| File name: | OperaGXSetup.exe |
| Full analysis: | https://app.any.run/tasks/40a8f58f-fec1-4b81-ae75-cfba61edea89 |
| Verdict: | Malicious activity |
| Analysis date: | October 07, 2024, 20:46:03 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 962A74C9682922D8D4FE687804E6E983 |
| SHA1: | 8C3B8B250B6F30A822D03E71E19E9FA072942307 |
| SHA256: | AC87318789EA6156BE615862E34C4275D44F8B3E474990E1F1745132698B9DCC |
| SSDEEP: | 98304:0HLbFiZuTvFf1RxT1Vxcfjy9crzXMJtZyW/wDGKnoDj56okBke8M2eNMbDVqXoqm:OOXo |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:05:13 16:30:34+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 285184 |
| InitializedDataSize: | 5661184 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x12a7c |
| OSVersion: | 10 |
| ImageVersion: | - |
| SubsystemVersion: | 10 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 109.0.5097.90 |
| ProductVersionNumber: | 109.0.5097.90 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Opera Software |
| FileDescription: | Opera GX Installer |
| FileVersion: | 109.0.5097.90 |
| InternalName: | Opera GX |
| LegalCopyright: | Copyright Opera Software 2024 |
| ProductName: | Opera GX Installer |
| ProductVersion: | 109.0.5097.90 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1372 | "C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe" --start-maximized | C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe | — | installer.exe | |||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera GX Internet Browser Version: 114.0.5282.84 Modules
| |||||||||||||||
| 1936 | C:\WINDOWS\SysWOW64\DllHost.exe /Processid:{60A90A2F-858D-42AF-8929-82BE9D99E8A1} | C:\Windows\SysWOW64\dllhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: COM Surrogate Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2352 | "C:\Users\admin\AppData\Local\Programs\Opera GX\114.0.5282.84\installer.exe" --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win64 --annotation=prod=OperaDesktopGX --annotation=ver=114.0.5282.84 --initial-client-data=0x2a0,0x2a4,0x2a8,0x22c,0x2ac,0x7fffd3eb9a90,0x7fffd3eb9a9c,0x7fffd3eb9aa8 | C:\Users\admin\AppData\Local\Programs\Opera GX\114.0.5282.84\installer.exe | installer.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera GX Installer Exit code: 0 Version: 114.0.5282.84 Modules
| |||||||||||||||
| 2524 | "C:\Users\admin\AppData\Local\Programs\Opera GX\114.0.5282.84\opera_crashreporter.exe" --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win64 --annotation=prod=OperaDesktopGX --annotation=ver=114.0.5282.84 --initial-client-data=0x25c,0x260,0x264,0x258,0x268,0x7fffc1bb3808,0x7fffc1bb3818,0x7fffc1bb3828 | C:\Users\admin\AppData\Local\Programs\Opera GX\114.0.5282.84\opera_crashreporter.exe | — | opera.exe | |||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera GX crash-reporter Version: 114.0.5282.84 Modules
| |||||||||||||||
| 2820 | C:\Users\admin\AppData\Local\Temp\OperaGXSetup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\crash_count.txt" --url=https://crashstats-collector.opera.com/collector/submit --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktopGX --annotation=ver=109.0.5097.90 --initial-client-data=0x2cc,0x2d0,0x2e0,0x2a8,0x2e4,0x72224260,0x7222426c,0x72224278 | C:\Users\admin\AppData\Local\Temp\OperaGXSetup.exe | OperaGXSetup.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera GX Installer Exit code: 0 Version: 109.0.5097.90 Modules
| |||||||||||||||
| 2904 | "C:\Users\admin\AppData\Local\Temp\OperaGXSetup.exe" --backend --install --import-browser-data=0 --enable-stats=1 --enable-installer-stats=1 --consent-given=1 --general-interests=1 --general-location=1 --personalized-content=1 --personalized-ads=1 --launchopera=1 --installfolder="C:\Users\admin\AppData\Local\Programs\Opera GX" --profile-folder --language=en --singleprofile=0 --copyonly=0 --allusers=0 --setdefaultbrowser=0 --pintotaskbar=1 --pintostartmenu=1 --run-at-startup=1 --server-tracking-data=server_tracking_data --initial-pid=3812 --package-dir-prefix="C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_20241007204611" --session-guid=a60b65c2-0d12-47ad-96eb-b779e28a362f --server-tracking-blob=YWFkOTg2ODk3MDExOTdiNDE0NjVkMTVjYjhiZWU1NTFjMzdlNDNlZTM1YzMzYzgzODIzNTFlNmJlYmM0ZjQ1Yjp7ImNvdW50cnkiOiJTQSIsImh0dHBfcmVmZXJyZXIiOiJodHRwczovL3d3dy5vcGVyYS5jb20vIiwiaW5zdGFsbGVyX25hbWUiOiJPcGVyYUdYU2V0dXAuZXhlIiwicHJvZHVjdCI6eyJuYW1lIjoib3BlcmFfZ3gifSwicXVlcnkiOiIvb3BlcmFfZ3gvc3RhYmxlL3dpbmRvd3M/dXRtX3NvdXJjZT1iaW5nJnV0bV9tZWRpdW09b3NlJnV0bV9jYW1wYWlnbj0lMjhub25lJTI5Jmh0dHBfcmVmZXJyZXI9aHR0cHMlM0ElMkYlMkZ3d3cuYmluZy5jb20lMkYmdXRtX3NpdGU9b3BlcmFfY29tJnV0bV9sYXN0cGFnZT1vcGVyYS5jb20lMkYmZGxfdG9rZW49OTk5MjU2NjciLCJzeXN0ZW0iOnsicGxhdGZvcm0iOnsiYXJjaCI6Ing4Nl82NCIsIm9wc3lzIjoiV2luZG93cyIsIm9wc3lzLXZlcnNpb24iOiIxMCIsInBhY2thZ2UiOiJFWEUifX0sInRpbWVzdGFtcCI6IjE3MTU4NzUzOTcuNDYzMyIsInVzZXJhZ2VudCI6Ik1vemlsbGEvNS4wIChXaW5kb3dzIE5UIDEwLjA7IFdpbjY0OyB4NjQpIEFwcGxlV2ViS2l0LzUzNy4zNiAoS0hUTUwsIGxpa2UgR2Vja28pIENocm9tZS8xMjQuMC4wLjAgU2FmYXJpLzUzNy4zNiBFZGcvMTI0LjAuMC4wIiwidXRtIjp7ImNhbXBhaWduIjoiKG5vbmUpIiwibGFzdHBhZ2UiOiJvcGVyYS5jb20vIiwibWVkaXVtIjoib3NlIiwic2l0ZSI6Im9wZXJhX2NvbSIsInNvdXJjZSI6ImJpbmcifSwidXVpZCI6ImNjMDE4MjIxLWE5OTItNGI1Mi1iNjQyLTI2ZmI0NGZkNGY4OCJ9 --desktopshortcut=1 --wait-for-package --initial-proc-handle=4809000000000000 | C:\Users\admin\AppData\Local\Temp\OperaGXSetup.exe | OperaGXSetup.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera GX Installer Exit code: 0 Version: 109.0.5097.90 Modules
| |||||||||||||||
| 3044 | "C:\Users\admin\AppData\Local\Programs\Opera GX\114.0.5282.84\installer.exe" --backend --initial-pid=3812 --install --import-browser-data=0 --enable-stats=1 --enable-installer-stats=1 --consent-given=1 --general-interests=1 --general-location=1 --personalized-content=1 --personalized-ads=1 --launchopera=1 --installfolder="C:\Users\admin\AppData\Local\Programs\Opera GX" --profile-folder --language=en --singleprofile=0 --copyonly=0 --allusers=0 --setdefaultbrowser=0 --pintotaskbar=1 --pintostartmenu=1 --run-at-startup=1 --server-tracking-data=server_tracking_data --package-dir="C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202410072046111" --session-guid=a60b65c2-0d12-47ad-96eb-b779e28a362f --server-tracking-blob=YWFkOTg2ODk3MDExOTdiNDE0NjVkMTVjYjhiZWU1NTFjMzdlNDNlZTM1YzMzYzgzODIzNTFlNmJlYmM0ZjQ1Yjp7ImNvdW50cnkiOiJTQSIsImh0dHBfcmVmZXJyZXIiOiJodHRwczovL3d3dy5vcGVyYS5jb20vIiwiaW5zdGFsbGVyX25hbWUiOiJPcGVyYUdYU2V0dXAuZXhlIiwicHJvZHVjdCI6eyJuYW1lIjoib3BlcmFfZ3gifSwicXVlcnkiOiIvb3BlcmFfZ3gvc3RhYmxlL3dpbmRvd3M/dXRtX3NvdXJjZT1iaW5nJnV0bV9tZWRpdW09b3NlJnV0bV9jYW1wYWlnbj0lMjhub25lJTI5Jmh0dHBfcmVmZXJyZXI9aHR0cHMlM0ElMkYlMkZ3d3cuYmluZy5jb20lMkYmdXRtX3NpdGU9b3BlcmFfY29tJnV0bV9sYXN0cGFnZT1vcGVyYS5jb20lMkYmZGxfdG9rZW49OTk5MjU2NjciLCJzeXN0ZW0iOnsicGxhdGZvcm0iOnsiYXJjaCI6Ing4Nl82NCIsIm9wc3lzIjoiV2luZG93cyIsIm9wc3lzLXZlcnNpb24iOiIxMCIsInBhY2thZ2UiOiJFWEUifX0sInRpbWVzdGFtcCI6IjE3MTU4NzUzOTcuNDYzMyIsInVzZXJhZ2VudCI6Ik1vemlsbGEvNS4wIChXaW5kb3dzIE5UIDEwLjA7IFdpbjY0OyB4NjQpIEFwcGxlV2ViS2l0LzUzNy4zNiAoS0hUTUwsIGxpa2UgR2Vja28pIENocm9tZS8xMjQuMC4wLjAgU2FmYXJpLzUzNy4zNiBFZGcvMTI0LjAuMC4wIiwidXRtIjp7ImNhbXBhaWduIjoiKG5vbmUpIiwibGFzdHBhZ2UiOiJvcGVyYS5jb20vIiwibWVkaXVtIjoib3NlIiwic2l0ZSI6Im9wZXJhX2NvbSIsInNvdXJjZSI6ImJpbmcifSwidXVpZCI6ImNjMDE4MjIxLWE5OTItNGI1Mi1iNjQyLTI2ZmI0NGZkNGY4OCJ9 --desktopshortcut=1 --install-subfolder=114.0.5282.84 | C:\Users\admin\AppData\Local\Programs\Opera GX\114.0.5282.84\installer.exe | OperaGXSetup.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera GX Installer Exit code: 0 Version: 114.0.5282.84 Modules
| |||||||||||||||
| 3184 | "C:\Users\admin\AppData\Local\Programs\Opera GX\114.0.5282.84\opera_gx_splash.exe" --instance-name=5dd08f40413fd477cb25fa615ff02371 | C:\Users\admin\AppData\Local\Programs\Opera GX\114.0.5282.84\opera_gx_splash.exe | — | opera.exe | |||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 3256 | "C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202410072046111\assistant\assistant_installer.exe" --version | C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202410072046111\assistant\assistant_installer.exe | OperaGXSetup.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera GX Browser Assistant Installer Exit code: 0 Version: 73.0.3856.382 Modules
| |||||||||||||||
| 3316 | "C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe" --type=renderer --with-feature:cashback-assistant=on --with-feature:address-bar-dropdown-autocompleted-domains=off --with-feature:address-bar-dropdown-unfiltered-full=off --with-feature:amazon-new-ids=on --with-feature:cashback-assistant=on --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-structured-partners=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:game-servers=off --with-feature:gx-live-wallpapers-companion-app=off --with-feature:gx-post-mortem=on --with-feature:gx-reactinator=on --with-feature:gx-spotlight=on --with-feature:gx-video-to-phone=on --with-feature:lucid-mode-hide-text=on --with-feature:panic-button=on --with-feature:password-generator=off --with-feature:play-again=on --with-feature:run-at-startup-default=on --with-feature:sd-suggestions-external=on --with-feature:session-restore-attribution=on --with-feature:side-profiles=on --with-feature:sitecheck-age=on --with-feature:tiktok-panel=on --with-feature:ui-compositor-multithreaded=on --with-feature:installer-experiment-test=off --with-feature:installer-bypass-launcher=on --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=12 --field-trial-handle=3112,i,1290384536337660895,9417616774957581208,262144 --disable-features=CertificateTransparencyAskBeforeEnabling --variations-seed-version --mojo-platform-channel-handle=3904 /prefetch:1 | C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe | — | opera.exe | |||||||||||
User: admin Company: Opera Software Integrity Level: LOW Description: Opera GX Internet Browser Version: 114.0.5282.84 Modules
| |||||||||||||||
| (PID) Process: | (3812) OperaGXSetup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (3812) OperaGXSetup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3812) OperaGXSetup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (2904) OperaGXSetup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Opera Software |
| Operation: | write | Name: | Last Opera GX Stable Install Path |
Value: C:\Users\admin\AppData\Local\Programs\Opera GX\ | |||
| (PID) Process: | (3044) installer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Opera Software |
| Operation: | write | Name: | Last Opera GX Stable Install Path |
Value: C:\Users\admin\AppData\Local\Programs\Opera GX\ | |||
| (PID) Process: | (3044) installer.exe | Key: | HKEY_CLASSES_ROOT\Opera GXStable |
| Operation: | write | Name: | FriendlyTypeName |
Value: Opera GX Web Document | |||
| (PID) Process: | (3044) installer.exe | Key: | HKEY_CLASSES_ROOT\Opera GXStable |
| Operation: | write | Name: | URL Protocol |
Value: | |||
| (PID) Process: | (3044) installer.exe | Key: | HKEY_CLASSES_ROOT\.gxanimations\OpenWithProgIDs |
| Operation: | write | Name: | Opera GXStable |
Value: | |||
| (PID) Process: | (3044) installer.exe | Key: | HKEY_CLASSES_ROOT\.opdownload\OpenWithProgIDs |
| Operation: | write | Name: | Opera GXStable |
Value: | |||
| (PID) Process: | (3044) installer.exe | Key: | HKEY_CLASSES_ROOT\.htm\OpenWithProgids |
| Operation: | write | Name: | Opera GXStable |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3812 | OperaGXSetup.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\AH8CR9J5\Opera_GX_114.0.5282.84_Autoupdate_x64[1].exe | — | |
MD5:— | SHA256:— | |||
| 3812 | OperaGXSetup.exe | C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202410072046111\opera_package | — | |
MD5:— | SHA256:— | |||
| 3812 | OperaGXSetup.exe | C:\Users\admin\AppData\Local\Temp\Opera_installer_2410072046098113812.dll | executable | |
MD5:3445ABB5CB1F0B8AAE4A9E9B233C7A52 | SHA256:2FC634B9BD505FE53F76E124ABF4979698391A1BAE375D8184AA3E82EC007304 | |||
| 3812 | OperaGXSetup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\59D76868C250B3240414CE3EFBB12518_17DD39A60A87A85D0DDEF9FD164BB3E9 | binary | |
MD5:D9F642C684F76D073EE274E857D8CA57 | SHA256:07735CA30B15BBB29FB9880374F248192E470B9CBFD188655A536B727FA5F83D | |||
| 3812 | OperaGXSetup.exe | C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\OperaGXSetup.exe | executable | |
MD5:962A74C9682922D8D4FE687804E6E983 | SHA256:AC87318789EA6156BE615862E34C4275D44F8B3E474990E1F1745132698B9DCC | |||
| 5104 | OperaGXSetup.exe | C:\Users\admin\AppData\Local\Temp\Opera_installer_2410072046111555104.dll | executable | |
MD5:3445ABB5CB1F0B8AAE4A9E9B233C7A52 | SHA256:2FC634B9BD505FE53F76E124ABF4979698391A1BAE375D8184AA3E82EC007304 | |||
| 3988 | OperaGXSetup.exe | C:\Users\admin\AppData\Local\Temp\Opera_installer_2410072046101243988.dll | executable | |
MD5:3445ABB5CB1F0B8AAE4A9E9B233C7A52 | SHA256:2FC634B9BD505FE53F76E124ABF4979698391A1BAE375D8184AA3E82EC007304 | |||
| 3812 | OperaGXSetup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419 | der | |
MD5:6B012EAEA8987B727161EA89DC9591CB | SHA256:3F1A2F7616483D56F89611E3C85C30BACFB036435082AF208A5F5B89449258C6 | |||
| 3812 | OperaGXSetup.exe | C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\Crash Reports\settings.dat | binary | |
MD5:407D3E6C201AB2284F1F29D7C0A91CA7 | SHA256:7A8C6D1638875D8C9D87C9A8917A1633410BE154FFF68CB0B2E8E7327D036838 | |||
| 3812 | OperaGXSetup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419 | binary | |
MD5:D24F4DA8A59BF88BFDD7981314B339BE | SHA256:EA0891562A2CE80CFD94EC4C57F222356FE2186251BFF0816D94DE6884EF8AAE | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5832 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
2480 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
2480 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
3812 | OperaGXSetup.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D | unknown | — | — | whitelisted |
2120 | MoUsoCoreWorker.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
3812 | OperaGXSetup.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D | unknown | — | — | whitelisted |
3812 | OperaGXSetup.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnxLiz3Fu1WB6n1%2FE6xWn1b0jXiQQUdIWAwGbH3zfez70pN6oDHb7tzRcCEAfyOr5A1UWlCmQhXhy%2Bwwk%3D | unknown | — | — | whitelisted |
3812 | OperaGXSetup.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D | unknown | — | — | whitelisted |
6504 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
3812 | OperaGXSetup.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEA55q9FkBjzsPoBm2GCDxI4%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
6432 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2120 | MoUsoCoreWorker.exe | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3812 | OperaGXSetup.exe | 82.145.217.121:443 | desktop-netinstaller-sub.osp.opera.software | Opera Software AS | NO | whitelisted |
3812 | OperaGXSetup.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
3812 | OperaGXSetup.exe | 185.26.182.124:443 | autoupdate.geo.opera.com | Opera Software AS | — | whitelisted |
3812 | OperaGXSetup.exe | 185.26.182.118:443 | features.opera-api2.com | Opera Software AS | — | malicious |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
desktop-netinstaller-sub.osp.opera.software |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
autoupdate.geo.opera.com |
| whitelisted |
features.opera-api2.com |
| malicious |
api.config.opr.gg |
| unknown |
c.pki.goog |
| whitelisted |
download.opera.com |
| whitelisted |
Process | Message |
|---|---|
assistant_installer.exe | [1007/204646.686:INFO:assistant_installer_main.cc(169)] Running assistant installer with command line "C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202410072046111\assistant\assistant_installer.exe" --version
|