| File name: | OperaGXSetup.exe |
| Full analysis: | https://app.any.run/tasks/dd1cf1bb-6602-44d0-b822-ff77c80f2fc6 |
| Verdict: | Malicious activity |
| Analysis date: | March 24, 2025, 11:27:44 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | 84868AAA52BBF2D772590B74F67D852E |
| SHA1: | 510CF3CE20B76C8005019036E1ED68311CA05B1B |
| SHA256: | 075A8D125E99F57B2B64D44576EDB6B4C3512E58FDF811AEFAA4696F3C635500 |
| SSDEEP: | 98304:3wyWSeMgtkxdMZTY0N0PrePVrqwz7FmD6uzHj9lzstTvJUC3P8N4VAE6P4GRXiar:3Sk20Pj |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:06:12 14:59:19+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.39 |
| CodeSize: | 238080 |
| InitializedDataSize: | 92672 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x213c0 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 117.0.5408.140 |
| ProductVersionNumber: | 117.0.5408.140 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Unknown |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| FileVersion: | 117.0.5408.140 |
| ProductVersion: | 117.0.5408.140 |
| FileDescription: | Opera installer SFX |
| CompanyName: | |
| LegalCopyright: | Opera Software 2025 |
| Productname: | Opera installer |
| Stream: | Stable |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 4 | System | [System Process] | |||||||||||||
User: SYSTEM Integrity Level: SYSTEM | |||||||||||||||
| 4172 | "BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1 | C:\Windows\System32\BackgroundTransferHost.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Download/Upload Host Exit code: 1 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4428 | "BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1 | C:\Windows\System32\BackgroundTransferHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Download/Upload Host Exit code: 1 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4464 | "C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202503241127541\assistant\Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe" | C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202503241127541\assistant\Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe | setup.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Opera installer SFX Exit code: 0 Version: 73.0.3856.382 Modules
| |||||||||||||||
| 5212 | C:\Users\admin\AppData\Local\Temp\7zS0EC158C0\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktopGX --annotation=ver=117.0.5408.140 --initial-client-data=0x348,0x34c,0x350,0x318,0x354,0x7193d2e4,0x7193d2f0,0x7193d2fc | C:\Users\admin\AppData\Local\Temp\7zS0EC158C0\setup.exe | setup.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera GX Installer Version: 117.0.5408.140 Modules
| |||||||||||||||
| 6424 | "BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1 | C:\Windows\System32\BackgroundTransferHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Download/Upload Host Exit code: 1 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7300 | "BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1 | C:\Windows\System32\BackgroundTransferHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Download/Upload Host Exit code: 1 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7392 | "C:\Users\admin\AppData\Local\Temp\OperaGXSetup.exe" | C:\Users\admin\AppData\Local\Temp\OperaGXSetup.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Opera installer SFX Version: 117.0.5408.140 Modules
| |||||||||||||||
| 7412 | "C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202503241127541\assistant\assistant_installer.exe" --version | C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202503241127541\assistant\assistant_installer.exe | — | setup.exe | |||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera GX Browser Assistant Installer Exit code: 0 Version: 73.0.3856.382 Modules
| |||||||||||||||
| 7420 | C:\Users\admin\AppData\Local\Temp\7zS0EC158C0\setup.exe --server-tracking-blob=NTdiYTFlMzg2ZjUyZjdkYmIzOTNjYTk0M2FhMzE0NzI4MjU2NDA1ZGJmYjMzYWZmYWIwODY2ZDkwMDUxNWM2MTp7ImNvdW50cnkiOiJDQSIsImVkaXRpb24iOiJzdGQtMiIsImh0dHBfcmVmZXJyZXIiOiJodHRwczovL3d3dy5vcGVyYS5jb20vIiwiaW5zdGFsbGVyX25hbWUiOiJPcGVyYUdYU2V0dXAuZXhlIiwicHJvZHVjdCI6Im9wZXJhX2d4IiwicXVlcnkiOiIvb3BlcmFfZ3gvc3RhYmxlL3dpbmRvd3M/ZWRpdGlvbj1zdGQtMiZ1dG1fc291cmNlPVBXTmdhbWVzJnV0bV9tZWRpdW09cGEmdXRtX2NhbXBhaWduPVBXTl9DQV9IVlJfOTU3MV9XRUJfMjYzNiZlZGl0aW9uPXN0ZC0yJnV0bV9pZD05OTUwODU1N2EwMzY0MTdhYTJiYTkxYzk2MTZhYjU4MSZodHRwX3JlZmVycmVyPWh0dHBzJTNBJTJGJTJGd3d3Lm9wZXJhLmNvbSUyRmdldCUyRm9wZXJhLWd4JTNGdXRtX21lZGl1bSUzRHBhJTI2dXRtX2NhbXBhaWduJTNEUFdOX0NBX0hWUl85NTcxX1dFQl8yNjM2JTI2dXRtX2lkJTNEOTk1MDg1NTdhMDM2NDE3YWEyYmE5MWM5NjE2YWI1ODElMjZ1dG1fc291cmNlJTNEUFdOZ2FtZXMlMjZlZGl0aW9uJTNEc3RkLTImdXRtX3NpdGU9b3BlcmFfY29tJnV0bV9sYXN0cGFnZT1vcGVyYS5jb20lMkZnZXQlMkZvcGVyYS1neCZ1dG1faWQ9OTk1MDg1NTdhMDM2NDE3YWEyYmE5MWM5NjE2YWI1ODEmZGxfdG9rZW49NTY2Njg1MzgiLCJ0aW1lc3RhbXAiOiIxNzQyODE1NTA5LjMzOTgiLCJ1c2VyYWdlbnQiOiJNb3ppbGxhLzUuMCAoV2luZG93cyBOVCAxMC4wOyBXaW42NDsgeDY0OyBydjoxMzYuMCkgR2Vja28vMjAxMDAxMDEgRmlyZWZveC8xMzYuMCIsInV0bSI6eyJjYW1wYWlnbiI6IlBXTl9DQV9IVlJfOTU3MV9XRUJfMjYzNiIsImlkIjoiOTk1MDg1NTdhMDM2NDE3YWEyYmE5MWM5NjE2YWI1ODEiLCJsYXN0cGFnZSI6Im9wZXJhLmNvbS9nZXQvb3BlcmEtZ3giLCJtZWRpdW0iOiJwYSIsInNpdGUiOiJvcGVyYV9jb20iLCJzb3VyY2UiOiJQV05nYW1lcyJ9LCJ1dWlkIjoiNjRlMjI2YzMtN2JlYy00NTY2LWJiN2QtZDRiMTQ5MGYwZDdkIn0= | C:\Users\admin\AppData\Local\Temp\7zS0EC158C0\setup.exe | OperaGXSetup.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera GX Installer Version: 117.0.5408.140 Modules
| |||||||||||||||
| (PID) Process: | (7420) setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (7420) setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (7420) setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (7300) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (7300) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (7300) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (4172) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (4172) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (4172) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (6424) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7392 | OperaGXSetup.exe | C:\Users\admin\AppData\Local\Temp\7zS0EC158C0\setup.exe | executable | |
MD5:1DA537C2C9CC107B25BC513A53C8B039 | SHA256:A27B8A1BFBC51B1C1CDCFFCE3DC51854363D1DB7D149FB938BF38B2232B3B8CC | |||
| 7420 | setup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419 | binary | |
MD5:AF3B4625AB697035DC7914EEE1E41834 | SHA256:B675186032BBD9659045928AB1157D21E67E66418D6D2035252760A6D999C123 | |||
| 4172 | BackgroundTransferHost.exe | C:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\c21f3c2f-16cd-49b5-b1cb-fd353fbcca96.down_data | — | |
MD5:— | SHA256:— | |||
| 7420 | setup.exe | C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\setup.exe | executable | |
MD5:1DA537C2C9CC107B25BC513A53C8B039 | SHA256:A27B8A1BFBC51B1C1CDCFFCE3DC51854363D1DB7D149FB938BF38B2232B3B8CC | |||
| 7420 | setup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\26C212D9399727259664BDFCA073966E_B7ED31D77D311A56FDCB56A0083B3E0B | binary | |
MD5:C4819688FC6F0ADA66DA50F651218C28 | SHA256:308FAE68F1155A8BEAB7E9961208F90C2ACA2410BB831EC482747A167CF41D9F | |||
| 7420 | setup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\59D76868C250B3240414CE3EFBB12518_9AD8E6D69BA520C5190A9B86E29789D5 | binary | |
MD5:EC368937EE665094E61544B4A1806E4F | SHA256:E1184C895F22C68C92F311EAEB43763A8B117E99957CA8E66272A92F740A210E | |||
| 7420 | setup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B398B80134F72209547439DB21AB308D_A4CF52CCA82D7458083F7280801A3A04 | binary | |
MD5:12382853C78E003B50F06BD0C4970281 | SHA256:7401A53525D15EF9EFC47E40E782627013347E003E4724553F8AA6ACAE519DC4 | |||
| 7420 | setup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\59D76868C250B3240414CE3EFBB12518_9AD8E6D69BA520C5190A9B86E29789D5 | binary | |
MD5:AF71EE38738874C0BC7D68D7E7664BF3 | SHA256:55E7D095003655084DECCDF2D117C330D12AC1E255092BAA249BE0C42D1CD372 | |||
| 7420 | setup.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\Opera_GX_117.0.5408.140_Autoupdate_x64[1].exe | — | |
MD5:— | SHA256:— | |||
| 7420 | setup.exe | C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202503241127541\opera_package | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.53.40.176:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
7420 | setup.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 23.53.40.176:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
7420 | setup.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAsA6S1NbXMfyjBZx8seGIY%3D | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7420 | setup.exe | GET | 200 | 142.250.185.195:80 | http://c.pki.goog/r/r4.crl | unknown | — | — | whitelisted |
7420 | setup.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnxLiz3Fu1WB6n1%2FE6xWn1b0jXiQQUdIWAwGbH3zfez70pN6oDHb7tzRcCEA17ZgsSl63KHstWnAbUez0%3D | unknown | — | — | whitelisted |
4172 | BackgroundTransferHost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
7420 | setup.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D | unknown | — | — | whitelisted |
7584 | backgroundTaskHost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 23.53.40.176:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
5496 | MoUsoCoreWorker.exe | 23.53.40.176:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
7420 | setup.exe | 82.145.217.121:443 | desktop-netinstaller-sub.osp.opera.software | Opera Software AS | NO | whitelisted |
7420 | setup.exe | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
3216 | svchost.exe | 40.113.110.67:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 20.190.160.14:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
desktop-netinstaller-sub.osp.opera.software |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
autoupdate.opera.com |
| whitelisted |
features.opera-api2.com |
| malicious |
api.config.opr.gg |
| unknown |