File name:

BlueStacksInstaller_5.4.50.1009_native_acd411592713f32b167aad61d6b0927a_0_V3l6ZSAtIE1ha2UgWW91ciBIb21lIFNtYXJ0ZXI=.exe

Full analysis: https://app.any.run/tasks/68798de1-cab1-4783-ab53-1f6ea84b2071
Verdict: Malicious activity
Analysis date: July 27, 2023, 18:58:37
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

7AC5C3E36D243197C69FA268B90A1710

SHA1:

BFF83DBE893C4FC267B01F03BE85FB5B4E138325

SHA256:

FEBCA76B3BF906043F039660B81912F709B65A1D91C1C36FF369F1D8B5639A3A

SSDEEP:

24576:vivtCXr9vk1QHZil3+CL0H40UMkc0LqhKmteFw4U6M8T:KtCXVk1gw9ZLoUMiLBWeG42m

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • BlueStacksInstaller.exe (PID: 748)
      • BlueStacksInstaller.exe (PID: 2604)
    • Loads dropped or rewritten executable

      • BlueStacksInstaller.exe (PID: 748)
  • SUSPICIOUS

    • Application launched itself

      • BlueStacksInstaller.exe (PID: 2604)
    • Reads the Internet Settings

      • e6e9be68-2751-4770-b17a-cb2638a0794e.exe (PID: 2924)
      • BlueStacksInstaller.exe (PID: 2604)
      • BlueStacksInstaller.exe (PID: 748)
    • Executable content was dropped or overwritten

      • e6e9be68-2751-4770-b17a-cb2638a0794e.exe (PID: 2924)
    • Reads settings of System Certificates

      • BlueStacksInstaller.exe (PID: 748)
  • INFO

    • Create files in a temporary directory

      • e6e9be68-2751-4770-b17a-cb2638a0794e.exe (PID: 2924)
      • BlueStacksInstaller.exe (PID: 748)
    • Checks supported languages

      • e6e9be68-2751-4770-b17a-cb2638a0794e.exe (PID: 2924)
      • BlueStacksInstaller.exe (PID: 2604)
      • BlueStacksInstaller.exe (PID: 748)
    • The process checks LSA protection

      • e6e9be68-2751-4770-b17a-cb2638a0794e.exe (PID: 2924)
      • BlueStacksInstaller.exe (PID: 2604)
      • BlueStacksInstaller.exe (PID: 748)
      • wisptis.exe (PID: 2596)
    • Reads the computer name

      • e6e9be68-2751-4770-b17a-cb2638a0794e.exe (PID: 2924)
      • BlueStacksInstaller.exe (PID: 2604)
      • BlueStacksInstaller.exe (PID: 748)
    • Reads the machine GUID from the registry

      • BlueStacksInstaller.exe (PID: 2604)
      • BlueStacksInstaller.exe (PID: 748)
    • Creates files or folders in the user directory

      • BlueStacksInstaller.exe (PID: 2604)
      • BlueStacksInstaller.exe (PID: 748)
    • Reads Environment values

      • BlueStacksInstaller.exe (PID: 748)
    • Manual execution by a user

      • opera.exe (PID: 3112)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

ProductVersion: 5
ProductName: BlueStacks 5
OriginalFileName: BlueStacksInstaller.exe
LegalCopyright: Copyright (c) 2010-2021 BlueStack Systems Inc.
InternalName: BlueStacks Installer
FileVersion: 5
FileDescription: BlueStacks Setup
CompanyName: BlueStack Systems Inc.
CharacterSet: Unicode
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Executable application
FileOS: Windows NT 32-bit
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 19.0.0.0
FileVersionNumber: 19.0.0.0
Subsystem: Windows GUI
SubsystemVersion: 5
ImageVersion: -
OSVersion: 5
EntryPoint: 0x1a5b2
UninitializedDataSize: -
InitializedDataSize: 160256
CodeSize: 133632
LinkerVersion: 9
PEType: PE32
ImageFileCharacteristics: No relocs, Executable, 32-bit
TimeStamp: 2021:07:19 13:21:27+00:00
MachineType: Intel 386 or later, and compatibles

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 19-Jul-2021 13:21:27
Detected languages:
  • English - United States
CompanyName: BlueStack Systems Inc.
FileDescription: BlueStacks Setup
FileVersion: 5.0
InternalName: BlueStacks Installer
LegalCopyright: Copyright (c) 2010-2021 BlueStack Systems Inc.
OriginalFilename: BlueStacksInstaller.exe
ProductName: BlueStacks 5
ProductVersion: 5.0

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000F0

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 4
Time date stamp: 19-Jul-2021 13:21:27
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x0002086A
0x00020A00
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.65255
.rdata
0x00022000
0x00007730
0x00007800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.7182
.data
0x0002A000
0x00004644
0x00001800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.06813
.rsrc
0x0002F000
0x0001E058
0x0001E200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.66881

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.17811
893
Latin 1 / Western European
English - United States
RT_MANIFEST
2
5.78375
4264
Latin 1 / Western European
English - United States
RT_ICON
3
5.3198
9640
Latin 1 / Western European
English - United States
RT_ICON
4
5.11421
16936
Latin 1 / Western European
English - United States
RT_ICON
5
4.72161
67624
Latin 1 / Western European
English - United States
RT_ICON
6
7.958
20348
Latin 1 / Western European
English - United States
RT_ICON
97
3.04857
184
Latin 1 / Western European
English - United States
RT_DIALOG
188
2.17822
84
Latin 1 / Western European
English - United States
RT_STRING
207
2.04373
76
Latin 1 / Western European
English - United States
RT_STRING

Imports

KERNEL32.dll
OLEAUT32.dll
SHELL32.dll
USER32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
6
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start e6e9be68-2751-4770-b17a-cb2638a0794e.exe bluestacksinstaller.exe no specs bluestacksinstaller.exe wisptis.exe no specs wisptis.exe no specs opera.exe

Process information

PID
CMD
Path
Indicators
Parent process
748"C:\Users\admin\AppData\Local\Temp\7zSC6B7FAB0\BlueStacksInstaller.exe" "e6e9be68-2751-4770-b17a-cb2638a0794e.exe"C:\Users\admin\AppData\Local\Temp\7zSC6B7FAB0\BlueStacksInstaller.exe
BlueStacksInstaller.exe
User:
admin
Company:
BlueStack Systems, Inc.
Integrity Level:
HIGH
Description:
BlueStacks 5 Installer
Exit code:
0
Version:
5.4.50.1009
Modules
Images
c:\users\admin\appdata\local\temp\7zsc6b7fab0\bluestacksinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2508"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\System32\wisptis.exeBlueStacksInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
2596"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\System32\wisptis.exeBlueStacksInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
24
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\oleaut32.dll
2604"C:\Users\admin\AppData\Local\Temp\7zSC6B7FAB0\BlueStacksInstaller.exe" C:\Users\admin\AppData\Local\Temp\7zSC6B7FAB0\BlueStacksInstaller.exee6e9be68-2751-4770-b17a-cb2638a0794e.exe
User:
admin
Company:
BlueStack Systems, Inc.
Integrity Level:
MEDIUM
Description:
BlueStacks 5 Installer
Exit code:
0
Version:
5.4.50.1009
Modules
Images
c:\users\admin\appdata\local\temp\7zsc6b7fab0\bluestacksinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2924"C:\Users\admin\AppData\Local\Temp\e6e9be68-2751-4770-b17a-cb2638a0794e.exe" C:\Users\admin\AppData\Local\Temp\e6e9be68-2751-4770-b17a-cb2638a0794e.exe
explorer.exe
User:
admin
Company:
BlueStack Systems Inc.
Integrity Level:
MEDIUM
Description:
BlueStacks Setup
Exit code:
0
Version:
5.0
Modules
Images
c:\users\admin\appdata\local\temp\e6e9be68-2751-4770-b17a-cb2638a0794e.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
3112"C:\Program Files\Opera\opera.exe" C:\Program Files\Opera\opera.exe
explorer.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera Internet Browser
Exit code:
0
Version:
1748
Modules
Images
c:\program files\opera\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
Total events
5 791
Read events
5 641
Write events
150
Delete events
0

Modification events

(PID) Process:(2924) e6e9be68-2751-4770-b17a-cb2638a0794e.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2924) e6e9be68-2751-4770-b17a-cb2638a0794e.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2924) e6e9be68-2751-4770-b17a-cb2638a0794e.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2924) e6e9be68-2751-4770-b17a-cb2638a0794e.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2604) BlueStacksInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2604) BlueStacksInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2604) BlueStacksInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2604) BlueStacksInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(748) BlueStacksInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
Explorer.EXE
(PID) Process:(748) BlueStacksInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
3
Suspicious files
22
Text files
77
Unknown types
0

Dropped files

PID
Process
Filename
Type
2924e6e9be68-2751-4770-b17a-cb2638a0794e.exeC:\Users\admin\AppData\Local\Temp\7zSC6B7FAB0\Assets\backicon.pngimage
MD5:7FF5DC8270B5FA7EF6C4A1420BD67A7F
SHA256:FA64884054171515E97B78AAA1AAD1EC5BAA9D1DAF9C682E0B3FB4A41A9CB1C1
2924e6e9be68-2751-4770-b17a-cb2638a0794e.exeC:\Users\admin\AppData\Local\Temp\7zSC6B7FAB0\Assets\checked_gray_hover.pngimage
MD5:EA22933E94C7AB813B639627F2B38286
SHA256:D7C79677D2EF897FA0AD1EFC90E916C46DA29F571208F78F24505603B7165C20
2924e6e9be68-2751-4770-b17a-cb2638a0794e.exeC:\Users\admin\AppData\Local\Temp\7zSC6B7FAB0\Assets\installer_bg.jpgimage
MD5:162C23F5962381EFBA79BE503B41089C
SHA256:04D70D0968675290294DF78800ED48FE4A681A72803405FBDC541B927B445457
2924e6e9be68-2751-4770-b17a-cb2638a0794e.exeC:\Users\admin\AppData\Local\Temp\7zSC6B7FAB0\Assets\exit_close_hover.pngimage
MD5:92C2BF222D6AB81FE7A0C072BF31C107
SHA256:BCC053A9A087E077D58114106D29701A34F7851F4052F3157102811355D3E709
2924e6e9be68-2751-4770-b17a-cb2638a0794e.exeC:\Users\admin\AppData\Local\Temp\7zSC6B7FAB0\Assets\checked_gray.pngimage
MD5:CE144D2AAB3BF213AF693D4E18F87A59
SHA256:D8E502FAB00B0C6F06BA6ABEDE6922AB3B423FE6F2D2F56941DABC887B229AD3
2924e6e9be68-2751-4770-b17a-cb2638a0794e.exeC:\Users\admin\AppData\Local\Temp\7zSC6B7FAB0\Assets\close_red.pngimage
MD5:93216B2F9D66D423B3E1311C0573332D
SHA256:D0B6D143642D356B40C47459A996131A344CADE6BB86158F1B74693426B09BFB
2924e6e9be68-2751-4770-b17a-cb2638a0794e.exeC:\Users\admin\AppData\Local\Temp\7zSC6B7FAB0\Assets\error_icon.pngimage
MD5:DAB2C4538A83422B5DEAE0E0DE9B7A30
SHA256:666AD4FE456216DDC06618967846ED31F81D8DB5BE97DA6531842C0667352B89
2924e6e9be68-2751-4770-b17a-cb2638a0794e.exeC:\Users\admin\AppData\Local\Temp\7zSC6B7FAB0\Assets\close_red_click.pngimage
MD5:6DB7460B73A6641C7621D0A6203A0A90
SHA256:D5A7E6FC5E92E0B29A4F65625030447F3379B4E3AC4BED051A0646A7932CE0CD
2924e6e9be68-2751-4770-b17a-cb2638a0794e.exeC:\Users\admin\AppData\Local\Temp\7zSC6B7FAB0\Assets\close_red_hover.pngimage
MD5:5CEAB43AA527BC146F9453A1586DDF03
SHA256:7C625AE4668CC03E37E4FFC478B87EACE06B49B77E71E3209F431C23D98ACDD0
2924e6e9be68-2751-4770-b17a-cb2638a0794e.exeC:\Users\admin\AppData\Local\Temp\7zSC6B7FAB0\Assets\custom_click.pngimage
MD5:CED07C9DB242115400E159D9A02BB7B7
SHA256:1318E0F34A551EDAE1E82818FDF7DE5AC627493DB5B24556D919F525052D5B90
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
24
DNS requests
10
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3112
opera.exe
GET
142.250.186.68:80
http://www.google.com/
US
malicious
3112
opera.exe
GET
200
172.217.18.110:80
http://clients1.google.com/complete/search?q=google&client=opera-suggest-omnibox&hl=de
US
text
138 b
whitelisted
3112
opera.exe
GET
400
185.26.182.93:80
http://sitecheck2.opera.com/?host=google.com&hdn=5cHJ/4cINcLBl65Ju%2BOcTQ==
unknown
html
150 b
whitelisted
3112
opera.exe
GET
400
185.26.182.93:80
http://sitecheck2.opera.com/?host=www.google.com&hdn=AGZGLiBzId7nGTYe3dxEwA==
unknown
html
150 b
whitelisted
3112
opera.exe
GET
301
142.250.185.206:80
http://google.com/
US
html
219 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
2720
svchost.exe
239.255.255.250:1900
whitelisted
748
BlueStacksInstaller.exe
18.66.26.70:443
cdn-bgp.bluestacks.com
US
unknown
748
BlueStacksInstaller.exe
13.32.99.23:443
cdn3.bluestacks.com
AMAZON-02
US
suspicious
3112
opera.exe
185.26.182.94:443
certs.opera.com
Opera Software AS
whitelisted
3112
opera.exe
185.26.182.93:443
certs.opera.com
Opera Software AS
whitelisted
3112
opera.exe
142.250.186.68:80
www.google.com
GOOGLE
US
whitelisted
3112
opera.exe
185.26.182.106:80
sitecheck2.opera.com
Opera Software AS
suspicious
3112
opera.exe
185.26.182.93:80
certs.opera.com
Opera Software AS
whitelisted
3112
opera.exe
172.217.18.110:80
clients1.google.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
cloud.bluestacks.com
  • 34.160.86.181
whitelisted
cdn-bgp.bluestacks.com
  • 18.66.26.70
  • 18.66.26.78
  • 18.66.26.30
  • 18.66.26.100
shared
cdn3.bluestacks.com
  • 13.32.99.23
  • 13.32.99.33
  • 13.32.99.107
  • 13.32.99.85
shared
certs.opera.com
  • 185.26.182.94
  • 185.26.182.93
whitelisted
clients1.google.com
  • 172.217.18.110
whitelisted
google.com
  • 142.250.185.206
malicious
sitecheck2.opera.com
  • 185.26.182.93
  • 185.26.182.106
  • 185.26.182.94
  • 185.26.182.111
  • 185.26.182.112
  • 185.26.182.118
whitelisted
www.google.com
  • 142.250.186.68
malicious
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
No debug info