File name:

raro.exe

Full analysis: https://app.any.run/tasks/5779ac3a-de45-4e5f-a787-8484e98850ac
Verdict: Malicious activity
Analysis date: September 27, 2024, 04:03:17
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
evasion
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

FB058839D5E394D48A86C8900431C540

SHA1:

E5E0CCFE6C4A67300E95F7FC059DF613A29A76DC

SHA256:

79579A7C9F2DCF5F2DB320EEAD74FCF9233987B2BCF856EB1C6892B49B0C49F1

SSDEEP:

49152:dnVQhBuOT8fUiBPJadRJbZsrE90Eh5/ZLjG/IWWBwZfSFgMSPTqbt2v3PY/jW+D+:LeT8fZavxZx90spjCWwUOMYSt6Y7W+wP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • raro.exe (PID: 6348)
      • BSX-Setup-5.21.560.1027_nxt.exe (PID: 4920)
      • raro.exe (PID: 2864)
      • 7zr.exe (PID: 6624)
      • 7zr.exe (PID: 5052)
      • BlueStacksServicesSetup.exe (PID: 6740)
      • 7zr.exe (PID: 4292)
      • BlueStacksInstaller.exe (PID: 1452)
      • BlueStacksServices.exe (PID: 3004)
      • 7zr.exe (PID: 2648)
    • Reads security settings of Internet Explorer

      • raro.exe (PID: 6348)
      • BlueStacksInstaller.exe (PID: 2280)
    • Reads the date of Windows installation

      • BlueStacksInstaller.exe (PID: 2280)
    • Application launched itself

      • BlueStacksInstaller.exe (PID: 2280)
      • BlueStacksServices.exe (PID: 3004)
    • Starts CMD.EXE for commands execution

      • wscript.exe (PID: 4224)
      • BlueStacksServices.exe (PID: 3004)
      • BlueStacksServicesSetup.exe (PID: 6740)
      • HD-LogCollector.exe (PID: 3692)
    • Drops 7-zip archiver for unpacking

      • BSX-Setup-5.21.560.1027_nxt.exe (PID: 4920)
      • raro.exe (PID: 2864)
      • 7zr.exe (PID: 5052)
      • BlueStacksServicesSetup.exe (PID: 6740)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • BSX-Setup-5.21.560.1027_nxt.exe (PID: 4920)
      • BlueStacksServicesSetup.exe (PID: 6740)
    • Process drops legitimate windows executable

      • BSX-Setup-5.21.560.1027_nxt.exe (PID: 4920)
      • 7zr.exe (PID: 4292)
      • raro.exe (PID: 2864)
      • 7zr.exe (PID: 5052)
      • BlueStacksServicesSetup.exe (PID: 6740)
    • The process drops C-runtime libraries

      • BSX-Setup-5.21.560.1027_nxt.exe (PID: 4920)
      • 7zr.exe (PID: 4292)
      • 7zr.exe (PID: 5052)
    • The process executes VB scripts

      • BSX-Setup-5.21.560.1027_nxt.exe (PID: 4920)
    • Drops a system driver (possible attempt to evade defenses)

      • 7zr.exe (PID: 5052)
    • Executing commands from a ".bat" file

      • wscript.exe (PID: 4224)
    • Uses NETSH.EXE to delete a firewall rule or allowed programs

      • cmd.exe (PID: 6468)
      • BlueStacksInstaller.exe (PID: 1452)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • cmd.exe (PID: 6468)
      • BlueStacksInstaller.exe (PID: 1452)
    • Get information on the list of running processes

      • BlueStacksServices.exe (PID: 3004)
      • cmd.exe (PID: 3464)
      • cmd.exe (PID: 5084)
      • BlueStacksServicesSetup.exe (PID: 6740)
      • cmd.exe (PID: 376)
      • cmd.exe (PID: 3356)
      • cmd.exe (PID: 6524)
      • cmd.exe (PID: 1184)
      • cmd.exe (PID: 1964)
      • cmd.exe (PID: 2252)
      • cmd.exe (PID: 788)
      • cmd.exe (PID: 2396)
      • cmd.exe (PID: 6200)
      • cmd.exe (PID: 6032)
      • cmd.exe (PID: 2944)
      • cmd.exe (PID: 1964)
      • cmd.exe (PID: 5112)
      • cmd.exe (PID: 7012)
      • cmd.exe (PID: 740)
      • cmd.exe (PID: 5992)
      • cmd.exe (PID: 4824)
      • cmd.exe (PID: 940)
      • cmd.exe (PID: 2928)
      • cmd.exe (PID: 1448)
      • cmd.exe (PID: 1164)
      • cmd.exe (PID: 6524)
      • cmd.exe (PID: 3876)
      • cmd.exe (PID: 2252)
      • cmd.exe (PID: 6516)
    • Connects to unusual port

      • BlueStacksServices.exe (PID: 3004)
    • Uses SYSTEMINFO.EXE to read the environment

      • HD-LogCollector.exe (PID: 3692)
    • Checks for external IP

      • HD-Player.exe (PID: 6588)
      • HD-Player.exe (PID: 6040)
    • Potential Corporate Privacy Violation

      • HD-Player.exe (PID: 6588)
      • HD-Player.exe (PID: 6040)
    • Lists all scheduled tasks in specific format

      • schtasks.exe (PID: 6796)
    • Uses NSLOOKUP.EXE to check DNS info

      • HD-LogCollector.exe (PID: 3692)
    • Process uses IPCONFIG to discover network configuration

      • HD-LogCollector.exe (PID: 3692)
  • INFO

    • Checks supported languages

      • raro.exe (PID: 6348)
      • BlueStacksInstaller.exe (PID: 2280)
      • HD-CheckCpu.exe (PID: 4328)
      • HD-CheckCpu.exe (PID: 2112)
      • HD-CheckCpu.exe (PID: 2804)
      • BlueStacksInstaller.exe (PID: 2816)
    • Create files in a temporary directory

      • raro.exe (PID: 6348)
    • Reads the computer name

      • raro.exe (PID: 6348)
      • BlueStacksInstaller.exe (PID: 2280)
      • BlueStacksInstaller.exe (PID: 2816)
    • The process uses the downloaded file

      • raro.exe (PID: 6348)
      • BlueStacksInstaller.exe (PID: 2280)
    • Process checks computer location settings

      • raro.exe (PID: 6348)
      • BlueStacksInstaller.exe (PID: 2280)
    • Reads the machine GUID from the registry

      • BlueStacksInstaller.exe (PID: 2280)
      • BlueStacksInstaller.exe (PID: 2816)
    • Creates files or folders in the user directory

      • BlueStacksInstaller.exe (PID: 2280)
    • Disables trace logs

      • BlueStacksInstaller.exe (PID: 2280)
      • BlueStacksInstaller.exe (PID: 2816)
    • Reads Environment values

      • BlueStacksInstaller.exe (PID: 2280)
      • BlueStacksInstaller.exe (PID: 2816)
    • Checks proxy server information

      • BlueStacksInstaller.exe (PID: 2280)
      • BlueStacksInstaller.exe (PID: 2816)
    • Reads the software policy settings

      • BlueStacksInstaller.exe (PID: 2280)
      • BlueStacksInstaller.exe (PID: 2816)
    • Manual execution by a user

      • BlueStacksServicesSetup.exe (PID: 6740)
      • BlueStacksServices.exe (PID: 3004)
      • HD-Player.exe (PID: 6040)
      • BlueStacksHelper.exe (PID: 5160)
      • HD-Player.exe (PID: 6588)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:07:19 13:21:27+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 133632
InitializedDataSize: 224768
UninitializedDataSize: -
EntryPoint: 0x1a5b2
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 19.0.0.0
ProductVersionNumber: 19.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: now.gg, Inc.
FileDescription: BlueStacks Setup
FileVersion: 5
InternalName: BlueStacks Installer
LegalCopyright: Copyright (c) 2010-2021 Bluestacks from Now.gg, Inc.
OriginalFileName: BlueStacksInstaller.exe
ProductName: BlueStacks 5
ProductVersion: 5
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
372
Monitored processes
232
Malicious processes
8
Suspicious processes
4

Behavior graph

Click at the process to see the details
start raro.exe bluestacksinstaller.exe hd-checkcpu.exe no specs conhost.exe no specs bluestacksinstaller.exe hd-checkcpu.exe no specs conhost.exe no specs hd-checkcpu.exe no specs conhost.exe no specs bsx-setup-5.21.560.1027_nxt.exe wscript.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs raro.exe bootstrapper.exe no specs bluestacksinstaller.exe 7zr.exe conhost.exe no specs 7zr.exe conhost.exe no specs hd-forcegpu.exe no specs conhost.exe no specs hd-glcheck.exe no specs conhost.exe no specs hd-glcheck.exe no specs conhost.exe no specs hd-glcheck.exe no specs conhost.exe no specs hd-glcheck.exe no specs conhost.exe no specs hd-glcheck.exe no specs conhost.exe no specs hd-glcheck.exe no specs conhost.exe no specs hd-checkcpu.exe no specs conhost.exe no specs 7zr.exe conhost.exe no specs bluestacksservicessetup.exe cmd.exe no specs conhost.exe no specs tasklist.exe no specs find.exe no specs 7zr.exe conhost.exe no specs bluestacksservices.exe bluestacksservices.exe no specs cscript.exe no specs conhost.exe no specs cscript.exe no specs conhost.exe no specs bluestacksservices.exe cscript.exe no specs conhost.exe no specs cscript.exe no specs conhost.exe no specs cscript.exe no specs conhost.exe no specs cscript.exe no specs conhost.exe no specs bluestacksservices.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs tasklist.exe no specs tasklist.exe no specs cscript.exe no specs cscript.exe no specs cscript.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs tasklist.exe no specs tasklist.exe no specs cscript.exe no specs cscript.exe no specs conhost.exe no specs conhost.exe no specs 7zr.exe no specs conhost.exe no specs 7zr.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs tasklist.exe no specs tasklist.exe no specs cscript.exe no specs conhost.exe no specs cscript.exe no specs conhost.exe no specs cscript.exe no specs conhost.exe no specs cscript.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs tasklist.exe no specs tasklist.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs tasklist.exe no specs tasklist.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs tasklist.exe no specs conhost.exe no specs tasklist.exe no specs hd-glcheck.exe no specs conhost.exe no specs hd-glcheck.exe no specs conhost.exe no specs hd-glcheck.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs hd-checkcpu.exe no specs conhost.exe no specs hd-comregistrar.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs tasklist.exe no specs tasklist.exe no specs hd-comregistrar.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs tasklist.exe no specs tasklist.exe no specs bstksvc.exe no specs bstkvmmgr.exe no specs conhost.exe no specs bstksvc.exe no specs bluestackshelper.exe hd-player.exe schtasks.exe no specs conhost.exe no specs bstksvc.exe no specs ffmpeg.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs tasklist.exe no specs tasklist.exe no specs ffmpeg.exe no specs conhost.exe no specs ffmpeg.exe no specs conhost.exe no specs hd-logcollector.exe reg.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs hd-glcheck.exe no specs conhost.exe no specs hd-hvutl.exe no specs systeminfo.exe no specs conhost.exe no specs hd-player.exe bstksvc.exe no specs ffmpeg.exe no specs conhost.exe no specs ffmpeg.exe no specs conhost.exe no specs ffmpeg.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs tasklist.exe no specs tasklist.exe no specs tiworker.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs tasklist.exe no specs tasklist.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs tasklist.exe no specs tasklist.exe no specs reg.exe no specs conhost.exe no specs nslookup.exe conhost.exe no specs netstat.exe no specs conhost.exe no specs net.exe no specs conhost.exe no specs net1.exe no specs ipconfig.exe no specs conhost.exe no specs 7zr.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs tasklist.exe no specs tasklist.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
376cmd /c tasklist /FI "USERNAME eq %USERNAME%" /FI "IMAGENAME eq BlueStacksServices.exe" | find "BlueStacksServices.exe"C:\Windows\SysWOW64\cmd.exeBlueStacksServicesSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
376"C:\Users\admin\AppData\Local\Temp\7zS03B663A8\7zr.exe" x "C:\Users\admin\AppData\Local\Temp\7zS03B663A8\PD.zip" -o"C:\ProgramData\BlueStacks_nxt" -aoaC:\Users\admin\AppData\Local\Temp\7zS03B663A8\7zr.exeBlueStacksInstaller.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Standalone Console
Exit code:
0
Version:
23.01
Modules
Images
c:\users\admin\appdata\local\temp\7zs03b663a8\7zr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
376"C:\Program Files\BlueStacks_nxt\BstkSVC.exe" -EmbeddingC:\Program Files\BlueStacks_nxt\BstkSVC.exesvchost.exe
User:
admin
Company:
Bluestack System Inc.
Integrity Level:
MEDIUM
Description:
Bluestacks Server Interface
Exit code:
0
Version:
6.1.36.156792
Modules
Images
c:\program files\bluestacks_nxt\bstksvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\psapi.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
740cscript.exe //Nologo C:\Users\admin\AppData\Local\Programs\bluestacks-services\resources\regedit\vbs\regList.wsf A "HKCU\SOFTWARE\BlueStacks X"C:\Windows\System32\cscript.exeBlueStacksServices.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Console Based Script Host
Exit code:
0
Version:
5.812.10240.16384
Modules
Images
c:\windows\system32\cscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
740C:\WINDOWS\system32\cmd.exe /d /s /c "tasklist /FI "IMAGENAME eq HD-Player.exe""C:\Windows\System32\cmd.exeBlueStacksServices.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
740"netstat" -aonC:\Windows\System32\NETSTAT.EXEHD-LogCollector.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
TCP/IP Netstat Command
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\netstat.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
788"C:\Users\admin\AppData\Local\Temp\7zS03B663A8\HD-GLCheck.exe" 4 2C:\Users\admin\AppData\Local\Temp\7zS03B663A8\HD-GLCheck.exeBlueStacksInstaller.exe
User:
admin
Company:
BlueStack Systems
Integrity Level:
HIGH
Description:
BlueStacks GLCheck Utility
Exit code:
0
Version:
5.21.560.1027
Modules
Images
c:\users\admin\appdata\local\temp\7zs03b663a8\hd-glcheck.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\opengl32.dll
788C:\WINDOWS\system32\cmd.exe /d /s /c "tasklist /FI "IMAGENAME eq HD-Player.exe""C:\Windows\System32\cmd.exeBlueStacksServices.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
840cscript.exe //Nologo C:\Users\admin\AppData\Local\Programs\bluestacks-services\resources\regedit\vbs\regList.wsf A HKCU\SOFTWARE\BlueStacksServicesC:\Windows\System32\cscript.exeBlueStacksServices.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Console Based Script Host
Exit code:
0
Version:
5.812.10240.16384
Modules
Images
c:\windows\system32\cscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
864tasklist /FI "IMAGENAME eq BlueStacks X.exe"C:\Windows\System32\tasklist.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
165 234
Read events
165 067
Write events
144
Delete events
23

Modification events

(PID) Process:(2280) BlueStacksInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BlueStacksInstaller_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2280) BlueStacksInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BlueStacksInstaller_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(2280) BlueStacksInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BlueStacksInstaller_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(2280) BlueStacksInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BlueStacksInstaller_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(2280) BlueStacksInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BlueStacksInstaller_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(2280) BlueStacksInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BlueStacksInstaller_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(2280) BlueStacksInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BlueStacksInstaller_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(2280) BlueStacksInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BlueStacksInstaller_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2280) BlueStacksInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BlueStacksInstaller_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(2280) BlueStacksInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BlueStacksInstaller_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
568
Suspicious files
516
Text files
683
Unknown types
0

Dropped files

PID
Process
Filename
Type
6348raro.exeC:\Users\admin\AppData\Local\Temp\7zSCC8AD6C5\Assets\close_red_hover.pngimage
MD5:5CEAB43AA527BC146F9453A1586DDF03
SHA256:7C625AE4668CC03E37E4FFC478B87EACE06B49B77E71E3209F431C23D98ACDD0
6348raro.exeC:\Users\admin\AppData\Local\Temp\7zSCC8AD6C5\Assets\change_click.pngimage
MD5:57092634754FC26E5515E3ED5CA7D461
SHA256:8E5847487DA148EBB3EA029CC92165AFD215CDC08F7122271E13EB37F94E6DC1
6348raro.exeC:\Users\admin\AppData\Local\Temp\7zSCC8AD6C5\Assets\checked_gray.pngimage
MD5:CE144D2AAB3BF213AF693D4E18F87A59
SHA256:D8E502FAB00B0C6F06BA6ABEDE6922AB3B423FE6F2D2F56941DABC887B229AD3
6348raro.exeC:\Users\admin\AppData\Local\Temp\7zSCC8AD6C5\Assets\backicon.pngimage
MD5:7FF5DC8270B5FA7EF6C4A1420BD67A7F
SHA256:FA64884054171515E97B78AAA1AAD1EC5BAA9D1DAF9C682E0B3FB4A41A9CB1C1
6348raro.exeC:\Users\admin\AppData\Local\Temp\7zSCC8AD6C5\Assets\close_red_click.pngimage
MD5:6DB7460B73A6641C7621D0A6203A0A90
SHA256:D5A7E6FC5E92E0B29A4F65625030447F3379B4E3AC4BED051A0646A7932CE0CD
6348raro.exeC:\Users\admin\AppData\Local\Temp\7zSCC8AD6C5\Assets\error_icon_72.pngimage
MD5:4AAF83D2B3FD56AD806708E60474DF39
SHA256:84E59D14D9433E6C3D92DAEB8C443063B5E3BE6C0B297F0403DBDE473A05CB3F
6348raro.exeC:\Users\admin\AppData\Local\Temp\7zSCC8AD6C5\Assets\checked_gray_hover.pngimage
MD5:EA22933E94C7AB813B639627F2B38286
SHA256:D7C79677D2EF897FA0AD1EFC90E916C46DA29F571208F78F24505603B7165C20
6348raro.exeC:\Users\admin\AppData\Local\Temp\7zSCC8AD6C5\Assets\custom_click.pngimage
MD5:CED07C9DB242115400E159D9A02BB7B7
SHA256:1318E0F34A551EDAE1E82818FDF7DE5AC627493DB5B24556D919F525052D5B90
6348raro.exeC:\Users\admin\AppData\Local\Temp\7zSCC8AD6C5\Assets\change_hover.pngimage
MD5:57092634754FC26E5515E3ED5CA7D461
SHA256:8E5847487DA148EBB3EA029CC92165AFD215CDC08F7122271E13EB37F94E6DC1
6348raro.exeC:\Users\admin\AppData\Local\Temp\7zSCC8AD6C5\Assets\change.pngimage
MD5:57092634754FC26E5515E3ED5CA7D461
SHA256:8E5847487DA148EBB3EA029CC92165AFD215CDC08F7122271E13EB37F94E6DC1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
104
DNS requests
44
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2120
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
888
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
888
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6572
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2968
svchost.exe
GET
200
2.16.164.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
unknown
whitelisted
2968
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicWinProPCA2011_2011-10-19.crl%20
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6588
HD-Player.exe
GET
200
142.250.185.195:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
6588
HD-Player.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
unknown
whitelisted
6588
HD-Player.exe
GET
200
142.250.185.195:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
3136
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2460
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
4324
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
2280
BlueStacksInstaller.exe
34.160.86.181:443
cloud.bluestacks.com
GOOGLE
US
whitelisted
2816
BlueStacksInstaller.exe
34.160.86.181:443
cloud.bluestacks.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 95.101.149.131
whitelisted
google.com
  • 172.217.16.206
whitelisted
cloud.bluestacks.com
  • 34.160.86.181
whitelisted
login.live.com
  • 20.190.159.75
  • 40.126.31.69
  • 40.126.31.67
  • 20.190.159.4
  • 20.190.159.68
  • 20.190.159.71
  • 20.190.159.0
  • 40.126.31.71
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 184.30.17.189
whitelisted
ak-build.bluestacks.com
  • 23.48.23.65
  • 23.48.23.5
whitelisted
slscr.update.microsoft.com
  • 52.165.165.26
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted

Threats

PID
Process
Class
Message
2256
svchost.exe
Misc activity
ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup
6588
HD-Player.exe
Misc activity
ET INFO External IP Address Lookup Domain (ipify .org) in TLS SNI
6040
HD-Player.exe
Misc activity
ET INFO External IP Address Lookup Domain (ipify .org) in TLS SNI
4 ETPRO signatures available at the full report
Process
Message
BSX-Setup-5.21.560.1027_nxt.exe
DirText
BSX-Setup-5.21.560.1027_nxt.exe
BtnOneClick
BSX-Setup-5.21.560.1027_nxt.exe
BtnInstallFinished
BSX-Setup-5.21.560.1027_nxt.exe
C:\Program Files (x86)
BSX-Setup-5.21.560.1027_nxt.exe
closebtn
BSX-Setup-5.21.560.1027_nxt.exe
CustomInstall
BSX-Setup-5.21.560.1027_nxt.exe
btnSelectDir
BSX-Setup-5.21.560.1027_nxt.exe
C:\Program Files (x86)
BSX-Setup-5.21.560.1027_nxt.exe
showInstallPage
BSX-Setup-5.21.560.1027_nxt.exe
0%