File name:

Subway Surfers Setup [1].exe

Full analysis: https://app.any.run/tasks/88f911d3-8a72-435d-915e-2228fb9ed5e7
Verdict: Malicious activity
Analysis date: August 22, 2024, 21:49:00
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

7C2C661DE6FCDF143E0E903815D9DB4D

SHA1:

306C4BC8CD045ACEC57695D2A5D4A06510D3FC2C

SHA256:

FB9194666C67A42840C8B3DACD5265491D984FE8C871194606D87C1E2F3F7529

SSDEEP:

98304:MmxyENGiAKOTCwFo71LAsTmbzo8EeXtYJJVUOLM39qI0NnZmOf+QYhkhlzTtVcoy:xf5TnpJlWNKjq1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • Subway Surfers Setup [1].exe (PID: 6776)
      • msiexec.exe (PID: 6344)
    • Reads the date of Windows installation

      • Subway Surfers Setup [1].exe (PID: 6776)
      • BlueStacks-ThinInstaller_0.7.17.916.exe (PID: 6896)
    • Reads security settings of Internet Explorer

      • Subway Surfers Setup [1].exe (PID: 6776)
      • BlueStacks-ThinInstaller_0.7.17.916.exe (PID: 6896)
    • Executable content was dropped or overwritten

      • Subway Surfers Setup [1].exe (PID: 6776)
      • rundll32.exe (PID: 2396)
      • rundll32.exe (PID: 6012)
      • rundll32.exe (PID: 1928)
    • Adds/modifies Windows certificates

      • BlueStacks-ThinInstaller_0.7.17.916.exe (PID: 6896)
    • Checks Windows Trust Settings

      • BlueStacks-ThinInstaller_0.7.17.916.exe (PID: 6896)
      • msiexec.exe (PID: 6344)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 6344)
    • Process drops legitimate windows executable

      • rundll32.exe (PID: 1928)
      • rundll32.exe (PID: 2396)
      • rundll32.exe (PID: 6012)
  • INFO

    • Checks supported languages

      • Subway Surfers Setup [1].exe (PID: 6776)
      • BlueStacks-ThinInstaller_0.7.17.916.exe (PID: 6896)
      • msiexec.exe (PID: 6344)
      • msiexec.exe (PID: 6696)
      • glcheck.exe (PID: 6456)
    • Create files in a temporary directory

      • Subway Surfers Setup [1].exe (PID: 6776)
      • BlueStacks-ThinInstaller_0.7.17.916.exe (PID: 6896)
      • msiexec.exe (PID: 4040)
      • rundll32.exe (PID: 1928)
      • rundll32.exe (PID: 6012)
    • Reads the computer name

      • Subway Surfers Setup [1].exe (PID: 6776)
      • BlueStacks-ThinInstaller_0.7.17.916.exe (PID: 6896)
      • msiexec.exe (PID: 6344)
      • msiexec.exe (PID: 6696)
      • glcheck.exe (PID: 6456)
    • Process checks computer location settings

      • Subway Surfers Setup [1].exe (PID: 6776)
      • BlueStacks-ThinInstaller_0.7.17.916.exe (PID: 6896)
    • Reads the software policy settings

      • BlueStacks-ThinInstaller_0.7.17.916.exe (PID: 6896)
      • msiexec.exe (PID: 6344)
      • rundll32.exe (PID: 2396)
      • rundll32.exe (PID: 6012)
    • Disables trace logs

      • BlueStacks-ThinInstaller_0.7.17.916.exe (PID: 6896)
      • rundll32.exe (PID: 6012)
    • Creates files or folders in the user directory

      • BlueStacks-ThinInstaller_0.7.17.916.exe (PID: 6896)
    • Creates files in the program directory

      • BlueStacks-ThinInstaller_0.7.17.916.exe (PID: 6896)
      • rundll32.exe (PID: 6012)
    • Reads the machine GUID from the registry

      • BlueStacks-ThinInstaller_0.7.17.916.exe (PID: 6896)
      • msiexec.exe (PID: 6344)
    • Reads Environment values

      • BlueStacks-ThinInstaller_0.7.17.916.exe (PID: 6896)
    • Checks proxy server information

      • BlueStacks-ThinInstaller_0.7.17.916.exe (PID: 6896)
      • rundll32.exe (PID: 6012)
    • Reads security settings of Internet Explorer

      • rundll32.exe (PID: 2396)
      • rundll32.exe (PID: 6012)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6344)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2010:11:18 16:27:32+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 82944
InitializedDataSize: 25088
UninitializedDataSize: -
EntryPoint: 0x1373c
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: BlueStack Systems Inc.
FileDescription: BlueStacks Thin Installer
FileVersion: 0.0.0.0
InternalName: BlueStacks Thin Installer
LegalCopyright: Copyright (c) BlueStack Systems Inc.
OriginalFileName: BlueStacks_ThinInstaller.exe
ProductName: BlueStacks Thin Installer
ProductVersion: 0.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
11
Malicious processes
0
Suspicious processes
4

Behavior graph

Click at the process to see the details
start subway surfers setup [1].exe bluestacks-thininstaller_0.7.17.916.exe msiexec.exe no specs msiexec.exe msiexec.exe no specs rundll32.exe rundll32.exe rundll32.exe glcheck.exe no specs conhost.exe no specs subway surfers setup [1].exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1928rundll32.exe "C:\WINDOWS\Installer\MSIA2C1.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_1221375 9 CustomActions!Actions.CreateUserGUIDC:\Windows\SysWOW64\rundll32.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2396rundll32.exe "C:\WINDOWS\Installer\MSIA12A.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_1221000 2 CustomActions!Integrity.CheckMsiIntegrityC:\Windows\SysWOW64\rundll32.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
4040"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\BlueStacks_52cc0nmq.cfr\BlueStacks_HD_AppPlayerSplit_setup_0.7.17.916_REL.msi" /qn P2DM=1 SPOTLIGHT=1 FEATURES=268435455 OEM=BlueStacks APPPLAYER=YESC:\Windows\SysWOW64\msiexec.exeBlueStacks-ThinInstaller_0.7.17.916.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
1603
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6012rundll32.exe "C:\WINDOWS\Installer\MSIA3AC.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_1221578 19 CustomActions!Actions.CheckIfGlSupportedC:\Windows\SysWOW64\rundll32.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6248\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeglcheck.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6344C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6456"glcheck.exe"C:\Windows\Installer\MSIA3AC.tmp-\glcheck.exerundll32.exe
User:
admin
Company:
BlueStack Systems
Integrity Level:
HIGH
Description:
BlueStacks GLCheck Utility
Exit code:
1
Version:
0.7.17.916
Modules
Images
c:\windows\installer\msia3ac.tmp-\glcheck.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\gdi32.dll
6696C:\Windows\syswow64\MsiExec.exe -Embedding A3ED01C82A883E430BCC937037912564C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6728"C:\Users\admin\Downloads\Subway Surfers Setup [1].exe" C:\Users\admin\Downloads\Subway Surfers Setup [1].exeexplorer.exe
User:
admin
Company:
BlueStack Systems Inc.
Integrity Level:
MEDIUM
Description:
BlueStacks Thin Installer
Exit code:
3221226540
Version:
0.0.0.0
Modules
Images
c:\users\admin\downloads\subway surfers setup [1].exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6776"C:\Users\admin\Downloads\Subway Surfers Setup [1].exe" C:\Users\admin\Downloads\Subway Surfers Setup [1].exe
explorer.exe
User:
admin
Company:
BlueStack Systems Inc.
Integrity Level:
HIGH
Description:
BlueStacks Thin Installer
Version:
0.0.0.0
Modules
Images
c:\users\admin\downloads\subway surfers setup [1].exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
Total events
24 549
Read events
24 493
Write events
51
Delete events
5

Modification events

(PID) Process:(6776) Subway Surfers Setup [1].exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6776) Subway Surfers Setup [1].exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6776) Subway Surfers Setup [1].exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6776) Subway Surfers Setup [1].exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(6896) BlueStacks-ThinInstaller_0.7.17.916.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates
Operation:delete valueName:742C3192E607E424EB4549542BE1BBC53E6174E2
Value:
(PID) Process:(6896) BlueStacks-ThinInstaller_0.7.17.916.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2
Operation:writeName:Blob
Value:
04000000010000001000000010FC635DF6263E0DF325BE5F79CD67677E0000000100000008000000000010C51E92D2011D000000010000001000000027B3517667331CE2C1E74002B5FF2298620000000100000020000000E7685634EFACF69ACE939A6B255B7B4FABEF42935B50A265ACB5CB6027E44E7009000000010000002A000000302806082B0601050507030206082B0601050507030306082B0601050507030406082B0601050507030119000000010000001000000091161B894B117ECDC257628DB460CC04030000000100000014000000742C3192E607E424EB4549542BE1BBC53E6174E20F0000000100000010000000D7C63BE0837DBABF881D4FBF5F986AD80B000000010000004600000056006500720069005300690067006E00200043006C006100730073002000330020005000750062006C006900630020005000720069006D00610072007900200043004100000053000000010000002400000030223020060A2B0601040182375E010130123010060A2B0601040182373C0101030200C0140000000100000014000000E27F7BD877D5DF9E0A3F9EB4CB0E2EA9EFDB69777A000000010000000E000000300C060A2B0601040182375E010268000000010000000800000000003DB65BD9D5012000000001000000400200003082023C308201A5021070BAE41D10D92934B638CA7B03CCBABF300D06092A864886F70D0101020500305F310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E31373035060355040B132E436C6173732033205075626C6963205072696D6172792043657274696669636174696F6E20417574686F72697479301E170D3936303132393030303030305A170D3238303830313233353935395A305F310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E31373035060355040B132E436C6173732033205075626C6963205072696D6172792043657274696669636174696F6E20417574686F7269747930819F300D06092A864886F70D010101050003818D0030818902818100C95C599EF21B8A0114B410DF0440DBE357AF6A45408F840C0BD133D9D911CFEE02581F25F72AA84405AAEC031F787F9E93B99A00AA237DD6AC85A26345C77227CCF44CC67571D239EF4F42F075DF0A90C68E206F980FF8AC235F702936A4C986E7B19A20CB53A585E73DBE7D9AFE244533DC7615ED0FA271644C652E816845A70203010001300D06092A864886F70D010102050003818100BB4C122BCF2C26004F1413DDA6FBFC0A11848CF3281C67922F7CB6C5FADFF0E895BC1D8F6C2CA851CC73D8A4C053F04ED626C076015781925E21F1D1B1FFE7D02158CD6917E3441C9C194439895CDC9C000F568D0299EDA290454CE4BB10A43DF032030EF1CEF8E8C9518CE6629FE69FC07DB7729CC9363A6B9F4EA8FF640D64
(PID) Process:(6896) BlueStacks-ThinInstaller_0.7.17.916.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2
Operation:writeName:Blob
Value:
5C00000001000000040000000004000068000000010000000800000000003DB65BD9D5017A000000010000000E000000300C060A2B0601040182375E0102140000000100000014000000E27F7BD877D5DF9E0A3F9EB4CB0E2EA9EFDB697753000000010000002400000030223020060A2B0601040182375E010130123010060A2B0601040182373C0101030200C00B000000010000004600000056006500720069005300690067006E00200043006C006100730073002000330020005000750062006C006900630020005000720069006D0061007200790020004300410000000F0000000100000010000000D7C63BE0837DBABF881D4FBF5F986AD8030000000100000014000000742C3192E607E424EB4549542BE1BBC53E6174E219000000010000001000000091161B894B117ECDC257628DB460CC0409000000010000002A000000302806082B0601050507030206082B0601050507030306082B0601050507030406082B06010505070301620000000100000020000000E7685634EFACF69ACE939A6B255B7B4FABEF42935B50A265ACB5CB6027E44E701D000000010000001000000027B3517667331CE2C1E74002B5FF22987E0000000100000008000000000010C51E92D20104000000010000001000000010FC635DF6263E0DF325BE5F79CD67672000000001000000400200003082023C308201A5021070BAE41D10D92934B638CA7B03CCBABF300D06092A864886F70D0101020500305F310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E31373035060355040B132E436C6173732033205075626C6963205072696D6172792043657274696669636174696F6E20417574686F72697479301E170D3936303132393030303030305A170D3238303830313233353935395A305F310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E31373035060355040B132E436C6173732033205075626C6963205072696D6172792043657274696669636174696F6E20417574686F7269747930819F300D06092A864886F70D010101050003818D0030818902818100C95C599EF21B8A0114B410DF0440DBE357AF6A45408F840C0BD133D9D911CFEE02581F25F72AA84405AAEC031F787F9E93B99A00AA237DD6AC85A26345C77227CCF44CC67571D239EF4F42F075DF0A90C68E206F980FF8AC235F702936A4C986E7B19A20CB53A585E73DBE7D9AFE244533DC7615ED0FA271644C652E816845A70203010001300D06092A864886F70D010102050003818100BB4C122BCF2C26004F1413DDA6FBFC0A11848CF3281C67922F7CB6C5FADFF0E895BC1D8F6C2CA851CC73D8A4C053F04ED626C076015781925E21F1D1B1FFE7D02158CD6917E3441C9C194439895CDC9C000F568D0299EDA290454CE4BB10A43DF032030EF1CEF8E8C9518CE6629FE69FC07DB7729CC9363A6B9F4EA8FF640D64
(PID) Process:(6896) BlueStacks-ThinInstaller_0.7.17.916.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates
Operation:delete valueName:4F65566336DB6598581D584A596C87934D5F2AB4
Value:
(PID) Process:(6896) BlueStacks-ThinInstaller_0.7.17.916.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4F65566336DB6598581D584A596C87934D5F2AB4
Operation:writeName:Blob
Value:
5C00000001000000040000000004000019000000010000001000000091161B894B117ECDC257628DB460CC040300000001000000140000004F65566336DB6598581D584A596C87934D5F2AB41D000000010000001000000027B3517667331CE2C1E74002B5FF2298140000000100000014000000E27F7BD877D5DF9E0A3F9EB4CB0E2EA9EFDB697709000000010000002A000000302806082B0601050507030406082B0601050507030206082B0601050507030306082B060105050703010B000000010000003800000056006500720069005300690067006E00200043006C006100730073002000330020005000720069006D006100720079002000430041000000040000000100000010000000782A02DFDB2E14D5A75F0ADFB68E9C5D0F0000000100000010000000F1BBAC2D9038DDEC8DB173C53BC72A2A2000000001000000410200003082023D308201A6021100E49EFDF33AE80ECFA5113E19A4240232300D06092A864886F70D0101020500305F310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E31373035060355040B132E436C6173732033205075626C6963205072696D6172792043657274696669636174696F6E20417574686F72697479301E170D3936303132393030303030305A170D3034303130373233353935395A305F310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E31373035060355040B132E436C6173732033205075626C6963205072696D6172792043657274696669636174696F6E20417574686F7269747930819F300D06092A864886F70D010101050003818D0030818902818100C95C599EF21B8A0114B410DF0440DBE357AF6A45408F840C0BD133D9D911CFEE02581F25F72AA84405AAEC031F787F9E93B99A00AA237DD6AC85A26345C77227CCF44CC67571D239EF4F42F075DF0A90C68E206F980FF8AC235F702936A4C986E7B19A20CB53A585E73DBE7D9AFE244533DC7615ED0FA271644C652E816845A70203010001300D06092A864886F70D0101020500038181006170EC2F3F9EFD2BE6685421B06779080C2096318A0D7ABEB626DF792C22694936E397776261A232D77A542136BA02C934E725DA4435B0D25C805DB394F8F9ACEEA460752A1F954923B14A7CF4B34772215B7E97AB54AC62E75DECAE9BD2C9B224FB82ADE967154BBAAAA6F097A0F6B0975700C80C3C09A08204BA41DAF799A4
(PID) Process:(6896) BlueStacks-ThinInstaller_0.7.17.916.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates
Operation:delete valueName:E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46
Value:
Executable files
28
Suspicious files
12
Text files
29
Unknown types
0

Dropped files

PID
Process
Filename
Type
6776Subway Surfers Setup [1].exeC:\Users\admin\AppData\Local\Temp\7zSDDDA.tmp\BlueStacks-ThinInstaller_0.7.17.916.exe.configxml
MD5:C3CF51530AAC160BB2AECD66FF2D8C52
SHA256:55626447967BBED852D4234E4A5B97012420361F8242C73A166CC04B3E1497B7
6896BlueStacks-ThinInstaller_0.7.17.916.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\60E31627FDA0A46932B0E5948949F2A5binary
MD5:7639818DC8E9CA74E706845CDBCEE323
SHA256:BDD1CBFC16F3995E69FC0CAE70DE3255EFF2C2ECFA3CFE93F560F0862CD5E630
6896BlueStacks-ThinInstaller_0.7.17.916.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6binary
MD5:5BFA51F3A417B98E7443ECA90FC94703
SHA256:BEBE2853A3485D1C2E5C5BE4249183E0DDAFF9F87DE71652371700A89D937128
6896BlueStacks-ThinInstaller_0.7.17.916.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\60E31627FDA0A46932B0E5948949F2A5binary
MD5:1BA25895DC793E6826CBE8D61DDD8293
SHA256:CC4C5C999CA59E5A62BC3FFE172A61F8CF13CC18C89FE48F628FF2A75BDC508A
6896BlueStacks-ThinInstaller_0.7.17.916.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\D47DBD2F9E3365FBBE008D71FB06716F_D33192D58AA9CA2B9097E848E9FE86DEbinary
MD5:CB9925B976D23568E9382DBA1AB64706
SHA256:029862CD2D3E4B6C7E6166FAC60CD29798E13ACBDF02606B67DC55DD8FFAAE6A
6896BlueStacks-ThinInstaller_0.7.17.916.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6binary
MD5:59A44C86D077D593A7B6D10E4D6C7B26
SHA256:9EACE58948B358E394FE4E750ED39DF2C0DDD149B0AEE1B19C9E9799B9C0C433
6896BlueStacks-ThinInstaller_0.7.17.916.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8DFDF057024880D7A081AFBF6D26B92Fder
MD5:A0AF4D81B2B19A99A3D01BE89D5F99D9
SHA256:DE9F05CEB1610CF9964F0DEF09D525005569602993C82A647743F192E9414D4A
6896BlueStacks-ThinInstaller_0.7.17.916.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\D47DBD2F9E3365FBBE008D71FB06716F_D33192D58AA9CA2B9097E848E9FE86DEbinary
MD5:5BFA51F3A417B98E7443ECA90FC94703
SHA256:BEBE2853A3485D1C2E5C5BE4249183E0DDAFF9F87DE71652371700A89D937128
6776Subway Surfers Setup [1].exeC:\Users\admin\AppData\Local\Temp\7zSDDDA.tmp\BlueStacks-ThinInstaller_0.7.17.916.exeexecutable
MD5:9DFFAFCE622D3410F7893A8B2C38A0B0
SHA256:4B13E944D0014A489D1B937D738DAD614A93B973A0E42D4EB27C42E36F1308F4
6896BlueStacks-ThinInstaller_0.7.17.916.exeC:\ProgramData\BlueStacksSetup\Images\SetupImage1.jpgimage
MD5:ED7BA05C557F18F4BB01F6B07C9FADD1
SHA256:EE4B98F8070C9DF9CDA53187510CC370F018ABF3F57A19A3FA87CD903E02F17D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
33
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6896
BlueStacks-ThinInstaller_0.7.17.916.exe
GET
200
152.199.19.74:80
http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X%2B%2BhEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECECUM6OAwYS6fK4n3BU18%2BP0%3D
unknown
whitelisted
6896
BlueStacks-ThinInstaller_0.7.17.916.exe
GET
200
152.199.19.74:80
http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X%2B%2BhEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECECUM6OAwYS6fK4n3BU18%2BP0%3D
unknown
whitelisted
7088
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
2212
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6388
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6896
BlueStacks-ThinInstaller_0.7.17.916.exe
GET
200
192.229.221.95:80
http://csc3-2010-crl.verisign.com/CSC3-2010.crl
unknown
whitelisted
6896
BlueStacks-ThinInstaller_0.7.17.916.exe
GET
200
152.199.19.74:80
http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CEH8eU%2FH0Jk7z4p7qksRDL%2FI%3D
unknown
whitelisted
6896
BlueStacks-ThinInstaller_0.7.17.916.exe
GET
200
192.229.221.95:80
http://crl.verisign.com/pca3.crl
unknown
whitelisted
6896
BlueStacks-ThinInstaller_0.7.17.916.exe
GET
200
152.199.19.74:80
http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c%3D
unknown
whitelisted
6896
BlueStacks-ThinInstaller_0.7.17.916.exe
GET
200
152.199.19.74:80
http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
1128
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6896
BlueStacks-ThinInstaller_0.7.17.916.exe
152.199.19.74:80
ocsp.verisign.com
EDGECAST
US
unknown
6896
BlueStacks-ThinInstaller_0.7.17.916.exe
192.229.221.95:80
crl.verisign.com
EDGECAST
US
whitelisted
6896
BlueStacks-ThinInstaller_0.7.17.916.exe
172.217.16.206:443
www.google-analytics.com
GOOGLE
US
whitelisted
1128
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3260
svchost.exe
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2212
svchost.exe
40.126.32.72:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
  • 51.124.78.146
whitelisted
google.com
  • 142.250.185.142
whitelisted
ocsp.verisign.com
  • 152.199.19.74
whitelisted
crl.verisign.com
  • 192.229.221.95
whitelisted
csc3-2010-crl.verisign.com
  • 192.229.221.95
whitelisted
www.google-analytics.com
  • 172.217.16.206
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
login.live.com
  • 40.126.32.72
  • 40.126.32.76
  • 40.126.32.133
  • 40.126.32.134
  • 20.190.160.17
  • 40.126.32.138
  • 40.126.32.74
  • 40.126.32.68
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
arc.msn.com
  • 20.31.169.57
whitelisted

Threats

No threats detected
No debug info