File name:

OperaGXSetup.exe

Full analysis: https://app.any.run/tasks/95e91b20-ac0c-479f-b638-87b13a673aaa
Verdict: Malicious activity
Analysis date: January 28, 2025, 03:53:19
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

0989A13E710CF58E17112D7DE5B51384

SHA1:

41A37C7B91916D780E97EE1F0BAA2C0D06950F19

SHA256:

891B01FA3524F72C3DC897D4E33D30C9DE5F630E8590293A6D88A2488A858E88

SSDEEP:

98304:iwyWSeMgteCMay6t0N+M2BNMZ8xrLRwDuG2KkJQuYXwM0Vy3gcFLGNG6Qg6pSI6k:ixGPdtobRZr

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • setup.exe (PID: 6204)
      • OperaGXSetup.exe (PID: 1468)
      • setup.exe (PID: 6180)
      • setup.exe (PID: 7028)
      • setup.exe (PID: 6308)
      • Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe (PID: 3364)
      • setup.exe (PID: 7052)
      • installer.exe (PID: 4548)
      • installer.exe (PID: 3876)
    • Application launched itself

      • setup.exe (PID: 6180)
      • setup.exe (PID: 7028)
      • assistant_installer.exe (PID: 624)
      • installer.exe (PID: 4548)
    • Starts itself from another location

      • setup.exe (PID: 6180)
    • Checks Windows Trust Settings

      • setup.exe (PID: 6180)
    • Reads security settings of Internet Explorer

      • setup.exe (PID: 6180)
      • installer.exe (PID: 4548)
    • Creates a software uninstall entry

      • installer.exe (PID: 4548)
    • Searches for installed software

      • installer.exe (PID: 4548)
    • Reads the date of Windows installation

      • installer.exe (PID: 4548)
  • INFO

    • Create files in a temporary directory

      • OperaGXSetup.exe (PID: 1468)
      • setup.exe (PID: 6204)
      • setup.exe (PID: 6308)
      • setup.exe (PID: 7028)
      • setup.exe (PID: 6180)
      • Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe (PID: 3364)
      • installer.exe (PID: 3876)
      • installer.exe (PID: 4548)
      • setup.exe (PID: 7052)
    • Checks supported languages

      • setup.exe (PID: 6180)
      • OperaGXSetup.exe (PID: 1468)
      • setup.exe (PID: 6204)
      • setup.exe (PID: 6308)
      • setup.exe (PID: 7028)
      • assistant_installer.exe (PID: 4648)
      • assistant_installer.exe (PID: 624)
      • installer.exe (PID: 3876)
      • setup.exe (PID: 7052)
      • Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe (PID: 3364)
      • installer.exe (PID: 4548)
      • opera.exe (PID: 6232)
    • Reads the computer name

      • setup.exe (PID: 6180)
      • setup.exe (PID: 7028)
      • assistant_installer.exe (PID: 624)
      • installer.exe (PID: 4548)
    • The sample compiled with english language support

      • OperaGXSetup.exe (PID: 1468)
      • setup.exe (PID: 6204)
      • setup.exe (PID: 6180)
      • setup.exe (PID: 7028)
      • setup.exe (PID: 6308)
      • Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe (PID: 3364)
      • setup.exe (PID: 7052)
      • installer.exe (PID: 3876)
      • installer.exe (PID: 4548)
    • Creates files or folders in the user directory

      • setup.exe (PID: 6204)
      • setup.exe (PID: 6180)
      • setup.exe (PID: 7028)
      • installer.exe (PID: 4548)
    • Checks proxy server information

      • setup.exe (PID: 6180)
    • Reads the machine GUID from the registry

      • setup.exe (PID: 6180)
    • Reads the software policy settings

      • setup.exe (PID: 6180)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:06:12 14:59:19+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.39
CodeSize: 238080
InitializedDataSize: 92672
UninitializedDataSize: -
EntryPoint: 0x213c0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 116.0.5366.54
ProductVersionNumber: 116.0.5366.54
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
FileVersion: 116.0.5366.54
ProductVersion: 116.0.5366.54
FileDescription: Opera installer SFX
CompanyName:
LegalCopyright: Opera Software 2025
Productname: Opera installer
Stream: Stable
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
137
Monitored processes
13
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start operagxsetup.exe setup.exe setup.exe setup.exe setup.exe setup.exe opera_gx_assistant_73.0.3856.382_setup.exe_sfx.exe assistant_installer.exe assistant_installer.exe no specs installer.exe installer.exe UIAutomationCrossBitnessHook32 Class no specs opera.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
624"C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202501280353261\assistant\assistant_installer.exe" --versionC:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202501280353261\assistant\assistant_installer.exe
setup.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera GX Browser Assistant Installer
Exit code:
0
Version:
73.0.3856.382
Modules
Images
c:\users\admin\appdata\local\temp\.opera\opera gx installer temp\opera_package_202501280353261\assistant\assistant_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1468"C:\Users\admin\AppData\Local\Temp\OperaGXSetup.exe" C:\Users\admin\AppData\Local\Temp\OperaGXSetup.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Opera installer SFX
Version:
116.0.5366.54
Modules
Images
c:\users\admin\appdata\local\temp\operagxsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
3364"C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202501280353261\assistant\Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe"C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202501280353261\assistant\Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe
setup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Opera installer SFX
Exit code:
0
Version:
73.0.3856.382
Modules
Images
c:\users\admin\appdata\local\temp\.opera\opera gx installer temp\opera_package_202501280353261\assistant\opera_gx_assistant_73.0.3856.382_setup.exe_sfx.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
3876"C:\Users\admin\AppData\Local\Programs\Opera GX\116.0.5366.54\installer.exe" --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win64 --annotation=prod=OperaDesktopGX --annotation=ver=116.0.5366.54 --initial-client-data=0x298,0x29c,0x2a0,0x27c,0x2a4,0x7ff8217e10d8,0x7ff8217e10e4,0x7ff8217e10f0C:\Users\admin\AppData\Local\Programs\Opera GX\116.0.5366.54\installer.exe
installer.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera GX Installer
Version:
116.0.5366.54
Modules
Images
c:\users\admin\appdata\local\programs\opera gx\116.0.5366.54\installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4548"C:\Users\admin\AppData\Local\Programs\Opera GX\116.0.5366.54\installer.exe" --backend --initial-pid=6180 --install --import-browser-data=0 --enable-crash-reporting=1 --enable-stats=1 --enable-installer-stats=1 --consent-given=1 --general-interests=1 --general-location=1 --personalized-content=1 --personalized-ads=1 --vought_browser=0 --launchopera=1 --showunbox=0 --installfolder="C:\Users\admin\AppData\Local\Programs\Opera GX" --profile-folder --language=en --singleprofile=0 --copyonly=0 --allusers=0 --setdefaultbrowser=1 --pintotaskbar=1 --pintostartmenu=1 --run-at-startup=1 --server-tracking-data=server_tracking_data --package-dir="C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202501280353261" --session-guid=ae623ab7-b688-4406-aec3-6725b14a66be --server-tracking-blob=ZjliMjkxNjFjMDYzMTYxMmU0YmZiYmY3YWU4MDIxNjQ5MWNlZjhmZGM5YzcwMmQyZmZiN2Y1MmE5YWRkYjQ0Yjp7ImNvdW50cnkiOiJVUyIsImVkaXRpb24iOiJzdGQtMiIsImh0dHBfcmVmZXJyZXIiOiJodHRwczovL3d3dy5vcGVyYS5jb20vIiwiaW5zdGFsbGVyX25hbWUiOiJPcGVyYUdYU2V0dXAuZXhlIiwicHJvZHVjdCI6eyJuYW1lIjoib3BlcmFfZ3gifSwicXVlcnkiOiIvb3BlcmFfZ3gvc3RhYmxlL3dpbmRvd3M/ZWRpdGlvbj1zdGQtMiZ1dG1fc291cmNlPVBXTmdhbWVzJnV0bV9tZWRpdW09cGEmdXRtX2NhbXBhaWduPVBXTl9VU19IVlJfOTM5Nl9XRUJfMzQwNSZlZGl0aW9uPXN0ZC0yJnV0bV9pZD00OWNmMjNjNDEyNDA0OTNlODg3OTdjOTljNTZlZjdmNyZodHRwX3JlZmVycmVyPWh0dHBzJTNBJTJGJTJGd3d3Lm9wZXJhLmNvbSUyRmdldCUyRm9wZXJhLWd4JTNGdXRtX3NvdXJjZSUzRFBXTmdhbWVzJTI2dXRtX21lZGl1bSUzRHBhJTI2dXRtX2NhbXBhaWduJTNEUFdOX1VTX0hWUl85Mzk2X1dFQl8zNDA1JTI2dXRtX2lkJTNENDljZjIzYzQxMjQwNDkzZTg4Nzk3Yzk5YzU2ZWY3ZjclMjZlZGl0aW9uJTNEc3RkLTImdXRtX3NpdGU9b3BlcmFfY29tJnV0bV9sYXN0cGFnZT1vcGVyYS5jb20lMkZnZXQlMkZvcGVyYS1neCZ1dG1faWQ9NDljZjIzYzQxMjQwNDkzZTg4Nzk3Yzk5YzU2ZWY3ZjcmZGxfdG9rZW49NDE4MDkzMTAiLCJzeXN0ZW0iOnsicGxhdGZvcm0iOnsiYXJjaCI6Ing4Nl82NCIsIm9wc3lzIjoiV2luZG93cyIsIm9wc3lzLXZlcnNpb24iOiIxMCIsInBhY2thZ2UiOiJFWEUifX0sInRpbWVzdGFtcCI6IjE3MzgwMzYxNDkuNzgyOSIsInVzZXJhZ2VudCI6Ik1vemlsbGEvNS4wIChXaW5kb3dzIE5UIDEwLjA7IFdpbjY0OyB4NjQpIEFwcGxlV2ViS2l0LzUzNy4zNiAoS0hUTUwsIGxpa2UgR2Vja28pIENocm9tZS8xMzIuMC4wLjAgU2FmYXJpLzUzNy4zNiIsInV0bSI6eyJjYW1wYWlnbiI6IlBXTl9VU19IVlJfOTM5Nl9XRUJfMzQwNSIsImlkIjoiNDljZjIzYzQxMjQwNDkzZTg4Nzk3Yzk5YzU2ZWY3ZjciLCJsYXN0cGFnZSI6Im9wZXJhLmNvbS9nZXQvb3BlcmEtZ3giLCJtZWRpdW0iOiJwYSIsInNpdGUiOiJvcGVyYV9jb20iLCJzb3VyY2UiOiJQV05nYW1lcyJ9LCJ1dWlkIjoiOWUwZTQ1ZDUtZGU5ZC00NTExLTljYmItNjRhN2I3NDdhNmY3In0= --desktopshortcut=1 --install-subfolder=116.0.5366.54C:\Users\admin\AppData\Local\Programs\Opera GX\116.0.5366.54\installer.exe
setup.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera GX Installer
Version:
116.0.5366.54
Modules
Images
c:\users\admin\appdata\local\programs\opera gx\116.0.5366.54\installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4648"C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202501280353261\assistant\assistant_installer.exe" --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\crash_count.txt" --url=https://crashstats-collector.opera.com/collector/submit --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktopGX --annotation=ver=73.0.3856.382 --initial-client-data=0x2b0,0x2b4,0x2b8,0x28c,0x2bc,0x1074f48,0x1074f58,0x1074f64C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202501280353261\assistant\assistant_installer.exeassistant_installer.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera GX Browser Assistant Installer
Exit code:
0
Version:
73.0.3856.382
Modules
Images
c:\users\admin\appdata\local\temp\.opera\opera gx installer temp\opera_package_202501280353261\assistant\assistant_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6180C:\Users\admin\AppData\Local\Temp\7zSCB58C373\setup.exe --server-tracking-blob=OGFjYmNmMmFiYTZkYmUxNWZlN2UyMGU5MzZiNTU0NmZlNzM5ZjMwNTEwMWVkMmM2NDZjNzBkMTQ1Yzc5YTAyMDp7ImNvdW50cnkiOiJVUyIsImVkaXRpb24iOiJzdGQtMiIsImh0dHBfcmVmZXJyZXIiOiJodHRwczovL3d3dy5vcGVyYS5jb20vIiwiaW5zdGFsbGVyX25hbWUiOiJPcGVyYUdYU2V0dXAuZXhlIiwicHJvZHVjdCI6Im9wZXJhX2d4IiwicXVlcnkiOiIvb3BlcmFfZ3gvc3RhYmxlL3dpbmRvd3M/ZWRpdGlvbj1zdGQtMiZ1dG1fc291cmNlPVBXTmdhbWVzJnV0bV9tZWRpdW09cGEmdXRtX2NhbXBhaWduPVBXTl9VU19IVlJfOTM5Nl9XRUJfMzQwNSZlZGl0aW9uPXN0ZC0yJnV0bV9pZD00OWNmMjNjNDEyNDA0OTNlODg3OTdjOTljNTZlZjdmNyZodHRwX3JlZmVycmVyPWh0dHBzJTNBJTJGJTJGd3d3Lm9wZXJhLmNvbSUyRmdldCUyRm9wZXJhLWd4JTNGdXRtX3NvdXJjZSUzRFBXTmdhbWVzJTI2dXRtX21lZGl1bSUzRHBhJTI2dXRtX2NhbXBhaWduJTNEUFdOX1VTX0hWUl85Mzk2X1dFQl8zNDA1JTI2dXRtX2lkJTNENDljZjIzYzQxMjQwNDkzZTg4Nzk3Yzk5YzU2ZWY3ZjclMjZlZGl0aW9uJTNEc3RkLTImdXRtX3NpdGU9b3BlcmFfY29tJnV0bV9sYXN0cGFnZT1vcGVyYS5jb20lMkZnZXQlMkZvcGVyYS1neCZ1dG1faWQ9NDljZjIzYzQxMjQwNDkzZTg4Nzk3Yzk5YzU2ZWY3ZjcmZGxfdG9rZW49NDE4MDkzMTAiLCJ0aW1lc3RhbXAiOiIxNzM4MDM2MTQ5Ljc4MjkiLCJ1c2VyYWdlbnQiOiJNb3ppbGxhLzUuMCAoV2luZG93cyBOVCAxMC4wOyBXaW42NDsgeDY0KSBBcHBsZVdlYktpdC81MzcuMzYgKEtIVE1MLCBsaWtlIEdlY2tvKSBDaHJvbWUvMTMyLjAuMC4wIFNhZmFyaS81MzcuMzYiLCJ1dG0iOnsiY2FtcGFpZ24iOiJQV05fVVNfSFZSXzkzOTZfV0VCXzM0MDUiLCJpZCI6IjQ5Y2YyM2M0MTI0MDQ5M2U4ODc5N2M5OWM1NmVmN2Y3IiwibGFzdHBhZ2UiOiJvcGVyYS5jb20vZ2V0L29wZXJhLWd4IiwibWVkaXVtIjoicGEiLCJzaXRlIjoib3BlcmFfY29tIiwic291cmNlIjoiUFdOZ2FtZXMifSwidXVpZCI6IjllMGU0NWQ1LWRlOWQtNDUxMS05Y2JiLTY0YTdiNzQ3YTZmNyJ9C:\Users\admin\AppData\Local\Temp\7zSCB58C373\setup.exe
OperaGXSetup.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera GX Installer
Version:
116.0.5366.54
Modules
Images
c:\users\admin\appdata\local\temp\7zscb58c373\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
6204C:\Users\admin\AppData\Local\Temp\7zSCB58C373\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktopGX --annotation=ver=116.0.5366.54 --initial-client-data=0x338,0x33c,0x340,0x2fc,0x344,0x74d42f6c,0x74d42f78,0x74d42f84C:\Users\admin\AppData\Local\Temp\7zSCB58C373\setup.exe
setup.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera GX Installer
Version:
116.0.5366.54
Modules
Images
c:\users\admin\appdata\local\temp\7zscb58c373\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
6232"C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe" --start-maximizedC:\Users\admin\AppData\Local\Programs\Opera GX\opera.exeinstaller.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera GX Internet Browser
Version:
116.0.5366.54
Modules
Images
c:\users\admin\appdata\local\programs\opera gx\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\programs\opera gx\116.0.5366.54\opera_elf.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shcore.dll
6308"C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\setup.exe" --versionC:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\setup.exe
setup.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\.opera\opera gx installer temp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
Total events
5 697
Read events
5 627
Write events
66
Delete events
4

Modification events

(PID) Process:(6180) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6180) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6180) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7028) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Opera Software
Operation:writeName:Last Opera GX Stable Install Path
Value:
C:\Users\admin\AppData\Local\Programs\Opera GX\
(PID) Process:(4548) installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Opera Software
Operation:writeName:Last Opera GX Stable Install Path
Value:
C:\Users\admin\AppData\Local\Programs\Opera GX\
(PID) Process:(4548) installer.exeKey:HKEY_CLASSES_ROOT\Opera GXStable
Operation:writeName:FriendlyTypeName
Value:
Opera GX Web Document
(PID) Process:(4548) installer.exeKey:HKEY_CLASSES_ROOT\Opera GXStable
Operation:writeName:URL Protocol
Value:
(PID) Process:(4548) installer.exeKey:HKEY_CLASSES_ROOT\.gxanimations\OpenWithProgIDs
Operation:writeName:Opera GXStable
Value:
(PID) Process:(4548) installer.exeKey:HKEY_CLASSES_ROOT\.opdownload\OpenWithProgIDs
Operation:writeName:Opera GXStable
Value:
(PID) Process:(4548) installer.exeKey:HKEY_CLASSES_ROOT\.htm\OpenWithProgids
Operation:writeName:Opera GXStable
Value:
Executable files
18
Suspicious files
42
Text files
32
Unknown types
0

Dropped files

PID
Process
Filename
Type
6180setup.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\Opera_GX_116.0.5366.54_Autoupdate_x64[1].exe
MD5:
SHA256:
6180setup.exeC:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202501280353261\opera_package
MD5:
SHA256:
1468OperaGXSetup.exeC:\Users\admin\AppData\Local\Temp\7zSCB58C373\setup.exeexecutable
MD5:0964E495FE984BC57511AA48D131DB03
SHA256:587BF26AA9B6FC20E9B844B2EC9FD73CC30AE6B2DEEB33BCE082EA96DA719175
6180setup.exeC:\Users\admin\AppData\Local\Temp\Opera_installer_2501280353256866180.dllexecutable
MD5:50C59FEAE31EC36E5F5EC12FA08A5072
SHA256:291A44E2302DCFB40E8C90676E6C21452094877513D7751E2590920E6B96574D
6180setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419binary
MD5:8B9BADE1F839BF2C9B8B73F5A0080FC6
SHA256:7F7E7193F4861EBCC574CB0EA757CBBFD3565E80521636FE2381B7C997AAC736
6180setup.exeC:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\setup.exeexecutable
MD5:0964E495FE984BC57511AA48D131DB03
SHA256:587BF26AA9B6FC20E9B844B2EC9FD73CC30AE6B2DEEB33BCE082EA96DA719175
6180setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12binary
MD5:C9BE626E9715952E9B70F92F912B9787
SHA256:C13E8D22800C200915F87F71C31185053E4E60CA25DE2E41E160E09CD2D815D4
6180setup.exeC:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\Crash Reports\settings.datbinary
MD5:82A3E507241B5BA183F4959830E97E91
SHA256:D2E867259DD3C072BE62D9A8CA7F511A5B9DB32B9AAB457FDA94E10E45BDFE62
7028setup.exeC:\Users\admin\AppData\Local\Temp\Opera_installer_2501280353336337028.dllexecutable
MD5:50C59FEAE31EC36E5F5EC12FA08A5072
SHA256:291A44E2302DCFB40E8C90676E6C21452094877513D7751E2590920E6B96574D
6180setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\59D76868C250B3240414CE3EFBB12518_9AD8E6D69BA520C5190A9B86E29789D5binary
MD5:37E90C6D6BFFB38E4DA2F21DB8D96209
SHA256:224C546419CDBEE85D69AA66C1D08EF2D71567A663F59213A3C4AF0D40D69A6F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
15
TCP/UDP connections
37
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6180
setup.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
unknown
whitelisted
6180
setup.exe
GET
200
172.217.16.195:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
6180
setup.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnxLiz3Fu1WB6n1%2FE6xWn1b0jXiQQUdIWAwGbH3zfez70pN6oDHb7tzRcCEA17ZgsSl63KHstWnAbUez0%3D
unknown
whitelisted
6180
setup.exe
GET
200
172.217.16.195:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
6180
setup.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
whitelisted
5064
SearchApp.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1704
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
436
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
1704
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5064
SearchApp.exe
2.23.227.208:443
www.bing.com
Ooredoo Q.S.C.
QA
whitelisted
6180
setup.exe
82.145.217.121:443
desktop-netinstaller-sub.osp.opera.software
Opera Software AS
NO
whitelisted
6180
setup.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
1076
svchost.exe
2.23.242.9:443
go.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
6180
setup.exe
185.26.182.123:443
autoupdate.opera.com
Opera Software AS
whitelisted
6180
setup.exe
82.145.216.16:443
features.opera-api2.com
Opera Software AS
NO
malicious
6180
setup.exe
104.18.24.17:443
api.config.opr.gg
CLOUDFLARENET
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.181.238
whitelisted
www.bing.com
  • 2.23.227.208
  • 2.23.227.215
whitelisted
desktop-netinstaller-sub.osp.opera.software
  • 82.145.217.121
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
go.microsoft.com
  • 2.23.242.9
whitelisted
autoupdate.opera.com
  • 185.26.182.123
  • 185.26.182.124
whitelisted
features.opera-api2.com
  • 82.145.216.16
  • 82.145.216.15
malicious
api.config.opr.gg
  • 104.18.24.17
  • 104.18.25.17
unknown
c.pki.goog
  • 172.217.16.195
whitelisted
download.opera.com
  • 82.145.216.49
  • 82.145.216.24
  • 82.145.216.48
  • 82.145.216.23
whitelisted

Threats

No threats detected
Process
Message
assistant_installer.exe
[0128/035406.751:INFO:assistant_installer_main.cc(169)] Running assistant installer with command line "C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202501280353261\assistant\assistant_installer.exe" --version