| File name: | OperaGXSetup.exe |
| Full analysis: | https://app.any.run/tasks/797fcfd0-2815-4d3d-9535-9860cc62c13e |
| Verdict: | Malicious activity |
| Analysis date: | May 30, 2025, 18:46:30 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | CC86C70D7A2CFC2C3715F987D427148C |
| SHA1: | 79FB0EF61C071850A7CF8BCA96490C3C058C6370 |
| SHA256: | 9885915CEDFA2B90D7842A02DFEC8E9318038FBC9EA6D948D32671866D6AABEE |
| SSDEEP: | 98304:7wyWSeMgt7jxG7CP+pmRZo13a1BByh+r8t33Vw9oGvN1glOVIBOkIg1cHS9lyxsQ:7R7oCx/YoS |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:06:12 14:59:19+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.39 |
| CodeSize: | 238080 |
| InitializedDataSize: | 92672 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x213c0 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 119.0.5497.58 |
| ProductVersionNumber: | 119.0.5497.58 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Unknown |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| FileVersion: | 119.0.5497.58 |
| ProductVersion: | 119.0.5497.58 |
| FileDescription: | Opera installer SFX |
| CompanyName: | |
| LegalCopyright: | Opera Software 2025 |
| Productname: | Opera installer |
| Stream: | Stable |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1696 | "C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\setup.exe" --version | C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\setup.exe | setup.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2196 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3784 | C:\Users\admin\AppData\Local\Temp\7zS48E94052\setup.exe --server-tracking-blob=MjllOWE5NmU4ZmYxZjg5MTg4ZmRjNTBhYjZiY2RiNmFiNmE4MDBlOWI1OWVhMjZkMjlmOWYyYWYyMDZhYjMxNDp7ImNvdW50cnkiOiJJRSIsImVkaXRpb24iOiJzdGQtMiIsImluc3RhbGxlcl9uYW1lIjoiT3BlcmFHWFNldHVwLmV4ZSIsInByb2R1Y3QiOiJvcGVyYV9neCIsInF1ZXJ5IjoiL29wZXJhX2d4L3N0YWJsZS9lZGl0aW9uL3N0ZC0yP3V0bV9zb3VyY2U9UFdOZ2FtZXMmdXRtX21lZGl1bT1wYSZ1dG1fY2FtcGFpZ249UFdOX0lFX0hWUl85Mzk3X0REXzEzNTgmdXRtX2lkPTkzMzMzMTZkODVjNTRlNzI4MDYzMjIzNTcyZTc0OGRhIiwidGltZXN0YW1wIjoiMTc0ODYxMzk3NC42MTI5IiwidXNlcmFnZW50IjoiTW96aWxsYS81LjAgKFdpbmRvd3MgTlQgMTAuMDsgV2luNjQ7IHg2NCkgQXBwbGVXZWJLaXQvNTM3LjM2IChLSFRNTCwgbGlrZSBHZWNrbykgQ2hyb21lLzEzNy4wLjAuMCBTYWZhcmkvNTM3LjM2IiwidXRtIjp7ImNhbXBhaWduIjoiUFdOX0lFX0hWUl85Mzk3X0REXzEzNTgiLCJpZCI6IjkzMzMzMTZkODVjNTRlNzI4MDYzMjIzNTcyZTc0OGRhIiwibWVkaXVtIjoicGEiLCJzb3VyY2UiOiJQV05nYW1lcyJ9LCJ1dWlkIjoiYTQzOGRkMjgtMGQxMi00MDMzLTg2OTItMGQ4OWRjYjIxY2RhIn0= | C:\Users\admin\AppData\Local\Temp\7zS48E94052\setup.exe | OperaGXSetup.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera GX Installer Version: 119.0.5497.58 Modules
| |||||||||||||||
| 4212 | "C:\Users\admin\AppData\Local\Temp\7zS48E94052\setup.exe" --backend --install --import-browser-data=0 --enable-crash-reporting=1 --enable-stats=1 --enable-installer-stats=1 --consent-given=1 --general-interests=1 --general-location=1 --personalized-content=1 --personalized-ads=1 --vought_browser=0 --launchopera=1 --showunbox=0 --installfolder="C:\Users\admin\AppData\Local\Programs\Opera GX" --profile-folder --language=en --singleprofile=0 --copyonly=0 --allusers=0 --pintotaskbar=1 --pintostartmenu=1 --run-at-startup=1 --server-tracking-data=server_tracking_data --initial-pid=3784 --package-dir-prefix="C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_20250530184641" --session-guid=2df5c10c-6405-4980-865a-33eb02a4574f --server-tracking-blob="MGM1ZGMyZGY1MGRlYTFhYzBjYWUzZGZlMzM0MTQxMWNkZGFkYWY4NDRkZTE2OTkwMjljZDI5N2IxY2YxZjIyZjp7ImNvdW50cnkiOiJJRSIsImVkaXRpb24iOiJzdGQtMiIsImluc3RhbGxlcl9uYW1lIjoiT3BlcmFHWFNldHVwLmV4ZSIsInByb2R1Y3QiOnsibmFtZSI6Im9wZXJhX2d4In0sInF1ZXJ5IjoiL29wZXJhX2d4L3N0YWJsZS9lZGl0aW9uL3N0ZC0yP3V0bV9zb3VyY2U9UFdOZ2FtZXMmdXRtX21lZGl1bT1wYSZ1dG1fY2FtcGFpZ249UFdOX0lFX0hWUl85Mzk3X0REXzEzNTgmdXRtX2lkPTkzMzMzMTZkODVjNTRlNzI4MDYzMjIzNTcyZTc0OGRhIiwic3lzdGVtIjp7InBsYXRmb3JtIjp7ImFyY2giOiJ4ODZfNjQiLCJvcHN5cyI6IldpbmRvd3MiLCJvcHN5cy12ZXJzaW9uIjoiMTAiLCJwYWNrYWdlIjoiRVhFIn19LCJ0aW1lc3RhbXAiOiIxNzQ4NjEzOTc0LjYxMjkiLCJ1c2VyYWdlbnQiOiJNb3ppbGxhLzUuMCAoV2luZG93cyBOVCAxMC4wOyBXaW42NDsgeDY0KSBBcHBsZVdlYktpdC81MzcuMzYgKEtIVE1MLCBsaWtlIEdlY2tvKSBDaHJvbWUvMTM3LjAuMC4wIFNhZmFyaS81MzcuMzYiLCJ1dG0iOnsiY2FtcGFpZ24iOiJQV05fSUVfSFZSXzkzOTdfRERfMTM1OCIsImlkIjoiOTMzMzMxNmQ4NWM1NGU3MjgwNjMyMjM1NzJlNzQ4ZGEiLCJtZWRpdW0iOiJwYSIsInNvdXJjZSI6IlBXTmdhbWVzIn0sInV1aWQiOiJhNDM4ZGQyOC0wZDEyLTQwMzMtODY5Mi0wZDg5ZGNiMjFjZGEifQ== " --desktopshortcut=1 --wait-for-package --initial-proc-handle=DC09000000000000 | C:\Users\admin\AppData\Local\Temp\7zS48E94052\setup.exe | setup.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera GX Installer Version: 119.0.5497.58 Modules
| |||||||||||||||
| 5096 | C:\Users\admin\AppData\Local\Temp\7zS48E94052\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win64 --annotation=prod=OperaDesktopGX --annotation=ver=119.0.5497.58 --initial-client-data=0x298,0x29c,0x2a0,0x274,0x2a4,0x7ffc899db048,0x7ffc899db054,0x7ffc899db060 | C:\Users\admin\AppData\Local\Temp\7zS48E94052\setup.exe | setup.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera GX Installer Version: 119.0.5497.58 Modules
| |||||||||||||||
| 6920 | C:\Users\admin\AppData\Local\Temp\7zS48E94052\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win64 --annotation=prod=OperaDesktopGX --annotation=ver=119.0.5497.58 --initial-client-data=0x2ac,0x2b0,0x2b4,0x260,0x2b8,0x7ffc8869b048,0x7ffc8869b054,0x7ffc8869b060 | C:\Users\admin\AppData\Local\Temp\7zS48E94052\setup.exe | setup.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera GX Installer Version: 119.0.5497.58 Modules
| |||||||||||||||
| 7812 | "C:\Users\admin\Desktop\OperaGXSetup.exe" | C:\Users\admin\Desktop\OperaGXSetup.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Opera installer SFX Version: 119.0.5497.58 Modules
| |||||||||||||||
| 7972 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (3784) setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (3784) setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3784) setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (4212) setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Opera Software |
| Operation: | write | Name: | Last Opera GX Stable Install Path |
Value: C:\Users\admin\AppData\Local\Programs\Opera GX\ | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5096 | setup.exe | C:\Users\admin\AppData\Local\Temp\Opera_installer_2505301846404985096.dll | executable | |
MD5:BDAA6924F0567F913E10A78C5EF237FE | SHA256:A8C1E0E2CBF0106E43265F1ADAD96F47D40AD1FADACAC758238AFB13FDC23096 | |||
| 3784 | setup.exe | C:\Users\admin\AppData\Local\Temp\Opera_installer_2505301846403413784.dll | executable | |
MD5:BDAA6924F0567F913E10A78C5EF237FE | SHA256:A8C1E0E2CBF0106E43265F1ADAD96F47D40AD1FADACAC758238AFB13FDC23096 | |||
| 3784 | setup.exe | C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\setup.exe | executable | |
MD5:F76EE883A4D3911110BA236D98C71B6C | SHA256:10284B2FF2F51A48048F66AD66EDA68F99FE60DEF257B09CF8FE9155C41CC3C6 | |||
| 1696 | setup.exe | C:\Users\admin\AppData\Local\Temp\Opera_installer_2505301846409661696.dll | executable | |
MD5:BDAA6924F0567F913E10A78C5EF237FE | SHA256:A8C1E0E2CBF0106E43265F1ADAD96F47D40AD1FADACAC758238AFB13FDC23096 | |||
| 7812 | OperaGXSetup.exe | C:\Users\admin\AppData\Local\Temp\7zS48E94052\setup.exe | executable | |
MD5:F76EE883A4D3911110BA236D98C71B6C | SHA256:10284B2FF2F51A48048F66AD66EDA68F99FE60DEF257B09CF8FE9155C41CC3C6 | |||
| 3784 | setup.exe | C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\Crash Reports\settings.dat | binary | |
MD5:B85C92640166510275F5467C4B85AB09 | SHA256:52CB9C30FC537F44E68522E1FA978A63C9B81C5B8B3531EC98077B3824CC550A | |||
| 6920 | setup.exe | C:\Users\admin\AppData\Local\Temp\Opera_installer_2505301846485786920.dll | executable | |
MD5:BDAA6924F0567F913E10A78C5EF237FE | SHA256:A8C1E0E2CBF0106E43265F1ADAD96F47D40AD1FADACAC758238AFB13FDC23096 | |||
| 3784 | setup.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\features[1].json | binary | |
MD5:615BE6B75D7962496CDAAE988405A97D | SHA256:959C9A05067212CBE9D88607B37B5BD49448B833CA5E9CDEAC18BCCEECCBF8A1 | |||
| 4212 | setup.exe | C:\Users\admin\AppData\Local\Temp\Opera_installer_2505301846484034212.dll | executable | |
MD5:BDAA6924F0567F913E10A78C5EF237FE | SHA256:A8C1E0E2CBF0106E43265F1ADAD96F47D40AD1FADACAC758238AFB13FDC23096 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | POST | 201 | 82.145.217.121:443 | https://desktop-netinstaller-sub.osp.opera.software/v1/binary | unknown | text | 36 b | whitelisted |
— | — | GET | 200 | 82.145.216.19:443 | https://autoupdate.opera.com/me/ | unknown | binary | 46 b | whitelisted |
1660 | svchost.exe | GET | 200 | 23.216.77.28:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | POST | 200 | 82.145.216.20:443 | https://autoupdate.opera.com/v5/netinstaller/gx/Stable/windows/x64 | unknown | binary | 1.44 Kb | whitelisted |
— | — | POST | 201 | 82.145.217.121:443 | https://desktop-netinstaller-sub.osp.opera.software/v1/binary | unknown | text | 36 b | whitelisted |
1660 | svchost.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
8044 | RUXIMICS.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 404 | 104.18.24.17:443 | https://api.config.opr.gg/v0/config?utm_campaign=PWN_IE_HVR_9397_DD_1358&utm_medium=pa&utm_source=PWNgames&product=gx&channel=Stable&client=netinstaller&edition=std-2 | unknown | — | — | — |
— | — | GET | 200 | 82.145.216.15:443 | https://features.opera-api2.com/api/v2/features?country=AL&language=en&uuid=e846dbf9-1306-4bf2-9ce9-a9434a848b71&product=gx&channel=Stable&version=119.0.5497.58 | unknown | binary | 1.35 Kb | malicious |
— | — | POST | 201 | 82.145.217.121:443 | https://desktop-netinstaller-sub.osp.opera.software/v1/binary | unknown | text | 36 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1660 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
8044 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1660 | svchost.exe | 23.216.77.28:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
3784 | setup.exe | 82.145.217.121:443 | desktop-netinstaller-sub.osp.opera.software | Opera Software AS | NO | whitelisted |
1660 | svchost.exe | 23.35.229.160:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
8044 | RUXIMICS.exe | 23.35.229.160:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
desktop-netinstaller-sub.osp.opera.software |
| whitelisted |
www.microsoft.com |
| whitelisted |
autoupdate.opera.com |
| whitelisted |
features.opera-api2.com |
| malicious |
api.config.opr.gg |
| unknown |
download.opera.com |
| whitelisted |
download5.operacdn.com |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Potential Corporate Privacy Violation | ET INFO Outgoing Basic Auth Base64 HTTP Password detected unencrypted |