URL:

https://d2punpeg7vtjci.cloudfront.net/public/dynamo/lockerClick.php?offer=53283670&offer_position=1&it=3549396&m=0&visitor_id=Vdb0d0edbe9dd3&cpguid=dcmobrn6p&hash=fc14e13a40fe9b52e06b8834aa22d1f6

Full analysis: https://app.any.run/tasks/3c07b18a-65b7-438b-94dc-a80333ec6165
Verdict: Malicious activity
Analysis date: April 12, 2023, 09:28:34
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

8BC738F16586C32E633F2248A350ED14

SHA1:

D2F903DFD9B2BBD396020DE5450069FD7C90D06B

SHA256:

BF36FF86E2AC1DA508AB18BD9DE736375D97538F5D5DEC473DF2BFE982C998D0

SSDEEP:

3:N8PVe5U+MVl/0/HJ7rvXzFNUvDGxWEc3UY9MlKX6AeuAcAQAnVDCDm2t5HfWlGn:2tfzM/HRXGqriUY9vBu/VrAWlG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • OperaSetup.exe (PID: 3740)
      • OperaSetup.exe (PID: 1188)
      • OperaSetup.exe (PID: 1908)
      • OperaSetup.exe (PID: 3156)
      • OperaSetup.exe (PID: 3556)
      • OperaSetup.exe (PID: 1804)
      • OperaSetup.exe (PID: 2960)
      • Assistant_96.0.4693.50_Setup.exe_sfx.exe (PID: 3344)
      • assistant_installer.exe (PID: 3596)
      • assistant_installer.exe (PID: 3204)
      • opera.exe (PID: 2784)
      • opera.exe (PID: 4060)
      • launcher.exe (PID: 2520)
    • Actions looks like stealing of personal data

      • OperaSetup.exe (PID: 3740)
      • OperaSetup.exe (PID: 1188)
      • OperaSetup.exe (PID: 3156)
      • OperaSetup.exe (PID: 3556)
      • OperaSetup.exe (PID: 1804)
      • OperaSetup.exe (PID: 2960)
      • assistant_installer.exe (PID: 3596)
      • assistant_installer.exe (PID: 3204)
      • installer.exe (PID: 2580)
      • installer.exe (PID: 2072)
      • installer.exe (PID: 3500)
      • installer.exe (PID: 3292)
    • Drops the executable file immediately after the start

      • OperaSetup.exe (PID: 1188)
      • OperaSetup.exe (PID: 3740)
      • OperaSetup.exe (PID: 1908)
      • OperaSetup.exe (PID: 3156)
      • OperaSetup.exe (PID: 3556)
      • OperaSetup.exe (PID: 1804)
      • Assistant_96.0.4693.50_Setup.exe_sfx.exe (PID: 3344)
      • installer.exe (PID: 2580)
      • installer.exe (PID: 2072)
      • installer.exe (PID: 3500)
      • installer.exe (PID: 3292)
      • OperaSetup.exe (PID: 2960)
    • Loads dropped or rewritten executable

      • OperaSetup.exe (PID: 1188)
      • OperaSetup.exe (PID: 1908)
      • OperaSetup.exe (PID: 3156)
      • OperaSetup.exe (PID: 3556)
      • installer.exe (PID: 2072)
      • installer.exe (PID: 2580)
  • SUSPICIOUS

    • Application launched itself

      • OperaSetup.exe (PID: 3740)
      • OperaSetup.exe (PID: 3156)
      • OperaSetup.exe (PID: 1804)
      • assistant_installer.exe (PID: 3596)
      • installer.exe (PID: 2072)
      • installer.exe (PID: 3500)
    • Executable content was dropped or overwritten

      • OperaSetup.exe (PID: 1188)
      • OperaSetup.exe (PID: 3740)
      • OperaSetup.exe (PID: 1908)
      • OperaSetup.exe (PID: 3156)
      • OperaSetup.exe (PID: 3556)
      • OperaSetup.exe (PID: 1804)
      • OperaSetup.exe (PID: 2960)
      • Assistant_96.0.4693.50_Setup.exe_sfx.exe (PID: 3344)
      • installer.exe (PID: 2072)
      • installer.exe (PID: 2580)
      • installer.exe (PID: 3500)
      • installer.exe (PID: 3292)
    • Searches for installed software

      • OperaSetup.exe (PID: 3740)
      • OperaSetup.exe (PID: 3156)
      • OperaSetup.exe (PID: 1804)
      • installer.exe (PID: 2072)
    • Starts itself from another location

      • OperaSetup.exe (PID: 3740)
    • Reads the Internet Settings

      • OperaSetup.exe (PID: 3740)
      • OperaSetup.exe (PID: 3156)
    • Reads security settings of Internet Explorer

      • OperaSetup.exe (PID: 3740)
    • Reads settings of System Certificates

      • OperaSetup.exe (PID: 3740)
    • Checks Windows Trust Settings

      • OperaSetup.exe (PID: 3740)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 908)
    • The process uses the downloaded file

      • iexplore.exe (PID: 908)
      • OperaSetup.exe (PID: 3740)
      • OperaSetup.exe (PID: 3156)
    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 908)
      • iexplore.exe (PID: 3284)
    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 3284)
      • iexplore.exe (PID: 908)
    • Checks supported languages

      • OperaSetup.exe (PID: 3740)
      • OperaSetup.exe (PID: 1188)
      • OperaSetup.exe (PID: 1908)
      • OperaSetup.exe (PID: 3156)
      • OperaSetup.exe (PID: 3556)
      • OperaSetup.exe (PID: 1804)
      • OperaSetup.exe (PID: 2960)
      • Assistant_96.0.4693.50_Setup.exe_sfx.exe (PID: 3344)
      • assistant_installer.exe (PID: 3596)
      • assistant_installer.exe (PID: 3204)
      • installer.exe (PID: 2580)
      • installer.exe (PID: 2072)
      • installer.exe (PID: 3500)
      • installer.exe (PID: 3292)
      • launcher.exe (PID: 2520)
    • Create files in a temporary directory

      • iexplore.exe (PID: 908)
      • OperaSetup.exe (PID: 3740)
      • OperaSetup.exe (PID: 1188)
      • OperaSetup.exe (PID: 1908)
      • OperaSetup.exe (PID: 3156)
      • OperaSetup.exe (PID: 3556)
      • OperaSetup.exe (PID: 1804)
      • OperaSetup.exe (PID: 2960)
      • Assistant_96.0.4693.50_Setup.exe_sfx.exe (PID: 3344)
      • installer.exe (PID: 2580)
      • installer.exe (PID: 2072)
      • installer.exe (PID: 3500)
      • installer.exe (PID: 3292)
      • opera.exe (PID: 2784)
    • Reads the computer name

      • OperaSetup.exe (PID: 3740)
      • OperaSetup.exe (PID: 3156)
      • OperaSetup.exe (PID: 1804)
      • assistant_installer.exe (PID: 3596)
      • installer.exe (PID: 2072)
      • installer.exe (PID: 3500)
      • launcher.exe (PID: 2520)
    • Drops a file that was compiled in debug mode

      • OperaSetup.exe (PID: 3740)
      • OperaSetup.exe (PID: 1188)
      • OperaSetup.exe (PID: 1908)
      • OperaSetup.exe (PID: 3156)
      • OperaSetup.exe (PID: 3556)
      • OperaSetup.exe (PID: 1804)
      • OperaSetup.exe (PID: 2960)
      • Assistant_96.0.4693.50_Setup.exe_sfx.exe (PID: 3344)
      • installer.exe (PID: 2580)
      • installer.exe (PID: 2072)
      • installer.exe (PID: 3500)
      • installer.exe (PID: 3292)
    • The process checks LSA protection

      • OperaSetup.exe (PID: 3740)
      • OperaSetup.exe (PID: 3156)
      • OperaSetup.exe (PID: 1804)
      • assistant_installer.exe (PID: 3596)
      • installer.exe (PID: 2072)
      • launcher.exe (PID: 2520)
      • installer.exe (PID: 3500)
    • Creates files or folders in the user directory

      • OperaSetup.exe (PID: 1188)
      • OperaSetup.exe (PID: 3740)
      • installer.exe (PID: 2072)
    • Checks proxy server information

      • OperaSetup.exe (PID: 3740)
    • Loads dropped or rewritten executable

      • OperaSetup.exe (PID: 3740)
    • Reads the machine GUID from the registry

      • OperaSetup.exe (PID: 3740)
      • installer.exe (PID: 2072)
      • installer.exe (PID: 3500)
    • Manual execution by a user

      • opera.exe (PID: 2784)
    • Creates files in the program directory

      • OperaSetup.exe (PID: 1804)
      • installer.exe (PID: 2072)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
63
Monitored processes
19
Malicious processes
15
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start iexplore.exe iexplore.exe operasetup.exe operasetup.exe operasetup.exe operasetup.exe operasetup.exe operasetup.exe operasetup.exe opera.exe assistant_96.0.4693.50_setup.exe_sfx.exe assistant_installer.exe assistant_installer.exe installer.exe installer.exe installer.exe installer.exe launcher.exe no specs opera.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
908"C:\Program Files\Internet Explorer\iexplore.exe" "https://d2punpeg7vtjci.cloudfront.net/public/dynamo/lockerClick.php?offer=53283670&offer_position=1&it=3549396&m=0&visitor_id=Vdb0d0edbe9dd3&cpguid=dcmobrn6p&hash=fc14e13a40fe9b52e06b8834aa22d1f6"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
1188"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\OperaSetup.exe" --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector.opera.com/collector/submit --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktop --annotation=ver=97.0.4719.63 --initial-client-data=0x16c,0x170,0x174,0x140,0x178,0x6a5933e0,0x6a5933f0,0x6a5933fcC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\OperaSetup.exe
OperaSetup.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera Installer
Exit code:
0
Version:
97.0.4719.63
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\po2hn1x2\operasetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1804"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\OperaSetup.exe" "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\OperaSetup.exe" --backend --initial-pid=3740 --install --import-browser-data=0 --enable-stats=1 --enable-installer-stats=1 --consent-given=1 --general-interests=1 --general-location=1 --personalized-content=1 --personalized-ads=1 --launchopera=0 --installfolder="C:\Program Files\Opera" --profile-folder --language=en --singleprofile=0 --copyonly=0 --allusers=0 --setdefaultbrowser=1 --pintotaskbar=1 --pintostartmenu=1 --run-at-startup=1 --server-tracking-data=server_tracking_data --package-dir-prefix="C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_20230412103012" --session-guid=86d23dbc-4629-4cb5-ad90-1f24d3137c6b --server-tracking-blob=NTFjYzQ2Njc2ODhlNzIwMzI0Mjg3NzY2MzlkZDFmMzIyMmM4OTA3NjFjNTlhZGIyNzkzYThmZWY3MzYxZDdjNjp7ImNvdW50cnkiOiJHQiIsImh0dHBfcmVmZXJyZXIiOiJodHRwczovL3d3dy5vcGVyYS5jb20vbGVnYWN5LXRoYW5rcz9uaT1zdGFibGUmb3M9d2luZG93cyIsImluc3RhbGxlcl9uYW1lIjoiT3BlcmFTZXR1cC5leGUiLCJwcm9kdWN0Ijp7Im5hbWUiOiJvcGVyYSJ9LCJxdWVyeSI6Ii9vcGVyYS9zdGFibGUvd2luZG93cz91dG1fdHJ5YWdhaW49eWVzIiwic3lzdGVtIjp7InBsYXRmb3JtIjp7ImFyY2giOiJ4ODYiLCJvcHN5cyI6IldpbmRvd3MiLCJvcHN5cy12ZXJzaW9uIjoiNyIsInBhY2thZ2UiOiJFWEUifX0sInRpbWVzdGFtcCI6IjE2ODEyOTE4MDkuMTM2MiIsInVzZXJhZ2VudCI6Ik1vemlsbGEvNS4wIChXaW5kb3dzIE5UIDYuMTsgVHJpZGVudC83LjA7IHJ2OjExLjApIGxpa2UgR2Vja28iLCJ1dG0iOnsidHJ5YWdhaW4iOiJ5ZXMifSwidXVpZCI6IjFkY2NjMGYwLWM0ZTgtNDc4OC05Nzg1LTg3NzAyMmM3YzkzMSJ9 --desktopshortcut=1 --parent-pid=3156 --wait-for-package --run-elevatedC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\OperaSetup.exe
OperaSetup.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera Installer
Exit code:
0
Version:
97.0.4719.63
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\po2hn1x2\operasetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1908"C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\OperaSetup.exe" --versionC:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\OperaSetup.exe
OperaSetup.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera Installer
Exit code:
0
Version:
97.0.4719.63
Modules
Images
c:\users\admin\appdata\local\temp\.opera\opera installer temp\operasetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\shlwapi.dll
2072"C:\Program Files\Opera\95.0.4635.80\installer.exe" --backend --initial-pid=3740 --install --import-browser-data=0 --enable-stats=1 --enable-installer-stats=1 --consent-given=1 --general-interests=1 --general-location=1 --personalized-content=1 --personalized-ads=1 --launchopera=0 --installfolder="C:\Program Files\Opera" --profile-folder --language=en --singleprofile=0 --copyonly=0 --allusers=0 --setdefaultbrowser=1 --pintotaskbar=1 --pintostartmenu=1 --run-at-startup=1 --server-tracking-data=server_tracking_data --package-dir="C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202304121030121" --session-guid=86d23dbc-4629-4cb5-ad90-1f24d3137c6b --server-tracking-blob=NTFjYzQ2Njc2ODhlNzIwMzI0Mjg3NzY2MzlkZDFmMzIyMmM4OTA3NjFjNTlhZGIyNzkzYThmZWY3MzYxZDdjNjp7ImNvdW50cnkiOiJHQiIsImh0dHBfcmVmZXJyZXIiOiJodHRwczovL3d3dy5vcGVyYS5jb20vbGVnYWN5LXRoYW5rcz9uaT1zdGFibGUmb3M9d2luZG93cyIsImluc3RhbGxlcl9uYW1lIjoiT3BlcmFTZXR1cC5leGUiLCJwcm9kdWN0Ijp7Im5hbWUiOiJvcGVyYSJ9LCJxdWVyeSI6Ii9vcGVyYS9zdGFibGUvd2luZG93cz91dG1fdHJ5YWdhaW49eWVzIiwic3lzdGVtIjp7InBsYXRmb3JtIjp7ImFyY2giOiJ4ODYiLCJvcHN5cyI6IldpbmRvd3MiLCJvcHN5cy12ZXJzaW9uIjoiNyIsInBhY2thZ2UiOiJFWEUifX0sInRpbWVzdGFtcCI6IjE2ODEyOTE4MDkuMTM2MiIsInVzZXJhZ2VudCI6Ik1vemlsbGEvNS4wIChXaW5kb3dzIE5UIDYuMTsgVHJpZGVudC83LjA7IHJ2OjExLjApIGxpa2UgR2Vja28iLCJ1dG0iOnsidHJ5YWdhaW4iOiJ5ZXMifSwidXVpZCI6IjFkY2NjMGYwLWM0ZTgtNDc4OC05Nzg1LTg3NzAyMmM3YzkzMSJ9 --desktopshortcut=1 --install-subfolder=95.0.4635.80 --parent-pid=3156C:\Program Files\Opera\95.0.4635.80\installer.exe
OperaSetup.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera Installer
Exit code:
0
Version:
95.0.4635.80
Modules
Images
c:\program files\opera\95.0.4635.80\installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
2520"C:\Program Files\Opera\launcher.exe" --new-tabC:\Program Files\Opera\launcher.exeinstaller.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera Internet Browser
Exit code:
0
Version:
95.0.4635.80
Modules
Images
c:\program files\opera\launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2580"C:\Program Files\Opera\95.0.4635.80\installer.exe" --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector.opera.com/collector/submit --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktop --annotation=ver=95.0.4635.80 --initial-client-data=0x16c,0x170,0x174,0x140,0x178,0x679fe428,0x679fe438,0x679fe444C:\Program Files\Opera\95.0.4635.80\installer.exe
installer.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera Installer
Exit code:
0
Version:
95.0.4635.80
Modules
Images
c:\program files\opera\95.0.4635.80\installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
2784"C:\Program Files\Opera\opera.exe" C:\Program Files\Opera\opera.exe
explorer.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera Internet Browser
Exit code:
0
Version:
1748
Modules
Images
c:\program files\opera\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\gdi32.dll
2960"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\OperaSetup.exe" --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector.opera.com/collector/submit --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktop --annotation=ver=97.0.4719.63 --initial-client-data=0x16c,0x170,0x174,0x140,0x178,0x692d33e0,0x692d33f0,0x692d33fcC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\OperaSetup.exe
OperaSetup.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera Installer
Exit code:
0
Version:
97.0.4719.63
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\po2hn1x2\operasetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3156"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\OperaSetup.exe" --backend --install --import-browser-data=0 --enable-stats=1 --enable-installer-stats=1 --consent-given=1 --general-interests=1 --general-location=1 --personalized-content=1 --personalized-ads=1 --launchopera=1 --installfolder="C:\Program Files\Opera" --profile-folder --language=en --singleprofile=0 --copyonly=0 --allusers=0 --setdefaultbrowser=1 --pintotaskbar=1 --pintostartmenu=1 --run-at-startup=1 --server-tracking-data=server_tracking_data --initial-pid=3740 --package-dir-prefix="C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_20230412103012" --session-guid=86d23dbc-4629-4cb5-ad90-1f24d3137c6b --server-tracking-blob=NTFjYzQ2Njc2ODhlNzIwMzI0Mjg3NzY2MzlkZDFmMzIyMmM4OTA3NjFjNTlhZGIyNzkzYThmZWY3MzYxZDdjNjp7ImNvdW50cnkiOiJHQiIsImh0dHBfcmVmZXJyZXIiOiJodHRwczovL3d3dy5vcGVyYS5jb20vbGVnYWN5LXRoYW5rcz9uaT1zdGFibGUmb3M9d2luZG93cyIsImluc3RhbGxlcl9uYW1lIjoiT3BlcmFTZXR1cC5leGUiLCJwcm9kdWN0Ijp7Im5hbWUiOiJvcGVyYSJ9LCJxdWVyeSI6Ii9vcGVyYS9zdGFibGUvd2luZG93cz91dG1fdHJ5YWdhaW49eWVzIiwic3lzdGVtIjp7InBsYXRmb3JtIjp7ImFyY2giOiJ4ODYiLCJvcHN5cyI6IldpbmRvd3MiLCJvcHN5cy12ZXJzaW9uIjoiNyIsInBhY2thZ2UiOiJFWEUifX0sInRpbWVzdGFtcCI6IjE2ODEyOTE4MDkuMTM2MiIsInVzZXJhZ2VudCI6Ik1vemlsbGEvNS4wIChXaW5kb3dzIE5UIDYuMTsgVHJpZGVudC83LjA7IHJ2OjExLjApIGxpa2UgR2Vja28iLCJ1dG0iOnsidHJ5YWdhaW4iOiJ5ZXMifSwidXVpZCI6IjFkY2NjMGYwLWM0ZTgtNDc4OC05Nzg1LTg3NzAyMmM3YzkzMSJ9 --desktopshortcut=1 --wait-for-package --initial-proc-handle=5406000000000000C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\OperaSetup.exe
OperaSetup.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera Installer
Exit code:
0
Version:
97.0.4719.63
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\po2hn1x2\operasetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
61 092
Read events
60 468
Write events
598
Delete events
26

Modification events

(PID) Process:(908) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(908) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(908) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(908) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(908) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(908) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(908) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(908) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(908) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(908) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
54
Suspicious files
168
Text files
794
Unknown types
108

Dropped files

PID
Process
Filename
Type
3284iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:
SHA256:
3284iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62binary
MD5:
SHA256:
3284iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\lockerClick[1].htmhtml
MD5:
SHA256:
3284iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\IL7IQBWQ.txttext
MD5:
SHA256:
3284iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894binary
MD5:
SHA256:
3284iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_B5D3A17E5BEDD2EDA793611A0A74E1E8binary
MD5:
SHA256:
3284iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\30D802E0E248FEE17AAF4A62594CC75Abinary
MD5:
SHA256:
3284iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850Dbinary
MD5:
SHA256:
3284iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894der
MD5:7CECA430A42A7B562296E777850D9A59
SHA256:69136A40F067B783DE49C6E27E1C30C12CA37A5F28D23495812934884605723A
3284iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75CA58072B9926F763A91F0CC2798706_B5D3A17E5BEDD2EDA793611A0A74E1E8der
MD5:D5125FF59BB40D49F4DEC8F736ECE33D
SHA256:B87741F7C1B28BB0225727D1E5E3FEC012BA22D4F659F6127E8A12CCA67A5963
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
70
TCP/UDP connections
280
DNS requests
83
Threats
11

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3284
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQrHR6YzPN2BNbByL0VoiTIBBMAOAQUCrwIKReMpTlteg7OM8cus%2B37w3oCEA0WcKqJz0qvV5nHApP7qas%3D
US
der
314 b
whitelisted
3284
iexplore.exe
GET
200
172.64.155.188:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEA9uAUFDljLnD1CR8PbHMzc%3D
US
der
471 b
whitelisted
3284
iexplore.exe
GET
200
13.32.47.54:80
http://crl.r2m01.amazontrust.com/r2m01.crl
US
binary
154 Kb
suspicious
3284
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
US
der
471 b
whitelisted
3284
iexplore.exe
GET
200
104.18.32.68:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D
US
der
2.18 Kb
whitelisted
3284
iexplore.exe
GET
200
108.138.2.173:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
US
der
1.70 Kb
whitelisted
3284
iexplore.exe
GET
200
52.222.250.42:80
http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
US
der
1.51 Kb
whitelisted
3284
iexplore.exe
GET
200
8.248.131.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8cb10c1ba2d5906b
US
compressed
4.70 Kb
whitelisted
908
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D
US
der
1.47 Kb
whitelisted
3284
iexplore.exe
GET
200
91.199.212.52:80
http://crt.sectigo.com/SectigoRSADomainValidationSecureServerCA.crt
GB
der
1.52 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
908
iexplore.exe
108.138.24.197:443
d2punpeg7vtjci.cloudfront.net
AMAZON-02
US
unknown
3284
iexplore.exe
34.91.234.242:443
blue.redredirector.com
GOOGLE-CLOUD-PLATFORM
NL
unknown
3284
iexplore.exe
91.199.212.52:80
crt.sectigo.com
Sectigo Limited
GB
suspicious
3284
iexplore.exe
104.18.32.68:80
ocsp.usertrust.com
CLOUDFLARENET
suspicious
3284
iexplore.exe
172.64.155.188:80
ocsp.usertrust.com
CLOUDFLARENET
US
suspicious
3284
iexplore.exe
52.70.250.63:443
www.getgx.net
AMAZON-AES
US
unknown
908
iexplore.exe
34.91.234.242:443
blue.redredirector.com
GOOGLE-CLOUD-PLATFORM
NL
unknown
3284
iexplore.exe
52.222.226.205:80
ocsp.r2m01.amazontrust.com
AMAZON-02
US
unknown
908
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
908
iexplore.exe
2.23.209.185:443
www.bing.com
Akamai International B.V.
GB
whitelisted

DNS requests

Domain
IP
Reputation
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 2.23.209.135
  • 2.23.209.185
  • 2.23.209.133
  • 2.23.209.130
  • 2.23.209.189
  • 2.23.209.176
  • 2.23.209.179
  • 2.23.209.182
  • 2.23.209.193
  • 2.23.209.149
  • 2.23.209.187
  • 2.23.209.140
  • 2.16.187.147
  • 2.16.187.27
  • 2.16.187.138
  • 2.16.187.146
  • 2.16.187.9
  • 2.16.187.154
  • 2.16.187.137
  • 2.16.187.160
  • 2.16.187.19
  • 2.16.187.67
  • 2.16.187.42
  • 2.16.187.113
  • 2.16.187.48
  • 2.16.187.106
  • 2.16.187.115
  • 2.16.187.98
  • 2.16.187.122
  • 2.16.187.97
  • 2.16.187.136
  • 2.16.187.10
  • 2.16.187.26
  • 2.16.187.66
  • 2.16.187.91
  • 2.16.187.64
  • 2.16.187.59
  • 2.16.187.43
  • 2.16.187.50
whitelisted
ctldl.windowsupdate.com
  • 8.248.131.254
  • 8.248.119.254
  • 8.248.137.254
  • 8.238.30.254
  • 8.238.190.126
whitelisted
o.ss2.us
  • 108.138.2.173
  • 108.138.2.195
  • 108.138.2.10
  • 108.138.2.107
whitelisted
ocsp.rootg2.amazontrust.com
  • 52.222.250.42
  • 52.222.250.185
  • 52.222.250.112
  • 52.222.250.174
whitelisted
ocsp.rootca1.amazontrust.com
  • 18.66.200.23
  • 18.66.200.204
  • 18.66.200.39
  • 18.66.200.130
shared
blue.redredirector.com
  • 34.91.234.242
  • 34.141.179.97
unknown
crt.sectigo.com
  • 91.199.212.52
whitelisted
ocsp.usertrust.com
  • 104.18.32.68
  • 172.64.155.188
whitelisted
ocsp.sectigo.com
  • 172.64.155.188
  • 104.18.32.68
whitelisted

Threats

PID
Process
Class
Message
2784
opera.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
2784
opera.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
2784
opera.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
2784
opera.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
2784
opera.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
2784
opera.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
2784
opera.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
2784
opera.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
2784
opera.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
2784
opera.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
Process
Message
assistant_installer.exe
[0412/103204.217:INFO:assistant_installer_main.cc(167)] Running assistant installer with command line "C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202304121030121\assistant\assistant_installer.exe" --version
assistant_installer.exe
[0412/103204.217:INFO:assistant_installer_main.cc(167)] Running assistant installer with command line "C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202304121030121\assistant\assistant_installer.exe" --version