download:

BlueStacksMicroInstaller_4.220.0.1109_native.exe

Full analysis: https://app.any.run/tasks/7fa808d2-c9f3-406f-82c2-d9d3616e6b3e
Verdict: Malicious activity
Analysis date: August 23, 2020, 22:35:59
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

9698F039AE70BA9B609BA0FCBD687699

SHA1:

9E158C45794F34A399F40D97DEF467908627E220

SHA256:

65A13A4E8B454D2670BFC0B46379A6782F48A477B840EA7BE125D7C0B19A4936

SSDEEP:

24576:KcVkKS/WtWrnngnnnKnanxNpAg0Vh/UIHDBGpVz7RdO8:KcB6WErnngnnnKnanz6jh/UIjB8Vz7jO

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • BlueStacksInstaller.exe (PID: 1472)
      • BlueStacksInstaller.exe (PID: 4048)
      • BlueStacksInstaller.exe (PID: 3592)
    • Changes settings of System certificates

      • BlueStacksInstaller.exe (PID: 4048)
    • Loads dropped or rewritten executable

      • BlueStacksInstaller.exe (PID: 4048)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • BlueStacksMicroInstaller_4.220.0.1109_native.exe (PID: 948)
      • BlueStacksMicroInstaller_4.220.0.1109_native.exe (PID: 3684)
      • BlueStacksInstaller.exe (PID: 4048)
    • Reads Environment values

      • BlueStacksInstaller.exe (PID: 1472)
      • BlueStacksInstaller.exe (PID: 4048)
    • Application launched itself

      • BlueStacksInstaller.exe (PID: 1472)
    • Adds / modifies Windows certificates

      • BlueStacksInstaller.exe (PID: 4048)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:02:21 17:00:00+01:00
PEType: PE32
LinkerVersion: 6
CodeSize: 104448
InitializedDataSize: 372224
UninitializedDataSize: -
EntryPoint: 0x1910c
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 19.0.0.0
ProductVersionNumber: 19.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: BlueStack Systems Inc.
FileDescription: BlueStacks Installer
FileVersion: 4
InternalName: BlueStacks Installer
LegalCopyright: Copyright (c) BlueStack Systems Inc.
OriginalFileName: BlueStacksInstaller.exe
ProductName: BlueStacks Installer
ProductVersion: 4

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 21-Feb-2019 16:00:00
Detected languages:
  • English - United States
CompanyName: BlueStack Systems Inc.
FileDescription: BlueStacks Installer
FileVersion: 4.00
InternalName: BlueStacks Installer
LegalCopyright: Copyright (c) BlueStack Systems Inc.
OriginalFilename: BlueStacksInstaller.exe
ProductName: BlueStacks Installer
ProductVersion: 4.0

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000108

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 21-Feb-2019 16:00:00
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LARGE_ADDRESS_AWARE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00019745
0x00019800
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.63014
.rdata
0x0001B000
0x00003A98
0x00003C00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.39319
.data
0x0001F000
0x000023F0
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
3.30023
.sxdata
0x00022000
0x00000004
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_LNK_INFO, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0.0203931
.rsrc
0x00023000
0x00056DB0
0x00056E00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.08403

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.02012
659
Latin 1 / Western European
English - United States
RT_MANIFEST
2
4.12778
67624
Latin 1 / Western European
English - United States
RT_ICON
3
4.47733
9640
Latin 1 / Western European
English - United States
RT_ICON
4
4.77612
4264
Latin 1 / Western European
English - United States
RT_ICON
5
5.18496
1128
Latin 1 / Western European
English - United States
RT_ICON
97
2.93146
144
Latin 1 / Western European
English - United States
RT_DIALOG
188
2.17822
84
Latin 1 / Western European
English - United States
RT_STRING
207
2.4279
108
Latin 1 / Western European
English - United States
RT_STRING

Imports

KERNEL32.dll
MSVCRT.dll
OLEAUT32.dll
SHELL32.dll
USER32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
5
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start bluestacksmicroinstaller_4.220.0.1109_native.exe bluestacksinstaller.exe bluestacksinstaller.exe bluestacksmicroinstaller_4.220.0.1109_native.exe bluestacksinstaller.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
948"C:\Users\admin\AppData\Local\Temp\BlueStacksMicroInstaller_4.220.0.1109_native.exe" C:\Users\admin\AppData\Local\Temp\BlueStacksMicroInstaller_4.220.0.1109_native.exe
explorer.exe
User:
admin
Company:
BlueStack Systems Inc.
Integrity Level:
MEDIUM
Description:
BlueStacks Installer
Exit code:
0
Version:
4.00
Modules
Images
c:\users\admin\appdata\local\temp\bluestacksmicroinstaller_4.220.0.1109_native.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1472"C:\Users\admin\AppData\Local\Temp\7zS4B36A2ED\BlueStacksInstaller.exe" C:\Users\admin\AppData\Local\Temp\7zS4B36A2ED\BlueStacksInstaller.exe
BlueStacksMicroInstaller_4.220.0.1109_native.exe
User:
admin
Company:
BlueStack Systems, Inc.
Integrity Level:
MEDIUM
Description:
BlueStacks Installer
Exit code:
0
Version:
4.220.0.1109
Modules
Images
c:\users\admin\appdata\local\temp\7zs4b36a2ed\bluestacksinstaller.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3592"C:\Users\admin\AppData\Local\Temp\7zS46E8723E\BlueStacksInstaller.exe" -versionMachineID=73fd3c50-d825-4759-9ee3-dcd378f196f1 -machineID=381bd1d6-0a91-4bb0-8737-ce670a9cd325 -pddir="C:\ProgramData\BlueStacks"C:\Users\admin\AppData\Local\Temp\7zS46E8723E\BlueStacksInstaller.exeBlueStacksMicroInstaller_4.220.0.1109_native.exe
User:
admin
Company:
BlueStack Systems, Inc.
Integrity Level:
HIGH
Description:
BlueStacks Installer
Exit code:
4294967295
Version:
4.220.0.1109
Modules
Images
c:\users\admin\appdata\local\temp\7zs46e8723e\bluestacksinstaller.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3684"C:\Users\admin\AppData\Local\BlueStacksSetup\BlueStacksMicroInstaller_4.220.0.1109_native.exe" -versionMachineID=73fd3c50-d825-4759-9ee3-dcd378f196f1 -machineID=381bd1d6-0a91-4bb0-8737-ce670a9cd325 -pddir="C:\ProgramData\BlueStacks"C:\Users\admin\AppData\Local\BlueStacksSetup\BlueStacksMicroInstaller_4.220.0.1109_native.exe
BlueStacksInstaller.exe
User:
admin
Company:
BlueStack Systems Inc.
Integrity Level:
HIGH
Description:
BlueStacks Installer
Exit code:
0
Version:
4.00
Modules
Images
c:\users\admin\appdata\local\bluestackssetup\bluestacksmicroinstaller_4.220.0.1109_native.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
4048"C:\Users\admin\AppData\Local\Temp\7zS4B36A2ED\BlueStacksInstaller.exe" "install" "BlueStacksMicroInstaller_4.220.0.1109_native.exe" "null" "non_admin" "381bd1d6-0a91-4bb0-8737-ce670a9cd325" "73fd3c50-d825-4759-9ee3-dcd378f196f1"C:\Users\admin\AppData\Local\Temp\7zS4B36A2ED\BlueStacksInstaller.exe
BlueStacksInstaller.exe
User:
admin
Company:
BlueStack Systems, Inc.
Integrity Level:
HIGH
Description:
BlueStacks Installer
Exit code:
0
Version:
4.220.0.1109
Modules
Images
c:\users\admin\appdata\local\temp\7zs4b36a2ed\bluestacksinstaller.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
1 604
Read events
1 542
Write events
62
Delete events
0

Modification events

(PID) Process:(948) BlueStacksMicroInstaller_4.220.0.1109_native.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(948) BlueStacksMicroInstaller_4.220.0.1109_native.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(1472) BlueStacksInstaller.exeKey:HKEY_CURRENT_USER\Software\BlueStacksInstaller
Operation:writeName:MachineID
Value:
381bd1d6-0a91-4bb0-8737-ce670a9cd325
(PID) Process:(1472) BlueStacksInstaller.exeKey:HKEY_CURRENT_USER\Software\BlueStacksInstaller
Operation:writeName:VersionMachineId_4.220.0.1109
Value:
73fd3c50-d825-4759-9ee3-dcd378f196f1
(PID) Process:(1472) BlueStacksInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BlueStacksInstaller_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(1472) BlueStacksInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BlueStacksInstaller_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(1472) BlueStacksInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BlueStacksInstaller_RASAPI32
Operation:writeName:FileTracingMask
Value:
4294901760
(PID) Process:(1472) BlueStacksInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BlueStacksInstaller_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
4294901760
(PID) Process:(1472) BlueStacksInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BlueStacksInstaller_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(1472) BlueStacksInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BlueStacksInstaller_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
Executable files
5
Suspicious files
0
Text files
46
Unknown types
0

Dropped files

PID
Process
Filename
Type
948BlueStacksMicroInstaller_4.220.0.1109_native.exeC:\Users\admin\AppData\Local\Temp\7zS4B36A2ED\Locales\i18n.en-US.txttext
MD5:19BBE3EC3A7D096F4752DD3EAB359678
SHA256:4558128FD5ACD625D6F8FD8D7958AF7E37C83CFC68055471AF6C9F226E07028C
948BlueStacksMicroInstaller_4.220.0.1109_native.exeC:\Users\admin\AppData\Local\Temp\7zS4B36A2ED\Locales\i18n.ja-JP.txttext
MD5:954D268B8D08CD25FEA6EEB33B524A62
SHA256:B25C1E761C15B45B4F13E37E1B4543572F5B3C69004750821F9B79D1F297AB9F
948BlueStacksMicroInstaller_4.220.0.1109_native.exeC:\Users\admin\AppData\Local\Temp\7zS4B36A2ED\Locales\i18n.pl-PL.txttext
MD5:51E843C243D489EA0614A21D10B92235
SHA256:7257872BEBC7992A738850D85F5A23671CB3C844C07E3170EBDF3F1A161B060E
948BlueStacksMicroInstaller_4.220.0.1109_native.exeC:\Users\admin\AppData\Local\Temp\7zS4B36A2ED\Locales\i18n.ar-EG.txttext
MD5:AD5E5BFE3FF366FA9BFBD8EC1C7E3638
SHA256:938EEEC36154F7AB3F2FD89D9A498F75F1318B557EC359D99E0B169EF9E367B0
948BlueStacksMicroInstaller_4.220.0.1109_native.exeC:\Users\admin\AppData\Local\Temp\7zS4B36A2ED\Locales\i18n.fr-FR.txttext
MD5:6596C88A5B2FFD7C79A0914FA1261C22
SHA256:55CC507F8DF8A84B8E61D9EC1C499714EDC3ABAAB14305162243C4AC4DDE3FE9
948BlueStacksMicroInstaller_4.220.0.1109_native.exeC:\Users\admin\AppData\Local\Temp\7zS4B36A2ED\Locales\i18n.ko-KR.txttext
MD5:2E7B42D79F12015C1768DB258BE496E9
SHA256:671D019D6FA2305733B7E88B8ADE6FC78E3A1DA0838386625F5630E11D019204
948BlueStacksMicroInstaller_4.220.0.1109_native.exeC:\Users\admin\AppData\Local\Temp\7zS4B36A2ED\Locales\i18n.pt-BR.txttext
MD5:FCD541D0EEC0834064C2FAF89E3C7AB5
SHA256:8A7F4B7590610009AF18206D228EFBC931601A8598307434E43A22EEC812A597
948BlueStacksMicroInstaller_4.220.0.1109_native.exeC:\Users\admin\AppData\Local\Temp\7zS4B36A2ED\Locales\i18n.de-DE.txttext
MD5:0F90F7E23DA107AA4C0E8A369E78014A
SHA256:505A2B92034519C5359546163953300B2758F779E5B656311BD1DAF0B21553EB
948BlueStacksMicroInstaller_4.220.0.1109_native.exeC:\Users\admin\AppData\Local\Temp\7zS4B36A2ED\Locales\i18n.th-TH.txttext
MD5:72C44B16C9B4F88CB464236B06CE38AB
SHA256:9362122AC28BCD296D4C074B7A00717CB09B2334AC47A407CF3D84E3FF9D2DF3
948BlueStacksMicroInstaller_4.220.0.1109_native.exeC:\Users\admin\AppData\Local\Temp\7zS4B36A2ED\Locales\i18n.ru-RU.txttext
MD5:74FD09534FB92A3B2030F319F9FB9620
SHA256:6B2A994625659F0EAFF5AC3A6A9EDFD36478514ACC95BDE99AB3AE0A664CF360
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4048
BlueStacksInstaller.exe
216.58.207.83:443
cloud.bluestacks.com
Google Inc.
US
whitelisted
1472
BlueStacksInstaller.exe
216.58.207.83:443
cloud.bluestacks.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
cloud.bluestacks.com
  • 216.58.207.83
whitelisted

Threats

No threats detected
No debug info