URL: | https://torproject.org |
Full analysis: | https://app.any.run/tasks/e1ea8207-be53-4b04-ae66-97cbcc01b756 |
Verdict: | Malicious activity |
Analysis date: | March 17, 2021, 19:39:10 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MD5: | D513C71DD4364354F5CEEB44AE15EB6D |
SHA1: | AB8128DED984DB73010625464DCE82CFAAA497CA |
SHA256: | 16A2E648E444CD11F09CD83F3BA6407F32CA6883EBE9CE5CA17BA603D334D078 |
SSDEEP: | 3:N8CXVa4G+XC:2CFa4Gf |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2476 | "C:\Program Files\Opera\opera.exe" "https://torproject.org" | C:\Program Files\Opera\opera.exe | explorer.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera Internet Browser Version: 1748 Modules
| |||||||||||||||
2344 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
|
(PID) Process: | (2476) opera.exe | Key: | HKEY_CURRENT_USER\Software\Opera Software |
Operation: | write | Name: | Last CommandLine v2 |
Value: C:\Program Files\Opera\opera.exe "https://torproject.org" | |||
(PID) Process: | (2476) opera.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (2476) opera.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E |
Operation: | write | Name: | @"%windir%\System32\ie4uinit.exe",-732 |
Value: Finds and displays information and Web sites on the Internet. | |||
(PID) Process: | (2476) opera.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU |
Operation: | write | Name: | NodeSlots |
Value: 0202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202 | |||
(PID) Process: | (2476) opera.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU |
Operation: | write | Name: | MRUListEx |
Value: 0200000001000000000000000B000000070000000A000000090000000800000006000000030000000500000004000000FFFFFFFF | |||
(PID) Process: | (2476) opera.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\50\ComDlg |
Operation: | write | Name: | TV_FolderType |
Value: {FBB3477E-C9E4-4B3B-A2BA-D3F5D3CD46F9} | |||
(PID) Process: | (2476) opera.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\50\ComDlg |
Operation: | write | Name: | TV_TopViewID |
Value: {82BA0782-5B7A-4569-B5D7-EC83085F08CC} | |||
(PID) Process: | (2476) opera.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\50\ComDlg |
Operation: | write | Name: | TV_TopViewVersion |
Value: 0 | |||
(PID) Process: | (2476) opera.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E |
Operation: | write | Name: | @C:\Windows\system32\NetworkExplorer.dll,-1 |
Value: Network | |||
(PID) Process: | (2476) opera.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRU |
Operation: | write | Name: | 2 |
Value: 6F0070006500720061002E00650078006500000014001F4225481E03947BC34DB131E946B44C8DD5740000001A00EEBBFE23000010007DB10D7BD29C934A973346CC89022E7C00002A0000000000EFBE000000200000000000000000000000000000000000000000000000000100000020002A0000001900EFBE7E47B3FBE4C93B4BA2BAD3F5D3CD46F98207BA827A5B6945B5D7EC83085F08CC20000000 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2476 | opera.exe | C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\opr70A7.tmp | — | |
MD5:— | SHA256:— | |||
2476 | opera.exe | C:\Users\admin\AppData\Roaming\Opera\Opera\opr70B8.tmp | — | |
MD5:— | SHA256:— | |||
2476 | opera.exe | C:\Users\admin\AppData\Roaming\Opera\Opera\opr7107.tmp | — | |
MD5:— | SHA256:— | |||
2476 | opera.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\BU7SM44TVVMX610KJIKA.temp | — | |
MD5:— | SHA256:— | |||
2476 | opera.exe | C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00001.tmp | — | |
MD5:— | SHA256:— | |||
2476 | opera.exe | C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\oprAB62.tmp | — | |
MD5:— | SHA256:— | |||
2476 | opera.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\16ec093b8f51508f.customDestinations-ms~RFe7c21.TMP | binary | |
MD5:1B1D31CC61AE6229BD975B3028268AEB | SHA256:95779D4B65B2D00D8B6BC498E792495D31E41FFCF08E5DD6B3395B67FBB8CF52 | |||
2476 | opera.exe | C:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xml | xml | |
MD5:5C5E8352F0F4CD75C9F104E1158254DC | SHA256:C6CE63D9E38A72AFA6906EC2F90C3302DE5E09D598EFD464067CA1218364F3AE | |||
2476 | opera.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\16ec093b8f51508f.customDestinations-ms | binary | |
MD5:1B1D31CC61AE6229BD975B3028268AEB | SHA256:95779D4B65B2D00D8B6BC498E792495D31E41FFCF08E5DD6B3395B67FBB8CF52 | |||
2476 | opera.exe | C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat | binary | |
MD5:744758A684A955B02A63DEF60856FC90 | SHA256:90349A20C5AC0FD589E5B789E9D77212FD947A60D53C3759422CF374A3D6FC55 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2476 | opera.exe | GET | 200 | 93.184.220.29:80 | http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl | US | der | 592 b | whitelisted |
2476 | opera.exe | GET | 302 | 185.26.182.110:80 | http://redir.opera.com/speeddials/previews/booking/default | unknown | html | 307 b | whitelisted |
2476 | opera.exe | GET | 200 | 13.32.11.218:80 | http://s.ss2.us/r.crl | US | der | 434 b | whitelisted |
2476 | opera.exe | GET | 200 | 13.32.11.230:80 | http://crl.rootca1.amazontrust.com/rootca1.crl | US | der | 439 b | whitelisted |
2476 | opera.exe | GET | 302 | 185.26.182.110:80 | http://redir.opera.com/speeddials/previews/shopping/de | unknown | html | 315 b | whitelisted |
2476 | opera.exe | GET | 200 | 2.23.159.161:80 | http://crl.identrust.com/DSTROOTCAX3CRL.crl | unknown | der | 1.16 Kb | whitelisted |
2476 | opera.exe | GET | 302 | 185.26.182.110:80 | http://redir.opera.com/speeddials/booking | unknown | html | 323 b | whitelisted |
2476 | opera.exe | GET | 302 | 185.26.182.110:80 | http://redir.opera.com/speeddials/amazon/ | unknown | html | 319 b | whitelisted |
2476 | opera.exe | GET | 404 | 185.26.182.110:80 | http://redir.opera.com/favicon.ico | unknown | text | 76 b | whitelisted |
2476 | opera.exe | GET | 200 | 93.184.220.29:80 | http://s.symcb.com/pca3-g5.crl | US | der | 834 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2476 | opera.exe | 93.184.220.29:80 | crl3.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2476 | opera.exe | 2.23.159.161:80 | crl.identrust.com | Telia Company AB | — | unknown |
2476 | opera.exe | 95.216.163.36:443 | torproject.org | Hetzner Online GmbH | DE | unknown |
2476 | opera.exe | 116.202.120.165:443 | www.torproject.org | 334,Udyog Vihar | IN | suspicious |
2476 | opera.exe | 185.26.182.110:80 | redir.opera.com | Opera Software AS | — | unknown |
2476 | opera.exe | 82.145.216.15:443 | sitecheck2.opera.com | Opera Software AS | — | suspicious |
2476 | opera.exe | 185.26.182.94:443 | certs.opera.com | Opera Software AS | — | whitelisted |
2476 | opera.exe | 13.224.223.75:80 | www.amazon.com | — | US | unknown |
2476 | opera.exe | 13.224.223.75:443 | www.amazon.com | — | US | unknown |
2476 | opera.exe | 54.87.59.200:443 | fls-na.amazon.com | Amazon.com, Inc. | US | unknown |
Domain | IP | Reputation |
---|---|---|
torproject.org |
| suspicious |
certs.opera.com |
| whitelisted |
sitecheck2.opera.com |
| whitelisted |
crl.identrust.com |
| whitelisted |
crl3.digicert.com |
| whitelisted |
www.torproject.org |
| shared |
redir.opera.com |
| whitelisted |
www.amazon.com |
| whitelisted |
crl4.digicert.com |
| whitelisted |
s.symcb.com |
| whitelisted |
PID | Process | Class | Message |
---|---|---|---|
— | — | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
— | — | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
— | — | Potentially Bad Traffic | ET INFO TLS Handshake Failure |