× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 2bcdc0a80d91ec5a91a5efd9f4b899ca55e552d55d1ae3b31fcf8d7f0440cfcf
File name: BlockDeviceFile
Detection ratio: 1 / 54
Analysis date: 2016-08-31 08:06:09 UTC ( 2 years, 4 months ago )
Antivirus Result Update
AegisLab W32.Sality.mBq5 20160831
Ad-Aware 20160831
AhnLab-V3 20160831
Alibaba 20160831
ALYac 20160831
Antiy-AVL 20160831
Arcabit 20160831
AVG 20160831
AVware 20160831
Baidu 20160831
BitDefender 20160831
Bkav 20160831
CAT-QuickHeal 20160831
ClamAV 20160831
CMC 20160830
Comodo 20160831
Cyren 20160831
DrWeb 20160831
Emsisoft 20160831
ESET-NOD32 20160831
F-Prot 20160831
F-Secure 20160831
Fortinet 20160831
GData 20160831
Ikarus 20160831
Sophos ML 20160830
Jiangmin 20160831
K7AntiVirus 20160831
K7GW 20160831
Kaspersky 20160831
Kingsoft 20160831
Malwarebytes 20160831
McAfee 20160831
McAfee-GW-Edition 20160831
Microsoft 20160831
eScan 20160831
NANO-Antivirus 20160831
nProtect 20160831
Panda 20160831
Qihoo-360 20160831
Rising 20160831
Sophos AV 20160831
SUPERAntiSpyware 20160831
Symantec 20160831
Tencent 20160831
TheHacker 20160829
TotalDefense 20160831
TrendMicro 20160831
TrendMicro-HouseCall 20160831
VBA32 20160831
VIPRE 20160831
ViRobot 20160831
Yandex 20160830
Zillya 20160831
Zoner 20160831
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows command line subsystem.
Authenticode signature block and FileVersionInfo properties
Copyright
Copyright 2011 BlueStack Systems, Inc. All Rights Reserved.

Product BlueStacks
Original name HD-BlockDevice.exe
File version 0.7.5.2700
Description BlueStacks Block Device Helper Process
Signature verification Signed file, verified signature
Signing date 11:34 AM 9/24/2012
Signers
[+] Bluestack Systems
Status This certificate or one of the certificates in the certificate chain is not time valid.
Issuer VeriSign Class 3 Code Signing 2010 CA
Valid from 1:00 AM 2/4/2012
Valid to 12:59 AM 3/22/2013
Valid usage Code Signing
Algorithm sha1RSA
Thumbprint 22D9A6E8EE52516D8BF1C029C8B3180E04CC66E5
Serial number 32 0E 40 B7 49 5D 08 40 E3 9F C0 C5 9C 37 A2 61
[+] VeriSign Class 3 Code Signing 2010 CA
Status Valid
Issuer VeriSign Class 3 Public Primary Certification Authority - G5
Valid from 1:00 AM 2/8/2010
Valid to 12:59 AM 2/8/2020
Valid usage Client Auth, Code Signing
Algorithm sha1RSA
Thumbprint 495847A93187CFB8C71F840CB7B41497AD95C64F
Serial number 52 00 E5 AA 25 56 FC 1A 86 ED 96 C9 D4 4B 33 C7
[+] VeriSign
Status Valid
Issuer VeriSign Class 3 Public Primary Certification Authority - G5
Valid from 1:00 AM 11/8/2006
Valid to 12:59 AM 7/17/2036
Valid usage Server Auth, Client Auth, Email Protection, Code Signing
Algorithm sha1RSA
Thumbprint 4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5
Serial number 18 DA D1 9E 26 7D E8 BB 4A 21 58 CD CC 6B 3B 4A
Counter signers
[+] COMODO Time Stamping Signer
Status This certificate or one of the certificates in the certificate chain is not time valid.
Issuer UTN-USERFirst-Object
Valid from 1:00 AM 5/10/2010
Valid to 12:59 AM 5/11/2015
Valid usage Timestamp Signing
Algorithm sha1RSA
Thumbrint 3DBB6DB5085C6DD5A1CA7F9CF84ECB1A3910CAC8
Serial number 47 8A 8E FB 59 E1 D8 3F 0C E1 42 D2 A2 87 07 BE
[+] USERTrust (Code Signing)
Status Valid
Issuer UTN-USERFirst-Object
Valid from 7:31 PM 7/9/1999
Valid to 7:40 PM 7/9/2019
Valid usage EFS, Timestamp Signing, Code Signing
Algorithm sha1RSA
Thumbrint E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46
Serial number 44 BE 0C 8B 50 00 24 B4 11 D3 36 2D E0 B3 5F 1B
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2012-09-24 10:34:17
Entry Point 0x00008BD7
Number of sections 5
PE sections
Overlays
MD5 ddaa7eeac37aeaddb1d1b4d26ca931e3
File type data
Offset 252416
Size 8056
Entropy 7.37
PE imports
RegCloseKey
RegQueryValueExW
RegOpenKeyExW
GetStockObject
GetStdHandle
GetConsoleOutputCP
GetOverlappedResult
WaitForSingleObject
HeapDestroy
GetLocalTime
FreeEnvironmentStringsA
DeleteCriticalSection
GetCurrentProcess
GetConsoleMode
GetLocaleInfoA
FreeEnvironmentStringsW
GetLocaleInfoW
SetStdHandle
GetCPInfo
GetStringTypeA
InterlockedExchange
WriteFile
GetTimeZoneInformation
GetSystemTimeAsFileTime
HeapReAlloc
GetStringTypeW
GetOEMCP
LocalFree
FormatMessageW
InitializeCriticalSection
LoadResource
GetStringTypeExW
TlsGetValue
GetStringTypeExA
OutputDebugStringA
GetEnvironmentVariableW
SetLastError
DeviceIoControl
GetEnvironmentVariableA
GetModuleFileNameW
HeapAlloc
FlushFileBuffers
GetModuleFileNameA
FlushViewOfFile
FreeLibrary
EnumSystemLocalesA
LoadLibraryExA
SetConsoleCtrlHandler
GetUserDefaultLCID
SetHandleCount
UnhandledExceptionFilter
InterlockedDecrement
MultiByteToWideChar
FatalAppExitA
SetFilePointerEx
SetFilePointer
CreateThread
SetUnhandledExceptionFilter
ExitThread
SetEnvironmentVariableA
TerminateProcess
WriteConsoleA
VirtualQuery
SetEndOfFile
GetCurrentThreadId
InterlockedIncrement
WriteConsoleW
CreateToolhelp32Snapshot
HeapFree
EnterCriticalSection
Process32First
lstrcmpiA
SetEvent
QueryPerformanceCounter
GetTickCount
TlsAlloc
VirtualProtect
GetVersionExA
lstrcmpiW
RtlUnwind
Process32Next
GetStartupInfoA
GetDateFormatA
OpenProcess
GetModuleHandleW
GetProcAddress
GetProcessHeap
CreateFileMappingW
CompareStringW
GetFileSizeEx
ExpandEnvironmentStringsW
CompareStringA
IsValidLocale
WaitForMultipleObjects
CreateEventW
CreateFileW
GetFileType
TlsSetValue
CreateFileA
ExitProcess
LeaveCriticalSection
GetLastError
LCMapStringW
UnmapViewOfFile
GetSystemInfo
lstrlenA
GetConsoleCP
FindResourceW
LCMapStringA
GetEnvironmentStringsW
lstrlenW
SizeofResource
GetCurrentProcessId
LockResource
GetCommandLineW
WideCharToMultiByte
HeapSize
GetCommandLineA
GetCurrentThread
RaiseException
MapViewOfFile
TlsFree
GetModuleHandleA
ReadFile
CloseHandle
GetTimeFormatA
GetACP
GetVersion
GetEnvironmentStrings
IsValidCodePage
HeapCreate
FindResourceExW
VirtualFree
Sleep
VirtualAlloc
ResetEvent
SysFreeString
CharLowerA
SendMessageW
UnregisterClassA
RegisterClassW
GetMessageW
CharUpperW
DefWindowProcW
LoadCursorW
FindWindowExW
CreateWindowExW
TranslateMessage
CharLowerW
CharUpperA
DispatchMessageW
SymInitialize
SymSetOptions
SymFromAddr
Number of PE resources by type
RT_VERSION 1
Number of PE resources by language
ENGLISH US 1
PE resources
Debug information
ExifTool file metadata
UninitializedDataSize
0

InitializedDataSize
2575360

ImageVersion
0.0

ProductName
BlueStacks

FileVersionNumber
0.7.5.2700

LanguageCode
English (U.S.)

FileFlagsMask
0x0001

FileDescription
BlueStacks Block Device Helper Process

CharacterSet
Unicode

LinkerVersion
9.0

FileTypeExtension
exe

OriginalFileName
HD-BlockDevice.exe

MIMEType
application/octet-stream

Subsystem
Windows command line

FileVersion
0.7.5.2700

TimeStamp
2012:09:24 11:34:17+01:00

FileType
Win32 EXE

PEType
PE32

ProductVersion
0.7.5.2700

SubsystemVersion
5.1

OSVersion
5.1

FileOS
Windows NT 32-bit

LegalCopyright
Copyright 2011 BlueStack Systems, Inc. All Rights Reserved.

MachineType
Intel 386 or later, and compatibles

CompanyName
BlueStack Systems

CodeSize
204288

FileSubtype
0

ProductVersionNumber
0.0.0.0

EntryPoint
0x8bd7

ObjectFileType
Executable application

Compressed bundles
File identification
MD5 5260d5fed5b575f960ef4afa26ab6160
SHA1 5b40616d2f401bdb533a456e7650e0c852b7f0de
SHA256 2bcdc0a80d91ec5a91a5efd9f4b899ca55e552d55d1ae3b31fcf8d7f0440cfcf
ssdeep
3072:TL3amq+E2dDCXKnDIpABX6kM1360oguVgnD2w1K0R62Wi5qoHnn+kQe:KmqjIC0MpA6RPoguVgD2iNgq3nr

authentihash d00a1496c5667e1dd045cf608a277aa2b96ba9a87e0d2c3a92c6d1acb330414f
imphash e9f5a9e20d0d7983e2b26c7fdecbbdd6
File size 254.4 KB ( 260472 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (console) Intel 80386 32-bit

TrID Win32 Executable MS Visual C++ (generic) (67.4%)
Win32 Dynamic Link Library (generic) (14.2%)
Win32 Executable (generic) (9.7%)
Generic Win/DOS Executable (4.3%)
DOS Executable Generic (4.3%)
Tags
peexe signed overlay

VirusTotal metadata
First submission 2012-09-29 02:33:32 UTC ( 6 years, 3 months ago )
Last submission 2012-09-29 02:33:32 UTC ( 6 years, 3 months ago )
File names BlockDeviceFile
HD-BlockDevice.exe
HD-BlockDevice.exe
HD-BlockDevice.exe
HD-BlockDevice.exe
HD-BlockDevice.exe
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!
Condensed report! The following is a condensed report of the behaviour of the file when executed in a controlled environment. The actions and events described were either performed by the file itself or by any other process launched by the executed file or subjected to code injection by the executed file.
UDP communications