URL:

https://en.exloader.net/

Full analysis: https://app.any.run/tasks/f6d9026c-5f8f-48d3-8db8-a849ec442c4f
Verdict: Malicious activity
Analysis date: December 11, 2024, 22:51:31
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
github
evasion
Indicators:
MD5:

D9EBD822E42A6C769EFEF3291AA0781E

SHA1:

95594BA28F7F8CB6FD6174D19E98F76504DE63AC

SHA256:

9475E917A2098510F2AC17F424AE7B3CAB8A7022A6BAA508D8DE4B0D34C14666

SSDEEP:

3:N8nBAvz:2y

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • opera.exe (PID: 7344)
      • opera.exe (PID: 6408)
    • Adds path to the Windows Defender exclusion list

      • ExLoader_Installer.exe (PID: 848)
      • passwordsbuttons.exe (PID: 10000)
  • SUSPICIOUS

    • Application launched itself

      • setup.exe (PID: 1684)
      • setup.exe (PID: 7792)
      • assistant_installer.exe (PID: 3700)
      • installer.exe (PID: 2412)
      • opera.exe (PID: 7344)
      • opera_autoupdate.exe (PID: 9808)
      • opera_autoupdate.exe (PID: 9720)
      • installer.exe (PID: 10032)
      • opera.exe (PID: 6408)
    • Executable content was dropped or overwritten

      • OperaGXSetup.exe (PID: 1796)
      • setup.exe (PID: 1684)
      • setup.exe (PID: 6920)
      • setup.exe (PID: 7408)
      • setup.exe (PID: 7792)
      • setup.exe (PID: 6012)
      • Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe (PID: 4244)
      • installer.exe (PID: 2612)
      • installer.exe (PID: 2412)
      • ExLoader.exe (PID: 7444)
    • Starts itself from another location

      • setup.exe (PID: 1684)
      • ExLoader.exe (PID: 7444)
    • Reads security settings of Internet Explorer

      • setup.exe (PID: 1684)
      • installer.exe (PID: 2412)
      • ExLoader_Installer.exe (PID: 7328)
      • passwordsbuttons.exe (PID: 10000)
    • Checks Windows Trust Settings

      • setup.exe (PID: 1684)
    • Creates a software uninstall entry

      • installer.exe (PID: 2412)
    • Reads the date of Windows installation

      • installer.exe (PID: 2412)
      • ExLoader_Installer.exe (PID: 7328)
      • opera.exe (PID: 7344)
    • Searches for installed software

      • installer.exe (PID: 2412)
    • The process executes via Task Scheduler

      • opera_autoupdate.exe (PID: 9720)
      • opera_autoupdate.exe (PID: 6160)
    • Script adds exclusion path to Windows Defender

      • ExLoader_Installer.exe (PID: 848)
      • passwordsbuttons.exe (PID: 10000)
    • Starts POWERSHELL.EXE for commands execution

      • ExLoader_Installer.exe (PID: 848)
      • passwordsbuttons.exe (PID: 10000)
    • Connects to unusual port

      • passwordsbuttons.exe (PID: 10000)
      • ExLoader.exe (PID: 7444)
    • Checks for external IP

      • svchost.exe (PID: 2192)
      • ExLoader_Installer.exe (PID: 848)
  • INFO

    • Checks supported languages

      • identity_helper.exe (PID: 8004)
      • OperaGXSetup.exe (PID: 1796)
      • setup.exe (PID: 1684)
      • Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe (PID: 4244)
      • setup.exe (PID: 7792)
      • assistant_installer.exe (PID: 3608)
      • assistant_installer.exe (PID: 3700)
      • installer.exe (PID: 2412)
      • setup.exe (PID: 7408)
      • installer.exe (PID: 2612)
      • setup.exe (PID: 6012)
      • opera.exe (PID: 7344)
      • opera_crashreporter.exe (PID: 7568)
      • setup.exe (PID: 6920)
      • opera.exe (PID: 2392)
      • opera.exe (PID: 644)
      • opera.exe (PID: 3032)
      • opera.exe (PID: 6988)
      • opera.exe (PID: 6868)
      • opera.exe (PID: 7188)
      • opera.exe (PID: 5300)
      • opera.exe (PID: 7016)
      • opera_gx_splash.exe (PID: 4908)
      • opera.exe (PID: 1920)
      • opera.exe (PID: 6932)
      • opera.exe (PID: 7196)
      • opera.exe (PID: 7640)
      • opera.exe (PID: 5200)
      • opera.exe (PID: 8040)
      • opera.exe (PID: 7248)
      • opera.exe (PID: 7628)
      • opera.exe (PID: 7392)
      • opera.exe (PID: 7528)
      • opera.exe (PID: 1044)
      • opera.exe (PID: 3792)
      • opera.exe (PID: 7816)
      • opera.exe (PID: 7296)
      • opera.exe (PID: 8068)
      • opera.exe (PID: 8092)
      • opera.exe (PID: 2996)
      • opera.exe (PID: 3988)
      • opera.exe (PID: 7404)
      • opera.exe (PID: 1868)
      • opera.exe (PID: 2800)
      • opera.exe (PID: 1304)
      • opera.exe (PID: 7688)
      • opera.exe (PID: 3508)
      • opera.exe (PID: 8012)
      • opera.exe (PID: 7412)
      • opera.exe (PID: 6292)
      • opera.exe (PID: 8220)
      • opera.exe (PID: 2972)
      • opera.exe (PID: 7240)
      • opera.exe (PID: 9700)
      • opera.exe (PID: 9644)
      • opera_autoupdate.exe (PID: 9808)
      • opera_autoupdate.exe (PID: 9832)
      • opera.exe (PID: 9848)
      • opera.exe (PID: 10060)
      • opera.exe (PID: 10040)
      • opera_autoupdate.exe (PID: 9720)
      • opera.exe (PID: 9912)
      • installer.exe (PID: 10208)
      • opera_autoupdate.exe (PID: 10192)
      • installer.exe (PID: 10032)
      • ExLoader_Installer.exe (PID: 7328)
      • ExLoader_Installer.exe (PID: 848)
      • opera.exe (PID: 4120)
      • identity_helper.exe (PID: 9480)
      • opera.exe (PID: 7116)
      • opera.exe (PID: 5192)
      • ExLoader.exe (PID: 7444)
      • passwordsbuttons.exe (PID: 10000)
      • opera_crashreporter.exe (PID: 1616)
      • opera.exe (PID: 6408)
      • opera.exe (PID: 8056)
      • opera_crashreporter.exe (PID: 7968)
      • opera.exe (PID: 5128)
      • opera.exe (PID: 4624)
      • opera.exe (PID: 7920)
      • opera.exe (PID: 4980)
      • opera.exe (PID: 2996)
      • opera.exe (PID: 4548)
      • opera.exe (PID: 9600)
      • opera.exe (PID: 9528)
      • opera.exe (PID: 9524)
      • opera.exe (PID: 2092)
      • opera.exe (PID: 2260)
      • opera.exe (PID: 2572)
      • opera.exe (PID: 6928)
      • opera.exe (PID: 4328)
      • opera.exe (PID: 3532)
      • opera.exe (PID: 7832)
      • opera.exe (PID: 7188)
      • opera.exe (PID: 7124)
      • opera.exe (PID: 7648)
      • opera.exe (PID: 10008)
      • opera.exe (PID: 9728)
      • opera.exe (PID: 7504)
    • Reads Environment values

      • identity_helper.exe (PID: 8004)
      • identity_helper.exe (PID: 9480)
      • passwordsbuttons.exe (PID: 10000)
    • The process uses the downloaded file

      • msedge.exe (PID: 7172)
      • msedge.exe (PID: 6204)
      • msedge.exe (PID: 2408)
    • The sample compiled with english language support

      • setup.exe (PID: 1684)
      • OperaGXSetup.exe (PID: 1796)
      • setup.exe (PID: 6920)
      • setup.exe (PID: 7408)
      • setup.exe (PID: 7792)
      • setup.exe (PID: 6012)
      • Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe (PID: 4244)
      • installer.exe (PID: 2612)
      • installer.exe (PID: 2412)
      • ExLoader.exe (PID: 7444)
    • Application launched itself

      • msedge.exe (PID: 6204)
      • msedge.exe (PID: 9500)
    • Creates files or folders in the user directory

      • setup.exe (PID: 6920)
      • setup.exe (PID: 1684)
      • setup.exe (PID: 7792)
      • installer.exe (PID: 2412)
      • opera.exe (PID: 7344)
      • opera.exe (PID: 2392)
      • passwordsbuttons.exe (PID: 10000)
      • opera.exe (PID: 6408)
      • opera.exe (PID: 7832)
    • Reads the computer name

      • identity_helper.exe (PID: 8004)
      • setup.exe (PID: 1684)
      • setup.exe (PID: 7792)
      • assistant_installer.exe (PID: 3700)
      • installer.exe (PID: 2412)
      • opera.exe (PID: 644)
      • opera.exe (PID: 7344)
      • opera.exe (PID: 2392)
      • opera_gx_splash.exe (PID: 4908)
      • ExLoader_Installer.exe (PID: 7328)
      • opera.exe (PID: 5192)
      • opera_autoupdate.exe (PID: 9808)
      • opera_autoupdate.exe (PID: 9720)
      • installer.exe (PID: 10032)
      • ExLoader_Installer.exe (PID: 848)
      • identity_helper.exe (PID: 9480)
      • opera.exe (PID: 3792)
      • ExLoader.exe (PID: 7444)
      • passwordsbuttons.exe (PID: 10000)
      • opera.exe (PID: 7920)
      • opera.exe (PID: 5128)
      • opera.exe (PID: 6408)
      • opera.exe (PID: 8056)
      • opera.exe (PID: 9728)
    • Create files in a temporary directory

      • OperaGXSetup.exe (PID: 1796)
      • setup.exe (PID: 6920)
      • setup.exe (PID: 7408)
      • setup.exe (PID: 7792)
      • setup.exe (PID: 1684)
      • setup.exe (PID: 6012)
      • Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe (PID: 4244)
      • installer.exe (PID: 2412)
      • installer.exe (PID: 2612)
      • opera.exe (PID: 7344)
      • ExLoader_Installer.exe (PID: 7328)
      • powershell.exe (PID: 1140)
      • passwordsbuttons.exe (PID: 10000)
      • opera.exe (PID: 6408)
    • Reads the software policy settings

      • setup.exe (PID: 1684)
      • powershell.exe (PID: 1140)
    • Reads the machine GUID from the registry

      • setup.exe (PID: 1684)
      • opera.exe (PID: 7344)
      • opera_autoupdate.exe (PID: 9808)
      • opera_autoupdate.exe (PID: 9832)
      • opera_autoupdate.exe (PID: 9720)
      • opera_autoupdate.exe (PID: 10192)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 6204)
      • msedge.exe (PID: 6512)
    • Sends debugging messages

      • assistant_installer.exe (PID: 3700)
    • Checks proxy server information

      • setup.exe (PID: 1684)
      • opera.exe (PID: 7344)
      • opera_autoupdate.exe (PID: 9808)
      • opera.exe (PID: 6408)
    • Process checks computer location settings

      • opera.exe (PID: 7344)
      • opera.exe (PID: 5300)
      • opera.exe (PID: 6932)
      • opera.exe (PID: 1920)
      • opera.exe (PID: 7196)
      • opera.exe (PID: 7816)
      • opera.exe (PID: 7628)
      • opera.exe (PID: 7296)
      • opera.exe (PID: 7640)
      • opera.exe (PID: 5200)
      • opera.exe (PID: 7116)
      • opera.exe (PID: 2996)
      • opera.exe (PID: 7392)
      • opera.exe (PID: 9700)
      • opera.exe (PID: 9644)
      • opera.exe (PID: 4980)
      • opera.exe (PID: 4120)
      • ExLoader_Installer.exe (PID: 7328)
      • ExLoader_Installer.exe (PID: 848)
      • passwordsbuttons.exe (PID: 10000)
      • ExLoader.exe (PID: 7444)
      • opera.exe (PID: 6408)
      • opera.exe (PID: 2572)
      • opera.exe (PID: 2260)
      • opera.exe (PID: 10008)
    • Creates files in the program directory

      • ExLoader_Installer.exe (PID: 848)
      • ExLoader.exe (PID: 7444)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 8092)
      • powershell.exe (PID: 8008)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 8092)
      • powershell.exe (PID: 8008)
    • Reads security settings of Internet Explorer

      • powershell.exe (PID: 1140)
    • Manual execution by a user

      • ExLoader.exe (PID: 9816)
      • ExLoader.exe (PID: 7444)
      • opera.exe (PID: 6408)
    • Reads product name

      • passwordsbuttons.exe (PID: 10000)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
356
Monitored processes
214
Malicious processes
11
Suspicious processes
1

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs operagxsetup.exe setup.exe setup.exe setup.exe msedge.exe no specs setup.exe setup.exe msedge.exe no specs msedge.exe no specs opera_gx_assistant_73.0.3856.382_setup.exe_sfx.exe assistant_installer.exe assistant_installer.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs installer.exe installer.exe UIAutomationCrossBitnessHook32 Class no specs opera.exe msedge.exe no specs msedge.exe no specs opera_crashreporter.exe no specs opera.exe no specs opera.exe opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera_gx_splash.exe no specs msedge.exe no specs msedge.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs exloader_installer.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs comppkgsrv.exe no specs opera.exe no specs opera.exe no specs opera_autoupdate.exe no specs opera_autoupdate.exe opera_autoupdate.exe no specs opera.exe no specs opera.exe no specs installer.exe no specs opera.exe no specs opera.exe no specs opera_autoupdate.exe no specs installer.exe no specs opera.exe no specs exloader_installer.exe no specs exloader_installer.exe powershell.exe no specs conhost.exe no specs msedge.exe no specs powershell.exe no specs conhost.exe no specs svchost.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs exloader.exe no specs exloader.exe passwordsbuttons.exe powershell.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs opera.exe no specs opera_crashreporter.exe no specs msedge.exe no specs opera.exe opera_crashreporter.exe no specs opera.exe no specs opera_crashreporter.exe no specs opera.exe no specs opera.exe opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs msedge.exe no specs comppkgsrv.exe no specs opera.exe no specs opera.exe no specs opera_autoupdate.exe no specs opera.exe no specs opera_autoupdate.exe no specs opera.exe no specs opera.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
396"C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --enable-quic --with-feature:cashback-assistant=on --with-feature:address-bar-dropdown-autocompleted-domains=on --with-feature:address-bar-dropdown-unfiltered-full=off --with-feature:amazon-new-ids=on --with-feature:cashback-assistant=on --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-cms-configuration=on --with-feature:continue-shopping-explore=off --with-feature:continue-shopping-structured-partners=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:game-servers=off --with-feature:gx-post-mortem=on --with-feature:gx-reactinator=on --with-feature:gx-spotlight=on --with-feature:gx-video-to-phone=on --with-feature:hide-navigations-from-extensions=on --with-feature:lucid-mode-hide-text=on --with-feature:panic-button=on --with-feature:password-generator=off --with-feature:play-again=on --with-feature:realtime-impressions-reporting=on --with-feature:run-at-startup-default=on --with-feature:sd-suggestions-external=on --with-feature:session-restore-attribution=on --with-feature:side-profiles=on --with-feature:sitecheck-age=on --with-feature:tiktok-panel=on --with-feature:ui-compositor-multithreaded=on --with-feature:installer-experiment-test=off --with-feature:installer-bypass-launcher=on --ab_tests=GXCTest25-test:DNA-99214_GXCTest25 --field-trial-handle=3288,i,14275038901154377722,10826031431636327662,262144 --disable-features=CertificateTransparencyAskBeforeEnabling --variations-seed-version --mojo-platform-channel-handle=3324 /prefetch:8C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera GX Internet Browser
Version:
114.0.5282.248
644"C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe" --type=gpu-process --start-stack-profiler --with-feature:cashback-assistant=on --with-feature:address-bar-dropdown-autocompleted-domains=on --with-feature:address-bar-dropdown-unfiltered-full=off --with-feature:amazon-new-ids=on --with-feature:cashback-assistant=on --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-cms-configuration=on --with-feature:continue-shopping-explore=off --with-feature:continue-shopping-structured-partners=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:game-servers=off --with-feature:gx-post-mortem=on --with-feature:gx-reactinator=on --with-feature:gx-spotlight=on --with-feature:gx-video-to-phone=on --with-feature:hide-navigations-from-extensions=on --with-feature:lucid-mode-hide-text=on --with-feature:panic-button=on --with-feature:password-generator=off --with-feature:play-again=on --with-feature:realtime-impressions-reporting=on --with-feature:run-at-startup-default=on --with-feature:sd-suggestions-external=on --with-feature:session-restore-attribution=on --with-feature:side-profiles=on --with-feature:sitecheck-age=on --with-feature:tiktok-panel=on --with-feature:ui-compositor-multithreaded=on --with-feature:installer-experiment-test=off --with-feature:installer-bypass-launcher=on --ab_tests=GXCTest25-test:DNA-99214_GXCTest25 --gpu-preferences=UAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --field-trial-handle=1908,i,16162018462468645459,13908018556527189690,262144 --disable-features=CertificateTransparencyAskBeforeEnabling --variations-seed-version --mojo-platform-channel-handle=1840 /prefetch:2C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera GX Internet Browser
Exit code:
0
Version:
114.0.5282.248
Modules
Images
c:\users\admin\appdata\local\programs\opera gx\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\programs\opera gx\114.0.5282.248\opera_elf.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
748"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=35 --mojo-platform-channel-handle=6904 --field-trial-handle=2356,i,8358838087223097160,10490850126378501262,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
848"C:\Users\admin\AppData\Local\Temp\RarSFX0\ExLoader_Installer.exe" C:\Users\admin\AppData\Local\Temp\RarSFX0\ExLoader_Installer.exe
ExLoader_Installer.exe
User:
admin
Company:
com.swiftsoft
Integrity Level:
HIGH
Description:
Installer for unified library of game modifications.
Exit code:
0
Version:
1.8.0+1560
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\exloader_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
932"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=8316 --field-trial-handle=2356,i,8358838087223097160,10490850126378501262,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
932\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1044"C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe" --type=utility --utility-sub-type=opera.lights.mojom.Razer --lang=en-US --service-sandbox-type=none --enable-quic --with-feature:cashback-assistant=on --with-feature:address-bar-dropdown-autocompleted-domains=on --with-feature:address-bar-dropdown-unfiltered-full=off --with-feature:amazon-new-ids=on --with-feature:cashback-assistant=on --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-cms-configuration=on --with-feature:continue-shopping-explore=off --with-feature:continue-shopping-structured-partners=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:game-servers=off --with-feature:gx-post-mortem=on --with-feature:gx-reactinator=on --with-feature:gx-spotlight=on --with-feature:gx-video-to-phone=on --with-feature:hide-navigations-from-extensions=on --with-feature:lucid-mode-hide-text=on --with-feature:panic-button=on --with-feature:password-generator=off --with-feature:play-again=on --with-feature:realtime-impressions-reporting=on --with-feature:run-at-startup-default=on --with-feature:sd-suggestions-external=on --with-feature:session-restore-attribution=on --with-feature:side-profiles=on --with-feature:sitecheck-age=on --with-feature:tiktok-panel=on --with-feature:ui-compositor-multithreaded=on --with-feature:installer-experiment-test=off --with-feature:installer-bypass-launcher=on --ab_tests=GXCTest25-test:DNA-99214_GXCTest25 --field-trial-handle=5420,i,16162018462468645459,13908018556527189690,262144 --disable-features=CertificateTransparencyAskBeforeEnabling --variations-seed-version --mojo-platform-channel-handle=5236 /prefetch:8C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera GX Internet Browser
Exit code:
0
Version:
114.0.5282.248
Modules
Images
c:\users\admin\appdata\local\programs\opera gx\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\programs\opera gx\114.0.5282.248\opera_elf.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
1140C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe -command "$WshShell = New-Object -comObject WScript.Shell $Shortcut = $WshShell.CreateShortcut(\"c:\users\admin\desktop\ExLoader.lnk\") $Shortcut.TargetPath = \"C:\Program Files\ExLoader\ExLoader.exe\" $Shortcut.Save()"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeExLoader_Installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\atl.dll
1304"C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --enable-quic --with-feature:cashback-assistant=on --with-feature:address-bar-dropdown-autocompleted-domains=on --with-feature:address-bar-dropdown-unfiltered-full=off --with-feature:amazon-new-ids=on --with-feature:cashback-assistant=on --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-cms-configuration=on --with-feature:continue-shopping-explore=off --with-feature:continue-shopping-structured-partners=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:game-servers=off --with-feature:gx-post-mortem=on --with-feature:gx-reactinator=on --with-feature:gx-spotlight=on --with-feature:gx-video-to-phone=on --with-feature:hide-navigations-from-extensions=on --with-feature:lucid-mode-hide-text=on --with-feature:panic-button=on --with-feature:password-generator=off --with-feature:play-again=on --with-feature:realtime-impressions-reporting=on --with-feature:run-at-startup-default=on --with-feature:sd-suggestions-external=on --with-feature:session-restore-attribution=on --with-feature:side-profiles=on --with-feature:sitecheck-age=on --with-feature:tiktok-panel=on --with-feature:ui-compositor-multithreaded=on --with-feature:installer-experiment-test=off --with-feature:installer-bypass-launcher=on --ab_tests=GXCTest25-test:DNA-99214_GXCTest25 --field-trial-handle=7500,i,16162018462468645459,13908018556527189690,262144 --disable-features=CertificateTransparencyAskBeforeEnabling --variations-seed-version --mojo-platform-channel-handle=8396 /prefetch:8C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera GX Internet Browser
Exit code:
0
Version:
114.0.5282.248
Modules
Images
c:\users\admin\appdata\local\programs\opera gx\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\programs\opera gx\114.0.5282.248\opera_elf.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
1304"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=3604 --field-trial-handle=2344,i,602905359902564824,6712385478152595444,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Total events
173 770
Read events
173 565
Write events
194
Delete events
11

Modification events

(PID) Process:(6204) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(6204) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(6204) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(6204) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(6204) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
F3361FB99C872F00
(PID) Process:(6204) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
9AFA28B99C872F00
(PID) Process:(6204) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\262892
Operation:writeName:WindowTabManagerFileMappingId
Value:
{B2F0F1D2-66C1-48A0-84DA-8F9E6143363B}
(PID) Process:(6204) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\262892
Operation:writeName:WindowTabManagerFileMappingId
Value:
{6264CB51-4C68-43B6-BDE5-E3F6190AAAD2}
(PID) Process:(6204) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\262892
Operation:writeName:WindowTabManagerFileMappingId
Value:
{317354CA-ED85-419C-AA78-06277426E1FB}
(PID) Process:(6204) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\262892
Operation:writeName:WindowTabManagerFileMappingId
Value:
{4DAACEB9-051D-4D99-833E-1C2450FB72AC}
Executable files
47
Suspicious files
1 198
Text files
642
Unknown types
50

Dropped files

PID
Process
Filename
Type
6204msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF135883.TMP
MD5:
SHA256:
6204msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
6204msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF135883.TMP
MD5:
SHA256:
6204msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF135883.TMP
MD5:
SHA256:
6204msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF135883.TMP
MD5:
SHA256:
6204msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
6204msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
6204msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
6204msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF135893.TMP
MD5:
SHA256:
6204msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
67
TCP/UDP connections
309
DNS requests
377
Threats
10

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6032
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6204
msedge.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
4144
svchost.exe
HEAD
200
146.75.122.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/68591036-2289-4858-9f7f-9149e89c8a08?P1=1734260405&P2=404&P3=2&P4=nuYLhrUjHZ%2f7f6p9SBNf8IASVM8qD8fOMtayy0pIp8qCDhqkfvXke2YGeuoJg8JGI%2bvuVFwsEJuLjmOAESWFtw%3d%3d
unknown
whitelisted
4144
svchost.exe
GET
206
146.75.122.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/68591036-2289-4858-9f7f-9149e89c8a08?P1=1734260405&P2=404&P3=2&P4=nuYLhrUjHZ%2f7f6p9SBNf8IASVM8qD8fOMtayy0pIp8qCDhqkfvXke2YGeuoJg8JGI%2bvuVFwsEJuLjmOAESWFtw%3d%3d
unknown
whitelisted
1684
setup.exe
GET
200
216.58.206.35:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
6204
msedge.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEA55q9FkBjzsPoBm2GCDxI4%3D
unknown
whitelisted
1684
setup.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnxLiz3Fu1WB6n1%2FE6xWn1b0jXiQQUdIWAwGbH3zfez70pN6oDHb7tzRcCEAfyOr5A1UWlCmQhXhy%2Bwwk%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4652
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
184.24.77.37:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
104.126.37.185:443
www.bing.com
Akamai International B.V.
DE
whitelisted
5064
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
6204
msedge.exe
239.255.255.250:1900
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 184.24.77.37
  • 184.24.77.35
whitelisted
google.com
  • 172.217.16.142
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
www.bing.com
  • 104.126.37.185
  • 104.126.37.144
  • 104.126.37.131
  • 104.126.37.145
  • 104.126.37.137
  • 104.126.37.123
  • 104.126.37.136
  • 104.126.37.186
  • 104.126.37.163
  • 2.16.110.121
  • 104.126.37.179
  • 104.126.37.161
  • 104.126.37.178
  • 104.126.37.177
  • 104.126.37.162
  • 104.126.37.171
  • 104.126.37.170
  • 104.126.37.130
  • 104.126.37.128
  • 104.126.37.129
  • 104.126.37.176
  • 104.126.37.139
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
en.exloader.net
  • 104.22.29.239
  • 104.22.28.239
  • 172.67.22.232
unknown
edge.microsoft.com
  • 13.107.21.239
  • 204.79.197.239
whitelisted
edge-mobile-static.azureedge.net
  • 13.107.246.45
whitelisted

Threats

PID
Process
Class
Message
2192
svchost.exe
Misc activity
ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup
2192
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
2192
svchost.exe
Misc activity
ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup
848
ExLoader_Installer.exe
Misc activity
ET INFO External IP Address Lookup Domain (ipify .org) in TLS SNI
2192
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
2192
svchost.exe
Device Retrieving External IP Address Detected
ET POLICY External IP Lookup Domain (ipapi .co in DNS lookup)
7832
opera.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
7832
opera.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
2 ETPRO signatures available at the full report
Process
Message
assistant_installer.exe
[1211/225309.101:INFO:assistant_installer_main.cc(169)] Running assistant installer with command line "C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202412112252301\assistant\assistant_installer.exe" --version