| File name: | OperaInstaller (3).exe |
| Full analysis: | https://app.any.run/tasks/ba5a7dd7-2d4b-4681-99ba-5f41b96420ab |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | February 10, 2026, 13:26:24 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | 9476256F46500D7B10360680EC8E473B |
| SHA1: | 2A7379C294A646D5A9B930FAB23E652D68873906 |
| SHA256: | 5255AA5F489C656C6BA3557C47AA26805C7C5B29C8E5E107C87DCDC9B08ACBE8 |
| SSDEEP: | 6144:fVNDuHmByrOPrDsBkfJfWQs/yO0DDDDDDDDDDDgrDDDDDDXfKBS/:dN/BU+rwBkh+QzDDDDDDDDDDDgrDDDDx |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2025:03:11 00:41:00+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.41 |
| CodeSize: | 87040 |
| InitializedDataSize: | 74240 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x4757 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 524 | "C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --enable-quic --no-pre-read-main-dll --force-high-res-timeticks=disabled --start-stack-profiler --with-feature:address-bar-dropdown-cities=on --with-feature:address-bar-intent=on --with-feature:address-bar-intent-internal-matching=on --with-feature:ai-tab-management=on --with-feature:ai-writing-mode-in-context-menu=on --with-feature:amp-requests-stats=on --with-feature:audio-analysis=on --with-feature:bluesky-in-sidebar=on --with-feature:cashback-assistant=off --with-feature:certificate-transparency-enforcement=on --with-feature:continue-filter=on --with-feature:continue-shopping-structured-partners=on --with-feature:discord-in-sidebar=on --with-feature:domain-suggestions-with-misspells=on --with-feature:early-bird=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:installer-experiment-test=off --with-feature:installer-move-opera-exe=off --with-feature:keywords-from-backend=on --with-feature:native-crypto-wallet=on --with-feature:opera-one-unskippable-introduction=on --with-feature:opera-startpage-special-2=off --with-feature:realtime-impressions-reporting=on --with-feature:run-at-startup-default=on --with-feature:sd-suggestions-external=on --with-feature:sitecheck-age=on --with-feature:slack-in-sidebar=on --with-feature:specific-keywords=on --with-feature:startpage-content=off --with-feature:startpage-opening-animation=off --with-feature:startpage-sync-banner-ref=on --with-feature:translator=on --with-feature:vpn-pro-v4-support=on --metrics-shmem-handle=2280,i,11380740897079712547,1463936230106198557,524288 --field-trial-handle=2036,i,3852360525079286602,15468552475483780465,262144 --enable-features=CertificateTransparencyAskBeforeEnabling,MultiThreadedUiCompositor --disable-features=AutoPictureInPictureForVideoPlayback,AutoPictureInPictureVideoHeuristics,CapitalOneCashbackProtection,MediaSessionEnterPictureInPicture,PlatformSoftwareH264EncoderInGpu,SyncWorkspacesInSessions --variations-seed-version --trace-process-track-uuid=3190708989122997041 --mojo-platform-channel-handle=2224 /prefetch:3 | C:\Users\admin\AppData\Local\Programs\Opera\opera.exe | opera.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera Internet Browser Exit code: 0 Version: 127.0.5778.14 Modules
| |||||||||||||||
| 664 | "C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --type=renderer --no-pre-read-main-dll --force-high-res-timeticks=disabled --start-stack-profiler --with-feature:address-bar-dropdown-cities=on --with-feature:address-bar-intent=on --with-feature:address-bar-intent-internal-matching=on --with-feature:ai-tab-management=on --with-feature:ai-writing-mode-in-context-menu=on --with-feature:amp-requests-stats=on --with-feature:audio-analysis=on --with-feature:bluesky-in-sidebar=on --with-feature:cashback-assistant=off --with-feature:certificate-transparency-enforcement=on --with-feature:continue-filter=on --with-feature:continue-shopping-structured-partners=on --with-feature:discord-in-sidebar=on --with-feature:domain-suggestions-with-misspells=on --with-feature:early-bird=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:installer-experiment-test=off --with-feature:installer-move-opera-exe=off --with-feature:keywords-from-backend=on --with-feature:native-crypto-wallet=on --with-feature:opera-one-unskippable-introduction=on --with-feature:opera-startpage-special-2=off --with-feature:realtime-impressions-reporting=on --with-feature:run-at-startup-default=on --with-feature:sd-suggestions-external=on --with-feature:sitecheck-age=on --with-feature:slack-in-sidebar=on --with-feature:specific-keywords=on --with-feature:startpage-content=off --with-feature:startpage-opening-animation=off --with-feature:startpage-sync-banner-ref=on --with-feature:translator=on --with-feature:vpn-pro-v4-support=on --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=16 --metrics-shmem-handle=5172,i,16362570790781491755,185565586464561223,2097152 --field-trial-handle=1904,i,3600888648884663366,12979576116179422497,262144 --enable-features=CertificateTransparencyAskBeforeEnabling,MultiThreadedUiCompositor --disable-features=AutoPictureInPictureForVideoPlayback,AutoPictureInPictureVideoHeuristics,CapitalOneCashbackProtection,MediaSessionEnterPictureInPicture,PlatformSoftwareH264EncoderInGpu,SyncWorkspacesInSessions --variations-seed-version --trace-process-track-uuid=3190709001304541078 --mojo-platform-channel-handle=5176 /prefetch:1 | C:\Users\admin\AppData\Local\Programs\Opera\opera.exe | — | opera.exe | |||||||||||
User: admin Company: Opera Software Integrity Level: LOW Description: Opera Internet Browser Version: 127.0.5778.14 Modules
| |||||||||||||||
| 752 | "C:\Users\admin\AppData\Local\Programs\Opera\127.0.5778.14\installer.exe" --backend --initial-pid=4292 --install --import-browser-data=0 --enable-crash-reporting=1 --enable-stats=1 --enable-installer-stats=1 --consent-given=0 --general-interests=0 --general-location=0 --personalized-content=0 --personalized-ads=0 --launchopera=1 --showunbox=0 --installfolder="C:\Users\admin\AppData\Local\Programs\Opera" --profile-folder --language=en --singleprofile=0 --copyonly=0 --allusers=0 --setdefaultbrowser=0 --pintotaskbar=1 --pintostartmenu=1 --run-at-startup=1 --server-tracking-data=server_tracking_data --show-intro-overlay --package-dir="C:\Users\admin\AppData\Local\Temp\.opera\8a69749e-be2a-469e-8bec-99c68fd9ee05 Opera Installer Temp\opera_package_202602100826351" --session-guid=77dc7a00-6d35-48b1-b27b-29add9b83ad7 --server-tracking-blob=OTVkMzNiNWJjODkwMTY2NDNkZjkzZTVmY2IxNmIwZGI1NThhNmM0MWUzNjdhZWFhNGIzNjc0OWY2ZDAzMGViYTp7ImNvdW50cnkiOiJESyIsImZhc3Rfb25ib2FyZGluZyI6e30sImluc3RhbGxlcl9uYW1lIjoiT3BlcmFTZXR1cC5leGUiLCJwcm9kdWN0Ijp7Im5hbWUiOiJvcGVyYSJ9LCJxdWVyeSI6Ii9vcGVyYS9zdGFibGUvd2luZG93cz91dG1fc291cmNlPXdyayZ1dG1fbWVkaXVtPXBiJnV0bV9jYW1wYWlnbj1PcGVyYV9EZXNrdG9wIiwic3lzdGVtIjp7InBsYXRmb3JtIjp7ImFyY2giOiJ4ODZfNjQiLCJvcHN5cyI6IldpbmRvd3MiLCJvcHN5cy12ZXJzaW9uIjoiMTAiLCJwYWNrYWdlIjoiRVhFIn19LCJ0aW1lc3RhbXAiOiIxNzcwNzI5OTkzLjExMjUiLCJ1c2VyYWdlbnQiOiJPcGVyYSBJbnN0YWxsZXIvMS4wIiwidXRtIjp7ImNhbXBhaWduIjoiT3BlcmFfRGVza3RvcCIsIm1lZGl1bSI6InBiIiwic291cmNlIjoid3JrIn0sInV1aWQiOiJjYWIxM2EyNS1jNzg2LTQ3NWMtODRmNi02OTBhZmEwMzZkMTEifQ== --silent --desktopshortcut=1 --install-subfolder=127.0.5778.14 | C:\Users\admin\AppData\Local\Programs\Opera\127.0.5778.14\installer.exe | setup.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera Installer Exit code: 0 Version: 127.0.5778.14 Modules
| |||||||||||||||
| 1080 | "C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --type=renderer --extension-process --no-pre-read-main-dll --force-high-res-timeticks=disabled --with-feature:address-bar-dropdown-cities=on --with-feature:address-bar-intent=on --with-feature:address-bar-intent-internal-matching=on --with-feature:ai-tab-management=on --with-feature:ai-writing-mode-in-context-menu=on --with-feature:amp-requests-stats=on --with-feature:audio-analysis=on --with-feature:bluesky-in-sidebar=on --with-feature:cashback-assistant=off --with-feature:certificate-transparency-enforcement=on --with-feature:continue-filter=on --with-feature:continue-shopping-structured-partners=on --with-feature:discord-in-sidebar=on --with-feature:domain-suggestions-with-misspells=on --with-feature:early-bird=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:installer-experiment-test=off --with-feature:installer-move-opera-exe=off --with-feature:keywords-from-backend=on --with-feature:native-crypto-wallet=on --with-feature:opera-one-unskippable-introduction=on --with-feature:opera-startpage-special-2=off --with-feature:realtime-impressions-reporting=on --with-feature:run-at-startup-default=on --with-feature:sd-suggestions-external=on --with-feature:sitecheck-age=on --with-feature:slack-in-sidebar=on --with-feature:specific-keywords=on --with-feature:startpage-content=off --with-feature:startpage-opening-animation=off --with-feature:startpage-sync-banner-ref=on --with-feature:translator=on --with-feature:vpn-pro-v4-support=on --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=54 --metrics-shmem-handle=7888,i,17605671455960082327,15074403502529798438,2097152 --field-trial-handle=1904,i,3600888648884663366,12979576116179422497,262144 --enable-features=CertificateTransparencyAskBeforeEnabling,MultiThreadedUiCompositor --disable-features=AutoPictureInPictureForVideoPlayback,AutoPictureInPictureVideoHeuristics,CapitalOneCashbackProtection,MediaSessionEnterPictureInPicture,PlatformSoftwareH264EncoderInGpu,SyncWorkspacesInSessions --variations-seed-version --trace-process-track-uuid=3190709036912131340 --mojo-platform-channel-handle=8760 /prefetch:2 | C:\Users\admin\AppData\Local\Programs\Opera\opera.exe | — | opera.exe | |||||||||||
User: admin Company: Opera Software Integrity Level: LOW Description: Opera Internet Browser Exit code: 0 Version: 127.0.5778.14 Modules
| |||||||||||||||
| 1156 | "C:\Users\admin\AppData\Local\Temp\.opera\8a69749e-be2a-469e-8bec-99c68fd9ee05 Opera Installer Temp\opera_package_202602100826351\assistant\assistant_installer.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktop --annotation=ver=127.0.5778.14 --initial-client-data=0x260,0x264,0x268,0x17c,0x26c,0xf05cc0,0xf05ccc,0xf05cd8 | C:\Users\admin\AppData\Local\Temp\.opera\8a69749e-be2a-469e-8bec-99c68fd9ee05 Opera Installer Temp\opera_package_202602100826351\assistant\assistant_installer.exe | assistant_installer.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera Browser Assistant Installer Exit code: 0 Version: 127.0.5778.14 Modules
| |||||||||||||||
| 1400 | "C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --enable-quic --no-pre-read-main-dll --force-high-res-timeticks=disabled --with-feature:address-bar-dropdown-cities=on --with-feature:address-bar-intent=on --with-feature:address-bar-intent-internal-matching=on --with-feature:ai-tab-management=on --with-feature:ai-writing-mode-in-context-menu=on --with-feature:amp-requests-stats=on --with-feature:audio-analysis=on --with-feature:bluesky-in-sidebar=on --with-feature:cashback-assistant=off --with-feature:certificate-transparency-enforcement=on --with-feature:continue-filter=on --with-feature:continue-shopping-structured-partners=on --with-feature:discord-in-sidebar=on --with-feature:domain-suggestions-with-misspells=on --with-feature:early-bird=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:installer-experiment-test=off --with-feature:installer-move-opera-exe=off --with-feature:keywords-from-backend=on --with-feature:native-crypto-wallet=on --with-feature:opera-one-unskippable-introduction=on --with-feature:opera-startpage-special-2=off --with-feature:realtime-impressions-reporting=on --with-feature:run-at-startup-default=on --with-feature:sd-suggestions-external=on --with-feature:sitecheck-age=on --with-feature:slack-in-sidebar=on --with-feature:specific-keywords=on --with-feature:startpage-content=off --with-feature:startpage-opening-animation=off --with-feature:startpage-sync-banner-ref=on --with-feature:translator=on --with-feature:vpn-pro-v4-support=on --metrics-shmem-handle=6968,i,8302920848234540810,12332513631103659945,524288 --field-trial-handle=1904,i,3600888648884663366,12979576116179422497,262144 --enable-features=CertificateTransparencyAskBeforeEnabling,MultiThreadedUiCompositor --disable-features=AutoPictureInPictureForVideoPlayback,AutoPictureInPictureVideoHeuristics,CapitalOneCashbackProtection,MediaSessionEnterPictureInPicture,PlatformSoftwareH264EncoderInGpu,SyncWorkspacesInSessions --variations-seed-version --trace-process-track-uuid=3190709007863834021 --mojo-platform-channel-handle=3780 /prefetch:8 | C:\Users\admin\AppData\Local\Programs\Opera\opera.exe | — | opera.exe | |||||||||||
User: admin Company: Opera Software Integrity Level: LOW Description: Opera Internet Browser Exit code: 0 Version: 127.0.5778.14 Modules
| |||||||||||||||
| 1424 | "C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --type=renderer --no-pre-read-main-dll --force-high-res-timeticks=disabled --start-stack-profiler --with-feature:address-bar-dropdown-cities=on --with-feature:address-bar-intent=on --with-feature:address-bar-intent-internal-matching=on --with-feature:ai-tab-management=on --with-feature:ai-writing-mode-in-context-menu=on --with-feature:amp-requests-stats=on --with-feature:audio-analysis=on --with-feature:bluesky-in-sidebar=on --with-feature:cashback-assistant=off --with-feature:certificate-transparency-enforcement=on --with-feature:continue-filter=on --with-feature:continue-shopping-structured-partners=on --with-feature:discord-in-sidebar=on --with-feature:domain-suggestions-with-misspells=on --with-feature:early-bird=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:installer-experiment-test=off --with-feature:installer-move-opera-exe=off --with-feature:keywords-from-backend=on --with-feature:native-crypto-wallet=on --with-feature:opera-one-unskippable-introduction=on --with-feature:opera-startpage-special-2=off --with-feature:realtime-impressions-reporting=on --with-feature:run-at-startup-default=on --with-feature:sd-suggestions-external=on --with-feature:sitecheck-age=on --with-feature:slack-in-sidebar=on --with-feature:specific-keywords=on --with-feature:startpage-content=off --with-feature:startpage-opening-animation=off --with-feature:startpage-sync-banner-ref=on --with-feature:translator=on --with-feature:vpn-pro-v4-support=on --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=15 --metrics-shmem-handle=4832,i,7847202735770237621,5773539185551477035,2097152 --field-trial-handle=1904,i,3600888648884663366,12979576116179422497,262144 --enable-features=CertificateTransparencyAskBeforeEnabling,MultiThreadedUiCompositor --disable-features=AutoPictureInPictureForVideoPlayback,AutoPictureInPictureVideoHeuristics,CapitalOneCashbackProtection,MediaSessionEnterPictureInPicture,PlatformSoftwareH264EncoderInGpu,SyncWorkspacesInSessions --variations-seed-version --trace-process-track-uuid=3190709000367499229 --mojo-platform-channel-handle=4840 /prefetch:1 | C:\Users\admin\AppData\Local\Programs\Opera\opera.exe | — | opera.exe | |||||||||||
User: admin Company: Opera Software Integrity Level: LOW Description: Opera Internet Browser Version: 127.0.5778.14 Modules
| |||||||||||||||
| 1492 | C:\Users\admin\AppData\Local\Programs\Opera\127.0.5778.14\opera_crashreporter.exe --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win64 --annotation=prod=OperaDesktop --annotation=ver=127.0.5778.14 --initial-client-data=0x2a8,0x2ac,0x2b0,0x2a4,0x2b4,0x7ffd61a11490,0x7ffd61a114a0,0x7ffd61a114b0 | C:\Users\admin\AppData\Local\Programs\Opera\127.0.5778.14\opera_crashreporter.exe | opera.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera crash-reporter Exit code: 0 Version: 127.0.5778.14 Modules
| |||||||||||||||
| 1524 | "C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --enable-quic --no-pre-read-main-dll --force-high-res-timeticks=disabled --with-feature:address-bar-dropdown-cities=on --with-feature:address-bar-intent=on --with-feature:address-bar-intent-internal-matching=on --with-feature:ai-tab-management=on --with-feature:ai-writing-mode-in-context-menu=on --with-feature:amp-requests-stats=on --with-feature:audio-analysis=on --with-feature:bluesky-in-sidebar=on --with-feature:cashback-assistant=off --with-feature:certificate-transparency-enforcement=on --with-feature:continue-filter=on --with-feature:continue-shopping-structured-partners=on --with-feature:discord-in-sidebar=on --with-feature:domain-suggestions-with-misspells=on --with-feature:early-bird=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:installer-experiment-test=off --with-feature:installer-move-opera-exe=off --with-feature:keywords-from-backend=on --with-feature:native-crypto-wallet=on --with-feature:opera-one-unskippable-introduction=on --with-feature:opera-startpage-special-2=off --with-feature:realtime-impressions-reporting=on --with-feature:run-at-startup-default=on --with-feature:sd-suggestions-external=on --with-feature:sitecheck-age=on --with-feature:slack-in-sidebar=on --with-feature:specific-keywords=on --with-feature:startpage-content=off --with-feature:startpage-opening-animation=off --with-feature:startpage-sync-banner-ref=on --with-feature:translator=on --with-feature:vpn-pro-v4-support=on --metrics-shmem-handle=6608,i,5672924778635194684,13471610314591741351,524288 --field-trial-handle=1904,i,3600888648884663366,12979576116179422497,262144 --enable-features=CertificateTransparencyAskBeforeEnabling,MultiThreadedUiCompositor --disable-features=AutoPictureInPictureForVideoPlayback,AutoPictureInPictureVideoHeuristics,CapitalOneCashbackProtection,MediaSessionEnterPictureInPicture,PlatformSoftwareH264EncoderInGpu,SyncWorkspacesInSessions --variations-seed-version --trace-process-track-uuid=3190709040660298736 --mojo-platform-channel-handle=7244 /prefetch:8 | C:\Users\admin\AppData\Local\Programs\Opera\opera.exe | — | opera.exe | |||||||||||
User: admin Company: Opera Software Integrity Level: LOW Description: Opera Internet Browser Exit code: 0 Version: 127.0.5778.14 Modules
| |||||||||||||||
| 1732 | "C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --enable-quic --no-pre-read-main-dll --force-high-res-timeticks=disabled --with-feature:address-bar-dropdown-cities=on --with-feature:address-bar-intent=on --with-feature:address-bar-intent-internal-matching=on --with-feature:ai-tab-management=on --with-feature:ai-writing-mode-in-context-menu=on --with-feature:amp-requests-stats=on --with-feature:audio-analysis=on --with-feature:bluesky-in-sidebar=on --with-feature:cashback-assistant=off --with-feature:certificate-transparency-enforcement=on --with-feature:continue-filter=on --with-feature:continue-shopping-structured-partners=on --with-feature:discord-in-sidebar=on --with-feature:domain-suggestions-with-misspells=on --with-feature:early-bird=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:installer-experiment-test=off --with-feature:installer-move-opera-exe=off --with-feature:keywords-from-backend=on --with-feature:native-crypto-wallet=on --with-feature:opera-one-unskippable-introduction=on --with-feature:opera-startpage-special-2=off --with-feature:realtime-impressions-reporting=on --with-feature:run-at-startup-default=on --with-feature:sd-suggestions-external=on --with-feature:sitecheck-age=on --with-feature:slack-in-sidebar=on --with-feature:specific-keywords=on --with-feature:startpage-content=off --with-feature:startpage-opening-animation=off --with-feature:startpage-sync-banner-ref=on --with-feature:translator=on --with-feature:vpn-pro-v4-support=on --metrics-shmem-handle=2520,i,1009118902227360667,940682209977517443,524288 --field-trial-handle=2036,i,3852360525079286602,15468552475483780465,262144 --enable-features=CertificateTransparencyAskBeforeEnabling,MultiThreadedUiCompositor --disable-features=AutoPictureInPictureForVideoPlayback,AutoPictureInPictureVideoHeuristics,CapitalOneCashbackProtection,MediaSessionEnterPictureInPicture,PlatformSoftwareH264EncoderInGpu,SyncWorkspacesInSessions --variations-seed-version --trace-process-track-uuid=3190708990060038890 --mojo-platform-channel-handle=2528 /prefetch:8 | C:\Users\admin\AppData\Local\Programs\Opera\opera.exe | — | opera.exe | |||||||||||
User: admin Company: Opera Software Integrity Level: LOW Description: Opera Internet Browser Exit code: 0 Version: 127.0.5778.14 Modules
| |||||||||||||||
| (PID) Process: | (1840) OperaInstaller (3).exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (1840) OperaInstaller (3).exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (1840) OperaInstaller (3).exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (4292) setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (4292) setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (4292) setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (8120) setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Opera Software |
| Operation: | write | Name: | Last Stable Install Path |
Value: C:\Users\admin\AppData\Local\Programs\Opera\ | |||
| (PID) Process: | (752) installer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Opera Software |
| Operation: | write | Name: | Last Stable Install Path |
Value: C:\Users\admin\AppData\Local\Programs\Opera\ | |||
| (PID) Process: | (752) installer.exe | Key: | HKEY_CLASSES_ROOT\OperaStable |
| Operation: | write | Name: | FriendlyTypeName |
Value: Opera Web Document | |||
| (PID) Process: | (752) installer.exe | Key: | HKEY_CLASSES_ROOT\OperaStable |
| Operation: | write | Name: | URL Protocol |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1840 | OperaInstaller (3).exe | C:\Users\admin\AppData\Local\Temp\bg.png | image | |
MD5:21EB6B8232802F32B6483EEDB96677BB | SHA256:1464A14A35131D5BD81B618A169401EBA231DAF63A78B18BE3C431EA514ED122 | |||
| 1840 | OperaInstaller (3).exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12 | binary | |
MD5:74ED7AD9D3F2461D8AE7F9F7975EDD8A | SHA256:4C3DD8A2FC098EAB5751011721A457E976A6D8BCB67FC13848D2B8418A1C786A | |||
| 1840 | OperaInstaller (3).exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12 | binary | |
MD5:4F53605EE73BF1920F9E0FBA0D5AD6E1 | SHA256:70361FC5BD4A7FBFA22050CCD859760C6116CF7D33BDE25CB161D909D05030DC | |||
| 4292 | setup.exe | C:\Users\admin\AppData\Local\Temp\.opera\8a69749e-be2a-469e-8bec-99c68fd9ee05 Opera Installer Temp\setup.exe | executable | |
MD5:9D9FC218063385C99FEC2090C97DA813 | SHA256:B0919102831AB03B596345924FEDC1F33D0639CF4A3113E9657DAFCC2D9E2100 | |||
| 1840 | OperaInstaller (3).exe | C:\Users\admin\AppData\Local\Temp\OpInst.exe | executable | |
MD5:BE20EDAE256446FC99F7D12391EB2528 | SHA256:E129E6A4429E08689D7377DCBB00822447BC3E18FEAA45896050369606F1A66B | |||
| 1840 | OperaInstaller (3).exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419 | binary | |
MD5:F3B5EA4D9584D9B28EDBC5F9F3B888AD | SHA256:BDD4F68524C12F68C0EDE2EF1C54B9895F633DF6FF71807D28D18B51B9C322F4 | |||
| 4292 | setup.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\E4DJRUXW\Opera_127.0.5778.14_Autoupdate_x64[1].exe | — | |
MD5:— | SHA256:— | |||
| 4292 | setup.exe | C:\Users\admin\AppData\Local\Temp\.opera\8a69749e-be2a-469e-8bec-99c68fd9ee05 Opera Installer Temp\opera_package_202602100826351\opera_package | — | |
MD5:— | SHA256:— | |||
| 1840 | OperaInstaller (3).exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419 | binary | |
MD5:AB0B50D61B5EC74EF685B95214C9C962 | SHA256:7E47E508F2262E936192C41814BF2A63D0B869E46A3C770BDAF1259DBD5388C9 | |||
| 1840 | OperaInstaller (3).exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8 | binary | |
MD5:1B266BFA4A7CF30EFBEFFFC084B4EF2E | SHA256:D41A16089C41CF0240DDC4264A2190BDA4C0D51567712C81C0841FD79671DFCE | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1840 | OperaInstaller (3).exe | GET | 302 | 104.26.11.119:443 | https://work.ink/_api/v2/affiliate/operaGX | unknown | — | — | unknown |
4292 | setup.exe | GET | 404 | 104.18.24.17:443 | https://api.config.opr.gg/v0/config?utm_campaign=Opera_Desktop&utm_medium=pb&utm_source=wrk&product=&channel=Stable&client=netinstaller&edition= | unknown | — | — | unknown |
4292 | setup.exe | GET | 302 | 185.26.182.117:443 | https://download.opera.com/download/get/?id=75647&autoupdate=1&ni=1&stream=stable&utm_campaign=Opera_Desktop&utm_medium=pb&utm_source=wrk&niuid=cab13a25-c786-475c-84f6-690afa036d11 | unknown | — | — | unknown |
4292 | setup.exe | GET | — | 104.18.11.89:443 | https://download5.operacdn.com/ftp/pub/opera/desktop/127.0.5778.14/win/Opera_127.0.5778.14_Autoupdate_x64.exe | unknown | — | — | unknown |
1840 | OperaInstaller (3).exe | GET | 200 | 142.251.127.94:80 | http://c.pki.goog/r/gsr1.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAjTxtAB8my1oj8MfWpz%2F7Y%3D | unknown | — | — | whitelisted |
1840 | OperaInstaller (3).exe | GET | 200 | 104.26.10.119:443 | https://opera-download.work.ink/op.png | unknown | image | 224 Kb | unknown |
— | — | GET | 200 | 204.79.197.203:80 | http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ3L3%2F%2Fa6ADK8NraY2GXzVaYrHG4AQUb6t%2B2v%2BXQ3LsO2d33oJhNYhHQoUCEzMAAAAGb6JMMcOVb6sAAAAAAAY%3D | unknown | — | — | whitelisted |
1840 | OperaInstaller (3).exe | GET | 200 | 142.251.127.94:80 | http://c.pki.goog/r/r4.crl | unknown | — | — | whitelisted |
1840 | OperaInstaller (3).exe | GET | 200 | 185.26.182.112:443 | https://net.geo.opera.com/opera/stable/windows?utm_source=wrk&utm_medium=pb&utm_campaign=Opera_Desktop | unknown | executable | 2.77 Mb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3656 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:137 | — | Not routed | — | whitelisted |
4936 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6768 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
5568 | SearchApp.exe | 2.16.204.146:443 | th.bing.com | AKAMAI-ASN1 | NL | whitelisted |
— | — | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
— | — | 204.79.197.203:80 | oneocsp.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
1840 | OperaInstaller (3).exe | 104.26.10.119:443 | opera-download.work.ink | CLOUDFLARENET | US | whitelisted |
1840 | OperaInstaller (3).exe | 142.251.127.94:80 | c.pki.goog | GOOGLE | US | whitelisted |
3412 | svchost.exe | 172.211.123.250:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
th.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
google.com |
| whitelisted |
oneocsp.microsoft.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
opera-download.work.ink |
| unknown |
c.pki.goog |
| whitelisted |
client.wns.windows.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1840 | OperaInstaller (3).exe | Potentially Bad Traffic | ET INFO PE EXE or DLL Windows file download HTTP |
1840 | OperaInstaller (3).exe | Misc activity | ET INFO EXE - Served Attached HTTP |
6768 | MoUsoCoreWorker.exe | Unknown Traffic | ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW) |
Process | Message |
|---|---|
setup.exe | RecursiveDirectoryCreate( C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable directory exists )
|
setup.exe | RecursiveDirectoryCreate( C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable directory exists )
|
assistant_installer.exe | [0210/082646.530:INFO:opera\desktop\windows\assistant\installer\assistant_installer_main.cc:170] Running assistant installer with command line "C:\Users\admin\AppData\Local\Temp\.opera\8a69749e-be2a-469e-8bec-99c68fd9ee05 Opera Installer Temp\opera_package_202602100826351\assistant\assistant_installer.exe" --version
|
assistant_installer.exe | RecursiveDirectoryCreate( C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable directory exists )
|
installer.exe | RecursiveDirectoryCreate( C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable directory exists )
|
assistant_installer.exe | [0210/082657.410:INFO:opera\desktop\windows\assistant\installer\assistant_installer_main.cc:170] Running assistant installer with command line "C:\Users\admin\AppData\Local\Temp\.opera\8a69749e-be2a-469e-8bec-99c68fd9ee05 Opera Installer Temp\opera_package_202602100826351\assistant\assistant_installer.exe" --installfolder="C:\Users\admin\AppData\Local\Programs\Opera\assistant" --copyonly=0 --allusers=0
|
assistant_installer.exe | RecursiveDirectoryCreate( C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable directory exists )
|
assistant_installer.exe | [0210/082657.441:INFO:opera\desktop\windows\assistant\installer\assistant_installer.cc:308] Setting up the registry
|
assistant_installer.exe | [0210/082657.472:INFO:opera\desktop\windows\assistant\installer\assistant_installer.cc:359] Creating scheduled task
|
assistant_installer.exe | RecursiveDirectoryCreate( C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable directory exists )
|