File name:

BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe

Full analysis: https://app.any.run/tasks/f2743086-b85f-4115-b5f8-15b545f9d865
Verdict: Malicious activity
Analysis date: January 31, 2024, 21:33:29
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

B9AAD0362D8ED8316B0ECC1CEDB7FAFD

SHA1:

BEC1947281D9F39A6BDF33C46FE1514214EC37FE

SHA256:

8614ABE7235F3750A5014E381149C51F0DCE2B58AEA794CFD4AAEF91370ACE08

SSDEEP:

24576:UcVkKS/WtWrnngnnnKnanxNpDcexw6kPEmEi90YAVk8B1MxWl+2w0NNx29sWD9kU:UcB6WErnngnnnKnanzSexoNfv8B1Mk+l

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe (PID: 1504)
      • BlueStacksInstaller.exe (PID: 1028)
      • BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe (PID: 3548)
  • SUSPICIOUS

    • Reads the Internet Settings

      • BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe (PID: 1504)
      • BlueStacksInstaller.exe (PID: 3988)
      • BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe (PID: 3548)
      • BlueStacksInstaller.exe (PID: 1028)
    • Executable content was dropped or overwritten

      • BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe (PID: 1504)
      • BlueStacksInstaller.exe (PID: 1028)
      • BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe (PID: 3548)
    • Reads settings of System Certificates

      • BlueStacksInstaller.exe (PID: 1028)
      • BlueStacksInstaller.exe (PID: 3988)
    • Application launched itself

      • BlueStacksInstaller.exe (PID: 3988)
  • INFO

    • Checks supported languages

      • BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe (PID: 1504)
      • BlueStacksInstaller.exe (PID: 3988)
      • BlueStacksInstaller.exe (PID: 1028)
      • BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe (PID: 3548)
      • BlueStacksInstaller.exe (PID: 3636)
    • Reads the computer name

      • BlueStacksInstaller.exe (PID: 3988)
      • BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe (PID: 1504)
      • BlueStacksInstaller.exe (PID: 1028)
      • BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe (PID: 3548)
      • BlueStacksInstaller.exe (PID: 3636)
    • Create files in a temporary directory

      • BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe (PID: 1504)
      • BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe (PID: 3548)
    • Reads the machine GUID from the registry

      • BlueStacksInstaller.exe (PID: 3988)
      • BlueStacksInstaller.exe (PID: 1028)
      • BlueStacksInstaller.exe (PID: 3636)
    • Creates files or folders in the user directory

      • BlueStacksInstaller.exe (PID: 3988)
    • Reads Environment values

      • BlueStacksInstaller.exe (PID: 3988)
      • BlueStacksInstaller.exe (PID: 1028)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:02:21 17:00:00+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 104448
InitializedDataSize: 372224
UninitializedDataSize: -
EntryPoint: 0x1910c
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 19.0.0.0
ProductVersionNumber: 19.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: BlueStack Systems Inc.
FileDescription: BlueStacks Installer
FileVersion: 4
InternalName: BlueStacks Installer
LegalCopyright: Copyright (c) BlueStack Systems Inc.
OriginalFileName: BlueStacksInstaller.exe
ProductName: BlueStacks Installer
ProductVersion: 4
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
5
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start bluestacksmicroinstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe bluestacksinstaller.exe bluestacksinstaller.exe bluestacksmicroinstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe bluestacksinstaller.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1028"C:\Users\admin\AppData\Local\Temp\7zS0E5D0E56\BlueStacksInstaller.exe" "install" "BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe" "50c0242bf14c27cbe93a0f46c44f14ea" "non_admin" "80e02d0d-4e08-446f-a8f9-8bb04533db0a" "125f7c64-5af9-478e-b1cd-d3387cea8e03"C:\Users\admin\AppData\Local\Temp\7zS0E5D0E56\BlueStacksInstaller.exe
BlueStacksInstaller.exe
User:
admin
Company:
BlueStack Systems, Inc.
Integrity Level:
HIGH
Description:
BlueStacks Installer
Exit code:
0
Version:
4.280.1.1002
Modules
Images
c:\users\admin\appdata\local\temp\7zs0e5d0e56\bluestacksinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1504"C:\Users\admin\AppData\Local\Temp\BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe" C:\Users\admin\AppData\Local\Temp\BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe
explorer.exe
User:
admin
Company:
BlueStack Systems Inc.
Integrity Level:
MEDIUM
Description:
BlueStacks Installer
Exit code:
0
Version:
4.00
Modules
Images
c:\users\admin\appdata\local\temp\bluestacksmicroinstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3548"C:\Users\admin\AppData\Local\BlueStacksSetup\BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe" -versionMachineID=125f7c64-5af9-478e-b1cd-d3387cea8e03 -machineID=80e02d0d-4e08-446f-a8f9-8bb04533db0a -pddir="C:\ProgramData\BlueStacks"C:\Users\admin\AppData\Local\BlueStacksSetup\BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe
BlueStacksInstaller.exe
User:
admin
Company:
BlueStack Systems Inc.
Integrity Level:
HIGH
Description:
BlueStacks Installer
Exit code:
0
Version:
4.00
Modules
Images
c:\users\admin\appdata\local\bluestackssetup\bluestacksmicroinstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3636"C:\Users\admin\AppData\Local\Temp\7zSCDD46D56\BlueStacksInstaller.exe" -versionMachineID=125f7c64-5af9-478e-b1cd-d3387cea8e03 -machineID=80e02d0d-4e08-446f-a8f9-8bb04533db0a -pddir="C:\ProgramData\BlueStacks"C:\Users\admin\AppData\Local\Temp\7zSCDD46D56\BlueStacksInstaller.exeBlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe
User:
admin
Company:
BlueStack Systems, Inc.
Integrity Level:
HIGH
Description:
BlueStacks Installer
Exit code:
4294967295
Version:
4.280.1.1002
Modules
Images
c:\users\admin\appdata\local\temp\7zscdd46d56\bluestacksinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3988"C:\Users\admin\AppData\Local\Temp\7zS0E5D0E56\BlueStacksInstaller.exe" C:\Users\admin\AppData\Local\Temp\7zS0E5D0E56\BlueStacksInstaller.exe
BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe
User:
admin
Company:
BlueStack Systems, Inc.
Integrity Level:
MEDIUM
Description:
BlueStacks Installer
Exit code:
0
Version:
4.280.1.1002
Modules
Images
c:\users\admin\appdata\local\temp\7zs0e5d0e56\bluestacksinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
10 645
Read events
10 578
Write events
67
Delete events
0

Modification events

(PID) Process:(1504) BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1504) BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1504) BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1504) BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3988) BlueStacksInstaller.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3988) BlueStacksInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3988) BlueStacksInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3988) BlueStacksInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3988) BlueStacksInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1028) BlueStacksInstaller.exeKey:HKEY_CURRENT_USER\Software\BlueStacksInstaller
Operation:writeName:MachineID
Value:
80e02d0d-4e08-446f-a8f9-8bb04533db0a
Executable files
7
Suspicious files
0
Text files
98
Unknown types
0

Dropped files

PID
Process
Filename
Type
1504BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exeC:\Users\admin\AppData\Local\Temp\7zS0E5D0E56\Assets\close_red.pngimage
MD5:93216B2F9D66D423B3E1311C0573332D
SHA256:D0B6D143642D356B40C47459A996131A344CADE6BB86158F1B74693426B09BFB
1504BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exeC:\Users\admin\AppData\Local\Temp\7zS0E5D0E56\Assets\custom_hover.pngimage
MD5:F3E05F142E742E25A98D4F5AF3AE0623
SHA256:D588EF0EAA334ED8482F32E5839A7EE0D0B544D5B8D5F7720B8C57010E080424
1504BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exeC:\Users\admin\AppData\Local\Temp\7zS0E5D0E56\Assets\error_icon.pngimage
MD5:DAB2C4538A83422B5DEAE0E0DE9B7A30
SHA256:666AD4FE456216DDC06618967846ED31F81D8DB5BE97DA6531842C0667352B89
1504BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exeC:\Users\admin\AppData\Local\Temp\7zS0E5D0E56\Assets\checked_gray_hover.pngimage
MD5:EA22933E94C7AB813B639627F2B38286
SHA256:D7C79677D2EF897FA0AD1EFC90E916C46DA29F571208F78F24505603B7165C20
1504BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exeC:\Users\admin\AppData\Local\Temp\7zS0E5D0E56\Assets\installer_flash_background.jpgimage
MD5:08D091FAF58DF0EA8218D7E08140BBEB
SHA256:7E5F6998D34D56AECA87F676C12A42C6C4362AE16A753DC567AAE00E253B0817
1504BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exeC:\Users\admin\AppData\Local\Temp\7zS0E5D0E56\Assets\exit_close.pngimage
MD5:26EB04B9E0105A7B121EA9C6601BBF2A
SHA256:7AAEF329BA9FA052791D1A09F127551289641EA743BABA171DE55FAA30EC1157
1504BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exeC:\Users\admin\AppData\Local\Temp\7zS0E5D0E56\Assets\close_red_click.pngimage
MD5:6DB7460B73A6641C7621D0A6203A0A90
SHA256:D5A7E6FC5E92E0B29A4F65625030447F3379B4E3AC4BED051A0646A7932CE0CD
1504BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exeC:\Users\admin\AppData\Local\Temp\7zS0E5D0E56\Assets\exit_close_hover.pngimage
MD5:92C2BF222D6AB81FE7A0C072BF31C107
SHA256:BCC053A9A087E077D58114106D29701A34F7851F4052F3157102811355D3E709
1504BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exeC:\Users\admin\AppData\Local\Temp\7zS0E5D0E56\Assets\installer_minimize_hover.pngimage
MD5:18FB6465B029206477D0222E8DA6FDF9
SHA256:57AAE4BF49DCBB0AD6CFF6263200015C89D7752DC75C2AD918BF846E1CE9646D
1504BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exeC:\Users\admin\AppData\Local\Temp\7zS0E5D0E56\Assets\installer_minimize.pngimage
MD5:38B539A1E4229738E5C196EEDB4EB225
SHA256:A064F417E3C2B8F3121A14BBDED268B2CDF635706880B7006F931DE31476BBC2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
3988
BlueStacksInstaller.exe
34.160.86.181:443
cloud.bluestacks.com
GOOGLE
US
unknown
1028
BlueStacksInstaller.exe
34.160.86.181:443
cloud.bluestacks.com
GOOGLE
US
unknown

DNS requests

Domain
IP
Reputation
cloud.bluestacks.com
  • 34.160.86.181
whitelisted

Threats

No threats detected
No debug info