bluestacks.exe

Smart Secure Software S.l.

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application bluestacks.exe by Smart Secure Software S.l has been detected as adware by 20 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer. The file has been seen being downloaded from ttb.files101.com.
Publisher:
Smart Secure Software S.l.  (signed and verified)

Version:
2.20.30.11

MD5:
425b09b64931875ff2077410c7e27a70

SHA-1:
b32e04be35b3c07ca0c98a1fbe483a4dcfdad6f8

SHA-256:
9fad0e8108467c4c8557aa1484aefcc7ff4cd5c538b136962c01e1738d53edbe

Scanner detections:
20 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/1/2025 3:18:44 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Graftor.162591
823

AhnLab V3 Security
PUP/Win32.SoftPulse
2014.11.04

Avira AntiVirus
APPL/Softpulse.O
7.11.182.228

avast!
Win32:Malware-gen
141025-0

AVG
Found Win32/DH{gRIxflCBB3lUTxVRgQkcU4ET}
2014.0.4189

Bitdefender
Gen:Variant.Adware.Graftor.162591
1.0.20.1535

Comodo Security
Application.Win32.DomaIQ.FSX
19984

Dr.Web
Trojan.DownLoader11.36367
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.162591
8.14.11.03.12

ESET NOD32
Win32/SoftPulse (variant)
8.10663

G Data
Gen:Variant.Adware.Graftor.162591
14.11.24

IKARUS anti.virus
Backdoor.Win32.Ruskill
t3scan.1.8.3.0

K7 AntiVirus
Unwanted-Program
13.185.13888

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.3002

Malwarebytes
PUP.Optional.DomaIQ
v2014.11.03.12

McAfee
Socrydo
5600.6957

NANO AntiVirus
Trojan.Win32.Agent.dhzclw
0.28.6.62995

Norman
Malware
11.20141103

Reason Heuristics
PUP.SmartSecureSoftwareSl.K
14.11.3.12

VIPRE Antivirus
Threat.4783235
34232

File size:
772.5 KB (791,000 bytes)

Product version:
2.20.30.11

Copyright:
Copyright (C) 2014

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Language:
English

Common path:
C:\users\{user}\downloads\bluestacks.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/16/2014 7:00:00 PM

Valid to:
6/17/2015 6:59:59 PM

Subject:
CN=Smart Secure Software S.l., O=Smart Secure Software S.l., L=Adeje, S=Santa Cruz de Tenerife, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
47353B4EEC0D902A135E20BEE1A66817

File PE Metadata
Compilation timestamp:
10/31/2014 11:07:50 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:5VCSFSEvZIZvYrsUwkwxizgPsYmBwolM+e5KLehq/JZZtcaC0fBPsSpBI:57SKoUXwkRMCK5oKqBxcaCGsiI

Entry address:
0x7E36

Entry point:
E8, 9D, 5F, 00, 00, E9, 7F, FE, FF, FF, E9, 3D, 0D, 00, 00, 55, 8B, EC, 83, EC, 10, EB, 0D, FF, 75, 08, E8, 64, 61, 00, 00, 59, 85, C0, 74, 0F, FF, 75, 08, E8, CD, 2B, 00, 00, 59, 85, C0, 74, E6, C9, C3, 6A, 01, 8D, 45, FC, 50, 8D, 4D, F0, C7, 45, FC, 30, 2C, 45, 00, E8, 70, 2F, 00, 00, 68, F0, 93, 45, 00, 8D, 45, F0, 50, C7, 45, F0, 28, 2C, 45, 00, E8, A7, 25, 00, 00, CC, 55, 8B, EC, 8B, 45, 08, 66, 8B, 08, 83, C0, 02, 66, 85, C9, 75, F5, 2B, 45, 08, D1, F8, 48, 5D, C3, CC, CC, CC, 57, 56, 8B, 74, 24, 10...
 
[+]

Entropy:
7.5212

Code size:
85 KB (87,040 bytes)

The file bluestacks.exe has been seen being distributed by the following URL.

Remove bluestacks.exe - Powered by Reason Core Security