File name:

OperaGXSetup.exe

Full analysis: https://app.any.run/tasks/95e91b20-ac0c-479f-b638-87b13a673aaa
Verdict: Malicious activity
Analysis date: January 28, 2025, 03:53:19
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

0989A13E710CF58E17112D7DE5B51384

SHA1:

41A37C7B91916D780E97EE1F0BAA2C0D06950F19

SHA256:

891B01FA3524F72C3DC897D4E33D30C9DE5F630E8590293A6D88A2488A858E88

SSDEEP:

98304:iwyWSeMgteCMay6t0N+M2BNMZ8xrLRwDuG2KkJQuYXwM0Vy3gcFLGNG6Qg6pSI6k:ixGPdtobRZr

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • setup.exe (PID: 6204)
      • setup.exe (PID: 6308)
      • setup.exe (PID: 7028)
      • setup.exe (PID: 7052)
      • Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe (PID: 3364)
      • installer.exe (PID: 3876)
      • OperaGXSetup.exe (PID: 1468)
      • setup.exe (PID: 6180)
      • installer.exe (PID: 4548)
    • Starts itself from another location

      • setup.exe (PID: 6180)
    • Checks Windows Trust Settings

      • setup.exe (PID: 6180)
    • Reads security settings of Internet Explorer

      • setup.exe (PID: 6180)
      • installer.exe (PID: 4548)
    • Application launched itself

      • setup.exe (PID: 7028)
      • assistant_installer.exe (PID: 624)
      • installer.exe (PID: 4548)
      • setup.exe (PID: 6180)
    • Searches for installed software

      • installer.exe (PID: 4548)
    • Creates a software uninstall entry

      • installer.exe (PID: 4548)
    • Reads the date of Windows installation

      • installer.exe (PID: 4548)
  • INFO

    • Create files in a temporary directory

      • OperaGXSetup.exe (PID: 1468)
      • setup.exe (PID: 6204)
      • setup.exe (PID: 6308)
      • setup.exe (PID: 6180)
      • setup.exe (PID: 7028)
      • setup.exe (PID: 7052)
      • installer.exe (PID: 4548)
      • Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe (PID: 3364)
      • installer.exe (PID: 3876)
    • Checks supported languages

      • OperaGXSetup.exe (PID: 1468)
      • setup.exe (PID: 6180)
      • setup.exe (PID: 6308)
      • setup.exe (PID: 7052)
      • setup.exe (PID: 7028)
      • Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe (PID: 3364)
      • assistant_installer.exe (PID: 624)
      • assistant_installer.exe (PID: 4648)
      • installer.exe (PID: 3876)
      • installer.exe (PID: 4548)
      • opera.exe (PID: 6232)
      • setup.exe (PID: 6204)
    • Creates files or folders in the user directory

      • setup.exe (PID: 6204)
      • setup.exe (PID: 6180)
      • setup.exe (PID: 7028)
      • installer.exe (PID: 4548)
    • The sample compiled with english language support

      • setup.exe (PID: 6204)
      • setup.exe (PID: 6180)
      • setup.exe (PID: 6308)
      • setup.exe (PID: 7028)
      • setup.exe (PID: 7052)
      • Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe (PID: 3364)
      • installer.exe (PID: 3876)
      • OperaGXSetup.exe (PID: 1468)
      • installer.exe (PID: 4548)
    • Reads the software policy settings

      • setup.exe (PID: 6180)
    • Checks proxy server information

      • setup.exe (PID: 6180)
    • Reads the machine GUID from the registry

      • setup.exe (PID: 6180)
    • Reads the computer name

      • setup.exe (PID: 7028)
      • assistant_installer.exe (PID: 624)
      • installer.exe (PID: 4548)
      • setup.exe (PID: 6180)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:06:12 14:59:19+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.39
CodeSize: 238080
InitializedDataSize: 92672
UninitializedDataSize: -
EntryPoint: 0x213c0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 116.0.5366.54
ProductVersionNumber: 116.0.5366.54
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
FileVersion: 116.0.5366.54
ProductVersion: 116.0.5366.54
FileDescription: Opera installer SFX
CompanyName:
LegalCopyright: Opera Software 2025
Productname: Opera installer
Stream: Stable
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
137
Monitored processes
13
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start operagxsetup.exe setup.exe setup.exe setup.exe setup.exe setup.exe opera_gx_assistant_73.0.3856.382_setup.exe_sfx.exe assistant_installer.exe assistant_installer.exe no specs installer.exe installer.exe UIAutomationCrossBitnessHook32 Class no specs opera.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
624"C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202501280353261\assistant\assistant_installer.exe" --versionC:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202501280353261\assistant\assistant_installer.exe
setup.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera GX Browser Assistant Installer
Exit code:
0
Version:
73.0.3856.382
Modules
Images
c:\users\admin\appdata\local\temp\.opera\opera gx installer temp\opera_package_202501280353261\assistant\assistant_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1468"C:\Users\admin\AppData\Local\Temp\OperaGXSetup.exe" C:\Users\admin\AppData\Local\Temp\OperaGXSetup.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Opera installer SFX
Version:
116.0.5366.54
Modules
Images
c:\users\admin\appdata\local\temp\operagxsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
3364"C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202501280353261\assistant\Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe"C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202501280353261\assistant\Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe
setup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Opera installer SFX
Exit code:
0
Version:
73.0.3856.382
Modules
Images
c:\users\admin\appdata\local\temp\.opera\opera gx installer temp\opera_package_202501280353261\assistant\opera_gx_assistant_73.0.3856.382_setup.exe_sfx.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
3876"C:\Users\admin\AppData\Local\Programs\Opera GX\116.0.5366.54\installer.exe" --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win64 --annotation=prod=OperaDesktopGX --annotation=ver=116.0.5366.54 --initial-client-data=0x298,0x29c,0x2a0,0x27c,0x2a4,0x7ff8217e10d8,0x7ff8217e10e4,0x7ff8217e10f0C:\Users\admin\AppData\Local\Programs\Opera GX\116.0.5366.54\installer.exe
installer.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera GX Installer
Version:
116.0.5366.54
Modules
Images
c:\users\admin\appdata\local\programs\opera gx\116.0.5366.54\installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4548"C:\Users\admin\AppData\Local\Programs\Opera GX\116.0.5366.54\installer.exe" --backend --initial-pid=6180 --install --import-browser-data=0 --enable-crash-reporting=1 --enable-stats=1 --enable-installer-stats=1 --consent-given=1 --general-interests=1 --general-location=1 --personalized-content=1 --personalized-ads=1 --vought_browser=0 --launchopera=1 --showunbox=0 --installfolder="C:\Users\admin\AppData\Local\Programs\Opera GX" --profile-folder --language=en --singleprofile=0 --copyonly=0 --allusers=0 --setdefaultbrowser=1 --pintotaskbar=1 --pintostartmenu=1 --run-at-startup=1 --server-tracking-data=server_tracking_data --package-dir="C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202501280353261" --session-guid=ae623ab7-b688-4406-aec3-6725b14a66be --server-tracking-blob=ZjliMjkxNjFjMDYzMTYxMmU0YmZiYmY3YWU4MDIxNjQ5MWNlZjhmZGM5YzcwMmQyZmZiN2Y1MmE5YWRkYjQ0Yjp7ImNvdW50cnkiOiJVUyIsImVkaXRpb24iOiJzdGQtMiIsImh0dHBfcmVmZXJyZXIiOiJodHRwczovL3d3dy5vcGVyYS5jb20vIiwiaW5zdGFsbGVyX25hbWUiOiJPcGVyYUdYU2V0dXAuZXhlIiwicHJvZHVjdCI6eyJuYW1lIjoib3BlcmFfZ3gifSwicXVlcnkiOiIvb3BlcmFfZ3gvc3RhYmxlL3dpbmRvd3M/ZWRpdGlvbj1zdGQtMiZ1dG1fc291cmNlPVBXTmdhbWVzJnV0bV9tZWRpdW09cGEmdXRtX2NhbXBhaWduPVBXTl9VU19IVlJfOTM5Nl9XRUJfMzQwNSZlZGl0aW9uPXN0ZC0yJnV0bV9pZD00OWNmMjNjNDEyNDA0OTNlODg3OTdjOTljNTZlZjdmNyZodHRwX3JlZmVycmVyPWh0dHBzJTNBJTJGJTJGd3d3Lm9wZXJhLmNvbSUyRmdldCUyRm9wZXJhLWd4JTNGdXRtX3NvdXJjZSUzRFBXTmdhbWVzJTI2dXRtX21lZGl1bSUzRHBhJTI2dXRtX2NhbXBhaWduJTNEUFdOX1VTX0hWUl85Mzk2X1dFQl8zNDA1JTI2dXRtX2lkJTNENDljZjIzYzQxMjQwNDkzZTg4Nzk3Yzk5YzU2ZWY3ZjclMjZlZGl0aW9uJTNEc3RkLTImdXRtX3NpdGU9b3BlcmFfY29tJnV0bV9sYXN0cGFnZT1vcGVyYS5jb20lMkZnZXQlMkZvcGVyYS1neCZ1dG1faWQ9NDljZjIzYzQxMjQwNDkzZTg4Nzk3Yzk5YzU2ZWY3ZjcmZGxfdG9rZW49NDE4MDkzMTAiLCJzeXN0ZW0iOnsicGxhdGZvcm0iOnsiYXJjaCI6Ing4Nl82NCIsIm9wc3lzIjoiV2luZG93cyIsIm9wc3lzLXZlcnNpb24iOiIxMCIsInBhY2thZ2UiOiJFWEUifX0sInRpbWVzdGFtcCI6IjE3MzgwMzYxNDkuNzgyOSIsInVzZXJhZ2VudCI6Ik1vemlsbGEvNS4wIChXaW5kb3dzIE5UIDEwLjA7IFdpbjY0OyB4NjQpIEFwcGxlV2ViS2l0LzUzNy4zNiAoS0hUTUwsIGxpa2UgR2Vja28pIENocm9tZS8xMzIuMC4wLjAgU2FmYXJpLzUzNy4zNiIsInV0bSI6eyJjYW1wYWlnbiI6IlBXTl9VU19IVlJfOTM5Nl9XRUJfMzQwNSIsImlkIjoiNDljZjIzYzQxMjQwNDkzZTg4Nzk3Yzk5YzU2ZWY3ZjciLCJsYXN0cGFnZSI6Im9wZXJhLmNvbS9nZXQvb3BlcmEtZ3giLCJtZWRpdW0iOiJwYSIsInNpdGUiOiJvcGVyYV9jb20iLCJzb3VyY2UiOiJQV05nYW1lcyJ9LCJ1dWlkIjoiOWUwZTQ1ZDUtZGU5ZC00NTExLTljYmItNjRhN2I3NDdhNmY3In0= --desktopshortcut=1 --install-subfolder=116.0.5366.54C:\Users\admin\AppData\Local\Programs\Opera GX\116.0.5366.54\installer.exe
setup.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera GX Installer
Version:
116.0.5366.54
Modules
Images
c:\users\admin\appdata\local\programs\opera gx\116.0.5366.54\installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4648"C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202501280353261\assistant\assistant_installer.exe" --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\crash_count.txt" --url=https://crashstats-collector.opera.com/collector/submit --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktopGX --annotation=ver=73.0.3856.382 --initial-client-data=0x2b0,0x2b4,0x2b8,0x28c,0x2bc,0x1074f48,0x1074f58,0x1074f64C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202501280353261\assistant\assistant_installer.exeassistant_installer.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera GX Browser Assistant Installer
Exit code:
0
Version:
73.0.3856.382
Modules
Images
c:\users\admin\appdata\local\temp\.opera\opera gx installer temp\opera_package_202501280353261\assistant\assistant_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6180C:\Users\admin\AppData\Local\Temp\7zSCB58C373\setup.exe --server-tracking-blob=OGFjYmNmMmFiYTZkYmUxNWZlN2UyMGU5MzZiNTU0NmZlNzM5ZjMwNTEwMWVkMmM2NDZjNzBkMTQ1Yzc5YTAyMDp7ImNvdW50cnkiOiJVUyIsImVkaXRpb24iOiJzdGQtMiIsImh0dHBfcmVmZXJyZXIiOiJodHRwczovL3d3dy5vcGVyYS5jb20vIiwiaW5zdGFsbGVyX25hbWUiOiJPcGVyYUdYU2V0dXAuZXhlIiwicHJvZHVjdCI6Im9wZXJhX2d4IiwicXVlcnkiOiIvb3BlcmFfZ3gvc3RhYmxlL3dpbmRvd3M/ZWRpdGlvbj1zdGQtMiZ1dG1fc291cmNlPVBXTmdhbWVzJnV0bV9tZWRpdW09cGEmdXRtX2NhbXBhaWduPVBXTl9VU19IVlJfOTM5Nl9XRUJfMzQwNSZlZGl0aW9uPXN0ZC0yJnV0bV9pZD00OWNmMjNjNDEyNDA0OTNlODg3OTdjOTljNTZlZjdmNyZodHRwX3JlZmVycmVyPWh0dHBzJTNBJTJGJTJGd3d3Lm9wZXJhLmNvbSUyRmdldCUyRm9wZXJhLWd4JTNGdXRtX3NvdXJjZSUzRFBXTmdhbWVzJTI2dXRtX21lZGl1bSUzRHBhJTI2dXRtX2NhbXBhaWduJTNEUFdOX1VTX0hWUl85Mzk2X1dFQl8zNDA1JTI2dXRtX2lkJTNENDljZjIzYzQxMjQwNDkzZTg4Nzk3Yzk5YzU2ZWY3ZjclMjZlZGl0aW9uJTNEc3RkLTImdXRtX3NpdGU9b3BlcmFfY29tJnV0bV9sYXN0cGFnZT1vcGVyYS5jb20lMkZnZXQlMkZvcGVyYS1neCZ1dG1faWQ9NDljZjIzYzQxMjQwNDkzZTg4Nzk3Yzk5YzU2ZWY3ZjcmZGxfdG9rZW49NDE4MDkzMTAiLCJ0aW1lc3RhbXAiOiIxNzM4MDM2MTQ5Ljc4MjkiLCJ1c2VyYWdlbnQiOiJNb3ppbGxhLzUuMCAoV2luZG93cyBOVCAxMC4wOyBXaW42NDsgeDY0KSBBcHBsZVdlYktpdC81MzcuMzYgKEtIVE1MLCBsaWtlIEdlY2tvKSBDaHJvbWUvMTMyLjAuMC4wIFNhZmFyaS81MzcuMzYiLCJ1dG0iOnsiY2FtcGFpZ24iOiJQV05fVVNfSFZSXzkzOTZfV0VCXzM0MDUiLCJpZCI6IjQ5Y2YyM2M0MTI0MDQ5M2U4ODc5N2M5OWM1NmVmN2Y3IiwibGFzdHBhZ2UiOiJvcGVyYS5jb20vZ2V0L29wZXJhLWd4IiwibWVkaXVtIjoicGEiLCJzaXRlIjoib3BlcmFfY29tIiwic291cmNlIjoiUFdOZ2FtZXMifSwidXVpZCI6IjllMGU0NWQ1LWRlOWQtNDUxMS05Y2JiLTY0YTdiNzQ3YTZmNyJ9C:\Users\admin\AppData\Local\Temp\7zSCB58C373\setup.exe
OperaGXSetup.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera GX Installer
Version:
116.0.5366.54
Modules
Images
c:\users\admin\appdata\local\temp\7zscb58c373\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
6204C:\Users\admin\AppData\Local\Temp\7zSCB58C373\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktopGX --annotation=ver=116.0.5366.54 --initial-client-data=0x338,0x33c,0x340,0x2fc,0x344,0x74d42f6c,0x74d42f78,0x74d42f84C:\Users\admin\AppData\Local\Temp\7zSCB58C373\setup.exe
setup.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera GX Installer
Version:
116.0.5366.54
Modules
Images
c:\users\admin\appdata\local\temp\7zscb58c373\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
6232"C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe" --start-maximizedC:\Users\admin\AppData\Local\Programs\Opera GX\opera.exeinstaller.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera GX Internet Browser
Version:
116.0.5366.54
Modules
Images
c:\users\admin\appdata\local\programs\opera gx\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\programs\opera gx\116.0.5366.54\opera_elf.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shcore.dll
6308"C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\setup.exe" --versionC:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\setup.exe
setup.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\.opera\opera gx installer temp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
Total events
5 697
Read events
5 627
Write events
66
Delete events
4

Modification events

(PID) Process:(6180) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6180) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6180) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7028) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Opera Software
Operation:writeName:Last Opera GX Stable Install Path
Value:
C:\Users\admin\AppData\Local\Programs\Opera GX\
(PID) Process:(4548) installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Opera Software
Operation:writeName:Last Opera GX Stable Install Path
Value:
C:\Users\admin\AppData\Local\Programs\Opera GX\
(PID) Process:(4548) installer.exeKey:HKEY_CLASSES_ROOT\Opera GXStable
Operation:writeName:FriendlyTypeName
Value:
Opera GX Web Document
(PID) Process:(4548) installer.exeKey:HKEY_CLASSES_ROOT\Opera GXStable
Operation:writeName:URL Protocol
Value:
(PID) Process:(4548) installer.exeKey:HKEY_CLASSES_ROOT\.gxanimations\OpenWithProgIDs
Operation:writeName:Opera GXStable
Value:
(PID) Process:(4548) installer.exeKey:HKEY_CLASSES_ROOT\.opdownload\OpenWithProgIDs
Operation:writeName:Opera GXStable
Value:
(PID) Process:(4548) installer.exeKey:HKEY_CLASSES_ROOT\.htm\OpenWithProgids
Operation:writeName:Opera GXStable
Value:
Executable files
18
Suspicious files
42
Text files
32
Unknown types
0

Dropped files

PID
Process
Filename
Type
6180setup.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\Opera_GX_116.0.5366.54_Autoupdate_x64[1].exe
MD5:
SHA256:
6180setup.exeC:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202501280353261\opera_package
MD5:
SHA256:
6180setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419binary
MD5:E7982FC643586AAD006AD0B708FE8815
SHA256:431593560BCE60D1ABA8F4A2F738CF1B8E5BE7352AFBEB0EDA1A0AC32BA2EB92
6180setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12binary
MD5:C9BE626E9715952E9B70F92F912B9787
SHA256:C13E8D22800C200915F87F71C31185053E4E60CA25DE2E41E160E09CD2D815D4
6180setup.exeC:\Users\admin\AppData\Local\Temp\Opera_installer_2501280353256866180.dllexecutable
MD5:50C59FEAE31EC36E5F5EC12FA08A5072
SHA256:291A44E2302DCFB40E8C90676E6C21452094877513D7751E2590920E6B96574D
6204setup.exeC:\Users\admin\AppData\Local\Temp\Opera_installer_2501280353260926204.dllexecutable
MD5:50C59FEAE31EC36E5F5EC12FA08A5072
SHA256:291A44E2302DCFB40E8C90676E6C21452094877513D7751E2590920E6B96574D
6308setup.exeC:\Users\admin\AppData\Local\Temp\Opera_installer_2501280353265296308.dllexecutable
MD5:50C59FEAE31EC36E5F5EC12FA08A5072
SHA256:291A44E2302DCFB40E8C90676E6C21452094877513D7751E2590920E6B96574D
1468OperaGXSetup.exeC:\Users\admin\AppData\Local\Temp\7zSCB58C373\setup.exeexecutable
MD5:0964E495FE984BC57511AA48D131DB03
SHA256:587BF26AA9B6FC20E9B844B2EC9FD73CC30AE6B2DEEB33BCE082EA96DA719175
6180setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B398B80134F72209547439DB21AB308D_A4CF52CCA82D7458083F7280801A3A04binary
MD5:C6EEC8A87C26B9F2F1FB02EF3B64610A
SHA256:999DE101795348B73F2E68C18F5908FAC7DC48219E0268965E233C39978D5593
6180setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B398B80134F72209547439DB21AB308D_A4CF52CCA82D7458083F7280801A3A04binary
MD5:BAF1B39C40546BAE846B00CC62E9EC27
SHA256:ED27488393E9382B54008D8D7C57D6EE30900ADBE72076236A858DFE63B54606
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
15
TCP/UDP connections
37
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6180
setup.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
unknown
whitelisted
6180
setup.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnxLiz3Fu1WB6n1%2FE6xWn1b0jXiQQUdIWAwGbH3zfez70pN6oDHb7tzRcCEA17ZgsSl63KHstWnAbUez0%3D
unknown
whitelisted
6180
setup.exe
GET
200
172.217.16.195:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
436
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6180
setup.exe
GET
200
172.217.16.195:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
6180
setup.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
whitelisted
1176
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1704
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1704
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6180
setup.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5064
SearchApp.exe
2.23.227.208:443
www.bing.com
Ooredoo Q.S.C.
QA
whitelisted
6180
setup.exe
82.145.217.121:443
desktop-netinstaller-sub.osp.opera.software
Opera Software AS
NO
whitelisted
6180
setup.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
1076
svchost.exe
2.23.242.9:443
go.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
6180
setup.exe
185.26.182.123:443
autoupdate.opera.com
Opera Software AS
whitelisted
6180
setup.exe
82.145.216.16:443
features.opera-api2.com
Opera Software AS
NO
malicious
6180
setup.exe
104.18.24.17:443
api.config.opr.gg
CLOUDFLARENET
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.181.238
whitelisted
www.bing.com
  • 2.23.227.208
  • 2.23.227.215
whitelisted
desktop-netinstaller-sub.osp.opera.software
  • 82.145.217.121
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
go.microsoft.com
  • 2.23.242.9
whitelisted
autoupdate.opera.com
  • 185.26.182.123
  • 185.26.182.124
whitelisted
features.opera-api2.com
  • 82.145.216.16
  • 82.145.216.15
malicious
api.config.opr.gg
  • 104.18.24.17
  • 104.18.25.17
unknown
c.pki.goog
  • 172.217.16.195
whitelisted
download.opera.com
  • 82.145.216.49
  • 82.145.216.24
  • 82.145.216.48
  • 82.145.216.23
whitelisted

Threats

No threats detected
Process
Message
assistant_installer.exe
[0128/035406.751:INFO:assistant_installer_main.cc(169)] Running assistant installer with command line "C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202501280353261\assistant\assistant_installer.exe" --version