File name:

BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe

Full analysis: https://app.any.run/tasks/f2743086-b85f-4115-b5f8-15b545f9d865
Verdict: Malicious activity
Analysis date: January 31, 2024, 21:33:29
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

B9AAD0362D8ED8316B0ECC1CEDB7FAFD

SHA1:

BEC1947281D9F39A6BDF33C46FE1514214EC37FE

SHA256:

8614ABE7235F3750A5014E381149C51F0DCE2B58AEA794CFD4AAEF91370ACE08

SSDEEP:

24576:UcVkKS/WtWrnngnnnKnanxNpDcexw6kPEmEi90YAVk8B1MxWl+2w0NNx29sWD9kU:UcB6WErnngnnnKnanzSexoNfv8B1Mk+l

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe (PID: 1504)
      • BlueStacksInstaller.exe (PID: 1028)
      • BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe (PID: 3548)
  • SUSPICIOUS

    • Reads the Internet Settings

      • BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe (PID: 1504)
      • BlueStacksInstaller.exe (PID: 3988)
      • BlueStacksInstaller.exe (PID: 1028)
      • BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe (PID: 3548)
    • Executable content was dropped or overwritten

      • BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe (PID: 1504)
      • BlueStacksInstaller.exe (PID: 1028)
      • BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe (PID: 3548)
    • Reads settings of System Certificates

      • BlueStacksInstaller.exe (PID: 3988)
      • BlueStacksInstaller.exe (PID: 1028)
    • Application launched itself

      • BlueStacksInstaller.exe (PID: 3988)
  • INFO

    • Checks supported languages

      • BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe (PID: 1504)
      • BlueStacksInstaller.exe (PID: 3988)
      • BlueStacksInstaller.exe (PID: 1028)
      • BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe (PID: 3548)
      • BlueStacksInstaller.exe (PID: 3636)
    • Reads the computer name

      • BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe (PID: 1504)
      • BlueStacksInstaller.exe (PID: 3988)
      • BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe (PID: 3548)
      • BlueStacksInstaller.exe (PID: 3636)
      • BlueStacksInstaller.exe (PID: 1028)
    • Create files in a temporary directory

      • BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe (PID: 1504)
      • BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe (PID: 3548)
    • Creates files or folders in the user directory

      • BlueStacksInstaller.exe (PID: 3988)
    • Reads the machine GUID from the registry

      • BlueStacksInstaller.exe (PID: 3988)
      • BlueStacksInstaller.exe (PID: 1028)
      • BlueStacksInstaller.exe (PID: 3636)
    • Reads Environment values

      • BlueStacksInstaller.exe (PID: 3988)
      • BlueStacksInstaller.exe (PID: 1028)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:02:21 17:00:00+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 104448
InitializedDataSize: 372224
UninitializedDataSize: -
EntryPoint: 0x1910c
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 19.0.0.0
ProductVersionNumber: 19.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: BlueStack Systems Inc.
FileDescription: BlueStacks Installer
FileVersion: 4
InternalName: BlueStacks Installer
LegalCopyright: Copyright (c) BlueStack Systems Inc.
OriginalFileName: BlueStacksInstaller.exe
ProductName: BlueStacks Installer
ProductVersion: 4
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
5
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start bluestacksmicroinstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe bluestacksinstaller.exe bluestacksinstaller.exe bluestacksmicroinstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe bluestacksinstaller.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1028"C:\Users\admin\AppData\Local\Temp\7zS0E5D0E56\BlueStacksInstaller.exe" "install" "BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe" "50c0242bf14c27cbe93a0f46c44f14ea" "non_admin" "80e02d0d-4e08-446f-a8f9-8bb04533db0a" "125f7c64-5af9-478e-b1cd-d3387cea8e03"C:\Users\admin\AppData\Local\Temp\7zS0E5D0E56\BlueStacksInstaller.exe
BlueStacksInstaller.exe
User:
admin
Company:
BlueStack Systems, Inc.
Integrity Level:
HIGH
Description:
BlueStacks Installer
Exit code:
0
Version:
4.280.1.1002
Modules
Images
c:\users\admin\appdata\local\temp\7zs0e5d0e56\bluestacksinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1504"C:\Users\admin\AppData\Local\Temp\BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe" C:\Users\admin\AppData\Local\Temp\BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe
explorer.exe
User:
admin
Company:
BlueStack Systems Inc.
Integrity Level:
MEDIUM
Description:
BlueStacks Installer
Exit code:
0
Version:
4.00
Modules
Images
c:\users\admin\appdata\local\temp\bluestacksmicroinstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3548"C:\Users\admin\AppData\Local\BlueStacksSetup\BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe" -versionMachineID=125f7c64-5af9-478e-b1cd-d3387cea8e03 -machineID=80e02d0d-4e08-446f-a8f9-8bb04533db0a -pddir="C:\ProgramData\BlueStacks"C:\Users\admin\AppData\Local\BlueStacksSetup\BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe
BlueStacksInstaller.exe
User:
admin
Company:
BlueStack Systems Inc.
Integrity Level:
HIGH
Description:
BlueStacks Installer
Exit code:
0
Version:
4.00
Modules
Images
c:\users\admin\appdata\local\bluestackssetup\bluestacksmicroinstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3636"C:\Users\admin\AppData\Local\Temp\7zSCDD46D56\BlueStacksInstaller.exe" -versionMachineID=125f7c64-5af9-478e-b1cd-d3387cea8e03 -machineID=80e02d0d-4e08-446f-a8f9-8bb04533db0a -pddir="C:\ProgramData\BlueStacks"C:\Users\admin\AppData\Local\Temp\7zSCDD46D56\BlueStacksInstaller.exeBlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe
User:
admin
Company:
BlueStack Systems, Inc.
Integrity Level:
HIGH
Description:
BlueStacks Installer
Exit code:
4294967295
Version:
4.280.1.1002
Modules
Images
c:\users\admin\appdata\local\temp\7zscdd46d56\bluestacksinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3988"C:\Users\admin\AppData\Local\Temp\7zS0E5D0E56\BlueStacksInstaller.exe" C:\Users\admin\AppData\Local\Temp\7zS0E5D0E56\BlueStacksInstaller.exe
BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exe
User:
admin
Company:
BlueStack Systems, Inc.
Integrity Level:
MEDIUM
Description:
BlueStacks Installer
Exit code:
0
Version:
4.280.1.1002
Modules
Images
c:\users\admin\appdata\local\temp\7zs0e5d0e56\bluestacksinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
10 645
Read events
10 578
Write events
67
Delete events
0

Modification events

(PID) Process:(1504) BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1504) BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1504) BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1504) BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3988) BlueStacksInstaller.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3988) BlueStacksInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3988) BlueStacksInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3988) BlueStacksInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3988) BlueStacksInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1028) BlueStacksInstaller.exeKey:HKEY_CURRENT_USER\Software\BlueStacksInstaller
Operation:writeName:MachineID
Value:
80e02d0d-4e08-446f-a8f9-8bb04533db0a
Executable files
7
Suspicious files
0
Text files
98
Unknown types
0

Dropped files

PID
Process
Filename
Type
1504BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exeC:\Users\admin\AppData\Local\Temp\7zS0E5D0E56\Assets\checked_gray.pngimage
MD5:CE144D2AAB3BF213AF693D4E18F87A59
SHA256:D8E502FAB00B0C6F06BA6ABEDE6922AB3B423FE6F2D2F56941DABC887B229AD3
1504BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exeC:\Users\admin\AppData\Local\Temp\7zS0E5D0E56\Assets\close_red_click.pngimage
MD5:6DB7460B73A6641C7621D0A6203A0A90
SHA256:D5A7E6FC5E92E0B29A4F65625030447F3379B4E3AC4BED051A0646A7932CE0CD
1504BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exeC:\Users\admin\AppData\Local\Temp\7zS0E5D0E56\Assets\custom_click.pngimage
MD5:CED07C9DB242115400E159D9A02BB7B7
SHA256:1318E0F34A551EDAE1E82818FDF7DE5AC627493DB5B24556D919F525052D5B90
1504BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exeC:\Users\admin\AppData\Local\Temp\7zS0E5D0E56\Assets\close_red.pngimage
MD5:93216B2F9D66D423B3E1311C0573332D
SHA256:D0B6D143642D356B40C47459A996131A344CADE6BB86158F1B74693426B09BFB
1504BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exeC:\Users\admin\AppData\Local\Temp\7zS0E5D0E56\Assets\checked_gray_hover.pngimage
MD5:EA22933E94C7AB813B639627F2B38286
SHA256:D7C79677D2EF897FA0AD1EFC90E916C46DA29F571208F78F24505603B7165C20
1504BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exeC:\Users\admin\AppData\Local\Temp\7zS0E5D0E56\Assets\installer_logo.pngimage
MD5:4CC6586C249AE201501C07FE5354B23B
SHA256:06F6630B150CCA4AB3A00B663BFB6B0FE0C53309D434036C5EF16B3FE01304ED
1504BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exeC:\Users\admin\AppData\Local\Temp\7zS0E5D0E56\Assets\exit_close.pngimage
MD5:26EB04B9E0105A7B121EA9C6601BBF2A
SHA256:7AAEF329BA9FA052791D1A09F127551289641EA743BABA171DE55FAA30EC1157
1504BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exeC:\Users\admin\AppData\Local\Temp\7zS0E5D0E56\Assets\custom.pngimage
MD5:03B17F0B1C067826B0FCC6746CCED2CB
SHA256:FBECE8BB5F4DFA55DCFBF41151B10608AF807B9477E99ACF0940954A11E68F7B
1504BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exeC:\Users\admin\AppData\Local\Temp\7zS0E5D0E56\Assets\exit_close_hover.pngimage
MD5:92C2BF222D6AB81FE7A0C072BF31C107
SHA256:BCC053A9A087E077D58114106D29701A34F7851F4052F3157102811355D3E709
1504BlueStacksMicroInstaller_4.280.1.1002_native_50c0242bf14c27cbe93a0f46c44f14ea.exeC:\Users\admin\AppData\Local\Temp\7zS0E5D0E56\Assets\installer_minimize_click.pngimage
MD5:08FC39A69FA17E0F529915919CEA1633
SHA256:2599D6A55A8E12B1F05A6E8982D55559151A25AE3690E6637510B6283622DD95
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
3988
BlueStacksInstaller.exe
34.160.86.181:443
cloud.bluestacks.com
GOOGLE
US
unknown
1028
BlueStacksInstaller.exe
34.160.86.181:443
cloud.bluestacks.com
GOOGLE
US
unknown

DNS requests

Domain
IP
Reputation
cloud.bluestacks.com
  • 34.160.86.181
whitelisted

Threats

No threats detected
No debug info