bluestacks.exe

The executable bluestacks.exe has been detected as malware by 1 anti-virus scanner. The file has been seen being downloaded from profficer.org.
MD5:
24e123f9b9ec0e1a958ff7d7d510cb95

SHA-1:
eeacd85357b3d11c19dd2c4d0624948451ad7963

SHA-256:
aeee8a3c1abbc441a10b48276911de089c588321ff237d684d079a9d3d29ea51

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/24/2024 10:35:08 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Win.Reputation.IMP
16.2.24.6

File size:
1 MB (1,050,143 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\bluestacks.exe

File PE Metadata
Compilation timestamp:
9/27/2012 4:42:03 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:zXYqsLrzivvpl/iB8KxrUo88DNrfTsREd4vpRZgK90V:DYqUiHpg7Uo88DNDAREyvv19G

Entry address:
0xB8269

Entry point:
E8, FE, 13, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 80, E9, 4F, 00, E8, 11, 19, 00, 00, E8, CB, 15, 00, 00, 0F, B7, F0, 6A, 02, E8, 91, 13, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 40, 03, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
7.4497

Code size:
757 KB (775,168 bytes)

The file bluestacks.exe has been seen being distributed by the following URL.

Remove bluestacks.exe - Powered by Reason Core Security