File name:

OperaSetup.exe

Full analysis: https://app.any.run/tasks/ba167b59-a39a-4ed9-bfe5-9755742c3fbd
Verdict: Malicious activity
Analysis date: November 21, 2021, 18:54:18
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

7AE8D0D9F207E218F563D42F9C573944

SHA1:

285999B513E640658DFB965AE6F251207B024D03

SHA256:

99EB8E43579573D7C2834D33F9115399130CA67E54F9D69CC02AE69571A49767

SSDEEP:

49152:w7+nSHJ05LnIx//NUdVUhuhpUP278Sg4CyK7Ze1JMeyLy7hkZA:EYI7UdVUhUYIK+yI2ZA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • OperaSetup.exe (PID: 4008)
      • OperaSetup.exe (PID: 3412)
      • OperaSetup.exe (PID: 956)
      • OperaSetup.exe (PID: 2144)
      • OperaSetup.exe (PID: 3564)
      • OperaSetup.exe (PID: 2412)
      • assistant_installer.exe (PID: 2216)
      • assistant_installer.exe (PID: 2124)
      • installer.exe (PID: 1620)
      • installer.exe (PID: 3424)
      • installer.exe (PID: 148)
      • installer.exe (PID: 284)
      • opera_crashreporter.exe (PID: 3792)
      • opera.exe (PID: 3120)
      • opera.exe (PID: 3448)
      • opera.exe (PID: 2524)
      • opera.exe (PID: 3236)
      • opera.exe (PID: 2408)
      • opera.exe (PID: 3148)
      • opera.exe (PID: 2612)
      • opera.exe (PID: 1636)
      • opera.exe (PID: 1056)
      • opera.exe (PID: 1560)
      • opera.exe (PID: 2436)
      • opera.exe (PID: 1764)
      • opera.exe (PID: 1524)
      • opera.exe (PID: 1608)
      • opera.exe (PID: 752)
      • opera.exe (PID: 3220)
      • opera.exe (PID: 2548)
      • opera.exe (PID: 2580)
      • opera.exe (PID: 2140)
      • opera.exe (PID: 3824)
      • opera.exe (PID: 3912)
      • opera.exe (PID: 2420)
      • opera.exe (PID: 3828)
      • opera.exe (PID: 612)
      • opera.exe (PID: 2392)
      • opera.exe (PID: 4000)
      • opera.exe (PID: 2480)
      • opera.exe (PID: 2544)
      • opera.exe (PID: 2944)
      • opera.exe (PID: 1764)
      • opera.exe (PID: 2884)
      • opera.exe (PID: 2136)
      • opera.exe (PID: 956)
      • opera.exe (PID: 2352)
      • opera.exe (PID: 1628)
      • opera_autoupdate.exe (PID: 2212)
      • opera_autoupdate.exe (PID: 2828)
      • opera.exe (PID: 3560)
      • opera.exe (PID: 2220)
      • opera.exe (PID: 3192)
      • opera.exe (PID: 3596)
      • opera.exe (PID: 1820)
      • opera.exe (PID: 3748)
      • opera.exe (PID: 3588)
      • opera.exe (PID: 2348)
      • opera.exe (PID: 2636)
      • opera.exe (PID: 2900)
      • opera.exe (PID: 2092)
      • opera.exe (PID: 2492)
      • opera.exe (PID: 3212)
      • opera.exe (PID: 1968)
      • opera.exe (PID: 1232)
      • opera.exe (PID: 3332)
      • opera.exe (PID: 148)
      • opera.exe (PID: 1584)
    • Drops executable file immediately after starts

      • OperaSetup.exe (PID: 4008)
      • OperaSetup.exe (PID: 3412)
      • OperaSetup.exe (PID: 520)
      • OperaSetup.exe (PID: 2144)
      • OperaSetup.exe (PID: 956)
      • OperaSetup.exe (PID: 3564)
      • OperaSetup.exe (PID: 2412)
      • _sfx.exe (PID: 1324)
      • installer.exe (PID: 1620)
      • installer.exe (PID: 3424)
      • installer.exe (PID: 148)
      • installer.exe (PID: 284)
      • opera.exe (PID: 3212)
    • Loads dropped or rewritten executable

      • OperaSetup.exe (PID: 520)
      • OperaSetup.exe (PID: 4008)
      • OperaSetup.exe (PID: 3412)
      • OperaSetup.exe (PID: 956)
      • OperaSetup.exe (PID: 2144)
      • OperaSetup.exe (PID: 3564)
      • OperaSetup.exe (PID: 2412)
      • opera.exe (PID: 2524)
      • opera.exe (PID: 3236)
      • opera.exe (PID: 1636)
      • opera.exe (PID: 2436)
      • opera.exe (PID: 3120)
      • opera.exe (PID: 3148)
      • opera.exe (PID: 3448)
      • opera.exe (PID: 1560)
      • opera.exe (PID: 2408)
      • opera.exe (PID: 1056)
      • opera.exe (PID: 1524)
      • opera.exe (PID: 3220)
      • opera.exe (PID: 2548)
      • opera.exe (PID: 1608)
      • opera.exe (PID: 2612)
      • opera.exe (PID: 2580)
      • opera.exe (PID: 1764)
      • opera.exe (PID: 752)
      • opera.exe (PID: 3912)
      • opera.exe (PID: 2140)
      • opera.exe (PID: 2420)
      • opera.exe (PID: 3828)
      • opera.exe (PID: 3824)
      • installer.exe (PID: 1620)
      • installer.exe (PID: 148)
      • installer.exe (PID: 284)
      • installer.exe (PID: 3424)
      • opera.exe (PID: 4000)
      • opera.exe (PID: 612)
      • opera.exe (PID: 2480)
      • opera.exe (PID: 2352)
      • opera.exe (PID: 2136)
      • opera.exe (PID: 1764)
      • opera.exe (PID: 2544)
      • opera.exe (PID: 2392)
      • opera.exe (PID: 2944)
      • opera.exe (PID: 2884)
      • opera.exe (PID: 956)
      • opera.exe (PID: 1628)
      • opera.exe (PID: 3560)
      • opera.exe (PID: 2220)
      • opera.exe (PID: 3192)
      • installer.exe (PID: 3296)
      • opera.exe (PID: 3596)
      • opera.exe (PID: 1820)
      • opera.exe (PID: 3748)
      • opera.exe (PID: 3588)
      • opera.exe (PID: 2348)
      • opera.exe (PID: 2636)
      • opera.exe (PID: 2492)
      • opera.exe (PID: 2900)
      • opera.exe (PID: 2092)
      • opera.exe (PID: 1968)
      • opera.exe (PID: 1232)
      • opera.exe (PID: 148)
      • opera.exe (PID: 3212)
      • opera.exe (PID: 3332)
      • opera.exe (PID: 1584)
    • Application was dropped or rewritten from another process

      • _sfx.exe (PID: 1324)
      • assistant_installer.exe (PID: 2124)
      • assistant_installer.exe (PID: 2216)
      • installer.exe (PID: 3424)
      • installer.exe (PID: 1620)
      • installer.exe (PID: 148)
      • installer.exe (PID: 284)
      • launcher.exe (PID: 2612)
      • opera.exe (PID: 3236)
      • opera.exe (PID: 3120)
      • opera.exe (PID: 3148)
      • opera.exe (PID: 1056)
      • opera.exe (PID: 2436)
      • opera.exe (PID: 1560)
      • opera.exe (PID: 2612)
      • opera.exe (PID: 1764)
      • opera.exe (PID: 2408)
      • opera.exe (PID: 3448)
      • opera.exe (PID: 2524)
      • opera.exe (PID: 1636)
      • opera.exe (PID: 2580)
      • opera.exe (PID: 1524)
      • opera.exe (PID: 1608)
      • opera.exe (PID: 2548)
      • opera.exe (PID: 3220)
      • opera.exe (PID: 752)
      • opera.exe (PID: 2140)
      • opera.exe (PID: 3824)
      • opera.exe (PID: 3912)
      • opera.exe (PID: 2420)
      • opera.exe (PID: 3828)
      • opera.exe (PID: 1764)
      • opera.exe (PID: 612)
      • opera.exe (PID: 2352)
      • opera.exe (PID: 2392)
      • opera_crashreporter.exe (PID: 3792)
      • opera.exe (PID: 2480)
      • opera.exe (PID: 4000)
      • opera.exe (PID: 2136)
      • opera.exe (PID: 2884)
      • opera.exe (PID: 2544)
      • opera.exe (PID: 956)
      • opera.exe (PID: 2944)
      • opera.exe (PID: 1628)
      • opera_autoupdate.exe (PID: 2212)
      • opera.exe (PID: 3560)
      • opera.exe (PID: 2220)
      • opera.exe (PID: 3192)
      • opera_autoupdate.exe (PID: 2828)
      • installer.exe (PID: 3296)
      • opera_autoupdate.exe (PID: 3988)
      • launcher.exe (PID: 3212)
      • opera.exe (PID: 3596)
      • opera.exe (PID: 3748)
      • opera.exe (PID: 1820)
      • opera.exe (PID: 3588)
      • opera_autoupdate.exe (PID: 4056)
      • opera.exe (PID: 2492)
      • opera.exe (PID: 2636)
      • opera.exe (PID: 2348)
      • opera.exe (PID: 1968)
      • opera.exe (PID: 2900)
      • opera.exe (PID: 2092)
      • opera.exe (PID: 1232)
      • opera.exe (PID: 148)
      • opera.exe (PID: 3212)
      • opera.exe (PID: 1584)
      • opera.exe (PID: 3332)
    • Loads the Task Scheduler COM API

      • installer.exe (PID: 3424)
      • opera.exe (PID: 3236)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • OperaSetup.exe (PID: 3412)
      • OperaSetup.exe (PID: 4008)
      • OperaSetup.exe (PID: 520)
      • OperaSetup.exe (PID: 956)
      • OperaSetup.exe (PID: 2144)
      • OperaSetup.exe (PID: 3564)
      • OperaSetup.exe (PID: 2412)
      • _sfx.exe (PID: 1324)
      • installer.exe (PID: 1620)
      • installer.exe (PID: 3424)
      • installer.exe (PID: 284)
      • installer.exe (PID: 148)
      • launcher.exe (PID: 3212)
      • installer.exe (PID: 3296)
      • opera.exe (PID: 3212)
    • Drops a file that was compiled in debug mode

      • OperaSetup.exe (PID: 4008)
      • OperaSetup.exe (PID: 3412)
      • OperaSetup.exe (PID: 520)
      • OperaSetup.exe (PID: 956)
      • OperaSetup.exe (PID: 2144)
      • OperaSetup.exe (PID: 3564)
      • OperaSetup.exe (PID: 2412)
      • _sfx.exe (PID: 1324)
      • installer.exe (PID: 1620)
      • installer.exe (PID: 3424)
      • installer.exe (PID: 284)
      • installer.exe (PID: 148)
      • launcher.exe (PID: 3212)
      • installer.exe (PID: 3296)
      • opera.exe (PID: 3212)
    • Drops a file with a compile date too recent

      • OperaSetup.exe (PID: 3412)
      • OperaSetup.exe (PID: 4008)
      • OperaSetup.exe (PID: 520)
      • OperaSetup.exe (PID: 956)
      • OperaSetup.exe (PID: 2144)
      • OperaSetup.exe (PID: 3564)
      • OperaSetup.exe (PID: 2412)
      • installer.exe (PID: 1620)
      • installer.exe (PID: 3424)
      • installer.exe (PID: 284)
      • installer.exe (PID: 148)
      • installer.exe (PID: 3296)
      • launcher.exe (PID: 3212)
    • Application launched itself

      • OperaSetup.exe (PID: 4008)
      • OperaSetup.exe (PID: 956)
      • OperaSetup.exe (PID: 3564)
      • assistant_installer.exe (PID: 2124)
      • installer.exe (PID: 3424)
      • installer.exe (PID: 284)
      • opera.exe (PID: 3236)
      • opera_autoupdate.exe (PID: 2212)
      • opera_autoupdate.exe (PID: 3988)
    • Checks supported languages

      • OperaSetup.exe (PID: 4008)
      • OperaSetup.exe (PID: 3412)
      • OperaSetup.exe (PID: 520)
      • OperaSetup.exe (PID: 956)
      • OperaSetup.exe (PID: 2144)
      • OperaSetup.exe (PID: 3564)
      • OperaSetup.exe (PID: 2412)
      • _sfx.exe (PID: 1324)
      • assistant_installer.exe (PID: 2124)
      • assistant_installer.exe (PID: 2216)
      • installer.exe (PID: 1620)
      • installer.exe (PID: 3424)
      • installer.exe (PID: 148)
      • installer.exe (PID: 284)
      • launcher.exe (PID: 2612)
      • opera_crashreporter.exe (PID: 3792)
      • opera.exe (PID: 2408)
      • opera.exe (PID: 3120)
      • opera.exe (PID: 3448)
      • opera.exe (PID: 2524)
      • opera.exe (PID: 3148)
      • opera.exe (PID: 1560)
      • opera.exe (PID: 3236)
      • opera.exe (PID: 1056)
      • opera.exe (PID: 1764)
      • opera.exe (PID: 2612)
      • opera.exe (PID: 1636)
      • opera.exe (PID: 2436)
      • opera.exe (PID: 2580)
      • opera.exe (PID: 3220)
      • opera.exe (PID: 1524)
      • opera.exe (PID: 2548)
      • opera.exe (PID: 1608)
      • opera.exe (PID: 752)
      • opera.exe (PID: 3912)
      • opera.exe (PID: 3824)
      • opera.exe (PID: 2140)
      • opera.exe (PID: 2420)
      • opera.exe (PID: 3828)
      • opera.exe (PID: 4000)
      • opera.exe (PID: 612)
      • opera.exe (PID: 1764)
      • opera.exe (PID: 2480)
      • opera.exe (PID: 2136)
      • opera.exe (PID: 2392)
      • opera.exe (PID: 2352)
      • opera.exe (PID: 2884)
      • opera.exe (PID: 2944)
      • opera.exe (PID: 2544)
      • opera.exe (PID: 956)
      • opera.exe (PID: 1628)
      • opera_autoupdate.exe (PID: 2212)
      • opera.exe (PID: 3560)
      • opera_autoupdate.exe (PID: 2828)
      • opera.exe (PID: 2220)
      • opera.exe (PID: 3192)
      • launcher.exe (PID: 3212)
      • installer.exe (PID: 3296)
      • opera_autoupdate.exe (PID: 3988)
      • opera_autoupdate.exe (PID: 4056)
      • opera.exe (PID: 3596)
      • opera.exe (PID: 3748)
      • opera.exe (PID: 1820)
      • opera.exe (PID: 3588)
      • opera.exe (PID: 2348)
      • opera.exe (PID: 2636)
      • opera.exe (PID: 2492)
      • opera.exe (PID: 2900)
      • opera.exe (PID: 2092)
      • opera.exe (PID: 1968)
      • opera.exe (PID: 1232)
      • opera.exe (PID: 3212)
      • opera.exe (PID: 3332)
      • opera.exe (PID: 148)
      • opera.exe (PID: 1584)
    • Reads the computer name

      • OperaSetup.exe (PID: 4008)
      • OperaSetup.exe (PID: 956)
      • OperaSetup.exe (PID: 3564)
      • assistant_installer.exe (PID: 2124)
      • installer.exe (PID: 3424)
      • installer.exe (PID: 284)
      • launcher.exe (PID: 2612)
      • opera.exe (PID: 3120)
      • opera.exe (PID: 3236)
      • opera.exe (PID: 3448)
      • opera.exe (PID: 2408)
      • opera.exe (PID: 2524)
      • opera.exe (PID: 3148)
      • opera.exe (PID: 1056)
      • opera.exe (PID: 1560)
      • opera.exe (PID: 2612)
      • opera.exe (PID: 1764)
      • opera.exe (PID: 1636)
      • opera.exe (PID: 2436)
      • opera.exe (PID: 2580)
      • opera.exe (PID: 1524)
      • opera.exe (PID: 3220)
      • opera.exe (PID: 1608)
      • opera.exe (PID: 2548)
      • opera.exe (PID: 752)
      • opera.exe (PID: 3824)
      • opera.exe (PID: 3912)
      • opera.exe (PID: 2140)
      • opera.exe (PID: 2420)
      • opera.exe (PID: 3828)
      • opera.exe (PID: 1764)
      • opera.exe (PID: 4000)
      • opera.exe (PID: 612)
      • opera.exe (PID: 2480)
      • opera.exe (PID: 2352)
      • opera.exe (PID: 2136)
      • opera.exe (PID: 2884)
      • opera.exe (PID: 2944)
      • opera.exe (PID: 2392)
      • opera.exe (PID: 2544)
      • opera.exe (PID: 1628)
      • opera_autoupdate.exe (PID: 2212)
      • opera.exe (PID: 956)
      • opera.exe (PID: 3560)
      • opera.exe (PID: 2220)
      • opera.exe (PID: 3192)
      • opera.exe (PID: 3596)
      • opera.exe (PID: 1820)
      • opera_autoupdate.exe (PID: 3988)
      • opera.exe (PID: 3748)
      • opera.exe (PID: 3588)
      • opera.exe (PID: 2348)
      • opera.exe (PID: 2636)
      • opera.exe (PID: 2492)
      • opera.exe (PID: 2900)
      • opera.exe (PID: 2092)
      • opera.exe (PID: 1968)
      • opera.exe (PID: 3212)
      • opera.exe (PID: 1232)
      • opera.exe (PID: 148)
      • opera.exe (PID: 3332)
      • opera.exe (PID: 1584)
    • Creates files in the user directory

      • OperaSetup.exe (PID: 3412)
      • installer.exe (PID: 3424)
      • opera.exe (PID: 3236)
      • opera.exe (PID: 2408)
      • opera_autoupdate.exe (PID: 2212)
    • Searches for installed software

      • OperaSetup.exe (PID: 4008)
      • OperaSetup.exe (PID: 956)
      • OperaSetup.exe (PID: 3564)
      • installer.exe (PID: 3424)
    • Starts itself from another location

      • OperaSetup.exe (PID: 4008)
    • Creates a directory in Program Files

      • OperaSetup.exe (PID: 3564)
      • installer.exe (PID: 3424)
    • Creates files in the program directory

      • installer.exe (PID: 3424)
      • OperaSetup.exe (PID: 3564)
      • opera_autoupdate.exe (PID: 3988)
    • Changes default file association

      • installer.exe (PID: 3424)
      • installer.exe (PID: 284)
    • Creates a software uninstall entry

      • installer.exe (PID: 3424)
    • Reads the date of Windows installation

      • installer.exe (PID: 3424)
      • opera.exe (PID: 3236)
    • Reads Windows Product ID

      • opera.exe (PID: 3236)
      • opera_autoupdate.exe (PID: 2212)
      • opera_autoupdate.exe (PID: 2828)
      • opera_autoupdate.exe (PID: 3988)
      • opera_autoupdate.exe (PID: 4056)
    • Executed via Task Scheduler

      • launcher.exe (PID: 3212)
    • Reads CPU info

      • opera.exe (PID: 3236)
  • INFO

    • Checks Windows Trust Settings

      • OperaSetup.exe (PID: 4008)
    • Reads settings of System Certificates

      • OperaSetup.exe (PID: 4008)
      • opera.exe (PID: 3236)
    • Dropped object may contain Bitcoin addresses

      • OperaSetup.exe (PID: 3564)
    • Reads the hosts file

      • opera.exe (PID: 3236)
      • opera.exe (PID: 2408)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:11:08 14:13:00+01:00
PEType: PE32
LinkerVersion: 14
CodeSize: 2568192
InitializedDataSize: 36864
UninitializedDataSize: 1929216
EntryPoint: 0x44a2a0
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 81.0.4196.37
ProductVersionNumber: 81.0.4196.37
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Opera Software
FileDescription: Opera Installer
FileVersion: 81.0.4196.37
InternalName: Opera
LegalCopyright: Copyright Opera Software 2021
ProductName: Opera Installer
ProductVersion: 81.0.4196.37

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 08-Nov-2021 13:13:00
Detected languages:
  • English - United States
CompanyName: Opera Software
FileDescription: Opera Installer
FileVersion: 81.0.4196.37
InternalName: Opera
LegalCopyright: Copyright Opera Software 2021
ProductName: Opera Installer
ProductVersion: 81.0.4196.37

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0078
Pages in file: 0x0001
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0x0000
Initial SS value: 0x0000
Initial SP value: 0x0000
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000078

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 3
Time date stamp: 08-Nov-2021 13:13:00
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LARGE_ADDRESS_AWARE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
UPX0
0x00001000
0x001D7000
0x00000000
IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0
UPX1
0x001D8000
0x00273000
0x00272600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
7.77217
.rsrc
0x0044B000
0x00009000
0x00008400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
5.81581

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.33361
1068
Latin 1 / Western European
English - United States
RT_MANIFEST
2
2.96057
488
Latin 1 / Western European
English - United States
RT_ICON
3
2.78424
744
Latin 1 / Western European
English - United States
RT_ICON
4
2.55697
1640
Latin 1 / Western European
English - United States
RT_ICON
5
5.43345
1384
Latin 1 / Western European
English - United States
RT_ICON
6
5.88737
1736
Latin 1 / Western European
English - United States
RT_ICON
7
5.93769
2216
Latin 1 / Western European
English - United States
RT_ICON
8
5.74304
3752
Latin 1 / Western European
English - United States
RT_ICON
9
5.7783
1128
Latin 1 / Western European
English - United States
RT_ICON
10
5.9419
2440
Latin 1 / Western European
English - United States
RT_ICON

Imports

COMCTL32.dll
KERNEL32.DLL
USER32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
117
Monitored processes
75
Malicious processes
74
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start drop and start drop and start drop and start start drop and start drop and start operasetup.exe operasetup.exe operasetup.exe operasetup.exe operasetup.exe operasetup.exe operasetup.exe _sfx.exe assistant_installer.exe assistant_installer.exe installer.exe installer.exe installer.exe installer.exe launcher.exe no specs opera.exe opera_crashreporter.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera_autoupdate.exe opera.exe opera_autoupdate.exe opera.exe opera.exe launcher.exe installer.exe opera_autoupdate.exe opera_autoupdate.exe no specs opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe

Process information

PID
CMD
Path
Indicators
Parent process
148"C:\Program Files\Opera\81.0.4196.54\installer.exe" --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector.opera.com/collector/submit --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktop --annotation=ver=81.0.4196.54 --initial-client-data=0x174,0x178,0x17c,0x148,0x180,0x6c5184e8,0x6c5184f8,0x6c518504C:\Program Files\Opera\81.0.4196.54\installer.exe
installer.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera Installer
Exit code:
0
Version:
81.0.4196.54
Modules
Images
c:\program files\opera\81.0.4196.54\installer.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
148"C:\Program Files\Opera\opera.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --field-trial-handle=1012,5649344169875940080,546516825159334456,131072 --lang=en-US --service-sandbox-type=utility --enable-quic --with-feature:adblock-snippets=on --with-feature:aliexpress-modal=off --with-feature:booking-modal=off --with-feature:bookmarks-trash-cleaner=on --with-feature:cashback-all-workspaces=on --with-feature:continue-on-booking=on --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:enhanced-address-bar=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:pinboard-local=on --with-feature:premium-valve-in=on --with-feature:reader-mode=on --with-feature:rollout-dna=on --with-feature:sd-suggestions-external=on --with-feature:startpage-sync-banner=on --with-feature:yandex-zen-leads-for-nonsdusers=off --with-feature:yandex-zen-lift-up=off --with-feature:yat-emoji-addresses=on --with-feature:installer-experiment-test=off --with-feature:installer-use-minimal-package=off --with-feature:installer-opera-exe-in-root=on --ab_tests=DNA-90363-ref:DNA-90363 --mojo-platform-channel-handle=1312 /prefetch:8C:\Program Files\Opera\opera.exe
opera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Exit code:
0
Version:
81.0.4196.54
Modules
Images
c:\program files\opera\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\opera\81.0.4196.54\opera_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
284"C:\Program Files\Opera\81.0.4196.54\installer.exe" --backend --initial-pid=4008 --install --import-browser-data=0 --enable-stats=1 --enable-installer-stats=1 --launchopera=1 --installfolder="C:\Program Files\Opera" --profile-folder --language=en --singleprofile=0 --copyonly=0 --allusers=0 --setdefaultbrowser=1 --pintotaskbar=1 --pintostartmenu=1 --pin-additional-shortcuts=1 --server-tracking-data=server_tracking_data --package-dir-prefix="C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_20211121185436" --session-guid=ebca4701-6b65-46a6-b649-1daf464a3f56 --server-tracking-blob=ZTUzYWI0ODA2YzlmMGE2MDA4ZjVmNGQ4MzkxOTM2M2I4YmEzYzQxMWE3YTQ4YWU1MjJlZGMyNGNjOTk3MWVlMjp7ImNvdW50cnkiOiJGSSIsImh0dHBfcmVmZXJyZXIiOiJodHRwczovL3d3dy5vcGVyYS5jb20vIiwiaW5zdGFsbGVyX25hbWUiOiJPcGVyYVNldHVwLmV4ZSIsInByb2R1Y3QiOiJvcGVyYSIsInF1ZXJ5IjoiL29wZXJhL3N0YWJsZS93aW5kb3dzP3V0bV90cnlhZ2Fpbj15ZXMmdXRtX3NvdXJjZT1tLm9wZXJhLmNvbV92aWFfb3BlcmFfY29tJnV0bV9tZWRpdW09cm9jJnV0bV9jYW1wYWlnbj0obm9uZSlfdmlhX29wZXJhX2NvbV9odHRwcyZ1dG1fY29udGVudD0lMkYmaHR0cF9yZWZlcnJlcj1odHRwJTNBJTJGJTJGbS5vcGVyYS5jb20lMkYmdXRtX3NpdGU9b3BlcmFfY29tJiZ1dG1fbGFzdHBhZ2U9b3BlcmEuY29tL2Rvd25sb2FkJmRsX3Rva2VuPTk1NDU1MDcwIiwidGltZXN0YW1wIjoiMTYzNzUxODM3Ni44MzM5IiwidXNlcmFnZW50IjoiTW96aWxsYS81LjAgKFgxMTsgTGludXggeDg2XzY0KSBBcHBsZVdlYktpdC81MzcuMzYgKEtIVE1MLCBsaWtlIEdlY2tvKSBDaHJvbWUvOTUuMC40NjM4Ljc0IFNhZmFyaS81MzcuMzYiLCJ1dG0iOnsiY2FtcGFpZ24iOiIobm9uZSlfdmlhX29wZXJhX2NvbV9odHRwcyIsImNvbnRlbnQiOiIvIiwibGFzdHBhZ2UiOiJvcGVyYS5jb20vZG93bmxvYWQiLCJtZWRpdW0iOiJyb2MiLCJzaXRlIjoib3BlcmFfY29tIiwic291cmNlIjoibS5vcGVyYS5jb21fdmlhX29wZXJhX2NvbSIsInRyeWFnYWluIjoieWVzIn0sInV1aWQiOiI4NWU1ODE3Ny02ZDIyLTRkOGYtYTY3Yi0wODdhMzJiYTdiNWMifQ== --desktopshortcut=1 --install-subfolder=81.0.4196.54 --post-elevated-install-tasksC:\Program Files\Opera\81.0.4196.54\installer.exe
OperaSetup.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera Installer
Exit code:
0
Version:
81.0.4196.54
Modules
Images
c:\program files\opera\81.0.4196.54\installer.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
520"C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\OperaSetup.exe" --versionC:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\OperaSetup.exe
OperaSetup.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera Installer
Exit code:
0
Version:
81.0.4196.37
Modules
Images
c:\users\admin\appdata\local\temp\.opera\opera installer temp\operasetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
612"C:\Program Files\Opera\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --field-trial-handle=1012,5649344169875940080,546516825159334456,131072 --lang=en-US --service-sandbox-type=service --enable-quic --with-feature:adblock-snippets=on --with-feature:aliexpress-modal=off --with-feature:booking-modal=off --with-feature:bookmarks-trash-cleaner=on --with-feature:cashback-all-workspaces=on --with-feature:continue-on-booking=on --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:enhanced-address-bar=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:pinboard-local=on --with-feature:premium-valve-in=on --with-feature:reader-mode=on --with-feature:rollout-dna=on --with-feature:sd-suggestions-external=on --with-feature:startpage-sync-banner=on --with-feature:yandex-zen-leads-for-nonsdusers=off --with-feature:yandex-zen-lift-up=off --with-feature:yat-emoji-addresses=on --with-feature:installer-experiment-test=off --with-feature:installer-use-minimal-package=off --with-feature:installer-opera-exe-in-root=on --ab_tests=DNA-90363-ref:DNA-90363 --mojo-platform-channel-handle=4024 /prefetch:8C:\Program Files\Opera\opera.exe
opera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Exit code:
0
Version:
81.0.4196.54
Modules
Images
c:\program files\opera\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\opera\81.0.4196.54\opera_elf.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\rpcrt4.dll
752"C:\Program Files\Opera\opera.exe" --type=renderer --extension-process --display-capture-permissions-policy-allowed --with-feature:adblock-snippets=on --with-feature:aliexpress-modal=off --with-feature:booking-modal=off --with-feature:bookmarks-trash-cleaner=on --with-feature:cashback-all-workspaces=on --with-feature:continue-on-booking=on --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:enhanced-address-bar=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:pinboard-local=on --with-feature:premium-valve-in=on --with-feature:reader-mode=on --with-feature:rollout-dna=on --with-feature:sd-suggestions-external=on --with-feature:startpage-sync-banner=on --with-feature:yandex-zen-leads-for-nonsdusers=off --with-feature:yandex-zen-lift-up=off --with-feature:yat-emoji-addresses=on --with-feature:installer-experiment-test=off --with-feature:installer-use-minimal-package=off --with-feature:installer-opera-exe-in-root=on --ab_tests=DNA-90363-ref:DNA-90363 --field-trial-handle=1012,5649344169875940080,546516825159334456,131072 --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --mojo-platform-channel-handle=1288 /prefetch:1C:\Program Files\Opera\opera.exe
opera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Exit code:
0
Version:
81.0.4196.54
Modules
Images
c:\program files\opera\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\opera\81.0.4196.54\opera_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
956"C:\Users\admin\AppData\Local\Temp\OperaSetup.exe" --backend --install --import-browser-data=0 --enable-stats=1 --enable-installer-stats=1 --launchopera=1 --installfolder="C:\Program Files\Opera" --profile-folder --language=en --singleprofile=0 --copyonly=0 --allusers=0 --setdefaultbrowser=1 --pintotaskbar=1 --pintostartmenu=1 --pin-additional-shortcuts=1 --server-tracking-data=server_tracking_data --initial-pid=4008 --package-dir-prefix="C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_20211121185436" --session-guid=ebca4701-6b65-46a6-b649-1daf464a3f56 --server-tracking-blob=ZTUzYWI0ODA2YzlmMGE2MDA4ZjVmNGQ4MzkxOTM2M2I4YmEzYzQxMWE3YTQ4YWU1MjJlZGMyNGNjOTk3MWVlMjp7ImNvdW50cnkiOiJGSSIsImh0dHBfcmVmZXJyZXIiOiJodHRwczovL3d3dy5vcGVyYS5jb20vIiwiaW5zdGFsbGVyX25hbWUiOiJPcGVyYVNldHVwLmV4ZSIsInByb2R1Y3QiOiJvcGVyYSIsInF1ZXJ5IjoiL29wZXJhL3N0YWJsZS93aW5kb3dzP3V0bV90cnlhZ2Fpbj15ZXMmdXRtX3NvdXJjZT1tLm9wZXJhLmNvbV92aWFfb3BlcmFfY29tJnV0bV9tZWRpdW09cm9jJnV0bV9jYW1wYWlnbj0obm9uZSlfdmlhX29wZXJhX2NvbV9odHRwcyZ1dG1fY29udGVudD0lMkYmaHR0cF9yZWZlcnJlcj1odHRwJTNBJTJGJTJGbS5vcGVyYS5jb20lMkYmdXRtX3NpdGU9b3BlcmFfY29tJiZ1dG1fbGFzdHBhZ2U9b3BlcmEuY29tL2Rvd25sb2FkJmRsX3Rva2VuPTk1NDU1MDcwIiwidGltZXN0YW1wIjoiMTYzNzUxODM3Ni44MzM5IiwidXNlcmFnZW50IjoiTW96aWxsYS81LjAgKFgxMTsgTGludXggeDg2XzY0KSBBcHBsZVdlYktpdC81MzcuMzYgKEtIVE1MLCBsaWtlIEdlY2tvKSBDaHJvbWUvOTUuMC40NjM4Ljc0IFNhZmFyaS81MzcuMzYiLCJ1dG0iOnsiY2FtcGFpZ24iOiIobm9uZSlfdmlhX29wZXJhX2NvbV9odHRwcyIsImNvbnRlbnQiOiIvIiwibGFzdHBhZ2UiOiJvcGVyYS5jb20vZG93bmxvYWQiLCJtZWRpdW0iOiJyb2MiLCJzaXRlIjoib3BlcmFfY29tIiwic291cmNlIjoibS5vcGVyYS5jb21fdmlhX29wZXJhX2NvbSIsInRyeWFnYWluIjoieWVzIn0sInV1aWQiOiI4NWU1ODE3Ny02ZDIyLTRkOGYtYTY3Yi0wODdhMzJiYTdiNWMifQ== --desktopshortcut=1 --wait-for-package --initial-proc-handle=D405000000000000C:\Users\admin\AppData\Local\Temp\OperaSetup.exe
OperaSetup.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera Installer
Exit code:
0
Version:
81.0.4196.37
Modules
Images
c:\users\admin\appdata\local\temp\operasetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
956"C:\Program Files\Opera\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --field-trial-handle=1012,5649344169875940080,546516825159334456,131072 --lang=en-US --service-sandbox-type=service --enable-quic --with-feature:adblock-snippets=on --with-feature:aliexpress-modal=off --with-feature:booking-modal=off --with-feature:bookmarks-trash-cleaner=on --with-feature:cashback-all-workspaces=on --with-feature:continue-on-booking=on --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:enhanced-address-bar=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:pinboard-local=on --with-feature:premium-valve-in=on --with-feature:reader-mode=on --with-feature:rollout-dna=on --with-feature:sd-suggestions-external=on --with-feature:startpage-sync-banner=on --with-feature:yandex-zen-leads-for-nonsdusers=off --with-feature:yandex-zen-lift-up=off --with-feature:yat-emoji-addresses=on --with-feature:installer-experiment-test=off --with-feature:installer-use-minimal-package=off --with-feature:installer-opera-exe-in-root=on --ab_tests=DNA-90363-ref:DNA-90363 --mojo-platform-channel-handle=3496 /prefetch:8C:\Program Files\Opera\opera.exe
opera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Exit code:
0
Version:
81.0.4196.54
Modules
Images
c:\program files\opera\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\opera\81.0.4196.54\opera_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
1056"C:\Program Files\Opera\opera.exe" --type=renderer --extension-process --display-capture-permissions-policy-allowed --with-feature:adblock-snippets=on --with-feature:aliexpress-modal=off --with-feature:booking-modal=off --with-feature:bookmarks-trash-cleaner=on --with-feature:cashback-all-workspaces=on --with-feature:continue-on-booking=on --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:enhanced-address-bar=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:pinboard-local=on --with-feature:premium-valve-in=on --with-feature:reader-mode=on --with-feature:rollout-dna=on --with-feature:sd-suggestions-external=on --with-feature:startpage-sync-banner=on --with-feature:yandex-zen-leads-for-nonsdusers=off --with-feature:yandex-zen-lift-up=off --with-feature:yat-emoji-addresses=on --with-feature:installer-experiment-test=off --with-feature:installer-use-minimal-package=off --with-feature:installer-opera-exe-in-root=on --ab_tests=DNA-90363-ref:DNA-90363 --field-trial-handle=1012,5649344169875940080,546516825159334456,131072 --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2152 /prefetch:1C:\Program Files\Opera\opera.exe
opera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Exit code:
0
Version:
81.0.4196.54
Modules
Images
c:\program files\opera\opera.exe
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
1232"C:\Program Files\Opera\opera.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --field-trial-handle=1012,5649344169875940080,546516825159334456,131072 --lang=en-US --service-sandbox-type=utility --enable-quic --with-feature:adblock-snippets=on --with-feature:aliexpress-modal=off --with-feature:booking-modal=off --with-feature:bookmarks-trash-cleaner=on --with-feature:cashback-all-workspaces=on --with-feature:continue-on-booking=on --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:enhanced-address-bar=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:pinboard-local=on --with-feature:premium-valve-in=on --with-feature:reader-mode=on --with-feature:rollout-dna=on --with-feature:sd-suggestions-external=on --with-feature:startpage-sync-banner=on --with-feature:yandex-zen-leads-for-nonsdusers=off --with-feature:yandex-zen-lift-up=off --with-feature:yat-emoji-addresses=on --with-feature:installer-experiment-test=off --with-feature:installer-use-minimal-package=off --with-feature:installer-opera-exe-in-root=on --ab_tests=DNA-90363-ref:DNA-90363 --mojo-platform-channel-handle=1456 /prefetch:8C:\Program Files\Opera\opera.exe
opera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Exit code:
0
Version:
81.0.4196.54
Modules
Images
c:\program files\opera\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\opera\81.0.4196.54\opera_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
Total events
31 319
Read events
30 292
Write events
1 011
Delete events
16

Modification events

(PID) Process:(4008) OperaSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(4008) OperaSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(4008) OperaSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(4008) OperaSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(4008) OperaSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000003B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A80164000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4008) OperaSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(4008) OperaSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(4008) OperaSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(4008) OperaSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(4008) OperaSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{362E934C-743B-4588-8259-D2482DB771A8}
Operation:writeName:WpadDecisionReason
Value:
1
Executable files
45
Suspicious files
249
Text files
318
Unknown types
93

Dropped files

PID
Process
Filename
Type
4008OperaSetup.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\Opera_81.0.4196.54_Autoupdate[1].exe
MD5:
SHA256:
4008OperaSetup.exeC:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202111211854361\opera_package
MD5:
SHA256:
3412OperaSetup.exeC:\Users\admin\AppData\Local\Temp\Opera_installer_2111211854367793412.dllexecutable
MD5:
SHA256:
4008OperaSetup.exeC:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\OperaSetup.exeexecutable
MD5:
SHA256:
4008OperaSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:
SHA256:
3412OperaSetup.exeC:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports\settings.datbinary
MD5:
SHA256:
4008OperaSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_A30EA9B4E1BC5DBF09A8EF399E086D27binary
MD5:
SHA256:
4008OperaSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_A30EA9B4E1BC5DBF09A8EF399E086D27der
MD5:
SHA256:
4008OperaSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_B514E3306E9B5CC22C1D3DB90570477Ader
MD5:
SHA256:
4008OperaSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2543B5AF7D46D42E6CEED21F85143F6A_76C8AADE6EB248401DF3904F8897EA75der
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
31
TCP/UDP connections
65
DNS requests
31
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/chmq42wq2tnxuyhxibhtmgwnby_2739/jflookgnkcckhobaglndicnbbgbonegd_2739_all_ad2oqlccgziux2cdpjsen2fevv2q.crx3
US
binary
5.66 Kb
whitelisted
4008
OperaSetup.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAonX%2BcE1u7LI9XNW0saTgQ%3D
US
der
471 b
whitelisted
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvZjE0QUFYTUR2NXNIakJsbE5jbXNrUkdfQQ/4.10.2391.0_oimompecagnajdejgnnjijobebaeigek.crx
US
binary
91.1 Kb
whitelisted
4008
OperaSetup.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAo1CNVcKSsBffitZcAP9%2BQ%3D
US
der
471 b
whitelisted
4008
OperaSetup.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAonX%2BcE1u7LI9XNW0saTgQ%3D
US
der
471 b
whitelisted
4008
OperaSetup.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTk45WiKdPUwcMf8JgMC07ACYqr2AQUt2ui6qiqhIx56rTaD5iyxZV2ufQCEAbZZpbmmtLB7MgcPACTNIo%3D
US
der
471 b
whitelisted
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvZjE0QUFYTUR2NXNIakJsbE5jbXNrUkdfQQ/4.10.2391.0_oimompecagnajdejgnnjijobebaeigek.crx
US
binary
9.26 Kb
whitelisted
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvZjE0QUFYTUR2NXNIakJsbE5jbXNrUkdfQQ/4.10.2391.0_oimompecagnajdejgnnjijobebaeigek.crx
US
binary
44.8 Kb
whitelisted
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvZjE0QUFYTUR2NXNIakJsbE5jbXNrUkdfQQ/4.10.2391.0_oimompecagnajdejgnnjijobebaeigek.crx
US
binary
8.10 Kb
whitelisted
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvZjE0QUFYTUR2NXNIakJsbE5jbXNrUkdfQQ/4.10.2391.0_oimompecagnajdejgnnjijobebaeigek.crx
US
binary
369 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2408
opera.exe
185.26.182.94:443
sitecheck.opera.com
Opera Software AS
whitelisted
2408
opera.exe
185.26.182.112:443
sitecheck.opera.com
Opera Software AS
malicious
2408
opera.exe
185.26.182.110:443
redir.opera.com
Opera Software AS
unknown
2408
opera.exe
185.26.182.93:443
sitecheck.opera.com
Opera Software AS
whitelisted
4008
OperaSetup.exe
185.26.182.124:443
autoupdate.geo.opera.com
Opera Software AS
suspicious
4008
OperaSetup.exe
82.145.217.121:443
desktop-netinstaller-sub.osp.opera.software
Opera Software AS
suspicious
4008
OperaSetup.exe
2.16.186.72:80
ctldl.windowsupdate.com
Akamai International B.V.
whitelisted
4008
OperaSetup.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2408
opera.exe
2.16.186.240:443
sd-images.operacdn.com
Akamai International B.V.
whitelisted
2408
opera.exe
104.111.243.59:443
cdn-production-opera-website.operacdn.com
Akamai International B.V.
NL
whitelisted

DNS requests

Domain
IP
Reputation
desktop-netinstaller-sub.osp.opera.software
  • 82.145.217.121
whitelisted
autoupdate.geo.opera.com
  • 185.26.182.124
  • 185.26.182.123
  • 82.145.216.19
  • 82.145.216.20
whitelisted
ctldl.windowsupdate.com
  • 2.16.186.72
  • 2.16.186.56
  • 2.16.186.89
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
download.opera.com
  • 82.145.216.23
  • 82.145.216.24
whitelisted
download5.operacdn.com
  • 104.18.2.211
  • 104.18.3.211
suspicious
features.opera-api.com
  • 82.145.216.15
  • 82.145.216.16
whitelisted
sitecheck.opera.com
  • 185.26.182.93
  • 185.26.182.118
  • 185.26.182.106
  • 185.26.182.111
  • 185.26.182.112
  • 185.26.182.94
whitelisted
speeddials.opera.com
  • 185.26.182.94
  • 185.26.182.93
  • 185.26.182.112
  • 185.26.182.111
whitelisted
merchandise.opera-api.com
  • 185.26.182.112
  • 185.26.182.111
malicious

Threats

No threats detected
Process
Message
assistant_installer.exe
[1121/185526.990:INFO:assistant_installer_main.cc(168)] Running assistant installer with command line "C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202111211854361\assistant\assistant_installer.exe" --version