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H........ ......................P ........................................g~W..<.ah...>]~KNh.n*...=.t,.'....Z.h,.*&...B|....d.F..i.o.....>~.8........W...I.........qnk.6..P'../.K.!..<.t"..{BSJB............v4.0.30319......`.......#~..(.......#Strings............#GUID... .......#Blob......................3................................................"...........;.l.........f.....!.E.....E.....>.................E...[.E.....E.....E.....E...B.E...O.E...v.............
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):669856
                                                                                                            Entropy (8bit):6.738177589721567
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:WauvNG3LGljZ0W5Yk0ZdmNtAj0mhIPLboapg1i6k90QdsAYcNCYq:WagNGbG2vBx093n6MVS7cZq
                                                                                                            MD5:621801207C70925E83F806DBD9954A4F
                                                                                                            SHA1:AC257BE3308F039A09E0439C4111F7FAFAED12DC
                                                                                                            SHA-256:4B1C1C6254C0F73E5CC110F3BB3E342D11EFF16ECA5F0F678E5158E896DC67BC
                                                                                                            SHA-512:82C842AB166058DAAA31CCED435D29BC996ECE3E7295C0F934541AB1B1969F2A9221612573BB3CD85412A98AE1780A9A2C5E38F3E34E2385300F5EA56D622F74
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....1..........." ..... ................................................................`...@......@............... ..................................p...`....7.......(..........0+..p...........................................................p...H............text............ .................. ..`.data...h....0.......0..............@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):186528
                                                                                                            Entropy (8bit):6.415230610741847
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:pSw4kXyyyLNMWWqfY8SJYrjXQori1RqU2TOK1xguZunS:VCyyKSA86YrkorvU2rfj0S
                                                                                                            MD5:287EDFA9B689281780A9475A99A587CC
                                                                                                            SHA1:B29E4F6C62D1C1FC83BD4DD9F73405F8173FD28D
                                                                                                            SHA-256:FA4952DF244AC5DD6D5D36B62E25B2CD0BF844453196D29838638518CB6944B6
                                                                                                            SHA-512:7D2BB2334D641E4831C3F2A4A304AB82DAE11B5F06718524B479D27C5B151212692E97A114FA40B7BB8610DB8FEBDE4B2BC2EC8A4C555197D295AF057B636C08
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....T..........." .....`...@.......................................................~....`...@......@............... .......................................N...........(..........h...p...............................................................H............text....T.......`.................. ..`.data....&...p...0...p..............@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1963680
                                                                                                            Entropy (8bit):6.322902076881355
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:24576:YPUQbNPsGu5PpXSMUgKrSfzOwv8/eczsn8KQj2US4kSn2RxUJ9LUdpjK8hVDl+G:s1Pu5cMUgYuCwjconQj22kS2vY9L27vf
                                                                                                            MD5:9B5895322EA58963C2C26B6AD0212A14
                                                                                                            SHA1:8A182CAC411C051CF514B27C42E0D315BD6B55F3
                                                                                                            SHA-256:C7EE407CED4846577A1E8A67EF61CC920010C4F126933774EDC24F46D43714E2
                                                                                                            SHA-512:0770B67B94C5063FE670E9A4D5FCD1997139DA632861814D3B9A2EF4E6E0C38F0816C2E63B43E6EC17007F139A5147DB0CB61C804D865A311F13364B5706C198
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......L..E........................................................:........................~..e....~..e.......e.b.............e.......Rich............PE..d....-.f.........." ...).H..........p,.......................................P.......q....`A........................................ ...T...t...@................K.......(......d7...#..p....................&..(.......@............`..h.......`....................text....G.......H.................. ..`.rdata..Xh...`...j...L..............@..@.data...........t..................@....pdata...K.......L...*..............@..@.didat..(............v..............@....rsrc................x..............@..@.reloc..d7.......8..................@..B........................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):338080
                                                                                                            Entropy (8bit):6.5467859190265045
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:KXlZtqaP75HL9eEIdkh+T9jb3b41PlmF6YZTdiX2JWb:KXlZtqweDdmMy8Wb
                                                                                                            MD5:A19AEDFEB37A15AFCCE8BCC5D4D78EC3
                                                                                                            SHA1:E0805A04BC3F3B6AF99DCB066A49940E64F2F2E7
                                                                                                            SHA-256:3468B4717F086423052FCBD305CD3151CC555EF0045B9269D43CCEDCA838E47A
                                                                                                            SHA-512:C2D939074F5EA4C28770556CEA5C5DCD2A173BC6D0A0BFBA43A7A29965DCB907B2390C1D0DAF74F07BDBBD572DAEB55A85FA15C87A81730AC84ED151526660EB
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .........p.......................................................^....`...@......@............... .......................................w...".......(...........%..p...............................................................H............text...+s.......................... ..`.data....S.......`..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16144
                                                                                                            Entropy (8bit):6.745282705194393
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:qjMTlhAxYPWuGWvlpWjA6Kr4PFHnhWgN7agWFdYPKDUX01k9z3AWipYNX:qjMTlMyWuGWvlYA6VFHRN79pR9zvHV
                                                                                                            MD5:9CCB06FECC5F840F88BBE8E7C9797CAC
                                                                                                            SHA1:75D00AF394B6E8406C5DFA3E7F96A68363368FC7
                                                                                                            SHA-256:C160277C510E5A535B2369A7B12135E2E790EDD1F34EC2B1E2FC80ED8DE475C8
                                                                                                            SHA-512:064B5AE4FAA13A3C68627F1CFC88E9B883179CF64FF14110DEE4AEE49F278DD66402BDA29B78ECBB9F3368A5A52A35C647C79D8EF7903B15BFE9725B5C5FB883
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................."!..0..............*... ........@.. ....................................`..................................*..X....@...................)...`.......)..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................*......H........ ......................P ........................................-*f;..??..`.~5c+)q5.b.[.....?q0........G.&...r<p....N.b.I[e..u,......fu....e.d....&G. ..?_t.[/...e..!..4.,6../.]|.G..K.%.H..BSJB............v4.0.30319......`...(...#~..........#Strings....0.......#GUID...@.......#Blob......................3..................................................P...X.P...p.....p.......v...V.....z.....).......1.....1...?...........>...............................P...........
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):2050208
                                                                                                            Entropy (8bit):6.677577580791444
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:49152:HUy8hZ9wf3V7i9KAgmJE2Jjd/mxObmVw6Q41x:HU4QRgeL41x
                                                                                                            MD5:814F7E26E5AEECCEC424393D142FEA98
                                                                                                            SHA1:A9F8B6CB03EBE4E64E2B17FB4E57C17D24B7B00A
                                                                                                            SHA-256:60F3B82345E2812DCFDEF98642B2CA707B34C51D917D86615DF309714EF1E9D8
                                                                                                            SHA-512:46FF8137B77EF79BF5C8CEDBC35F263AB671641B50E0C16D705B744A9E902E1D6349D58570D3BBF4532CCCDD8DAAFBB30C2173C52E02734B589303516ACB43E4
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .....`................................................... ......c.....`...@......@............... ..........................................d.... ...(..........H...p...............................................................H............text....U.......`.................. ..`.data.......p.......p..............@....reloc........... ..................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):43680
                                                                                                            Entropy (8bit):5.842163683540018
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:768:C+1fsSED2vCeDQvRzXB3gWql6375IVxedktN7xPBhwsR/JG39QRoNvsh2JcfoDLf:2B/LuYdy50b4b7RSHnbOiKmVzvP
                                                                                                            MD5:EA2E0866F900117135C1771D85281303
                                                                                                            SHA1:EC58A506017621DB3233D1513D28727EA2FA7C7A
                                                                                                            SHA-256:819E11FE3C456DFD56377233B2BAE5BC11FEF41FA3A8816ED30FAFFF74A2090F
                                                                                                            SHA-512:4FAE0463DD343E74D73401E9724E17F044699CCCCEE3873467A0171360FA1F0AF080178A71AD7DDC7878218C9069ECCD9B7B85557E699FAC0CDAAA28BAE0C40A
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...3............."!..0..x.............. ........@.. ..............................{.....`.....................................Z.......T................(..............T............................................ ............... ..H............text....w... ...x.................. ..`.rsrc...T............z..............@..@.reloc..............................@..B.......................H........ ...u..................P .......................................n.-9..0...l..3./?Z<WL*.c7..+h.(.......m.!e....}..u.:. I.G..#>.DMl.g.t^.!.OF.X.(..&.$......3.p......'q%W..k9...=...|.s.IBSJB............v4.0.30319......`....2..#~...2..T@..#Strings....<s......#GUID...Ls......#Blob......................3................................{......#...........6..`..6....m6..(7....4.. .....%.....%....m#.....6...!.6..&..%.....%.....%..s..%.....%.....%.....%.....6..........
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):17056
                                                                                                            Entropy (8bit):6.59164397370935
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:DnA37W6LWv2qYA6VFHRN74G/6fR9znQJ0:Dnka2qFCl4t9z9
                                                                                                            MD5:5B8D61FE9D1525A7F1479001B5ADFA91
                                                                                                            SHA1:92A41489B496F19730C99AC70A3F4B85AA9A4024
                                                                                                            SHA-256:7AF94B0D91DE391BE95AB3DC816EAD7072CB2354199773FBB05C2D3AC1C3F871
                                                                                                            SHA-512:B9D843B6501E304D971CCC8C3B579E4430E4D7C05A2122EE28DDEBB017C5A0EC1A348BEE7D1C6E1DB11EEC01FCE6F11909284ECABE079ADA742800D94F34F235
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................."!..0.............~/... ........@.. ....................................`.................................#/..X....@...................(...`......,...T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................`/......H........ ..\...................P ........................................J......#.}1..T\>..M.].WQN...I...)0.!.Zc..........9....;{*.z...K=J...6.c.Dr.!...q..^E.e<B.....tM.!.^.\....+....^c.p...J.`.BSJB............v4.0.30319......`.......#~..P...d...#Strings............#GUID...........#Blob......................3................................M.....I.........B.$.....$...[.....D...........A.............k........."...........{.......................b.....o.......$...........
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):456864
                                                                                                            Entropy (8bit):6.54420536200444
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:KHcXqG6bINOxPS5n7aGTh6npadBcV85eu:K3GjOdY7wBu
                                                                                                            MD5:3C8EA9AD233098B980F254A5CB0A01A8
                                                                                                            SHA1:B95600708DE3949EEEA51E27868988B1B66F867C
                                                                                                            SHA-256:1D391B2A96A07D45236778B81FE80CAD479B194FEE464900B5C551E896AA2F53
                                                                                                            SHA-512:3ABB1EA3C626922BB677A97B109CEDCF349FB23E87CB14DF1037F08E2DA333FA5A8BF156FEEC87E25776C4D24D0423C2B4FDBBA406866BD84998F9778129259B
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .....P...p............................................................`...@......@............... ..................................h........(.......(......p...p;..p...........................................................h&..H............text....B.......P.................. ..`.data....[...`...`...`..............@....reloc..p...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):101024
                                                                                                            Entropy (8bit):5.497003708267034
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:kYsYXj0p2NYq5V4bgDHsPdIpuSE5L3Ukcz9wFgi+CzN7f:xMkYe4bgDUAxCFglC5j
                                                                                                            MD5:9332AA569690A1135EC72AA1EA9D1EDE
                                                                                                            SHA1:3662B089DF497BE01400C6B609D87D12162AC7D2
                                                                                                            SHA-256:E7BF779CB608124A7812160CE3D8BBE83C1E49C46A81EE0C2DC91447F191D1BB
                                                                                                            SHA-512:5B4A11F3A9B66406489CDDEA7BBF338A9F7F7EC834CEAA5EDD8EB8194F6A58667880EFDEDD4FB870E5E20EB78C43BB51733369F897C3E9B9A3C370DD15120FBB
                                                                                                            Malicious:true
                                                                                                            Yara Hits:
                                                                                                            • Rule: JoeSecurity_GenericDownloader_1, Description: Yara detected Generic Downloader, Source: C:\Users\user\AppData\Local\Programs\SteamClient\is-EL3N4.tmp, Author: Joe Security
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...jQ............" ..0..X...........v... ........... ..............................;.....`.................................?v..O.......4............b...(..........hu..T............................................ ............... ..H............text....V... ...X.................. ..`.rsrc...4............Z..............@..@.reloc...............`..............@..B................sv......H.......P ...T...................t......................................BSJB............v4.0.30319......l...`...#~..... ...#Strings.....Q......#US..Q......#GUID....R......#Blob......................3............................P...,......H.........5....:....'...m......,.@..5#.T..P4.T...7.J...B....i5....u:.T..n7.T..&1.T.....T.../.T..(7.T...(.T.............................)....1....9....A....Q.. .Y....a....i....q....y..........................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16648
                                                                                                            Entropy (8bit):6.674662538277605
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:HaTGqLWl2Wv4MYA6VFHRN7paxMR9zGV5wwgTp:HaiqeX4MFClpp9zTTp
                                                                                                            MD5:9D85EDC5D0EFA8F803820E3D40FCFA23
                                                                                                            SHA1:73E9BFB4AC2B7B9424B7DBD5D257DF1E04945A32
                                                                                                            SHA-256:560E53DE0E025CDE566C2C30080DA83E3DA28D592D5BCFFBA78CCC6198F2B2A8
                                                                                                            SHA-512:BD15EA96737C7AE62C75218BADD5C979656252BC30DE81718EC07A0C177B2A268157A82EEDAB838EA2B4690D8AD609297DC518200F377878DF986BB5910772C1
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....]..........."!..0..............+... ........@.. ...............................@....`..................................+..N....@...................)...`.......*..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................+......H........ ......................P ............................................6...(~s1..(IE.?.>.1..1....~4...#.m..9.5{.....pz.j..eU...~.Lf../W.c.\Sf..].@.O..........x..%......pi..g...z5.+...*.8.HBSJB............v4.0.30319......`.......#~......H...#Strings....4.......#GUID...D.......#Blob......................3......................................Z.........9.........................,...5.............{.........F.............................#.....p.........................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):51464
                                                                                                            Entropy (8bit):4.966231479839345
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:qOwMiFMwIImR3GwWxUezVsPkDb6i5DC4dezFTa:qpdm5GwYxEkDb6KFIta
                                                                                                            MD5:3CF7102500300B05DA0684577ED54202
                                                                                                            SHA1:7DBD4086C08A45C405AD38338E1D0B4306671B09
                                                                                                            SHA-256:64889EC4D820F87797894D0DBCE86240830F8DEC085A3C1DC6E21250F512E34E
                                                                                                            SHA-512:C7AE087E7E30DD14315DC4AA4C70E4A7C94F272C41BB49D3041F18474240D895371DF0ED2373AE92FB561004324565D52237C21607F7C0BA3DAD33CD61DA7DD2
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...0.'..........." .....p... .......................................................#....`...@......@............... .................................. ................)..............p........................................................... ...H............text...Zg.......p.................. ..`.data...............................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1075360
                                                                                                            Entropy (8bit):6.616695520960553
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:yPiP0JcnrfOsdV0Z8oApKK1sPTdokGH5OTNWLOdN2XyhtAVv5d6wGGDSxw0aY1ne:yLmnuuy/6TlGGD6zaIn16O9LH1unv
                                                                                                            MD5:29DC8A1515153483DC01004EBFF4EA6F
                                                                                                            SHA1:5981CDA980A00577D8B0D4777315417B12730256
                                                                                                            SHA-256:3C65989CF6C67DE98E21CE52A607F2A49F335BB465937AA9BA994B0F8C86E541
                                                                                                            SHA-512:BD71C0C1BBCDE7F540AA25BD03A39301A8704F63D33E1FBD7CB98C9D3117CA68A4447DD43FB78B8D26B98727408DA02CFC2435B0296543DF8886B7456D4C6346
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .....P...................................................@............`...@......@............... ...............................................@...(... .......K..p........................................................... ...H............text....B.......P.................. ..`.data........`.......`..............@....reloc....... ... ... ..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.684545508308997
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:+t1KdJWg4WvvQYA6VFHRN7N3GtHNsAR9zF0T:+tMdtJIFClNEts89zmT
                                                                                                            MD5:AAD69625CA4EA9ED2176D8E11DB56E2C
                                                                                                            SHA1:3F3D9E94B07D40135DFB0A294002BA00BF866E6B
                                                                                                            SHA-256:97C5A3EA6CC5086323EACE63B8DA07DA484055CEDA72856B98BDD507A6080B02
                                                                                                            SHA-512:7C7614D77604B4E94E1C7AF45F0642DB8C8553D8AB2ECCD166EA4BADCB23802D191B59466E3C1F3DBC29B1CAEFFB2C666BDD1C9082613CFBB8FCFEE70D1FCF24
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0.............>+... ...@....... ....................................`..................................*..O....@..T................(...`.......*..T............................................ ............... ..H............text...D.... ...................... ..`.rsrc...T....@......................@..@.reloc.......`......................@..B.................+......H.......P ..<....................)......................................BSJB............v4.0.30319......l...$...#~..........#Strings....@.......#US.D.......#GUID...T.......#Blob......................3................................................L.............................p.@.....@.....,.....@.....@.....@.....@.....@...l.@.....@.................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........:.....C.....b...#.k...+.....+.....3.....;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):17568
                                                                                                            Entropy (8bit):6.594046728282668
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:j63EqCxAvK2WIBWv59pWjA6Kr4PFHnhWgN7awWneCjVi6KrIX01k9z3AszWInEn6:20qIOWIBWv3YA6VFHRN7R49R9zriJ6
                                                                                                            MD5:3D57375A1B2FB9E988E522F05125C445
                                                                                                            SHA1:B11D29EED40A5F27A20186C8A31F97098B54CB37
                                                                                                            SHA-256:3BB8895B734D1967615845BD34FE9A3BB7AEC23546D1E55C16678697B92E466D
                                                                                                            SHA-512:C31248443035E571CCBD87996DDA2F2898EBB5665EAF99B8799A046D7C6F6D4FBB1B2DE1F5B87BE56D8A6B4181EDFBDCA8D0C873AE0856F1EB0E801349DC07F1
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....H-..........." ..0.............R0... ...@....... ...............................P....`................................../..O....@...................(...`..........T............................................ ............... ..H............text...X.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................30......H.......P .. ...................p.......................................BSJB............v4.0.30319......l.......#~..t.......#Strings....|.......#US.........#GUID...........#Blob......................3................................>...........................?.....6.....j.....%.d.....d...U.M...k.d...:.d.....d.....d.....d...!.d...S.d.....H...........................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):862368
                                                                                                            Entropy (8bit):7.456874615261393
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:5f7xn7kZQ6kliVreJIHHr0tRYbKr2KtG9VKABC6rPQYBKgTWeUAm:5D9km6k/IwRYbiBeKGCHYTy/Am
                                                                                                            MD5:BD45A5557BDB95B90A2B51CE1C82E868
                                                                                                            SHA1:576C6EC24EA8DAA10FB7C8360B867C26A78CD9FB
                                                                                                            SHA-256:F22C997008FDA321A85557778F5BF95F369AE6DB161A52D4BB08CEA6991215A2
                                                                                                            SHA-512:989CB3A5B896644775CF5874E99E8DFDA3654AF6D7E8AEA7B38769078B67CF2B87B475A0D494D1717E83C4CA7A11B15895B01BD0C16D122F101E1FC46EC05F00
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....+............" .........@.......................................................O....`...@......@............... .......................................B..p........(......<...8...p...............................................................H............text............................... ..`.data...`!.......0..................@....reloc..<...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):276744
                                                                                                            Entropy (8bit):6.735103537020919
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:zH8+KHhcm1xa3ZvGFehyhyO28ibc8wXD6GK:zPChcm1xachD2PbVE+GK
                                                                                                            MD5:34E8718BED9FFCB954586F833672F548
                                                                                                            SHA1:EE3D827879373D2AE7708D90C6916EFDE84B98BD
                                                                                                            SHA-256:635D3192EBC262DCEAFB679C30D63A06375D686E9E9BAD9E43B1914B4ACE483E
                                                                                                            SHA-512:A406540C34C699BDC6EA69635047EA206E295CB1E6C2EF80EC9C0374B74F2FE4C3754B309ADB2BD173D8F4D6261DB6BE6570B518A7FD7D2CBBC4304921A38923
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...d6(..........." .........P............................................................`...@......@............... .......................................n...........)..............p...............................................................H............text.............................. ..`.data...h=.......@..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):7989512
                                                                                                            Entropy (8bit):6.799190907572347
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:49152:xgKjbhmQzKo84xxpBR2ZPQ3DtqDTXNaVC8v4aYzqNmKG82o4AgcKVLDSvdEAzsfr:xlRDDnVul2QSvdEhYw2gfW5WUFH5chT
                                                                                                            MD5:1B47420D8AD2071CDED2C944E3F6C984
                                                                                                            SHA1:157CD6B1DC208BAFCCA11282FB3B6259D9D5DCED
                                                                                                            SHA-256:CFB4DBA4AC73773F5EAC02006F0FE7E6399CD67F5A12B4CE26C9F0F406A7EDED
                                                                                                            SHA-512:4ECE5BE567CAC3751FFFBA31FE00F73458E205F658A3C55AC42271D00E43CEDA2ACE6C0D59272B527B36A83EC1C340A1FB7EBD9B041FCF841BADB0B6B92FC80A
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...X............." ......s...................................................y.....Z.z...`...@......@............... ..................................p............y..)...Py..h.....p...........................................................p...H............text.....s.......s................. ..`.data....Z....s..`....s.............@....reloc...h...Py..p...Py.............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16136
                                                                                                            Entropy (8bit):6.746130186809866
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:VWqx+7wWEUWvFpWjA6Kr4PFHnhWgN7acWHx6RMySX01k9z3AhV5JC4qRH:8wawWEUWvFYA6VFHRN7nMR9zGV5wbRH
                                                                                                            MD5:DF0207D04392D91A07047F9309B5DB3D
                                                                                                            SHA1:AC61281D2717E1DC8E78BAC27BC84DAAFF4DB1BF
                                                                                                            SHA-256:80C531B9CEE91C4B770264ADD3788E7C55E168DAB69A880616E25C288C1AFD1B
                                                                                                            SHA-512:BBD5A9BD24630787E99A806DF0CD178F604398043F0CF65D4CC7191C052B427EB2DD50D86F455D02D04373E7C73C319B079DBE47AA9F2F05726C6CD5F2B02BEC
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...U.o..........."!..0..............*... ........@.. ....................................`.................................;*..P....@...................)...`......0)..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................p*......H........ ..`...................P ...................................... k.}A...<........H.y.;...J.2O..\.. ./.)J....5H..G...b.G.S......>......N.....QKm7a....B.)dn..".)..u...;O..~....{../c.w..i..aBSJB............v4.0.30319......`.......#~..l...D...#Strings............#GUID...........#Blob......................3................................................"...........;...........f.....!.b.....b.....7.................b...[.b.....b.....b.....b...B.b...O.b...v.............
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):59672
                                                                                                            Entropy (8bit):5.885523824307154
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:rn/dGA98odbfSYCDVgHvwkcm7WwvCwmEWGzR:rnrq7KHoTeWSNtF
                                                                                                            MD5:EB5B2FB46C0F5AB93ECA0C5DB054FFE0
                                                                                                            SHA1:E1AA25DDD2C359FB08B260180B8AE3A651953A33
                                                                                                            SHA-256:77B8748C3ECDA6E06BFFAFE34F14840185E2AE2FB3ABE3A4F6B577323C23EE62
                                                                                                            SHA-512:EB9128389C0C3F36D832118EF706761A08D9AE33789AFE190023B3170D2ED11C7E8EC704D45544B775AC94F46CC673C09D582AC6927E8445747851D747DC9875
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................" ......... ............................................................`...@......@............... ......................................< ...........)..........H...p...............................................................H............text............................... ..`.data...............................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):133400
                                                                                                            Entropy (8bit):6.277895373459539
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:Zj3t+/k1S+F3g2vlsEjd2fzs6FlsdJQ/WoioIa3cBPdzcWxRC4dezFTDkn:Zj3tYkwQQQmEjd2ZFli6/riY5avItDkn
                                                                                                            MD5:4D0F0F9563809C92DD1A38DEB4E24F33
                                                                                                            SHA1:03D2328EFB08D1E86686F8876595A162753BE374
                                                                                                            SHA-256:20DDABA930EE090B47FA38722EB0D5D23C9F860E45B3A2C1F03CDB4EA1B69C53
                                                                                                            SHA-512:DCDE9B8BEA8DD1111B2908FF89C96FD8CAD0812881E359EAB59BDF13451F5FF1DD50EADFC2FA2489B8B60A90926DBADC9D4641196974C65442006B0F142B5ABA
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...7.<..........." .........@............................................................`...@......@............... ......................................L7...........)..............p...............................................................H............text.............................. ..`.data....#.......0..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):551184
                                                                                                            Entropy (8bit):6.571055787933049
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:KmIFBDqpp+4F/B7VRZ3KYNB0hZJ6c7fkDNRd2B/eBl3EWZg0gG/qikXOG4drks:veip+4F/BJNuZJZx++WZgoQOzrks
                                                                                                            MD5:57905BE512F822BCF59258FBF2448DF8
                                                                                                            SHA1:27828B211218F240CE1ED73997BFC7B0A04527D8
                                                                                                            SHA-256:CDAD57CC4B992A6BBE2BB79BACD6DD28D248694BF089731BB474BEC682CA77C6
                                                                                                            SHA-512:9B2044A712E59FE7F6BDAD8420FD21451E5679D7AECD7B4479341C7AA27ADA290967CB32F898A899BF6E344A88F1FB7285EB214A98792C760BD374EBCBDE02B5
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...%............" .........................................................@.......O....`...@......@............... ......................................T...0*...@...)...0.......,..p...............................................................H............text....s.......................... ..`.data..............................@....reloc.......0.......0..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16656
                                                                                                            Entropy (8bit):6.715593579536355
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:OvV8AxNaHvxAPADWZfWvT4pWjA6Kr4PFHnhWgN7agWkzKDUX01k9z3AWipd6T4:+EHZjWZfWvsYA6VFHRN7rpR9zv6
                                                                                                            MD5:A52D0E2B5EDA30DA599AB9EF536EE43F
                                                                                                            SHA1:C2CA58894F9B26B27E090BAB6D483546C1F83F56
                                                                                                            SHA-256:F45FBB7D188FEF81BEBFC32F177335FCCB6CE9E9BC014CBB99752D8F085CEEFC
                                                                                                            SHA-512:4C9FF15E1BE5B968990726BE10C2A910187E368AA6E9AA55F9235438F036F50B3D04B40DD6C9BC3EFC2AC2C275F2183A750E033AD359646A20A6AF6045E07719
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.... ..........." ..0..............,... ...@....... ....................................`..................................,..O....@...................)...`.......+..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................,......H.......P ...................... +......................................BSJB............v4.0.30319......l...<...#~..........#Strings....0.......#US.4.......#GUID...D.......#Blob......................3......................................d.........J.!.....!.........A.......J...n.....,.........................................j.........................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.713782816724895
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:yzRHy1MW92WvNYA6VFHRN7hUtHNsAR9zF06Im:yzRS13XNFClMts89zm6J
                                                                                                            MD5:14C84085F431CE7FBA0F91AEC4448847
                                                                                                            SHA1:97FADEBD3354FFCCBE81BF2B0B29F7FEC60AFAC1
                                                                                                            SHA-256:432AB703B7DFA567EC4E9C4717DFD2B9BB0EC8F373DBDA0771C10A5897E08D9D
                                                                                                            SHA-512:5CA5F10ECBC7575F6C022BB1B45498F0F8D0417CB5CF4B5F647971C439E216FFA51526BCFA2FB39997D3C01F0F129228A2A3401C164AD756D1F1D807D1BD112B
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...Xmn..........." ..0..............+... ...@....... ..............................._....`..................................*..O....@...................(...`.......)..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................*......H.......P ......................L)......................................BSJB............v4.0.30319......l.......#~......p...#Strings....h.......#US.l.......#GUID...|.......#Blob......................3....................................../.........h...................................J.......a...............-.............................../...........................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):136984
                                                                                                            Entropy (8bit):3.9056973889632753
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:HIH591YWvh7xR+l5dZU49N9SqignwJ5cvBMgSIctpoECyIWLzH:HIHhal5dZU4dSqHns2SpSkIAT
                                                                                                            MD5:136282A8FF7A4730B2F719AFA5DADF90
                                                                                                            SHA1:A86A5911C6BE4CE1E9535FC3F993677050EA5F15
                                                                                                            SHA-256:95EED17CA001846333831DA4DB370FB838AE114CCE512DB31380E8B45C464024
                                                                                                            SHA-512:3061C63242A95554A9855652D750FA3609860637EBB020A94CF3656761C182F0A1E15CFC87C6276BEF34FF75CDCB3FEDDA1E3B74D33A4E1B27628A36FA4302BB
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......%%=.aDS.aDS.aDS.q...`DS.q.Q.`DS.RichaDS.PE..d......f.........." ...(..................................................................`.......................................................... ...................)..............T............................................................................rdata..X...........................@..@.rsrc........ ......................@..@.......f........j...l...l..........f...........................f........l...................................RSDS.. 2v.ZA.].`S6Sc....D:\a\_work\1\s\artifacts\obj\coreclr\windows.x64.Release\dlls\mscorrc\mscorrc.pdb...............................T....rdata..T........rdata$voltmd...l........rdata$zzzdbg.... ..P....rsrc$01....P:.......rsrc$02....................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):55456
                                                                                                            Entropy (8bit):5.787077196786641
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:768:RZtyjfZsPdcoZZtWjbOQSW3sfy91AxQSvv3XvPHlfe2FCl1DuO9zr:RX0s1dZ4jNSW3s6cQSvv3XvPHBBi9zr
                                                                                                            MD5:FB43BE837BF3B54DAA6CA9DBB875AABC
                                                                                                            SHA1:D891C123A71A6C458DAE3BFBCADF0CB6D4472F06
                                                                                                            SHA-256:1729EE8E1CF5FC6EF86CF9AEF5BD2F689C0AEA02055963BEFE23ABE4C49F701C
                                                                                                            SHA-512:F949B1C09F7A6521282EDC49EF1162046F8E6F33298C4B6ADD25B3B0A9ECD646270DD60865C7CCE882FAD2E0DDF81300874B410AC246BF5995E50732BA5DB755
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....p..........." ......... .......................................................\....`...@......@............... .......................................!...........(..............p...............................................................H............text...(y.......................... ..`.data...A...........................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15520
                                                                                                            Entropy (8bit):6.724762605096555
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:bF7xXs50WANWvqGMpWjA6Kr4PFHnhWgN7awWmCjVi6KrIX01k9z3AszWTA1MCu:J1XWANWvRMYA6VFHRN7549R9zriU1MCu
                                                                                                            MD5:4CE41C17B5695E5A862531C9CF10049C
                                                                                                            SHA1:2647BCC625BA83DC830827B97063A7CAD92F48AC
                                                                                                            SHA-256:7EF9E8E2D7E8BCF66C0A1A22D6709D4732B4CCDC61F395A364DA9591FBFDA5A4
                                                                                                            SHA-512:9C3725C5C94620C08A5489BA186DCD42BD4262398FB64356ACF93E087E1865EBB72536A4730F97F540DE36F114ABA1E70E1F2490F894DD33B1625F18B5817C7B
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....p..........." ..0.............Z)... ...@....... ..............................{!....`..................................)..O....@..T................(...`......((..T............................................ ............... ..H............text...`.... ...................... ..`.rsrc...T....@......................@..@.reloc.......`......................@..B................;)......H.......P ..X....................'......................................BSJB............v4.0.30319......l...8...#~..........#Strings....\.......#US.`.......#GUID...p.......#Blob......................3................................................'.f.....f...e.S...............K...........{...........`.......................G.....y.......-...........%.....%.....%...).%...1.%...9.%...A.%...I.%...Q.%...Y.%...a.%...i.%...q.%...y.%.......:.....C.....b...#.k...+.....+.....3.....;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):88336
                                                                                                            Entropy (8bit):5.879093770998518
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:1fNv1C2lUQAOT1sJu0Z33qpE3JZr4GBo333333333333AQ3Hkkk33kLHtSaiOpTe:11dVl5Apu0ZqpmDr4G6333333333333g
                                                                                                            MD5:401E2BCACEA756C5452E02FB3BDF39A1
                                                                                                            SHA1:E4EFD4116196365376EC8082E16DE95B6FA7BD7D
                                                                                                            SHA-256:61865DD41C1516623E403109118DDFA7645FD95121CBAC0583BA1CA2D541E556
                                                                                                            SHA-512:0BB32643A9D86D047EF359D91C60634823F7220473C53CA22AE9A92B6A68A60CA60C383290846107828EC39CA52A16566A3879A3047211AFC0D7E5466F1A19A0
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....r..........." .........0...............................................0............`...@......@............... ......................................h).......0...)... ......X...p...............................................................H............text............................... ..`.data............ ..................@....reloc....... ....... ..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16048
                                                                                                            Entropy (8bit):6.76076698039701
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:RCVT05B091ncmYdJfFWCXWvL4X6HRN7N49R9zriD:8VAMopWL4WN69zu
                                                                                                            MD5:1748BB8AE9ADB170599FBBF94B472B8C
                                                                                                            SHA1:A8C8C75A96743945325B9FF652FC99F3037EBC4C
                                                                                                            SHA-256:578E16D2A7B2C1647F925A611962CF256D8915121B86B5A9EDDEA82A9B3C012F
                                                                                                            SHA-512:08A8E6F71445C2D84075111B889618B7935D70312A33E165525210DD96EE9DE5287118443A87EBE6811CBB0334F574762EC2CCFB8A63E625D3173559EB959EE4
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0.............V+... ...@....... ..............................J.....`..................................+..O....@...................(...`.......*..T............................................ ............... ..H............text...\.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................7+......H.......P ..0....................)......................................BSJB............v4.0.30319......l...d...#~..........#Strings............#US.........#GUID...........#Blob......................3......................................s...............1...........A.......O.................................W...........1...................p...........................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):100632
                                                                                                            Entropy (8bit):6.038277233896664
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:Xl4Xlu9IUefYv9AfOWog+qBWO7bBjLLEORWNzrT:Xl4XlDl89Bg+uV7bBjLLEOR2fT
                                                                                                            MD5:4F6F32BEE2BC12E8C6087488D856AF5D
                                                                                                            SHA1:AFE5F7581CB31B6934F31C9410AF4D08EE5934A2
                                                                                                            SHA-256:8971C704C33BAFE87445FD4B8E5417E2824F8F878052B11BED2AD02F7DE31DA0
                                                                                                            SHA-512:EC0416BF1B814CA94A6FAAD2B97A605BA01BBE4D62697088C665908A6EFCABFA9834E4A7C45FD4BD5DA34E59616E49607D11C9F8335946B30DB01E76AB2EA0D3
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................" .........@...............................................`......D.....`...@......@............... .......................................,..<....`...)...P..x.......p...............................................................H............text...[........................... ..`.data...s!... ...0... ..............@....reloc..x....P.......P..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):17568
                                                                                                            Entropy (8bit):6.601523102100865
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:4hubcrkpKZyS3YxAstDhWVVaWvipWjA6Kr4PFHnhWgN7akW98xu3O6YX01k9z3Aj:S3132LFhWVVaWviYA6VFHRN7FR9zKj
                                                                                                            MD5:A0260D173E91A0BA02B39CB673986BFA
                                                                                                            SHA1:AFCD7A4EF3B64B6112F67C568DE61E2599D5E3F9
                                                                                                            SHA-256:2E28BCA4C04A512CE8B481B7FA8FA93A342406A5E554B9D9075F9BA20060701E
                                                                                                            SHA-512:62BC5F23C77674916D2B552B397E7C3891B276D5304FC9AB6C48A70F60190EAEBB1A06B10023A820EB9E58069A9C81B1E7D7B73951F69839B0A8BF5E6A5DAC06
                                                                                                            Malicious:true
                                                                                                            Yara Hits:
                                                                                                            • Rule: JoeSecurity_GenericDownloader_1, Description: Yara detected Generic Downloader, Source: C:\Users\user\AppData\Local\Programs\SteamClient\is-H6DF9.tmp, Author: Joe Security
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....x..........." ..0..............1... ...@....... ....................................`..................................0..O....@..4................(...`......./..T............................................ ............... ..H............text... .... ...................... ..`.rsrc...4....@......................@..@.reloc.......`......................@..B.................0......H.......P .. ...................p/......................................BSJB............v4.0.30319......l.......#~..|.......#Strings............#US.........#GUID.......|...#Blob......................3................................6.....x.........................../.......L.................................p...........................................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.C...+.Y...3.o...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):805152
                                                                                                            Entropy (8bit):6.7416805748123725
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:nbwydNnBKT9DzuU4/sKE5QmSfc+1yQgdY5wDG00eK0CszcyYl:nbzpKT9PuO5QmaryQgdYai0ZK03k
                                                                                                            MD5:19464109760AF17AE6CD8DBA5D222722
                                                                                                            SHA1:9DA4FA8D3C740182134C3D2B2977DCF0E0FAB669
                                                                                                            SHA-256:A4E353C60F26EAC3140F493C270320302BFB2E5FFCC1D4131682EA3E4C02D244
                                                                                                            SHA-512:47397137669BAB558BBFDB42B9AABC24A6301F8671253B0BC4632A975AD4AA0BAB87C9472AB4553A526132634CCD93A88BC09C4B8353E7FAB14DE0E2F498B7AD
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." ......................................................... ......i{....`...@......@............... ......................................p....d... .. )......T.......p...............................................................H............text............................... ..`.data....U.......`..................@....reloc..T........ ..................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):104608
                                                                                                            Entropy (8bit):6.03720418323957
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:eE8AlMvSLSjaab0PihEzfQHl9I+CAvpYhLKPyf9DKiVzm4G:eEjGKWKAuf+af9DKCy
                                                                                                            MD5:3760E66ADE87F95A0AF203D73335570E
                                                                                                            SHA1:81D2896860642BFD22384D01F3EAAC123BA8E8BC
                                                                                                            SHA-256:3F9B710E88C21089D7D7ED538B4612527A2BC5C160A41C148B872A8C84FBA756
                                                                                                            SHA-512:79AE5F2801E2498EF13C756F4CA3162F612146D5875081D85EB94EAAE15339F3D20E208E2803DEFD42C6917ED7E7F3B1606D7EAD04035007BA77FA9068BFE405
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....%i..........." .....0...0...............................................p.......@....`...@......@............... ......................................H-.......p...(...`......x...p...............................................................H............text...{ .......0.................. ..`.data........@... ...@..............@....reloc.......`.......`..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):284160
                                                                                                            Entropy (8bit):6.50709590444457
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:LC/97GWicf+DwiNJZ0KvQHRUBRlzPTkZvE8xHOKeKB:LCsAqJHIqBRlzP6vE8xa
                                                                                                            MD5:B0D8807729D9E3347923CF84BA186633
                                                                                                            SHA1:66E0228A718F9B318123A0EC46334BCC52C24142
                                                                                                            SHA-256:563BC9E0F9C674A9816B2253737978E23C3C0C7F47FC39B829F93EC06967BC93
                                                                                                            SHA-512:9EC5EBD71986FDA4E64E41C23E614F235CA6C3F4FD9858BE67D243EB42F201141E93E227D2E473D5FF707C281C290D9F6DD56949ABBC17A858F8C79C45CFDDFB
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...w............." ..0..L..........bk... ........... ....................................`..................................k..O.......................................p............................................ ............... ..H............text...hK... ...L.................. ..`.rsrc................N..............@..@.reloc...............T..............@..B................Bk......H.......|.......................<.........................................{5...*..{6...*V.(7.....}5.....}6...*...0..A........u........4.,/(8....{5....{5...o9...,.(:....{6....{6...o;...*.*.*. Z$P1 )UU.Z(8....{5...o<...X )UU.Z(:....{6...o=...X*...0..b........r...p......%..{5......%q.........-.&.+.......o>....%..{6......%q.........-.&.+.......o>....(?...*..{@...*..{A...*V.(7.....}@.....}A...*.0..A........u........4.,/(8....{@....{@...o9...,.(:....{A....{A...o;...*.*.*. ... )UU.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):272544
                                                                                                            Entropy (8bit):6.427109808525276
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:gbFX7U01FlqnpLMjwFMi8m7zd1XVSaos5gU+NTB4dOVGkK1:oFLU0PonpHFdlSDs5gD34qXS
                                                                                                            MD5:A315F2B9A4D56A36B35758AFBFB2E9E7
                                                                                                            SHA1:21AB6249AD343F43697A740068BDFFBE8019590A
                                                                                                            SHA-256:291AD602E68F54502BF4414BD0585981E605DA41B3A9C8CDE7AF57555A0E96C1
                                                                                                            SHA-512:141D9D36A2353A839FCC85D237DFD53BA03595159E420147D1F16848A22B2401D90B3C2B59243F09E34D824BA7288C2362C5DAB9C707C23097122B873C37118B
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...%m(..........." .........0......................................................P.....`...@......@............... ......................................|4...........(..........h...T...............................................................H............text...u........................... ..`.data............ ..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1419424
                                                                                                            Entropy (8bit):6.68633763415658
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:24576:9V+eIoWov6n9R1CNbtBh+I6hMqa1GIrsCbQt8dq1ZZo:vNWov6n9R1C9tBMW4QQ1A
                                                                                                            MD5:87605F39616FA8F05F32EA9087681CBE
                                                                                                            SHA1:1B971B72C32B1CB2D0C3E1C9000B7BF14F5B0122
                                                                                                            SHA-256:6EFE4C56C90455A4A5DCD11DE881DDDFBFCF343D523EDFEE30BC318B4622EBC3
                                                                                                            SHA-512:DB7071F23469D0B69197C69DC2258F221EC966E5FFD92767031CC095296EE0B1ABFC024738C47AC11C30E2146DEF634B267355518D1F1D979B7BA7E6CF39DD49
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....V............" .................................................................T....`...@......@............... ...................................................(...`......p`..T........................................................... ...H............text............................... ..`.data....^.......`..................@....reloc.......`... ...`..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15536
                                                                                                            Entropy (8bit):6.831442459723241
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:oz3xAn1e9WABijRWvtWxNzx95jmHnhWgN7awWChD/DoSJj+iX01k9z3AjFDk:i79WABijRWvuX6HRN7v9/DX+iR9zwW
                                                                                                            MD5:4C8CC0E429ED432A088EFACAEC656770
                                                                                                            SHA1:590F274CA3075533293AD01E6088B473E604602C
                                                                                                            SHA-256:738F70CFAC6A793F518DB6E3586F2740BBA663DAABC07672CE2A4918A9EF5580
                                                                                                            SHA-512:7C1BA5A2B9B4433C728462928FBA4A3E5C42E3E63EB202F4DAE90C129B31FBB5CA0DB3522ADAAEB29AB2D0D67D4AC476C9EC6959A5AE771DE19AA7016627FE98
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....}............" ..0..............)... ...@....... ....................................`..................................)..O....@...................(...`.......(..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H.......P .......................(......................................BSJB............v4.0.30319......l.......#~..X.......#Strings.... .......#US.$.......#GUID...4.......#Blob......................3..................................................|.....|...E.i.........p.....+.Q.....Q...[.J...q.Q...@.Q.....Q.....Q.....Q...'.Q...Y.Q.................c.....c.....c...).c...1.c...9.c...A.c...I.c...Q.c...Y.c...a.c...i.c...q.c...y.c.......................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15632
                                                                                                            Entropy (8bit):6.801183385142263
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:GzxAe+rIH5WL2WvAApWjA6Kr4PFHnhWgN7agWyZLrp0KBQfX01k9z3AlC+V/C:AAgWL2WvtYA6VFHRN73ZRxB+R9z0W
                                                                                                            MD5:C1CBD3AEC800C18949C8E91853BBE2B3
                                                                                                            SHA1:1002548B57C17FACAAB39960B0E6764D063A9E8D
                                                                                                            SHA-256:BC700629D14BC36FE3FB97F28B9E0ECA8C59312F85E3844749E738B374CFEE7F
                                                                                                            SHA-512:54B6407EA7772F2834ABAF1791FAAF6B7D56141B097D7D03346054D89844287062EA9FA6045654A7954562F00994CCFE94942DF2E36CB90C5B6AD8377816D764
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0.............F)... ...@....... ....................................`..................................(..O....@...................)...`.......'..T............................................ ............... ..H............text...L.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................%)......H.......P ......................d'......................................BSJB............v4.0.30319......l.......#~......d...#Strings....p.......#US.t.......#GUID...........#Blob......................3..................................................4.....4...Z.!...T...........@...........p...........U.......................<.....n...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):133296
                                                                                                            Entropy (8bit):6.342375712378606
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:UzCkkW0glfG6WVKdrhYnS+5On3kg9dE8rVP9kiTL:0kWxI6WVKVhjg8rVPOif
                                                                                                            MD5:8B391D187DB389BE181E700081C81906
                                                                                                            SHA1:EE3E0803D217FC947EFA6BA2D51CF196337EA4F6
                                                                                                            SHA-256:C44D73E3582228CAE2CDBFE74F6A60D11B4E1B4FCBD7343FA52F3C3C12AEA770
                                                                                                            SHA-512:0D89BEC917A2E82D39EDB089E8AF23C9732FA67205391709608DD0AA826DF5C9FAA9FEC4C265F7ED6AB8D109D620C878AD97F4F9EC8DD6D3CD1E6222DF007DBE
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...r............." .........@............................................................`...@......@............... ......................................44...........(..........@...p...............................................................H............text............................... ..`.data....$.......0..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):190752
                                                                                                            Entropy (8bit):6.3691331105031095
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:tOEp0tsypJKO0BYnjbpL8DqJVyR3IUQeu0IeW+1omEAa9NYLbkbmvh0dksI8mt/R:fpKsnRnYQzIeW+1odmvhSR7mtxrX
                                                                                                            MD5:3C9FDD9789791E468453B420FA39CEC5
                                                                                                            SHA1:92386B6677D421CD2EFEC73F67D66975A41017E7
                                                                                                            SHA-256:7CD51A14E2E1D4231FA85440AFB3047B65AB4F397BFF37C91F50ED20DEF9A800
                                                                                                            SHA-512:B74F822E016E468C15B70274797944F8444A38BE9E68F6B83BA42B30A02FCA892E3EEC0E4E177AD267DBE90DF0D8FEB1B999EB2A866489E0B2B659E6282BF1F0
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...[.v..........." .....`...P.......................................................a....`...@......@............... .......................................L.......... )......d.......p...............................................................H............text....Q.......`.................. ..`.data...O7...p...@...p..............@....reloc..d...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1241520
                                                                                                            Entropy (8bit):6.349941690072582
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:YyL6o2u8NwfPWN0uenPtMDQUxbDjDDF2FZNd0W+/y9RtI/2gTZWQ9s16y6p54yqX:YyL6oXnU0uePtM/DjDDFA7dFiugTypf
                                                                                                            MD5:18C328AE6740B28D3BCB238BDA17AEB9
                                                                                                            SHA1:AB73DDA2F6EB35B743C56BABD2E3F5CADEBDB938
                                                                                                            SHA-256:1676DF96BF8D0DA277F1ADC2102E7FC711240982D61C31610F83474F093092F4
                                                                                                            SHA-512:CC5821C2E80F11BE3B010AD11943B53555C8537DD2975F900556B45A2FBA3C600D64707BFA72828EB320CEE74E48EF90FD726F76C5011361085824085017E024
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......\........................*.......*.......*..<...S......S..............-.......-..h....-.......-i......-......Rich............PE..d.....f.........." ...(............0O...............................................Z....`A........................................P...`....................@...........%......p...@:..p....................<..(....9..@............ ...............................text............................... ..`.rdata..(.... ......................@..@.data........ ......................@....pdata.......@......................@..@.rsrc...............................@..@.reloc..p...........................@..B................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16648
                                                                                                            Entropy (8bit):6.6812317734380064
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:lmh7op9/MWbCWvCYA6VFHRN75l3VXC4deR9zVjTTC:lm5op9ZjCFClnVXC4dC9zVjTG
                                                                                                            MD5:6DD949F6AA63BB8FE19BBF6B6B076083
                                                                                                            SHA1:FAD97047B28D631D1DDBFE4DA79E2D4E624FDFAA
                                                                                                            SHA-256:45886BE34B3B81717B4913564361B12D7AE3B9926BC85F80DF64026C4EE9B4D7
                                                                                                            SHA-512:B62404B9AF3077DF8318E3CF8C7D9A3E97070EAAD07F5F6AB3E9E7C8F1763C14966298B7ABC41BE0AD96A07E3DCA2B2620C234ECFEEC6E020762CFCF6156FE4E
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....Z............" ..0..............,... ...@....... ....................................`.................................a,..O....@...................)...`......t+..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................,......H.......P .......................*......................................BSJB............v4.0.30319......l...<...#~......h...#Strings............#US.........#GUID...$.......#Blob......................3......................................&.........W.............................j.Z...9.Z.....A.....Z.....Z.....Z.....Z.....Z...w.Z.....Z.....#...........................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16672
                                                                                                            Entropy (8bit):6.749834751700326
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:cARUY7xW2WGPWv7srWxNzx95jmHnhWgN7agWYLrp0KBQfX01k9z3AlC+1ZIVpdt:cYdVfWGPWv7jX6HRN7XRxB+R9z0DZIL
                                                                                                            MD5:AD19CF1AEE37E575B7417387272ACFDB
                                                                                                            SHA1:A268235CD212375CDB20176B499AA154EF3FB145
                                                                                                            SHA-256:E7DB86F2176EC876DE7AF4BECD8B7C4EEA60E133F4866FC014403F318928CD24
                                                                                                            SHA-512:F9D853ECC9ABF4D505794C1E41AE9C0D25078ADE7B861F86E69E4D6D0C586CE0B7AD5168F172DE2C9C901BF3EB76B98EBCC7C92D5920814D19396BDEAD8BE51B
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...:.y..........."!..0..............,... ........@.. ....................................`.................................c,..X....@.................. )...`......\+..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................,......H........"..t...........P ......h"...........................................<linker>.. <assembly fullname="System.IO.Pipes.AccessControl" feature="System.Resources.UseSystemResourceKeys" featurevalue="true">.. System.Resources.UseSystemResourceKeys removes resource strings and instead uses the resource key as the exception message -->.. <resource name="FxResources.System.IO.Pipes.AccessControl.SR.resources" action="remove" />.. <type fullname="System.SR">..
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):55560
                                                                                                            Entropy (8bit):6.584918050714321
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:OayNEwaeXqJMkhw8Vb6TVpm2wkdxpim9zTfi:Oowa0qJE8Vb6TVpm2wkdxv9vfi
                                                                                                            MD5:3D19AC5866E193231AAB0888EAC74A56
                                                                                                            SHA1:CF3A6E805498201A1D21BC87067F058C89DC31B2
                                                                                                            SHA-256:53726755857B538B3676CABC39989874BE072028FD5B39360A7580D73A14E562
                                                                                                            SHA-512:681B24EF94B6F4E39F21532D67ED61DC693F5F0BAB16AAAAC76149C79D17C43118C69157D86D951714DEEB9EC2238468D9F0C1A99673B54CFE805989D4FB81AB
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....n..........." ..0.............N.... ........... ....................... ......5&....`.....................................O.......T................).......... ...T............................................ ............... ..H............text........ ...................... ..`.rsrc...T...........................@..@.reloc..............................@..B................/.......H.......p^..HS...........................................................s&...z.~....*...0..........(....,..*..(.....o'......&...*...................0...........(.......((...-..,..*.*.(....,.r...p......%...%...()...*..(*...*.(....,.r...p......%...%...%...()...*...(+...*.(....,!r...p......%...%...%...%...()...*....(,...*..,&(....,..r...pr...p.()...(-...*..(....*.*.(....,.r...p......%...%...()...*...(/...*.(....,.r...p......%...%...%...()...*....(0...*.(....,"r...p......%...%..
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):47368
                                                                                                            Entropy (8bit):5.313584058986443
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:768:DEOyP3H1ppKzS/Y7Fzq7roiIJPMuFCl20VXC4dC9zVjTQ:D9yP3H1ppKO6FzqYi2i5C4dezFTQ
                                                                                                            MD5:D38BBF660F3694B32D26AEB7A4113BCB
                                                                                                            SHA1:D1FB7DA85BBF49A937D233BEF2E329CDB9B68241
                                                                                                            SHA-256:C85BA2F97897AC62919E6367E4FC05D166B3A4D13E5757E21998883312C52294
                                                                                                            SHA-512:0C7B9ACF7D318E705BD2F9785AF3892BF4BACA9247EBBEA96A294DA32C62B9D912BFD2D4E1FB5B2693DBAD8F3084AAA3382C690BBBA82AB7456BD00512CAFC52
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....H............" .....`... ......................................................._....`...@......@............... ...................................................)..........P...p...............................................................H............text...8U.......`.................. ..`.data........p.......p..............@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):153600
                                                                                                            Entropy (8bit):7.110434070329448
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:gd5NVzHUHXe6F6e2zHX8D5VFcB3rqC3rsG3ThNSHoNOb3ThNSHoNOF:EAXkrsdV2ZGC7syfT2fT
                                                                                                            MD5:E17923870064DF5200CD84F4B60AFED6
                                                                                                            SHA1:BC5F5E3573868896505E3B743C5626EE10292DF6
                                                                                                            SHA-256:405B6D4EBA43D561DC8914A44AB6A2D70088FC0B18C2909E3B403B1F7871D6CD
                                                                                                            SHA-512:BC3D0F7B9F7D94E4A8A4355033D45C91A265118CF518253C6A5411C63F01DDD349497FFDEDC8308AE61D6BC37558D80A04C25A132EA36F15E50AA73F5F3370EF
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...{.<..........."...0......T........... .....@..... ....................................`...@......@............... ...............................@...S.........................., ..T............................................................ ..H............text........ ...................... ..`.rsrc....S...@...T..................@..@........................................H.......|L..XY.............Xz..........................................J.r...p.s....(....*Js....%o....o....&*..( ...*..(!....(.....{....r%..p.r[..p("...o#...*>.o$...-..(%...*..0..$........{....,.*..}....rc..p.s.......(&...*.0..C...............+1..t....}....*..t....}.....{...........s'...o(...*..}....*R.(!....(......(....*.0...........r...p()...-..r...p()...:.....r...p()...-j*.{....r...ps*...s+...o,....{.....o-....{.....{....o....o/....{....r9..po#....{....ry..po0....{.....o1...*.{..
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):166048
                                                                                                            Entropy (8bit):6.346422693533479
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:oqlaVz+We9hgsXZyPTA8pLtx1k82pq1L8p9X8f/F:tAVzeosXZf8pL0p9X8fd
                                                                                                            MD5:E6115534751BE304966019E057F40DE2
                                                                                                            SHA1:671416A123E8ED8243A0F352520CDB25D999AB17
                                                                                                            SHA-256:7C2A4EAD45C9BACD5AE24BDF7C1D2481F1A06F75088E7F884974AA0257E798FA
                                                                                                            SHA-512:B8834D7F4CA23F4954C0D2FF351215FD522F53055A9751EE4CEA5F965B169A29EADCA7E9376A0F24B2AAB0A72D8C5286032AA42C4958A98B0FBADB776523A341
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...m+............" .........@...............................................`............`...@......@............... ..................................P...t@..X....`...(...P......@...p...........................................................P...H............text............................... ..`.data...6/... ...0... ..............@....reloc.......P.......P..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):21168
                                                                                                            Entropy (8bit):6.542009642868284
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:KBmy0h6gSGR5OcHivWt/WbX6HRN7KtHNsAR9zF0H:bSyOcHLgWwts89zmH
                                                                                                            MD5:3A293D421E4A853F569C2E7B5BF27775
                                                                                                            SHA1:64BE26396D3569E2A32FFE25A3A5B3F30D8EB67C
                                                                                                            SHA-256:F59C6ACF3ABA059DAD7414BA0046E0EA0646FA54036827C2A611CE8843232463
                                                                                                            SHA-512:8D9636E69105DCF5B3A5A07191E7C993A5A49B64869A9D2E8801FA31ACC1778C53E850E1286B0CD45F1111D8CC54CC8409C4C493B0601C68B92C980661AF4C30
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......f...........!..... ...........?... ...@....... ..............................ld....@..................................>..O....@...............*...(...`....................................................... ............... ..H............text........ ... .................. ..`.rsrc........@......."..............@..@.reloc.......`.......(..............@..B.................>......H........ ......................P ......................................H!j*.......8M..{.c....BD.l.....EVt.RL..*.8.c...Q...w....2..E..W...U..c..m..d&GA.,..rND...I>.v.......Ea...r..2..]..&.Fk.!...sTBSJB............v4.0.30319......l...,...#~..........#Strings............#US. .......#GUID...0.......#Blob...........W.........%3........!...........7...................t...3..................................... ...............^.?...y.r...........?...............-.....D.....d.....
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):346272
                                                                                                            Entropy (8bit):6.521387641131273
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:+f/JWsKEin0hypPmFjQMt5e15XxGGIDvdDp3k+fc3CU1S2Du:6JW7EincF9QEe0THQCU1HDu
                                                                                                            MD5:44E2EFFD739146A1EDE87973AE254B2A
                                                                                                            SHA1:E342395ED09EF148F5848EDD1D79C3DC201A9738
                                                                                                            SHA-256:3FA27A91DAA93BD98F0EC6943DCB08531D799327B3E08E87EBC1BC9FCADF1CB8
                                                                                                            SHA-512:13507AD994D29D7DB8DBCF460819DBC2D7343FF9001426167361688DEFD3191051D233D71FCDAC51E0C16AE44CFAC5BB5A2F2A42D8389C32A51A533647977911
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...9..........." ......................................................... ......ik....`...@......@............... ..................................p...h....#... ...(......H...H)..p...........................................................p...H............text...Z........................... ..`.data...=n.......p..................@....reloc..H...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):39072
                                                                                                            Entropy (8bit):5.152976144651618
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:fWtXILG8kxsuQ7JfADw7fmlE8QMnYA6VFHRN7WVtHNsAR9zRY:iX2GHxsuQ7JH7fOVFCluts89zS
                                                                                                            MD5:289320F577443CF8FB301A730E2E0577
                                                                                                            SHA1:9C4EEA8D1D7B3800E63FD1D455DFA2AC516B5842
                                                                                                            SHA-256:B77EC004EABCD8759B0991E923F200FF107A5110861B49238873F475998119F0
                                                                                                            SHA-512:DCB3E2A02910C1C8CF01EF95E7A0F7A006B95A6DFA2A6247EFD33E99C83348DC9B7E19682A83D2C14194C2D778AF1323ACCEE214BE5775F15D7CF898AC0B37B2
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....SE..........." .....@... ...............................................p............`...@......@............... ...............................................p...(...`..|.......T...............................................................H............text....7.......@.................. ..`.data........P.......P..............@....reloc..|....`.......`..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16124064
                                                                                                            Entropy (8bit):6.814489484370051
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:196608:YffCqPQVBYD+IsWs7Y5gIeLHOdwzLPlT+AJ0ysEKvqg:YffCq4ptWP5gIeLHOdwzblT43Jvr
                                                                                                            MD5:FCE0527DCEA85FB4F9256C2D398BE500
                                                                                                            SHA1:A3E485D52C82461129D317B06B252CBB64FCFD3A
                                                                                                            SHA-256:B903285A81535D3F7D394E284FD8BAFF2DF2001CFF2D590B63BF159D6435E5F7
                                                                                                            SHA-512:A3F202A35AF1FF36E371588B5D2EEC57718D94028A1AF8388453F7467F1A20502197376A2A1F02E4486CF8D91E773868018554F8F82AC6971195F7C93E7F9F51
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....cC..........." ................................................................7.....`...@......@............... ..................................l........$.......(......./...j..T...........................................................p...H............text...^........................... ..`.data....... ....... ..............@....reloc.../.......0..................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):296960
                                                                                                            Entropy (8bit):6.619863520346344
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:PW7EJC6KZ8NBwVdM8H+oMc3yMtvWgoYlXYSAiQubi7w:ccx8HJ+SA7Ci7w
                                                                                                            MD5:8AD7C12B2D3B20AD452C8B69F8258F15
                                                                                                            SHA1:095F9669D5F72A1D074FDD4DAC31B6B238707792
                                                                                                            SHA-256:53909D82F6FAB9A7A810F1A78C6C9CB526863E15878DFECA0AD652AB2851CB6A
                                                                                                            SHA-512:F97B8E2C0EB6EC63438F75F67E9717052F494FCDD33CEF96016061B6657F0221625E5E14709BD38FE6ED3EF4040EDF642902F0C2E009810F9FDAC01841153723
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....K..........." ..0..~..........*.... ........... ....................................`....................................O...................................\...p............................................ ............... ..H............text...0}... ...~.................. ..`.rsrc...............................@..@.reloc..............................@..B........................H........>................................................................(u...*..(u...*^.(u..........%...}....*:.(u.....}....*:.(u.....}....*V!.o./.....sv........*..(w...*.0...........o.........(....*&...(....*..0.._........(........!..Y.5)....(..... .....~x...(...+*...(y...(....*r...p.(.........>...oz...({....(....*..0...........o.......(....*..0...........(g.......$..Y.5\...........~x...(...+...(....*.(6.....!...........!..........+.~|.....+.~}.....+..(~.......*.....(.....
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16160
                                                                                                            Entropy (8bit):6.70432965142328
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:rWQRLWdRoRA0RHWvFSX6HRN72OFDR9zzKUVx:rWi06AuGFaW2Gl9zDx
                                                                                                            MD5:202E1D4882ADC18706D82E39A66BC8B1
                                                                                                            SHA1:C9CF5CF0AE8377E7D19FFBAF194127F7937B6CEB
                                                                                                            SHA-256:AF0431593029BE941368EEB132DC9BDD8666A1E4735E5F7209B2B998A50B25AF
                                                                                                            SHA-512:EDAFA2FF6BB5E229FD3CD44B0AC3E65F021C0BE53B98D5EBCD0E4E4691369B9AA0055BF3769E45CC7700B81E7C4FD51492B4C2E949B99FDC98DF975F32E90684
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....0............" ..0.............v*... ...@....... ..............................ka....`.................................!*..O....@.................. )...`......8)..T............................................ ............... ..H............text...|.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................U*......H.......P ..h....................(......................................BSJB............v4.0.30319......l...T...#~..........#Strings............#US.........#GUID...........#Blob......................3............................................................D...........o.....*...........Z.....p.....?.......................&.....X...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):403616
                                                                                                            Entropy (8bit):6.600068240160654
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:QxxBCAdWeda9F5g7yB4cPIm1OwpXQgQbTCtYnzrZjzEOdlIZJ4aU:QDBZHU9F5Rv7/QnCSnz1fQZyaU
                                                                                                            MD5:CE7139BB6444A47C86FAF3780F4D561B
                                                                                                            SHA1:32538812CF09B179760E17148E95AD84581AD8AC
                                                                                                            SHA-256:A113BB3BD9E8C13B1EAF126C3EC614A08C3193A51F52C277B3BD5F4DC00D08FB
                                                                                                            SHA-512:F2F1CEA8ED59D7DF0BE03279FDAF2A1764D2E8C00C975BFB60C81BB838FCA0B210AE7BE2A6D1B2ABDAA2A8AB9799D2D5BD568F9A6F59DB95E37C736A9B55D092
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................" .....p................................................................`...@......@............... ...........................................-.......(...........)..p...............................................................H............text...fb.......p.................. ..`.data...Sd.......p..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):80144
                                                                                                            Entropy (8bit):5.803230831022685
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:Gdq4De0RKXrgcCGfNiQSstWrHG73Vii33zTT:GY0MrqQN4rHG7FiQ3r
                                                                                                            MD5:95C0763C84097068062150DE68644010
                                                                                                            SHA1:87480BBCFD5D3D5CCB062470DA0E3EE6043216AD
                                                                                                            SHA-256:EC4EA965B4BDC6886EF9EBB234BD568543ED9846CD6FA32E4EB33B5529841A38
                                                                                                            SHA-512:56CE8D3E416158D356B54174A6D5968EE3556A593E2AABF884126163EE14C9264F5E624B0528058BD586C4433FE6D54D7CC6F781BEA429FEBE98DEE809030FA2
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...+.$..........." .........0......................................................'a....`...@......@............... ..................................p...\%...........)......T.......p...........................................................p...H............text...o........................... ..`.data............ ..................@....reloc..T...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):2309152
                                                                                                            Entropy (8bit):6.414576855139372
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:49152:jH+fGgFyzuNiG6H0n8D1gkrz/OAyFAopdrq/c/:+GgFQq8DT/ZyFDN0c
                                                                                                            MD5:A71CD05C01F0FC603C0BD782516F806D
                                                                                                            SHA1:C15E261D5E7318875D324D28AB70A883CD434C81
                                                                                                            SHA-256:7F8DCF37D9D66EAE14C48A79FA2FCD447BD0F38A21BE0203A9C4A89398AACF28
                                                                                                            SHA-512:CE53F6DC1F02889ED6FB1F8DF226F9BADBB039F79505CDBD599A00A32B6617DA5E19F2AD7F76BB8134B3CCAD39FAB2209ED8EC6AE42CD30402C4E450FC19FA88
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......Wq0...^...^...^.Xh]...^.Xh[..^.XhZ...^..]...^..Z.'.^.Xh_...^..._...^..[.m.^..W...^..^...^......^.......^..\...^.Rich..^.........................PE..d....ZY..........." ...(.....\...... 0........................................#......)$...`A.........................................Z!.p....[!.P....P#.......!..W....#. (...`#..>.....p.......................(....U..@...................0Y!.`....................text............................... ..`.rdata...Y.......Z..................@..@.data....a...p!......^!.............@....pdata...W....!..X...t!.............@..@.didat..p....@#.......".............@....rsrc........P#.......".............@..@.reloc...>...`#..@....".............@..B................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15536
                                                                                                            Entropy (8bit):6.762522427444249
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:3hDixAXGWI3WvxNWxNzx95jmHnhWgN7awWJpccpBm+0U8X01k9z3AH50:eZWI3WvQX6HRN7CpcsBmo8R9zY2
                                                                                                            MD5:6467861CB0D9DEA2AEC7DE8BE11739B5
                                                                                                            SHA1:72EC68876D3115A13BAB42C9039613012AF2F82B
                                                                                                            SHA-256:EF8A510D31E84CDB66278C00B62CCC92658C128026422A227A6774A2E8A727CC
                                                                                                            SHA-512:FB2D0B89B8268BC3A29213B101FD6577612B2104FB1F16147F3C0551F28403E7BB91CE04328A0F65EB3164A3D186F1C3088BE051334FDA4346F745CBC18C95E9
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..............)... ...@....... ..............................p%....`..................................(..O....@...................(...`.......'..T............................................ ............... ..H............text... .... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................(......H.......P ......................X'......................................BSJB............v4.0.30319......l.......#~......h...#Strings....t.......#US.x.......#GUID...........#Blob......................3..................................................%...x.%...3.....V.....^.................I....._.................w.................G...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15648
                                                                                                            Entropy (8bit):6.804728776210739
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:Gv8XzaxAQy8W1WWvoiWxNzx95jmHnhWgN7agW8jNOghHssDX01k9z3AeKDJA:GEDAxW1WWvoxX6HRN7BjNOgFDR9zzKlA
                                                                                                            MD5:00346A61DDEAFB150D595887D6ACA36F
                                                                                                            SHA1:735B7CD1B62787861BAF51EC0D02C66C294962F0
                                                                                                            SHA-256:AFACE1464DF1D31BD96CC897F4D47C6B5A855707CBBFC954E624E68F3AC16372
                                                                                                            SHA-512:60395D751677C3728C3CD7763A36B1950E329D8407649C97CA7B049D8FCF8117943D1618B06087F376D6FAFE4EAE1ABE64BF0CE2D5FEC39C68FDED69687FC02A
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...k............" ..0.............z)... ...@....... ..............................9?....`.................................%)..O....@.................. )...`......,(..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................Y)......H.......P ..\....................'......................................BSJB............v4.0.30319......l.......#~..(.......#Strings............#US.........#GUID...........#Blob......................3......................................................x.....3.....4.....^.................I....._.................w.................G...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):448672
                                                                                                            Entropy (8bit):6.474085434530271
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:lrZkP7nVEPMrK7u2aAc8tU9kmMxKoVPtfwrfAX:lr+P7neErK75aAc8O9km5oPwrfY
                                                                                                            MD5:B07A911B77E9C6BFB40BEE9EDBB30003
                                                                                                            SHA1:CEE3FA050CEB5C9F91E927B0A7F59F7B244BCB40
                                                                                                            SHA-256:6D380E65B7C9F95B4AC9FBD92DA35CE7ED95E4E3170154AD9405461DEBBE2150
                                                                                                            SHA-512:975DD732BA4B84759314E30031FEB921699DA75311C46CB28FE5E453594FBEEE0780F2D08E971474EFC431359863B1F44D5F260CB78ED678A11DE65C4C44934D
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....H..........." .....`...@.......................................................W....`...@......@............... .......................................`...........(......L...x...T...............................................................H............text....].......`.................. ..`.data....(...p...0...p..............@....reloc..L...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):3676336
                                                                                                            Entropy (8bit):6.684594575848001
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:49152:h6S6FKfOBPKD5EUsp4Zq2daW7L2+K06Fs4sZ39SuMsFIW/pR:HOBiOmbp8uMsFIW/pR
                                                                                                            MD5:C3C16C39F19ED16A1AB42EF8DE7AE641
                                                                                                            SHA1:F072B19500679A70D1D6DD113B55921C6F963CBA
                                                                                                            SHA-256:10E4BC750F17578252293AAF7192E24E72A330D3EDC0146BE9245E9586CAC19D
                                                                                                            SHA-512:89307D4FDCF1DE91C6A0DD8C0807E56863856B803322C33AA845D90C0EEB6988F97ED70CA2754601FB61A739C0C364F2D8ADC7A28869F4921D6D5CF358FB0D2C
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....y............" .....P1...................................................7.......8...`...@......@............... ..........................................`.....7..(....7.,f...b..p...............................................................H............text...dK1......P1................. ..`.data........`1.. ...`1.............@....reloc..,f....7..p....7.............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):19616
                                                                                                            Entropy (8bit):6.475079017005305
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:cMXTSv/fUNRvGZYdf3zyP/we9+uH5WdNWvFYA6VFHRN7Iz8u/6fR9znQQD:fQ9gcFFClIgl9zJ
                                                                                                            MD5:CA0B1BEED7162550FB7FA2389A6B94E8
                                                                                                            SHA1:11B6A2A0A81A67270A152391D2D8863B42FD388A
                                                                                                            SHA-256:D88BB22EC1FF049550D1DD13B8B9C27B094822FBF73D034BDB4F5546F1AEC579
                                                                                                            SHA-512:1068AF9F03FB8CAFA236F2D720F5C01C30D90E5B67EA03B54C9C42406B680945A6E808ACC31A57E11F9B788DD007E029CE114A919564E53FC6B9C0B97577C260
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...'............." ..0.............v8... ...@....... ...............................i....`.................................!8..O....@...............$...(...`......87..T............................................ ............... ..H............text...|.... ...................... ..`.rsrc........@......................@..@.reloc.......`......."..............@..B................U8......H.......P ..h....................6......................................BSJB............v4.0.30319......l...h...#~..........#Strings............#US.........#GUID...........#Blob......................3................................h.................2...%.2.........R.......b.....U.....U.....,.....U.....U.....U.....U...3.U.....U.....U.................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.C...+.Y...3.o...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):84128
                                                                                                            Entropy (8bit):5.872675308344579
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:TqgxVcA9+/PACL3jTuDw9wbnEiZE+eU6p3ikzg1O:Tqg/f+3AiXu8ebnu+P6N/8s
                                                                                                            MD5:4528413D622621E35856F07EA263CD1B
                                                                                                            SHA1:5BB25492DD02CC7E9490CF6CFBCF28A248636DD4
                                                                                                            SHA-256:A298995294C59D04947F91290FB7030ACDC4DB3C5B6B1981FBC8C0136CD1B25C
                                                                                                            SHA-512:4CF1CB3A615C431080842CDB5BF3E3C322737BDC6719AC061898ADCF38E47E1A24C0B72238E30BAD0BABC91DFCC7F6BA5148195E1D43A3CC595E1CBC5D93EEE0
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...:+>..........." .........0............................................... ......d,....`...@......@............... ......................................t(..L.... ...(..........8...p...............................................................H............text............................... ..`.data............ ..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):13564064
                                                                                                            Entropy (8bit):6.473811993244613
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:98304:1EOVu5/pZoar/RZhFM3fxqbyRitP7AXfDPWkOSiQM/:1EOVUvRZhy32EitP7AXfDnOSB4
                                                                                                            MD5:CEB0075D090BC07B793D886B0F47D596
                                                                                                            SHA1:A18E0A3E872B6BF9B392A933136A219AE27C77B8
                                                                                                            SHA-256:215C333D7279D35CF60197EA4DAE1DA9FDD125404EF5A3BC9478D27EF237A8B3
                                                                                                            SHA-512:5CE4628D87203A27F6D4C3CB74C5C4CF94876415B4E33F0F1C3EC04E2885520A27BA3CB6ECC7921A8CCE115DA186EFA378712ABED071E72991EA214AECB5A647
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .....`...`............................................................`...@......@............... .......................................P...........(...@..p....^..p...............................................................H............text...kP.......`.................. ..`.data...N....p.......p..............@....reloc..p....@.......@..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):137376
                                                                                                            Entropy (8bit):6.275208849412791
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:vfoPuayYTnyCWulExt5qLkKkuWH/6V+937:30uanTFWumWkRuWf6o9r
                                                                                                            MD5:D631DB8DBEE0555534672D63369D484B
                                                                                                            SHA1:57CE3A34BFB747D53033BB1FD6923D093FCFBB6E
                                                                                                            SHA-256:9819A338F2CC06AFF2C1172DDFC98D942EF86435DF4ED4109E893B61AEB4EBF9
                                                                                                            SHA-512:8E4DEF62C695F856FC96CE8BBD25451A2696740F3455C8DE41B2E66F41F6174863281F888E29C387E2CF3BF23230A53C2C0DECA72BA52472E970BBFD6C84ABC5
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.... ............" .........0.......................................................~....`...@......@............... ......................................d3...........(..............T...............................................................H............text...}........................... ..`.data............ ..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):239776
                                                                                                            Entropy (8bit):6.273420553853626
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:oP05HdISwFh/zzfClS5/zm7Y9EqS3StS3fM+bj:Q0JdIN7EqSitS3Zn
                                                                                                            MD5:986799438340C732BB482628FFFBB2F7
                                                                                                            SHA1:1AE12FD48B575E4A6FA7EF20C8FFAE43B9AEE019
                                                                                                            SHA-256:03CB4DCB63A2388368F04E3C542865D46D445F44359BAAC2A78CC6143FF7C5CE
                                                                                                            SHA-512:07D8858FA934AB98BD1A4DCA59CA7D4A9EB7A889FB2B5363A40E19E2A3BE9A7C178BF26E7ED702533C26C3311EE3F0540ABB18A61E00CAD96B6CAE539D927158
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...;P!..........." .....@...0.......................................................9....`...@......@............... ......................................,+...........(...p..T...X...T...............................................................H............text....1.......@.................. ..`.data...7....P... ...P..............@....reloc..T....p.......p..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1501456
                                                                                                            Entropy (8bit):6.703064329512441
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:24576:iNDUuuRgw5xH6D9+YFVCwIbvRz6ySHAJcEVAvM8UbUJnBpK95:8vmTH6DMYTCwIlzPScp8UJ
                                                                                                            MD5:44E63A84FC57C49E4F2FA313CF651CBF
                                                                                                            SHA1:65240A270AFB9C06B65BB08ABF2CB8C1FD44EE97
                                                                                                            SHA-256:DC8B1118B266EC750AF5B4480869E01A97751A2F55352AC6908CEFB4A59499D1
                                                                                                            SHA-512:A0078A0FE7C8A092E71841287543E276643A0B469DA77D11B78F7857A6D5A1099FF6E4CE67A7B9992B60D97184922EA118AFD378EF4A357943D054A796456491
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....%..........." .....0................................................................`...@......@............... ...................................... ............)...........R..p...............................................................H............text....&.......0.................. ..`.data...\Q...@...`...@..............@....reloc........... ..................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):34976
                                                                                                            Entropy (8bit):4.86447641958981
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:hWArL6BLzBGcr6K9mN9ABN8YA6VFHRN756R9zekg:1n6zMO8FCl529zE
                                                                                                            MD5:29AADEB003680D153EE1FBFA4F13007D
                                                                                                            SHA1:DA596E2EF94DFE6DD9DE4174496E9DAC95DB4C9E
                                                                                                            SHA-256:8225F2F463DFD22409BF35D68A186B3CF4D4E2BFB3D06E970C2AFFC8911347CE
                                                                                                            SHA-512:AF3F5D7C88D65EBD89CC28DC1FC823E9ECB3AE32867E849D70B414AED7F104763D092AEDDA062168CB24D744729666BF9EFB25FAF15D5FC8DB258E0C168E3B7B
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................" .....0... ...............................................`............`...@......@............... ......................................l........`...(...P..t.......T...............................................................H............text...7&.......0.................. ..`.data........@.......@..............@....reloc..t....P.......P..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):75936
                                                                                                            Entropy (8bit):5.93517438959376
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:4PYWVA8CWZpWNv6zIMuSxRlHJ5ZYoqtTJogirzK:4gX8CWZpWNv6txRl+Nt7E2
                                                                                                            MD5:F714AC64710C190EEB50638803184D4C
                                                                                                            SHA1:49548E940524ADD22AD2F6CBFADDCB1D819F81E6
                                                                                                            SHA-256:7D1417C97CF840F4AEBBD50A7179026BF78A099F6FA4304FFD8262342B965A3C
                                                                                                            SHA-512:E142D3A048B2115DA4FA1F4D119643BA8E84A4ABFC867D28E67879EFF3195F44DE08138A3C764A26A1BE80C88C4D471E6D8AA10B48F30EE5677B8E7257A4D31F
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .........0.......................................................)....`...@......@............... .......................................$..|........(......P.......p...............................................................H............text.............................. ..`.data............ ..................@....reloc..P...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):260272
                                                                                                            Entropy (8bit):6.618737529882049
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:nXiJoXLKgtvcp1M5eRWAbQW0ryS1woXh3m3x:XYCKgtEzweMiD0rGqJmB
                                                                                                            MD5:C755E2D819F1462687BA99F28D7FB638
                                                                                                            SHA1:1758E9E47D46C3B1D4F71520D09F3FA80E40C9D6
                                                                                                            SHA-256:7EE67CDC969F5BD5BA1A4E99A17ED8A67C2DD835537A982CB41A7EBE3AD025FE
                                                                                                            SHA-512:060610E7C30AB2625C85315E0AC105E08888BD2B37A9ABCFA33566565C632E7397FC5DB5EDF03054FECA2B2F46CB73F54E2CDB258CCD470D1947A27BC7DE997D
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...77............" .....p...P.......................................................e....`...@......@............... ..................................p....Z..8........(..............p...........................................................p...H............text....g.......p.................. ..`.data....>.......@..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):23712
                                                                                                            Entropy (8bit):6.267200741035943
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:c58Ieq5ufyw8bcB8yGn70WzjsWvyYA6VFHRN7x6R9zdS:c58IeWv39yFClx29zA
                                                                                                            MD5:4512B147B8F78C18047A105F2BB1A429
                                                                                                            SHA1:C0BCB9C44F2DED879855E86FBC1CA9F755DEE78D
                                                                                                            SHA-256:4A23D5325BA071AB2AE359F524062C6CAE2454A75DDAAB206022CE877E3AA13B
                                                                                                            SHA-512:72ADAB86F3457653380BBA8775D4477A5DA20AB08BF55897EB6F53CF27D2CABBBDCA259DCE23E0080C3CA9DE6C8A29BF00689D6B9B58A317616E1A73BB8D9CB6
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....Q..........." ..0..*...........I... ...`....... ...............................y....`..................................H..O....`..4............4...(...........H..T............................................ ............... ..H............text...4)... ...*.................. ..`.rsrc...4....`.......,..............@..@.reloc...............2..............@..B.................I......H.......P ..4'...................G......................................BSJB............v4.0.30319......l...x...#~......X...#Strings....<%......#US.@%......#GUID...P%......#Blob......................3..................................................................S.....:.y...<.....O...................................................................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........:.....C.....b...#.k...+.....+.....3.....;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):211120
                                                                                                            Entropy (8bit):6.371401919540868
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:JVj+vjFiZoYqqcgVPCmU82iYwBpIUG2pQBd5eVJm495kCl5qf0B9iKCDQc1MSmsH:/pnjPU8AKpG2xkby51lc3n
                                                                                                            MD5:0F11173A55103D5AC405DD5E8083E6DF
                                                                                                            SHA1:F41120F21511CBA636DC8CE428306B3321FFA5F0
                                                                                                            SHA-256:85F28B33B26119D03AAEDCB55A62972832DCA2E4010DFCBD38DBB78FF40CB5A5
                                                                                                            SHA-512:BB45C4EB036D79A9210558CB842C7DB5D532AF8FF7FE89EDF415688FFF50C0D65984FE78F8D8886C2FEC6B1CF17DB38EC81843B32CBAFABB93B5DCA17AA990A9
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....f............" .........`......................................................f ....`...@......@............... ..................................|....J..x........(......L.......T...............................................................H............text............................... ..`.data....O.......P..................@....reloc..L...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):61752
                                                                                                            Entropy (8bit):6.3493073551414625
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:768:+hwLsWpGD774wTlENE9Kb8lS8BE3EqG01Ekks3uN2wP2QpTLFClk9z/:+hwLsWpG4Ntb8l4mD28liMz/
                                                                                                            MD5:03EC12EEAF45EF8E1747862CE905F51A
                                                                                                            SHA1:E4A47D35C7689C884B9F0AA491D8F824DA0DD469
                                                                                                            SHA-256:4B82AFBE3419EDA1B9C9742F55CA2A2692CDF9C5C23B61068313494B3164925B
                                                                                                            SHA-512:4A86B4BE9D521AC4F7D93E1E5F826D8D560750D97240BCA83D4982E8718186CF0BF23F61EB059C77B95C9B7719F64F00D6AE318798B7C0D76A2BF1F8E14D9263
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...............................e.......e.......e................................t.....................Rich....................PE..d......f.........."....(.r...Z......@/.........@....................................wD....`.............................................................................8)......t......T...............................@............................................text....p.......r.................. ..`.rdata...=.......>...v..............@..@.data...`...........................@....pdata..............................@..@.rsrc...............................@..@.reloc..t...........................@..B........................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):17184
                                                                                                            Entropy (8bit):6.676772135546476
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:ckrZI8N3bMWsUBBgWvBgEX6HRN7x9R9zUsp/:ckrZI8N3biUBBBBgMW59zzp/
                                                                                                            MD5:FB2252EE905F33760D6D40FF4E5A37A7
                                                                                                            SHA1:C93E55DF5AFC58809BF4099EF62F739F089525EE
                                                                                                            SHA-256:3F91EEC7FDF494D6C223B093024ACA3B6F16444F89D1D7A26B2F4F289BC8F830
                                                                                                            SHA-512:38200EE479F480C34A94822C563A6862A124493F14F786FFD63249215F5047389DCC3E95CB6ED1CB729DDF89BDC23F0A25845677F19C47212403B8D1995CA20A
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....M............"!..0.................. ........@.. ...................................`.................................M...N....@.................. )...`......H-..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B........................H........ ..x...................P .......................................C.J.O.S.lE{..k.@.[..:1..%qiF6.6.L....w...g..d'..p.-..8.s.&..-{...w5e._k...!v....'p.T.7_o.T@..)*.I/...))...<....F....BSJB............v4.0.30319......`.......#~..........#Strings............#GUID...........#Blob......................3................................"...........................W.a...............=.............Q.........R.......................9.....k.....m...................A.....
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):120992
                                                                                                            Entropy (8bit):6.141095686333107
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:HY1NwrxWkbGKzcNqJSvEVcULVii1i81SFUt:Dl6KYqJSvEVz7/iO
                                                                                                            MD5:4FD4616455D07E7252B50B565A2E75C5
                                                                                                            SHA1:CD6DB5A8DCA0D94AA5E48717E32F3EC3E1B17998
                                                                                                            SHA-256:853DA3E1E5BA29DECFC91A39FA1B70955BDC63E18F034AE119635DF53704E9D9
                                                                                                            SHA-512:1E37902F3B4AFCC08ACD7C8450E72DE11CA16D1D338B8E076BF4940BDE832866D410900ED6513B1D6BA67E7FCF579336998D7B2A2AC9483404B3FA2C6866EE2D
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...M.)..........." .....p...0......................................................NX....`...@......@............... .......................................4...........(..........0...p...............................................................H............text...Kh.......p.................. ..`.data...a........ ..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.74478738201605
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:geMRqXWDRquRqm0Rq7Wv0YA6VFHRN7utHNsAR9zF09RGZ1:/GqKq0qmuqK0FClMts89zm9RG7
                                                                                                            MD5:8E55387B87036298850351AB1C4E6473
                                                                                                            SHA1:F17FF8CD1DF79360702FD7EC6B14F4E5351B9653
                                                                                                            SHA-256:B6B0E4CFAA7C085A4854B80327052A0ADA77CBD8D6242C73316AFF391A14EE56
                                                                                                            SHA-512:8EF76D0448570A217BFCFEF2185E1A910386285FC3F640E2BE9337289D5CE46DC23BE15F2F453DCB49F1EC3EE8FA56F0009AC1AB1848B3727B23F3CAF8368C70
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....7............" ..0.............:+... ...@....... ..............................z~....`..................................*..O....@...................(...`.......)..T............................................ ............... ..H............text...@.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................+......H.......P ......................h)......................................BSJB............v4.0.30319......l...p...#~..........#Strings....|.......#US.........#GUID...........#Blob......................3..................................................;...x.;...3.(...[.....^.................I....._.................w.................G..................."....."....."...)."...1."...9."...A."...I."...Q."...Y."...a."...i."...q."...y.".......................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15520
                                                                                                            Entropy (8bit):6.831239516010608
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:q7e1eTxASTWyUWvqPpWjA6Kr4PFHnhWgN7awWr4I8HNsAX01k9z3Aa30ah1A:qCUNVWyUWvcYA6VFHRN7LtHNsAR9zF0x
                                                                                                            MD5:FA3EC6DB4842FE658F04CF3789CD7209
                                                                                                            SHA1:8E471D546C18604F20AC6F4EB4C242B887CA0689
                                                                                                            SHA-256:B7EF3589E7F793D9780FA32EFB2595C91A85D92E6E0FF62B5187142114F1707C
                                                                                                            SHA-512:337ABA8011D756C69BBA57C2517487FCDFFB0A5D22362669047776D28D789EABA286E867E15196736F83346466B63AF0DA412E283E6BC3884F5C7819085F97CA
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....h..........." ..0..............)... ...@....... ..............................U.....`.................................{)..O....@..d................(...`......X(..T............................................ ............... ..H............text........ ...................... ..`.rsrc...d....@......................@..@.reloc.......`......................@..B.................)......H.......P .......................'......................................BSJB............v4.0.30319......l.......#~..(.......#Strings............#US.........#GUID...........#Blob......................3............................................................@.O.........k.....&.7.....7...V.....l.7...;.7.....7.....7.....7...".7...T.7.................I.....I.....I...).I...1.I...9.I...A.I...I.I...Q.I...Y.I...a.I...i.I...q.I...y.I.......................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):444576
                                                                                                            Entropy (8bit):6.440833272545049
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:wNPuxxnrOCMgPaisoAAnzQ9km0OsSVPtfwUh:wAznrO+PavoAAn89kmQSPwUh
                                                                                                            MD5:234B4CDFA3C0E3F92A8A8B6D023D475B
                                                                                                            SHA1:99777FE5D31FD9F22FA264BEC205DFCEA9B59341
                                                                                                            SHA-256:1EC111968837EB9B3D110680ED6B3F55CE2208C458F42350EBE8BFDDAFBB3850
                                                                                                            SHA-512:59246448DAEE1E880925E0D58C44DF44BE3FFFDFB907650F8BF9D04E1119F0A2F0E622CB4AD779D9B44F3AB9AF0954856431AD8C49DC404C153D171AD83379B7
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....[X..........." .....P...@......................................................hj....`...@......@............... .......................................`...........(......L...x...T...............................................................H............text...QE.......P.................. ..`.data....(...`...0...`..............@....reloc..L...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):23840
                                                                                                            Entropy (8bit):6.309945960737407
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:hS9H4Ay0l9Jr3OzFPhoact/iKMePLexkrW1rU1ZXt8+EFWc2WvDcrX6HRN7HVyNf:E9H4Ay0l9Jr34FPhoact/iKMePLAxiA8
                                                                                                            MD5:7690C569AA58A3BB3D19D8B45D37DF15
                                                                                                            SHA1:EF1D0FC539EC8B943B58C02C7E9B78415BFF599F
                                                                                                            SHA-256:3735702159E6D3D1EACA9BB7A9763D1CE58F84A4ED246066EF1780F6AEC67F63
                                                                                                            SHA-512:3E9CD45453CA82616BE8FD97092E6741CC2AAE98E0B710282674806D2C9C7E6782F89B580F241D00584173A68642643E64F70AE9FBCD25FAEF3A1D46D3A1393A
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..*...........H... ...`....... ..............................5.....`.................................sH..O....`..4............4.. )...........G..T............................................ ............... ..H............text....(... ...*.................. ..`.rsrc...4....`.......,..............@..@.reloc...............2..............@..B.................H......H.......P ...&...................G......................................BSJB............v4.0.30319......l...<...#~..........#Strings.....$......#US..$......#GUID....$......#Blob......................3......................................................i.......G...........................:.n...J.t.....t...P.................C.....`...............................................).....1.....9.....A.....Q... .Y.....a.....i.....q.....y.....................I.....R.....q...#.z...+.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1338400
                                                                                                            Entropy (8bit):6.358098724993395
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:cABsjnIunobZ5eGiBSk7uf9xg9Y/ydKEPXoRyingNLi0/rqsaoGSZNrWVgi00szd:cjIuG4Sk7ug9Y/ytNe4rqsa0njGzQD
                                                                                                            MD5:05D4804E5EA5509E19A3388B46A363E2
                                                                                                            SHA1:31EA1248542D2914FC76179E5731126DFCCDBFA0
                                                                                                            SHA-256:61350E7EE96E614900D641B4ECC3F35271AA2BA72C0455AE0D021E20C95F9A3E
                                                                                                            SHA-512:6DBD79B065E8C0D3B042DA7615ABC0EF7DC7522E86AEB3DF9707080AFE113077A894F5CB963D2B0A179B5755296011798B24F7102AE9A5274CCD5C0FF9959EDA
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........=I.nI.nI.n@.-nC.n.l.oC.n.l.oF.n.l.oc.n...oM.n...oB.nI.n..nYk.o..nYk.oH.nYkAnH.nYk.oH.nRichI.n........PE..d.....f.........." ...(.b..........................................................R.....`A.........................................g..p...Pi.......`..........<....F.. &...p..........p.......................(...@...@............................................text...`a.......b.................. ..`.rdata...............f..............@..@.data................^..............@....pdata..<............l..............@..@.rsrc........`.......$..............@..@.reloc.......p.......*..............@..B........................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):43168
                                                                                                            Entropy (8bit):5.182597235608364
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:iWJeWvhx1Yc6PuTNtyVC0a+SKODVt9jR3YA6VFHRN7dBWkBmo8R9zYU:NvbGc6WTUK+jOZVFClGCmoQ9zp
                                                                                                            MD5:1679D883CB813D80B1257AF4ADC0AD77
                                                                                                            SHA1:F8573165E89592339B18FE392C0FC004405BBD74
                                                                                                            SHA-256:9784CA5F49D11E8A112D39FF3EB1105502A20FD2331EA1523CD2F491A5E8208B
                                                                                                            SHA-512:8D80120B954C338AF0BC3C17EE113028921EBC66A4A2F061BAA32CD6F21D163F125600CF3209948D1890952F4E5EB2A480C888F18563DD2FD4C149AF80E34E48
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....C..........." .....P... .......................................................!....`...@......@............... ...................................................(...p..........p...............................................................H............text....G.......P.................. ..`.data........`.......`..............@....reloc.......p.......p..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):186544
                                                                                                            Entropy (8bit):5.9668644667656325
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:kuNLd2rZAzaoZdXEooSgEooVEooYEooeTlVXBIg0WPgE2uU7:f6r+zlpEooSgEooVEooYEooefXag0eg7
                                                                                                            MD5:297784722000D8F6C1DCC6272CB93C54
                                                                                                            SHA1:7CCBAC742B6338CFA8F6ECBED8804C6445D966F7
                                                                                                            SHA-256:7172998EC636B80C3251F7F26AE11190C11A7767D3489B356D82B96CEF0E9A2B
                                                                                                            SHA-512:C25E408C610F645C0CAB5626B1D6FBB0DD97DAE683AEC729BFE9519C24CB01EAF4319EE96B01B7289B563E79B4107ECDED56ADE0895C812A7BF89AC91DDEC5C6
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....j............" ......... ......................................................zJ....`...@......@............... ......................................85..@>.......(...........)..p...............................................................H............text....}.......................... ..`.data...............................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15640
                                                                                                            Entropy (8bit):6.801577686636654
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:kB0LPxAb0OOi3jWVMfWvVWIWxNzx95jmHnhWgN7acWnwKUWX01k9z3Ad7eTowl5:dL5+WKfWv0nX6HRN7Z2R9zGAl5
                                                                                                            MD5:D5AB3127B17D4E08CE04CFD5CC3DB2DA
                                                                                                            SHA1:D40032C264C94D084ACC129FD4B467AEA550936F
                                                                                                            SHA-256:5F45B771954E4B7DC4213F1E808AA1C01971384F314E17A804595604FA272735
                                                                                                            SHA-512:347977CD08F6C7242D8F1557C36340D617E06F2CABBFF8452F16BDA1E57DE105F72C016846717F317357071EA6F874D60CD8F3E552C58EE4B4DD3C0478BCCF86
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....j..........." ..0.............j)... ...@....... ..............................:.....`..................................)..O....@...................)...`......$(..T............................................ ............... ..H............text...p.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................K)......H.......P ..T....................'......................................BSJB............v4.0.30319......l.......#~..4.......#Strings............#US.........#GUID...........#Blob......................3..................................................=...x.=...3.*...].....^.................I....._.................w.................G...................$.....$.....$...).$...1.$...9.$...A.$...I.$...Q.$...Y.$...a.$...i.$...q.$...y.$.......................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):759968
                                                                                                            Entropy (8bit):6.636461086910098
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:UxoB+nhcBfFBUnQi70v8uEJh5UOSDxGcmptxF7VWG2tObhE4K5:yHQu/0EueexGcUtxF7VWG2tOlE95
                                                                                                            MD5:8D2B652263E5884FC82ABC73A210BA2A
                                                                                                            SHA1:4AD1E5DB2033EF1579E3B7BC3D6BEA638C2E56E2
                                                                                                            SHA-256:BC0E941D59F7BF9DBC240EF83DEB8D1EE63B3595DD098967C1E733D90260F851
                                                                                                            SHA-512:91DC26606D5E37A3E2A09EF614BFA0FF561F851AA81DBDA30EBE59E58B846DD6C1E5B2CFA2B0AF8D6A7BA537BCA7D59B895736A590E0AF06F3075DAF0D68472E
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...pVt..........." .........................................................p............`...@......@............... ...........................................;...p...(...`.......:..p...............................................................H............text...2........................... ..`.data..............................@....reloc.......`.......`..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15632
                                                                                                            Entropy (8bit):6.8277201917102674
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:H9jw4pWw+WvLYA6VFHRN7htvR2IR9zXRq:H9jw4dPLFClhtvgU9zw
                                                                                                            MD5:DEB54D7C28DC4BAF320D8E762CD3906D
                                                                                                            SHA1:28D9096B448B0C8611302D7E27A6667050252682
                                                                                                            SHA-256:7800B0FD6AAC7979CAC550E1BAAE3AFAC15CFA8081FC186B27553BF7CBA7A0A3
                                                                                                            SHA-512:F748B155577DCEE8141C15E0684EF79FD6197891B5B1215074EFA7299539A38F7AD54EA97AFAB41F4DC42AC0F8904F36BE791494EFBF4E0EE0D1257185B2A538
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..............)... ...@....... ...............................u....`..................................)..O....@...................)...`.......(..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H.......P .......................(......................................BSJB............v4.0.30319......l.......#~..D.......#Strings............#US.........#GUID...(.......#Blob......................3................................................$...........=.n.........h.....#.>.....>...x.7.................>...].>.....>.....>.....>...D.>...Q.>.................h.....h.....h...).h...1.h...9.h...A.h...Q.h. .Y.h...a.h...i.h...q.h...y.h.....h.....h.......................#.....+.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                            Category:dropped
                                                                                                            Size (bytes):525261
                                                                                                            Entropy (8bit):4.608916738911991
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:QdKci/CH1EcBdEjjjYEjQLw8SyteN1KaYEYF8+teM:2EM
                                                                                                            MD5:91A7F728567604FAB6ABEA623554EE11
                                                                                                            SHA1:8945E3296D8B60230B6E615329F362AEEB551511
                                                                                                            SHA-256:A6258E5296FD7457A827038B7C89F8AB25F573345C536D0A8DC892681A8942A2
                                                                                                            SHA-512:F4023B1C4C2929A8F6885DCFFA9613F997B78CC08E45C57AED892E6E3009337CA3916B8DC8FB662C86EBE98B6911DE9171766BF985749B8A9A61EC91039AA315
                                                                                                            Malicious:false
                                                                                                            Preview:<?xml version="1.0"?>..<doc>.. <assembly>.. <name>SteamKit2</name>.. </assembly>.. <members>.. <member name="T:SteamKit2.ClientMsgProtobuf">.. <summary>.. Represents a protobuf backed client message. Only contains the header information... </summary>.. </member>.. <member name="P:SteamKit2.ClientMsgProtobuf.IsProto">.. <summary>.. Gets a value indicating whether this client message is protobuf backed... Client messages of this type are always protobuf backed... </summary>.. <value>.. .<c>true</c> if this instance is protobuf backed; otherwise, <c>false</c>... </value>.. </member>.. <member name="P:SteamKit2.ClientMsgProtobuf.MsgType">.. <summary>.. Gets the network message type of this client message... </summary>.. <value>.. The network message type... </value>.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.712115863132619
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:9CAmXhpuwx9HlWgJWvJpWjA6Kr4PFHnhWgN7agWtYJxu3O6YX01k9z3AnE9:9qxvrWgJWvJYA6VFHRN74YdR9zKE9
                                                                                                            MD5:8DC6E3FB54FAA14613CE7A90722569E4
                                                                                                            SHA1:87F0EDB5AEE1326917F74586B8985C06C4246E60
                                                                                                            SHA-256:08E5A63DEB24F9F9DF1AA4128F2020644A86EDC8CC42D23D3E5E4E00A4A1F52A
                                                                                                            SHA-512:B29AF1804677F24B4E2A9EFBA474C66580F530C09B001E747D9E6676762FD0025D23B6CA2A400F2EA7B09ED7469F160DC32D79856DF30031FC55204EB8C9B936
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...s.$..........."!..0.............N*... ........@.. ..............................#T....`..................................)..L....@...................(...`.......(..T............................................ ............... ..H............text...T.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................0*......H........ ..,...................P ......................................5.Q.....Q...s..Wc....N.f%.........}.8........vB......o.b..3.R...J......2.ED...hg.x..&.F....5...6.xD_^../..G. ...l`,..[.\BSJB............v4.0.30319......`.......#~..`... ...#Strings............#GUID...........#Blob......................3......................................O........."...........;...........f.!...!.z.....z.....s.........;.......z...[.z.....z.....z.....z...B.z...O.z...v.............
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16152
                                                                                                            Entropy (8bit):6.795893683417245
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:bTbUikV/AvcaTAFC2xArKWJtWvjWkWxNzx95jmHnhWgN7acW6swKUWX01k9z3AdF:PbUVJWJtWvCLX6HRN75t2R9zGFP
                                                                                                            MD5:A6C3B858EE0CA8E265219DBDD692DA96
                                                                                                            SHA1:1A6C76B404ED9ACC793A7C1DAC68FB664FAE0718
                                                                                                            SHA-256:44BFFA0D3D0C59AFCB6205071167B52D6AE5DB3E8F167C955FBC5592EE422510
                                                                                                            SHA-512:6D466C9A8C5DF820DDFECDCEA511DF858CD7B26958A629D7F0463C0441DA1AE9B1F929C2B19B0B63D1F494C4338855AF2B333FD57E01AAEB99B0E35FDED3FBD8
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...d............" ..0..............+... ...@....... ...............................p....`.................................}+..O....@...................)...`......|*..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................+......H.......P .......................)......................................BSJB............v4.0.30319......l.......#~..........#Strings............#US.........#GUID... .......#Blob......................3......................................................x.....3.n.........^.................I....._.................w.................G...................h.....h.....h...).h...1.h...9.h...A.h...I.h...Q.h...Y.h...a.h...i.h...q.h...y.h.......................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.7207100865383165
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:cCA6iA+GWZvWvZYA6VFHRN7zr49R9zriC:qs+R+ZFClzr69zZ
                                                                                                            MD5:F0366F13E8A05F94B99A8CF97734C0CC
                                                                                                            SHA1:9AFFFAF9AA03E4B982662A951C6704DBDD4D82D2
                                                                                                            SHA-256:468A023FAE4823A00132B0D91EF77CD783A474B8AB16441AB5C879CB022397F4
                                                                                                            SHA-512:AA4D08B1101F0F2D54E5C48199671674B2AFBF7A1B7F8E22752984CAA684931E1BA5D361EFE3585A1E66F7625ABB22F63415B9F69F9DC6EF4B7E697DE459B688
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...C.t..........."!..0..............*... ........@.. ....................................`..................................*..N....@..d................(...`.......)..T............................................ ............... ..H............text........ ...................... ..`.rsrc...d....@......................@..@.reloc.......`......................@..B.................*......H........ ......................P .......................................8.e+...&.......x.zX{.0{.O.<...c.d.p....p......H..XT-~.c_N.;....3B....I.........Mc...W.P....h..3...z.qo.*J..=...).E..fBSJB............v4.0.30319......`.......#~......\...#Strings....P.......#GUID...`.......#Blob......................3......................................'.........C.............................g.{...%.{.....d.....{...|.{.....{.....{.....{...c.{.....{.............................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):129184
                                                                                                            Entropy (8bit):6.196981583264401
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:4YBSzjfI+HAOaaRH8/OhcRRY4beMDSZkXs3pMGudO:ifIcJxRHMOhO+Zkcyz0
                                                                                                            MD5:AD794A89E1FB0BFD63D31E0BA44A9690
                                                                                                            SHA1:38636C92963BADC5F01B4A3AFCCEA17BE099C4DD
                                                                                                            SHA-256:7CE9E667B76C9F647E7124755BF25F56115C5CEB3A68DBDFB0254CE16AECF19E
                                                                                                            SHA-512:5D48755E0C03D7554E5924DAFF35C1505987664E5C5BAC4F4CFB3B2DF7AC74AE214DC6B1D7D778FF04579360EAC86111A56467A0B4C86552669B109145972679
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....i............" .....p...P......................................................<.....`...@......@............... .......................................4..<........(......l...0...p...............................................................H............text...Qe.......p.................. ..`.data....8.......@..................@....reloc..l...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):288928
                                                                                                            Entropy (8bit):6.3565468587913
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:A4CftCb7K5nZsY8H6y1KmUc13znPwEDDOz4hJ0/8oFyS63ZUybmglHY2/YO/hUSo:qftCX6lu6gqyBDDOzHUddlttpUR
                                                                                                            MD5:C5B20B04C09A5A9E56E695016D5D52C9
                                                                                                            SHA1:507E9ACDC223A8DF9EC446158121F59BE73CE1C3
                                                                                                            SHA-256:1033977B422496B3B5F008979BE89CF9A06743581A36B6408CB4DED628D714A4
                                                                                                            SHA-512:BC608F0128ED30E40BD16F13E1C749EE86ECDCBC615184E59096697B04E3C69D879999DC9A14B4E047DD20DBD2CF81297E748F8F32AE92AD121A033813C269B9
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....g..........." .........`...............................................@............`...@......@............... .......................................`.......@...(...0..`...0$..p...............................................................H............text............................... ..`.data...6M.......P..................@....reloc..`....0.......0..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):30896
                                                                                                            Entropy (8bit):4.671392181687111
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:gWQvA1blqixkPVHulGwgjX6HRN7vDX+iR9zXoK41:6vmpqixoVPwOWvDuO9z4K41
                                                                                                            MD5:4443643BBA915CC3E79936F70A126AA1
                                                                                                            SHA1:33440C787A52D4C4CEC825B083AECC7D6E619BBA
                                                                                                            SHA-256:BC907F0FB61F2139B333DD22D90A18991190E56AE1B8E5F7F6544DBCA166A9C4
                                                                                                            SHA-512:EC4FD6F0417A4DDE8A4A88B30765FEF695E9A2C2A5C64C256E2DEC900C4F7DE7D50EB58117F07D137D13711391F9A4434119BB444C84D80EE5A63F6BC2011EF2
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....X............" ..... ... ...............................................P.......\....`...@......@............... ......................................t...H....P...(...@..$.......T...............................................................H............text............ .................. ..`.data...2....0.......0..............@....reloc..$....@.......@..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):18192
                                                                                                            Entropy (8bit):6.55554414057899
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:AYSj5rt9x+uicWKNWv9YA6VFHRN7s2IR9zXRv:ATj1t71c9FClPU9zl
                                                                                                            MD5:76436C13BBA8732978A08454FD284D23
                                                                                                            SHA1:359A7A36E8DF9517450BFF786C07C68ABC004C9A
                                                                                                            SHA-256:AD4C4C92BAD3D1BE04793A39377129A42C45C227FE404113FB9F9BEBDA3C4B06
                                                                                                            SHA-512:23DCEF122EE3DA9E0D3A40BCBAE1673DC5EF84103207D56FE5B3823E8D20D5B15124BC83DE0E6DD60AC06BDE8F0EE6527E7D70A654956DB68F4AF97FC4102A6E
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....4............" ..0.............22... ...@....... ..............................kK....`..................................1..O....@...................)...`.......0..T............................................ ............... ..H............text...8.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................2......H.......P ......................l0......................................BSJB............v4.0.30319......l.......#~..........#Strings............#US.........#GUID...........#Blob......................3................................I.....3...................................................i.v.........N...........%.....B.....5.........................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1288352
                                                                                                            Entropy (8bit):6.742211790346322
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:24576:Br2JFGlyXQfoVGd3HAS0gZZ3xhRToFP9x:BzZzZZmFr
                                                                                                            MD5:191F203634A63CEF1542DD95BEB5C4C0
                                                                                                            SHA1:B12F2314A6A5A7E9899DCF7E43789D2FA19A177E
                                                                                                            SHA-256:0F9B35AA4326DCB6B8E3EBB610C5ED6AD3A116A24A97A6CEBB6CF14C80B75FEB
                                                                                                            SHA-512:9AEEB8424F87E9D993AE2FDAA3FCBE4C30E6F04D3EEF20B848083FC8531C001A8EE1319B73A35B700FDA57868B39C5DCE1DA89F86E96BFC3232F4E1C5533763D
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....j..........." .....`...........................................................g....`...@......@............... ..................................<........B.......(...`..L....<..T...........................................................@...H............text...a\.......`.................. ..`.data........p.......p..............@....reloc..L....`... ...`..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):47264
                                                                                                            Entropy (8bit):5.383416201972765
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:768:NB+D3qmLYSzA+DUnFT08vkFY4mPFsNEFClDm9zw:NzmLYSz1DUnFvc64miNwiDyzw
                                                                                                            MD5:1E16A3F143BBC16769EDB8E90FEF330B
                                                                                                            SHA1:CAE5E3C1186E4C6631FA3A607FB09627E60CA6E2
                                                                                                            SHA-256:D10AB35B57C343C006F982473D98ED2D2125D6D311B131390113011BC96D820E
                                                                                                            SHA-512:05A5FE0E8488D28A691824119F0B3FA03D493D91CEBED9977112A40C1BE7AB69E34ADCD49595386F231CBF756AA2CE0469867FD398642AB107B3D6449A6B9A99
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...=............." .....`... ......................................................0.....`...@......@............... ..........................................8........(..............p...............................................................H............text....V.......`.................. ..`.data........p.......p..............@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):47368
                                                                                                            Entropy (8bit):5.343676854529679
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:+W+wWvLfT+rudWBj/DbodqYfhKnVsL9WkS89KJKfCvDXxO88+aEZ4jIwVsBvzN42:eRLkYoYkaBv688IVO/X8FCltxf9z56g
                                                                                                            MD5:CF4ADD9E2E8C056C75B770CA9E4B64B8
                                                                                                            SHA1:B8EE4E78731D0D65E3EDEAF9C263BF703873AD7E
                                                                                                            SHA-256:A28CE11CFA6608760F22E102423BFCD6AC33B693287C1F15AFBCDABD3EBAAECB
                                                                                                            SHA-512:D72DEEC88359E38454FC783B82FF7C36CE0A50FB76DBFB74E469F7BA262457105474E80F9DAA09B04A10CAA70A45860D83926ED80EFCE8D685FE1961599B057C
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d..............." .....`... ......................................................7M....`...@......@............... ...................................................)..............p...............................................................H............text....W.......`.................. ..`.data........p.......p..............@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15520
                                                                                                            Entropy (8bit):6.736585195684987
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:YfFQWJmWvMYA6VFHRN7YgJtHNsAR9zF0TYZbv:6FHHMFClLts89zmTM
                                                                                                            MD5:80BCD0CC0FED45B44F8AE08E6C55ABE4
                                                                                                            SHA1:21C2FFCC9848ACC81BAF04B7BAC62978549E1D87
                                                                                                            SHA-256:1F3F7EB23DE0768F8BBE4F043EC8818E42AD66D7438A60991B2CED69F67A94F5
                                                                                                            SHA-512:394EF89DFFC287C0CF2E9BC76A4D88AF4277DD0B34CABFC8BE9747F79A6BFECD69F8A56EF3D5B17D64C9B1AD291C9681260B5D4B5FAD4497CE691F565BA04FA5
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..............)... ...@....... ....................................`..................................(..O....@...................(...`.......'..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................(......H.......P ......................,'......................................BSJB............v4.0.30319......l.......#~..,.......#Strings............#US.........#GUID...........#Blob......................3..................................................U.....U...Q.B...u.....|.....7.*.....*...g.....}.*...L.*.....*.....*.....*...3.*...e.*.................<.....<.....<...).<...1.<...9.<...A.<...I.<...Q.<...Y.<...a.<...i.<...q.<...y.<.......C.....L.....k...#.t...+.....+.....3.....;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.750565769577352
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:qBz2EM0u8ZWI7WvtYA6VFHRN7ptHNsAR9zF0+T:qlE2KtFClXts89zmU
                                                                                                            MD5:A1A92B8791B4D56C7B6E335483E38135
                                                                                                            SHA1:8C9D7FC7B452C7993313D349722A2C25283BB53B
                                                                                                            SHA-256:9B1F4F2C7FC17D2CD4F49FECDD6B8D71C77998F54509EF1B28F2910DC9A6B618
                                                                                                            SHA-512:B03148C8FB0F67F5D1C2ACBFF7BE34C8E5D9E17B4FDF60C85AF3437815AACC69DE8DD3E693B44C7E40EA8228EA1E3399849646666046E218972F2CAB8B15CB29
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................."!..0.............^+... ........@.. ..............................(v....`..................................+..T....@...................(...`.......*..T............................................ ............... ..H............text...d.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................@+......H........ ..D...................P ......................................,......#...>....'._D.Xf..........jgO...e....(.."..e......)>. ..rn.Q...2......i$)..>gC..=.a.f.u...H.].p../5...O..../3..BSJB............v4.0.30319......`...|...#~..........#Strings............#GUID...........#Blob......................3......................................].........U.@.....@...n.....`...........T.............y...0.!...9.!.................................u.............@...........
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):55456
                                                                                                            Entropy (8bit):5.600389797972162
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:768:WeKDjiacl7ACvmx7FKI+ptTD9Wg7k57n2eJqFCl/wDuO9z4KB:WDya0cCveFG75Wr2eAi+z4KB
                                                                                                            MD5:320327E2A99304156AE3B0EC3F134270
                                                                                                            SHA1:71AC532EA74B4310DA58BA9F0529DACC0C19F1AB
                                                                                                            SHA-256:0D4095AA5E0373F21F0D046E0EFD3304624156D36ADEAE2996E7652A222AE4BF
                                                                                                            SHA-512:EBC7C767F5F0E3A1B070D1D4BF4FA939A5FBD4183F9BF0003FF2EFCB68ACAC84F4B7B5983334455F7A21ED9230560AC33A4E3B3A741B5FDD8D6EE6498B70EF3C
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....4............" ......... ............................................................`...@......@............... ..................................$................(......d...h...p...........................................................(...H............text....v.......................... ..`.data...............................@....reloc..d...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1530016
                                                                                                            Entropy (8bit):6.604389115791053
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:24576:js+K3mAKW1QUvE5k9fqzGgBBg/NGidXkOJxPSqQRJzAJO:js+NAKV5k9fqzpBg/NBdXkOJY
                                                                                                            MD5:ACF93F1D6F7AAB7CBCC26DFBC12348F2
                                                                                                            SHA1:A1A49DD8B6607E4D382DDC95A04528EAA98804A1
                                                                                                            SHA-256:3446ED6793FD49E51580FDBB047A8F15F81950D0039C2181396E3A9CC327774D
                                                                                                            SHA-512:FDC14BCAB8815987A320D9618872D978A314F3C0A3048D00EF408CBFCEE8DE67BFBE2197AE15675B813D8BC084DF33115E101F63B297E2C548E96E3200EF6A23
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." ..... ...................................................0............`...@......@............... ......................................$...p....0...(..........(...p...............................................................H............text............ .................. ..`.data...g....0.......0..............@....reloc........... ..................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):264472
                                                                                                            Entropy (8bit):6.565006382155934
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:B14BmTBMCV3tgcWf/e9wYxn1Wc/od4pFFm4n2C:/GCV3CfqpFFgC
                                                                                                            MD5:DB981290B935938AA7FCD85B332E370F
                                                                                                            SHA1:21E754B0DBBC323F6444D38E551AD4237C1E3CF5
                                                                                                            SHA-256:D57CFCF89FDFAFC8B5F86B7DA586B72AFF6B1997AE7896A17323993BF1741389
                                                                                                            SHA-512:45EE7D549EAC2990B17F15AA326DF1CAC57825C5E5EA2E1F854C9EED352FA03102687FD8FAC041F2CBCCAC4CD690EBF609B7AC4EEF5F97859079974BEA20DF02
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.... 8..........." .........P.......................................................K....`...@......@............... .......................................f...........)..........X%..p...............................................................H............text...5........................... ..`.data...2;.......@..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):2255024
                                                                                                            Entropy (8bit):6.594152174912454
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:49152:BSSZ/3BjajYVeLQo2P6AjRIOuoU82S1VGG2hFGYYB45gkQdh:YSlR6A6oU82S1VGG2hFGYmh
                                                                                                            MD5:3A905AF6B4A0C8431E438B35E8E0AFAC
                                                                                                            SHA1:7F33226B0501ABBB4A8E685F752A172F4A486987
                                                                                                            SHA-256:56799A464AB74E86F00104D3CB39DDEB6FCA2E9DA8CF063B660CE67C47A2979A
                                                                                                            SHA-512:AE69AB68318DD3F4931F657A95231E8BEC5D6EFF007A29C17A1FE22448E1F5A5D06B0C5FE76E614AA5EE71CB546C74451904911FD8C415DA5C360FF1AAE8F2A1
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...j............." .....@ ..................................................@"......."...`...@......@............... ......................................tj..<....@"..(...."..%......T........................................................... ...H............text....7 ......@ ................. ..`.data........P ......P .............@....reloc...%...."..0....".............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):104712
                                                                                                            Entropy (8bit):5.9531643262406995
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:4QoktJ1UcLZmsYAZwmkXjhXVrMZREnZWzUdhiszMO:4jk9vZ7I1GZKZPHoO
                                                                                                            MD5:7DFE9C0A526E8BE845FDF94C77A40215
                                                                                                            SHA1:C3C84D477A91F553167C88D7DC77EC77723138B4
                                                                                                            SHA-256:4F96E191302A84C970545AADB2FC53FA9B5455B1DE54187A5373E0E3B5C90991
                                                                                                            SHA-512:61971E48894E92832ED76967B06E0D8AB57B8748096159852BF2F6AD8C74F8B6DC759EC3FA868AE91F1F08D4F9ECB15CC3A8DF697452DD17972A96715B0C73A3
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....n............" .....0...0...............................................p............`...@......@............... ......................................@0.......p...)...`..........p...............................................................H............text...*+.......0.................. ..`.data........@... ...@..............@....reloc.......`.......`..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):203024
                                                                                                            Entropy (8bit):6.207298456243025
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:ADzcvTHdJdCe4dCLLe+Yfn3gwmMWQArD5/oE5bF65eUV/uuTG:AQT9WDvgwzWQArHUV/uui
                                                                                                            MD5:2B2EBCE91DD24647BA64032AFF474EEA
                                                                                                            SHA1:633B37C3F8ED3E2E036A6301E3A99AE2382F9BE6
                                                                                                            SHA-256:CE51C0A016E0D830BB2325B917DE3B959E42DF82C47A681287C97F0C27846AF4
                                                                                                            SHA-512:9718A8E686CA2F7E27DB887AB94E0C5578CDA23170C27E97BEA1D0F95A30F29A4D742BDBC791C1E2F91D9AD5D2BE383701DBBA3D0AD054DA06D30863CD5DA1F4
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .........P............................................................`...@......@............... ......................................0I..p........)......L....!..p...............................................................H............text............................... ..`.data...M9.......@..................@....reloc..L...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):837896
                                                                                                            Entropy (8bit):6.723078162409922
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:crJR+uRoPwK6eN8/98vTU4dQEE3k0T9YLVgHr4lucvMgllgg9n:w+uM8abw+CMlFDll/n
                                                                                                            MD5:E8D86E48D55490F58ACC8DDDCEF458CC
                                                                                                            SHA1:DCDB9C0D60B300467962E58602A82BBE6EC77AAC
                                                                                                            SHA-256:FC48AA677A344F912C1A9160115DAFD396B4F69EEDD27F4B53B14C2B512E92D2
                                                                                                            SHA-512:18F993F4C7899856AA0C6AD200863D2444FDFA4745ED4CB961AA38DB9F7E6DCB5576665CC1D487A9D1EA7C3B526A95710734AA65049410CBC2E58FD7C3DEFD15
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...f............." .....@...P...........................................................`...@......@............... ..........................................Hr.......)..........( ..p...............................................................H............text...P0.......@.................. ..`.data...L$...P...0...P..............@....reloc........... ..................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):8542368
                                                                                                            Entropy (8bit):6.777702600079919
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:98304:HmsdFJMKLTfQUtV5sIexZwO1oHy7xAz+BianSJhw36pbIy6Py99:zJMKx6BxZr1manSJhw36+y6A9
                                                                                                            MD5:EB08E99C6FCF641A2D936D4E16160408
                                                                                                            SHA1:B0C22D6F0049629BD3575430FEF188F13E593906
                                                                                                            SHA-256:C325EC0006A3A743CBF2DF266E6C57A3B07BD0865938467204AF1F36992C8A3C
                                                                                                            SHA-512:3BAB6873F737CED3CC8700EF953355DB4F7B9DE3706EF35BF87516A3C4ECF3A9FAC77EF047266B3C4BDA3DFF146CAE329A8ACAF5B9E6B5D27D86152A64B679E1
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...h.2..........." .....p{..................................................0......IN....`...@......@............... ..................................L...l...h9...0...(..........x..T...........................................................P...H............text....i{......p{................. ..`.data...w.....{.. ....{.............@....reloc.............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.7004639534089705
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:puw2W9NWv5YA6VFHRN77vhk7vDX+iR9zwB6:puoc5FCl7pEDuO9zR
                                                                                                            MD5:B68AD44BDAF4F427A9E17E58326AC076
                                                                                                            SHA1:6274AB86C6F1F2A0BC2C13C541BA970AB7B7090A
                                                                                                            SHA-256:5A33C014C9AD5C8A60E889F80F1D9E4B3D36DD10FAB49BD1D2538325E7B6EDAB
                                                                                                            SHA-512:1911C839E162A8FE4ED80A5CADCB9019D74E07CFEDFD68AE151A66D0B38A9A601CFE458EA1FB79B608A799618C454EC70C971A5F3EE92C96E35BCE77C3604907
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..............*... ...@....... ...................................`.................................a*..O....@...................(...`......x)..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................*......H.......P .......................(......................................BSJB............v4.0.30319......l...T...#~......T...#Strings............#US.........#GUID...(.......#Blob......................3......................................M...............x.....3.....7.....^.......m.....m...I.f..._.m.....m.....m...w.m.....m.....m...G.m.................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):174352
                                                                                                            Entropy (8bit):6.296291995805638
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:i3adgejQmgA0o3eXZI6e07fww49JKotL3aZv0Tl:EadgQuA0/pI6eufww49F3aJ0J
                                                                                                            MD5:B58CC7032740F5EEC429E8414737B9EC
                                                                                                            SHA1:A18595EAD4A4F6ACE6F03B94248ED8E1BC1E599C
                                                                                                            SHA-256:59656C67991255D19B868DC1F48D1AD10BC8D8B6C667F792C2C9AFFBF69E47EF
                                                                                                            SHA-512:4382B3227139F6D15CBC4E2E25D4DB33B591FCC56E28E4B02D1FFD91F485CE908F0FCA236ED214B974483D856B92F348C48A06A7C1036CCB716DD20E7E69DCCD
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................" .........p............................................................`...@......@............... .......................................+...........)...p..........p...............................................................H............text............................... ..`.data....V.......`..................@....reloc.......p.......p..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):84128
                                                                                                            Entropy (8bit):5.965475930237355
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:rRgoICPT0eXImrmODZcUBeZ8j0qEHawde3qGRm3LGgmi5zS:rRgo9PpYFtZ8j0qEHawdezRYGgmGW
                                                                                                            MD5:2552D8702CCE0128057F347BF760AD72
                                                                                                            SHA1:F32D9D8051C0820CF92D6D326D7CD65226850A75
                                                                                                            SHA-256:5F4184FD0607DCB2E3006118B618AAC3417B9C52E51C6D58C9C396A1F6AF9720
                                                                                                            SHA-512:F25554ECCED6E7FF8FA370C8A2D526A204BA7139AA944E4B42F010F30A199DD7C0D434A187DB9CD97CCFB054B9810E059BD3A50C5E0C2B40594C741F289B2DFD
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." ......... ............................................... .......@....`...@......@............... ..................................`....'....... ...(......T...`...p...........................................................`...H............text............................... ..`.data...............................@....reloc..T...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):280840
                                                                                                            Entropy (8bit):6.504374684121034
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:6T5mQ9WRSfuurvHljMR4WGTSttIqq+xM8cSA7ljZZ2uy:W5/9WRSfuMHljCxMkA7lNZ2uy
                                                                                                            MD5:D351D8F0647E32577C3F03481B85A225
                                                                                                            SHA1:611C0862E644752153C74E81E6603EC0711F7BF8
                                                                                                            SHA-256:32409E5B1F753B13850D2C88CCBA73CB9CC4678D41F11A6B30C020AF3B787054
                                                                                                            SHA-512:A4AA5C66899B9E7FAF6B30E84826AF4F2CAC4C8A0EEED0B4292B30642FAC53AD20C42E401D9448195B78AC88A2D2F8F0D5AF28A9484E6B0D85570C15C7EA296F
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...2uJ..........." .........p............................................... ............`...@......@............... ..................................P....b....... ...)..........p!..p...........................................................P...H............text............................... ..`.data....U.......`..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):174240
                                                                                                            Entropy (8bit):6.276884758080206
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:ioeEmXYzdfd6+Vfz5mDVVdwF6xARZvcKZzxuR1BB1GwRV:Ve1X4fd6qwVdC6x2ZvcK14B73
                                                                                                            MD5:60BE3B0FE0CE54306E547728C541616F
                                                                                                            SHA1:505519153734F9B58FB37DC4E86740FF7D057896
                                                                                                            SHA-256:577D62369B948EC8DAC8D01403987007EDEF6409A8FAE7DF733FBBC068086A75
                                                                                                            SHA-512:AB770C4882396808EA49D216367853D0041A63F20CEE3F6BB64A06417D7A5AF07FC1C19BB60948B04D411D0B27B45B1B3C5C316F1D06E623A34B54E79512D055
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...<r............" .....0...@......................................................H:....`...@......@............... ..................................P....<...........(...p......X...p...........................................................P...H............text...}!.......0.................. ..`.data...."...@...0...@..............@....reloc.......p.......p..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):133392
                                                                                                            Entropy (8bit):6.080206645595261
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:LQz5724yeP4Sy2vmH00N6no5WkCIJJoRc0onc:y57O6mpMSoZB
                                                                                                            MD5:4E55F8E2CD309634892AC4E34D78D1C7
                                                                                                            SHA1:B96BF1860E415BDB99BCD94AF0973F31D0CCAD7A
                                                                                                            SHA-256:E8A06462CDFB428C9ACFC5ACA4BB97AB6D2C715E8029A6CD8FD5760F831A3D92
                                                                                                            SHA-512:C4F154AFA33991A3F2494F92AE0A0F2866A21C55DBC86DFD789DB143A72C241589553E433B8C86B8EBC2FDA8A756E20AE4BD59FE368200A5F094C29208DC81F9
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....D..........." .........0......................................................Rn....`...@......@............... .......................................-...........)......<...@...p...............................................................H............text............................... ..`.data............ ..................@....reloc..<...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):2082976
                                                                                                            Entropy (8bit):6.703393423935663
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:49152:lEOFavlNDjaq8s+3kOCP8tOEFxOouLsY2DLzv6EI6P7:lE8a2kdUy6P7
                                                                                                            MD5:219492E04A852A3AD7A112EDC2559480
                                                                                                            SHA1:6AE74ADDD7165FDBDB7E038AC9BD2C2B9522ACF2
                                                                                                            SHA-256:29C546097FF7E5AC94202E71311EF2BCBAE2D7DDEA6BF8E951F1FB3BC942DE75
                                                                                                            SHA-512:994A2C824539DA7C966A57CBB4B58B4A89F283BF4293C27AE33B9A6B0EE267F8DCDB644B96ED80080D449615A6EA672552EB16250EBCC8AE1220A3DB5F3F2F0C
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....Zi..........." ................................................................k.....`...@......@............... .................................. ....[...........(...p...'.. v..p........................................................... ...H............text...+........................... ..`.data...X...........................@....reloc...'...p...0...p..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1452192
                                                                                                            Entropy (8bit):6.692930879882557
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:24576:s9tKjFlRYS616HJ6cC/X3pqNRPP0AjFAdgGPD6+a0Yre:PlyS616HJ6c+ZQntKnaE
                                                                                                            MD5:E54F1341C9288EFFE1A21BCC372CFC68
                                                                                                            SHA1:AB8DC7991A47FD33051CB7D403DFDE31BCF6493D
                                                                                                            SHA-256:1236B218A205E8114EA578F8A3F19023A1A8FA2D01BA96E89F4182D84F41FB68
                                                                                                            SHA-512:7B33899C861ECB8C2A8D68081B31AD811C2E41D525ABC9967E64639E2CCD3C000E24D6F4377C8B295352FAA33637B3263D6D1D7F484A9BC48742E56DD2899B2C
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................" .........@.......................................................m....`...@......@............... ......................................LW...........(..........HS..T...............................................................H............text............................... ..`.data............ ..................@....reloc........... ..................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):393488
                                                                                                            Entropy (8bit):6.332083868536635
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:8LsyeU2urknHxoHs+n1wg1xhDrLj5OAS0+QB02u7FksfEX7RPzfUz:ysyN2urknCHsAwgtrsA6Qu2v7dcz
                                                                                                            MD5:4DF8367F195394E23720173C751CF159
                                                                                                            SHA1:E215CF52164D4180605D5C16F873691649F4C32E
                                                                                                            SHA-256:29BCB525992E2BF1DC2C66918450ADE3B36E88226B1CEAB18A8C110A0E0DA0DC
                                                                                                            SHA-512:FD5DB356CB08578B731C62AFE3A98D57FDE6889ED1664038F01FBEF00FE06C83BC93365CFE94B8D23906990BFF5DA437A97C684C69CB61812E46C627C55CDD34
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........Q...?..?..?.Qb<..?.Qb;..?.Qb:...?....?..>..?..>.Q.?.e6..?.e?..?.e...?.e=..?.Rich..?.........PE..d......f.........." ...(.8..........P........................................ ............`A............................................ ...0...........x........2.......)..............p.......................(.......@............P...............................text...\7.......8.................. ..`.rdata..(N...P...P...<..............@..@.data...............................@....pdata...2.......4..................@..@.rsrc...x...........................@..@.reloc..............................@..B................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):17168
                                                                                                            Entropy (8bit):6.744985038171994
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:2Hzoc2l9WWfWv7YA6VFHRN70ORxB+R9z0AG:4zovlru7FCl0ORxw9zXG
                                                                                                            MD5:D671EFA2A023A61CCA5729BC5696B4FA
                                                                                                            SHA1:B26DFFC059655C32092CFF62F6C6D074C4F2B186
                                                                                                            SHA-256:02C67B42BD1C6E8D8954F96C3AB7C00575E7FAAAACCD58A8F60CD20CD74A2D43
                                                                                                            SHA-512:0EDA02115C25C6BE1F48D5EF85C87C2889F9ADEACE939F17320EE25EE27BDCE741E18289D7E36E2B1634C2C56AD1EE38C6B1DDE05A735E2CBF910DF4060F0AF3
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....c..........." ..0............../... ...@....... ...............................y....`.................................s/..O....@..D................)...`......X...T............................................ ............... ..H............text........ ...................... ..`.rsrc...D....@......................@..@.reloc.......`......................@..B................./......H.......P .......................-......................................BSJB............v4.0.30319......l.......#~......T...#Strings............#US.........#GUID...........#Blob......................3................................-.....r...............'...................X.....k.....k...........k.....k...i.k...&.k...C.k.....k.....k.................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):18592
                                                                                                            Entropy (8bit):6.50782634151712
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:uW7XHkE3jDvupZFiVyJjxA7A63WwDWvtpWjA6Kr4PFHnhWgN7akWWKIjwX01k9za:5If+3WwDWvtYA6VFHRN7EHR9z0A27ELu
                                                                                                            MD5:042B64BA15515B5ACC1B53D31076EADD
                                                                                                            SHA1:C8D810607D642B7D63C4F0A70FC5D891CD0C4D83
                                                                                                            SHA-256:5CD2E42D0C8C3BEAD4B8BD993750A3D5D266039DAA52506F7BFC27783990226E
                                                                                                            SHA-512:E624E89ED367F0C91D8B597CB351A030ECD6FC0CBE45AE5AD5F48A45D76C0C3F28EF8A4BFDFD32D37E51A7555E7FFC74B0CCE5E751FF0CAE6F8C7E8A90F9953E
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...~............." ..0..............4... ...@....... ...............................J....`..................................3..O....@..T............ ...(...`.......2..T............................................ ............... ..H............text........ ...................... ..`.rsrc...T....@......................@..@.reloc.......`......................@..B.................3......H.......P ......................P2......................................BSJB............v4.0.30319......l...H...#~..........#Strings....h.......#US.l.......#GUID...|.......#Blob......................3................................O.....................0...........3.......x..... ..... ........... ..... ...r. ..... ...*. ..... ..... .................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.C...+.Y...3.o...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):137392
                                                                                                            Entropy (8bit):6.141873621571383
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:hJ4+cFoEaEKuh23IIBbL61G26uREGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGV:E+cF+Ezk3b0AJ0EGGGGGGGGGGGGGGGGA
                                                                                                            MD5:AACAA4C6CF82CC31170B35E85088BAEE
                                                                                                            SHA1:729F82BDA28D082F6E50DC92A8FD3CA535F51F8A
                                                                                                            SHA-256:7A758A27E1EE75D4434332984FA37875A723DA0E6BF31D9160C8986B0315C4D6
                                                                                                            SHA-512:CD92A09D0F89AA4A5C3C06D079FED08B4804562CA89FD2798630520D07DC1752295BD7ADBFD6DC23BA8C6BE6FF3409C2EEEF33EA98F0C861EEDFA7BBC4597A0C
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....<..........." .........0......................................................;o....`...@......@............... ..................................P...D5...........(..............p...........................................................P...H............text............................... ..`.data............ ..................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16032
                                                                                                            Entropy (8bit):6.760114531130961
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:KLIiUA/xzgWddWvBpWjA6Kr4PFHnhWgN7akWMgtUtxu3O6YX01k9z3AnQQO:KLjJ8WddWvBYA6VFHRN71JR9zKQQO
                                                                                                            MD5:F5C6679493D864440EE6A19B508D21C4
                                                                                                            SHA1:8D34E56F84ED52F3AEAC4E074505D2BCED16A189
                                                                                                            SHA-256:52FD1A9D7666DB207E9F447A2F0C530C43539370633F1A8DA4CB930B9F62B420
                                                                                                            SHA-512:5082DC05D0B99449F2B5231614FA988A990313DEE7F96A49600C2CBBAE50EA1AF453C77EA018156413849541129836AFBCDDD1D6053D94A00C3D2D51FCCD3419
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................."!..0..............+... ........@.. ...............................n....`.................................m+..N....@...................(...`.......*..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................+......H........ ......................P .......................................&.H.....y.V!.. hs..p/M$..HQ.....Y.<.k/.q.&.9.....m.R...f.BgH.WL....c...:7..N#..[...5cxJ.t@.?...Z>e........~x.......`6).BSJB............v4.0.30319......`.......#~..d.......#Strings............#GUID...$.......#Blob......................3................................................L.............................p.L.....L.....8.....L.....L.....L.....L.....L...l.L.....L.............................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):288928
                                                                                                            Entropy (8bit):6.5444388161484195
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:5n7+Xf7eNhl3tukQB0mVgGLknb6bQSBj/Fx:5SXDe3F8kbXOkGbd/X
                                                                                                            MD5:07B65047D965B216881DBEA41FE6195B
                                                                                                            SHA1:55B9DEF720100000E115C4DD0EE887F76AF547EF
                                                                                                            SHA-256:FCBB8213C0E39D76C251588A9D6DF23B956559CE18FB38C1E7E036E822B14934
                                                                                                            SHA-512:B83292085F1C38F9B0C4F7CABF217C5B18FA5F27804CE736EAE6AB257FCB0535F6EA6BEAC88357F779A428ABFC9A3068B57609076B4F14F99C7B9EDCD6C8BE1E
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .........P...............................................@............`...@......@............... .......................................l.......@...(...0.. ....!..p...............................................................H............text...D........................... ..`.data....;.......@..................@....reloc.. ....0.......0..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):30880
                                                                                                            Entropy (8bit):4.305226325250858
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:jWe1Wv4QqU2+30cM5YA6VFHRN7kuiHR9z0vD+z/:N03eFClkt9zaD+z/
                                                                                                            MD5:F0A9C1F351FD248118EEE637D9B404D6
                                                                                                            SHA1:25596AC1293D92EB144261BADFA3E76D51413E65
                                                                                                            SHA-256:A3E2FE9700B643FCCCE0628540A846F45714F51A9DA17C0FFE56BDC4C739046F
                                                                                                            SHA-512:0F05B14C36907A33A13EAD741F48C6679D06F42D667AA517CB31C8B06642499558D985C2955335CB3F426B63410B84B9E21E27A84546CC6EC8BAE84116058321
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." ..... ... ...............................................P.......I....`...@......@............... ..........................................0....P...(...@......0...p...............................................................H............text...1........ .................. ..`.data........0.......0..............@....reloc.......@.......@..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16136
                                                                                                            Entropy (8bit):6.7781584154919665
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:ifO9v9WY3WvbYA6VFHRN70zwVXC4deR9zVjTTDS:OOFZ2bFCl0cVXC4dC9zVjTnS
                                                                                                            MD5:8B04C9FB125B99DA5BFC0381692A5FD3
                                                                                                            SHA1:19746B26152A1A83A0A5B3A736A131CB59287779
                                                                                                            SHA-256:825A454E5B4595CA7F105A308288873A9A28F02EEA1A524D395AED224DBD57A2
                                                                                                            SHA-512:15F30712C990050A455708CBCF2AF2B18F1FDC4581E5F0A2A3E7992F3AFC8C59FE110273AF9D7FFA9E0D0D7F7844D5C0AD1CD6950C9F235BEC7389B6B5D5C27A
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....4..........." ..0.............v+... ...@....... ..............................%.....`.................................#+..O....@...................)...`.......*..T............................................ ............... ..H............text...|.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................W+......H.......P ..D....................)......................................BSJB............v4.0.30319......l.......#~..........#Strings............#US.........#GUID...........#Blob......................3................................................4...........r.................X.............(.........m.......................T.........................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):2861216
                                                                                                            Entropy (8bit):6.795350514221502
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:49152:/LlMm2mf+ncGZUm3k+mywJOHPxIyiNMZ62YGkO3egTxiZsc5hBhB0X1v:DOOQZYyZ62YGkO3egTxiZs209
                                                                                                            MD5:D9A6328A389DAD8E4A5C9BF9EFD8FA77
                                                                                                            SHA1:05C93E421CFA10B7504E867E8EDEB3E68C4EBE8D
                                                                                                            SHA-256:1BB6848E76A1AC2966515EE04B80FFF63A1566CC086F267B184040E9F681E808
                                                                                                            SHA-512:052CF47E55E025A03E7E0B92FFE49B8131BF7E7A0E46A4244598077601AD01B72D4060A393E8214CC4045435D930F9516B740D0DB666FF1207D7D0E7BCCC50A6
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....a..........." .....@)..0................................................+.....0.+...`...@......@............... ..................................p.............+..(...P+..-.....p...........................................................p...H............text....8)......@)................. ..`.data........P)......P).............@....reloc...-...P+..0...P+.............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):16152
                                                                                                            Entropy (8bit):6.7495299582867805
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:UVhg/xiIqHVWbodB5WvgWcWxNzx95jmHnhWgN7acWnqAgfcMbnoQNpX01k9z3AZl:UV0fYVWbodB5WvtjX6HRN7Eq/7R9z5iR
                                                                                                            MD5:083C2972E3414380BD45BC621EB5295D
                                                                                                            SHA1:1F3ECEF2865EC4C45E513A9846258DC6A280B3E8
                                                                                                            SHA-256:17AD1F1709F3A153FA0DBD43D4DD46D2477D090949AE86E7E88953D8C19A83F0
                                                                                                            SHA-512:7F3E0AFC520CB9C6C7D8DEDF3E97B4AEDB8D44EFC2BDD1CBAF27CA02A0DB5E09BDC6FCF6894E22A548575BF523AE1A6895838BB816A5DE1323EBAC87C0A3DDAB
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....0..........."!..0..............*... ........@.. ....................................`.................................S*..X....@...................)...`......L)..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................*......H........ ..|...................P ......................................j.u..j..y..p...C....+........4.n...Y..\0$c.....?^BV6...LR.mF^..8...P.....c..}.:Ac..W.5_.c6r.}.db...8>...?{....eq$>..-...<..pBSJB............v4.0.30319......`.......#~..x...d...#Strings............#GUID...........#Blob......................3............................................................3...........^.......O.....O...a.....w.O.....O.....O...w.O.....O.....O...G.O...I.........................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15536
                                                                                                            Entropy (8bit):6.73756934231282
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:38lEdg8Wj2WvQlWxNzx95jmHnhWgN7awWHBm+0U8X01k9z3AH5Q:3C0Wj2WvQGX6HRN76Bmo8R9zYG
                                                                                                            MD5:B2F03EA9F7B56D26733B2A1C9224A397
                                                                                                            SHA1:6C49E77764E38C99E092B4D74B8D22954723289A
                                                                                                            SHA-256:236910220ECDC4F1E7B0A6EFFBED8A9177AEE6BCB090F16807E83368F17563DB
                                                                                                            SHA-512:A1F2B9BAF03DF6D68DE01DF6D33970819668A46138CE38925426437E63A8A4A075DC0D4B6890A1C06DD40A95D6FC8657C8D6F791F356F68DD729A7B7CF7BB5DB
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..............(... ...@....... ....................................`..................................(..O....@..T................(...`.......'..T............................................ ............... ..H............text........ ...................... ..`.rsrc...T....@......................@..@.reloc.......`......................@..B.................(......H.......P ......................('......................................BSJB............v4.0.30319......l.......#~......@...#Strings....L.......#US.P.......#GUID...`...x...#Blob......................3............................................................?.....!.....j.....%...........U.....k.....:.......................!.....S...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15648
                                                                                                            Entropy (8bit):6.828509514457341
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:icRPWYRZRp0RjWvUfX6HRN7UJRFDR9zzKKDmP:iWNvpuiUfWCzl9zs
                                                                                                            MD5:7BE96ACC4C7DD6DAF7D374CD907E9E69
                                                                                                            SHA1:32A66E89D313C03054DB64C0E2817B377D395B88
                                                                                                            SHA-256:41D02C060070592CB1E75C25E1F052823DE17DE692F65C53A0050E292156B4C8
                                                                                                            SHA-512:2891F08E8CA1321E555841CA8C8A831CB4C1090DEF9FCDDFFA5973E2FFBA3694C53F52861F92D41C146A51F3FE1EA96FED99609C84A35C8378AFE8D4B7630B00
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...;............" ..0..............)... ...@....... ....................................`.................................k)..O....@.................. )...`......l(..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H.......P .......................'......................................BSJB............v4.0.30319......l.......#~..4.......#Strings............#US.........#GUID...........#Blob......................3..................................................8...x.8...3.%...X.....^.................I....._.................w.................G...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1116320
                                                                                                            Entropy (8bit):6.6439477896792
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:43e0ziO6AJ8+utVRA8WDlLeO9om5EoU/mSdWKURfeGWTbrWnoDzgVdkn:43e0BlJ8TRocOWmc/DamGWTbwIn
                                                                                                            MD5:496F077B5C7B487EBF3E6222A53783EB
                                                                                                            SHA1:EEADF861F1EC14A8FAC957ADC2191B252E609FCE
                                                                                                            SHA-256:F8DC3E1AFC09A8C21B5C4C7AFB17C520AFE0263CCE8366CF57471D1D203728ED
                                                                                                            SHA-512:DDD0BA22E2BC0F76DA573EA6CD4AEC89A0F3CC1D32223938C963850F2348D1C8086C508E06F4076F3820A1A2B35A47D0497C4CA5E211CAF5BAC18BBA4F53185B
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....3............" .................................................................Y....`...@......@............... ......................................@...........(...........W..p...............................................................H............text............................... ..`.data...A...........................@....reloc........... ..................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):17160
                                                                                                            Entropy (8bit):6.688880877671809
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:p6Xu2tNCj8NMbLWgV4BHWvPYA6VFHRN7wVKau2R9zGN0u:MXNtNCj8NmPV4BGPFClwAauK9zI0u
                                                                                                            MD5:C173858DDAECFEB532221BC0714655E9
                                                                                                            SHA1:E6C6812A3562369FD0DEAC4A58573D278FE61E65
                                                                                                            SHA-256:3FF4F2C5A52617AC51B1B030FA1C77D5BCE4CB39C173BB78EFBBBC2A7C84BF66
                                                                                                            SHA-512:A0825419C6C6C118D37D11276E079EF64D94321E97AD880CAECB8AF41129E19CDF769AC3A762637E108443AEF7CBD171C4ECEA0369C515752911B5AA36F9B6A5
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...v.D..........." ..0............../... ...@....... ...............................j....`.................................u/..O....@...................)...`......|...T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................./......H.......P .......................-......................................BSJB............v4.0.30319......l...d...#~..........#Strings............#US.........#GUID...........#Blob......................3..................................................~...<.~.....S...........Z...a.;...{.;.........#.;.....;...0.;.....;.....;.....;.....;.................3.....3.....3...).3...1.3...9.3...A.3...I.3...Q.3...Y.3...a.3...i.3...q.3...y.3.......:.....C.....b...#.k...+.....+.....3.....;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):30896
                                                                                                            Entropy (8bit):4.273248077657323
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:JWHeWv4UpNUVBZu4xVXY7mWWxNzx95jmHnhWgN7agWGKIjwX01k9z3ABC/XO+R:JWHeWv4UpNJWC7AX6HRN7uHR9z0C/XOO
                                                                                                            MD5:77D0B6E9DB4FE2D47149541ABB658C2C
                                                                                                            SHA1:2D9349D25164FE01369B12FBBE392E5602F4FE5A
                                                                                                            SHA-256:E8F7DE93A7F5F6AD2A909B4B849C594EB872498D1F491DCF2EEBFC740EDE56A0
                                                                                                            SHA-512:47DE7B112EAE0F6AF383CBAC202DBF1417A3EDD6C3C0EAFC136E99E871AC819D5DC0D5507CE570F371B41D8B6E651960B09BF36E230F056982922CF16D3E0244
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....."..........." ..... ... ...............................................P......b.....`...@......@............... ...............................................P...(...@......h...p...............................................................H............text...3........ .................. ..`.data.../....0.......0..............@....reloc.......@.......@..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1022128
                                                                                                            Entropy (8bit):6.821588247611613
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:24576:7PNtms1Go9Fz7KPTT8inDiv67tA2ehjEnQKL:N1G457KLTRivKehjg7
                                                                                                            MD5:66FEE2E52A143A1227E062E88F4C3C19
                                                                                                            SHA1:65F5B79A84F89C820DE6273D0F7F323189C81FF4
                                                                                                            SHA-256:B9FE1181B9C0504D97940331B47DA8817BE5C202A0D57C2B92FE6909972F2012
                                                                                                            SHA-512:36E1CDB8C5AD2064F46BC30FF2F3742DE94D057C0D7ECCC1B1AFE1416EAD3128673CF35768396289FD34249324AE2958B0EF9C1E06298D533FCE7B40EBECD1A2
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....mL..........." .........P...............................................p.......q....`...@......@............... ...........................................G...p...(...P......h...p...............................................................H............text............................... ..`.data....)... ...0... ..............@....reloc.......P... ...P..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15520
                                                                                                            Entropy (8bit):6.73836549241893
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:XkWrBaWi7WvaYA6VFHRN7JQDX+iR9zwYiQ:XkWd2KaFClJQDuO9zh
                                                                                                            MD5:36B89A91AA27942AA5948EE349CAB75E
                                                                                                            SHA1:89656249ED33686F86533A0ED8DC8CBEA81ECBAA
                                                                                                            SHA-256:E0ED6218EB92190388E554288C0794CF3E85018F85EB753D1D6EE90167628D99
                                                                                                            SHA-512:9A26A9B94231FADE42E9DC4F57A21D52ADD215D3D6A416A371BFFAF91085EE0866E4341D1C7D10707CC617E08297D7E1F69A32CDC062A02421355B3E08D79425
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...D.K..........." ..0..............(... ...@....... ..............................Kb....`..................................(..O....@..d................(...`.......'..T............................................ ............... ..H............text........ ...................... ..`.rsrc...d....@......................@..@.reloc.......`......................@..B.................(......H.......P ......................('......................................BSJB............v4.0.30319......l.......#~......<...#Strings....H.......#US.L.......#GUID...\...|...#Blob......................3......................................................x.....3...........^.................I....._.................w.................G...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):80032
                                                                                                            Entropy (8bit):5.840306606911554
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:PH4czT4Vhd+Cv8A/oqZvD2olsyrbktai3zY:PV49+S85qxD2omyr3sE
                                                                                                            MD5:A862087E377CB4E1CED00DFA23160CB3
                                                                                                            SHA1:65198639EFED63E4EB19839876453E6DC3C1D957
                                                                                                            SHA-256:7F450304CD7FF566C745EA2C776160865DB400D42A2EDC206020D8735C7B233F
                                                                                                            SHA-512:136ADC24E973984D67227E66FCB6BDB3002C23D9883D20F111D78448B6DCB667DA0A32E30292D669AC55AE35B2106FE754D8C262505AE5EDE9058D750E74B50F
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....S............" ......... ......................................................C.....`...@......@............... ......................................4&..X........(..........p...p...............................................................H............text............................... ..`.data...............................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):311056
                                                                                                            Entropy (8bit):4.240184363331846
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:SE9XK6chFa5y9sh33X+QIa7rGgtfqYZdLqt:xq0FfqYZdLk
                                                                                                            MD5:433E16EF5493F3056333B527F1E2DD60
                                                                                                            SHA1:FE62C578F0186E2184EC45F2DAD74BB541949B07
                                                                                                            SHA-256:C78605F3D54C17048715442A67E02C104EDF16BA63845E76E5C58EA39F3EAB5D
                                                                                                            SHA-512:1D6D372A802A99383BDBA8788E96417D60CA19F072CB471BF36622190F44A34260C3F0F823C378091474FBA3082EB062D9560AE30A62966AB2B4925B51111262
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......%%=.aDS.aDS.aDS.q...`DS.q.Q.`DS.RichaDS.PE..d......f.........." ...(.............................................................R....`.......................................................... ...................)..............T............................................................................rdata..X...........................@..@.rsrc........ ......................@..@.......f........l...l...l..........f...........................f........l...................................RSDS.".7(.BH...w".......D:\a\_work\1\s\artifacts\obj\coreclr\windows.x64.Release\dlls\clretwrc\clretwrc.pdb.............................T....rdata..T........rdata$voltmd...l........rdata$zzzdbg.... .......rsrc$01.....!......rsrc$02....................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):247968
                                                                                                            Entropy (8bit):6.37445921548819
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:L/Ko6Z6pKRRO48OkdzAbCbDme2+zi2bQTFh:Liyp4SdGKru2ETFh
                                                                                                            MD5:6D96BA9C49ABCA46C4E5E6DB1A83561C
                                                                                                            SHA1:B0CC05C727A0AA4F7E2149427E3E434A1D2D372B
                                                                                                            SHA-256:232CFFB26231A28F7B7884ADFCB9C49CF23C5F8289E0BA9D90F4644BA7C9C312
                                                                                                            SHA-512:DC68E50B2168513E12B29E3CAA3ADC69C18F30FB99E7EB19056C556E75E1B73EC95671343133C1FB6B2D3A0C6747A984F73A37F456CA0B4183BDBFE65874E76C
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." ..... ...p............................................................`...@......@............... .......................................[...........(...........#..p...............................................................H............text............ .................. ..`.data...NX...0...`...0..............@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):34976
                                                                                                            Entropy (8bit):5.07371888821369
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:3WE8CO6PzDix+GtH6fDonYqHT4CjeYA6VFHRN7kfNFu49R9zFlK:X26PzOKkn/T4xFClkFFu69zq
                                                                                                            MD5:C8694E9CD42C325CB3AE356CC4DFF7FE
                                                                                                            SHA1:636986A78005DD775C632EB7AB1314471AF7CC0F
                                                                                                            SHA-256:E266AA3D2EDE9B36C8C0F4A3C256E1C553101312EAF5BB71A5AF32F168ACB282
                                                                                                            SHA-512:6EEF36D795E206A1AC543ED731C53751429BC715AF8BA77DBCCF6FE2ECE5495BE4A42B1E78D8D53486CBC963BEE9BDEC67444306EBFBF7A24415E93DE8DB448C
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." .....0... ...............................................`.......(....`...@......@............... ...............................................`...(...P..\...x...T...............................................................H............text....+.......0.................. ..`.data........@.......@..............@....reloc..\....P.......P..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):55568
                                                                                                            Entropy (8bit):5.419488526897619
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:768:+TUsLf/NM8/u0koRo21g1PCYh0UskMFClYRFT9zQ:+QmNMH0ko71g1aYOUskIiSTzQ
                                                                                                            MD5:7815CF4E3103FB75B16B322B82CA0A92
                                                                                                            SHA1:1904D409EF775FECBFD81195B44F85BFDD097AC7
                                                                                                            SHA-256:EC73EF6B6BE1C451C5222C593E7178DAD79C8E61292BFBE44CD1292D5BF6D9BC
                                                                                                            SHA-512:E6900B2B1A2D6BEA175DA8D2453BBDC6432E20EE28CEA1156B1644CD02945B3886337C620C9EEA9A6FCEA7EAA68F23CC46E3D70BF9641DAA1F6393A8308A1D7B
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...}.<..........." ......... ............................................................`...@......@............... ...................................................)..........X...p...............................................................H............text....p.......................... ..`.data...E...........................@....reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1005832
                                                                                                            Entropy (8bit):6.717630206703801
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:24576:Wuz94uYWl+9whtbSp1HVu9yH+sChDUD3IX+:v54uZ++tbQHVu9yHugrH
                                                                                                            MD5:AC45B05C090E28DDE2BDD3E6D460330F
                                                                                                            SHA1:54A64B5C41A365E4F03974E620D9227582E0B6B1
                                                                                                            SHA-256:FBA4224E5DEABCCD781BD7E0371C16A9765F7BE0EA165F8BB499F5D62F4531BF
                                                                                                            SHA-512:6DCDB591E85C9F2C241ED2BCFAFA214B7F1B75E6D681BB40F76CC3B121FCE41CE9455FA3C44D455A4E4F2FF4BA4F159F0DE51C0EA74FFC73837B342794AB7389
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...o............" ..... ...................................................0............`...@......@............... ..................................`....*..TQ...0...)...........;..p...........................................................`...H............text............ .................. ..`.data........0.......0..............@....reloc........... ..................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15632
                                                                                                            Entropy (8bit):6.8214166952315685
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:kKfpo0MNnIWbmWv+YA6VFHRN7DRxB+R9z0d:DBo0MLH+FClDRxw9zC
                                                                                                            MD5:3AB302DE13AB2C008D41B4BC381F5C45
                                                                                                            SHA1:DA82EF01893EC54D6AB9371EA93B398270923323
                                                                                                            SHA-256:0D269D39F04173829F9686CFFBD8AF33030D2D6BBE42BF090FD35FB86DA6FCF3
                                                                                                            SHA-512:E313ACA9F9805B7CF98BB855E843D88F5E0585B86F132B788D58A593A0017C18521ACBC1F842421B50D2FCB56B62ECFD3CF0C87BD7DA7129D56BD2CBB5150488
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...u.i..........." ..0..............)... ...@....... ..............................k.....`..................................)..O....@...................)...`.......(..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H.......P .......................(......................................BSJB............v4.0.30319......l.......#~..D.......#Strings....0.......#US.4.......#GUID...D.......#Blob......................3................................................(.`.....`...f.................L...........|...........a.......................H.....z...................(.....(.....(...).(...1.(...9.(...A.(...I.(...Q.(...Y.(...a.(...i.(...q.(...y.(.......................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):92440
                                                                                                            Entropy (8bit):5.817248773055368
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:0fohJcqhNwo3SjZw4gGv7+J+lNxhh5h+WcziX:0Ancqhio3SjZw4gGD+J+lNxb+ze
                                                                                                            MD5:65C30C4B56E172195C803385B3542743
                                                                                                            SHA1:9DA75B8C3CB5C87EEB1E2A99589B11F048A8073A
                                                                                                            SHA-256:A3FE636D2E150BBA7692E47E891E5E81501060D3E136CC7DF45AEC21429B202B
                                                                                                            SHA-512:C3ECF3DFA558872A5352FC829A644B7E67561F2A96B99A5A027F9C972398EDD47BEE91CF2E4973334B31470C51B296DAA73B1C5BF94340A27446B55DF8EBB2A4
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...?sE..........." .........0...............................................@............`...@......@............... .......................................*.......@...)...0..........p...............................................................H............text...]........................... ..`.data............ ..................@....reloc.......0.......0..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):272544
                                                                                                            Entropy (8bit):6.50562073982023
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:9q6gkJLdnAwEqvTlz1aYqsOMBFK0rkir51KYb8FK3MEIS3PQnZg28aq/xv642ucw:0dkJLN5EqvpzTC01anZ0/H2NfFgzFIS
                                                                                                            MD5:3D7131BF95378643004211E17DF764AC
                                                                                                            SHA1:5A4C0F7C5AE61FED16345B693E5CEFE2C3CB728C
                                                                                                            SHA-256:B649BBE057F0C5B5EEFEF65087AFB3EA54EE2DBDE1BB03C532A0D894E783C031
                                                                                                            SHA-512:1C730C3BD483223D0B8E622EE649C838F0DA6F97E25F5050F9A629A1B0271A8B8E10741D101A5A0645D7C4166E2FD7F53982506EBF10A4A17F7EC65A6394317C
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...P............." .........p......................................................v'....`...@......@............... ..................................p....f...........(......L....%..p...........................................................p...H............text....|.......................... ..`.data....V.......`..................@....reloc..L...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):15648
                                                                                                            Entropy (8bit):6.812729868383133
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:192:aATqxAOjfFWhUWv8VWxNzx95jmHnhWgN7agWCvwKDUX01k9z3AWipfx:awwBWhUWv82X6HRN7UpR9zvox
                                                                                                            MD5:6E5EF37CC93928F186A03F70E18D2E06
                                                                                                            SHA1:45415524ADDEF2322609C9A99B661711D4D83AF0
                                                                                                            SHA-256:8C6B948D52A18E77B796E5AE43139E155E52362075B9D3F94929BD2E1C20D3C0
                                                                                                            SHA-512:4C777BE5C8F211F448364A007BB28A45F8575B03D42B0CCAE057F0EB0EB9204CE2681AA0EDAA1A46D441B072F8188BC6361D85BF0D32A843D0F883065576D681
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...et..........." ..0..............)... ...@....... ....................................`.................................Q)..O....@.................. )...`......`(..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H.......P .......................'......................................BSJB............v4.0.30319......l.......#~..(.......#Strings............#US.........#GUID...........#Blob......................3................................................F.h.....h.....U.................%...(.%...........%.....%.....%.....%.....%...f.%.....%.................O.....O.....O...).O...1.O...9.O...A.O...I.O...Q.O...Y.O...a.O...i.O...q.O...y.O.......................#.....+.:...+.P...3.f...;.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):34976
                                                                                                            Entropy (8bit):4.6401763861103875
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:XWFBrWvK8kH6cKRbOEnYA6VFHRN7v2BHR9zJVEb3:Y6S6vRbOSFClv29zMb3
                                                                                                            MD5:F8BCC72E3315CA75D42B83090D1DE38E
                                                                                                            SHA1:7DBDA01CE3F9F6ACE4E42A7A5FC1D2DB22B3EED8
                                                                                                            SHA-256:3E3FFC9A7F24222A811A0394BD7E72DF11DBC466B10DEB6F669A8E1D79C77E2C
                                                                                                            SHA-512:8377537479DC150A47F6D8DEFECF371052CABBB6AEC85143C9E8F931743910066CD8AF31EC8B54B87450AA0684A219DBAF27C82895CD53B547A31760EB632954
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...z............." .....0... ...............................................`......PA....`...@......@............... ..........................................0....`...(...P..........p...............................................................H............text...p&.......0.................. ..`.data........@.......@..............@....reloc.......P.......P..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):84128
                                                                                                            Entropy (8bit):5.795749731518867
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:yIx5ebzfb/qs7in9eq7Zb8GJZe/c9G97kA6tirmVzO:yIxeD/q99vb8G2/e6kA8L6
                                                                                                            MD5:55BB40A1BC70FA96FBCD33B65AEB709E
                                                                                                            SHA1:E34EBB648AC89C41C8F53E6831E3B707096F8004
                                                                                                            SHA-256:2A5CE27B0E82264E6FA09504680B32B0014BE188FEF4AEDFE86D3392C3190477
                                                                                                            SHA-512:D0349F16BFAD2BB35738ABDB336C9B852A1316EFFF11095BF219753A61AEB926F620A928321FFB97B2E24CA7DBEFCF6592A516636C2DF2638572C2B364CE3D42
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....b..........." .........0............................................... ......B.....`...@......@............... .......................................%..|.... ...(......<.......p...............................................................H............text............................... ..`.data...`........ ..................@....reloc..<...........................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):5564592
                                                                                                            Entropy (8bit):5.9838147426391055
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:49152:eFXznRh41kiAVUkJawXhoIPgkLQ4jhXlNXKU/kg48YD9YCT2JZelq:cznE1kjJaw1xxkWbz
                                                                                                            MD5:95648A2FA7627D161B9D1FDD1D0459F5
                                                                                                            SHA1:444C386A91A4EE72AE4253C18BF910004AA4F5FC
                                                                                                            SHA-256:F9AE092A343964DBE400BA59D7C7AAC6B17BD027B92E196C11B71EC3C7434BCF
                                                                                                            SHA-512:9617D46F4A7EA6DBB19CB35257DEEE93C4E0461BE7A274547A3B18AFFD9657E5D6EB2F70EDEB101682896231E81DFCE8DF057EC143302E8F5860AB74BF47B5F7
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....g............" ......Q.. ................................................T......nU...`...@......@............... ......................................$...t0....T..(....T..>..p...p...............................................................H............text...%.Q.......Q................. ..`.data.........Q.......Q.............@....reloc...>....T..@....T.............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):231688
                                                                                                            Entropy (8bit):6.4927538353537635
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3072:QTJLDgw9ow9j0rKu8bmb3KD/L8V8/6Xe9QF+wVkjox7rtefYGA/+PXuXUGL:mgw9ow9A4bmrA/mt7jWfuka
                                                                                                            MD5:01187D21FC09DD04F699064387D5E27C
                                                                                                            SHA1:F6B7086AAABAB39E2AB7A2FC5B130BC2150FC1C5
                                                                                                            SHA-256:BC1F295790C53358899C6721E0CED2F33F695C2421B2BB97FAB18F9DFFDD0198
                                                                                                            SHA-512:185FFE28CDFF7738DA5E278616B374DF79D0B1486B3D4B218266E1C408003DB509AEACF9D5C10D3F84EADED3BB9BD2A1A55F1156F9CB1C320384D62B05009410
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...4............." .........@...............................................`...........`...@......@............... .......................................U..t....`...)...P..H...P ..p...............................................................H............text...S........................... ..`.data....$... ...0... ..............@....reloc..H....P.......P..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):119888
                                                                                                            Entropy (8bit):6.600983758182253
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:dI2v39UXigCBs29DdxfggO6vMMKZsY2ofRjoecbdhUwdJTzmZhTzC:diwskD8B6vMMEs5oGecbd2wHT0Te
                                                                                                            MD5:CAF9EDDED91C1F6C0022B278C16679AA
                                                                                                            SHA1:4812DA5EB86A93FB0ADC5BB60A4980EE8B0AD33A
                                                                                                            SHA-256:02C6AA0E6E624411A9F19B0360A7865AB15908E26024510E5C38A9C08362C35A
                                                                                                            SHA-512:32AC84642A9656609C45A6B649B222829BE572B5FDEB6D5D93ACEA203E02816CF6C06063334470E8106871BDC9F2F3C7F0D1D3E554DA1832BA1490F644E18362
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......|6..8W..8W..8W..s/..:W..1/S.3W..8W...W..8W..9W......(W......'W......-W......9W....?.9W......9W..Rich8W..........PE..d................." ...(."...d............................................................`A........................................0u..4...d}..........................PP...........^..p............................\..@............@...............................text............................... ..`fothk........0...................... ..`.rdata...C...@...D...&..............@..@.data................j..............@....pdata...............n..............@..@_RDATA...............z..............@..@.rsrc................|..............@..@.reloc..............................@..B................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1338400
                                                                                                            Entropy (8bit):6.358098724993395
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:cABsjnIunobZ5eGiBSk7uf9xg9Y/ydKEPXoRyingNLi0/rqsaoGSZNrWVgi00szd:cjIuG4Sk7ug9Y/ytNe4rqsa0njGzQD
                                                                                                            MD5:05D4804E5EA5509E19A3388B46A363E2
                                                                                                            SHA1:31EA1248542D2914FC76179E5731126DFCCDBFA0
                                                                                                            SHA-256:61350E7EE96E614900D641B4ECC3F35271AA2BA72C0455AE0D021E20C95F9A3E
                                                                                                            SHA-512:6DBD79B065E8C0D3B042DA7615ABC0EF7DC7522E86AEB3DF9707080AFE113077A894F5CB963D2B0A179B5755296011798B24F7102AE9A5274CCD5C0FF9959EDA
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........=I.nI.nI.n@.-nC.n.l.oC.n.l.oF.n.l.oc.n...oM.n...oB.nI.n..nYk.o..nYk.oH.nYkAnH.nYk.oH.nRichI.n........PE..d.....f.........." ...(.b..........................................................R.....`A.........................................g..p...Pi.......`..........<....F.. &...p..........p.......................(...@...@............................................text...`a.......b.................. ..`.rdata...............f..............@..@.data................^..............@....pdata..<............l..............@..@.rsrc........`.......$..............@..@.reloc.......p.......*..............@..B........................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1338400
                                                                                                            Entropy (8bit):6.358098724993395
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:cABsjnIunobZ5eGiBSk7uf9xg9Y/ydKEPXoRyingNLi0/rqsaoGSZNrWVgi00szd:cjIuG4Sk7ug9Y/ytNe4rqsa0njGzQD
                                                                                                            MD5:05D4804E5EA5509E19A3388B46A363E2
                                                                                                            SHA1:31EA1248542D2914FC76179E5731126DFCCDBFA0
                                                                                                            SHA-256:61350E7EE96E614900D641B4ECC3F35271AA2BA72C0455AE0D021E20C95F9A3E
                                                                                                            SHA-512:6DBD79B065E8C0D3B042DA7615ABC0EF7DC7522E86AEB3DF9707080AFE113077A894F5CB963D2B0A179B5755296011798B24F7102AE9A5274CCD5C0FF9959EDA
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........=I.nI.nI.n@.-nC.n.l.oC.n.l.oF.n.l.oc.n...oM.n...oB.nI.n..nYk.o..nYk.oH.nYkAnH.nYk.oH.nRichI.n........PE..d.....f.........." ...(.b..........................................................R.....`A.........................................g..p...Pi.......`..........<....F.. &...p..........p.......................(...@...@............................................text...`a.......b.................. ..`.rdata...............f..............@..@.data................^..............@....pdata..<............l..............@..@.rsrc........`.......$..............@..@.reloc.......p.......*..............@..B........................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1241520
                                                                                                            Entropy (8bit):6.349941690072582
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:YyL6o2u8NwfPWN0uenPtMDQUxbDjDDF2FZNd0W+/y9RtI/2gTZWQ9s16y6p54yqX:YyL6oXnU0uePtM/DjDDFA7dFiugTypf
                                                                                                            MD5:18C328AE6740B28D3BCB238BDA17AEB9
                                                                                                            SHA1:AB73DDA2F6EB35B743C56BABD2E3F5CADEBDB938
                                                                                                            SHA-256:1676DF96BF8D0DA277F1ADC2102E7FC711240982D61C31610F83474F093092F4
                                                                                                            SHA-512:CC5821C2E80F11BE3B010AD11943B53555C8537DD2975F900556B45A2FBA3C600D64707BFA72828EB320CEE74E48EF90FD726F76C5011361085824085017E024
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......\........................*.......*.......*..<...S......S..............-.......-..h....-.......-i......-......Rich............PE..d.....f.........." ...(............0O...............................................Z....`A........................................P...`....................@...........%......p...@:..p....................<..(....9..@............ ...............................text............................... ..`.rdata..(.... ......................@..@.data........ ......................@....pdata.......@......................@..@.rsrc...............................@..@.reloc..p...........................@..B................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):59552
                                                                                                            Entropy (8bit):5.643119448166663
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:768:lt51EDMpCUoqFY66Gw17oqZn/TEHmyrchswz6EEZcYf5o4ba2yGlG1QeY48lCi5m:ltFcC3ZcYf5o4bZyGc1A4c53iPmVz8n
                                                                                                            MD5:67972D6AF44F5E08E9F3EACC31D302AC
                                                                                                            SHA1:976D10328572171E8122FA1AA765E92AB54CEC45
                                                                                                            SHA-256:217BC7C04BE852B4FCF8104F8BA8F673F1B177D2D8C5CAF455E7A18E6BBE2097
                                                                                                            SHA-512:BE2B63E849A046A0D786EB25958F423A088BDE3431800FA4CB6667D5FA4147D1FD363AD2D7E3E4FE9EB8BCF03A0DCCBE5A23FA4252AA228D8EA1A380597AEC57
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0.................. ........... ....................... ............`.................................q...O.......$................(..............T............................................ ............... ..H............text....... ...................... ..`.rsrc...$...........................@..@.reloc..............................@..B........................H.......P ..................... .......................................BSJB............v4.0.30319......l...$O..#~...O..(b..#Strings............#US.........#GUID..........#Blob......................3................................e.....b/........L%.O...).O....RO..EP.......+..:.:4..J$:4...&S0...+.O...%.O...(:4...&:4...":4....:4....:4..U&:4....:4.................N.....N.....N..)..N..1..N..9..N..A..N..Q..N .Y..N..a..N..i..N..q..N..y..N.....N.....N......R.....[.....z...#.....+.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):136984
                                                                                                            Entropy (8bit):3.9056973889632753
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:HIH591YWvh7xR+l5dZU49N9SqignwJ5cvBMgSIctpoECyIWLzH:HIHhal5dZU4dSqHns2SpSkIAT
                                                                                                            MD5:136282A8FF7A4730B2F719AFA5DADF90
                                                                                                            SHA1:A86A5911C6BE4CE1E9535FC3F993677050EA5F15
                                                                                                            SHA-256:95EED17CA001846333831DA4DB370FB838AE114CCE512DB31380E8B45C464024
                                                                                                            SHA-512:3061C63242A95554A9855652D750FA3609860637EBB020A94CF3656761C182F0A1E15CFC87C6276BEF34FF75CDCB3FEDDA1E3B74D33A4E1B27628A36FA4302BB
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......%%=.aDS.aDS.aDS.q...`DS.q.Q.`DS.RichaDS.PE..d......f.........." ...(..................................................................`.......................................................... ...................)..............T............................................................................rdata..X...........................@..@.rsrc........ ......................@..@.......f........j...l...l..........f...........................f........l...................................RSDS.. 2v.ZA.].`S6Sc....D:\a\_work\1\s\artifacts\obj\coreclr\windows.x64.Release\dlls\mscorrc\mscorrc.pdb...............................T....rdata..T........rdata$voltmd...l........rdata$zzzdbg.... ..P....rsrc$01....P:.......rsrc$02....................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):538136
                                                                                                            Entropy (8bit):6.299714405457925
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:12288:q5YDDKStgzRK093ertSfiOMVAXUYYJJOb:qmDxSP6OaLYYJC
                                                                                                            MD5:027854570A4412624BECEE78A10395C1
                                                                                                            SHA1:6B0E6BC0CD97F2CAC1B962BE868FC7CB621D77F8
                                                                                                            SHA-256:2D67E87859ECAEB15C4DD621B0983F1A9AD3E2AA9B11624C018A43E6D6B06BEC
                                                                                                            SHA-512:8593D309434C7954AA42E5BD63F76A5BAE783C8F2130798EA285032C71F890C4C1783614597EE2BA3DA3294A68CE636EA2A9DCB21A858A840C8D8F6316928D65
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~...:..:..:..:..;..<U..%..<U..1..<U..*..3......q...?..:.....q...8..TU.....TU..;..TUj.;..:...8..TU..;..Rich:..................PE..d......e.........." ...&.@...................................................p......7.....`A.........................................|..h....|..h........@.......:.......(...`......0...T..............................@............P..h............................text...q>.......@.................. ..`.rdata...C...P...D...D..............@..@.data...............................@....pdata...:.......<..................@..@_RDATA..............................@..@.rsrc....@.......B..................@..@.reloc.......`......................@..B........................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):101024
                                                                                                            Entropy (8bit):5.497003708267034
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:kYsYXj0p2NYq5V4bgDHsPdIpuSE5L3Ukcz9wFgi+CzN7f:xMkYe4bgDUAxCFglC5j
                                                                                                            MD5:9332AA569690A1135EC72AA1EA9D1EDE
                                                                                                            SHA1:3662B089DF497BE01400C6B609D87D12162AC7D2
                                                                                                            SHA-256:E7BF779CB608124A7812160CE3D8BBE83C1E49C46A81EE0C2DC91447F191D1BB
                                                                                                            SHA-512:5B4A11F3A9B66406489CDDEA7BBF338A9F7F7EC834CEAA5EDD8EB8194F6A58667880EFDEDD4FB870E5E20EB78C43BB51733369F897C3E9B9A3C370DD15120FBB
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...jQ............" ..0..X...........v... ........... ..............................;.....`.................................?v..O.......4............b...(..........hu..T............................................ ............... ..H............text....V... ...X.................. ..`.rsrc...4............Z..............@..@.reloc...............`..............@..B................sv......H.......P ...T...................t......................................BSJB............v4.0.30319......l...`...#~..... ...#Strings.....Q......#US..Q......#GUID....R......#Blob......................3............................P...,......H.........5....:....'...m......,.@..5#.T..P4.T...7.J...B....i5....u:.T..n7.T..&1.T.....T.../.T..(7.T...(.T.............................)....1....9....A....Q.. .Y....a....i....q....y..........................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):296960
                                                                                                            Entropy (8bit):6.619863520346344
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:PW7EJC6KZ8NBwVdM8H+oMc3yMtvWgoYlXYSAiQubi7w:ccx8HJ+SA7Ci7w
                                                                                                            MD5:8AD7C12B2D3B20AD452C8B69F8258F15
                                                                                                            SHA1:095F9669D5F72A1D074FDD4DAC31B6B238707792
                                                                                                            SHA-256:53909D82F6FAB9A7A810F1A78C6C9CB526863E15878DFECA0AD652AB2851CB6A
                                                                                                            SHA-512:F97B8E2C0EB6EC63438F75F67E9717052F494FCDD33CEF96016061B6657F0221625E5E14709BD38FE6ED3EF4040EDF642902F0C2E009810F9FDAC01841153723
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....K..........." ..0..~..........*.... ........... ....................................`....................................O...................................\...p............................................ ............... ..H............text...0}... ...~.................. ..`.rsrc...............................@..@.reloc..............................@..B........................H........>................................................................(u...*..(u...*^.(u..........%...}....*:.(u.....}....*:.(u.....}....*V!.o./.....sv........*..(w...*.0...........o.........(....*&...(....*..0.._........(........!..Y.5)....(..... .....~x...(...+*...(y...(....*r...p.(.........>...oz...({....(....*..0...........o.......(....*..0...........(g.......$..Y.5\...........~x...(...+...(....*.(6.....!...........!..........+.~|.....+.~}.....+..(~.......*.....(.....
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):284160
                                                                                                            Entropy (8bit):6.50709590444457
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:6144:LC/97GWicf+DwiNJZ0KvQHRUBRlzPTkZvE8xHOKeKB:LCsAqJHIqBRlzP6vE8xa
                                                                                                            MD5:B0D8807729D9E3347923CF84BA186633
                                                                                                            SHA1:66E0228A718F9B318123A0EC46334BCC52C24142
                                                                                                            SHA-256:563BC9E0F9C674A9816B2253737978E23C3C0C7F47FC39B829F93EC06967BC93
                                                                                                            SHA-512:9EC5EBD71986FDA4E64E41C23E614F235CA6C3F4FD9858BE67D243EB42F201141E93E227D2E473D5FF707C281C290D9F6DD56949ABBC17A858F8C79C45CFDDFB
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...w............." ..0..L..........bk... ........... ....................................`..................................k..O.......................................p............................................ ............... ..H............text...hK... ...L.................. ..`.rsrc................N..............@..@.reloc...............T..............@..B................Bk......H.......|.......................<.........................................{5...*..{6...*V.(7.....}5.....}6...*...0..A........u........4.,/(8....{5....{5...o9...,.(:....{6....{6...o;...*.*.*. Z$P1 )UU.Z(8....{5...o<...X )UU.Z(:....{6...o=...X*...0..b........r...p......%..{5......%q.........-.&.+.......o>....%..{6......%q.........-.&.+.......o>....(?...*..{@...*..{A...*V.(7.....}@.....}A...*.0..A........u........4.,/(8....{@....{@...o9...,.(:....{A....{A...o;...*.*.*. ... )UU.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:InnoSetup Log Steam {97C23183-77ED-457C-90C7-3FA73E699316}, version 0x418, 48687 bytes, 657773\37\user\376, C:\Users\user\AppData\Local\Programs\Stea
                                                                                                            Category:dropped
                                                                                                            Size (bytes):48687
                                                                                                            Entropy (8bit):3.3349500848039444
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:384:Z699gthqbaVPRqpRZRPvxIMDuU3b080Ah0H56:AApZq/vPvxIMDuUfnhJ
                                                                                                            MD5:F3272A41AD0B2B46C8BBBB372B2D68D1
                                                                                                            SHA1:CB5215D1641FBD48BA08C648687E5238E5CB241A
                                                                                                            SHA-256:AA2793503B073E3274C147B44A4C09A21F61DE991369A3F6C12EAD875F5536AB
                                                                                                            SHA-512:15AA850A17F591EDF157850533D42AD095C63357B2ED1B9FBA11310CFA6A1CBE8AFDE2767397A40790EB74F91AAD6DA739B02CDBF017805044DA0E7D1B0ECFF2
                                                                                                            Malicious:false
                                                                                                            Preview:Inno Setup Uninstall Log (b)....................................{97C23183-77ED-457C-90C7-3FA73E699316}..........................................................................................Steam.................................................................................................................................../...%..........................................................................................................................T..................6.5.7.7.7.3......j.o.n.e.s......C.:.\.U.s.e.r.s.\.j.o.n.e.s.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.P.r.o.g.r.a.m.s.\.S.t.e.a.m.C.l.i.e.n.t....................... .....B..................C.:.\.U.s.e.r.s.\.j.o.n.e.s.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.P.r.o.g.r.a.m.s.\.S.t.e.a.m.C.l.i.e.n.t..d...C.:.\.U.s.e.r.s.\.j.o.n.e.s.\.A.p.p.D.a.t.a.\.R.o.a.m.i.n.g.\.M.i.c.r.o.s.o.f.t.\.W.i.n.d.o.w.s.\.S.t.a.r.t. .M.e.n.u.\.P.r.o.g.r.a.m.s.\.(.D.e.f.a.u.l.t.)......(.D.e.f.a.u.l.t.)......e.n.g.l.i.s.h.............h........C.:.\.U.s.e.r.s.\.j.o.n.e.
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):3156541
                                                                                                            Entropy (8bit):6.3749448508652815
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:49152:1WGtLBcXqFpBR6SVb8kq4pgquLMMji4NYxtJpkxhGjIHTbd333sx:vtLutqgwh4NYxtJpkxhGq333s
                                                                                                            MD5:FB8F887F569CECF50AF68290EE751386
                                                                                                            SHA1:95D34DBD4B472707BD7073B559E51C1E61020952
                                                                                                            SHA-256:C339A2F77F23B7E371DBD0560E8993535666B8E6B55FD8194188D7F3DA04325B
                                                                                                            SHA-512:12217CCDE00A204FCB32FB37DAF98F8EDEA8D26F01D231DCCB95E04F29C5C75E32064190B9251E6EA4576130DAB4BF3A4D4E7A32C40A3691307D4BC05343DCA7
                                                                                                            Malicious:false
                                                                                                            Preview:MZP.....................@.......................InUn....................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L......c.................L,..|......hf,......p,...@...........................0...........@......@....................-.......-..9...................................................................................-.......-......................text.... ,......",................. ..`.itext...(...@,..*...&,............. ..`.data...X....p,......P,.............@....bss.....y....-..........................idata...9....-..:....,.............@....didata.......-.......-.............@....edata........-......*-.............@..@.tls....L.....-..........................rdata..]............,-.............@..@.rsrc.................-.............@..@..............1.......0.............@..@........................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):119888
                                                                                                            Entropy (8bit):6.600983758182253
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:1536:dI2v39UXigCBs29DdxfggO6vMMKZsY2ofRjoecbdhUwdJTzmZhTzC:diwskD8B6vMMEs5oGecbd2wHT0Te
                                                                                                            MD5:CAF9EDDED91C1F6C0022B278C16679AA
                                                                                                            SHA1:4812DA5EB86A93FB0ADC5BB60A4980EE8B0AD33A
                                                                                                            SHA-256:02C6AA0E6E624411A9F19B0360A7865AB15908E26024510E5C38A9C08362C35A
                                                                                                            SHA-512:32AC84642A9656609C45A6B649B222829BE572B5FDEB6D5D93ACEA203E02816CF6C06063334470E8106871BDC9F2F3C7F0D1D3E554DA1832BA1490F644E18362
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......|6..8W..8W..8W..s/..:W..1/S.3W..8W...W..8W..9W......(W......'W......-W......9W....?.9W......9W..Rich8W..........PE..d................." ...(."...d............................................................`A........................................0u..4...d}..........................PP...........^..p............................\..@............@...............................text............................... ..`fothk........0...................... ..`.rdata...C...@...D...&..............@..@.data................j..............@....pdata...............n..............@..@_RDATA...............z..............@..@.rsrc................|..............@..@.reloc..............................@..B................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1963680
                                                                                                            Entropy (8bit):6.322902076881355
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:24576:YPUQbNPsGu5PpXSMUgKrSfzOwv8/eczsn8KQj2US4kSn2RxUJ9LUdpjK8hVDl+G:s1Pu5cMUgYuCwjconQj22kS2vY9L27vf
                                                                                                            MD5:9B5895322EA58963C2C26B6AD0212A14
                                                                                                            SHA1:8A182CAC411C051CF514B27C42E0D315BD6B55F3
                                                                                                            SHA-256:C7EE407CED4846577A1E8A67EF61CC920010C4F126933774EDC24F46D43714E2
                                                                                                            SHA-512:0770B67B94C5063FE670E9A4D5FCD1997139DA632861814D3B9A2EF4E6E0C38F0816C2E63B43E6EC17007F139A5147DB0CB61C804D865A311F13364B5706C198
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......L..E........................................................:........................~..e....~..e.......e.b.............e.......Rich............PE..d....-.f.........." ...).H..........p,.......................................P.......q....`A........................................ ...T...t...@................K.......(......d7...#..p....................&..(.......@............`..h.......`....................text....G.......H.................. ..`.rdata..Xh...`...j...L..............@..@.data...........t..................@....pdata...K.......L...*..............@..@.didat..(............v..............@....rsrc................x..............@..@.reloc..d7.......8..................@..B........................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):6144
                                                                                                            Entropy (8bit):4.720366600008286
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:96:sfkcXegaJ/ZAYNzcld1xaX12p+gt1sONA0:sfJEVYlvxaX12C6A0
                                                                                                            MD5:E4211D6D009757C078A9FAC7FF4F03D4
                                                                                                            SHA1:019CD56BA687D39D12D4B13991C9A42EA6BA03DA
                                                                                                            SHA-256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
                                                                                                            SHA-512:17257F15D843E88BB78ADCFB48184B8CE22109CC2C99E709432728A392AFAE7B808ED32289BA397207172DE990A354F15C2459B6797317DA8EA18B040C85787E
                                                                                                            Malicious:false
                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......^...............l...............=\......=\......=\......Rich............................PE..d.....R..........#............................@.............................`.......,......................................................<!.......P..H....@..0.................................................................... ...............................text............................... ..`.rdata..|.... ......................@..@.data...,....0......................@....pdata..0....@......................@..@.rsrc...H....P......................@..@................................................................................................................................................................................................................................................................................................................................
                                                                                                            Process:C:\Users\user\Desktop\SteamSetup.exe
                                                                                                            File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                                            Category:dropped
                                                                                                            Size (bytes):3132416
                                                                                                            Entropy (8bit):6.38838830778387
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:49152:9WGtLBcXqFpBR6SVb8kq4pgquLMMji4NYxtJpkxhGjIHTbd333sr:ntLutqgwh4NYxtJpkxhGq333Q
                                                                                                            MD5:5338593C8A3654FEF48E3EFD7FBBE890
                                                                                                            SHA1:6B301281F7ED992E22FEDBF962314EDCEE4560CD
                                                                                                            SHA-256:A29E2A4B87D32A4949C359D321B3B3EBB9D471AE5380500A5725BCE414158760
                                                                                                            SHA-512:56CB89B9C51010C5EE73A4DA935FDBD75EE93AFACB5681CD9648F9523339D3D2E151DE35976974FDA58874A0C5247A3251A5BD8428FD2435B07BF8E45D4035E4
                                                                                                            Malicious:false
                                                                                                            Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L......c.................L,..|......hf,......p,...@...........................0...........@......@....................-.......-..9...................................................................................-.......-......................text.... ,......",................. ..`.itext...(...@,..*...&,............. ..`.data...X....p,......P,.............@....bss.....y....-..........................idata...9....-..:....,.............@....didata.......-.......-.............@....edata........-......*-.............@..@.tls....L.....-..........................rdata..]............,-.............@..@.rsrc.................-.............@..@..............1.......0.............@..@........................................................
                                                                                                            Process:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Tue Nov 19 22:00:10 2024, mtime=Tue Nov 19 22:00:10 2024, atime=Fri Oct 18 04:36:24 2024, length=158720, window=hide
                                                                                                            Category:dropped
                                                                                                            Size (bytes):1281
                                                                                                            Entropy (8bit):4.851716489978697
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:24:8mGOHlvRCRxdj+JhmiqAJgBk78A7yfUGBmi+kt9GBmitNnqyFm:8m9HlvsRx9+JhjqigBkH7+UGBj+kt9GL
                                                                                                            MD5:334C7817CFA19BDA30EF0A0227FD0E35
                                                                                                            SHA1:6AC06940870B6D8EC4ED9864FF840DF5E57E669F
                                                                                                            SHA-256:D52CF7738E21D938A7279F6880501B8CE09366B8E56DB475987B00868C249B73
                                                                                                            SHA-512:01A970C78CC38960C9CAF73AF8E84DB612A9BD9B3F0BFF6DA23AD0D8AE1DD588B9DF9E74A99F5C9554A8F9C3DB0C9FFB956CC8306B3C6B30DADF1A8D2F2C8FE9
                                                                                                            Malicious:false
                                                                                                            Preview:L..................F.... ...N....:...Z...:....X..!...l......................(.:..DG..Yr?.D..U..k0.&...&......vk.v....o....:...Q...:......t...CFSF..1.....CW.^..AppData...t.Y^...H.g.3..(.....gVA.G..k...@......CW.^sY.............................%..A.p.p.D.a.t.a...B.P.1.....sY....Local.<......CW.^sY......b.........................L.o.c.a.l.....Z.1.....sY....Programs..B......sY..sY................................P.r.o.g.r.a.m.s.....`.1.....sY....STEAMC~1..H......sY..sY.............................j.S.t.e.a.m.C.l.i.e.n.t.....`.2..l..RY., .Steam2.exe..F......sY..sY......a.........................S.t.e.a.m.2...e.x.e.......k...............-.......j...........u+al.....C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exe..4.....\.....\.....\.....\.....\.L.o.c.a.l.\.P.r.o.g.r.a.m.s.\.S.t.e.a.m.C.l.i.e.n.t.\.S.t.e.a.m.2...e.x.e.1.C.:.\.U.s.e.r.s.\.j.o.n.e.s.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.P.r.o.g.r.a.m.s.\.S.t.e.a.m.C.l.i.e.n.t.........|....I.J.H..K..:...`.......X.......657773.......
                                                                                                            File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                                            Entropy (8bit):7.9983871769630035
                                                                                                            TrID:
                                                                                                            • Win32 Executable (generic) a (10002005/4) 98.45%
                                                                                                            • Inno Setup installer (109748/4) 1.08%
                                                                                                            • Win32 EXE PECompact compressed (generic) (41571/9) 0.41%
                                                                                                            • Win16/32 Executable Delphi generic (2074/23) 0.02%
                                                                                                            • Generic Win/DOS Executable (2004/3) 0.02%
                                                                                                            File name:SteamSetup.exe
                                                                                                            File size:50'219'482 bytes
                                                                                                            MD5:1b34108b77b984e227bbad718d89594a
                                                                                                            SHA1:a75f5432e2ce39dc6c3f190d8d35ee2475a0ae6b
                                                                                                            SHA256:3f27a1a005beb7b1032bf9aef9fe5128ee1cccc332de862717b42d0b7f9c1f34
                                                                                                            SHA512:a8b82b25c7b0ed36f075cee24201ef6982bfc9978268d21c8631a1f2c03f64f1bf84f1cecd6400582c912883ea195939bd3d9d28975b8b380406a829bad0cd57
                                                                                                            SSDEEP:786432:gRc3O2roQS8SUvmFaCLN2bywU4AKuoaklrh9EWtAN7OE1jWyUWolR1f/9jLgfipY:kc3OmS8nvdgkmF4AKflli1dWy5ol7/9O
                                                                                                            TLSH:37B7332BF159A63FE96F4B3505739210987FB771A40A8C1A53F40A5CCF6B8A01F3B646
                                                                                                            File Content Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7.......................................................................................................................................
                                                                                                            Icon Hash:0f63c5d3f31c6917
                                                                                                            Entrypoint:0x4b5eec
                                                                                                            Entrypoint Section:.itext
                                                                                                            Digitally signed:false
                                                                                                            Imagebase:0x400000
                                                                                                            Subsystem:windows gui
                                                                                                            Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
                                                                                                            DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                                                                                                            Time Stamp:0x63ECF218 [Wed Feb 15 14:54:16 2023 UTC]
                                                                                                            TLS Callbacks:
                                                                                                            CLR (.Net) Version:
                                                                                                            OS Version Major:6
                                                                                                            OS Version Minor:1
                                                                                                            File Version Major:6
                                                                                                            File Version Minor:1
                                                                                                            Subsystem Version Major:6
                                                                                                            Subsystem Version Minor:1
                                                                                                            Import Hash:e569e6f445d32ba23766ad67d1e3787f
                                                                                                            Instruction
                                                                                                            push ebp
                                                                                                            mov ebp, esp
                                                                                                            add esp, FFFFFFA4h
                                                                                                            push ebx
                                                                                                            push esi
                                                                                                            push edi
                                                                                                            xor eax, eax
                                                                                                            mov dword ptr [ebp-3Ch], eax
                                                                                                            mov dword ptr [ebp-40h], eax
                                                                                                            mov dword ptr [ebp-5Ch], eax
                                                                                                            mov dword ptr [ebp-30h], eax
                                                                                                            mov dword ptr [ebp-38h], eax
                                                                                                            mov dword ptr [ebp-34h], eax
                                                                                                            mov dword ptr [ebp-2Ch], eax
                                                                                                            mov dword ptr [ebp-28h], eax
                                                                                                            mov dword ptr [ebp-14h], eax
                                                                                                            mov eax, 004B14B8h
                                                                                                            call 00007F4F44D8C095h
                                                                                                            xor eax, eax
                                                                                                            push ebp
                                                                                                            push 004B65E2h
                                                                                                            push dword ptr fs:[eax]
                                                                                                            mov dword ptr fs:[eax], esp
                                                                                                            xor edx, edx
                                                                                                            push ebp
                                                                                                            push 004B659Eh
                                                                                                            push dword ptr fs:[edx]
                                                                                                            mov dword ptr fs:[edx], esp
                                                                                                            mov eax, dword ptr [004BE634h]
                                                                                                            call 00007F4F44E2EB87h
                                                                                                            call 00007F4F44E2E6DAh
                                                                                                            lea edx, dword ptr [ebp-14h]
                                                                                                            xor eax, eax
                                                                                                            call 00007F4F44DA1B34h
                                                                                                            mov edx, dword ptr [ebp-14h]
                                                                                                            mov eax, 004C1D84h
                                                                                                            call 00007F4F44D86C87h
                                                                                                            push 00000002h
                                                                                                            push 00000000h
                                                                                                            push 00000001h
                                                                                                            mov ecx, dword ptr [004C1D84h]
                                                                                                            mov dl, 01h
                                                                                                            mov eax, dword ptr [004238ECh]
                                                                                                            call 00007F4F44DA2CB7h
                                                                                                            mov dword ptr [004C1D88h], eax
                                                                                                            xor edx, edx
                                                                                                            push ebp
                                                                                                            push 004B654Ah
                                                                                                            push dword ptr fs:[edx]
                                                                                                            mov dword ptr fs:[edx], esp
                                                                                                            call 00007F4F44E2EC0Fh
                                                                                                            mov dword ptr [004C1D90h], eax
                                                                                                            mov eax, dword ptr [004C1D90h]
                                                                                                            cmp dword ptr [eax+0Ch], 01h
                                                                                                            jne 00007F4F44E34E2Ah
                                                                                                            mov eax, dword ptr [004C1D90h]
                                                                                                            mov edx, 00000028h
                                                                                                            call 00007F4F44DA35ACh
                                                                                                            mov edx, dword ptr [004C1D90h]
                                                                                                            NameVirtual AddressVirtual Size Is in Section
                                                                                                            IMAGE_DIRECTORY_ENTRY_EXPORT0xc40000x9a.edata
                                                                                                            IMAGE_DIRECTORY_ENTRY_IMPORT0xc20000xfdc.idata
                                                                                                            IMAGE_DIRECTORY_ENTRY_RESOURCE0xc70000x8110.rsrc
                                                                                                            IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                                                                            IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                                                                            IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                                                                                                            IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                                                                                            IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                                                            IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                                                            IMAGE_DIRECTORY_ENTRY_TLS0xc60000x18.rdata
                                                                                                            IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                                                                                            IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                                                            IMAGE_DIRECTORY_ENTRY_IAT0xc22f40x254.idata
                                                                                                            IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0xc30000x1a4.didata
                                                                                                            IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                                                                            IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                                                                            NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                                                            .text0x10000xb39e40xb3a0043af0a9476ca224d8e8461f1e22c94daFalse0.34525867693110646data6.357635049994181IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                                                                            .itext0xb50000x16880x1800185e04b9a1f554e31f7f848515dc890cFalse0.54443359375data5.971425428435973IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                                                                            .data0xb70000x37a40x3800cab2107c933b696aa5cf0cc6c3fd3980False0.36097935267857145data5.048648594372454IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                            .bss0xbb0000x6de80x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                            .idata0xc20000xfdc0x1000e7d1635e2624b124cfdce6c360ac21cdFalse0.3798828125data5.029087481102678IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                            .didata0xc30000x1a40x2008ced971d8a7705c98b173e255d8c9aa7False0.345703125data2.7509822285969876IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                            .edata0xc40000x9a0x2008d4e1e508031afe235bf121c80fd7d5fFalse0.2578125data1.877162954504408IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                            .tls0xc50000x180x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                            .rdata0xc60000x5d0x2008f2f090acd9622c88a6a852e72f94e96False0.189453125data1.3838943752217987IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                            .rsrc0xc70000x81100x8200525899abf62de326bf7945b6f12f7e0eFalse0.7301081730769231data7.001913398079108IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                            NameRVASizeTypeLanguageCountryZLIB Complexity
                                                                                                            RT_ICON0xc74380x4d2ePNG image data, 256 x 256, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0008097985626077
                                                                                                            RT_STRING0xcc1680x360data0.34375
                                                                                                            RT_STRING0xcc4c80x260data0.3256578947368421
                                                                                                            RT_STRING0xcc7280x45cdata0.4068100358422939
                                                                                                            RT_STRING0xccb840x40cdata0.3754826254826255
                                                                                                            RT_STRING0xccf900x2d4data0.39226519337016574
                                                                                                            RT_STRING0xcd2640xb8data0.6467391304347826
                                                                                                            RT_STRING0xcd31c0x9cdata0.6410256410256411
                                                                                                            RT_STRING0xcd3b80x374data0.4230769230769231
                                                                                                            RT_STRING0xcd72c0x398data0.3358695652173913
                                                                                                            RT_STRING0xcdac40x368data0.3795871559633027
                                                                                                            RT_STRING0xcde2c0x2a4data0.4275147928994083
                                                                                                            RT_RCDATA0xce0d00x10data1.5
                                                                                                            RT_RCDATA0xce0e00x2c4data0.6384180790960452
                                                                                                            RT_RCDATA0xce3a40x2cdata1.1818181818181819
                                                                                                            RT_GROUP_ICON0xce3d00x14dataEnglishUnited States1.2
                                                                                                            RT_VERSION0xce3e40x584dataEnglishUnited States0.2563739376770538
                                                                                                            RT_MANIFEST0xce9680x7a8XML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.3377551020408163
                                                                                                            DLLImport
                                                                                                            kernel32.dllGetACP, GetExitCodeProcess, LocalFree, CloseHandle, SizeofResource, VirtualProtect, VirtualFree, GetFullPathNameW, ExitProcess, HeapAlloc, GetCPInfoExW, RtlUnwind, GetCPInfo, GetStdHandle, GetModuleHandleW, FreeLibrary, HeapDestroy, ReadFile, CreateProcessW, GetLastError, GetModuleFileNameW, SetLastError, FindResourceW, CreateThread, CompareStringW, LoadLibraryA, ResetEvent, GetVersion, RaiseException, FormatMessageW, SwitchToThread, GetExitCodeThread, GetCurrentThread, LoadLibraryExW, LockResource, GetCurrentThreadId, UnhandledExceptionFilter, VirtualQuery, VirtualQueryEx, Sleep, EnterCriticalSection, SetFilePointer, LoadResource, SuspendThread, GetTickCount, GetFileSize, GetStartupInfoW, GetFileAttributesW, InitializeCriticalSection, GetSystemWindowsDirectoryW, GetThreadPriority, SetThreadPriority, GetCurrentProcess, VirtualAlloc, GetSystemInfo, GetCommandLineW, LeaveCriticalSection, GetProcAddress, ResumeThread, GetVersionExW, VerifyVersionInfoW, HeapCreate, GetWindowsDirectoryW, VerSetConditionMask, GetDiskFreeSpaceW, FindFirstFileW, GetUserDefaultUILanguage, lstrlenW, QueryPerformanceCounter, SetEndOfFile, HeapFree, WideCharToMultiByte, FindClose, MultiByteToWideChar, LoadLibraryW, SetEvent, CreateFileW, GetLocaleInfoW, GetSystemDirectoryW, DeleteFileW, GetLocalTime, GetEnvironmentVariableW, WaitForSingleObject, WriteFile, ExitThread, DeleteCriticalSection, TlsGetValue, GetDateFormatW, SetErrorMode, IsValidLocale, TlsSetValue, CreateDirectoryW, GetSystemDefaultUILanguage, EnumCalendarInfoW, LocalAlloc, GetUserDefaultLangID, RemoveDirectoryW, CreateEventW, SetThreadLocale, GetThreadLocale
                                                                                                            comctl32.dllInitCommonControls
                                                                                                            version.dllGetFileVersionInfoSizeW, VerQueryValueW, GetFileVersionInfoW
                                                                                                            user32.dllCreateWindowExW, TranslateMessage, CharLowerBuffW, CallWindowProcW, CharUpperW, PeekMessageW, GetSystemMetrics, SetWindowLongW, MessageBoxW, DestroyWindow, CharUpperBuffW, CharNextW, MsgWaitForMultipleObjects, LoadStringW, ExitWindowsEx, DispatchMessageW
                                                                                                            oleaut32.dllSysAllocStringLen, SafeArrayPtrOfIndex, VariantCopy, SafeArrayGetLBound, SafeArrayGetUBound, VariantInit, VariantClear, SysFreeString, SysReAllocStringLen, VariantChangeType, SafeArrayCreate
                                                                                                            netapi32.dllNetWkstaGetInfo, NetApiBufferFree
                                                                                                            advapi32.dllConvertStringSecurityDescriptorToSecurityDescriptorW, RegQueryValueExW, AdjustTokenPrivileges, GetTokenInformation, ConvertSidToStringSidW, LookupPrivilegeValueW, RegCloseKey, OpenProcessToken, RegOpenKeyExW
                                                                                                            NameOrdinalAddress
                                                                                                            TMethodImplementationIntercept30x4541a8
                                                                                                            __dbk_fcall_wrapper20x40d0a0
                                                                                                            dbkFCallWrapperAddr10x4be63c
                                                                                                            Language of compilation systemCountry where language is spokenMap
                                                                                                            EnglishUnited States
                                                                                                            TimestampSource PortDest PortSource IPDest IP
                                                                                                            Nov 20, 2024 00:00:47.131558895 CET52303443192.168.2.4104.102.49.254
                                                                                                            Nov 20, 2024 00:00:47.131654978 CET44352303104.102.49.254192.168.2.4
                                                                                                            Nov 20, 2024 00:00:47.131746054 CET52303443192.168.2.4104.102.49.254
                                                                                                            Nov 20, 2024 00:00:47.147532940 CET52303443192.168.2.4104.102.49.254
                                                                                                            Nov 20, 2024 00:00:47.147573948 CET44352303104.102.49.254192.168.2.4
                                                                                                            Nov 20, 2024 00:00:48.118535995 CET44352303104.102.49.254192.168.2.4
                                                                                                            Nov 20, 2024 00:00:48.118649006 CET52303443192.168.2.4104.102.49.254
                                                                                                            Nov 20, 2024 00:00:48.121434927 CET52303443192.168.2.4104.102.49.254
                                                                                                            Nov 20, 2024 00:00:48.121463060 CET44352303104.102.49.254192.168.2.4
                                                                                                            Nov 20, 2024 00:00:48.121809959 CET44352303104.102.49.254192.168.2.4
                                                                                                            Nov 20, 2024 00:00:48.170052052 CET52303443192.168.2.4104.102.49.254
                                                                                                            Nov 20, 2024 00:00:48.173839092 CET52303443192.168.2.4104.102.49.254
                                                                                                            Nov 20, 2024 00:00:48.215329885 CET44352303104.102.49.254192.168.2.4
                                                                                                            Nov 20, 2024 00:00:48.672684908 CET44352303104.102.49.254192.168.2.4
                                                                                                            Nov 20, 2024 00:00:48.672741890 CET44352303104.102.49.254192.168.2.4
                                                                                                            Nov 20, 2024 00:00:48.672764063 CET44352303104.102.49.254192.168.2.4
                                                                                                            Nov 20, 2024 00:00:48.672802925 CET44352303104.102.49.254192.168.2.4
                                                                                                            Nov 20, 2024 00:00:48.672822952 CET52303443192.168.2.4104.102.49.254
                                                                                                            Nov 20, 2024 00:00:48.672851086 CET44352303104.102.49.254192.168.2.4
                                                                                                            Nov 20, 2024 00:00:48.672926903 CET44352303104.102.49.254192.168.2.4
                                                                                                            Nov 20, 2024 00:00:48.672992945 CET52303443192.168.2.4104.102.49.254
                                                                                                            Nov 20, 2024 00:00:48.672992945 CET52303443192.168.2.4104.102.49.254
                                                                                                            Nov 20, 2024 00:00:48.672992945 CET52303443192.168.2.4104.102.49.254
                                                                                                            Nov 20, 2024 00:00:48.672992945 CET52303443192.168.2.4104.102.49.254
                                                                                                            Nov 20, 2024 00:00:48.808943987 CET44352303104.102.49.254192.168.2.4
                                                                                                            Nov 20, 2024 00:00:48.808993101 CET44352303104.102.49.254192.168.2.4
                                                                                                            Nov 20, 2024 00:00:48.809056997 CET52303443192.168.2.4104.102.49.254
                                                                                                            Nov 20, 2024 00:00:48.809092045 CET44352303104.102.49.254192.168.2.4
                                                                                                            Nov 20, 2024 00:00:48.809122086 CET44352303104.102.49.254192.168.2.4
                                                                                                            Nov 20, 2024 00:00:48.809123993 CET52303443192.168.2.4104.102.49.254
                                                                                                            Nov 20, 2024 00:00:48.809144020 CET52303443192.168.2.4104.102.49.254
                                                                                                            Nov 20, 2024 00:00:48.809159040 CET44352303104.102.49.254192.168.2.4
                                                                                                            Nov 20, 2024 00:00:48.809189081 CET52303443192.168.2.4104.102.49.254
                                                                                                            Nov 20, 2024 00:00:48.809346914 CET44352303104.102.49.254192.168.2.4
                                                                                                            Nov 20, 2024 00:00:48.809407949 CET52303443192.168.2.4104.102.49.254
                                                                                                            Nov 20, 2024 00:00:48.810534000 CET52303443192.168.2.4104.102.49.254
                                                                                                            Nov 20, 2024 00:00:48.810563087 CET44352303104.102.49.254192.168.2.4
                                                                                                            Nov 20, 2024 00:00:48.847487926 CET5230427018192.168.2.4162.254.199.165
                                                                                                            Nov 20, 2024 00:00:48.852912903 CET2701852304162.254.199.165192.168.2.4
                                                                                                            Nov 20, 2024 00:00:48.853033066 CET5230427018192.168.2.4162.254.199.165
                                                                                                            Nov 20, 2024 00:00:48.853681087 CET5230427018192.168.2.4162.254.199.165
                                                                                                            Nov 20, 2024 00:00:48.858644962 CET2701852304162.254.199.165192.168.2.4
                                                                                                            Nov 20, 2024 00:00:49.374578953 CET2701852304162.254.199.165192.168.2.4
                                                                                                            Nov 20, 2024 00:00:49.374643087 CET2701852304162.254.199.165192.168.2.4
                                                                                                            Nov 20, 2024 00:00:49.374705076 CET5230427018192.168.2.4162.254.199.165
                                                                                                            Nov 20, 2024 00:00:49.403095007 CET5230427018192.168.2.4162.254.199.165
                                                                                                            Nov 20, 2024 00:00:49.408312082 CET2701852304162.254.199.165192.168.2.4
                                                                                                            Nov 20, 2024 00:00:49.522701025 CET2701852304162.254.199.165192.168.2.4
                                                                                                            Nov 20, 2024 00:00:49.525916100 CET5230427018192.168.2.4162.254.199.165
                                                                                                            Nov 20, 2024 00:00:49.530992031 CET2701852304162.254.199.165192.168.2.4
                                                                                                            Nov 20, 2024 00:00:49.646600962 CET2701852304162.254.199.165192.168.2.4
                                                                                                            Nov 20, 2024 00:00:49.701189041 CET5230427018192.168.2.4162.254.199.165
                                                                                                            Nov 20, 2024 00:00:49.808345079 CET5230427018192.168.2.4162.254.199.165
                                                                                                            Nov 20, 2024 00:00:49.813353062 CET2701852304162.254.199.165192.168.2.4
                                                                                                            Nov 20, 2024 00:01:19.655226946 CET5230427018192.168.2.4162.254.199.165
                                                                                                            Nov 20, 2024 00:01:19.660191059 CET2701852304162.254.199.165192.168.2.4
                                                                                                            Nov 20, 2024 00:01:49.654841900 CET5230427018192.168.2.4162.254.199.165
                                                                                                            Nov 20, 2024 00:01:49.659823895 CET2701852304162.254.199.165192.168.2.4
                                                                                                            Nov 20, 2024 00:01:56.929836035 CET2701852304162.254.199.165192.168.2.4
                                                                                                            Nov 20, 2024 00:01:56.982707977 CET5230427018192.168.2.4162.254.199.165
                                                                                                            Nov 20, 2024 00:01:57.025258064 CET2701852304162.254.199.165192.168.2.4
                                                                                                            Nov 20, 2024 00:01:57.026236057 CET5230427018192.168.2.4162.254.199.165
                                                                                                            Nov 20, 2024 00:01:57.031572104 CET2701852304162.254.199.165192.168.2.4
                                                                                                            Nov 20, 2024 00:01:57.031666040 CET5230427018192.168.2.4162.254.199.165
                                                                                                            Nov 20, 2024 00:01:57.634166002 CET52571443192.168.2.4162.254.199.184
                                                                                                            Nov 20, 2024 00:01:57.634243011 CET52572443192.168.2.4162.254.199.184
                                                                                                            Nov 20, 2024 00:01:57.634259939 CET44352571162.254.199.184192.168.2.4
                                                                                                            Nov 20, 2024 00:01:57.634330034 CET44352572162.254.199.184192.168.2.4
                                                                                                            Nov 20, 2024 00:01:57.634345055 CET52571443192.168.2.4162.254.199.184
                                                                                                            Nov 20, 2024 00:01:57.634404898 CET52572443192.168.2.4162.254.199.184
                                                                                                            Nov 20, 2024 00:01:57.634759903 CET52571443192.168.2.4162.254.199.184
                                                                                                            Nov 20, 2024 00:01:57.634795904 CET44352571162.254.199.184192.168.2.4
                                                                                                            Nov 20, 2024 00:01:57.634906054 CET52572443192.168.2.4162.254.199.184
                                                                                                            Nov 20, 2024 00:01:57.634990931 CET44352572162.254.199.184192.168.2.4
                                                                                                            Nov 20, 2024 00:01:58.168752909 CET44352571162.254.199.184192.168.2.4
                                                                                                            Nov 20, 2024 00:01:58.168864965 CET52571443192.168.2.4162.254.199.184
                                                                                                            Nov 20, 2024 00:01:58.169686079 CET44352572162.254.199.184192.168.2.4
                                                                                                            Nov 20, 2024 00:01:58.169780970 CET52572443192.168.2.4162.254.199.184
                                                                                                            Nov 20, 2024 00:01:58.171658039 CET52572443192.168.2.4162.254.199.184
                                                                                                            Nov 20, 2024 00:01:58.171685934 CET44352572162.254.199.184192.168.2.4
                                                                                                            Nov 20, 2024 00:01:58.172102928 CET44352572162.254.199.184192.168.2.4
                                                                                                            Nov 20, 2024 00:01:58.172655106 CET52571443192.168.2.4162.254.199.184
                                                                                                            Nov 20, 2024 00:01:58.172678947 CET44352571162.254.199.184192.168.2.4
                                                                                                            Nov 20, 2024 00:01:58.173089027 CET44352571162.254.199.184192.168.2.4
                                                                                                            Nov 20, 2024 00:01:58.180280924 CET52572443192.168.2.4162.254.199.184
                                                                                                            Nov 20, 2024 00:01:58.223407030 CET44352572162.254.199.184192.168.2.4
                                                                                                            Nov 20, 2024 00:01:58.225435019 CET52571443192.168.2.4162.254.199.184
                                                                                                            Nov 20, 2024 00:01:58.298475981 CET44352572162.254.199.184192.168.2.4
                                                                                                            Nov 20, 2024 00:01:58.298755884 CET44352572162.254.199.184192.168.2.4
                                                                                                            Nov 20, 2024 00:01:58.298851013 CET52572443192.168.2.4162.254.199.184
                                                                                                            Nov 20, 2024 00:01:58.303662062 CET52572443192.168.2.4162.254.199.184
                                                                                                            Nov 20, 2024 00:01:58.303726912 CET44352572162.254.199.184192.168.2.4
                                                                                                            Nov 20, 2024 00:01:58.811469078 CET52573443192.168.2.4155.133.253.36
                                                                                                            Nov 20, 2024 00:01:58.811553955 CET44352573155.133.253.36192.168.2.4
                                                                                                            Nov 20, 2024 00:01:58.811650991 CET52573443192.168.2.4155.133.253.36
                                                                                                            Nov 20, 2024 00:01:58.874392033 CET52573443192.168.2.4155.133.253.36
                                                                                                            Nov 20, 2024 00:01:58.874465942 CET44352573155.133.253.36192.168.2.4
                                                                                                            Nov 20, 2024 00:01:59.458574057 CET44352573155.133.253.36192.168.2.4
                                                                                                            Nov 20, 2024 00:01:59.458803892 CET52573443192.168.2.4155.133.253.36
                                                                                                            Nov 20, 2024 00:01:59.463901043 CET52573443192.168.2.4155.133.253.36
                                                                                                            Nov 20, 2024 00:01:59.463984013 CET44352573155.133.253.36192.168.2.4
                                                                                                            Nov 20, 2024 00:01:59.464386940 CET44352573155.133.253.36192.168.2.4
                                                                                                            Nov 20, 2024 00:01:59.466114998 CET52573443192.168.2.4155.133.253.36
                                                                                                            Nov 20, 2024 00:01:59.511328936 CET44352573155.133.253.36192.168.2.4
                                                                                                            Nov 20, 2024 00:01:59.625757933 CET44352573155.133.253.36192.168.2.4
                                                                                                            Nov 20, 2024 00:01:59.625942945 CET44352573155.133.253.36192.168.2.4
                                                                                                            Nov 20, 2024 00:01:59.626013041 CET52573443192.168.2.4155.133.253.36
                                                                                                            Nov 20, 2024 00:01:59.626540899 CET52573443192.168.2.4155.133.253.36
                                                                                                            Nov 20, 2024 00:01:59.626605988 CET44352573155.133.253.36192.168.2.4
                                                                                                            Nov 20, 2024 00:02:06.148220062 CET52574443192.168.2.4162.254.192.98
                                                                                                            Nov 20, 2024 00:02:06.148293972 CET44352574162.254.192.98192.168.2.4
                                                                                                            Nov 20, 2024 00:02:06.148390055 CET52574443192.168.2.4162.254.192.98
                                                                                                            Nov 20, 2024 00:02:06.148798943 CET52574443192.168.2.4162.254.192.98
                                                                                                            Nov 20, 2024 00:02:06.148832083 CET44352574162.254.192.98192.168.2.4
                                                                                                            Nov 20, 2024 00:02:06.645148993 CET44352574162.254.192.98192.168.2.4
                                                                                                            Nov 20, 2024 00:02:06.645236969 CET52574443192.168.2.4162.254.192.98
                                                                                                            Nov 20, 2024 00:02:06.646812916 CET52574443192.168.2.4162.254.192.98
                                                                                                            Nov 20, 2024 00:02:06.646842003 CET44352574162.254.192.98192.168.2.4
                                                                                                            Nov 20, 2024 00:02:06.647370100 CET44352574162.254.192.98192.168.2.4
                                                                                                            Nov 20, 2024 00:02:06.648904085 CET52574443192.168.2.4162.254.192.98
                                                                                                            Nov 20, 2024 00:02:06.695427895 CET44352574162.254.192.98192.168.2.4
                                                                                                            Nov 20, 2024 00:02:06.754694939 CET44352574162.254.192.98192.168.2.4
                                                                                                            Nov 20, 2024 00:02:06.754762888 CET44352574162.254.192.98192.168.2.4
                                                                                                            Nov 20, 2024 00:02:06.754882097 CET52574443192.168.2.4162.254.192.98
                                                                                                            Nov 20, 2024 00:02:06.755441904 CET52574443192.168.2.4162.254.192.98
                                                                                                            Nov 20, 2024 00:02:06.755502939 CET44352574162.254.192.98192.168.2.4
                                                                                                            Nov 20, 2024 00:02:07.164402008 CET52575443192.168.2.4162.254.192.99
                                                                                                            Nov 20, 2024 00:02:07.164488077 CET44352575162.254.192.99192.168.2.4
                                                                                                            Nov 20, 2024 00:02:07.164578915 CET52575443192.168.2.4162.254.192.99
                                                                                                            Nov 20, 2024 00:02:07.164943933 CET52575443192.168.2.4162.254.192.99
                                                                                                            Nov 20, 2024 00:02:07.164974928 CET44352575162.254.192.99192.168.2.4
                                                                                                            Nov 20, 2024 00:02:07.668412924 CET44352575162.254.192.99192.168.2.4
                                                                                                            Nov 20, 2024 00:02:07.668500900 CET52575443192.168.2.4162.254.192.99
                                                                                                            Nov 20, 2024 00:02:07.670002937 CET52575443192.168.2.4162.254.192.99
                                                                                                            Nov 20, 2024 00:02:07.670047045 CET44352575162.254.192.99192.168.2.4
                                                                                                            Nov 20, 2024 00:02:07.670543909 CET44352575162.254.192.99192.168.2.4
                                                                                                            Nov 20, 2024 00:02:07.673654079 CET52575443192.168.2.4162.254.192.99
                                                                                                            Nov 20, 2024 00:02:07.719322920 CET44352575162.254.192.99192.168.2.4
                                                                                                            Nov 20, 2024 00:02:07.780056953 CET44352575162.254.192.99192.168.2.4
                                                                                                            Nov 20, 2024 00:02:07.780200005 CET44352575162.254.192.99192.168.2.4
                                                                                                            Nov 20, 2024 00:02:07.780497074 CET52575443192.168.2.4162.254.192.99
                                                                                                            Nov 20, 2024 00:02:07.780916929 CET52575443192.168.2.4162.254.192.99
                                                                                                            Nov 20, 2024 00:02:07.780952930 CET44352575162.254.192.99192.168.2.4
                                                                                                            Nov 20, 2024 00:02:10.212136984 CET52576443192.168.2.4155.133.253.52
                                                                                                            Nov 20, 2024 00:02:10.212224007 CET44352576155.133.253.52192.168.2.4
                                                                                                            Nov 20, 2024 00:02:10.212318897 CET52576443192.168.2.4155.133.253.52
                                                                                                            Nov 20, 2024 00:02:10.212764978 CET52576443192.168.2.4155.133.253.52
                                                                                                            Nov 20, 2024 00:02:10.212846041 CET44352576155.133.253.52192.168.2.4
                                                                                                            Nov 20, 2024 00:02:10.768913031 CET44352576155.133.253.52192.168.2.4
                                                                                                            Nov 20, 2024 00:02:10.769073009 CET52576443192.168.2.4155.133.253.52
                                                                                                            Nov 20, 2024 00:02:10.770371914 CET52576443192.168.2.4155.133.253.52
                                                                                                            Nov 20, 2024 00:02:10.770426989 CET44352576155.133.253.52192.168.2.4
                                                                                                            Nov 20, 2024 00:02:10.770973921 CET44352576155.133.253.52192.168.2.4
                                                                                                            Nov 20, 2024 00:02:10.771823883 CET52576443192.168.2.4155.133.253.52
                                                                                                            Nov 20, 2024 00:02:10.815408945 CET44352576155.133.253.52192.168.2.4
                                                                                                            Nov 20, 2024 00:02:10.932045937 CET44352576155.133.253.52192.168.2.4
                                                                                                            Nov 20, 2024 00:02:10.932267904 CET44352576155.133.253.52192.168.2.4
                                                                                                            Nov 20, 2024 00:02:10.932465076 CET52576443192.168.2.4155.133.253.52
                                                                                                            Nov 20, 2024 00:02:10.932548046 CET52576443192.168.2.4155.133.253.52
                                                                                                            Nov 20, 2024 00:02:10.932585955 CET44352576155.133.253.52192.168.2.4
                                                                                                            TimestampSource PortDest PortSource IPDest IP
                                                                                                            Nov 20, 2024 00:00:37.443185091 CET5361292162.159.36.2192.168.2.4
                                                                                                            Nov 20, 2024 00:00:37.919338942 CET6504953192.168.2.41.1.1.1
                                                                                                            Nov 20, 2024 00:00:37.926680088 CET53650491.1.1.1192.168.2.4
                                                                                                            Nov 20, 2024 00:00:47.118854046 CET5804353192.168.2.41.1.1.1
                                                                                                            Nov 20, 2024 00:00:47.126313925 CET53580431.1.1.1192.168.2.4
                                                                                                            Nov 20, 2024 00:00:48.837941885 CET5038353192.168.2.41.1.1.1
                                                                                                            Nov 20, 2024 00:00:48.846267939 CET53503831.1.1.1192.168.2.4
                                                                                                            Nov 20, 2024 00:01:57.625673056 CET6024653192.168.2.41.1.1.1
                                                                                                            Nov 20, 2024 00:01:57.633006096 CET53602461.1.1.1192.168.2.4
                                                                                                            Nov 20, 2024 00:01:58.744932890 CET6004853192.168.2.41.1.1.1
                                                                                                            Nov 20, 2024 00:01:58.752301931 CET53600481.1.1.1192.168.2.4
                                                                                                            Nov 20, 2024 00:02:06.140228033 CET5588853192.168.2.41.1.1.1
                                                                                                            Nov 20, 2024 00:02:06.147452116 CET53558881.1.1.1192.168.2.4
                                                                                                            Nov 20, 2024 00:02:07.156227112 CET5655953192.168.2.41.1.1.1
                                                                                                            Nov 20, 2024 00:02:07.163667917 CET53565591.1.1.1192.168.2.4
                                                                                                            Nov 20, 2024 00:02:10.203949928 CET6520953192.168.2.41.1.1.1
                                                                                                            Nov 20, 2024 00:02:10.211467028 CET53652091.1.1.1192.168.2.4
                                                                                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                                            Nov 20, 2024 00:00:37.919338942 CET192.168.2.41.1.1.10x6277Standard query (0)198.187.3.20.in-addr.arpaPTR (Pointer record)IN (0x0001)false
                                                                                                            Nov 20, 2024 00:00:47.118854046 CET192.168.2.41.1.1.10xe501Standard query (0)api.steampowered.comA (IP address)IN (0x0001)false
                                                                                                            Nov 20, 2024 00:00:48.837941885 CET192.168.2.41.1.1.10x5c06Standard query (0)cmp1-atl3.steamserver.netA (IP address)IN (0x0001)false
                                                                                                            Nov 20, 2024 00:01:57.625673056 CET192.168.2.41.1.1.10xdd5dStandard query (0)cmp2-atl3.steamserver.netA (IP address)IN (0x0001)false
                                                                                                            Nov 20, 2024 00:01:58.744932890 CET192.168.2.41.1.1.10x6db7Standard query (0)cmp1-dfw1.steamserver.netA (IP address)IN (0x0001)false
                                                                                                            Nov 20, 2024 00:02:06.140228033 CET192.168.2.41.1.1.10xe461Standard query (0)cmp1-iad1.steamserver.netA (IP address)IN (0x0001)false
                                                                                                            Nov 20, 2024 00:02:07.156227112 CET192.168.2.41.1.1.10xd5beStandard query (0)cmp2-iad1.steamserver.netA (IP address)IN (0x0001)false
                                                                                                            Nov 20, 2024 00:02:10.203949928 CET192.168.2.41.1.1.10x26deStandard query (0)cmp2-dfw1.steamserver.netA (IP address)IN (0x0001)false
                                                                                                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                                            Nov 20, 2024 00:00:37.926680088 CET1.1.1.1192.168.2.40x6277Name error (3)198.187.3.20.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)false
                                                                                                            Nov 20, 2024 00:00:47.126313925 CET1.1.1.1192.168.2.40xe501No error (0)api.steampowered.com104.102.49.254A (IP address)IN (0x0001)false
                                                                                                            Nov 20, 2024 00:00:48.846267939 CET1.1.1.1192.168.2.40x5c06No error (0)cmp1-atl3.steamserver.net162.254.199.165A (IP address)IN (0x0001)false
                                                                                                            Nov 20, 2024 00:01:57.633006096 CET1.1.1.1192.168.2.40xdd5dNo error (0)cmp2-atl3.steamserver.net162.254.199.184A (IP address)IN (0x0001)false
                                                                                                            Nov 20, 2024 00:01:58.752301931 CET1.1.1.1192.168.2.40x6db7No error (0)cmp1-dfw1.steamserver.net155.133.253.36A (IP address)IN (0x0001)false
                                                                                                            Nov 20, 2024 00:02:06.147452116 CET1.1.1.1192.168.2.40xe461No error (0)cmp1-iad1.steamserver.net162.254.192.98A (IP address)IN (0x0001)false
                                                                                                            Nov 20, 2024 00:02:07.163667917 CET1.1.1.1192.168.2.40xd5beNo error (0)cmp2-iad1.steamserver.net162.254.192.99A (IP address)IN (0x0001)false
                                                                                                            Nov 20, 2024 00:02:10.211467028 CET1.1.1.1192.168.2.40x26deNo error (0)cmp2-dfw1.steamserver.net155.133.253.52A (IP address)IN (0x0001)false
                                                                                                            • api.steampowered.com
                                                                                                            • cmp2-atl3.steamserver.net
                                                                                                            • cmp1-dfw1.steamserver.net
                                                                                                            • cmp1-iad1.steamserver.net
                                                                                                            • cmp2-iad1.steamserver.net
                                                                                                            • cmp2-dfw1.steamserver.net
                                                                                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                            0192.168.2.452303104.102.49.2544437640C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exe
                                                                                                            TimestampBytes transferredDirectionData
                                                                                                            2024-11-19 23:00:48 UTC133OUTGET /ISteamDirectory/GetCMListForConnect/v1/?format=vdf&cellid=0 HTTP/1.1
                                                                                                            Host: api.steampowered.com
                                                                                                            User-Agent: SteamKit/3.0.0
                                                                                                            2024-11-19 23:00:48 UTC226INHTTP/1.1 200 OK
                                                                                                            Server: nginx
                                                                                                            Content-Type: text/vdf; charset=UTF-8
                                                                                                            Cache-Control: public, max-age=5
                                                                                                            Expires: Tue, 19 Nov 2024 23:00:53 GMT
                                                                                                            Date: Tue, 19 Nov 2024 23:00:48 GMT
                                                                                                            Content-Length: 36792
                                                                                                            Connection: close
                                                                                                            2024-11-19 23:00:48 UTC16158INData Raw: 22 72 65 73 70 6f 6e 73 65 22 0a 7b 0a 09 22 73 65 72 76 65 72 6c 69 73 74 22 0a 09 7b 0a 09 09 22 30 22 0a 09 09 7b 0a 09 09 09 22 65 6e 64 70 6f 69 6e 74 22 09 22 63 6d 70 31 2d 61 74 6c 33 2e 73 74 65 61 6d 73 65 72 76 65 72 2e 6e 65 74 3a 32 37 30 31 38 22 0a 09 09 09 22 6c 65 67 61 63 79 5f 65 6e 64 70 6f 69 6e 74 22 09 22 63 6d 70 31 2d 61 74 6c 33 2e 73 74 65 61 6d 73 65 72 76 65 72 2e 6e 65 74 3a 32 37 30 31 38 22 0a 09 09 09 22 74 79 70 65 22 09 22 77 65 62 73 6f 63 6b 65 74 73 22 0a 09 09 09 22 64 63 22 09 22 61 74 6c 33 22 0a 09 09 09 22 72 65 61 6c 6d 22 09 22 73 74 65 61 6d 67 6c 6f 62 61 6c 22 0a 09 09 09 22 6c 6f 61 64 22 09 22 32 36 22 0a 09 09 09 22 77 74 64 5f 6c 6f 61 64 22 09 22 31 34 2e 33 36 32 32 31 35 30 34 32 31 31 34 32 35 37 38
                                                                                                            Data Ascii: "response"{"serverlist"{"0"{"endpoint""cmp1-atl3.steamserver.net:27018""legacy_endpoint""cmp1-atl3.steamserver.net:27018""type""websockets""dc""atl3""realm""steamglobal""load""26""wtd_load""14.3622150421142578
                                                                                                            2024-11-19 23:00:48 UTC16384INData Raw: 73 65 72 76 65 72 2e 6e 65 74 3a 32 37 30 31 38 22 0a 09 09 09 22 74 79 70 65 22 09 22 77 65 62 73 6f 63 6b 65 74 73 22 0a 09 09 09 22 64 63 22 09 22 6f 72 64 31 22 0a 09 09 09 22 72 65 61 6c 6d 22 09 22 73 74 65 61 6d 67 6c 6f 62 61 6c 22 0a 09 09 09 22 6c 6f 61 64 22 09 22 34 33 22 0a 09 09 09 22 77 74 64 5f 6c 6f 61 64 22 09 22 37 37 2e 37 30 33 30 35 37 32 38 39 31 32 33 35 33 35 32 22 0a 09 09 7d 0a 09 09 22 37 31 22 0a 09 09 7b 0a 09 09 09 22 65 6e 64 70 6f 69 6e 74 22 09 22 63 6d 70 31 2d 6f 72 64 31 2e 73 74 65 61 6d 73 65 72 76 65 72 2e 6e 65 74 3a 32 37 30 31 38 22 0a 09 09 09 22 6c 65 67 61 63 79 5f 65 6e 64 70 6f 69 6e 74 22 09 22 63 6d 70 31 2d 6f 72 64 31 2e 73 74 65 61 6d 73 65 72 76 65 72 2e 6e 65 74 3a 32 37 30 31 38 22 0a 09 09 09 22 74
                                                                                                            Data Ascii: server.net:27018""type""websockets""dc""ord1""realm""steamglobal""load""43""wtd_load""77.7030572891235352"}"71"{"endpoint""cmp1-ord1.steamserver.net:27018""legacy_endpoint""cmp1-ord1.steamserver.net:27018""t
                                                                                                            2024-11-19 23:00:48 UTC3448INData Raw: 0a 09 09 09 22 6c 6f 61 64 22 09 22 31 33 22 0a 09 09 09 22 77 74 64 5f 6c 6f 61 64 22 09 22 32 35 30 2e 38 32 30 30 32 38 33 30 35 30 35 33 37 31 31 22 0a 09 09 7d 0a 09 09 22 31 34 32 22 0a 09 09 7b 0a 09 09 09 22 65 6e 64 70 6f 69 6e 74 22 09 22 63 6d 70 31 2d 6c 68 72 31 2e 73 74 65 61 6d 73 65 72 76 65 72 2e 6e 65 74 3a 32 37 30 32 30 22 0a 09 09 09 22 6c 65 67 61 63 79 5f 65 6e 64 70 6f 69 6e 74 22 09 22 63 6d 70 31 2d 6c 68 72 31 2e 73 74 65 61 6d 73 65 72 76 65 72 2e 6e 65 74 3a 32 37 30 32 30 22 0a 09 09 09 22 74 79 70 65 22 09 22 77 65 62 73 6f 63 6b 65 74 73 22 0a 09 09 09 22 64 63 22 09 22 6c 68 72 31 22 0a 09 09 09 22 72 65 61 6c 6d 22 09 22 73 74 65 61 6d 67 6c 6f 62 61 6c 22 0a 09 09 09 22 6c 6f 61 64 22 09 22 31 33 22 0a 09 09 09 22 77 74
                                                                                                            Data Ascii: "load""13""wtd_load""250.820028305053711"}"142"{"endpoint""cmp1-lhr1.steamserver.net:27020""legacy_endpoint""cmp1-lhr1.steamserver.net:27020""type""websockets""dc""lhr1""realm""steamglobal""load""13""wt
                                                                                                            2024-11-19 23:00:48 UTC802INData Raw: 09 09 09 22 64 63 22 09 22 70 61 72 31 22 0a 09 09 09 22 72 65 61 6c 6d 22 09 22 73 74 65 61 6d 67 6c 6f 62 61 6c 22 0a 09 09 09 22 6c 6f 61 64 22 09 22 32 32 22 0a 09 09 09 22 77 74 64 5f 6c 6f 61 64 22 09 22 33 31 36 2e 34 33 31 33 32 37 38 31 39 38 32 34 32 31 39 22 0a 09 09 7d 0a 09 09 22 31 35 37 22 0a 09 09 7b 0a 09 09 09 22 65 6e 64 70 6f 69 6e 74 22 09 22 31 38 35 2e 32 35 2e 31 38 32 2e 32 30 3a 32 37 30 31 37 22 0a 09 09 09 22 6c 65 67 61 63 79 5f 65 6e 64 70 6f 69 6e 74 22 09 22 31 38 35 2e 32 35 2e 31 38 32 2e 32 30 3a 32 37 30 31 37 22 0a 09 09 09 22 74 79 70 65 22 09 22 6e 65 74 66 69 6c 74 65 72 22 0a 09 09 09 22 64 63 22 09 22 70 61 72 31 22 0a 09 09 09 22 72 65 61 6c 6d 22 09 22 73 74 65 61 6d 67 6c 6f 62 61 6c 22 0a 09 09 09 22 6c 6f 61
                                                                                                            Data Ascii: "dc""par1""realm""steamglobal""load""22""wtd_load""316.431327819824219"}"157"{"endpoint""185.25.182.20:27017""legacy_endpoint""185.25.182.20:27017""type""netfilter""dc""par1""realm""steamglobal""loa


                                                                                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                            1192.168.2.452572162.254.199.1844437640C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exe
                                                                                                            TimestampBytes transferredDirectionData
                                                                                                            2024-11-19 23:01:58 UTC173OUTGET /cmsocket/ HTTP/1.1
                                                                                                            Host: cmp2-atl3.steamserver.net
                                                                                                            Connection: Upgrade
                                                                                                            Upgrade: websocket
                                                                                                            Sec-WebSocket-Key: SX1pmJICoUOgvcAEWO04Yg==
                                                                                                            Sec-WebSocket-Version: 13
                                                                                                            2024-11-19 23:01:58 UTC265INHTTP/1.1 400 Bad Request
                                                                                                            Server: nginx/1.25.5
                                                                                                            Date: Tue, 19 Nov 2024 23:01:58 GMT
                                                                                                            Content-Type: text/html; charset=UTF-8
                                                                                                            Content-Length: 96
                                                                                                            Connection: close
                                                                                                            Expires: Mon, 26 Jul 1997 05:00:00 GMT
                                                                                                            Cache-Control: no-cache,must-revalidate
                                                                                                            Pragma: no-cache
                                                                                                            2024-11-19 23:01:58 UTC96INData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 68 31 3e 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 0a 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e
                                                                                                            Data Ascii: <html><head><title>400 Bad Request</title></head><body><h1>Bad Request</h1></body></html>


                                                                                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                            2192.168.2.452573155.133.253.364437640C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exe
                                                                                                            TimestampBytes transferredDirectionData
                                                                                                            2024-11-19 23:01:59 UTC173OUTGET /cmsocket/ HTTP/1.1
                                                                                                            Host: cmp1-dfw1.steamserver.net
                                                                                                            Connection: Upgrade
                                                                                                            Upgrade: websocket
                                                                                                            Sec-WebSocket-Key: 8pAM8HKoEEa2SDwRfJv7Yw==
                                                                                                            Sec-WebSocket-Version: 13
                                                                                                            2024-11-19 23:01:59 UTC265INHTTP/1.1 400 Bad Request
                                                                                                            Server: nginx/1.25.5
                                                                                                            Date: Tue, 19 Nov 2024 23:01:59 GMT
                                                                                                            Content-Type: text/html; charset=UTF-8
                                                                                                            Content-Length: 96
                                                                                                            Connection: close
                                                                                                            Expires: Mon, 26 Jul 1997 05:00:00 GMT
                                                                                                            Cache-Control: no-cache,must-revalidate
                                                                                                            Pragma: no-cache
                                                                                                            2024-11-19 23:01:59 UTC96INData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 68 31 3e 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 0a 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e
                                                                                                            Data Ascii: <html><head><title>400 Bad Request</title></head><body><h1>Bad Request</h1></body></html>


                                                                                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                            3192.168.2.452574162.254.192.984437640C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exe
                                                                                                            TimestampBytes transferredDirectionData
                                                                                                            2024-11-19 23:02:06 UTC173OUTGET /cmsocket/ HTTP/1.1
                                                                                                            Host: cmp1-iad1.steamserver.net
                                                                                                            Connection: Upgrade
                                                                                                            Upgrade: websocket
                                                                                                            Sec-WebSocket-Key: 4Mzn+oyKNEOPx/VMky/HWA==
                                                                                                            Sec-WebSocket-Version: 13
                                                                                                            2024-11-19 23:02:06 UTC265INHTTP/1.1 400 Bad Request
                                                                                                            Server: nginx/1.25.5
                                                                                                            Date: Tue, 19 Nov 2024 23:02:06 GMT
                                                                                                            Content-Type: text/html; charset=UTF-8
                                                                                                            Content-Length: 96
                                                                                                            Connection: close
                                                                                                            Expires: Mon, 26 Jul 1997 05:00:00 GMT
                                                                                                            Cache-Control: no-cache,must-revalidate
                                                                                                            Pragma: no-cache
                                                                                                            2024-11-19 23:02:06 UTC96INData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 68 31 3e 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 0a 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e
                                                                                                            Data Ascii: <html><head><title>400 Bad Request</title></head><body><h1>Bad Request</h1></body></html>


                                                                                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                            4192.168.2.452575162.254.192.994437640C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exe
                                                                                                            TimestampBytes transferredDirectionData
                                                                                                            2024-11-19 23:02:07 UTC173OUTGET /cmsocket/ HTTP/1.1
                                                                                                            Host: cmp2-iad1.steamserver.net
                                                                                                            Connection: Upgrade
                                                                                                            Upgrade: websocket
                                                                                                            Sec-WebSocket-Key: 9SfrCnjzD0+vkNHqMYQEtw==
                                                                                                            Sec-WebSocket-Version: 13
                                                                                                            2024-11-19 23:02:07 UTC265INHTTP/1.1 400 Bad Request
                                                                                                            Server: nginx/1.25.5
                                                                                                            Date: Tue, 19 Nov 2024 23:02:07 GMT
                                                                                                            Content-Type: text/html; charset=UTF-8
                                                                                                            Content-Length: 96
                                                                                                            Connection: close
                                                                                                            Expires: Mon, 26 Jul 1997 05:00:00 GMT
                                                                                                            Cache-Control: no-cache,must-revalidate
                                                                                                            Pragma: no-cache
                                                                                                            2024-11-19 23:02:07 UTC96INData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 68 31 3e 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 0a 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e
                                                                                                            Data Ascii: <html><head><title>400 Bad Request</title></head><body><h1>Bad Request</h1></body></html>


                                                                                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                            5192.168.2.452576155.133.253.524437640C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exe
                                                                                                            TimestampBytes transferredDirectionData
                                                                                                            2024-11-19 23:02:10 UTC173OUTGET /cmsocket/ HTTP/1.1
                                                                                                            Host: cmp2-dfw1.steamserver.net
                                                                                                            Connection: Upgrade
                                                                                                            Upgrade: websocket
                                                                                                            Sec-WebSocket-Key: gct+FU7dl0WK9aM8K5/MdQ==
                                                                                                            Sec-WebSocket-Version: 13
                                                                                                            2024-11-19 23:02:10 UTC265INHTTP/1.1 400 Bad Request
                                                                                                            Server: nginx/1.25.5
                                                                                                            Date: Tue, 19 Nov 2024 23:02:10 GMT
                                                                                                            Content-Type: text/html; charset=UTF-8
                                                                                                            Content-Length: 96
                                                                                                            Connection: close
                                                                                                            Expires: Mon, 26 Jul 1997 05:00:00 GMT
                                                                                                            Cache-Control: no-cache,must-revalidate
                                                                                                            Pragma: no-cache
                                                                                                            2024-11-19 23:02:10 UTC96INData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 68 31 3e 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 0a 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e
                                                                                                            Data Ascii: <html><head><title>400 Bad Request</title></head><body><h1>Bad Request</h1></body></html>


                                                                                                            Click to jump to process

                                                                                                            Click to jump to process

                                                                                                            Click to dive into process behavior distribution

                                                                                                            Click to jump to process

                                                                                                            Target ID:0
                                                                                                            Start time:18:00:04
                                                                                                            Start date:19/11/2024
                                                                                                            Path:C:\Users\user\Desktop\SteamSetup.exe
                                                                                                            Wow64 process (32bit):true
                                                                                                            Commandline:"C:\Users\user\Desktop\SteamSetup.exe"
                                                                                                            Imagebase:0x400000
                                                                                                            File size:50'219'482 bytes
                                                                                                            MD5 hash:1B34108B77B984E227BBAD718D89594A
                                                                                                            Has elevated privileges:true
                                                                                                            Has administrator privileges:true
                                                                                                            Programmed in:Borland Delphi
                                                                                                            Reputation:low
                                                                                                            Has exited:true

                                                                                                            Target ID:1
                                                                                                            Start time:18:00:04
                                                                                                            Start date:19/11/2024
                                                                                                            Path:C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp
                                                                                                            Wow64 process (32bit):true
                                                                                                            Commandline:"C:\Users\user\AppData\Local\Temp\is-CVTB5.tmp\SteamSetup.tmp" /SL5="$10472,49358704,796160,C:\Users\user\Desktop\SteamSetup.exe"
                                                                                                            Imagebase:0x400000
                                                                                                            File size:3'132'416 bytes
                                                                                                            MD5 hash:5338593C8A3654FEF48E3EFD7FBBE890
                                                                                                            Has elevated privileges:true
                                                                                                            Has administrator privileges:true
                                                                                                            Programmed in:Borland Delphi
                                                                                                            Reputation:low
                                                                                                            Has exited:true

                                                                                                            Target ID:3
                                                                                                            Start time:18:00:23
                                                                                                            Start date:19/11/2024
                                                                                                            Path:C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exe
                                                                                                            Wow64 process (32bit):false
                                                                                                            Commandline:"C:\Users\user\AppData\Local\Programs\SteamClient\Steam2.exe"
                                                                                                            Imagebase:0x7ff69f810000
                                                                                                            File size:158'720 bytes
                                                                                                            MD5 hash:24579F75EE35BDD8E4CCC5351295BD9D
                                                                                                            Has elevated privileges:true
                                                                                                            Has administrator privileges:true
                                                                                                            Programmed in:C, C++ or other language
                                                                                                            Reputation:low
                                                                                                            Has exited:false

                                                                                                            No disassembly