URL:

https://cdn3.bluestacks.com/downloads/windows/bgp/4.260.0.1032/c0a68ea9cb87973b3be6c8da4e48730f/BlueStacksMicroInstaller_4.260.0.1032_native.exe?filename=BlueStacksInstaller_4.260.0.1032_native_2755b7af4b9e59bce8df602eb2cb76e7.exe

Full analysis: https://app.any.run/tasks/f073d874-3c5b-4766-8ccf-8688dc3f8105
Verdict: Malicious activity
Analysis date: January 30, 2021, 23:06:04
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

FA2ACD46FDC6B61DD7F5775A529C249C

SHA1:

7D4ED6A1E472EB9B3991365EC2F3F51D2AF85A71

SHA256:

2E308A310475E48FFFE2FAF054151B0C3075E864D3CC0330463731645B890CF8

SSDEEP:

6:2cMFtaIG/H1SodyPvCqOXqwEJ+M7UrwXqwEuSXjS9:2cMFtrGPByPxOXfUXOS9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • BlueStacksInstaller_4.260.0.1032_native_2755b7af4b9e59bce8df602eb2cb76e7.exe (PID: 1500)
      • BlueStacksInstaller.exe (PID: 2524)
      • BlueStacksInstaller.exe (PID: 3368)
    • Drops executable file immediately after starts

      • BlueStacksInstaller_4.260.0.1032_native_2755b7af4b9e59bce8df602eb2cb76e7.exe (PID: 1500)
    • Loads dropped or rewritten executable

      • BlueStacksInstaller.exe (PID: 3368)
    • Changes settings of System certificates

      • BlueStacksInstaller.exe (PID: 3368)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • chrome.exe (PID: 2208)
      • BlueStacksInstaller_4.260.0.1032_native_2755b7af4b9e59bce8df602eb2cb76e7.exe (PID: 1500)
    • Drops a file that was compiled in debug mode

      • BlueStacksInstaller_4.260.0.1032_native_2755b7af4b9e59bce8df602eb2cb76e7.exe (PID: 1500)
    • Drops a file with a compile date too recent

      • BlueStacksInstaller_4.260.0.1032_native_2755b7af4b9e59bce8df602eb2cb76e7.exe (PID: 1500)
    • Reads Environment values

      • BlueStacksInstaller.exe (PID: 2524)
      • BlueStacksInstaller.exe (PID: 3368)
    • Application launched itself

      • BlueStacksInstaller.exe (PID: 2524)
    • Adds / modifies Windows certificates

      • BlueStacksInstaller.exe (PID: 3368)
  • INFO

    • Application launched itself

      • chrome.exe (PID: 2208)
    • Reads settings of System Certificates

      • chrome.exe (PID: 1872)
      • BlueStacksInstaller.exe (PID: 3368)
    • Reads the hosts file

      • chrome.exe (PID: 1872)
      • chrome.exe (PID: 2208)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
11
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs bluestacksinstaller_4.260.0.1032_native_2755b7af4b9e59bce8df602eb2cb76e7.exe bluestacksinstaller.exe bluestacksinstaller.exe

Process information

PID
CMD
Path
Indicators
Parent process
1500"C:\Users\admin\Downloads\BlueStacksInstaller_4.260.0.1032_native_2755b7af4b9e59bce8df602eb2cb76e7.exe" C:\Users\admin\Downloads\BlueStacksInstaller_4.260.0.1032_native_2755b7af4b9e59bce8df602eb2cb76e7.exe
chrome.exe
User:
admin
Company:
BlueStack Systems Inc.
Integrity Level:
MEDIUM
Description:
BlueStacks Installer
Exit code:
0
Version:
4.00
Modules
Images
c:\users\admin\downloads\bluestacksinstaller_4.260.0.1032_native_2755b7af4b9e59bce8df602eb2cb76e7.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1872"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1020,9454912941508575617,5245467823055956320,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=network --service-request-channel-token=478508334927666716 --mojo-platform-channel-handle=1572 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2208"C:\Program Files\Google\Chrome\Application\chrome.exe" --disk-cache-dir=null --disk-cache-size=1 --media-cache-size=1 --disable-gpu-shader-disk-cache --disable-background-networking "https://cdn3.bluestacks.com/downloads/windows/bgp/4.260.0.1032/c0a68ea9cb87973b3be6c8da4e48730f/BlueStacksMicroInstaller_4.260.0.1032_native.exe?filename=BlueStacksInstaller_4.260.0.1032_native_2755b7af4b9e59bce8df602eb2cb76e7.exe"C:\Program Files\Google\Chrome\Application\chrome.exe
explorer.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
3221225547
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2304"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,9454912941508575617,5245467823055956320,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=9761315538654158179 --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2204 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2408"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=2228 --on-initialized-event-handle=316 --parent-handle=320 /prefetch:6C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2504"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,9454912941508575617,5245467823055956320,131072 --enable-features=PasswordImport --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=14726312489953250838 --renderer-client-id=4 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2476 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2524"C:\Users\admin\AppData\Local\Temp\7zSCD5A9105\BlueStacksInstaller.exe" C:\Users\admin\AppData\Local\Temp\7zSCD5A9105\BlueStacksInstaller.exe
BlueStacksInstaller_4.260.0.1032_native_2755b7af4b9e59bce8df602eb2cb76e7.exe
User:
admin
Company:
BlueStack Systems, Inc.
Integrity Level:
MEDIUM
Description:
BlueStacks Installer
Exit code:
0
Version:
4.260.0.1032
Modules
Images
c:\users\admin\appdata\local\temp\7zscd5a9105\bluestacksinstaller.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3112"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=75.0.3770.100 --initial-client-data=0x7c,0x80,0x84,0x78,0x88,0x71a6a9d0,0x71a6a9e0,0x71a6a9ecC:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
3368"C:\Users\admin\AppData\Local\Temp\7zSCD5A9105\BlueStacksInstaller.exe" "install" "BlueStacksInstaller_4.260.0.1032_native_2755b7af4b9e59bce8df602eb2cb76e7.exe" "2755b7af4b9e59bce8df602eb2cb76e7" "non_admin" "bd122ffd-9953-44dd-9ab9-6b74653157d6" "ed9dc619-baff-49f1-bdcd-c86eb6969b0b"C:\Users\admin\AppData\Local\Temp\7zSCD5A9105\BlueStacksInstaller.exe
BlueStacksInstaller.exe
User:
admin
Company:
BlueStack Systems, Inc.
Integrity Level:
HIGH
Description:
BlueStacks Installer
Exit code:
0
Version:
4.260.0.1032
Modules
Images
c:\users\admin\appdata\local\temp\7zscd5a9105\bluestacksinstaller.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3436"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1020,9454912941508575617,5245467823055956320,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=16026661753139144870 --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2184 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
Total events
1 569
Read events
1 469
Write events
97
Delete events
3

Modification events

(PID) Process:(2208) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(2208) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(2208) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(2208) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(2208) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(2408) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:writeName:2208-13256521579091125
Value:
259
(PID) Process:(2208) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:dr
Value:
1
(PID) Process:(2208) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome
Operation:writeName:UsageStatsInSample
Value:
0
(PID) Process:(2208) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:delete valueName:3252-13245750958665039
Value:
0
(PID) Process:(2208) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
Executable files
6
Suspicious files
20
Text files
127
Unknown types
4

Dropped files

PID
Process
Filename
Type
2208chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-6015E66B-8A0.pma
MD5:
SHA256:
2208chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old
MD5:
SHA256:
2208chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old
MD5:
SHA256:
2208chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\edd3231b-6fe5-4094-96b0-3601ce496c1f.tmp
MD5:
SHA256:
2208chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000048.dbtmp
MD5:
SHA256:
2208chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.oldtext
MD5:
SHA256:
2208chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RF150568.TMPtext
MD5:
SHA256:
2208chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.oldtext
MD5:
SHA256:
2208chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old
MD5:
SHA256:
2208chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old~RF15071e.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
9
DNS requests
7
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2208
chrome.exe
GET
200
205.185.216.42:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
57.7 Kb
whitelisted
3368
BlueStacksInstaller.exe
GET
65.9.7.96:80
http://cdn3.bluestacks.com/downloads/windows/bgp/4.260.0.1032/c0a68ea9cb87973b3be6c8da4e48730f/x86/BlueStacks-Installer_4.260.0.1032_x86_native.exe?filename=BlueStacksInstaller_4.260.0.1032_native_2755b7af4b9e59bce8df602eb2cb76e7.exe
US
shared
2208
chrome.exe
GET
304
205.185.216.42:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
57.7 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1872
chrome.exe
65.9.7.108:443
cdn3.bluestacks.com
AT&T Services, Inc.
US
suspicious
1872
chrome.exe
142.250.186.77:443
accounts.google.com
Google Inc.
US
suspicious
2208
chrome.exe
205.185.216.42:80
www.download.windowsupdate.com
Highwinds Network Group, Inc.
US
whitelisted
1872
chrome.exe
172.253.124.136:443
sb-ssl.google.com
Google Inc.
US
unknown
2524
BlueStacksInstaller.exe
216.58.212.179:443
cloud.bluestacks.com
Google Inc.
US
whitelisted
3368
BlueStacksInstaller.exe
216.58.212.179:443
cloud.bluestacks.com
Google Inc.
US
whitelisted
3368
BlueStacksInstaller.exe
65.9.7.96:80
cdn3.bluestacks.com
AT&T Services, Inc.
US
suspicious

DNS requests

Domain
IP
Reputation
cdn3.bluestacks.com
  • 65.9.7.108
  • 65.9.7.26
  • 65.9.7.89
  • 65.9.7.96
shared
accounts.google.com
  • 142.250.186.77
shared
sb-ssl.google.com
  • 172.253.124.136
  • 172.253.124.93
  • 172.253.124.91
  • 172.253.124.190
whitelisted
www.download.windowsupdate.com
  • 205.185.216.42
  • 205.185.216.10
whitelisted
cloud.bluestacks.com
  • 216.58.212.179
whitelisted

Threats

PID
Process
Class
Message
3368
BlueStacksInstaller.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .exe file with no User-Agent
3368
BlueStacksInstaller.exe
Potentially Bad Traffic
ET POLICY Executable served from Amazon S3
3368
BlueStacksInstaller.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3368
BlueStacksInstaller.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
No debug info