| File name: | OperaGXSetup.exe |
| Full analysis: | https://app.any.run/tasks/95e91b20-ac0c-479f-b638-87b13a673aaa |
| Verdict: | Malicious activity |
| Analysis date: | January 28, 2025, 03:53:19 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | 0989A13E710CF58E17112D7DE5B51384 |
| SHA1: | 41A37C7B91916D780E97EE1F0BAA2C0D06950F19 |
| SHA256: | 891B01FA3524F72C3DC897D4E33D30C9DE5F630E8590293A6D88A2488A858E88 |
| SSDEEP: | 98304:iwyWSeMgteCMay6t0N+M2BNMZ8xrLRwDuG2KkJQuYXwM0Vy3gcFLGNG6Qg6pSI6k:ixGPdtobRZr |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:06:12 14:59:19+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.39 |
| CodeSize: | 238080 |
| InitializedDataSize: | 92672 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x213c0 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 116.0.5366.54 |
| ProductVersionNumber: | 116.0.5366.54 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Unknown |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| FileVersion: | 116.0.5366.54 |
| ProductVersion: | 116.0.5366.54 |
| FileDescription: | Opera installer SFX |
| CompanyName: | |
| LegalCopyright: | Opera Software 2025 |
| Productname: | Opera installer |
| Stream: | Stable |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 624 | "C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202501280353261\assistant\assistant_installer.exe" --version | C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202501280353261\assistant\assistant_installer.exe | setup.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera GX Browser Assistant Installer Exit code: 0 Version: 73.0.3856.382 Modules
| |||||||||||||||
| 1468 | "C:\Users\admin\AppData\Local\Temp\OperaGXSetup.exe" | C:\Users\admin\AppData\Local\Temp\OperaGXSetup.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Opera installer SFX Version: 116.0.5366.54 Modules
| |||||||||||||||
| 3364 | "C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202501280353261\assistant\Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe" | C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202501280353261\assistant\Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe | setup.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Opera installer SFX Exit code: 0 Version: 73.0.3856.382 Modules
| |||||||||||||||
| 3876 | "C:\Users\admin\AppData\Local\Programs\Opera GX\116.0.5366.54\installer.exe" --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win64 --annotation=prod=OperaDesktopGX --annotation=ver=116.0.5366.54 --initial-client-data=0x298,0x29c,0x2a0,0x27c,0x2a4,0x7ff8217e10d8,0x7ff8217e10e4,0x7ff8217e10f0 | C:\Users\admin\AppData\Local\Programs\Opera GX\116.0.5366.54\installer.exe | installer.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera GX Installer Version: 116.0.5366.54 Modules
| |||||||||||||||
| 4548 | "C:\Users\admin\AppData\Local\Programs\Opera GX\116.0.5366.54\installer.exe" --backend --initial-pid=6180 --install --import-browser-data=0 --enable-crash-reporting=1 --enable-stats=1 --enable-installer-stats=1 --consent-given=1 --general-interests=1 --general-location=1 --personalized-content=1 --personalized-ads=1 --vought_browser=0 --launchopera=1 --showunbox=0 --installfolder="C:\Users\admin\AppData\Local\Programs\Opera GX" --profile-folder --language=en --singleprofile=0 --copyonly=0 --allusers=0 --setdefaultbrowser=1 --pintotaskbar=1 --pintostartmenu=1 --run-at-startup=1 --server-tracking-data=server_tracking_data --package-dir="C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202501280353261" --session-guid=ae623ab7-b688-4406-aec3-6725b14a66be --server-tracking-blob=ZjliMjkxNjFjMDYzMTYxMmU0YmZiYmY3YWU4MDIxNjQ5MWNlZjhmZGM5YzcwMmQyZmZiN2Y1MmE5YWRkYjQ0Yjp7ImNvdW50cnkiOiJVUyIsImVkaXRpb24iOiJzdGQtMiIsImh0dHBfcmVmZXJyZXIiOiJodHRwczovL3d3dy5vcGVyYS5jb20vIiwiaW5zdGFsbGVyX25hbWUiOiJPcGVyYUdYU2V0dXAuZXhlIiwicHJvZHVjdCI6eyJuYW1lIjoib3BlcmFfZ3gifSwicXVlcnkiOiIvb3BlcmFfZ3gvc3RhYmxlL3dpbmRvd3M/ZWRpdGlvbj1zdGQtMiZ1dG1fc291cmNlPVBXTmdhbWVzJnV0bV9tZWRpdW09cGEmdXRtX2NhbXBhaWduPVBXTl9VU19IVlJfOTM5Nl9XRUJfMzQwNSZlZGl0aW9uPXN0ZC0yJnV0bV9pZD00OWNmMjNjNDEyNDA0OTNlODg3OTdjOTljNTZlZjdmNyZodHRwX3JlZmVycmVyPWh0dHBzJTNBJTJGJTJGd3d3Lm9wZXJhLmNvbSUyRmdldCUyRm9wZXJhLWd4JTNGdXRtX3NvdXJjZSUzRFBXTmdhbWVzJTI2dXRtX21lZGl1bSUzRHBhJTI2dXRtX2NhbXBhaWduJTNEUFdOX1VTX0hWUl85Mzk2X1dFQl8zNDA1JTI2dXRtX2lkJTNENDljZjIzYzQxMjQwNDkzZTg4Nzk3Yzk5YzU2ZWY3ZjclMjZlZGl0aW9uJTNEc3RkLTImdXRtX3NpdGU9b3BlcmFfY29tJnV0bV9sYXN0cGFnZT1vcGVyYS5jb20lMkZnZXQlMkZvcGVyYS1neCZ1dG1faWQ9NDljZjIzYzQxMjQwNDkzZTg4Nzk3Yzk5YzU2ZWY3ZjcmZGxfdG9rZW49NDE4MDkzMTAiLCJzeXN0ZW0iOnsicGxhdGZvcm0iOnsiYXJjaCI6Ing4Nl82NCIsIm9wc3lzIjoiV2luZG93cyIsIm9wc3lzLXZlcnNpb24iOiIxMCIsInBhY2thZ2UiOiJFWEUifX0sInRpbWVzdGFtcCI6IjE3MzgwMzYxNDkuNzgyOSIsInVzZXJhZ2VudCI6Ik1vemlsbGEvNS4wIChXaW5kb3dzIE5UIDEwLjA7IFdpbjY0OyB4NjQpIEFwcGxlV2ViS2l0LzUzNy4zNiAoS0hUTUwsIGxpa2UgR2Vja28pIENocm9tZS8xMzIuMC4wLjAgU2FmYXJpLzUzNy4zNiIsInV0bSI6eyJjYW1wYWlnbiI6IlBXTl9VU19IVlJfOTM5Nl9XRUJfMzQwNSIsImlkIjoiNDljZjIzYzQxMjQwNDkzZTg4Nzk3Yzk5YzU2ZWY3ZjciLCJsYXN0cGFnZSI6Im9wZXJhLmNvbS9nZXQvb3BlcmEtZ3giLCJtZWRpdW0iOiJwYSIsInNpdGUiOiJvcGVyYV9jb20iLCJzb3VyY2UiOiJQV05nYW1lcyJ9LCJ1dWlkIjoiOWUwZTQ1ZDUtZGU5ZC00NTExLTljYmItNjRhN2I3NDdhNmY3In0= --desktopshortcut=1 --install-subfolder=116.0.5366.54 | C:\Users\admin\AppData\Local\Programs\Opera GX\116.0.5366.54\installer.exe | setup.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera GX Installer Version: 116.0.5366.54 Modules
| |||||||||||||||
| 4648 | "C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202501280353261\assistant\assistant_installer.exe" --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\crash_count.txt" --url=https://crashstats-collector.opera.com/collector/submit --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktopGX --annotation=ver=73.0.3856.382 --initial-client-data=0x2b0,0x2b4,0x2b8,0x28c,0x2bc,0x1074f48,0x1074f58,0x1074f64 | C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202501280353261\assistant\assistant_installer.exe | — | assistant_installer.exe | |||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera GX Browser Assistant Installer Exit code: 0 Version: 73.0.3856.382 Modules
| |||||||||||||||
| 6180 | C:\Users\admin\AppData\Local\Temp\7zSCB58C373\setup.exe --server-tracking-blob=OGFjYmNmMmFiYTZkYmUxNWZlN2UyMGU5MzZiNTU0NmZlNzM5ZjMwNTEwMWVkMmM2NDZjNzBkMTQ1Yzc5YTAyMDp7ImNvdW50cnkiOiJVUyIsImVkaXRpb24iOiJzdGQtMiIsImh0dHBfcmVmZXJyZXIiOiJodHRwczovL3d3dy5vcGVyYS5jb20vIiwiaW5zdGFsbGVyX25hbWUiOiJPcGVyYUdYU2V0dXAuZXhlIiwicHJvZHVjdCI6Im9wZXJhX2d4IiwicXVlcnkiOiIvb3BlcmFfZ3gvc3RhYmxlL3dpbmRvd3M/ZWRpdGlvbj1zdGQtMiZ1dG1fc291cmNlPVBXTmdhbWVzJnV0bV9tZWRpdW09cGEmdXRtX2NhbXBhaWduPVBXTl9VU19IVlJfOTM5Nl9XRUJfMzQwNSZlZGl0aW9uPXN0ZC0yJnV0bV9pZD00OWNmMjNjNDEyNDA0OTNlODg3OTdjOTljNTZlZjdmNyZodHRwX3JlZmVycmVyPWh0dHBzJTNBJTJGJTJGd3d3Lm9wZXJhLmNvbSUyRmdldCUyRm9wZXJhLWd4JTNGdXRtX3NvdXJjZSUzRFBXTmdhbWVzJTI2dXRtX21lZGl1bSUzRHBhJTI2dXRtX2NhbXBhaWduJTNEUFdOX1VTX0hWUl85Mzk2X1dFQl8zNDA1JTI2dXRtX2lkJTNENDljZjIzYzQxMjQwNDkzZTg4Nzk3Yzk5YzU2ZWY3ZjclMjZlZGl0aW9uJTNEc3RkLTImdXRtX3NpdGU9b3BlcmFfY29tJnV0bV9sYXN0cGFnZT1vcGVyYS5jb20lMkZnZXQlMkZvcGVyYS1neCZ1dG1faWQ9NDljZjIzYzQxMjQwNDkzZTg4Nzk3Yzk5YzU2ZWY3ZjcmZGxfdG9rZW49NDE4MDkzMTAiLCJ0aW1lc3RhbXAiOiIxNzM4MDM2MTQ5Ljc4MjkiLCJ1c2VyYWdlbnQiOiJNb3ppbGxhLzUuMCAoV2luZG93cyBOVCAxMC4wOyBXaW42NDsgeDY0KSBBcHBsZVdlYktpdC81MzcuMzYgKEtIVE1MLCBsaWtlIEdlY2tvKSBDaHJvbWUvMTMyLjAuMC4wIFNhZmFyaS81MzcuMzYiLCJ1dG0iOnsiY2FtcGFpZ24iOiJQV05fVVNfSFZSXzkzOTZfV0VCXzM0MDUiLCJpZCI6IjQ5Y2YyM2M0MTI0MDQ5M2U4ODc5N2M5OWM1NmVmN2Y3IiwibGFzdHBhZ2UiOiJvcGVyYS5jb20vZ2V0L29wZXJhLWd4IiwibWVkaXVtIjoicGEiLCJzaXRlIjoib3BlcmFfY29tIiwic291cmNlIjoiUFdOZ2FtZXMifSwidXVpZCI6IjllMGU0NWQ1LWRlOWQtNDUxMS05Y2JiLTY0YTdiNzQ3YTZmNyJ9 | C:\Users\admin\AppData\Local\Temp\7zSCB58C373\setup.exe | OperaGXSetup.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera GX Installer Version: 116.0.5366.54 Modules
| |||||||||||||||
| 6204 | C:\Users\admin\AppData\Local\Temp\7zSCB58C373\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktopGX --annotation=ver=116.0.5366.54 --initial-client-data=0x338,0x33c,0x340,0x2fc,0x344,0x74d42f6c,0x74d42f78,0x74d42f84 | C:\Users\admin\AppData\Local\Temp\7zSCB58C373\setup.exe | setup.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera GX Installer Version: 116.0.5366.54 Modules
| |||||||||||||||
| 6232 | "C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe" --start-maximized | C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe | — | installer.exe | |||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera GX Internet Browser Version: 116.0.5366.54 Modules
| |||||||||||||||
| 6308 | "C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\setup.exe" --version | C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\setup.exe | setup.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (6180) setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (6180) setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (6180) setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (7028) setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Opera Software |
| Operation: | write | Name: | Last Opera GX Stable Install Path |
Value: C:\Users\admin\AppData\Local\Programs\Opera GX\ | |||
| (PID) Process: | (4548) installer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Opera Software |
| Operation: | write | Name: | Last Opera GX Stable Install Path |
Value: C:\Users\admin\AppData\Local\Programs\Opera GX\ | |||
| (PID) Process: | (4548) installer.exe | Key: | HKEY_CLASSES_ROOT\Opera GXStable |
| Operation: | write | Name: | FriendlyTypeName |
Value: Opera GX Web Document | |||
| (PID) Process: | (4548) installer.exe | Key: | HKEY_CLASSES_ROOT\Opera GXStable |
| Operation: | write | Name: | URL Protocol |
Value: | |||
| (PID) Process: | (4548) installer.exe | Key: | HKEY_CLASSES_ROOT\.gxanimations\OpenWithProgIDs |
| Operation: | write | Name: | Opera GXStable |
Value: | |||
| (PID) Process: | (4548) installer.exe | Key: | HKEY_CLASSES_ROOT\.opdownload\OpenWithProgIDs |
| Operation: | write | Name: | Opera GXStable |
Value: | |||
| (PID) Process: | (4548) installer.exe | Key: | HKEY_CLASSES_ROOT\.htm\OpenWithProgids |
| Operation: | write | Name: | Opera GXStable |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6180 | setup.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\Opera_GX_116.0.5366.54_Autoupdate_x64[1].exe | — | |
MD5:— | SHA256:— | |||
| 6180 | setup.exe | C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202501280353261\opera_package | — | |
MD5:— | SHA256:— | |||
| 1468 | OperaGXSetup.exe | C:\Users\admin\AppData\Local\Temp\7zSCB58C373\setup.exe | executable | |
MD5:0964E495FE984BC57511AA48D131DB03 | SHA256:587BF26AA9B6FC20E9B844B2EC9FD73CC30AE6B2DEEB33BCE082EA96DA719175 | |||
| 6180 | setup.exe | C:\Users\admin\AppData\Local\Temp\Opera_installer_2501280353256866180.dll | executable | |
MD5:50C59FEAE31EC36E5F5EC12FA08A5072 | SHA256:291A44E2302DCFB40E8C90676E6C21452094877513D7751E2590920E6B96574D | |||
| 6180 | setup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419 | binary | |
MD5:8B9BADE1F839BF2C9B8B73F5A0080FC6 | SHA256:7F7E7193F4861EBCC574CB0EA757CBBFD3565E80521636FE2381B7C997AAC736 | |||
| 6180 | setup.exe | C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\setup.exe | executable | |
MD5:0964E495FE984BC57511AA48D131DB03 | SHA256:587BF26AA9B6FC20E9B844B2EC9FD73CC30AE6B2DEEB33BCE082EA96DA719175 | |||
| 6180 | setup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12 | binary | |
MD5:C9BE626E9715952E9B70F92F912B9787 | SHA256:C13E8D22800C200915F87F71C31185053E4E60CA25DE2E41E160E09CD2D815D4 | |||
| 6180 | setup.exe | C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\Crash Reports\settings.dat | binary | |
MD5:82A3E507241B5BA183F4959830E97E91 | SHA256:D2E867259DD3C072BE62D9A8CA7F511A5B9DB32B9AAB457FDA94E10E45BDFE62 | |||
| 7028 | setup.exe | C:\Users\admin\AppData\Local\Temp\Opera_installer_2501280353336337028.dll | executable | |
MD5:50C59FEAE31EC36E5F5EC12FA08A5072 | SHA256:291A44E2302DCFB40E8C90676E6C21452094877513D7751E2590920E6B96574D | |||
| 6180 | setup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\59D76868C250B3240414CE3EFBB12518_9AD8E6D69BA520C5190A9B86E29789D5 | binary | |
MD5:37E90C6D6BFFB38E4DA2F21DB8D96209 | SHA256:224C546419CDBEE85D69AA66C1D08EF2D71567A663F59213A3C4AF0D40D69A6F | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6180 | setup.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D | unknown | — | — | whitelisted |
6180 | setup.exe | GET | 200 | 172.217.16.195:80 | http://c.pki.goog/r/gsr1.crl | unknown | — | — | whitelisted |
6180 | setup.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnxLiz3Fu1WB6n1%2FE6xWn1b0jXiQQUdIWAwGbH3zfez70pN6oDHb7tzRcCEA17ZgsSl63KHstWnAbUez0%3D | unknown | — | — | whitelisted |
6180 | setup.exe | GET | 200 | 172.217.16.195:80 | http://c.pki.goog/r/r4.crl | unknown | — | — | whitelisted |
6180 | setup.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D | unknown | — | — | whitelisted |
5064 | SearchApp.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
1704 | SIHClient.exe | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
436 | backgroundTaskHost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
1704 | SIHClient.exe | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 4.231.128.59:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5064 | SearchApp.exe | 2.23.227.208:443 | www.bing.com | Ooredoo Q.S.C. | QA | whitelisted |
6180 | setup.exe | 82.145.217.121:443 | desktop-netinstaller-sub.osp.opera.software | Opera Software AS | NO | whitelisted |
6180 | setup.exe | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
1076 | svchost.exe | 2.23.242.9:443 | go.microsoft.com | Ooredoo Q.S.C. | QA | whitelisted |
6180 | setup.exe | 185.26.182.123:443 | autoupdate.opera.com | Opera Software AS | — | whitelisted |
6180 | setup.exe | 82.145.216.16:443 | features.opera-api2.com | Opera Software AS | NO | malicious |
6180 | setup.exe | 104.18.24.17:443 | api.config.opr.gg | CLOUDFLARENET | — | unknown |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
desktop-netinstaller-sub.osp.opera.software |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
autoupdate.opera.com |
| whitelisted |
features.opera-api2.com |
| malicious |
api.config.opr.gg |
| unknown |
c.pki.goog |
| whitelisted |
download.opera.com |
| whitelisted |
Process | Message |
|---|---|
assistant_installer.exe | [0128/035406.751:INFO:assistant_installer_main.cc(169)] Running assistant installer with command line "C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202501280353261\assistant\assistant_installer.exe" --version
|