File name:

ExLoader_Installer.exe

Full analysis: https://app.any.run/tasks/98a8ab12-71ad-451b-91a4-88850e57fb85
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: January 25, 2025, 10:11:56
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
github
evasion
stealer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 6 sections
MD5:

1156779D6A1FE7ECA6F4F70B7E159280

SHA1:

DF0058C5E0B2B6696D25E49CAD5511A9D5FD9F08

SHA256:

BAB846B6030449F4C37AF32C8119FFE595B5A3D0D924D5E99370DD059BAC2767

SSDEEP:

6144:ifBPQHP3CafC0+QkISBCDGSnFJKbUMuvmC6WQoWdvJS:ifBPQHP3Ca6JQkISBCDGSFJ1M5CpwvJS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Adds path to the Windows Defender exclusion list

      • ExLoader_Installer.exe (PID: 520)
      • entityregularlytalk.exe (PID: 6872)
    • Steals credentials from Web Browsers

      • setup.exe (PID: 3208)
      • setup.exe (PID: 1612)
      • setup.exe (PID: 1080)
      • setup.exe (PID: 5752)
      • assistant_installer.exe (PID: 2456)
      • assistant_installer.exe (PID: 5488)
      • installer.exe (PID: 6004)
      • installer.exe (PID: 5192)
      • assistant_installer.exe (PID: 5640)
      • assistant_installer.exe (PID: 2124)
      • assistant_installer.exe (PID: 4244)
      • assistant_installer.exe (PID: 3984)
      • opera_crashreporter.exe (PID: 3000)
      • opera.exe (PID: 1172)
      • opera.exe (PID: 6328)
      • opera_crashreporter.exe (PID: 7104)
      • opera_crashreporter.exe (PID: 748)
      • opera_crashreporter.exe (PID: 6912)
      • opera.exe (PID: 5776)
      • opera.exe (PID: 6200)
      • opera_crashreporter.exe (PID: 7120)
      • browser_assistant.exe (PID: 6704)
      • browser_assistant.exe (PID: 4264)
      • opera.exe (PID: 6812)
      • opera.exe (PID: 5788)
      • opera_crashreporter.exe (PID: 3992)
      • opera.exe (PID: 5000)
      • opera_crashreporter.exe (PID: 6816)
      • opera.exe (PID: 540)
      • opera_crashreporter.exe (PID: 6372)
      • opera.exe (PID: 6284)
      • opera.exe (PID: 3744)
      • installer.exe (PID: 7424)
      • installer.exe (PID: 8188)
      • opera_autoupdate.exe (PID: 7852)
      • opera_autoupdate.exe (PID: 7440)
      • opera_autoupdate.exe (PID: 7976)
      • opera_autoupdate.exe (PID: 7460)
    • Actions looks like stealing of personal data

      • setup.exe (PID: 3208)
      • setup.exe (PID: 1612)
      • setup.exe (PID: 5752)
      • setup.exe (PID: 1080)
      • assistant_installer.exe (PID: 5488)
      • assistant_installer.exe (PID: 2456)
      • installer.exe (PID: 5192)
      • installer.exe (PID: 6004)
      • assistant_installer.exe (PID: 5640)
      • assistant_installer.exe (PID: 2124)
      • assistant_installer.exe (PID: 3984)
      • opera.exe (PID: 1172)
      • opera.exe (PID: 6328)
      • opera_crashreporter.exe (PID: 3000)
      • assistant_installer.exe (PID: 4244)
      • opera.exe (PID: 5776)
      • opera_crashreporter.exe (PID: 748)
      • browser_assistant.exe (PID: 4264)
      • opera_crashreporter.exe (PID: 7104)
      • opera.exe (PID: 5076)
      • opera.exe (PID: 7092)
      • opera.exe (PID: 6812)
      • opera_crashreporter.exe (PID: 6912)
      • browser_assistant.exe (PID: 6704)
      • opera.exe (PID: 6408)
      • opera.exe (PID: 6200)
      • opera_crashreporter.exe (PID: 7120)
      • opera.exe (PID: 5788)
      • opera.exe (PID: 5000)
      • opera_crashreporter.exe (PID: 6816)
      • opera_crashreporter.exe (PID: 3992)
      • opera_crashreporter.exe (PID: 6372)
      • opera.exe (PID: 3744)
      • opera.exe (PID: 540)
      • opera.exe (PID: 3040)
      • opera.exe (PID: 6284)
      • opera.exe (PID: 5268)
      • opera.exe (PID: 6392)
      • opera.exe (PID: 6828)
      • opera.exe (PID: 3656)
      • opera.exe (PID: 6900)
      • opera.exe (PID: 6596)
      • opera.exe (PID: 3420)
      • opera.exe (PID: 6840)
      • opera.exe (PID: 4320)
      • opera.exe (PID: 6360)
      • opera.exe (PID: 6904)
      • opera.exe (PID: 6332)
      • opera.exe (PID: 2928)
      • opera.exe (PID: 5568)
      • opera.exe (PID: 3080)
      • opera.exe (PID: 2324)
      • opera.exe (PID: 6932)
      • opera.exe (PID: 6916)
      • opera.exe (PID: 6648)
      • opera.exe (PID: 5652)
      • opera.exe (PID: 6236)
      • opera.exe (PID: 6016)
      • opera.exe (PID: 4136)
      • opera.exe (PID: 6180)
      • opera.exe (PID: 4392)
      • opera.exe (PID: 6388)
      • opera.exe (PID: 6572)
      • opera.exe (PID: 440)
      • opera.exe (PID: 7196)
      • opera.exe (PID: 7188)
      • opera.exe (PID: 1192)
      • opera.exe (PID: 7172)
      • opera.exe (PID: 7252)
      • opera.exe (PID: 6644)
      • opera.exe (PID: 7180)
      • opera.exe (PID: 5684)
      • opera.exe (PID: 7348)
      • opera.exe (PID: 7224)
      • installer.exe (PID: 8188)
      • installer.exe (PID: 7424)
      • opera_autoupdate.exe (PID: 7852)
      • opera_autoupdate.exe (PID: 7440)
      • opera_autoupdate.exe (PID: 7460)
      • opera.exe (PID: 7600)
      • opera.exe (PID: 7736)
      • opera.exe (PID: 7472)
      • opera.exe (PID: 6840)
      • opera.exe (PID: 7648)
      • opera.exe (PID: 1296)
      • opera_autoupdate.exe (PID: 7976)
      • opera.exe (PID: 7232)
      • opera.exe (PID: 7632)
      • opera.exe (PID: 7696)
      • opera.exe (PID: 7640)
      • opera.exe (PID: 7428)
      • opera.exe (PID: 7832)
      • opera.exe (PID: 7420)
      • opera.exe (PID: 6796)
      • opera.exe (PID: 8176)
      • opera.exe (PID: 2212)
      • opera.exe (PID: 3560)
      • opera.exe (PID: 7736)
      • opera.exe (PID: 7812)
    • Changes the autorun value in the registry

      • assistant_installer.exe (PID: 2124)
      • opera.exe (PID: 6328)
      • opera.exe (PID: 540)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 3532)
      • ExLoader_Installer.exe (PID: 520)
      • Assistant_116.0.5366.21_Setup.exe_sfx.exe (PID: 2148)
      • assistant_installer.exe (PID: 2124)
    • Starts POWERSHELL.EXE for commands execution

      • ExLoader_Installer.exe (PID: 520)
      • entityregularlytalk.exe (PID: 6872)
    • Script adds exclusion path to Windows Defender

      • ExLoader_Installer.exe (PID: 520)
      • entityregularlytalk.exe (PID: 6872)
    • Executable content was dropped or overwritten

      • ExLoader_Installer.exe (PID: 520)
      • OperaSetup.exe (PID: 1556)
      • setup.exe (PID: 1220)
      • setup.exe (PID: 3208)
      • setup.exe (PID: 1612)
      • setup.exe (PID: 5752)
      • setup.exe (PID: 1080)
      • ExLoader.exe (PID: 7156)
      • Assistant_116.0.5366.21_Setup.exe_sfx.exe (PID: 2148)
      • installer.exe (PID: 5192)
      • installer.exe (PID: 6004)
      • assistant_installer.exe (PID: 2124)
    • The process drops C-runtime libraries

      • ExLoader_Installer.exe (PID: 520)
    • Checks for external IP

      • ExLoader_Installer.exe (PID: 520)
      • svchost.exe (PID: 2192)
    • There is functionality for taking screenshot (YARA)

      • ExLoader_Installer.exe (PID: 520)
      • setup.exe (PID: 3208)
      • setup.exe (PID: 1612)
      • setup.exe (PID: 5752)
      • setup.exe (PID: 1080)
    • Connects to unusual port

      • ExLoader.exe (PID: 4864)
      • entityregularlytalk.exe (PID: 6872)
    • Application launched itself

      • setup.exe (PID: 3208)
      • setup.exe (PID: 5752)
      • assistant_installer.exe (PID: 5488)
      • installer.exe (PID: 5192)
      • assistant_installer.exe (PID: 2124)
      • assistant_installer.exe (PID: 3984)
      • browser_assistant.exe (PID: 4264)
      • opera.exe (PID: 6328)
      • opera.exe (PID: 540)
      • installer.exe (PID: 8188)
      • opera_autoupdate.exe (PID: 7440)
      • opera_autoupdate.exe (PID: 7460)
    • Reads security settings of Internet Explorer

      • setup.exe (PID: 3208)
      • installer.exe (PID: 5192)
      • browser_assistant.exe (PID: 4264)
    • Starts itself from another location

      • setup.exe (PID: 3208)
      • ExLoader.exe (PID: 7156)
    • Checks Windows Trust Settings

      • setup.exe (PID: 3208)
      • installer.exe (PID: 5192)
      • browser_assistant.exe (PID: 4264)
    • Reads the date of Windows installation

      • installer.exe (PID: 5192)
      • opera.exe (PID: 540)
    • Searches for installed software

      • browser_assistant.exe (PID: 4264)
      • installer.exe (PID: 5192)
    • Creates a software uninstall entry

      • installer.exe (PID: 5192)
    • Reads Mozilla Firefox installation path

      • opera.exe (PID: 540)
    • The process checks if it is being run in the virtual environment

      • opera.exe (PID: 540)
    • The process executes via Task Scheduler

      • opera_autoupdate.exe (PID: 7460)
  • INFO

    • Manual execution by a user

      • WinRAR.exe (PID: 3532)
      • ExLoader_Installer.exe (PID: 520)
      • ExLoader.exe (PID: 736)
      • ExLoader.exe (PID: 7156)
      • assistant_installer.exe (PID: 3984)
      • opera.exe (PID: 540)
    • The sample compiled with english language support

      • ExLoader_Installer.exe (PID: 6636)
      • WinRAR.exe (PID: 3532)
      • ExLoader_Installer.exe (PID: 520)
      • OperaSetup.exe (PID: 1556)
      • setup.exe (PID: 3208)
      • setup.exe (PID: 1612)
      • setup.exe (PID: 1220)
      • setup.exe (PID: 5752)
      • setup.exe (PID: 1080)
      • ExLoader.exe (PID: 7156)
      • Assistant_116.0.5366.21_Setup.exe_sfx.exe (PID: 2148)
      • installer.exe (PID: 6004)
      • installer.exe (PID: 5192)
      • assistant_installer.exe (PID: 2124)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3532)
    • Reads the computer name

      • ExLoader_Installer.exe (PID: 520)
      • ExLoader.exe (PID: 4864)
      • setup.exe (PID: 3208)
      • setup.exe (PID: 5752)
      • ExLoader.exe (PID: 7156)
      • entityregularlytalk.exe (PID: 6872)
      • assistant_installer.exe (PID: 5488)
      • installer.exe (PID: 5192)
      • assistant_installer.exe (PID: 2124)
      • assistant_installer.exe (PID: 3984)
      • opera.exe (PID: 6328)
      • opera.exe (PID: 1172)
      • browser_assistant.exe (PID: 4264)
      • opera.exe (PID: 5776)
      • opera.exe (PID: 5076)
      • opera.exe (PID: 6812)
      • opera.exe (PID: 7092)
      • opera.exe (PID: 6200)
      • opera.exe (PID: 5788)
      • opera.exe (PID: 5000)
      • opera.exe (PID: 540)
      • opera.exe (PID: 3040)
      • opera.exe (PID: 3744)
      • opera_gx_splash.exe (PID: 5040)
      • opera.exe (PID: 3080)
      • opera.exe (PID: 6572)
      • installer.exe (PID: 8188)
      • opera_autoupdate.exe (PID: 7460)
      • opera_autoupdate.exe (PID: 7440)
    • Checks supported languages

      • ExLoader_Installer.exe (PID: 520)
      • ExLoader.exe (PID: 4864)
      • OperaSetup.exe (PID: 1556)
      • setup.exe (PID: 3208)
      • setup.exe (PID: 1220)
      • setup.exe (PID: 5752)
      • setup.exe (PID: 1612)
      • setup.exe (PID: 1080)
      • ExLoader.exe (PID: 7156)
      • entityregularlytalk.exe (PID: 6872)
      • assistant_installer.exe (PID: 2456)
      • assistant_installer.exe (PID: 5488)
      • Assistant_116.0.5366.21_Setup.exe_sfx.exe (PID: 2148)
      • installer.exe (PID: 6004)
      • installer.exe (PID: 5192)
      • assistant_installer.exe (PID: 2124)
      • assistant_installer.exe (PID: 5640)
      • assistant_installer.exe (PID: 3984)
      • opera.exe (PID: 1172)
      • browser_assistant.exe (PID: 4264)
      • opera.exe (PID: 6328)
      • opera_crashreporter.exe (PID: 3000)
      • opera_crashreporter.exe (PID: 748)
      • assistant_installer.exe (PID: 4244)
      • browser_assistant.exe (PID: 6704)
      • opera.exe (PID: 5776)
      • opera_crashreporter.exe (PID: 7104)
      • opera.exe (PID: 5076)
      • opera.exe (PID: 7092)
      • opera.exe (PID: 6812)
      • opera_crashreporter.exe (PID: 6912)
      • opera.exe (PID: 6408)
      • opera.exe (PID: 6200)
      • opera_crashreporter.exe (PID: 7120)
      • opera.exe (PID: 5000)
      • opera.exe (PID: 5788)
      • opera_crashreporter.exe (PID: 3992)
      • opera.exe (PID: 540)
      • opera_crashreporter.exe (PID: 6816)
      • opera_crashreporter.exe (PID: 6372)
      • opera.exe (PID: 3744)
      • opera.exe (PID: 3040)
      • opera.exe (PID: 6284)
      • opera.exe (PID: 5268)
      • opera.exe (PID: 6840)
      • opera.exe (PID: 6392)
      • opera.exe (PID: 6828)
      • opera.exe (PID: 6900)
      • opera.exe (PID: 6596)
      • opera.exe (PID: 3420)
      • opera.exe (PID: 3656)
      • opera_gx_splash.exe (PID: 5040)
      • opera.exe (PID: 4320)
      • opera.exe (PID: 6904)
      • opera.exe (PID: 6332)
      • opera.exe (PID: 2928)
      • opera.exe (PID: 6360)
      • opera.exe (PID: 5568)
      • opera.exe (PID: 4136)
      • opera.exe (PID: 5652)
      • opera.exe (PID: 6644)
      • opera.exe (PID: 6180)
      • opera.exe (PID: 6648)
      • opera.exe (PID: 1192)
      • opera.exe (PID: 4392)
      • opera.exe (PID: 3080)
      • opera.exe (PID: 6932)
      • opera.exe (PID: 2324)
      • opera.exe (PID: 7196)
      • opera.exe (PID: 6916)
      • opera.exe (PID: 6236)
      • opera.exe (PID: 6016)
      • opera.exe (PID: 5684)
      • opera.exe (PID: 6388)
      • opera.exe (PID: 440)
      • opera.exe (PID: 7188)
      • opera.exe (PID: 7252)
      • opera.exe (PID: 7172)
      • opera.exe (PID: 7180)
      • installer.exe (PID: 8188)
      • installer.exe (PID: 7424)
      • opera.exe (PID: 7224)
      • opera.exe (PID: 6572)
      • opera.exe (PID: 7348)
      • opera_autoupdate.exe (PID: 7460)
      • opera_autoupdate.exe (PID: 7976)
      • opera_autoupdate.exe (PID: 7440)
      • opera_autoupdate.exe (PID: 7852)
      • opera.exe (PID: 7600)
      • opera.exe (PID: 7736)
      • opera.exe (PID: 7472)
      • opera.exe (PID: 7648)
      • opera.exe (PID: 1296)
      • opera.exe (PID: 6840)
      • opera.exe (PID: 6796)
      • opera.exe (PID: 7232)
      • opera.exe (PID: 7696)
      • opera.exe (PID: 7632)
      • opera.exe (PID: 7640)
      • opera.exe (PID: 7428)
      • opera.exe (PID: 7832)
      • opera.exe (PID: 7420)
      • opera.exe (PID: 7812)
      • opera.exe (PID: 3560)
      • opera.exe (PID: 7736)
      • opera.exe (PID: 8176)
      • opera.exe (PID: 2212)
    • Process checks computer location settings

      • ExLoader_Installer.exe (PID: 520)
      • ExLoader.exe (PID: 4864)
      • entityregularlytalk.exe (PID: 6872)
      • opera.exe (PID: 6328)
      • opera.exe (PID: 540)
      • opera.exe (PID: 6392)
      • opera.exe (PID: 6360)
      • opera.exe (PID: 4320)
      • opera.exe (PID: 6904)
      • opera.exe (PID: 2928)
      • opera.exe (PID: 5568)
      • opera.exe (PID: 6332)
      • opera.exe (PID: 4136)
      • opera.exe (PID: 5652)
      • opera.exe (PID: 7188)
      • opera.exe (PID: 7600)
      • opera.exe (PID: 7696)
      • opera.exe (PID: 7640)
      • opera.exe (PID: 7736)
    • Creates files in the program directory

      • ExLoader_Installer.exe (PID: 520)
      • ExLoader.exe (PID: 7156)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 2160)
      • powershell.exe (PID: 720)
      • powershell.exe (PID: 7120)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 2160)
      • powershell.exe (PID: 720)
      • powershell.exe (PID: 7120)
    • Reads the software policy settings

      • powershell.exe (PID: 7112)
      • setup.exe (PID: 3208)
      • installer.exe (PID: 5192)
      • browser_assistant.exe (PID: 4264)
    • Create files in a temporary directory

      • powershell.exe (PID: 7112)
      • ExLoader_Installer.exe (PID: 520)
      • setup.exe (PID: 3208)
      • OperaSetup.exe (PID: 1556)
      • setup.exe (PID: 1612)
      • setup.exe (PID: 1220)
      • setup.exe (PID: 5752)
      • setup.exe (PID: 1080)
      • entityregularlytalk.exe (PID: 6872)
      • Assistant_116.0.5366.21_Setup.exe_sfx.exe (PID: 2148)
      • installer.exe (PID: 6004)
      • installer.exe (PID: 5192)
      • opera.exe (PID: 540)
      • installer.exe (PID: 8188)
      • installer.exe (PID: 7424)
    • Reads security settings of Internet Explorer

      • powershell.exe (PID: 7112)
    • Creates files or folders in the user directory

      • setup.exe (PID: 3208)
      • setup.exe (PID: 1612)
      • ExLoader.exe (PID: 7156)
      • entityregularlytalk.exe (PID: 6872)
      • setup.exe (PID: 5752)
      • installer.exe (PID: 5192)
      • assistant_installer.exe (PID: 2124)
      • opera.exe (PID: 6328)
      • browser_assistant.exe (PID: 4264)
      • opera.exe (PID: 540)
      • opera.exe (PID: 3744)
      • opera_autoupdate.exe (PID: 7440)
      • opera_autoupdate.exe (PID: 7852)
    • Reads the machine GUID from the registry

      • setup.exe (PID: 3208)
      • installer.exe (PID: 5192)
      • opera.exe (PID: 6328)
      • opera.exe (PID: 540)
      • browser_assistant.exe (PID: 4264)
      • opera_autoupdate.exe (PID: 7852)
      • opera_autoupdate.exe (PID: 7460)
      • opera_autoupdate.exe (PID: 7440)
      • opera_autoupdate.exe (PID: 7976)
    • Checks proxy server information

      • setup.exe (PID: 3208)
      • opera.exe (PID: 6328)
      • browser_assistant.exe (PID: 4264)
      • opera.exe (PID: 540)
      • opera_autoupdate.exe (PID: 7440)
    • Reads product name

      • entityregularlytalk.exe (PID: 6872)
    • Reads Environment values

      • entityregularlytalk.exe (PID: 6872)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:12:02 19:33:14+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.41
CodeSize: 51712
InitializedDataSize: 137728
UninitializedDataSize: -
EntryPoint: 0xc704
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.8.0.1560
ProductVersionNumber: 1.8.0.1560
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: com.swiftsoft
FileDescription: Installer for unified library of game modifications.
FileVersion: 1.8.0+1560
InternalName: ExLoader_Installer
LegalCopyright: Copyright (C) 2018-2023 SwiftSoft LLC. All rights reserved.
OriginalFileName: ExLoader_Installer.exe
ProductName: ExLoader_Installer
ProductVersion: 1.8.0+1560
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
260
Monitored processes
125
Malicious processes
40
Suspicious processes
66

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
440"C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --enable-quic --with-feature:cashback-assistant=on --with-feature:address-bar-dropdown-autocompleted-domains=on --with-feature:address-bar-dropdown-cities=on --with-feature:address-bar-keywords-monetization=on --with-feature:amazon-bookmarks-tags-update=on --with-feature:amazon-new-ids=on --with-feature:amp-requests-stats=on --with-feature:cashback-assistant=on --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-cms-configuration=on --with-feature:continue-shopping-explore=off --with-feature:continue-shopping-structured-partners=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:hide-navigations-from-extensions=on --with-feature:lucid-mode-hide-text=on --with-feature:native-crypto-wallet=on --with-feature:opera-startpage-special=on --with-feature:password-generator=off --with-feature:proxy-switcher-ui-default-visible=on --with-feature:realtime-impressions-reporting=on --with-feature:sd-suggestions-external=on --with-feature:session-restore-attribution=on --with-feature:shopping-corner=on --with-feature:sitecheck-age=on --with-feature:specific-keywords=on --with-feature:startpage-content-phase-1=off --with-feature:startpage-opening-animation=off --with-feature:startpage-sync-banner=on --with-feature:installer-experiment-test=off --field-trial-handle=7308,i,6365659688116433013,6831268219785054100,262144 --disable-features=CertificateTransparencyAskBeforeEnabling,PlatformSoftwareH264EncoderInGpu --variations-seed-version --mojo-platform-channel-handle=8896 /prefetch:8C:\Users\admin\AppData\Local\Programs\Opera\opera.exe
opera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Exit code:
0
Version:
116.0.5366.51
520"C:\Users\admin\Desktop\Ex\ExLoader_Installer.exe" C:\Users\admin\Desktop\Ex\ExLoader_Installer.exe
explorer.exe
User:
admin
Company:
com.swiftsoft
Integrity Level:
HIGH
Description:
Installer for unified library of game modifications.
Exit code:
0
Version:
1.8.0+1560
Modules
Images
c:\users\admin\desktop\ex\exloader_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\dwmapi.dll
540"C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --show-intro-overlay --start-maximized --lowered-browserC:\Users\admin\AppData\Local\Programs\Opera\opera.exe
explorer.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera Internet Browser
Version:
116.0.5366.51
Modules
Images
c:\users\admin\appdata\local\programs\opera\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
720C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe -command Add-MpPreference -ExclusionPath "\"C:\Users\admin\AppData\Local\Temp\""C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeExLoader_Installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
736"C:\Program Files\ExLoader\ExLoader.exe" C:\Program Files\ExLoader\ExLoader.exeexplorer.exe
User:
admin
Company:
com.swiftsoft
Integrity Level:
MEDIUM
Description:
Unified library of game modifications.
Exit code:
3221226540
Version:
3.5.108+1560
Modules
Images
c:\program files\exloader\exloader.exe
c:\windows\system32\ntdll.dll
748C:\Users\admin\AppData\Local\Programs\Opera\116.0.5366.51\opera_crashreporter.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win64 --annotation=prod=OperaDesktop --annotation=ver=116.0.5366.51 --initial-client-data=0x2a0,0x2a4,0x2a8,0x29c,0x2ac,0x7ff814d5f658,0x7ff814d5f668,0x7ff814d5f678C:\Users\admin\AppData\Local\Programs\Opera\116.0.5366.51\opera_crashreporter.exe
opera.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera crash-reporter
Exit code:
0
Version:
116.0.5366.51
Modules
Images
c:\users\admin\appdata\local\programs\opera\116.0.5366.51\opera_crashreporter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1080C:\Users\admin\AppData\Local\Temp\7zS416A1CB4\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktop --annotation=ver=116.0.5366.51 --initial-client-data=0x334,0x338,0x33c,0x330,0x340,0x730ccf5c,0x730ccf68,0x730ccf74C:\Users\admin\AppData\Local\Temp\7zS416A1CB4\setup.exe
setup.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera Installer
Exit code:
0
Version:
116.0.5366.51
Modules
Images
c:\users\admin\appdata\local\temp\7zs416a1cb4\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
1172"C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --streamC:\Users\admin\AppData\Local\Programs\Opera\opera.exe
browser_assistant.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera Internet Browser
Exit code:
0
Version:
116.0.5366.51
Modules
Images
c:\users\admin\appdata\local\programs\opera\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1192"C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --enable-quic --with-feature:cashback-assistant=on --with-feature:address-bar-dropdown-autocompleted-domains=on --with-feature:address-bar-dropdown-cities=on --with-feature:address-bar-keywords-monetization=on --with-feature:amazon-bookmarks-tags-update=on --with-feature:amazon-new-ids=on --with-feature:amp-requests-stats=on --with-feature:cashback-assistant=on --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-cms-configuration=on --with-feature:continue-shopping-explore=off --with-feature:continue-shopping-structured-partners=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:hide-navigations-from-extensions=on --with-feature:lucid-mode-hide-text=on --with-feature:native-crypto-wallet=on --with-feature:opera-startpage-special=on --with-feature:password-generator=off --with-feature:proxy-switcher-ui-default-visible=on --with-feature:realtime-impressions-reporting=on --with-feature:sd-suggestions-external=on --with-feature:session-restore-attribution=on --with-feature:shopping-corner=on --with-feature:sitecheck-age=on --with-feature:specific-keywords=on --with-feature:startpage-content-phase-1=off --with-feature:startpage-opening-animation=off --with-feature:startpage-sync-banner=on --with-feature:installer-experiment-test=off --field-trial-handle=7296,i,6365659688116433013,6831268219785054100,262144 --disable-features=CertificateTransparencyAskBeforeEnabling,PlatformSoftwareH264EncoderInGpu --variations-seed-version --mojo-platform-channel-handle=8756 /prefetch:8C:\Users\admin\AppData\Local\Programs\Opera\opera.exe
opera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Exit code:
0
Version:
116.0.5366.51
1220"C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exe" --versionC:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exe
setup.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera Installer
Exit code:
0
Version:
116.0.5366.51
Modules
Images
c:\users\admin\appdata\local\temp\.opera\opera installer temp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
Total events
194 165
Read events
193 947
Write events
204
Delete events
14

Modification events

(PID) Process:(3532) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(3532) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(3532) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(3532) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Ex.rar
(PID) Process:(3532) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3532) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3532) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3532) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3532) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFD9FFFFFF270000009903000010020000
(PID) Process:(3532) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
Executable files
113
Suspicious files
358
Text files
655
Unknown types
0

Dropped files

PID
Process
Filename
Type
3532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3532.27657\Ex\data\app.so
MD5:
SHA256:
3532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3532.27657\Ex\api-ms-win-crt-runtime-l1-1-0.dllexecutable
MD5:F1A23C251FCBB7041496352EC9BCFFBE
SHA256:D899C2F061952B3B97AB9CDBCA2450290B0F005909DDD243ED0F4C511D32C198
3532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3532.27657\Ex\data\flutter_assets\AssetManifest.binbinary
MD5:E6EE07A908803B70DCDF31271BBC05BC
SHA256:5BC7D9A70129040CB1A99067D26A8A74F1679B345AE7E7FBD6C71D26A97E2688
3532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3532.27657\Ex\data\flutter_assets\fonts\MaterialIcons-Regular.otfbinary
MD5:E7069DFD19B331BE16BED984668FE080
SHA256:D9865B671A09D683D13A863089D8825E0F61A37696CE5D7D448BC8023AA62453
3532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3532.27657\Ex\data\flutter_assets\resources\audio\AbominationPissed_EN.wavbinary
MD5:04DE7B1FD5D0FCE157B378EBEDE59DF1
SHA256:3939FCAA3B0EFD6D601DA475ABEA862D9F7C078643F1063DF51C83609CF47A6F
3532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3532.27657\Ex\data\flutter_assets\resources\audio\AbominationPissed_DE.wavbinary
MD5:B287FCC8278972FF72B8E46B481C4AB7
SHA256:C87CB5C9C64B5798769AF14563E268080ED82C7C8A1958F6FA1C1B5E7F10D2E2
3532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3532.27657\Ex\data\flutter_assets\NOTICES.Zcompressed
MD5:91408E65C3243B8EED6C8E8D991A1D82
SHA256:6873CC4CA1A29FD50EA191B9E54C1CD90EBD701C2CFEBD1E62A619D867ACF332
3532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3532.27657\Ex\data\flutter_assets\resources\audio\CSGO_press.wavbinary
MD5:5CF6F422F37B61B16F732E177C4A67CE
SHA256:880CC2BE6F458BF853DBA78CAF06BD2B97BC4B06FEA141599DB74E95BBD59528
3532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3532.27657\Ex\data\flutter_assets\resources\audio\CSGO_hover.wavbinary
MD5:8D6E22BDE35607FE3801E02FDB12B022
SHA256:AAA3F0F824D04CE5E93D1DA17873D3AEB3C4D3A8FEE25B7006851E4089BFADFC
3532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3532.27657\Ex\data\flutter_assets\resources\audio\Fortnite_hover.wavbinary
MD5:B66B7D55B6EEB2FF344A1AF41E42A27F
SHA256:3E3ABB7E29D38FA4B0261AC78427633E8BF6DDF3708DE5A45BBDDDC2A9F4AA6B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
15
TCP/UDP connections
241
DNS requests
134
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3208
setup.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
DE
binary
471 b
whitelisted
3208
setup.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
DE
binary
471 b
whitelisted
3208
setup.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAfy81yHqHeveu%2FpR5k1Jb0%3D
DE
binary
471 b
whitelisted
3208
setup.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
DE
binary
727 b
whitelisted
GET
301
213.180.193.146:80
http://213.180.193.146:80/showcaptcha?cc=1&mt=8B85382F957975F7F63F6BB423C6D479FA4DE4BAC8BB5E200C988C171092D40D853FD1E26FC385B8A27F309B6F2E70729CD2365BF126140E00CDF3F19876CC63559272E8EA4511B10222E1DFB8FB4427E297B6D112D537D2DE65DB7D60B5CE8960F3ACF9424E2F725E7331B60707B7D4ABD0DA008C87DF88D48F36589D167174D6CC82B1288941D9F50F54691413726112D5C32B1FDF376DBE5E2F1576ED5402955FDADBD150EE07B585365BF0EEE3B00EA28932F0B8C7F9451239A18B568C065ACD4DAE88BE2E3401A264E4E590E2D30B9A71E3E41C1E7AF10F9BA9144FCC&retpath=aHR0cDovL21ldGV1bS5haS93ZWF0aGVyL2VuLVVTPw%2C%2C_37cdc70ea8d918bf6564984569b16920&t=2/1737800175/bdf1d27da0554419863ea7a42d75b096&u=5941331168243627980&s=10679c1b3058b575b818c844d0fc7d85
RU
whitelisted
3208
setup.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAkd76%2BHl%2BdEje5x5DkdF8w%3D
DE
binary
727 b
whitelisted
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
1.01 Kb
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
DE
binary
313 b
whitelisted
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
973 b
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5064
SearchApp.exe
2.16.110.155:443
www.bing.com
Akamai International B.V.
DE
whitelisted
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.52.120.96:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
4712
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3584
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
20.190.159.23:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
  • 20.73.194.208
whitelisted
www.bing.com
  • 2.16.110.155
  • 2.16.110.171
  • 2.16.110.146
  • 2.16.110.131
  • 2.16.110.179
  • 2.16.110.176
  • 2.16.110.163
  • 2.16.110.162
  • 2.16.110.153
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 23.52.120.96
whitelisted
google.com
  • 142.250.185.174
whitelisted
ocsp.digicert.com
  • 2.17.190.73
  • 2.23.77.188
whitelisted
login.live.com
  • 20.190.159.23
  • 40.126.31.67
  • 20.190.159.75
  • 40.126.31.69
  • 20.190.159.71
  • 20.190.159.4
  • 40.126.31.73
  • 40.126.31.71
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
arc.msn.com
  • 20.74.47.205
whitelisted
fd.api.iris.microsoft.com
  • 20.199.58.43
whitelisted

Threats

PID
Process
Class
Message
2192
svchost.exe
Misc activity
ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup
520
ExLoader_Installer.exe
Misc activity
ET INFO External IP Address Lookup Domain (ipify .org) in TLS SNI
2192
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
2192
svchost.exe
Misc activity
ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup
2192
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
2192
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain (ipapi .co in DNS lookup)
2192
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain (ipapi .co in DNS lookup)
Process
Message
assistant_installer.exe
[0125/101415.073:INFO:assistant_installer_main.cc(168)] Running assistant installer with command line "C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202501251013311\assistant\assistant_installer.exe" --version
assistant_installer.exe
[0125/101448.064:INFO:assistant_installer_main.cc(168)] Running assistant installer with command line "C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202501251013311\assistant\assistant_installer.exe" --installfolder="C:\Users\admin\AppData\Local\Programs\Opera\assistant" --copyonly=0 --allusers=0
assistant_installer.exe
[0125/101448.200:INFO:assistant_installer.cc(306)] Setting up the registry
assistant_installer.exe
[0125/101448.332:INFO:assistant_installer.cc(357)] Creating scheduled task
assistant_installer.exe
[0125/101448.436:INFO:assistant_installer.cc(265)] Running Assistant
assistant_installer.exe
[0125/101448.436:INFO:assistant_installer_main.cc(168)] Running assistant installer with command line "C:\Users\admin\AppData\Local\Programs\Opera\assistant\assistant_installer.exe" --installfolder="C:\Users\admin\AppData\Local\Programs\Opera\assistant" --run-assistant --allusers=0
browser_assistant.exe
[0125/101453.000:ERROR:tracking_data_utils.cc(72)] Can't read edition: missing value.
browser_assistant.exe
[0125/101453.858:INFO:browser_installation_event_reporter.cc(144)] Chrome
browser_assistant.exe
[0125/101453.858:INFO:browser_installation_event_reporter.cc(142)] Installed browsers:
browser_assistant.exe
[0125/101453.858:INFO:browser_installation_event_reporter.cc(144)] Firefox