URL:

winningcompetition.weebly.com

Full analysis: https://app.any.run/tasks/d01b26fe-8257-4d95-a3a6-e0efae1c3317
Verdict: Malicious activity
Analysis date: November 22, 2023, 20:33:40
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
qrcode
Indicators:
SHA1:

95C33FB66E11FA0BFD1B9549FF0AAC06DB04908B

SHA256:

0D251383F0838D3B52763DB67F52FBF1FC481202990EA95E801264ACBFEF5F4A

SSDEEP:

3:cLCKV0QMQ3nLdI:DQMQ3nZI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • Opera_95.0.4635.90_Setup.exe (PID: 3708)
      • Opera_95.0.4635.90_Setup.exe (PID: 3760)
      • Opera_95.0.4635.90_Setup.exe (PID: 148)
      • Opera_95.0.4635.90_Setup.exe (PID: 1996)
      • Opera_95.0.4635.90_Setup.exe (PID: 1644)
      • Opera_95.0.4635.90_Setup.exe (PID: 2292)
      • assistant_installer.exe (PID: 668)
      • assistant_installer.exe (PID: 1876)
      • installer.exe (PID: 368)
      • installer.exe (PID: 2396)
      • assistant_installer.exe (PID: 2868)
      • assistant_installer.exe (PID: 2884)
      • assistant_installer.exe (PID: 3100)
      • assistant_installer.exe (PID: 3148)
      • browser_assistant.exe (PID: 3088)
      • browser_assistant.exe (PID: 2492)
      • installer.exe (PID: 3624)
      • installer.exe (PID: 3908)
      • assistant_installer.exe (PID: 3240)
      • opera_crashreporter.exe (PID: 2936)
      • assistant_installer.exe (PID: 3632)
      • opera.exe (PID: 1452)
      • opera.exe (PID: 3876)
      • opera.exe (PID: 2804)
      • opera.exe (PID: 1604)
      • opera.exe (PID: 1808)
      • opera.exe (PID: 600)
      • opera.exe (PID: 1352)
      • opera.exe (PID: 1152)
      • opera.exe (PID: 1608)
      • opera.exe (PID: 316)
      • opera.exe (PID: 1356)
      • opera.exe (PID: 556)
      • opera.exe (PID: 3320)
      • opera.exe (PID: 2672)
      • opera.exe (PID: 1820)
      • opera.exe (PID: 1660)
      • opera.exe (PID: 3800)
      • opera.exe (PID: 668)
      • opera.exe (PID: 2080)
      • opera.exe (PID: 1344)
      • opera.exe (PID: 2392)
      • opera.exe (PID: 1876)
      • opera.exe (PID: 1584)
      • opera.exe (PID: 120)
      • opera.exe (PID: 2408)
      • opera.exe (PID: 1868)
      • opera.exe (PID: 3000)
      • opera.exe (PID: 2532)
      • opera.exe (PID: 276)
      • opera.exe (PID: 2620)
      • opera_autoupdate.exe (PID: 1452)
      • opera.exe (PID: 3336)
      • opera_autoupdate.exe (PID: 4004)
      • opera.exe (PID: 1212)
      • opera.exe (PID: 3480)
      • opera.exe (PID: 2396)
      • opera.exe (PID: 2860)
      • opera.exe (PID: 2632)
      • opera.exe (PID: 2400)
      • opera.exe (PID: 3348)
      • opera.exe (PID: 2464)
      • opera.exe (PID: 1228)
      • opera.exe (PID: 1236)
      • opera.exe (PID: 916)
      • opera.exe (PID: 3528)
      • opera.exe (PID: 1152)
      • opera.exe (PID: 2628)
      • opera.exe (PID: 2108)
      • opera.exe (PID: 1432)
      • opera.exe (PID: 1700)
      • opera.exe (PID: 3192)
      • opera.exe (PID: 2620)
      • opera.exe (PID: 3472)
      • opera.exe (PID: 2464)
      • opera.exe (PID: 3796)
      • opera.exe (PID: 3552)
      • opera.exe (PID: 4012)
      • opera.exe (PID: 3236)
      • opera.exe (PID: 3912)
      • opera.exe (PID: 3636)
      • opera.exe (PID: 3804)
      • opera.exe (PID: 1348)
      • opera.exe (PID: 3512)
      • opera.exe (PID: 2824)
      • opera.exe (PID: 3796)
      • opera.exe (PID: 2640)
      • opera.exe (PID: 2428)
      • opera.exe (PID: 3924)
      • opera.exe (PID: 3564)
      • opera.exe (PID: 2396)
      • opera.exe (PID: 3192)
      • opera.exe (PID: 2096)
      • opera.exe (PID: 3468)
      • opera.exe (PID: 1360)
      • opera.exe (PID: 2792)
      • opera.exe (PID: 2176)
      • opera.exe (PID: 2108)
      • opera.exe (PID: 148)
      • opera.exe (PID: 3564)
      • opera.exe (PID: 3440)
      • opera.exe (PID: 3732)
      • opera.exe (PID: 1416)
      • opera.exe (PID: 2688)
      • opera.exe (PID: 4080)
      • opera.exe (PID: 3912)
      • opera.exe (PID: 3896)
      • opera.exe (PID: 3592)
      • opera.exe (PID: 4008)
      • opera.exe (PID: 1184)
      • opera.exe (PID: 1008)
      • opera.exe (PID: 3960)
    • Drops the executable file immediately after the start

      • Opera_95.0.4635.90_Setup.exe (PID: 3760)
      • Opera_95.0.4635.90_Setup.exe (PID: 3560)
      • Opera_95.0.4635.90_Setup.exe (PID: 148)
      • Opera_95.0.4635.90_Setup.exe (PID: 1996)
      • Opera_95.0.4635.90_Setup.exe (PID: 2292)
      • Opera_95.0.4635.90_Setup.exe (PID: 1644)
      • Opera_95.0.4635.90_Setup.exe (PID: 3708)
      • assistant_package_sfx.exe (PID: 2780)
      • installer.exe (PID: 2396)
      • installer.exe (PID: 368)
      • assistant_installer.exe (PID: 2868)
      • installer.exe (PID: 3624)
      • installer.exe (PID: 3908)
      • installer.exe (PID: 2444)
      • launcher.exe (PID: 528)
      • opera_autoupdate.exe (PID: 1928)
      • installer.exe (PID: 2632)
      • opera.exe (PID: 2672)
  • SUSPICIOUS

    • Application launched itself

      • Opera_95.0.4635.90_Setup.exe (PID: 3708)
      • Opera_95.0.4635.90_Setup.exe (PID: 148)
      • Opera_95.0.4635.90_Setup.exe (PID: 1644)
      • assistant_installer.exe (PID: 1876)
      • installer.exe (PID: 368)
      • assistant_installer.exe (PID: 3148)
      • assistant_installer.exe (PID: 2868)
      • browser_assistant.exe (PID: 3088)
      • installer.exe (PID: 3624)
      • assistant_installer.exe (PID: 3240)
      • opera.exe (PID: 2672)
      • opera_autoupdate.exe (PID: 1452)
      • opera_autoupdate.exe (PID: 1928)
    • Reads the Internet Settings

      • Opera_95.0.4635.90_Setup.exe (PID: 3708)
      • Opera_95.0.4635.90_Setup.exe (PID: 148)
      • browser_assistant.exe (PID: 3088)
      • opera.exe (PID: 2672)
      • opera_autoupdate.exe (PID: 1452)
      • opera_autoupdate.exe (PID: 1928)
      • opera.exe (PID: 1184)
    • Starts itself from another location

      • Opera_95.0.4635.90_Setup.exe (PID: 3708)
    • Checks Windows Trust Settings

      • Opera_95.0.4635.90_Setup.exe (PID: 3708)
      • installer.exe (PID: 368)
      • browser_assistant.exe (PID: 3088)
    • Reads security settings of Internet Explorer

      • Opera_95.0.4635.90_Setup.exe (PID: 3708)
      • installer.exe (PID: 368)
      • browser_assistant.exe (PID: 3088)
    • Reads settings of System Certificates

      • Opera_95.0.4635.90_Setup.exe (PID: 3708)
      • installer.exe (PID: 368)
      • browser_assistant.exe (PID: 3088)
      • opera.exe (PID: 2672)
    • The process executes via Task Scheduler

      • launcher.exe (PID: 528)
    • Connects to unusual port

      • opera.exe (PID: 2804)
  • INFO

    • Checks supported languages

      • wmpnscfg.exe (PID: 3412)
      • Opera_95.0.4635.90_Setup.exe (PID: 3708)
      • Opera_95.0.4635.90_Setup.exe (PID: 3760)
      • Opera_95.0.4635.90_Setup.exe (PID: 148)
      • Opera_95.0.4635.90_Setup.exe (PID: 3560)
      • Opera_95.0.4635.90_Setup.exe (PID: 1996)
      • Opera_95.0.4635.90_Setup.exe (PID: 1644)
      • Opera_95.0.4635.90_Setup.exe (PID: 2292)
      • assistant_package_sfx.exe (PID: 2780)
      • assistant_installer.exe (PID: 1876)
      • installer.exe (PID: 368)
      • installer.exe (PID: 2396)
      • assistant_installer.exe (PID: 668)
      • assistant_installer.exe (PID: 2884)
      • assistant_installer.exe (PID: 3148)
      • assistant_installer.exe (PID: 3100)
      • browser_assistant.exe (PID: 3088)
      • launcher.exe (PID: 3056)
      • assistant_installer.exe (PID: 2868)
      • browser_assistant.exe (PID: 2492)
      • launcher.exe (PID: 968)
      • installer.exe (PID: 3624)
      • launcher.exe (PID: 3832)
      • launcher.exe (PID: 3276)
      • launcher.exe (PID: 3364)
      • installer.exe (PID: 3908)
      • assistant_installer.exe (PID: 3240)
      • launcher.exe (PID: 4044)
      • assistant_installer.exe (PID: 3632)
      • opera.exe (PID: 2672)
      • opera_crashreporter.exe (PID: 2936)
      • opera.exe (PID: 2804)
      • opera.exe (PID: 3876)
      • opera.exe (PID: 1608)
      • opera.exe (PID: 1808)
      • opera.exe (PID: 1452)
      • opera.exe (PID: 316)
      • opera.exe (PID: 1352)
      • opera.exe (PID: 1152)
      • opera.exe (PID: 1604)
      • opera.exe (PID: 2248)
      • opera.exe (PID: 556)
      • opera.exe (PID: 1356)
      • opera.exe (PID: 600)
      • opera.exe (PID: 1660)
      • opera.exe (PID: 1820)
      • opera.exe (PID: 1344)
      • opera.exe (PID: 3320)
      • opera.exe (PID: 2080)
      • opera.exe (PID: 3800)
      • opera.exe (PID: 1584)
      • opera.exe (PID: 2392)
      • opera.exe (PID: 120)
      • opera.exe (PID: 668)
      • opera.exe (PID: 1876)
      • opera.exe (PID: 2860)
      • opera.exe (PID: 1868)
      • opera.exe (PID: 3000)
      • opera.exe (PID: 1212)
      • opera.exe (PID: 276)
      • opera.exe (PID: 3336)
      • opera.exe (PID: 1700)
      • opera.exe (PID: 2620)
      • opera.exe (PID: 3348)
      • opera.exe (PID: 2408)
      • opera.exe (PID: 1228)
      • opera.exe (PID: 2532)
      • opera.exe (PID: 2628)
      • opera.exe (PID: 1432)
      • opera.exe (PID: 2396)
      • opera.exe (PID: 2400)
      • opera.exe (PID: 2632)
      • opera.exe (PID: 2108)
      • opera.exe (PID: 3480)
      • opera.exe (PID: 2464)
      • opera.exe (PID: 3528)
      • opera.exe (PID: 1236)
      • opera.exe (PID: 3192)
      • opera.exe (PID: 916)
      • launcher.exe (PID: 528)
      • opera.exe (PID: 1152)
      • opera_autoupdate.exe (PID: 4004)
      • opera.exe (PID: 3472)
      • opera_autoupdate.exe (PID: 1452)
      • opera_autoupdate.exe (PID: 1928)
      • opera.exe (PID: 2620)
      • installer.exe (PID: 2444)
      • opera_autoupdate.exe (PID: 1560)
      • opera.exe (PID: 2464)
      • opera.exe (PID: 3796)
      • opera.exe (PID: 3552)
      • opera.exe (PID: 3636)
      • opera.exe (PID: 3236)
      • opera.exe (PID: 4012)
      • opera.exe (PID: 3804)
      • opera.exe (PID: 3912)
      • opera.exe (PID: 1348)
      • opera.exe (PID: 3512)
      • opera.exe (PID: 3924)
      • opera.exe (PID: 2824)
      • opera.exe (PID: 3796)
      • opera.exe (PID: 2640)
      • opera.exe (PID: 2428)
      • opera.exe (PID: 2096)
      • opera.exe (PID: 3192)
      • installer.exe (PID: 2632)
      • opera.exe (PID: 3564)
      • opera.exe (PID: 2396)
      • opera.exe (PID: 1360)
      • opera.exe (PID: 2108)
      • opera.exe (PID: 2792)
      • opera.exe (PID: 2176)
      • opera.exe (PID: 148)
      • opera.exe (PID: 3468)
      • opera.exe (PID: 3440)
      • opera.exe (PID: 2688)
      • opera.exe (PID: 3732)
      • opera.exe (PID: 1416)
      • opera.exe (PID: 3564)
      • opera.exe (PID: 4080)
      • opera.exe (PID: 3912)
      • opera.exe (PID: 3896)
      • opera.exe (PID: 3592)
      • opera.exe (PID: 4008)
      • opera.exe (PID: 3960)
      • opera.exe (PID: 1184)
      • opera.exe (PID: 1008)
    • Application launched itself

      • iexplore.exe (PID: 3448)
    • Reads the computer name

      • wmpnscfg.exe (PID: 3412)
      • Opera_95.0.4635.90_Setup.exe (PID: 3708)
      • Opera_95.0.4635.90_Setup.exe (PID: 148)
      • Opera_95.0.4635.90_Setup.exe (PID: 1644)
      • assistant_installer.exe (PID: 1876)
      • installer.exe (PID: 368)
      • assistant_installer.exe (PID: 2868)
      • assistant_installer.exe (PID: 3148)
      • browser_assistant.exe (PID: 3088)
      • installer.exe (PID: 3624)
      • assistant_installer.exe (PID: 3240)
      • opera.exe (PID: 2672)
      • launcher.exe (PID: 4044)
      • opera.exe (PID: 3876)
      • opera.exe (PID: 2804)
      • opera.exe (PID: 1608)
      • opera.exe (PID: 600)
      • opera.exe (PID: 1452)
      • opera.exe (PID: 1352)
      • opera.exe (PID: 316)
      • opera.exe (PID: 1152)
      • opera.exe (PID: 1604)
      • opera.exe (PID: 1660)
      • opera.exe (PID: 2248)
      • opera.exe (PID: 556)
      • opera.exe (PID: 1808)
      • opera.exe (PID: 1356)
      • opera.exe (PID: 1344)
      • opera.exe (PID: 3320)
      • opera.exe (PID: 2080)
      • opera.exe (PID: 1820)
      • opera.exe (PID: 1584)
      • opera.exe (PID: 1876)
      • opera.exe (PID: 3800)
      • opera.exe (PID: 120)
      • opera.exe (PID: 2392)
      • opera.exe (PID: 668)
      • opera.exe (PID: 3348)
      • opera.exe (PID: 1868)
      • opera.exe (PID: 3000)
      • opera.exe (PID: 2860)
      • opera.exe (PID: 276)
      • opera.exe (PID: 3336)
      • opera.exe (PID: 1212)
      • opera.exe (PID: 2628)
      • opera.exe (PID: 2408)
      • opera.exe (PID: 2532)
      • opera.exe (PID: 2396)
      • opera.exe (PID: 1228)
      • opera.exe (PID: 1432)
      • opera.exe (PID: 2400)
      • opera.exe (PID: 1700)
      • opera.exe (PID: 2620)
      • opera.exe (PID: 3480)
      • opera.exe (PID: 2464)
      • opera.exe (PID: 2632)
      • opera.exe (PID: 2108)
      • opera.exe (PID: 3192)
      • opera.exe (PID: 916)
      • opera.exe (PID: 1236)
      • opera.exe (PID: 3528)
      • opera.exe (PID: 1152)
      • opera.exe (PID: 3472)
      • opera_autoupdate.exe (PID: 1452)
      • opera_autoupdate.exe (PID: 1928)
      • opera.exe (PID: 2464)
      • opera.exe (PID: 3796)
      • opera.exe (PID: 3552)
      • opera.exe (PID: 3636)
      • opera.exe (PID: 2620)
      • opera.exe (PID: 4012)
      • opera.exe (PID: 3804)
      • opera.exe (PID: 3512)
      • opera.exe (PID: 3236)
      • opera.exe (PID: 3912)
      • opera.exe (PID: 1348)
      • opera.exe (PID: 2824)
      • opera.exe (PID: 3796)
      • opera.exe (PID: 2640)
      • opera.exe (PID: 2428)
      • opera.exe (PID: 2096)
      • opera.exe (PID: 3924)
      • opera.exe (PID: 2396)
      • opera.exe (PID: 3192)
      • opera.exe (PID: 3564)
      • opera.exe (PID: 3468)
      • opera.exe (PID: 1360)
      • opera.exe (PID: 2792)
      • opera.exe (PID: 2176)
      • opera.exe (PID: 3440)
      • opera.exe (PID: 2108)
      • opera.exe (PID: 3564)
      • opera.exe (PID: 3732)
      • opera.exe (PID: 2688)
      • opera.exe (PID: 4080)
      • opera.exe (PID: 148)
      • opera.exe (PID: 1416)
      • opera.exe (PID: 3912)
      • opera.exe (PID: 3896)
      • opera.exe (PID: 3592)
      • opera.exe (PID: 4008)
      • opera.exe (PID: 3960)
      • opera.exe (PID: 1184)
      • opera.exe (PID: 1008)
    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 3412)
      • Opera_95.0.4635.90_Setup.exe (PID: 3708)
      • installer.exe (PID: 368)
      • assistant_installer.exe (PID: 2868)
      • browser_assistant.exe (PID: 3088)
      • installer.exe (PID: 3624)
      • opera.exe (PID: 2672)
      • opera_autoupdate.exe (PID: 4004)
      • opera_autoupdate.exe (PID: 1452)
      • opera_autoupdate.exe (PID: 1560)
      • opera.exe (PID: 2620)
      • opera_autoupdate.exe (PID: 1928)
      • opera.exe (PID: 3912)
      • opera.exe (PID: 1184)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3412)
      • assistant_installer.exe (PID: 3148)
    • The process uses the downloaded file

      • iexplore.exe (PID: 3448)
      • Opera_95.0.4635.90_Setup.exe (PID: 3708)
      • Opera_95.0.4635.90_Setup.exe (PID: 148)
    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 3484)
    • Create files in a temporary directory

      • Opera_95.0.4635.90_Setup.exe (PID: 3708)
      • Opera_95.0.4635.90_Setup.exe (PID: 3760)
      • Opera_95.0.4635.90_Setup.exe (PID: 3560)
      • Opera_95.0.4635.90_Setup.exe (PID: 148)
      • Opera_95.0.4635.90_Setup.exe (PID: 1996)
      • Opera_95.0.4635.90_Setup.exe (PID: 1644)
      • Opera_95.0.4635.90_Setup.exe (PID: 2292)
      • assistant_package_sfx.exe (PID: 2780)
      • installer.exe (PID: 368)
      • installer.exe (PID: 2396)
      • installer.exe (PID: 3624)
      • installer.exe (PID: 3908)
      • opera.exe (PID: 2672)
      • launcher.exe (PID: 528)
      • opera_autoupdate.exe (PID: 1560)
      • opera_autoupdate.exe (PID: 1928)
      • installer.exe (PID: 2444)
      • installer.exe (PID: 2632)
    • Creates files or folders in the user directory

      • Opera_95.0.4635.90_Setup.exe (PID: 3760)
      • Opera_95.0.4635.90_Setup.exe (PID: 3708)
      • installer.exe (PID: 368)
      • browser_assistant.exe (PID: 3088)
      • opera.exe (PID: 2672)
      • opera.exe (PID: 2804)
    • Checks proxy server information

      • Opera_95.0.4635.90_Setup.exe (PID: 3708)
      • browser_assistant.exe (PID: 3088)
    • Creates files in the program directory

      • Opera_95.0.4635.90_Setup.exe (PID: 1644)
      • installer.exe (PID: 368)
      • assistant_installer.exe (PID: 2868)
      • opera_autoupdate.exe (PID: 1928)
    • Process checks computer location settings

      • opera.exe (PID: 2672)
      • opera.exe (PID: 1604)
      • opera.exe (PID: 1356)
      • opera.exe (PID: 3320)
      • opera.exe (PID: 556)
      • opera.exe (PID: 1820)
      • opera.exe (PID: 1660)
      • opera.exe (PID: 668)
      • opera.exe (PID: 1344)
      • opera.exe (PID: 2392)
      • opera.exe (PID: 1584)
      • opera.exe (PID: 120)
      • opera.exe (PID: 1876)
      • opera.exe (PID: 3512)
      • opera.exe (PID: 3236)
      • opera.exe (PID: 2428)
      • opera.exe (PID: 3564)
      • opera.exe (PID: 2396)
      • opera.exe (PID: 3192)
      • opera.exe (PID: 2096)
      • opera.exe (PID: 3468)
      • opera.exe (PID: 3896)
      • opera.exe (PID: 3592)
      • opera.exe (PID: 4008)
      • opera.exe (PID: 3960)
    • Reads CPU info

      • opera.exe (PID: 2672)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
176
Monitored processes
129
Malicious processes
31
Suspicious processes
3

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe wmpnscfg.exe no specs opera_95.0.4635.90_setup.exe opera_95.0.4635.90_setup.exe opera_95.0.4635.90_setup.exe no specs opera_95.0.4635.90_setup.exe opera_95.0.4635.90_setup.exe opera_95.0.4635.90_setup.exe opera_95.0.4635.90_setup.exe assistant_package_sfx.exe no specs assistant_installer.exe assistant_installer.exe installer.exe installer.exe assistant_installer.exe assistant_installer.exe assistant_installer.exe assistant_installer.exe browser_assistant.exe launcher.exe no specs browser_assistant.exe launcher.exe no specs launcher.exe no specs installer.exe launcher.exe no specs launcher.exe no specs installer.exe assistant_installer.exe launcher.exe no specs assistant_installer.exe opera.exe opera_crashreporter.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe no specs opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera_autoupdate.exe launcher.exe no specs opera.exe opera.exe opera_autoupdate.exe installer.exe no specs opera_autoupdate.exe opera_autoupdate.exe no specs opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe installer.exe no specs opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe

Process information

PID
CMD
Path
Indicators
Parent process
120"C:\Program Files\Opera\opera.exe" --type=renderer --extension-process --with-feature:aliexpress-modal=off --with-feature:amazon-new-ids=on --with-feature:cashback=on --with-feature:continue-on-booking=on --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-structured-partners=on --with-feature:extended-unstoppable-domains=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:game-maker-studio-integration=on --with-feature:gaming-api=on --with-feature:lucid-mode-hide-text=on --with-feature:native-crypto-wallet=on --with-feature:personalized-speeddials=on --with-feature:premium-valve-in=on --with-feature:proxy-switcher-ui-default-visible=on --with-feature:sd-suggestions-external=on --with-feature:shopping-corner=on --with-feature:sitecheck-age=on --with-feature:specific-keywords=on --with-feature:startpage-sync-banner=on --with-feature:installer-experiment-test=off --with-feature:installer-bypass-launcher=off --with-feature:installer-one-version-one-subfolder=off --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=22 --mojo-platform-channel-handle=4500 --field-trial-handle=1108,i,8836380703062188607,5838043566341095726,131072 /prefetch:1C:\Program Files\Opera\opera.exe
opera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Exit code:
0
Version:
95.0.4635.90
Modules
Images
c:\program files\opera\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\opera\95.0.4635.90\opera_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
148"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\Opera_95.0.4635.90_Setup.exe" --backend --install --import-browser-data=0 --enable-stats=1 --enable-installer-stats=1 --consent-given=1 --general-interests=1 --general-location=1 --personalized-content=1 --personalized-ads=1 --launchopera=1 --installfolder="C:\Program Files\Opera" --profile-folder --language=en --singleprofile=0 --copyonly=0 --allusers=0 --setdefaultbrowser=1 --pintotaskbar=1 --pintostartmenu=1 --pin-additional-shortcuts=1 --run-at-startup=1 --server-tracking-data=server_tracking_data --initial-pid=3708 --package-dir-prefix="C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_20231122203543" --session-guid=64feb958-5019-4ab7-97cb-410a0b476272 --desktopshortcut=1 --wait-for-package --initial-proc-handle=3C06000000000000C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\Opera_95.0.4635.90_Setup.exe
Opera_95.0.4635.90_Setup.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera Installer
Exit code:
0
Version:
95.0.4635.90
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\po2hn1x2\opera_95.0.4635.90_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
148"C:\Program Files\Opera\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --enable-quic --with-feature:aliexpress-modal=off --with-feature:amazon-new-ids=on --with-feature:cashback=on --with-feature:continue-on-booking=on --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-structured-partners=on --with-feature:extended-unstoppable-domains=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:game-maker-studio-integration=on --with-feature:gaming-api=on --with-feature:lucid-mode-hide-text=on --with-feature:native-crypto-wallet=on --with-feature:personalized-speeddials=on --with-feature:premium-valve-in=on --with-feature:proxy-switcher-ui-default-visible=on --with-feature:sd-suggestions-external=on --with-feature:shopping-corner=on --with-feature:sitecheck-age=on --with-feature:specific-keywords=on --with-feature:startpage-sync-banner=on --with-feature:installer-experiment-test=off --with-feature:installer-bypass-launcher=off --with-feature:installer-one-version-one-subfolder=off --mojo-platform-channel-handle=648 --field-trial-handle=1108,i,8836380703062188607,5838043566341095726,131072 /prefetch:8C:\Program Files\Opera\opera.exe
opera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Exit code:
0
Version:
95.0.4635.90
Modules
Images
c:\program files\opera\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\opera\95.0.4635.90\opera_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
276"C:\Program Files\Opera\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --enable-quic --with-feature:aliexpress-modal=off --with-feature:amazon-new-ids=on --with-feature:cashback=on --with-feature:continue-on-booking=on --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-structured-partners=on --with-feature:extended-unstoppable-domains=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:game-maker-studio-integration=on --with-feature:gaming-api=on --with-feature:lucid-mode-hide-text=on --with-feature:native-crypto-wallet=on --with-feature:personalized-speeddials=on --with-feature:premium-valve-in=on --with-feature:proxy-switcher-ui-default-visible=on --with-feature:sd-suggestions-external=on --with-feature:shopping-corner=on --with-feature:sitecheck-age=on --with-feature:specific-keywords=on --with-feature:startpage-sync-banner=on --with-feature:installer-experiment-test=off --with-feature:installer-bypass-launcher=off --with-feature:installer-one-version-one-subfolder=off --mojo-platform-channel-handle=3992 --field-trial-handle=1108,i,8836380703062188607,5838043566341095726,131072 /prefetch:8C:\Program Files\Opera\opera.exe
opera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Exit code:
0
Version:
95.0.4635.90
Modules
Images
c:\program files\opera\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\opera\95.0.4635.90\opera_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
316"C:\Program Files\Opera\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --enable-quic --with-feature:aliexpress-modal=off --with-feature:amazon-new-ids=on --with-feature:cashback=on --with-feature:continue-on-booking=on --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-structured-partners=on --with-feature:extended-unstoppable-domains=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:game-maker-studio-integration=on --with-feature:gaming-api=on --with-feature:lucid-mode-hide-text=on --with-feature:native-crypto-wallet=on --with-feature:personalized-speeddials=on --with-feature:premium-valve-in=on --with-feature:proxy-switcher-ui-default-visible=on --with-feature:sd-suggestions-external=on --with-feature:shopping-corner=on --with-feature:sitecheck-age=on --with-feature:specific-keywords=on --with-feature:startpage-sync-banner=on --with-feature:installer-experiment-test=off --with-feature:installer-bypass-launcher=off --with-feature:installer-one-version-one-subfolder=off --mojo-platform-channel-handle=2024 --field-trial-handle=1108,i,8836380703062188607,5838043566341095726,131072 /prefetch:8C:\Program Files\Opera\opera.exe
opera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Exit code:
0
Version:
95.0.4635.90
Modules
Images
c:\program files\opera\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\opera\95.0.4635.90\opera_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
368"C:\Program Files\Opera\95.0.4635.90\installer.exe" --backend --initial-pid=3708 --install --import-browser-data=0 --enable-stats=1 --enable-installer-stats=1 --consent-given=1 --general-interests=1 --general-location=1 --personalized-content=1 --personalized-ads=1 --launchopera=0 --installfolder="C:\Program Files\Opera" --profile-folder --language=en --singleprofile=0 --copyonly=0 --allusers=0 --setdefaultbrowser=1 --pintotaskbar=1 --pintostartmenu=1 --pin-additional-shortcuts=1 --run-at-startup=1 --server-tracking-data=server_tracking_data --package-dir="C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202311222035431" --session-guid=64feb958-5019-4ab7-97cb-410a0b476272 --desktopshortcut=1 --install-subfolder=95.0.4635.90 --parent-pid=148C:\Program Files\Opera\95.0.4635.90\installer.exe
Opera_95.0.4635.90_Setup.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera Installer
Exit code:
0
Version:
95.0.4635.90
Modules
Images
c:\program files\opera\95.0.4635.90\installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
528"C:\Program Files\Opera\launcher.exe" --scheduledautoupdate --autoupdaterequesttype=automatic --autoupdateoperaversion=95.0.4635.90 --newautoupdaterlogicC:\Program Files\Opera\launcher.exetaskeng.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera Internet Browser
Exit code:
0
Version:
95.0.4635.90
Modules
Images
c:\program files\opera\launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\oleaut32.dll
556"C:\Program Files\Opera\opera.exe" --type=renderer --with-feature:aliexpress-modal=off --with-feature:amazon-new-ids=on --with-feature:cashback=on --with-feature:continue-on-booking=on --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-structured-partners=on --with-feature:extended-unstoppable-domains=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:game-maker-studio-integration=on --with-feature:gaming-api=on --with-feature:lucid-mode-hide-text=on --with-feature:native-crypto-wallet=on --with-feature:personalized-speeddials=on --with-feature:premium-valve-in=on --with-feature:proxy-switcher-ui-default-visible=on --with-feature:sd-suggestions-external=on --with-feature:shopping-corner=on --with-feature:sitecheck-age=on --with-feature:specific-keywords=on --with-feature:startpage-sync-banner=on --with-feature:installer-experiment-test=off --with-feature:installer-bypass-launcher=off --with-feature:installer-one-version-one-subfolder=off --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=14 --mojo-platform-channel-handle=2964 --field-trial-handle=1108,i,8836380703062188607,5838043566341095726,131072 /prefetch:1C:\Program Files\Opera\opera.exe
opera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Exit code:
0
Version:
95.0.4635.90
Modules
Images
c:\program files\opera\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\opera\95.0.4635.90\opera_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
600"C:\Program Files\Opera\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --enable-quic --with-feature:aliexpress-modal=off --with-feature:amazon-new-ids=on --with-feature:cashback=on --with-feature:continue-on-booking=on --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-structured-partners=on --with-feature:extended-unstoppable-domains=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:game-maker-studio-integration=on --with-feature:gaming-api=on --with-feature:lucid-mode-hide-text=on --with-feature:native-crypto-wallet=on --with-feature:personalized-speeddials=on --with-feature:premium-valve-in=on --with-feature:proxy-switcher-ui-default-visible=on --with-feature:sd-suggestions-external=on --with-feature:shopping-corner=on --with-feature:sitecheck-age=on --with-feature:specific-keywords=on --with-feature:startpage-sync-banner=on --with-feature:installer-experiment-test=off --with-feature:installer-bypass-launcher=off --with-feature:installer-one-version-one-subfolder=off --mojo-platform-channel-handle=2000 --field-trial-handle=1108,i,8836380703062188607,5838043566341095726,131072 /prefetch:8C:\Program Files\Opera\opera.exe
opera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Exit code:
0
Version:
95.0.4635.90
Modules
Images
c:\program files\opera\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\opera\95.0.4635.90\opera_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
668"C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202311222035431\assistant\assistant_installer.exe" --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector.opera.com/collector/submit --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktop --annotation=ver=95.0.4635.90 --initial-client-data=0x120,0x124,0x128,0xf4,0x12c,0x1334bd0,0x1334be0,0x1334becC:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202311222035431\assistant\assistant_installer.exe
assistant_installer.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera Browser Assistant Installer
Exit code:
0
Version:
95.0.4635.90
Modules
Images
c:\users\admin\appdata\local\temp\.opera\opera installer temp\opera_package_202311222035431\assistant\assistant_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\oleaut32.dll
Total events
49 953
Read events
49 639
Write events
285
Delete events
29

Modification events

(PID) Process:(3448) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(3448) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(3448) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(3448) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3448) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3448) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3448) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3448) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3448) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3448) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
37
Suspicious files
656
Text files
592
Unknown types
0

Dropped files

PID
Process
Filename
Type
3484iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
3484iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419binary
MD5:27E6F24496689CAB05293311C6F9BB55
SHA256:0325D58C6B0745E2B24C2DB8AE8252BD4DA480B6780254776E81250CE912668D
3484iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\W7HICID3.htmhtml
MD5:F0703FCA7DA2F4FFC650BE6326367994
SHA256:BA58CF5C5FBD7483F1732F7268509B3144547ABFCC88E9E43B43799DEE7B23D2
3484iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419binary
MD5:C8C55385F5093BD31CA20813D6E03A6F
SHA256:D40640D3AA4F5A30105B735658051920A3C9B63AE95B9A801045FBB363E40FBD
3484iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:CBE8578EA2343E4A20AE775CC8274F38
SHA256:3E66B216BCE1F3A7745B4A53DBDAFEFFDB502BA6F3735BB5E7516CC9A67F6FD1
3484iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B039FEA45CB4CC4BBACFC013C7C55604_89709BA6A8E04CB298EC71539929CC6Dbinary
MD5:64A826C6D19CD1433327E344F618FF4D
SHA256:DD5777553D5183D10714DEA7557E7986FAF27D62A07FDD5FB02AE449A11A840C
3484iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\59D76868C250B3240414CE3EFBB12518_2C5F0ED2F89F8ECF54C55F34FCBF12DAbinary
MD5:C7D6D91EB2E8E5E5DEF5C04C352A9EE5
SHA256:634081509D3B9C23779290860C3EEEB4DB8B65B9C85BEE9D3C117617C8CA33FA
3484iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\59D76868C250B3240414CE3EFBB12518_2C5F0ED2F89F8ECF54C55F34FCBF12DAbinary
MD5:40BF9304BBFB897783CC36E6F4DF9073
SHA256:7DC4B493272433EF9CBA4AD277AE9A2493261CCA9335547F6FC0D6F7AE651205
3484iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\7ETCDF68.txttext
MD5:CD62875963023FF33D685A748D2A2188
SHA256:B1782A091AD3A0A6E80680190501453026F50B2371DC9801B22FF6F316A1B270
3484iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\main_style[1].csstext
MD5:F8D3C9B6422BE85B0A85D64E08B2D209
SHA256:01FAE738C9A6A7015A30FCC090AAE6B499C34965E73EE84D67134A4AC4A62BF4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
71
TCP/UDP connections
314
DNS requests
239
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3484
iexplore.exe
GET
301
199.34.228.53:80
http://winningcompetition.weebly.com/
unknown
html
398 b
unknown
3484
iexplore.exe
GET
200
23.216.77.177:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?ef2e01c2b2bd93b0
unknown
compressed
4.66 Kb
unknown
3484
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
unknown
binary
471 b
unknown
3484
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnxLiz3Fu1WB6n1%2FE6xWn1b0jXiQQUdIWAwGbH3zfez70pN6oDHb7tzRcCEAgrLkwGpCB95PF3gVJY%2F%2Bw%3D
unknown
binary
471 b
unknown
3484
iexplore.exe
GET
200
104.18.21.226:80
http://ocsp2.globalsign.com/rootr3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCEH3wUWDKXSh7Z3b6AuDWurw%3D
unknown
binary
1.40 Kb
unknown
3484
iexplore.exe
GET
200
142.250.185.163:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
unknown
binary
724 b
unknown
3484
iexplore.exe
GET
200
142.250.185.163:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
3484
iexplore.exe
GET
200
142.250.185.163:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQChuVoVf7HVAxLxWCb2kXo7
unknown
binary
472 b
unknown
3448
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D
unknown
binary
313 b
unknown
3484
iexplore.exe
GET
200
172.64.149.23:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D
unknown
binary
2.18 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2588
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
3484
iexplore.exe
199.34.228.53:80
winningcompetition.weebly.com
WEEBLY
US
unknown
3484
iexplore.exe
199.34.228.53:443
winningcompetition.weebly.com
WEEBLY
US
unknown
3484
iexplore.exe
23.216.77.177:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
3484
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3484
iexplore.exe
151.101.1.46:443
cdn2.editmysite.com
FASTLY
US
unknown
3484
iexplore.exe
104.18.21.226:80
ocsp2.globalsign.com
CLOUDFLARENET
shared
3484
iexplore.exe
216.58.206.40:443
ssl.google-analytics.com
GOOGLE
US
unknown
3484
iexplore.exe
142.250.185.163:80
ocsp.pki.goog
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
winningcompetition.weebly.com
  • 199.34.228.53
  • 199.34.228.54
unknown
ctldl.windowsupdate.com
  • 23.216.77.177
  • 23.216.77.140
  • 23.216.77.132
  • 23.216.77.185
  • 23.216.77.168
  • 23.216.77.149
  • 23.216.77.146
  • 23.216.77.145
  • 23.216.77.178
  • 23.216.77.165
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
cdn2.editmysite.com
  • 151.101.1.46
  • 151.101.65.46
  • 151.101.129.46
  • 151.101.193.46
whitelisted
ocsp2.globalsign.com
  • 104.18.21.226
  • 104.18.20.226
whitelisted
ssl.google-analytics.com
  • 216.58.206.40
  • 142.250.185.72
whitelisted
ocsp.pki.goog
  • 142.250.185.163
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 92.123.104.37
  • 92.123.104.32
  • 92.123.104.36
  • 92.123.104.43
  • 92.123.104.44
  • 92.123.104.41
  • 92.123.104.40
  • 92.123.104.49
  • 92.123.104.34
  • 204.79.197.200
  • 13.107.21.200
whitelisted
smrturl.co
  • 104.21.29.202
  • 172.67.149.199
malicious

Threats

No threats detected
Process
Message
assistant_installer.exe
[1122/203559.119:INFO:assistant_installer_main.cc(167)] Running assistant installer with command line "C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202311222035431\assistant\assistant_installer.exe" --version
assistant_installer.exe
[1122/203613.443:INFO:assistant_installer_main.cc(167)] Running assistant installer with command line "C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202311222035431\assistant\assistant_installer.exe" --installfolder="C:\Program Files\Opera\assistant" --copyonly=0 --allusers=0
assistant_installer.exe
[1122/203613.498:INFO:assistant_installer.cc(283)] Setting up the registry
assistant_installer.exe
[1122/203613.599:INFO:assistant_installer.cc(337)] Creating scheduled task
assistant_installer.exe
[1122/203613.638:INFO:assistant_installer_main.cc(167)] Running assistant installer with command line "C:\Program Files\Opera\assistant\assistant_installer.exe" --installfolder="C:\Program Files\Opera\assistant" --run-assistant --allusers=0
assistant_installer.exe
[1122/203613.638:INFO:assistant_installer.cc(242)] Running Assistant
browser_assistant.exe
[1122/203614.013:ERROR:tracking_data_utils.cc(72)] Can't read edition: missing value.
assistant_installer.exe
[1122/203614.318:INFO:assistant_installer_main.cc(167)] Running assistant installer with command line "C:\Program Files\Opera\assistant\assistant_installer.exe" --post-elevated-install-tasks --installfolder="C:\Program Files\Opera\assistant"