ANY.RUN Interactive Sandbox
- Full browser-level visibility into phishing
- Huge database of samples and IOCs
- Interactivity in a safe environment
- Actionable Tier 1 reports
Get full visibility into malware and phishing behavior in a safe environment.
| File name: | ExLoader_Installer.exe |
| Full analysis: | https://app.any.run/tasks/98a8ab12-71ad-451b-91a4-88850e57fb85 |
| Verdict: | Malicious activity |
| Threats: | Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns. |
| Analysis date: | January 25, 2025, 10:11:56 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32+ executable (GUI) x86-64, for MS Windows, 6 sections |
| MD5: | 1156779D6A1FE7ECA6F4F70B7E159280 |
| SHA1: | DF0058C5E0B2B6696D25E49CAD5511A9D5FD9F08 |
| SHA256: | BAB846B6030449F4C37AF32C8119FFE595B5A3D0D924D5E99370DD059BAC2767 |
| SSDEEP: | 6144:ifBPQHP3CafC0+QkISBCDGSnFJKbUMuvmC6WQoWdvJS:ifBPQHP3Ca6JQkISBCDGSFJ1M5CpwvJS |
| .exe | | | Win64 Executable (generic) (87.3) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (6.3) |
| .exe | | | DOS Executable Generic (6.3) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2024:12:02 19:33:14+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32+ |
| LinkerVersion: | 14.41 |
| CodeSize: | 51712 |
| InitializedDataSize: | 137728 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xc704 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.8.0.1560 |
| ProductVersionNumber: | 1.8.0.1560 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | com.swiftsoft |
| FileDescription: | Installer for unified library of game modifications. |
| FileVersion: | 1.8.0+1560 |
| InternalName: | ExLoader_Installer |
| LegalCopyright: | Copyright (C) 2018-2023 SwiftSoft LLC. All rights reserved. |
| OriginalFileName: | ExLoader_Installer.exe |
| ProductName: | ExLoader_Installer |
| ProductVersion: | 1.8.0+1560 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 440 | "C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --enable-quic --with-feature:cashback-assistant=on --with-feature:address-bar-dropdown-autocompleted-domains=on --with-feature:address-bar-dropdown-cities=on --with-feature:address-bar-keywords-monetization=on --with-feature:amazon-bookmarks-tags-update=on --with-feature:amazon-new-ids=on --with-feature:amp-requests-stats=on --with-feature:cashback-assistant=on --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-cms-configuration=on --with-feature:continue-shopping-explore=off --with-feature:continue-shopping-structured-partners=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:hide-navigations-from-extensions=on --with-feature:lucid-mode-hide-text=on --with-feature:native-crypto-wallet=on --with-feature:opera-startpage-special=on --with-feature:password-generator=off --with-feature:proxy-switcher-ui-default-visible=on --with-feature:realtime-impressions-reporting=on --with-feature:sd-suggestions-external=on --with-feature:session-restore-attribution=on --with-feature:shopping-corner=on --with-feature:sitecheck-age=on --with-feature:specific-keywords=on --with-feature:startpage-content-phase-1=off --with-feature:startpage-opening-animation=off --with-feature:startpage-sync-banner=on --with-feature:installer-experiment-test=off --field-trial-handle=7308,i,6365659688116433013,6831268219785054100,262144 --disable-features=CertificateTransparencyAskBeforeEnabling,PlatformSoftwareH264EncoderInGpu --variations-seed-version --mojo-platform-channel-handle=8896 /prefetch:8 | C:\Users\admin\AppData\Local\Programs\Opera\opera.exe | opera.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: LOW Description: Opera Internet Browser Exit code: 0 Version: 116.0.5366.51 | |||||||||||||||
| 520 | "C:\Users\admin\Desktop\Ex\ExLoader_Installer.exe" | C:\Users\admin\Desktop\Ex\ExLoader_Installer.exe | explorer.exe | ||||||||||||
User: admin Company: com.swiftsoft Integrity Level: HIGH Description: Installer for unified library of game modifications. Exit code: 0 Version: 1.8.0+1560 Modules
| |||||||||||||||
| 540 | "C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --show-intro-overlay --start-maximized --lowered-browser | C:\Users\admin\AppData\Local\Programs\Opera\opera.exe | explorer.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera Internet Browser Version: 116.0.5366.51 Modules
| |||||||||||||||
| 720 | C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe -command Add-MpPreference -ExclusionPath "\"C:\Users\admin\AppData\Local\Temp\"" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | ExLoader_Installer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 736 | "C:\Program Files\ExLoader\ExLoader.exe" | C:\Program Files\ExLoader\ExLoader.exe | — | explorer.exe | |||||||||||
User: admin Company: com.swiftsoft Integrity Level: MEDIUM Description: Unified library of game modifications. Exit code: 3221226540 Version: 3.5.108+1560 Modules
| |||||||||||||||
| 748 | C:\Users\admin\AppData\Local\Programs\Opera\116.0.5366.51\opera_crashreporter.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win64 --annotation=prod=OperaDesktop --annotation=ver=116.0.5366.51 --initial-client-data=0x2a0,0x2a4,0x2a8,0x29c,0x2ac,0x7ff814d5f658,0x7ff814d5f668,0x7ff814d5f678 | C:\Users\admin\AppData\Local\Programs\Opera\116.0.5366.51\opera_crashreporter.exe | opera.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: HIGH Description: Opera crash-reporter Exit code: 0 Version: 116.0.5366.51 Modules
| |||||||||||||||
| 1080 | C:\Users\admin\AppData\Local\Temp\7zS416A1CB4\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktop --annotation=ver=116.0.5366.51 --initial-client-data=0x334,0x338,0x33c,0x330,0x340,0x730ccf5c,0x730ccf68,0x730ccf74 | C:\Users\admin\AppData\Local\Temp\7zS416A1CB4\setup.exe | setup.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: HIGH Description: Opera Installer Exit code: 0 Version: 116.0.5366.51 Modules
| |||||||||||||||
| 1172 | "C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --stream | C:\Users\admin\AppData\Local\Programs\Opera\opera.exe | browser_assistant.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera Internet Browser Exit code: 0 Version: 116.0.5366.51 Modules
| |||||||||||||||
| 1192 | "C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --enable-quic --with-feature:cashback-assistant=on --with-feature:address-bar-dropdown-autocompleted-domains=on --with-feature:address-bar-dropdown-cities=on --with-feature:address-bar-keywords-monetization=on --with-feature:amazon-bookmarks-tags-update=on --with-feature:amazon-new-ids=on --with-feature:amp-requests-stats=on --with-feature:cashback-assistant=on --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-cms-configuration=on --with-feature:continue-shopping-explore=off --with-feature:continue-shopping-structured-partners=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:hide-navigations-from-extensions=on --with-feature:lucid-mode-hide-text=on --with-feature:native-crypto-wallet=on --with-feature:opera-startpage-special=on --with-feature:password-generator=off --with-feature:proxy-switcher-ui-default-visible=on --with-feature:realtime-impressions-reporting=on --with-feature:sd-suggestions-external=on --with-feature:session-restore-attribution=on --with-feature:shopping-corner=on --with-feature:sitecheck-age=on --with-feature:specific-keywords=on --with-feature:startpage-content-phase-1=off --with-feature:startpage-opening-animation=off --with-feature:startpage-sync-banner=on --with-feature:installer-experiment-test=off --field-trial-handle=7296,i,6365659688116433013,6831268219785054100,262144 --disable-features=CertificateTransparencyAskBeforeEnabling,PlatformSoftwareH264EncoderInGpu --variations-seed-version --mojo-platform-channel-handle=8756 /prefetch:8 | C:\Users\admin\AppData\Local\Programs\Opera\opera.exe | opera.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: LOW Description: Opera Internet Browser Exit code: 0 Version: 116.0.5366.51 | |||||||||||||||
| 1220 | "C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exe" --version | C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exe | setup.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: HIGH Description: Opera Installer Exit code: 0 Version: 116.0.5366.51 Modules
| |||||||||||||||
| (PID) Process: | (3532) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (3532) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (3532) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (3532) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\Ex.rar | |||
| (PID) Process: | (3532) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3532) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3532) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3532) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3532) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFD9FFFFFF270000009903000010020000 | |||
| (PID) Process: | (3532) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths |
| Operation: | write | Name: | name |
Value: 256 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3532 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3532.27657\Ex\data\app.so | — | |
MD5:— | SHA256:— | |||
| 3532 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3532.27657\Ex\api-ms-win-crt-runtime-l1-1-0.dll | executable | |
MD5:F1A23C251FCBB7041496352EC9BCFFBE | SHA256:D899C2F061952B3B97AB9CDBCA2450290B0F005909DDD243ED0F4C511D32C198 | |||
| 3532 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3532.27657\Ex\data\flutter_assets\AssetManifest.bin | binary | |
MD5:E6EE07A908803B70DCDF31271BBC05BC | SHA256:5BC7D9A70129040CB1A99067D26A8A74F1679B345AE7E7FBD6C71D26A97E2688 | |||
| 3532 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3532.27657\Ex\data\flutter_assets\fonts\MaterialIcons-Regular.otf | binary | |
MD5:E7069DFD19B331BE16BED984668FE080 | SHA256:D9865B671A09D683D13A863089D8825E0F61A37696CE5D7D448BC8023AA62453 | |||
| 3532 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3532.27657\Ex\data\flutter_assets\resources\audio\AbominationPissed_EN.wav | binary | |
MD5:04DE7B1FD5D0FCE157B378EBEDE59DF1 | SHA256:3939FCAA3B0EFD6D601DA475ABEA862D9F7C078643F1063DF51C83609CF47A6F | |||
| 3532 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3532.27657\Ex\data\flutter_assets\resources\audio\AbominationPissed_DE.wav | binary | |
MD5:B287FCC8278972FF72B8E46B481C4AB7 | SHA256:C87CB5C9C64B5798769AF14563E268080ED82C7C8A1958F6FA1C1B5E7F10D2E2 | |||
| 3532 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3532.27657\Ex\data\flutter_assets\NOTICES.Z | compressed | |
MD5:91408E65C3243B8EED6C8E8D991A1D82 | SHA256:6873CC4CA1A29FD50EA191B9E54C1CD90EBD701C2CFEBD1E62A619D867ACF332 | |||
| 3532 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3532.27657\Ex\data\flutter_assets\resources\audio\CSGO_press.wav | binary | |
MD5:5CF6F422F37B61B16F732E177C4A67CE | SHA256:880CC2BE6F458BF853DBA78CAF06BD2B97BC4B06FEA141599DB74E95BBD59528 | |||
| 3532 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3532.27657\Ex\data\flutter_assets\resources\audio\CSGO_hover.wav | binary | |
MD5:8D6E22BDE35607FE3801E02FDB12B022 | SHA256:AAA3F0F824D04CE5E93D1DA17873D3AEB3C4D3A8FEE25B7006851E4089BFADFC | |||
| 3532 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3532.27657\Ex\data\flutter_assets\resources\audio\Fortnite_hover.wav | binary | |
MD5:B66B7D55B6EEB2FF344A1AF41E42A27F | SHA256:3E3ABB7E29D38FA4B0261AC78427633E8BF6DDF3708DE5A45BBDDDC2A9F4AA6B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3208 | setup.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D | DE | binary | 471 b | whitelisted |
3208 | setup.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D | DE | binary | 471 b | whitelisted |
3208 | setup.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAfy81yHqHeveu%2FpR5k1Jb0%3D | DE | binary | 471 b | whitelisted |
3208 | setup.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D | DE | binary | 727 b | whitelisted |
— | — | GET | 301 | 213.180.193.146:80 | http://213.180.193.146:80/showcaptcha?cc=1&mt=8B85382F957975F7F63F6BB423C6D479FA4DE4BAC8BB5E200C988C171092D40D853FD1E26FC385B8A27F309B6F2E70729CD2365BF126140E00CDF3F19876CC63559272E8EA4511B10222E1DFB8FB4427E297B6D112D537D2DE65DB7D60B5CE8960F3ACF9424E2F725E7331B60707B7D4ABD0DA008C87DF88D48F36589D167174D6CC82B1288941D9F50F54691413726112D5C32B1FDF376DBE5E2F1576ED5402955FDADBD150EE07B585365BF0EEE3B00EA28932F0B8C7F9451239A18B568C065ACD4DAE88BE2E3401A264E4E590E2D30B9A71E3E41C1E7AF10F9BA9144FCC&retpath=aHR0cDovL21ldGV1bS5haS93ZWF0aGVyL2VuLVVTPw%2C%2C_37cdc70ea8d918bf6564984569b16920&t=2/1737800175/bdf1d27da0554419863ea7a42d75b096&u=5941331168243627980&s=10679c1b3058b575b818c844d0fc7d85 | RU | — | — | whitelisted |
3208 | setup.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAkd76%2BHl%2BdEje5x5DkdF8w%3D | DE | binary | 727 b | whitelisted |
— | — | GET | 200 | 23.48.23.156:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | DE | binary | 1.01 Kb | whitelisted |
— | — | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | DE | binary | 313 b | whitelisted |
— | — | GET | 200 | 23.52.120.96:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | DE | binary | 973 b | whitelisted |
1176 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | DE | binary | 471 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5064 | SearchApp.exe | 2.16.110.155:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
— | — | 23.48.23.156:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 23.52.120.96:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
— | — | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3584 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1176 | svchost.exe | 20.190.159.23:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2192 | svchost.exe | Misc activity | ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup |
520 | ExLoader_Installer.exe | Misc activity | ET INFO External IP Address Lookup Domain (ipify .org) in TLS SNI |
2192 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Attempting to access raw user content on GitHub |
2192 | svchost.exe | Misc activity | ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup |
2192 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Attempting to access raw user content on GitHub |
2192 | svchost.exe | Device Retrieving External IP Address Detected | ET INFO External IP Lookup Domain (ipapi .co in DNS lookup) |
2192 | svchost.exe | Device Retrieving External IP Address Detected | ET INFO External IP Lookup Domain (ipapi .co in DNS lookup) |
Process | Message |
|---|---|
assistant_installer.exe | [0125/101415.073:INFO:assistant_installer_main.cc(168)] Running assistant installer with command line "C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202501251013311\assistant\assistant_installer.exe" --version
|
assistant_installer.exe | [0125/101448.064:INFO:assistant_installer_main.cc(168)] Running assistant installer with command line "C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202501251013311\assistant\assistant_installer.exe" --installfolder="C:\Users\admin\AppData\Local\Programs\Opera\assistant" --copyonly=0 --allusers=0
|
assistant_installer.exe | [0125/101448.200:INFO:assistant_installer.cc(306)] Setting up the registry
|
assistant_installer.exe | [0125/101448.332:INFO:assistant_installer.cc(357)] Creating scheduled task
|
assistant_installer.exe | [0125/101448.436:INFO:assistant_installer.cc(265)] Running Assistant
|
assistant_installer.exe | [0125/101448.436:INFO:assistant_installer_main.cc(168)] Running assistant installer with command line "C:\Users\admin\AppData\Local\Programs\Opera\assistant\assistant_installer.exe" --installfolder="C:\Users\admin\AppData\Local\Programs\Opera\assistant" --run-assistant --allusers=0
|
browser_assistant.exe | [0125/101453.000:ERROR:tracking_data_utils.cc(72)] Can't read edition: missing value.
|
browser_assistant.exe | [0125/101453.858:INFO:browser_installation_event_reporter.cc(144)] Chrome
|
browser_assistant.exe | [0125/101453.858:INFO:browser_installation_event_reporter.cc(142)] Installed browsers:
|
browser_assistant.exe | [0125/101453.858:INFO:browser_installation_event_reporter.cc(144)] Firefox
|