File name:

OperaGXSetup.exe

Full analysis: https://app.any.run/tasks/1ed0d4a7-1b06-459f-8fd3-25e7ad7c25d5
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: February 12, 2026, 21:07:26
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
stealer
opera
tool
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

0C6AEA83FF2EEBB94DE7C9BB3330981F

SHA1:

F8D7526A2D214A7D1FDF614C16D73521AE09BB34

SHA256:

5E0C15DC4EE14AF45FE95A7EF1F79873B21EFD7223918A07BF0FFA7E527AA0C1

SSDEEP:

98304:FwyWSeMgtXHQOnTMN3EdHcJTdSVUIOksUbIioBFzZXe7U6lBxkrhgSqZ8b98dkfZ:FIs

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • assistant_installer.exe (PID: 6940)
      • opera.exe (PID: 7412)
    • Steals credentials from Web Browsers

      • opera.exe (PID: 7412)
    • Actions looks like stealing of personal data

      • opera.exe (PID: 7412)
  • SUSPICIOUS

    • Application launched itself

      • setup.exe (PID: 7284)
      • setup.exe (PID: 7424)
      • assistant_installer.exe (PID: 5392)
      • installer.exe (PID: 4036)
      • assistant_installer.exe (PID: 6940)
      • assistant_installer.exe (PID: 3560)
      • browser_assistant.exe (PID: 8332)
      • opera.exe (PID: 7412)
      • installer.exe (PID: 2872)
      • opera_autoupdate.exe (PID: 9324)
      • opera_autoupdate.exe (PID: 9340)
    • Executable content was dropped or overwritten

      • setup.exe (PID: 7896)
      • setup.exe (PID: 7284)
      • setup.exe (PID: 7424)
      • setup.exe (PID: 7372)
      • Opera_GX_assistant_127.0.5778.41_Setup.exe_sfx.exe (PID: 2912)
      • installer.exe (PID: 2364)
      • installer.exe (PID: 4036)
      • assistant_installer.exe (PID: 6940)
      • setup.exe (PID: 6056)
      • installer.exe (PID: 7712)
      • installer.exe (PID: 2872)
      • opera_autoupdate.exe (PID: 9324)
      • installer.exe (PID: 7452)
    • Starts itself from another location

      • setup.exe (PID: 7284)
      • assistant_installer.exe (PID: 6940)
    • Process drops legitimate windows executable

      • setup.exe (PID: 7424)
      • Opera_GX_assistant_127.0.5778.41_Setup.exe_sfx.exe (PID: 2912)
      • assistant_installer.exe (PID: 6940)
    • Searches for installed software

      • installer.exe (PID: 4036)
      • browser_assistant.exe (PID: 8332)
    • Reads the date of Windows installation

      • installer.exe (PID: 4036)
      • opera.exe (PID: 7412)
    • Possible stealing from browsers

      • opera_crashreporter.exe (PID: 4152)
      • opera.exe (PID: 7412)
      • opera_crashreporter.exe (PID: 7788)
      • opera_crashreporter.exe (PID: 3240)
      • opera_crashreporter.exe (PID: 1212)
      • browser_assistant.exe (PID: 4364)
      • opera_crashreporter.exe (PID: 4128)
      • opera_crashreporter.exe (PID: 4800)
      • browser_assistant.exe (PID: 8332)
      • opera_autoupdate.exe (PID: 9464)
    • Reads Mozilla Firefox installation path

      • opera.exe (PID: 7412)
    • The process executes via Task Scheduler

      • opera_autoupdate.exe (PID: 9324)
  • INFO

    • Create files in a temporary directory

      • OperaGXSetup.exe (PID: 7876)
      • setup.exe (PID: 7284)
      • setup.exe (PID: 7896)
      • setup.exe (PID: 7424)
      • setup.exe (PID: 7372)
      • installer.exe (PID: 4036)
      • Opera_GX_assistant_127.0.5778.41_Setup.exe_sfx.exe (PID: 2912)
      • installer.exe (PID: 2364)
      • setup.exe (PID: 6056)
      • opera.exe (PID: 7412)
      • installer.exe (PID: 2872)
      • installer.exe (PID: 7712)
      • opera_autoupdate.exe (PID: 9324)
      • installer.exe (PID: 7452)
    • Checks supported languages

      • OperaGXSetup.exe (PID: 7876)
      • setup.exe (PID: 7896)
      • setup.exe (PID: 7284)
      • setup.exe (PID: 7372)
      • setup.exe (PID: 7424)
      • Opera_GX_assistant_127.0.5778.41_Setup.exe_sfx.exe (PID: 2912)
      • assistant_installer.exe (PID: 5392)
      • assistant_installer.exe (PID: 508)
      • installer.exe (PID: 2364)
      • installer.exe (PID: 4036)
      • assistant_installer.exe (PID: 6940)
      • assistant_installer.exe (PID: 8380)
      • assistant_installer.exe (PID: 3560)
      • opera.exe (PID: 7412)
      • browser_assistant.exe (PID: 8332)
      • opera.exe (PID: 9168)
      • opera_crashreporter.exe (PID: 4152)
      • setup.exe (PID: 6056)
      • browser_assistant.exe (PID: 4364)
      • assistant_installer.exe (PID: 6280)
      • opera_crashreporter.exe (PID: 7788)
      • opera.exe (PID: 224)
      • opera_crashreporter.exe (PID: 3240)
      • opera.exe (PID: 524)
      • opera_crashreporter.exe (PID: 1212)
      • opera.exe (PID: 5508)
      • opera.exe (PID: 7508)
      • opera_crashreporter.exe (PID: 4128)
      • opera.exe (PID: 7660)
      • opera_crashreporter.exe (PID: 4800)
      • opera.exe (PID: 8816)
      • opera.exe (PID: 2432)
      • opera.exe (PID: 8788)
      • opera.exe (PID: 2212)
      • opera.exe (PID: 2220)
      • opera.exe (PID: 144)
      • opera.exe (PID: 4144)
      • opera.exe (PID: 8228)
      • opera.exe (PID: 5200)
      • opera.exe (PID: 6320)
      • opera.exe (PID: 4040)
      • opera_gx_splash.exe (PID: 7776)
      • opera.exe (PID: 4604)
      • opera.exe (PID: 9048)
      • opera.exe (PID: 6416)
      • opera.exe (PID: 2280)
      • opera.exe (PID: 3988)
      • opera.exe (PID: 8512)
      • opera.exe (PID: 8028)
      • opera.exe (PID: 3636)
      • opera.exe (PID: 5224)
      • opera.exe (PID: 5100)
      • opera.exe (PID: 3628)
      • opera.exe (PID: 2608)
      • opera.exe (PID: 6640)
      • opera.exe (PID: 1732)
      • opera.exe (PID: 524)
      • opera.exe (PID: 7284)
      • opera.exe (PID: 2784)
      • opera.exe (PID: 3368)
      • opera.exe (PID: 6784)
      • opera.exe (PID: 7056)
      • opera.exe (PID: 1040)
      • opera.exe (PID: 5508)
      • opera.exe (PID: 4800)
      • opera.exe (PID: 1868)
      • opera.exe (PID: 7988)
      • opera.exe (PID: 3384)
      • opera.exe (PID: 1044)
      • opera.exe (PID: 8120)
      • installer.exe (PID: 2872)
      • installer.exe (PID: 7712)
      • opera_autoupdate.exe (PID: 9372)
      • opera_autoupdate.exe (PID: 9324)
      • opera_autoupdate.exe (PID: 9464)
      • opera_autoupdate.exe (PID: 9340)
      • opera.exe (PID: 9992)
      • opera.exe (PID: 9764)
      • opera.exe (PID: 9912)
      • opera.exe (PID: 9920)
      • opera.exe (PID: 10084)
      • opera.exe (PID: 10004)
      • opera.exe (PID: 508)
      • opera.exe (PID: 5204)
      • opera.exe (PID: 6504)
      • opera.exe (PID: 9288)
      • opera.exe (PID: 8996)
      • opera.exe (PID: 7392)
      • opera.exe (PID: 2280)
      • installer.exe (PID: 7452)
      • opera.exe (PID: 10152)
      • opera.exe (PID: 10200)
      • opera.exe (PID: 10208)
    • The sample compiled with english language support

      • setup.exe (PID: 7284)
      • setup.exe (PID: 7896)
      • setup.exe (PID: 7372)
      • setup.exe (PID: 7424)
      • Opera_GX_assistant_127.0.5778.41_Setup.exe_sfx.exe (PID: 2912)
      • installer.exe (PID: 2364)
      • installer.exe (PID: 4036)
      • assistant_installer.exe (PID: 6940)
      • setup.exe (PID: 6056)
      • installer.exe (PID: 7712)
      • installer.exe (PID: 2872)
      • opera_autoupdate.exe (PID: 9324)
      • installer.exe (PID: 7452)
    • Reads the computer name

      • setup.exe (PID: 7284)
      • setup.exe (PID: 7424)
      • assistant_installer.exe (PID: 5392)
      • installer.exe (PID: 4036)
      • assistant_installer.exe (PID: 6940)
      • assistant_installer.exe (PID: 3560)
      • opera.exe (PID: 7412)
      • opera.exe (PID: 9168)
      • browser_assistant.exe (PID: 8332)
      • opera.exe (PID: 224)
      • opera.exe (PID: 524)
      • opera.exe (PID: 5508)
      • opera.exe (PID: 7660)
      • opera.exe (PID: 7508)
      • opera.exe (PID: 8816)
      • opera_gx_splash.exe (PID: 7776)
      • opera.exe (PID: 6784)
      • installer.exe (PID: 2872)
      • opera_autoupdate.exe (PID: 9372)
      • opera_autoupdate.exe (PID: 9324)
      • opera_autoupdate.exe (PID: 9464)
      • opera_autoupdate.exe (PID: 9340)
    • Creates files or folders in the user directory

      • setup.exe (PID: 7896)
      • setup.exe (PID: 7424)
      • installer.exe (PID: 4036)
      • assistant_installer.exe (PID: 6940)
      • setup.exe (PID: 7284)
      • opera.exe (PID: 7412)
      • opera.exe (PID: 7508)
      • opera_autoupdate.exe (PID: 9340)
      • opera_autoupdate.exe (PID: 9372)
      • browser_assistant.exe (PID: 8332)
      • opera_autoupdate.exe (PID: 9324)
    • Reads security settings of Internet Explorer

      • setup.exe (PID: 7284)
      • installer.exe (PID: 4036)
      • browser_assistant.exe (PID: 8332)
    • Checks proxy server information

      • setup.exe (PID: 7284)
      • browser_assistant.exe (PID: 8332)
      • opera.exe (PID: 7412)
      • opera_autoupdate.exe (PID: 9340)
      • opera_autoupdate.exe (PID: 9324)
    • Reads the machine GUID from the registry

      • setup.exe (PID: 7284)
      • installer.exe (PID: 4036)
      • opera.exe (PID: 7412)
      • browser_assistant.exe (PID: 8332)
      • opera_autoupdate.exe (PID: 9340)
      • opera_autoupdate.exe (PID: 9372)
      • opera_autoupdate.exe (PID: 9324)
      • opera_autoupdate.exe (PID: 9464)
    • Drops script file

      • setup.exe (PID: 7424)
      • installer.exe (PID: 4036)
      • opera.exe (PID: 7412)
      • opera.exe (PID: 10004)
      • opera.exe (PID: 9992)
      • opera.exe (PID: 508)
      • opera.exe (PID: 9288)
    • There is functionality for taking screenshot (YARA)

      • setup.exe (PID: 7284)
    • Creates a software uninstall entry

      • installer.exe (PID: 4036)
    • Launching a file from a Registry key

      • assistant_installer.exe (PID: 6940)
      • opera.exe (PID: 7412)
    • OPERA mutex has been found

      • opera.exe (PID: 7412)
      • browser_assistant.exe (PID: 8332)
      • opera_autoupdate.exe (PID: 9340)
      • opera_autoupdate.exe (PID: 9324)
    • Process checks computer location settings

      • opera.exe (PID: 7412)
      • opera.exe (PID: 4144)
      • opera.exe (PID: 5200)
      • opera.exe (PID: 6320)
      • opera.exe (PID: 4604)
      • opera.exe (PID: 9048)
      • opera.exe (PID: 144)
      • opera.exe (PID: 8512)
      • opera.exe (PID: 524)
      • opera.exe (PID: 7284)
      • opera.exe (PID: 1044)
      • opera.exe (PID: 7988)
      • opera.exe (PID: 9764)
      • opera.exe (PID: 10084)
      • opera.exe (PID: 1040)
      • opera.exe (PID: 5204)
      • opera.exe (PID: 2280)
      • opera.exe (PID: 10208)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:06:12 14:59:19+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.39
CodeSize: 238080
InitializedDataSize: 92672
UninitializedDataSize: -
EntryPoint: 0x213c0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 127.0.5778.53
ProductVersionNumber: 127.0.5778.53
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
FileVersion: 127.0.5778.53
ProductVersion: 127.0.5778.53
FileDescription: Opera installer SFX
CompanyName:
LegalCopyright: Opera Software 2026
Productname: Opera installer
Stream: Stable
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
242
Monitored processes
97
Malicious processes
5
Suspicious processes
5

Behavior graph

Click at the process to see the details
start operagxsetup.exe no specs setup.exe setup.exe setup.exe setup.exe setup.exe opera_gx_assistant_127.0.5778.41_setup.exe_sfx.exe assistant_installer.exe assistant_installer.exe installer.exe installer.exe assistant_installer.exe assistant_installer.exe assistant_installer.exe assistant_installer.exe opera.exe browser_assistant.exe opera.exe no specs opera_crashreporter.exe opera_crashreporter.exe browser_assistant.exe opera.exe no specs opera_crashreporter.exe opera.exe no specs opera_crashreporter.exe opera.exe no specs opera_crashreporter.exe opera.exe no specs opera_crashreporter.exe unsecapp.exe no specs opera.exe no specs opera.exe opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera_gx_splash.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs installer.exe installer.exe opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera_autoupdate.exe opera_autoupdate.exe opera_autoupdate.exe opera_autoupdate.exe opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs comppkgsrv.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs installer.exe slui.exe no specs svchost.exe

Process information

PID
CMD
Path
Indicators
Parent process
144"C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe" --type=renderer --user-agent="Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36 OPR/127.0.0.0 (Edition std-2)" --no-pre-read-main-dll --force-high-res-timeticks=disabled --start-stack-profiler --with-feature:address-bar-dropdown-unfiltered-full=off --with-feature:address-bar-intent=on --with-feature:address-bar-intent-internal-matching=on --with-feature:ai-writing-mode-in-context-menu=on --with-feature:cashback-assistant=off --with-feature:certificate-transparency-enforcement=on --with-feature:continue-filter=on --with-feature:continue-shopping-structured-partners=on --with-feature:domain-suggestions-with-misspells=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:fun-voice-messages=on --with-feature:gx-post-mortem=on --with-feature:gx-streamlabs-promo-text=on --with-feature:image-search-support=on --with-feature:installer-experiment-test=off --with-feature:installer-move-opera-exe=off --with-feature:keywords-from-backend=on --with-feature:realtime-impressions-reporting=on --with-feature:run-at-startup-default=on --with-feature:sd-suggestions-external=on --with-feature:sitecheck-age=on --with-feature:tiktok-panel=on --with-feature:universal-skip-button=on --with-feature:vpn-pro-v4-support=on --ab_tests=GXCTest50-ref:DNA-99214_GXCTest50 --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=15 --metrics-shmem-handle=5320,i,16623143553103001263,4427520000153837387,2097152 --field-trial-handle=2008,i,14735383237363464474,8259557111573806048,262144 --enable-features=CertificateTransparencyAskBeforeEnabling,MultiThreadedUiCompositor --disable-features=AutoPictureInPictureForVideoPlayback,AutoPictureInPictureVideoHeuristics,CapitalOneCashbackProtection,MediaSessionEnterPictureInPicture,PlatformSoftwareH264EncoderInGpu,SyncWorkspacesInSessions --variations-seed-version --trace-process-track-uuid=3190709000367499229 --mojo-platform-channel-handle=5328 /prefetch:1C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera GX Internet Browser
Version:
127.0.5778.53
Modules
Images
c:\users\admin\appdata\local\programs\opera gx\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\programs\opera gx\127.0.5778.53\opera_elf.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
224"C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe" --streamC:\Users\admin\AppData\Local\Programs\Opera GX\opera.exebrowser_assistant.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera GX Internet Browser
Exit code:
0
Version:
127.0.5778.53
Modules
Images
c:\users\admin\appdata\local\programs\opera gx\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\programs\opera gx\127.0.5778.53\opera_elf.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shcore.dll
508"C:\Users\admin\AppData\Local\Temp\.opera\9de2e994-a724-4e67-8b75-4bc00b8b9b49 Opera GX Installer Temp\opera_package_202602121607331\assistant\assistant_installer.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktopGX --annotation=ver=127.0.5778.41 --initial-client-data=0x260,0x264,0x268,0x23c,0x26c,0x485cc0,0x485ccc,0x485cd8C:\Users\admin\AppData\Local\Temp\.opera\9de2e994-a724-4e67-8b75-4bc00b8b9b49 Opera GX Installer Temp\opera_package_202602121607331\assistant\assistant_installer.exe
assistant_installer.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera GX Browser Assistant Installer
Exit code:
0
Version:
127.0.5778.41
Modules
Images
c:\users\admin\appdata\local\temp\.opera\9de2e994-a724-4e67-8b75-4bc00b8b9b49 opera gx installer temp\opera_package_202602121607331\assistant\assistant_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
508"C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --enable-quic --no-pre-read-main-dll --force-high-res-timeticks=disabled --with-feature:address-bar-dropdown-unfiltered-full=off --with-feature:address-bar-intent=on --with-feature:address-bar-intent-internal-matching=on --with-feature:ai-writing-mode-in-context-menu=on --with-feature:cashback-assistant=off --with-feature:certificate-transparency-enforcement=on --with-feature:continue-filter=on --with-feature:continue-shopping-structured-partners=on --with-feature:domain-suggestions-with-misspells=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:fun-voice-messages=on --with-feature:gx-post-mortem=on --with-feature:gx-streamlabs-promo-text=on --with-feature:image-search-support=on --with-feature:installer-experiment-test=off --with-feature:installer-move-opera-exe=off --with-feature:keywords-from-backend=on --with-feature:realtime-impressions-reporting=on --with-feature:run-at-startup-default=on --with-feature:sd-suggestions-external=on --with-feature:sitecheck-age=on --with-feature:tiktok-panel=on --with-feature:universal-skip-button=on --with-feature:vpn-pro-v4-support=on --ab_tests=GXCTest50-ref:DNA-99214_GXCTest50 --metrics-shmem-handle=10572,i,5123272213520640216,10815217172965597150,524288 --field-trial-handle=2008,i,14735383237363464474,8259557111573806048,262144 --enable-features=CertificateTransparencyAskBeforeEnabling,MultiThreadedUiCompositor --disable-features=AutoPictureInPictureForVideoPlayback,AutoPictureInPictureVideoHeuristics,CapitalOneCashbackProtection,MediaSessionEnterPictureInPicture,PlatformSoftwareH264EncoderInGpu,SyncWorkspacesInSessions --variations-seed-version --trace-process-track-uuid=3190709035975089491 --mojo-platform-channel-handle=7720 /prefetch:8C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera GX Internet Browser
Exit code:
0
Version:
127.0.5778.53
Modules
Images
c:\users\admin\appdata\local\programs\opera gx\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\programs\opera gx\127.0.5778.53\opera_elf.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
524"C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe" --streamC:\Users\admin\AppData\Local\Programs\Opera GX\opera.exebrowser_assistant.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera GX Internet Browser
Exit code:
0
Version:
127.0.5778.53
Modules
Images
c:\users\admin\appdata\local\programs\opera gx\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\programs\opera gx\127.0.5778.53\opera_elf.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shcore.dll
524"C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe" --type=renderer --user-agent="Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36 OPR/127.0.0.0 (Edition std-2)" --no-pre-read-main-dll --force-high-res-timeticks=disabled --with-feature:address-bar-dropdown-unfiltered-full=off --with-feature:address-bar-intent=on --with-feature:address-bar-intent-internal-matching=on --with-feature:ai-writing-mode-in-context-menu=on --with-feature:cashback-assistant=off --with-feature:certificate-transparency-enforcement=on --with-feature:continue-filter=on --with-feature:continue-shopping-structured-partners=on --with-feature:domain-suggestions-with-misspells=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:fun-voice-messages=on --with-feature:gx-post-mortem=on --with-feature:gx-streamlabs-promo-text=on --with-feature:image-search-support=on --with-feature:installer-experiment-test=off --with-feature:installer-move-opera-exe=off --with-feature:keywords-from-backend=on --with-feature:realtime-impressions-reporting=on --with-feature:run-at-startup-default=on --with-feature:sd-suggestions-external=on --with-feature:sitecheck-age=on --with-feature:tiktok-panel=on --with-feature:universal-skip-button=on --with-feature:vpn-pro-v4-support=on --ab_tests=GXCTest50-ref:DNA-99214_GXCTest50 --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=11 --metrics-shmem-handle=7436,i,11689528944335477199,10553718216526058480,2097152 --field-trial-handle=2008,i,14735383237363464474,8259557111573806048,262144 --enable-features=CertificateTransparencyAskBeforeEnabling,MultiThreadedUiCompositor --disable-features=AutoPictureInPictureForVideoPlayback,AutoPictureInPictureVideoHeuristics,CapitalOneCashbackProtection,MediaSessionEnterPictureInPicture,PlatformSoftwareH264EncoderInGpu,SyncWorkspacesInSessions --variations-seed-version --trace-process-track-uuid=3190708996619331833 --mojo-platform-channel-handle=6716 /prefetch:1C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera GX Internet Browser
Version:
127.0.5778.53
Modules
Images
c:\users\admin\appdata\local\programs\opera gx\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\programs\opera gx\127.0.5778.53\opera_elf.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
1040"C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe" --type=renderer --extension-process --user-agent="Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36 OPR/127.0.0.0 (Edition std-2)" --no-pre-read-main-dll --force-high-res-timeticks=disabled --with-feature:address-bar-dropdown-unfiltered-full=off --with-feature:address-bar-intent=on --with-feature:address-bar-intent-internal-matching=on --with-feature:ai-writing-mode-in-context-menu=on --with-feature:cashback-assistant=off --with-feature:certificate-transparency-enforcement=on --with-feature:continue-filter=on --with-feature:continue-shopping-structured-partners=on --with-feature:domain-suggestions-with-misspells=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:fun-voice-messages=on --with-feature:gx-post-mortem=on --with-feature:gx-streamlabs-promo-text=on --with-feature:image-search-support=on --with-feature:installer-experiment-test=off --with-feature:installer-move-opera-exe=off --with-feature:keywords-from-backend=on --with-feature:realtime-impressions-reporting=on --with-feature:run-at-startup-default=on --with-feature:sd-suggestions-external=on --with-feature:sitecheck-age=on --with-feature:tiktok-panel=on --with-feature:universal-skip-button=on --with-feature:vpn-pro-v4-support=on --ab_tests=GXCTest50-ref:DNA-99214_GXCTest50 --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=24 --metrics-shmem-handle=6864,i,8215695489031229774,5778032678696828242,2097152 --field-trial-handle=2008,i,14735383237363464474,8259557111573806048,262144 --enable-features=CertificateTransparencyAskBeforeEnabling,MultiThreadedUiCompositor --disable-features=AutoPictureInPictureForVideoPlayback,AutoPictureInPictureVideoHeuristics,CapitalOneCashbackProtection,MediaSessionEnterPictureInPicture,PlatformSoftwareH264EncoderInGpu,SyncWorkspacesInSessions --variations-seed-version --trace-process-track-uuid=3190709008800875870 --mojo-platform-channel-handle=6944 /prefetch:2C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera GX Internet Browser
Version:
127.0.5778.53
Modules
Images
c:\users\admin\appdata\local\programs\opera gx\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\programs\opera gx\127.0.5778.53\opera_elf.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
1044"C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe" --type=renderer --user-agent="Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36 OPR/127.0.0.0 (Edition std-2)" --no-pre-read-main-dll --force-high-res-timeticks=disabled --with-feature:address-bar-dropdown-unfiltered-full=off --with-feature:address-bar-intent=on --with-feature:address-bar-intent-internal-matching=on --with-feature:ai-writing-mode-in-context-menu=on --with-feature:cashback-assistant=off --with-feature:certificate-transparency-enforcement=on --with-feature:continue-filter=on --with-feature:continue-shopping-structured-partners=on --with-feature:domain-suggestions-with-misspells=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:fun-voice-messages=on --with-feature:gx-post-mortem=on --with-feature:gx-streamlabs-promo-text=on --with-feature:image-search-support=on --with-feature:installer-experiment-test=off --with-feature:installer-move-opera-exe=off --with-feature:keywords-from-backend=on --with-feature:realtime-impressions-reporting=on --with-feature:run-at-startup-default=on --with-feature:sd-suggestions-external=on --with-feature:sitecheck-age=on --with-feature:tiktok-panel=on --with-feature:universal-skip-button=on --with-feature:vpn-pro-v4-support=on --ab_tests=GXCTest50-ref:DNA-99214_GXCTest50 --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=41 --metrics-shmem-handle=10160,i,9668241693445808234,14133243437194702454,2097152 --field-trial-handle=2008,i,14735383237363464474,8259557111573806048,262144 --enable-features=CertificateTransparencyAskBeforeEnabling,MultiThreadedUiCompositor --disable-features=AutoPictureInPictureForVideoPlayback,AutoPictureInPictureVideoHeuristics,CapitalOneCashbackProtection,MediaSessionEnterPictureInPicture,PlatformSoftwareH264EncoderInGpu,SyncWorkspacesInSessions --variations-seed-version --trace-process-track-uuid=3190709024730587303 --mojo-platform-channel-handle=3592 /prefetch:1C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera GX Internet Browser
Version:
127.0.5778.53
Modules
Images
c:\users\admin\appdata\local\programs\opera gx\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\programs\opera gx\127.0.5778.53\opera_elf.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
1212"C:\Users\admin\AppData\Local\Programs\Opera GX\127.0.5778.53\opera_crashreporter.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win64 --annotation=prod=OperaDesktopGX --annotation=ver=127.0.5778.53 --initial-client-data=0x218,0x21c,0x220,0x214,0x224,0x7ffd6198e3b0,0x7ffd6198e3c0,0x7ffd6198e3d0C:\Users\admin\AppData\Local\Programs\Opera GX\127.0.5778.53\opera_crashreporter.exe
opera.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera GX crash-reporter
Exit code:
0
Version:
127.0.5778.53
Modules
Images
c:\users\admin\appdata\local\programs\opera gx\127.0.5778.53\opera_crashreporter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1732"C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --enable-quic --no-pre-read-main-dll --force-high-res-timeticks=disabled --with-feature:address-bar-dropdown-unfiltered-full=off --with-feature:address-bar-intent=on --with-feature:address-bar-intent-internal-matching=on --with-feature:ai-writing-mode-in-context-menu=on --with-feature:cashback-assistant=off --with-feature:certificate-transparency-enforcement=on --with-feature:continue-filter=on --with-feature:continue-shopping-structured-partners=on --with-feature:domain-suggestions-with-misspells=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:fun-voice-messages=on --with-feature:gx-post-mortem=on --with-feature:gx-streamlabs-promo-text=on --with-feature:image-search-support=on --with-feature:installer-experiment-test=off --with-feature:installer-move-opera-exe=off --with-feature:keywords-from-backend=on --with-feature:realtime-impressions-reporting=on --with-feature:run-at-startup-default=on --with-feature:sd-suggestions-external=on --with-feature:sitecheck-age=on --with-feature:tiktok-panel=on --with-feature:universal-skip-button=on --with-feature:vpn-pro-v4-support=on --ab_tests=GXCTest50-ref:DNA-99214_GXCTest50 --metrics-shmem-handle=8800,i,8598458070250350427,2636912576853706067,524288 --field-trial-handle=2008,i,14735383237363464474,8259557111573806048,262144 --enable-features=CertificateTransparencyAskBeforeEnabling,MultiThreadedUiCompositor --disable-features=AutoPictureInPictureForVideoPlayback,AutoPictureInPictureVideoHeuristics,CapitalOneCashbackProtection,MediaSessionEnterPictureInPicture,PlatformSoftwareH264EncoderInGpu,SyncWorkspacesInSessions --variations-seed-version --trace-process-track-uuid=3190709019108336209 --mojo-platform-channel-handle=8980 /prefetch:8C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera GX Internet Browser
Exit code:
0
Version:
127.0.5778.53
Modules
Images
c:\users\admin\appdata\local\programs\opera gx\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\programs\opera gx\127.0.5778.53\opera_elf.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
Total events
19 740
Read events
19 162
Write events
567
Delete events
11

Modification events

(PID) Process:(7284) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7284) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7284) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7424) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Opera Software
Operation:writeName:Last Opera GX Stable Install Path
Value:
C:\Users\admin\AppData\Local\Programs\Opera GX\
(PID) Process:(4036) installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Opera Software
Operation:writeName:Last Opera GX Stable Install Path
Value:
C:\Users\admin\AppData\Local\Programs\Opera GX\
(PID) Process:(4036) installer.exeKey:HKEY_CLASSES_ROOT\Opera GXStable
Operation:writeName:FriendlyTypeName
Value:
Opera GX Web Document
(PID) Process:(4036) installer.exeKey:HKEY_CLASSES_ROOT\Opera GXStable
Operation:writeName:URL Protocol
Value:
(PID) Process:(4036) installer.exeKey:HKEY_CLASSES_ROOT\.gxanimations\OpenWithProgIDs
Operation:writeName:Opera GXStable
Value:
(PID) Process:(4036) installer.exeKey:HKEY_CLASSES_ROOT\.opdownload\OpenWithProgIDs
Operation:writeName:Opera GXStable
Value:
(PID) Process:(4036) installer.exeKey:HKEY_CLASSES_ROOT\.htm\OpenWithProgids
Operation:writeName:Opera GXStable
Value:
Executable files
46
Suspicious files
695
Text files
900
Unknown types
4

Dropped files

PID
Process
Filename
Type
7284setup.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\features[1].jsontext
MD5:A768D7D64A2F1763A7F10E81AC77671D
SHA256:9D28AB28B429B4EE36B2FD694692DD1EB815754B212F5E27F08A3564EEEA6042
7284setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\26C212D9399727259664BDFCA073966E_B7ED31D77D311A56FDCB56A0083B3E0Bbinary
MD5:1BC4A4EEEAC7B19D7BA12C6C11A62438
SHA256:F5D2D672C0713ADFC203BD6F69BB115B978CA62227A98D95F386CABE8FE857EA
7284setup.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KCV3KQBA\Opera_GX_127.0.5778.53_Autoupdate_x64[1].exe
MD5:
SHA256:
7284setup.exeC:\Users\admin\AppData\Local\Temp\.opera\9de2e994-a724-4e67-8b75-4bc00b8b9b49 Opera GX Installer Temp\opera_package_202602121607331\opera_package
MD5:
SHA256:
7284setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419binary
MD5:691DEF7A00FC708B53F040119DA7122E
SHA256:72D8C0F765D6837707112D909A75542A387495C23D0DB4F04A49AC0C75C87FF8
7284setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419binary
MD5:89C41E9AA13AE36E825AFB3F99136C89
SHA256:70F8441D93E3179D43FE48F70CEC3B01C8A1D7C1698AAA8EA6DB09876A35AA9A
7284setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CB77E3D8FE906716C4DEE1FAFFCB74A5binary
MD5:C94BCBC79C5D57DAF56CD558B5AB68E8
SHA256:B45FC464087EE87C97E8B9CB0FC20D5630AE38FB1D190CCFD41EA102E77203A7
7284setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8binary
MD5:DCD9D0A9086CA44C55B7577445350C08
SHA256:496E28F33151ED3E2DDE962BC79CD652EC6D3354A6C631693407C1BDC9F190AC
7284setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8binary
MD5:047F3E9D21D6B325D592B1959E4362E6
SHA256:D2BB091268ADE68AD8121D2184D0FBCE128070156304BD4DE312E6FBD267409C
7284setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\26C212D9399727259664BDFCA073966E_B7ED31D77D311A56FDCB56A0083B3E0Bbinary
MD5:07B8FFD352BCBBCBF0490B90CB54D931
SHA256:0055CCD14601B329968D950342EAE6BB6CAF53F9241EF09D85EE03F37CEC40EB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
30
TCP/UDP connections
127
DNS requests
107
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7284
setup.exe
GET
404
104.18.25.17:443
https://api.config.opr.gg/v0/config?utm_campaign=PWN_PL_HVR_9397_DD_268&utm_medium=pa&utm_source=PWNgames&product=gx&channel=Stable&client=netinstaller&edition=std-2
unknown
unknown
7284
setup.exe
GET
302
82.145.216.24:443
https://download.opera.com/download/get/?id=75873&autoupdate=1&ni=1&stream=stable&utm_campaign=PWN_PL_HVR_9397_DD_268&utm_id=8dc36bc5b9de4ace8bb8f8a67dd182af&utm_medium=pa&utm_source=PWNgames&niuid=1346eccc-1ea8-4de7-a171-5e8caf4f7511
unknown
unknown
7284
setup.exe
GET
104.18.11.89:443
https://download5.operacdn.com/ftp/pub/opera_gx/127.0.5778.53/win/Opera_GX_127.0.5778.53_Autoupdate_x64.exe
unknown
unknown
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAjTxtAB8my1oj8MfWpz%2F7Y%3D
unknown
whitelisted
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ3L3%2F%2Fa6ADK8NraY2GXzVaYrHG4AQUb6t%2B2v%2BXQ3LsO2d33oJhNYhHQoUCEzMAAAAGb6JMMcOVb6sAAAAAAAY%3D
unknown
whitelisted
7284
setup.exe
POST
201
82.145.217.121:443
https://desktop-netinstaller-sub.osp.opera.software/v1/binary
unknown
text
36 b
unknown
7284
setup.exe
GET
200
2.17.190.73:80
http://statusd.digitalcertvalidation.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRNolijWxrE%2B4oss3hMFE8Heagz1AQU9VYiH9m%2Fa1kkUrDhas3A4Vdn6egCEAaV2Cvjf8%2BY2vZ6CGdVSuk%3D
unknown
unknown
7284
setup.exe
POST
201
82.145.217.121:443
https://desktop-netinstaller-sub.osp.opera.software/v1/binary
unknown
text
36 b
unknown
7284
setup.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA7EEe3wAvcwNsTl1C8%2BNPI%3D
unknown
whitelisted
7284
setup.exe
POST
201
82.145.217.121:443
https://desktop-netinstaller-sub.osp.opera.software/v1/binary
unknown
text
36 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
8124
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
5040
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5568
SearchApp.exe
2.16.204.146:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
204.79.197.203:80
oneocsp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3412
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
7284
setup.exe
82.145.217.121:443
desktop-netinstaller-sub.osp.opera.software
NO-OPERA
NO
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
whitelisted
self.events.data.microsoft.com
  • 13.78.111.198
whitelisted
www.bing.com
  • 2.16.204.146
  • 2.16.204.143
  • 2.16.204.150
  • 2.16.204.139
  • 2.16.204.147
  • 2.16.204.141
  • 2.16.204.134
  • 2.16.204.148
  • 2.16.204.149
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
google.com
  • 142.251.127.113
  • 142.251.127.102
  • 142.251.127.138
  • 142.251.127.139
  • 142.251.127.100
  • 142.251.127.101
whitelisted
oneocsp.microsoft.com
  • 204.79.197.203
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
desktop-netinstaller-sub.osp.opera.software
  • 82.145.217.121
whitelisted
statusd.digitalcertvalidation.com
  • 2.17.190.73
whitelisted
autoupdate.opera.com
  • 185.26.182.123
  • 185.26.182.124
  • 82.145.216.20
  • 82.145.216.19
  • 82.145.216.47
  • 82.145.216.46
whitelisted

Threats

No threats detected
Process
Message
setup.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable directory exists )
setup.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable directory exists )
assistant_installer.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable directory exists )
assistant_installer.exe
[0212/160748.520:INFO:opera\desktop\windows\assistant\installer\assistant_installer_main.cc:170] Running assistant installer with command line "C:\Users\admin\AppData\Local\Temp\.opera\9de2e994-a724-4e67-8b75-4bc00b8b9b49 Opera GX Installer Temp\opera_package_202602121607331\assistant\assistant_installer.exe" --version
installer.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable directory exists )
assistant_installer.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable directory exists )
assistant_installer.exe
[0212/160758.994:INFO:opera\desktop\windows\assistant\installer\assistant_installer_main.cc:170] Running assistant installer with command line "C:\Users\admin\AppData\Local\Temp\.opera\9de2e994-a724-4e67-8b75-4bc00b8b9b49 Opera GX Installer Temp\opera_package_202602121607331\assistant\assistant_installer.exe" --installfolder="C:\Users\admin\AppData\Local\Programs\Opera GX\assistant" --copyonly=0 --allusers=0
assistant_installer.exe
[0212/160759.026:INFO:opera\desktop\windows\assistant\installer\assistant_installer.cc:308] Setting up the registry
assistant_installer.exe
[0212/160759.041:INFO:opera\desktop\windows\assistant\installer\assistant_installer.cc:359] Creating scheduled task
assistant_installer.exe
[0212/160759.104:INFO:opera\desktop\windows\assistant\installer\assistant_installer_main.cc:170] Running assistant installer with command line "C:\Users\admin\AppData\Local\Programs\Opera GX\assistant\assistant_installer.exe" --installfolder="C:\Users\admin\AppData\Local\Programs\Opera GX\assistant" --run-assistant --allusers=0