URL:

https://www.bluestacks.com/download.html?utm_campaign=download-page-en

Full analysis: https://app.any.run/tasks/732dd885-e050-489b-983d-9e960c7b5384
Verdict: Malicious activity
Analysis date: November 17, 2024, 00:56:08
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
evasion
Indicators:
MD5:

8D26236B1273A1C9C1A0698706B7DE03

SHA1:

C96A14E9D97AAFB491FEA12F20B3F5DD7C282072

SHA256:

C7F5F79AC89B83D29E7B6D94D14F71A28878E26247A7331D07CABB3C582550F8

SSDEEP:

3:N8DSLp8iZq3BKKo18m1VECY:2OL9tKo18m0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • BlueStacksServices.exe (PID: 7596)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • BlueStacks10Installer_10.41.610.1001_native_68ff33630d466cfef1db36b6c4155aaf_MDs1LDM7MTUsMTsxNSw0OzE1LA==.exe (PID: 5080)
      • BSX-Setup-5.21.610.1003_nxt.exe (PID: 3740)
      • BlueStacksInstaller.exe (PID: 6960)
      • BlueStacks10Installer_10.41.610.1001_native_68ff33630d466cfef1db36b6c4155aaf_MDs1LDM7MTUsMTsxNSw0OzE1LA==.exe (PID: 2224)
      • Bootstrapper.exe (PID: 2816)
      • BlueStacksInstaller.exe (PID: 7100)
      • BlueStacksServicesSetup.exe (PID: 7512)
    • Executable content was dropped or overwritten

      • BlueStacks10Installer_10.41.610.1001_native_68ff33630d466cfef1db36b6c4155aaf_MDs1LDM7MTUsMTsxNSw0OzE1LA==.exe (PID: 5080)
      • BSX-Setup-5.21.610.1003_nxt.exe (PID: 3740)
      • BlueStacks10Installer_10.41.610.1001_native_68ff33630d466cfef1db36b6c4155aaf_MDs1LDM7MTUsMTsxNSw0OzE1LA==.exe (PID: 2224)
      • 7zr.exe (PID: 5652)
      • BlueStacksServicesSetup.exe (PID: 7512)
      • 7zr.exe (PID: 7360)
      • BlueStacksInstaller.exe (PID: 7928)
      • 7zr.exe (PID: 7788)
      • BlueStacksServices.exe (PID: 7596)
      • 7zr.exe (PID: 6468)
      • 7z.exe (PID: 7224)
    • Application launched itself

      • BlueStacksInstaller.exe (PID: 7100)
      • BlueStacksServices.exe (PID: 7596)
    • Reads the date of Windows installation

      • BlueStacksInstaller.exe (PID: 7100)
      • BlueStacksInstaller.exe (PID: 6960)
      • Bootstrapper.exe (PID: 2816)
    • Drops 7-zip archiver for unpacking

      • BSX-Setup-5.21.610.1003_nxt.exe (PID: 3740)
      • BlueStacks10Installer_10.41.610.1001_native_68ff33630d466cfef1db36b6c4155aaf_MDs1LDM7MTUsMTsxNSw0OzE1LA==.exe (PID: 2224)
      • 7zr.exe (PID: 7360)
      • BlueStacksServicesSetup.exe (PID: 7512)
    • The process creates files with name similar to system file names

      • BSX-Setup-5.21.610.1003_nxt.exe (PID: 3740)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • BSX-Setup-5.21.610.1003_nxt.exe (PID: 3740)
      • BlueStacksServicesSetup.exe (PID: 7512)
    • The process executes VB scripts

      • BSX-Setup-5.21.610.1003_nxt.exe (PID: 3740)
    • Process drops legitimate windows executable

      • BSX-Setup-5.21.610.1003_nxt.exe (PID: 3740)
      • BlueStacks10Installer_10.41.610.1001_native_68ff33630d466cfef1db36b6c4155aaf_MDs1LDM7MTUsMTsxNSw0OzE1LA==.exe (PID: 2224)
      • 7zr.exe (PID: 5652)
      • 7zr.exe (PID: 7360)
      • BlueStacksServicesSetup.exe (PID: 7512)
      • BlueStacks X.exe (PID: 8144)
      • 7z.exe (PID: 7224)
    • The process drops C-runtime libraries

      • BSX-Setup-5.21.610.1003_nxt.exe (PID: 3740)
      • 7zr.exe (PID: 5652)
      • 7zr.exe (PID: 7360)
      • BlueStacks X.exe (PID: 8144)
      • 7z.exe (PID: 7224)
    • Creates a software uninstall entry

      • BlueStacksInstaller.exe (PID: 6960)
      • BlueStacksServicesSetup.exe (PID: 7512)
      • BlueStacksInstaller.exe (PID: 7928)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 7556)
    • Starts CMD.EXE for commands execution

      • wscript.exe (PID: 7556)
      • BlueStacksServicesSetup.exe (PID: 7512)
      • BlueStacksServices.exe (PID: 7596)
      • HD-LogCollector.exe (PID: 6660)
    • Executing commands from a ".bat" file

      • wscript.exe (PID: 7556)
    • Searches for installed software

      • BlueStacksInstaller.exe (PID: 6960)
      • BlueStacksInstaller.exe (PID: 7928)
    • Uses NETSH.EXE to delete a firewall rule or allowed programs

      • cmd.exe (PID: 6280)
      • BlueStacksInstaller.exe (PID: 7928)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • cmd.exe (PID: 6280)
      • BlueStacksInstaller.exe (PID: 7928)
    • Drops a system driver (possible attempt to evade defenses)

      • 7zr.exe (PID: 7360)
    • Get information on the list of running processes

      • BlueStacksServicesSetup.exe (PID: 7512)
      • cmd.exe (PID: 7324)
      • cmd.exe (PID: 7344)
      • BlueStacksServices.exe (PID: 7596)
      • cmd.exe (PID: 7032)
      • cmd.exe (PID: 4012)
      • cmd.exe (PID: 2632)
      • cmd.exe (PID: 7604)
      • cmd.exe (PID: 6276)
      • cmd.exe (PID: 7376)
      • cmd.exe (PID: 4032)
      • cmd.exe (PID: 1880)
      • cmd.exe (PID: 7968)
      • cmd.exe (PID: 7688)
      • cmd.exe (PID: 6556)
      • cmd.exe (PID: 7504)
      • cmd.exe (PID: 7280)
      • cmd.exe (PID: 6228)
      • cmd.exe (PID: 6456)
      • cmd.exe (PID: 6980)
      • cmd.exe (PID: 6240)
      • cmd.exe (PID: 7348)
      • cmd.exe (PID: 1552)
      • cmd.exe (PID: 7536)
      • cmd.exe (PID: 7492)
      • cmd.exe (PID: 1748)
      • cmd.exe (PID: 6300)
    • Reads data from a binary Stream object (SCRIPT)

      • cscript.exe (PID: 8120)
      • cscript.exe (PID: 6660)
      • cscript.exe (PID: 7688)
      • cscript.exe (PID: 540)
      • cscript.exe (PID: 7656)
      • cscript.exe (PID: 1432)
      • cscript.exe (PID: 1748)
      • cscript.exe (PID: 2124)
      • cscript.exe (PID: 700)
      • cscript.exe (PID: 7848)
      • cscript.exe (PID: 916)
      • cscript.exe (PID: 6380)
      • cscript.exe (PID: 2620)
      • cscript.exe (PID: 3676)
    • Gets full path of the running script (SCRIPT)

      • cscript.exe (PID: 8120)
      • cscript.exe (PID: 6660)
      • cscript.exe (PID: 7688)
      • cscript.exe (PID: 7656)
      • cscript.exe (PID: 540)
      • cscript.exe (PID: 1432)
      • cscript.exe (PID: 2124)
      • cscript.exe (PID: 1748)
      • cscript.exe (PID: 700)
      • cscript.exe (PID: 7848)
      • cscript.exe (PID: 6380)
      • cscript.exe (PID: 916)
      • cscript.exe (PID: 2620)
      • cscript.exe (PID: 3676)
    • Creates FileSystem object to access computer's file system (SCRIPT)

      • cscript.exe (PID: 8120)
      • cscript.exe (PID: 6660)
      • cscript.exe (PID: 7688)
      • cscript.exe (PID: 7656)
      • cscript.exe (PID: 540)
      • cscript.exe (PID: 1748)
      • cscript.exe (PID: 1432)
      • cscript.exe (PID: 2124)
      • cscript.exe (PID: 700)
      • cscript.exe (PID: 7848)
      • cscript.exe (PID: 916)
      • cscript.exe (PID: 6380)
      • cscript.exe (PID: 3676)
      • cscript.exe (PID: 2620)
    • Writes binary data to a Stream object (SCRIPT)

      • cscript.exe (PID: 8120)
      • cscript.exe (PID: 6660)
      • cscript.exe (PID: 540)
      • cscript.exe (PID: 2124)
      • cscript.exe (PID: 1432)
      • cscript.exe (PID: 700)
      • cscript.exe (PID: 7848)
      • cscript.exe (PID: 1748)
      • cscript.exe (PID: 2620)
      • cscript.exe (PID: 916)
      • cscript.exe (PID: 6380)
      • cscript.exe (PID: 3676)
    • Connects to unusual port

      • BlueStacksServices.exe (PID: 7596)
    • Creates/Modifies COM task schedule object

      • HD-ComRegistrar.exe (PID: 5640)
    • Lists all scheduled tasks in specific format

      • schtasks.exe (PID: 1732)
    • Checks for external IP

      • HD-Player.exe (PID: 6696)
    • Potential Corporate Privacy Violation

      • HD-Player.exe (PID: 6696)
    • Uses SYSTEMINFO.EXE to read the environment

      • HD-LogCollector.exe (PID: 6660)
    • Uses NSLOOKUP.EXE to check DNS info

      • HD-LogCollector.exe (PID: 6660)
    • Process uses IPCONFIG to discover network configuration

      • HD-LogCollector.exe (PID: 6660)
  • INFO

    • Executable content was dropped or overwritten

      • firefox.exe (PID: 4868)
    • Application launched itself

      • firefox.exe (PID: 5892)
      • firefox.exe (PID: 4868)
    • The process uses the downloaded file

      • firefox.exe (PID: 4868)
      • BlueStacks10Installer_10.41.610.1001_native_68ff33630d466cfef1db36b6c4155aaf_MDs1LDM7MTUsMTsxNSw0OzE1LA==.exe (PID: 5080)
      • BlueStacksInstaller.exe (PID: 7100)
    • Checks supported languages

      • BlueStacks10Installer_10.41.610.1001_native_68ff33630d466cfef1db36b6c4155aaf_MDs1LDM7MTUsMTsxNSw0OzE1LA==.exe (PID: 5080)
      • BlueStacksInstaller.exe (PID: 7100)
      • HD-CheckCpu.exe (PID: 7044)
      • HD-CheckCpu.exe (PID: 7648)
      • BSX-Setup-5.21.610.1003_nxt.exe (PID: 3740)
      • BlueStacksInstaller.exe (PID: 6960)
      • HD-CheckCpu.exe (PID: 7992)
      • BlueStacks10Installer_10.41.610.1001_native_68ff33630d466cfef1db36b6c4155aaf_MDs1LDM7MTUsMTsxNSw0OzE1LA==.exe (PID: 2224)
      • Bootstrapper.exe (PID: 2816)
      • BlueStacksInstaller.exe (PID: 7928)
      • 7zr.exe (PID: 5652)
      • 7zr.exe (PID: 6468)
      • HD-ForceGPU.exe (PID: 6236)
      • HD-GLCheck.exe (PID: 1336)
      • HD-GLCheck.exe (PID: 8044)
      • HD-GLCheck.exe (PID: 6244)
      • HD-CheckCpu.exe (PID: 3024)
      • 7zr.exe (PID: 7360)
      • HD-GLCheck.exe (PID: 512)
      • HD-GLCheck.exe (PID: 7844)
      • BlueStacksServicesSetup.exe (PID: 7512)
      • 7zr.exe (PID: 7788)
      • BlueStacksServices.exe (PID: 7596)
      • BlueStacksServices.exe (PID: 5036)
      • 7zr.exe (PID: 7000)
      • 7zr.exe (PID: 6424)
      • BlueStacksServices.exe (PID: 6264)
      • HD-GLCheck.exe (PID: 7380)
      • BlueStacksServices.exe (PID: 7984)
      • HD-GLCheck.exe (PID: 6532)
      • HD-GLCheck.exe (PID: 7940)
      • HD-CheckCpu.exe (PID: 7348)
      • HD-ComRegistrar.exe (PID: 1432)
      • HD-ComRegistrar.exe (PID: 5640)
      • HD-GLCheck.exe (PID: 1748)
      • BstkSVC.exe (PID: 3832)
      • BstkVMMgr.exe (PID: 7812)
      • BlueStacksHelper.exe (PID: 2236)
      • BstkSVC.exe (PID: 6344)
      • BstkSVC.exe (PID: 7880)
      • ffmpeg.exe (PID: 6268)
      • ffmpeg.exe (PID: 7492)
      • ffmpeg.exe (PID: 1252)
      • ffmpeg.exe (PID: 3904)
      • HD-Player.exe (PID: 6696)
    • Reads the computer name

      • BlueStacks10Installer_10.41.610.1001_native_68ff33630d466cfef1db36b6c4155aaf_MDs1LDM7MTUsMTsxNSw0OzE1LA==.exe (PID: 5080)
      • BlueStacksInstaller.exe (PID: 7100)
      • BlueStacksInstaller.exe (PID: 6960)
      • BSX-Setup-5.21.610.1003_nxt.exe (PID: 3740)
      • BlueStacks10Installer_10.41.610.1001_native_68ff33630d466cfef1db36b6c4155aaf_MDs1LDM7MTUsMTsxNSw0OzE1LA==.exe (PID: 2224)
      • Bootstrapper.exe (PID: 2816)
      • BlueStacksInstaller.exe (PID: 7928)
      • 7zr.exe (PID: 5652)
      • 7zr.exe (PID: 6468)
      • HD-GLCheck.exe (PID: 7380)
      • HD-GLCheck.exe (PID: 6244)
      • HD-GLCheck.exe (PID: 1336)
      • HD-GLCheck.exe (PID: 8044)
      • 7zr.exe (PID: 7360)
      • HD-GLCheck.exe (PID: 512)
      • HD-GLCheck.exe (PID: 7844)
      • BlueStacksServicesSetup.exe (PID: 7512)
      • 7zr.exe (PID: 7788)
      • BlueStacksServices.exe (PID: 6264)
      • 7zr.exe (PID: 6424)
      • BlueStacksServices.exe (PID: 5036)
      • 7zr.exe (PID: 7000)
      • BlueStacksServices.exe (PID: 7596)
      • HD-GLCheck.exe (PID: 6532)
      • HD-ComRegistrar.exe (PID: 1432)
      • HD-GLCheck.exe (PID: 7940)
      • HD-GLCheck.exe (PID: 1748)
      • HD-ComRegistrar.exe (PID: 5640)
      • BstkVMMgr.exe (PID: 7812)
      • BstkSVC.exe (PID: 6344)
      • BstkSVC.exe (PID: 3832)
      • BlueStacksHelper.exe (PID: 2236)
      • HD-Player.exe (PID: 6696)
      • BstkSVC.exe (PID: 7880)
      • ffmpeg.exe (PID: 7492)
      • ffmpeg.exe (PID: 1252)
    • Create files in a temporary directory

      • BlueStacks10Installer_10.41.610.1001_native_68ff33630d466cfef1db36b6c4155aaf_MDs1LDM7MTUsMTsxNSw0OzE1LA==.exe (PID: 5080)
      • BSX-Setup-5.21.610.1003_nxt.exe (PID: 3740)
    • Process checks computer location settings

      • BlueStacks10Installer_10.41.610.1001_native_68ff33630d466cfef1db36b6c4155aaf_MDs1LDM7MTUsMTsxNSw0OzE1LA==.exe (PID: 5080)
      • BlueStacksInstaller.exe (PID: 7100)
      • BSX-Setup-5.21.610.1003_nxt.exe (PID: 3740)
      • BlueStacksInstaller.exe (PID: 6960)
      • Bootstrapper.exe (PID: 2816)
      • BlueStacks10Installer_10.41.610.1001_native_68ff33630d466cfef1db36b6c4155aaf_MDs1LDM7MTUsMTsxNSw0OzE1LA==.exe (PID: 2224)
      • BlueStacksServices.exe (PID: 7984)
      • BlueStacksServices.exe (PID: 7596)
      • HD-Player.exe (PID: 6696)
    • Creates files or folders in the user directory

      • BlueStacksInstaller.exe (PID: 7100)
      • BlueStacksInstaller.exe (PID: 6960)
    • Disables trace logs

      • BlueStacksInstaller.exe (PID: 7100)
      • BlueStacksInstaller.exe (PID: 6960)
      • BlueStacksInstaller.exe (PID: 7928)
      • BlueStacksHelper.exe (PID: 2236)
    • Reads the machine GUID from the registry

      • BlueStacksInstaller.exe (PID: 7100)
      • BlueStacksInstaller.exe (PID: 6960)
      • BlueStacksInstaller.exe (PID: 7928)
      • BlueStacksServices.exe (PID: 7596)
      • BlueStacksHelper.exe (PID: 2236)
      • HD-Player.exe (PID: 6696)
    • Reads Environment values

      • BlueStacksInstaller.exe (PID: 7100)
      • BlueStacksInstaller.exe (PID: 6960)
      • BSX-Setup-5.21.610.1003_nxt.exe (PID: 3740)
      • BlueStacksInstaller.exe (PID: 7928)
      • BlueStacksServices.exe (PID: 7596)
      • BlueStacksHelper.exe (PID: 2236)
      • HD-Player.exe (PID: 6696)
    • Checks proxy server information

      • BlueStacksInstaller.exe (PID: 7100)
      • BlueStacksInstaller.exe (PID: 6960)
      • slui.exe (PID: 6888)
      • BlueStacksInstaller.exe (PID: 7928)
      • BlueStacksServices.exe (PID: 7596)
      • BlueStacksHelper.exe (PID: 2236)
      • HD-Player.exe (PID: 6696)
    • Reads the software policy settings

      • BlueStacksInstaller.exe (PID: 7100)
      • BlueStacksInstaller.exe (PID: 6960)
      • slui.exe (PID: 4904)
      • slui.exe (PID: 6888)
      • BlueStacksInstaller.exe (PID: 7928)
      • HD-Player.exe (PID: 6696)
      • BlueStacksHelper.exe (PID: 2236)
    • Creates files in the program directory

      • BlueStacksInstaller.exe (PID: 6960)
      • BSX-Setup-5.21.610.1003_nxt.exe (PID: 3740)
    • Reads product name

      • BSX-Setup-5.21.610.1003_nxt.exe (PID: 3740)
      • BlueStacksServices.exe (PID: 7596)
    • Sends debugging messages

      • BSX-Setup-5.21.610.1003_nxt.exe (PID: 3740)
      • HD-Player.exe (PID: 6696)
      • BlueStacksWeb.exe (PID: 3844)
      • BlueStacks X.exe (PID: 8144)
    • Manual execution by a user

      • BlueStacksServicesSetup.exe (PID: 7512)
      • BlueStacksServices.exe (PID: 7596)
      • BlueStacksHelper.exe (PID: 2236)
      • HD-Player.exe (PID: 6696)
      • BlueStacks X.exe (PID: 8144)
    • Reads security settings of Internet Explorer

      • cscript.exe (PID: 8120)
      • cscript.exe (PID: 6660)
      • cscript.exe (PID: 7688)
      • cscript.exe (PID: 7656)
      • cscript.exe (PID: 540)
      • cscript.exe (PID: 1748)
      • cscript.exe (PID: 1432)
      • cscript.exe (PID: 2124)
      • cscript.exe (PID: 7848)
      • cscript.exe (PID: 700)
      • cscript.exe (PID: 916)
      • cscript.exe (PID: 6380)
      • cscript.exe (PID: 3676)
      • cscript.exe (PID: 2620)
    • Reads CPU info

      • BlueStacksInstaller.exe (PID: 7928)
      • HD-Player.exe (PID: 6696)
    • Reads mouse settings

      • HD-Player.exe (PID: 6696)
    • Reads the time zone

      • HD-Player.exe (PID: 6696)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
384
Monitored processes
239
Malicious processes
30
Suspicious processes
3

Behavior graph

Click at the process to see the details
start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs bluestacks10installer_10.41.610.1001_native_68ff33630d466cfef1db36b6c4155aaf_mds1ldm7mtusmtsxnsw0oze1la==.exe bluestacksinstaller.exe hd-checkcpu.exe no specs conhost.exe no specs bluestacksinstaller.exe hd-checkcpu.exe no specs conhost.exe no specs hd-checkcpu.exe no specs conhost.exe no specs sppextcomobj.exe no specs slui.exe bsx-setup-5.21.610.1003_nxt.exe wscript.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs slui.exe bluestacks10installer_10.41.610.1001_native_68ff33630d466cfef1db36b6c4155aaf_mds1ldm7mtusmtsxnsw0oze1la==.exe bootstrapper.exe no specs bluestacksinstaller.exe 7zr.exe conhost.exe no specs 7zr.exe conhost.exe no specs hd-forcegpu.exe no specs conhost.exe no specs hd-glcheck.exe no specs conhost.exe no specs hd-glcheck.exe no specs conhost.exe no specs hd-glcheck.exe no specs conhost.exe no specs hd-glcheck.exe no specs conhost.exe no specs hd-glcheck.exe no specs conhost.exe no specs hd-glcheck.exe no specs conhost.exe no specs hd-checkcpu.exe no specs conhost.exe no specs 7zr.exe conhost.exe no specs bluestacksservicessetup.exe cmd.exe no specs conhost.exe no specs tasklist.exe no specs find.exe no specs 7zr.exe conhost.exe no specs bluestacksservices.exe bluestacksservices.exe no specs cscript.exe no specs conhost.exe no specs cscript.exe no specs conhost.exe no specs bluestacksservices.exe 7zr.exe no specs conhost.exe no specs cscript.exe no specs conhost.exe no specs 7zr.exe no specs conhost.exe no specs cscript.exe no specs conhost.exe no specs cscript.exe no specs conhost.exe no specs cscript.exe no specs conhost.exe no specs bluestacksservices.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs cscript.exe no specs cscript.exe no specs tasklist.exe no specs tasklist.exe no specs cscript.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cscript.exe no specs cscript.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs tasklist.exe no specs tasklist.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs tasklist.exe no specs tasklist.exe no specs cscript.exe no specs conhost.exe no specs cscript.exe no specs conhost.exe no specs cscript.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs tasklist.exe no specs conhost.exe no specs tasklist.exe no specs cscript.exe no specs conhost.exe no specs hd-glcheck.exe no specs conhost.exe no specs hd-glcheck.exe no specs conhost.exe no specs hd-glcheck.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs hd-checkcpu.exe no specs conhost.exe no specs hd-comregistrar.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs tasklist.exe no specs tasklist.exe no specs hd-comregistrar.exe no specs bstksvc.exe no specs bstkvmmgr.exe no specs conhost.exe no specs bstksvc.exe no specs bluestackshelper.exe hd-player.exe cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs tasklist.exe no specs tasklist.exe no specs schtasks.exe no specs conhost.exe no specs bstksvc.exe no specs ffmpeg.exe no specs conhost.exe no specs ffmpeg.exe no specs conhost.exe no specs ffmpeg.exe no specs conhost.exe no specs ffmpeg.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs tasklist.exe no specs tasklist.exe no specs hd-logcollector.exe reg.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs hd-glcheck.exe no specs conhost.exe no specs hd-hvutl.exe no specs systeminfo.exe no specs conhost.exe no specs bluestacks x.exe tiworker.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs tasklist.exe no specs tasklist.exe no specs bluestacksweb.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs tasklist.exe no specs tasklist.exe no specs 7z.exe conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs tasklist.exe no specs tasklist.exe no specs reg.exe no specs conhost.exe no specs nslookup.exe conhost.exe no specs netstat.exe no specs conhost.exe no specs net.exe no specs conhost.exe no specs net1.exe no specs ipconfig.exe no specs conhost.exe no specs 7zr.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs tasklist.exe no specs tasklist.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs tasklist.exe no specs tasklist.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
512"C:\Users\admin\AppData\Local\Temp\7zS0B8FFB9B\HD-GLCheck.exe" 2 1C:\Users\admin\AppData\Local\Temp\7zS0B8FFB9B\HD-GLCheck.exeBlueStacksInstaller.exe
User:
admin
Company:
BlueStack Systems
Integrity Level:
HIGH
Description:
BlueStacks GLCheck Utility
Exit code:
0
Version:
5.21.610.1003
Modules
Images
c:\users\admin\appdata\local\temp\7zs0b8ffb9b\hd-glcheck.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\opengl32.dll
512\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
540cscript.exe //Nologo C:\Users\admin\AppData\Local\Programs\bluestacks-services\resources\regedit\vbs\regList.wsf A "HKCU\SOFTWARE\BlueStacks X"C:\Windows\System32\cscript.exeBlueStacksServices.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Console Based Script Host
Exit code:
0
Version:
5.812.10240.16384
Modules
Images
c:\windows\system32\cscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
540\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exereg.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
540\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
616C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\TiWorker.exe -EmbeddingC:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\TiWorker.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Modules Installer Worker
Version:
10.0.19041.3989 (WinBuild.160101.0800)
692\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeipconfig.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
696\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
700cscript.exe //Nologo C:\Users\admin\AppData\Local\Programs\bluestacks-services\resources\regedit\vbs\regList.wsf A HKLM\SOFTWARE\BlueStacks_nxtC:\Windows\System32\cscript.exeBlueStacksServices.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Console Based Script Host
Exit code:
0
Version:
5.812.10240.16384
Modules
Images
c:\windows\system32\cscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
780\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeHD-GLCheck.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
110 078
Read events
109 897
Write events
158
Delete events
23

Modification events

(PID) Process:(4868) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(4868) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
(PID) Process:(7100) BlueStacksInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BlueStacksInstaller_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(7100) BlueStacksInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BlueStacksInstaller_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(7100) BlueStacksInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BlueStacksInstaller_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(7100) BlueStacksInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BlueStacksInstaller_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(7100) BlueStacksInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BlueStacksInstaller_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(7100) BlueStacksInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BlueStacksInstaller_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(7100) BlueStacksInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BlueStacksInstaller_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(7100) BlueStacksInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BlueStacksInstaller_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
Executable files
607
Suspicious files
707
Text files
736
Unknown types
23

Dropped files

PID
Process
Filename
Type
4868firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin
MD5:
SHA256:
4868firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
4868firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.binbinary
MD5:C09FF302D57C404B61E6A89B0B9F36E7
SHA256:6A5B4F82595799346D0E501FE6CC8629E0FD6ED27B74D0E6CB5073DDB2E3C40B
4868firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\SiteSecurityServiceState.binbinary
MD5:8BD5A39F8A2C639298BCB418EBED8349
SHA256:F9A4203FEAEABEE8E69EB039DEDE4AC8A843051C9ED5E07555021C68BDACDE1C
4868firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cert9.db-journalbinary
MD5:0A047086215A598C3D028105E10D6C1D
SHA256:B7607B2CBA8DF9987F6D938EE7A0EBDF26B1463F42DEC9884D3A0BDFAC51D7DF
4868firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
4868firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\datareporting\glean\db\data.safe.tmpdbf
MD5:C78F36BF78A74A5C37232FA18305FA6E
SHA256:319C730AC6614FDCE611894E281CBE1B5E1A304DCD812D6B642D3BE978E82EEC
4868firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cert9.dbbinary
MD5:11AFE07B5A15049FB21840CE72D417A3
SHA256:1658DEE98FE0705A1FE50635661FDACE9A36C87402B0FB8DDCAF6A2051E43AFB
4868firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
4868firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\datareporting\glean\db\data.safe.bindbf
MD5:C78F36BF78A74A5C37232FA18305FA6E
SHA256:319C730AC6614FDCE611894E281CBE1B5E1A304DCD812D6B642D3BE978E82EEC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
46
TCP/UDP connections
209
DNS requests
179
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.164.9:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4868
firefox.exe
POST
200
142.250.185.227:80
http://o.pki.goog/wr2
unknown
whitelisted
4868
firefox.exe
POST
200
142.250.185.227:80
http://o.pki.goog/wr2
unknown
whitelisted
4868
firefox.exe
POST
200
142.250.185.227:80
http://o.pki.goog/s/wr3/yvU
unknown
whitelisted
4868
firefox.exe
POST
200
95.101.54.107:80
http://r11.o.lencr.org/
unknown
whitelisted
4868
firefox.exe
POST
200
95.101.54.107:80
http://r11.o.lencr.org/
unknown
whitelisted
4868
firefox.exe
POST
200
142.250.185.227:80
http://o.pki.goog/wr2
unknown
whitelisted
4868
firefox.exe
POST
200
142.250.185.227:80
http://o.pki.goog/wr2
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5488
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.16.164.9:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4360
SearchApp.exe
2.23.209.130:443
www.bing.com
Akamai International B.V.
GB
whitelisted
4360
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
4868
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
  • 40.127.240.158
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 2.16.164.9
  • 2.16.164.49
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 184.30.21.171
whitelisted
google.com
  • 172.217.18.14
whitelisted
www.bing.com
  • 2.23.209.130
  • 2.23.209.187
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
www.bluestacks.com
  • 13.32.121.15
  • 13.32.121.33
  • 13.32.121.127
  • 13.32.121.53
whitelisted
dbk589trlnxim.cloudfront.net
  • 13.32.121.15
  • 13.32.121.33
  • 13.32.121.127
  • 13.32.121.53
  • 2600:9000:211e:fa00:6:6ae6:9b80:93a1
  • 2600:9000:211e:6e00:6:6ae6:9b80:93a1
  • 2600:9000:211e:a000:6:6ae6:9b80:93a1
  • 2600:9000:211e:3a00:6:6ae6:9b80:93a1
  • 2600:9000:211e:ca00:6:6ae6:9b80:93a1
  • 2600:9000:211e:4e00:6:6ae6:9b80:93a1
  • 2600:9000:211e:a200:6:6ae6:9b80:93a1
  • 2600:9000:211e:800:6:6ae6:9b80:93a1
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted

Threats

PID
Process
Class
Message
Misc activity
ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup
Misc activity
ET INFO External IP Address Lookup Domain (ipify .org) in TLS SNI
2 ETPRO signatures available at the full report
Process
Message
BSX-Setup-5.21.610.1003_nxt.exe
closebtn
BSX-Setup-5.21.610.1003_nxt.exe
C:\Program Files (x86)
BSX-Setup-5.21.610.1003_nxt.exe
CustomInstall
BSX-Setup-5.21.610.1003_nxt.exe
BtnOneClick
BSX-Setup-5.21.610.1003_nxt.exe
DirText
BSX-Setup-5.21.610.1003_nxt.exe
BtnInstallFinished
BSX-Setup-5.21.610.1003_nxt.exe
btnSelectDir
BSX-Setup-5.21.610.1003_nxt.exe
C:\Program Files (x86)
BSX-Setup-5.21.610.1003_nxt.exe
showInstallPage
BSX-Setup-5.21.610.1003_nxt.exe
0%