File name:

OperaGXSetup.exe

Full analysis: https://app.any.run/tasks/aa41605c-588d-4f3a-a952-5bca2651bef9
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: May 23, 2025, 17:36:55
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
opera
tool
stealer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

8C8D45634B0BE10CA7EA33DBDB4F570A

SHA1:

A20FBCE17EE93C46A304727FFC23FCD70F80FC63

SHA256:

AB349DFD6CCB45CE5EA7C8732ECF62F36AEBB08990E494E83EA0A416EE6B0652

SSDEEP:

98304:EwyWSeMgtXYSgRQKCTzPuJyMACrhSLUyQiXMEZIndZvsG2/cA/8HlcoDEe1HoQ+q:EvDH2lpTmb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • opera.exe (PID: 632)
    • Steals credentials from Web Browsers

      • opera.exe (PID: 632)
    • Actions looks like stealing of personal data

      • opera.exe (PID: 632)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • OperaGXSetup.exe (PID: 1764)
      • setup.exe (PID: 2148)
      • setup.exe (PID: 6724)
      • setup.exe (PID: 1272)
      • setup.exe (PID: 1312)
      • setup.exe (PID: 6620)
      • Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe (PID: 4980)
      • installer.exe (PID: 6108)
      • installer.exe (PID: 736)
      • installer.exe (PID: 9068)
      • installer.exe (PID: 7904)
      • installer.exe (PID: 8320)
      • opera_autoupdate.exe (PID: 8860)
    • Application launched itself

      • setup.exe (PID: 2148)
      • assistant_installer.exe (PID: 1312)
      • setup.exe (PID: 6724)
      • installer.exe (PID: 736)
      • opera.exe (PID: 632)
      • opera_autoupdate.exe (PID: 8936)
      • installer.exe (PID: 9068)
      • opera_autoupdate.exe (PID: 8860)
    • Reads security settings of Internet Explorer

      • setup.exe (PID: 2148)
      • installer.exe (PID: 736)
    • Starts itself from another location

      • setup.exe (PID: 2148)
    • Searches for installed software

      • installer.exe (PID: 736)
    • Creates a software uninstall entry

      • installer.exe (PID: 736)
    • There is functionality for taking screenshot (YARA)

      • setup.exe (PID: 1272)
      • setup.exe (PID: 2148)
    • Reads the date of Windows installation

      • installer.exe (PID: 736)
      • opera.exe (PID: 632)
    • Reads Mozilla Firefox installation path

      • opera.exe (PID: 632)
    • The process checks if it is being run in the virtual environment

      • opera.exe (PID: 632)
    • The process executes via Task Scheduler

      • opera_autoupdate.exe (PID: 8860)
    • Executes application which crashes

      • opera.exe (PID: 7912)
  • INFO

    • Checks supported languages

      • OperaGXSetup.exe (PID: 1764)
      • setup.exe (PID: 2148)
      • setup.exe (PID: 1272)
      • setup.exe (PID: 1312)
      • Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe (PID: 4980)
      • assistant_installer.exe (PID: 1312)
      • assistant_installer.exe (PID: 6700)
      • setup.exe (PID: 6620)
      • setup.exe (PID: 6724)
      • installer.exe (PID: 6108)
      • installer.exe (PID: 736)
      • opera_crashreporter.exe (PID: 1164)
      • opera.exe (PID: 3304)
      • opera.exe (PID: 2432)
      • opera.exe (PID: 6192)
      • opera.exe (PID: 5776)
      • opera.exe (PID: 6032)
      • opera.exe (PID: 4980)
      • opera.exe (PID: 3268)
      • opera.exe (PID: 5984)
      • opera.exe (PID: 4224)
      • opera.exe (PID: 632)
      • opera_gx_splash.exe (PID: 7432)
      • opera.exe (PID: 7676)
      • opera.exe (PID: 7692)
      • opera.exe (PID: 7832)
      • opera.exe (PID: 7816)
      • opera.exe (PID: 7800)
      • opera.exe (PID: 7872)
      • opera.exe (PID: 7900)
      • opera.exe (PID: 7912)
      • opera.exe (PID: 7888)
      • opera.exe (PID: 7964)
      • opera.exe (PID: 8028)
      • opera.exe (PID: 8068)
      • opera.exe (PID: 8036)
      • opera.exe (PID: 8188)
      • opera.exe (PID: 1052)
      • opera.exe (PID: 8180)
      • opera.exe (PID: 5760)
      • opera.exe (PID: 616)
      • opera.exe (PID: 2236)
      • opera.exe (PID: 6728)
      • opera.exe (PID: 8020)
      • opera.exe (PID: 7388)
      • opera.exe (PID: 7048)
      • opera.exe (PID: 7392)
      • opera.exe (PID: 5556)
      • opera.exe (PID: 4724)
      • opera.exe (PID: 5124)
      • opera.exe (PID: 7668)
      • opera.exe (PID: 9048)
      • opera_autoupdate.exe (PID: 8952)
      • opera.exe (PID: 8876)
      • opera.exe (PID: 8652)
      • opera_autoupdate.exe (PID: 8936)
      • opera.exe (PID: 9076)
      • opera.exe (PID: 8520)
      • opera.exe (PID: 8636)
      • installer.exe (PID: 7904)
      • opera_autoupdate.exe (PID: 8268)
      • opera_autoupdate.exe (PID: 8860)
      • installer.exe (PID: 9068)
      • opera.exe (PID: 8376)
      • opera.exe (PID: 2908)
      • opera.exe (PID: 9160)
    • Create files in a temporary directory

      • OperaGXSetup.exe (PID: 1764)
      • setup.exe (PID: 1272)
      • setup.exe (PID: 6724)
      • setup.exe (PID: 2148)
      • setup.exe (PID: 1312)
      • Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe (PID: 4980)
      • setup.exe (PID: 6620)
      • installer.exe (PID: 736)
      • installer.exe (PID: 6108)
      • opera.exe (PID: 632)
      • installer.exe (PID: 9068)
      • installer.exe (PID: 7904)
    • The sample compiled with english language support

      • OperaGXSetup.exe (PID: 1764)
      • setup.exe (PID: 2148)
      • setup.exe (PID: 1272)
      • setup.exe (PID: 1312)
      • setup.exe (PID: 6724)
      • setup.exe (PID: 6620)
      • Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe (PID: 4980)
      • installer.exe (PID: 6108)
      • installer.exe (PID: 736)
      • installer.exe (PID: 9068)
      • installer.exe (PID: 7904)
      • opera_autoupdate.exe (PID: 8860)
      • installer.exe (PID: 8320)
    • Reads the computer name

      • setup.exe (PID: 2148)
      • assistant_installer.exe (PID: 1312)
      • setup.exe (PID: 6724)
      • installer.exe (PID: 736)
      • opera.exe (PID: 632)
      • opera.exe (PID: 6192)
      • opera.exe (PID: 2432)
      • opera_gx_splash.exe (PID: 7432)
      • opera.exe (PID: 7668)
      • opera_autoupdate.exe (PID: 8936)
      • opera_autoupdate.exe (PID: 8860)
      • installer.exe (PID: 9068)
    • Reads the machine GUID from the registry

      • setup.exe (PID: 2148)
      • opera.exe (PID: 632)
      • opera_autoupdate.exe (PID: 8936)
      • opera_autoupdate.exe (PID: 8952)
      • opera_autoupdate.exe (PID: 8860)
      • opera_autoupdate.exe (PID: 8268)
    • Creates files or folders in the user directory

      • setup.exe (PID: 2148)
      • setup.exe (PID: 1272)
      • setup.exe (PID: 6724)
      • installer.exe (PID: 736)
      • opera.exe (PID: 632)
      • opera.exe (PID: 2432)
      • WerFault.exe (PID: 8500)
    • Reads the software policy settings

      • setup.exe (PID: 2148)
    • Checks proxy server information

      • setup.exe (PID: 2148)
      • opera.exe (PID: 632)
      • opera_autoupdate.exe (PID: 8936)
    • OPERA mutex has been found

      • opera.exe (PID: 632)
      • opera_autoupdate.exe (PID: 8936)
    • Process checks computer location settings

      • opera.exe (PID: 632)
      • opera.exe (PID: 7692)
      • opera.exe (PID: 7676)
      • opera.exe (PID: 7800)
      • opera.exe (PID: 7832)
      • opera.exe (PID: 5984)
      • opera.exe (PID: 7816)
      • opera.exe (PID: 8020)
      • opera.exe (PID: 8036)
      • opera.exe (PID: 8028)
      • opera.exe (PID: 8068)
      • opera.exe (PID: 7964)
      • opera.exe (PID: 8876)
      • opera.exe (PID: 8520)
      • opera.exe (PID: 8376)
      • opera.exe (PID: 9160)
      • opera.exe (PID: 2908)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:06:12 14:59:19+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.39
CodeSize: 238080
InitializedDataSize: 92672
UninitializedDataSize: -
EntryPoint: 0x213c0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 117.0.5408.193
ProductVersionNumber: 117.0.5408.193
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
FileVersion: 117.0.5408.193
ProductVersion: 117.0.5408.193
FileDescription: Opera installer SFX
CompanyName:
LegalCopyright: Opera Software 2025
Productname: Opera installer
Stream: Stable
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
229
Monitored processes
98
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
start operagxsetup.exe setup.exe setup.exe sppextcomobj.exe no specs slui.exe setup.exe setup.exe setup.exe opera_gx_assistant_73.0.3856.382_setup.exe_sfx.exe assistant_installer.exe no specs assistant_installer.exe no specs installer.exe installer.exe opera.exe opera_crashreporter.exe no specs opera.exe no specs opera.exe opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera_gx_splash.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs comppkgsrv.exe no specs opera_autoupdate.exe opera.exe no specs opera_autoupdate.exe opera_autoupdate.exe no specs opera.exe no specs installer.exe opera.exe no specs opera_autoupdate.exe no specs installer.exe opera.exe no specs werfault.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs installer.exe slui.exe no specs svchost.exe

Process information

PID
CMD
Path
Indicators
Parent process
616"C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --enable-quic --no-pre-read-main-dll --with-feature:cashback-assistant=on --with-feature:address-bar-dropdown-autocompleted-domains=on --with-feature:address-bar-dropdown-cities=off --with-feature:address-bar-dropdown-keyword-ads=on --with-feature:address-bar-dropdown-unfiltered-full=off --with-feature:ai-writing-mode-in-context-menu=on --with-feature:aria-in-tab-view=on --with-feature:cashback-assistant=on --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-amazon-us-associates=off --with-feature:continue-shopping-explore=off --with-feature:continue-shopping-structured-partners=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:game-servers=off --with-feature:gx-april1st=off --with-feature:gx-post-mortem=on --with-feature:gx-reactinator=on --with-feature:gx-spotlight=on --with-feature:gx-video-to-phone=on --with-feature:hide-navigations-from-extensions=on --with-feature:keywords-from-backend=off --with-feature:panic-button=on --with-feature:play-again=on --with-feature:realtime-impressions-reporting=on --with-feature:run-at-startup-default=on --with-feature:sd-suggestions-external=on --with-feature:side-profiles=on --with-feature:sitecheck-age=on --with-feature:tiktok-panel=on --with-feature:ui-compositor-multithreaded=on --with-feature:installer-experiment-test=off --ab_tests=GXCTest50-ref:DNA-99214_GXCTest50 --field-trial-handle=2028,i,1115011098638327239,18309260416520720872,262144 --disable-features=CertificateTransparencyAskBeforeEnabling,PlatformSoftwareH264EncoderInGpu,UpdatableKeyPins --variations-seed-version --mojo-platform-channel-handle=8472 /prefetch:8C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera GX Internet Browser
Exit code:
0
Version:
119.0.5497.43
632"C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe" --start-maximizedC:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe
installer.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera GX Internet Browser
Version:
119.0.5497.43
736"C:\Users\admin\AppData\Local\Programs\Opera GX\119.0.5497.43\installer.exe" --backend --initial-pid=2148 --install --import-browser-data=0 --enable-crash-reporting=1 --enable-stats=1 --enable-installer-stats=1 --consent-given=1 --general-interests=1 --general-location=1 --personalized-content=1 --personalized-ads=1 --vought_browser=0 --launchopera=1 --showunbox=0 --installfolder="C:\Users\admin\AppData\Local\Programs\Opera GX" --profile-folder --language=en --singleprofile=0 --copyonly=0 --allusers=0 --setdefaultbrowser=0 --pintotaskbar=1 --pintostartmenu=1 --run-at-startup=1 --server-tracking-data=server_tracking_data --package-dir="C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202505231737001" --session-guid=f6305211-89a2-492f-a97f-b24cd2b2d8ab --server-tracking-blob=ZTk4YzNhZmU3NWI1MGJlM2U4ZTM1NmRkYjBkZGQ3ZjczNDE0Y2UyMzM4NTNhNTc1MzAwZjlmMWMwNTI0M2E4Mzp7ImNvdW50cnkiOiJBVCIsImh0dHBfcmVmZXJyZXIiOiJodHRwczovL3d3dy5vcGVyYS5jb20vIiwiaW5zdGFsbGVyX25hbWUiOiJPcGVyYUdYU2V0dXAuZXhlIiwicHJvZHVjdCI6eyJuYW1lIjoib3BlcmFfZ3gifSwicXVlcnkiOiIvb3BlcmFfZ3gvc3RhYmxlL3dpbmRvd3M/dXRtX3NvdXJjZT1iaW5nJnV0bV9tZWRpdW09b3NlJnV0bV9jYW1wYWlnbj0lMjhub25lJTI5Jmh0dHBfcmVmZXJyZXI9aHR0cHMlM0ElMkYlMkZ3d3cuYmluZy5jb20lMkYmdXRtX3NpdGU9b3BlcmFfY29tJnV0bV9sYXN0cGFnZT1vcGVyYS5jb20lMkZneCZkbF90b2tlbj0zNDg4Mzc0OSIsInN5c3RlbSI6eyJwbGF0Zm9ybSI6eyJhcmNoIjoieDg2XzY0Iiwib3BzeXMiOiJXaW5kb3dzIiwib3BzeXMtdmVyc2lvbiI6IjEwIiwicGFja2FnZSI6IkVYRSJ9fSwidGltZXN0YW1wIjoiMTc0MzY5MzQxNC42Mzg2IiwidXNlcmFnZW50IjoiTW96aWxsYS81LjAgKFdpbmRvd3MgTlQgMTAuMDsgV2luNjQ7IHg2NCkgQXBwbGVXZWJLaXQvNTM3LjM2IChLSFRNTCwgbGlrZSBHZWNrbykgQ2hyb21lLzEzNC4wLjAuMCBTYWZhcmkvNTM3LjM2IEVkZy8xMzQuMC4wLjAiLCJ1dG0iOnsiY2FtcGFpZ24iOiIobm9uZSkiLCJsYXN0cGFnZSI6Im9wZXJhLmNvbS9neCIsIm1lZGl1bSI6Im9zZSIsInNpdGUiOiJvcGVyYV9jb20iLCJzb3VyY2UiOiJiaW5nIn0sInV1aWQiOiJlZmExYzg4Ny0wZTczLTQ3YmUtOWRkMi03MjdkMjg4ZWFiMzUifQ== --desktopshortcut=1 --install-subfolder=119.0.5497.43C:\Users\admin\AppData\Local\Programs\Opera GX\119.0.5497.43\installer.exe
setup.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera GX Installer
Exit code:
0
Version:
119.0.5497.43
1052"C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --enable-quic --no-pre-read-main-dll --with-feature:cashback-assistant=on --with-feature:address-bar-dropdown-autocompleted-domains=on --with-feature:address-bar-dropdown-cities=off --with-feature:address-bar-dropdown-keyword-ads=on --with-feature:address-bar-dropdown-unfiltered-full=off --with-feature:ai-writing-mode-in-context-menu=on --with-feature:aria-in-tab-view=on --with-feature:cashback-assistant=on --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-amazon-us-associates=off --with-feature:continue-shopping-explore=off --with-feature:continue-shopping-structured-partners=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:game-servers=off --with-feature:gx-april1st=off --with-feature:gx-post-mortem=on --with-feature:gx-reactinator=on --with-feature:gx-spotlight=on --with-feature:gx-video-to-phone=on --with-feature:hide-navigations-from-extensions=on --with-feature:keywords-from-backend=off --with-feature:panic-button=on --with-feature:play-again=on --with-feature:realtime-impressions-reporting=on --with-feature:run-at-startup-default=on --with-feature:sd-suggestions-external=on --with-feature:side-profiles=on --with-feature:sitecheck-age=on --with-feature:tiktok-panel=on --with-feature:ui-compositor-multithreaded=on --with-feature:installer-experiment-test=off --ab_tests=GXCTest50-ref:DNA-99214_GXCTest50 --field-trial-handle=2028,i,1115011098638327239,18309260416520720872,262144 --disable-features=CertificateTransparencyAskBeforeEnabling,PlatformSoftwareH264EncoderInGpu,UpdatableKeyPins --variations-seed-version --mojo-platform-channel-handle=8108 /prefetch:8C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera GX Internet Browser
Exit code:
0
Version:
119.0.5497.43
1164"C:\Users\admin\AppData\Local\Programs\Opera GX\119.0.5497.43\opera_crashreporter.exe" --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win64 --annotation=prod=OperaDesktopGX --annotation=ver=119.0.5497.43 --initial-client-data=0x220,0x224,0x228,0x21c,0x22c,0x7ffc826c5030,0x7ffc826c5040,0x7ffc826c5050C:\Users\admin\AppData\Local\Programs\Opera GX\119.0.5497.43\opera_crashreporter.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera GX crash-reporter
Version:
119.0.5497.43
1272C:\Users\admin\AppData\Local\Temp\7zS4E6B2E80\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win64 --annotation=prod=OperaDesktopGX --annotation=ver=117.0.5408.193 --initial-client-data=0x298,0x29c,0x2a0,0x274,0x2a4,0x7ffc897a1788,0x7ffc897a1794,0x7ffc897a17a0C:\Users\admin\AppData\Local\Temp\7zS4E6B2E80\setup.exe
setup.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera GX Installer
Exit code:
0
Version:
117.0.5408.193
1312"C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\setup.exe" --versionC:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\setup.exe
setup.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
1312"C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202505231737001\assistant\assistant_installer.exe" --versionC:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202505231737001\assistant\assistant_installer.exesetup.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera GX Browser Assistant Installer
Exit code:
0
Version:
73.0.3856.382
1764"C:\Users\admin\AppData\Local\Temp\OperaGXSetup.exe" C:\Users\admin\AppData\Local\Temp\OperaGXSetup.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Opera installer SFX
Exit code:
0
Version:
117.0.5408.193
2148C:\Users\admin\AppData\Local\Temp\7zS4E6B2E80\setup.exe --server-tracking-blob=Y2VkNTNkNzNlYTVjZGJmMzY5NzFhZDAwZDYwNzA5OWU2MGM4M2QyZjRiNmU2YTgxNjNiMDJjODYwODk3MjlmYTp7ImNvdW50cnkiOiJBVCIsImh0dHBfcmVmZXJyZXIiOiJodHRwczovL3d3dy5vcGVyYS5jb20vIiwiaW5zdGFsbGVyX25hbWUiOiJPcGVyYUdYU2V0dXAuZXhlIiwicHJvZHVjdCI6Im9wZXJhX2d4IiwicXVlcnkiOiIvb3BlcmFfZ3gvc3RhYmxlL3dpbmRvd3M/dXRtX3NvdXJjZT1iaW5nJnV0bV9tZWRpdW09b3NlJnV0bV9jYW1wYWlnbj0lMjhub25lJTI5Jmh0dHBfcmVmZXJyZXI9aHR0cHMlM0ElMkYlMkZ3d3cuYmluZy5jb20lMkYmdXRtX3NpdGU9b3BlcmFfY29tJnV0bV9sYXN0cGFnZT1vcGVyYS5jb20lMkZneCZkbF90b2tlbj0zNDg4Mzc0OSIsInRpbWVzdGFtcCI6IjE3NDM2OTM0MTQuNjM4NiIsInVzZXJhZ2VudCI6Ik1vemlsbGEvNS4wIChXaW5kb3dzIE5UIDEwLjA7IFdpbjY0OyB4NjQpIEFwcGxlV2ViS2l0LzUzNy4zNiAoS0hUTUwsIGxpa2UgR2Vja28pIENocm9tZS8xMzQuMC4wLjAgU2FmYXJpLzUzNy4zNiBFZGcvMTM0LjAuMC4wIiwidXRtIjp7ImNhbXBhaWduIjoiKG5vbmUpIiwibGFzdHBhZ2UiOiJvcGVyYS5jb20vZ3giLCJtZWRpdW0iOiJvc2UiLCJzaXRlIjoib3BlcmFfY29tIiwic291cmNlIjoiYmluZyJ9LCJ1dWlkIjoiZWZhMWM4ODctMGU3My00N2JlLTlkZDItNzI3ZDI4OGVhYjM1In0=C:\Users\admin\AppData\Local\Temp\7zS4E6B2E80\setup.exe
OperaGXSetup.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera GX Installer
Exit code:
0
Version:
117.0.5408.193
Total events
0
Read events
0
Write events
0
Delete events
0

Modification events

No data
Executable files
34
Suspicious files
983
Text files
618
Unknown types
2

Dropped files

PID
Process
Filename
Type
2148setup.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\Opera_GX_119.0.5497.43_Autoupdate_x64[1].exe
MD5:
SHA256:
2148setup.exeC:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202505231737001\opera_package
MD5:
SHA256:
2148setup.exeC:\Users\admin\AppData\Local\Temp\Opera_installer_2505231737002842148.dllexecutable
MD5:153815CF08BEA9621B3E96A28E63C76C
SHA256:A808AA13A9950D22DAC1A574816C710ACB3BE8B705C7DBB9720775389A974EF4
2148setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\59D76868C250B3240414CE3EFBB12518_9AD8E6D69BA520C5190A9B86E29789D5binary
MD5:78C26288670002F63B2567493749862A
SHA256:28755C568269D4D2FF8538ADFAEC68ADECC1D29C8E6EDA9DD81852CD5FA899F6
2148setup.exeC:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\Crash Reports\settings.datbinary
MD5:48A87D80F2BE8F1ACB47069821AE944B
SHA256:BACEC5148B5B4355D52E7ED71E43FFBB48E5454C0331710A1A664E1DE88EC158
1764OperaGXSetup.exeC:\Users\admin\AppData\Local\Temp\7zS4E6B2E80\setup.exeexecutable
MD5:5D05A327B62196FF6A97F42964C42BE6
SHA256:D4B9BA8C1939A9442B7BE503FCAAD17A8A14C11E9AD7663676899BE3F9D743A4
2148setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\26C212D9399727259664BDFCA073966E_B7ED31D77D311A56FDCB56A0083B3E0Bbinary
MD5:69C6B9A9AEE368ECCDFE0EBE5B4EDFDC
SHA256:50CE0465A3235BF25BE02FC68E1662D85AC7E29451D4D6A6C77FDE4FDC7895E9
2148setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419binary
MD5:B2E669275FFD37E3FF4D1605D98A2568
SHA256:4B5B0893BF36A056BC1A8630CEA1BA11E0FE112CF601CFE482DCB157D77DBF11
2148setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\59D76868C250B3240414CE3EFBB12518_9AD8E6D69BA520C5190A9B86E29789D5binary
MD5:1159C6F9D84376CBE3B2D0F5F74EF7AF
SHA256:EDD6AA105B60B30FB6DAB49057EC2888ED31EF8BA8E564B0E6B9284756A88C4E
2148setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419binary
MD5:D6A6B79FD8FB2B068CBFC913BF777023
SHA256:194F7E5E6CC4CED87A6A6A65B325B4F93655414DC9B92E613F851DDE759CE804
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
101
DNS requests
101
Threats
30

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.53.40.178:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5796
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2148
setup.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
unknown
whitelisted
2148
setup.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnxLiz3Fu1WB6n1%2FE6xWn1b0jXiQQUdIWAwGbH3zfez70pN6oDHb7tzRcCEA17ZgsSl63KHstWnAbUez0%3D
unknown
whitelisted
2148
setup.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAsA6S1NbXMfyjBZx8seGIY%3D
unknown
whitelisted
2148
setup.exe
GET
200
172.217.23.99:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
2148
setup.exe
GET
200
172.217.23.99:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
2148
setup.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
2148
setup.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA0xwj6yJJzmEblT%2BxbqDSU%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.53.40.178:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5796
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5496
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5212
RUXIMICS.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5796
svchost.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2148
setup.exe
82.145.217.121:443
desktop-netinstaller-sub.osp.opera.software
Opera Software AS
NO
whitelisted
2148
setup.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 23.53.40.178
  • 23.53.40.176
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
google.com
  • 142.250.186.78
whitelisted
desktop-netinstaller-sub.osp.opera.software
  • 82.145.217.121
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
autoupdate.opera.com
  • 82.145.216.20
  • 82.145.216.19
  • 82.145.216.47
  • 82.145.216.46
  • 185.26.182.124
  • 185.26.182.123
whitelisted
features.opera-api2.com
  • 82.145.216.16
  • 82.145.216.58
  • 82.145.216.59
  • 82.145.216.15
  • 185.26.182.111
  • 185.26.182.94
  • 185.26.182.112
  • 185.26.182.106
  • 185.26.182.118
  • 185.26.182.93
malicious
api.config.opr.gg
  • 104.18.25.17
  • 104.18.24.17
unknown
c.pki.goog
  • 172.217.23.99
whitelisted
download.opera.com
  • 82.145.216.24
  • 82.145.216.23
  • 82.145.216.48
  • 82.145.216.49
whitelisted

Threats

PID
Process
Class
Message
2432
opera.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2432
opera.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2432
opera.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
2432
opera.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
2432
opera.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
2432
opera.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
2432
opera.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2432
opera.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2432
opera.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
2432
opera.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
No debug info