General Info

URL

https://live-nba.stream/watch/43062/2/portland-trail-blazers-golden-state-warriors-live.html

Full analysis
https://app.any.run/tasks/1d32bde1-a317-409b-8b69-59d0d4b59f02
Verdict
Malicious activity
Analysis date
5/15/2019, 08:27:55
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (73.0.3683.75)
  • Google Update Helper (1.3.33.23)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 65.0.2 (x86 en-US) (65.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO

No malicious indicators.

No suspicious indicators.

Creates files in the user directory
  • opera.exe (PID: 3660)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Screenshots

Processes

Total processes
35
Monitored processes
3
Malicious processes
0
Suspicious processes
0

Behavior graph

+
start opera.exe acrord32.exe no specs acrord32.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3660
CMD
"C:\Program Files\Opera\opera.exe" https://live-nba.stream/watch/43062/2/portland-trail-blazers-golden-state-warriors-live.html
Path
C:\Program Files\Opera\opera.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Opera Software
Description
Opera Internet Browser
Version
1748
Modules
Image
c:\program files\opera\opera.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\program files\opera\opera.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
c:\windows\system32\version.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\profapi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\devenum.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\avicap32.dll
c:\windows\system32\msvfw32.dll
c:\windows\system32\quartz.dll
c:\program files\adobe\acrobat reader dc\reader\browser\nppdf32.dll
c:\windows\system32\macromed\flash\npswf32_26_0_0_131.dll
c:\program files\java\jre1.8.0_92\bin\dtplugin\npdeployjava1.dll
c:\program files\java\jre1.8.0_92\bin\plugin2\npjp2.dll
c:\progra~1\micros~1\office14\npauthz.dll
c:\progra~1\micros~1\office14\npspwrap.dll
c:\program files\google\update\1.3.33.23\npgoogleupdate3.dll
c:\program files\videolan\vlc\npvlc.dll
c:\program files\adobe\acrobat reader dc\reader\air\nppdf32.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\dsound.dll
c:\windows\system32\mscms.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dinput8.dll
c:\windows\system32\mlang.dll
c:\windows\system32\credssp.dll
c:\windows\system32\schannel.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\audioses.dll
c:\windows\system32\msvcp120.dll
c:\windows\system32\msvcr120.dll
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe

PID
2856
CMD
"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" /o /eo /l /b /id 3660
Path
C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
Indicators
No indicators
Parent process
opera.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Adobe Systems Incorporated
Description
Adobe Acrobat Reader DC
Version
15.23.20070.215641
Modules
Image
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\kbdus.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\psapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll

PID
1684
CMD
"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" --type=renderer /o /eo /l /b /id 3660
Path
C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
Indicators
No indicators
Parent process
AcroRd32.exe
User
admin
Integrity Level
LOW
Version:
Company
Adobe Systems Incorporated
Description
Adobe Acrobat Reader DC
Version
15.23.20070.215641
Modules
Image
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\shell32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\program files\adobe\acrobat reader dc\reader\acrord32.dll
c:\program files\adobe\acrobat reader dc\reader\agm.dll
c:\windows\system32\msvcp120.dll
c:\windows\system32\msvcr120.dll
c:\windows\system32\version.dll
c:\program files\adobe\acrobat reader dc\reader\bib.dll
c:\program files\adobe\acrobat reader dc\reader\cooltype.dll
c:\program files\adobe\acrobat reader dc\reader\ace.dll
c:\windows\system32\profapi.dll
c:\program files\adobe\acrobat reader dc\reader\cryptocme.dll
c:\program files\adobe\acrobat reader dc\reader\ccme_base.dll
c:\program files\adobe\acrobat reader dc\reader\ccme_base_non_fips.dll
c:\program files\adobe\acrobat reader dc\reader\ccme_asym.dll
c:\program files\adobe\acrobat reader dc\reader\ccme_ecc.dll
c:\program files\adobe\acrobat reader dc\reader\ccme_ecdrbg.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\msftedit.dll

Registry activity

Total events
265
Read events
204
Write events
61
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
3660
opera.exe
write
HKEY_CURRENT_USER\Software\Opera Software
Last CommandLine v2
C:\Program Files\Opera\opera.exe https://live-nba.stream/watch/43062/2/portland-trail-blazers-golden-state-warriors-live.html
3660
opera.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
LanguageList
en-US
1684
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\ExitSection
bLastExitNormal
0

Files activity

Executable files
0
Suspicious files
87
Text files
46
Unknown types
58

Dropped files

PID
Process
Filename
Type
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win
text
MD5: 21f2d3abef4b826e91f2a54f6a054a51
SHA256: 632e24f65178bf143c91ffb28f9940a3d70babfae851cefc0f4550129bad500b
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00015.tmp
compressed
MD5: 820bdf1feb6ec5c273cec0a2b376fd32
SHA256: 6dcc5ced7b4fa1e3cf286902b8c292078e5b7898d9ef764e3a9da3f578b07f5d
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\oprA2BD.tmp
––
MD5:  ––
SHA256:  ––
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0002R.tmp
image
MD5: 9fe46ab42817105ddf80d6a4c0319739
SHA256: 7e1f96fe29dc95c3320d8f3ac4855219185b6193abb377f19a19ce1b1a937f03
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0002S.tmp
html
MD5: 1f428316b4eff0c17534e1222ce5a225
SHA256: 76feec6e30209ecfcf7ebc62f298d0fcdc7bb56fb35fdd668d7b1912164a2872
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0002Q.tmp
compressed
MD5: 820bdf1feb6ec5c273cec0a2b376fd32
SHA256: 6dcc5ced7b4fa1e3cf286902b8c292078e5b7898d9ef764e3a9da3f578b07f5d
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0002P.tmp
compressed
MD5: 6a008391d7aa02dd6e40002a3526d7f2
SHA256: 9b971c7aa06acc460b750910e70924fad0ecf94203dbd3a922d3b06ac7c47478
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win
text
MD5: 1dba90608751925f894ab0da2dae6bed
SHA256: 4b8009da463e9c9669dd0233e29ca2ce40fdb752ae7ddf556491eb3754375b2c
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\opr9242.tmp
––
MD5:  ––
SHA256:  ––
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\global_history.dat
text
MD5: 6b4d206d3506aa1bc312c07d04a68335
SHA256: 4c33d3bec12725d92d064d6eedb452f7e637412d80484a9d6387e1eb5d38f965
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\g_0000\opr0002O.tmp
compressed
MD5: 9808ebfa0d76d616f1feb4ba114f9e1c
SHA256: 5701e2a985b2e2292249b5ce245b8e99895585aa04823bbf77233a4797b4d9cf
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win
text
MD5: 3c6367f578a86bcfafcf8d8723d887af
SHA256: f36ed199ecaae6145efd268c7eb5a210fc51adda6a966532cdc622ff71f6f4c9
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\opr83F8.tmp
––
MD5:  ––
SHA256:  ––
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\g_0000\opr0002O.tmp
compressed
MD5: 87432d13c3a263c26860866aa58fc8e0
SHA256: 6fbcf80f04621fba3bf5517f4735567495af17d52389cfccfdbedc831e95e5c8
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\g_0000\opr0002N.tmp
compressed
MD5: 45f28c9cf5b7a8f45f64d7245b73b22e
SHA256: bbd138e348e01e894ee9e18aa77a6b1ce86f902defd3b67de7f86f6e89cf3605
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\g_0000\opr0002N.tmp
compressed
MD5: e2b2d0632f375f221d8fd674aaf21081
SHA256: 7edbf6b032aeef65a0bab4d531da840b0e38cad965d8b26f413cb2bf76ff4683
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Flive-nba-stream.chatango.com%2Fimages%2Ffavicon.png
image
MD5: 2e547c72c8df77c9894d415b300a8cb1
SHA256: bc9218ce49a0a725c1dbb63cfd6cfb6b368555b74231e5952ea9041eefaa8d6d
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\live-nba-stream.chatango.com.idx
text
MD5: 430336821ee79ca3e71a666aa2a71a3b
SHA256: 8422a2831b4f19aecd6e667757a606fc2f07d56ca7834486125a2735c0790e6e
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win
text
MD5: b05aafb686be842ebdd0e7c741814d29
SHA256: 2fc4a9d0e990ca5876bd00938c19c94e0dfa9aa5e10a1d6792ad5644211c8b86
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\opr783F.tmp
––
MD5:  ––
SHA256:  ––
3660
opera.exe
C:\Users\admin\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sxx
––
MD5:  ––
SHA256:  ––
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\vlink4.dat
binary
MD5: 5dfd8d01e7021480bc68101f25d4de41
SHA256: a7e4d47881fec0ca3613d3318745b828a9b37d8c50c6054ede35c187ef5801ac
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opr4FA8.tmp
––
MD5:  ––
SHA256:  ––
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\cookies4.dat
binary
MD5: a08bff50b14aff129cbb844f1727a5e8
SHA256: cffb3bd97ba308f0a8cf47dba17b23c4d8ceb295069b7eb1b1382fabaf7c5e3a
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\dcache4.url
binary
MD5: c1780f75d6159066e9a76e1d114bc16b
SHA256: e11f272459595f8de34c4d42a0ab85e6d389782839afc777f9047556e3cda3c7
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\opcache\dcache4.url
binary
MD5: 829944cd9e03bea2944ecd245d970947
SHA256: 28589d036668b87a1f0d5a8ad385a68b9c73e8cdb87b22c154c7644f934e98e0
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opr4F88.tmp
––
MD5:  ––
SHA256:  ––
1684
AcroRd32.exe
C:\Users\admin\AppData\Local\Temp\acrord32_sbx\A9R1x5i6zy_57tdi_1as.tmp
––
MD5:  ––
SHA256:  ––
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\global_history.dat
text
MD5: 0eb3c34588e3798c48dc5698b0a3f30f
SHA256: cb808c824a87e3ca8d53b0c0bcb47973c124d3be3f9dc5568f8ccf82043436e4
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win
text
MD5: f552ff9f7db43597ba8244c231521e62
SHA256: faca796d13ff5a4b1ced1e93c3fa40b24c47e283d64be99edfc04669dd28ede2
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\opr2AF7.tmp
––
MD5:  ––
SHA256:  ––
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0002J.tmp
compressed
MD5: 7033c51b9723af39fcfe089efe33e08f
SHA256: cebaae6891288c0de984dd37e947faab93b1e3102423d45d0820b707724381dc
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0002M.tmp
compressed
MD5: 6edadb451bdf5f851894269d67e37854
SHA256: b77a89ae132f84ea3b8b1e308475815c94fd094a9ee956b7ae61892cc6ebc17c
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0002L.tmp
image
MD5: 29862bbe4812df99b54c9838a7db49b8
SHA256: ec33d184b7577e83911691e1d2062ac03294924b749b80d64102b4d98d20b633
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0002K.tmp
compressed
MD5: 3acda5c43961aa7cfc95ad39dfaccd9c
SHA256: 4779cfaff23c4b7c8a352e028bde925ad756ccdd692c84fe87204ea54cc4da93
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0002E.tmp
compressed
MD5: 24106f7bf795411f92562c9f736f5786
SHA256: 16349b88c26739f81bfabad27ddabc79397548405b2d42db20b469a05a005c6d
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0002H.tmp
compressed
MD5: 9777dbd1e23405320a735a51e185e618
SHA256: 33039ae7cdd9d1a267b0706aa55cefe2b8123cefd805a26dff49ef738801e029
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0002I.tmp
image
MD5: e5e9b7d6e6a1851f99ec3d6194596ab4
SHA256: 13f16ddff41d604e065579c489c7dc272e55014e488337307aad49711c52a7ee
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0002C.tmp
compressed
MD5: 904f2592075004e8f6fd629e4603760c
SHA256: c39c5407cf791422241b88824e50d5f8b49c1462731c6dfa6b10ba9422c37617
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0002F.tmp
image
MD5: 6fdc42afd2a2d72032f8d076ae52a905
SHA256: 1833cb203f004f64c0e8650100879c086c00689f7179163bfdfc1dd577c10eb8
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0002G.tmp
compressed
MD5: a78e471c62f51f84e70ea955616f6203
SHA256: 6138df0bb990f46d23e032132300903d78e4df19f81bd9e5c3b3ed51736f09f4
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0002D.tmp
compressed
MD5: 8a8829762d5c6799b6a4906e6ceda2e9
SHA256: f5ab4131982a424939ca07e039c4fcfee41073ca49fd21da6e50b12f78833c69
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00028.tmp
compressed
MD5: 91ddf3ad468cea5141720e380cb7859b
SHA256: 8c50377b410432246807a37efccab9378ce95ecfdeb06890b672886495f92c8f
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0002A.tmp
html
MD5: 38bc9bc6b283957dad5c52db4372b39c
SHA256: 08630027391c138931d700d9f8fa6abfc179311c2d3846abc1f7ae02577ab70d
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00026.tmp
compressed
MD5: 642db42f624d97df130bc0cfe374dc0f
SHA256: d9287e4e3331482beb071091bea3b82f21d971a89fae1890f83577be8f354094
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00027.tmp
compressed
MD5: 686cfba8de6a32ea10bc8680006c896b
SHA256: 6e1c04fa84f5b8a6ee3407e4569f3a1c3589d4a4d4c50bae16eee36c7e2ff3a2
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00025.tmp
image
MD5: 8e7232cc5e5c0426a547a1012fa8fda0
SHA256: bed57a09b10b5cfc83c33f5bc6205831a9db085c874bc72d096d05ad2136e4b4
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00029.tmp
compressed
MD5: c111ac40494e1111b51d44c0be565ada
SHA256: 8e9a480c5d7c79dbc049c33f899090678a36f3b5554a7cc320c69cc210ddfdc4
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0002B.tmp
html
MD5: 55d2343b50b0cca7cb586a94db2f98b4
SHA256: 1e705c455293f94c5f1bf531d680f3d0f26e91c0fd2e2c6669d78053683b6707
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00024.tmp
compressed
MD5: 211f326ec68d8a8c62dcbaa59e84e3a1
SHA256: 768ce7db3d4df987048a178d65be0c175fce7bf24c43acb5e4fe01d8805f458a
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00022.tmp
compressed
MD5: 97462cd45a1f089a5206f6d0ee06cbc7
SHA256: e25ea9dd5099ea7be2774aac7ae4e1d789504aa22aa520d329606f666044b375
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00021.tmp
compressed
MD5: cd55611fecd0a6fab97c09c701fbe0de
SHA256: 9c5f2a4212c1d6f12fb2032b7bb7f4c6b3e014c5f75812bb3dbfda5941eb6ebb
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00023.tmp
compressed
MD5: bcb286d6ed3d6caaaf137a57c2dd8706
SHA256: bf6f5ca77a1a5f929d27620cd2f7a7b999ac59d880783089dc538c603952e49f
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0001W.tmp
compressed
MD5: 6235b321530b6e9e4b4fee82cdf940dd
SHA256: 7ad58b8a07a8e668891fd59dc5116b7438352afc5c3f11fbdbc7ad1670f1d164
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0001Q.tmp
compressed
MD5: 98ccb565ccc1bdc260dfc0ba743ef926
SHA256: 937e3e638424a0d25ea8275ff412436040d593c39c23e97ca14e7b2e6eb9553d
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0001V.tmp
compressed
MD5: b385507ae3c0914a02c3145608f5ffe8
SHA256: 170809acbbcd3b34c1ec8c723e1424340268f1a1a056ce422be941a405a23176
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0001U.tmp
compressed
MD5: 3d5731ae684e0b753b1b9bb696c73352
SHA256: fb1b08e2d22ab7aeac8fe11f802e51af53a50dc450f006e2c612f03f6176d69a
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0001X.tmp
image
MD5: 7902d821c5ef1950ccb12c80dd2aae5d
SHA256: 545f4359550b571139127b4e4cea51fa157a480d913a13431b9942a86aa69231
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0001Z.tmp
image
MD5: a1927f7cb91217299bd81f21c08509d4
SHA256: 0e95d0c1443a6aa310389b66bb94f6a7457fac4c3e44077d4df766b0d2b02fc8
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0001R.tmp
text
MD5: 69b194971a91d90ee36d1b2fdb4afe42
SHA256: d03b7842aa784e00edb0353515958e06b44c9e29d5e4e2e798d852b46f0b608b
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00020.tmp
compressed
MD5: 01c65a610e30184c969eb20261339c1c
SHA256: b3f4126b079aa87922615278d5ce2e889bbbb7c3434ae8b2a58a60e672976435
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0001Y.tmp
image
MD5: fe6a8daf46a5b3f624f0966edef60a65
SHA256: 2ae6e38eff17a18640c3c78bc9b8cf4db2812281904272474328e27f54cac179
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0001T.tmp
compressed
MD5: b212bb11951b836c47410d289cf70d0e
SHA256: 80d4130b8ebb7171e0ae8292434dc7232d1f624f3ababdcf45c6cccc32ef2f88
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0001S.tmp
compressed
MD5: 5e541c4c4e9ba2d7a067061b7b451021
SHA256: 1f48acbf55dc41bc1f87989420ca9c51435cf93e29284a547b99fb34d03d52a0
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0001E.tmp
image
MD5: 242d5d5d57512a8f8ea0854054c59e3e
SHA256: ff6f99e59ae4cc6965dee0059eba9d18dd1334ef1b5335058467d57faf1dfdc5
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0001P.tmp
image
MD5: b05fbc2388edbc27fa2d3a8f183b82cb
SHA256: f2bca8f2943738017b2317235836eaf44a579798d83db0d154162c7c5ce7ad09
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0001I.tmp
compressed
MD5: 17da68b66064b13281f19df0a79f0dd7
SHA256: 03e63f5af11109896083acec421d970a9ef94047b2d8b0d3e7199e97e020e254
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0001J.tmp
image
MD5: ece6fd7e80e4f906c012de25ae70ecd3
SHA256: 818ce38e548c8222a2d3d31e6739658683964f9233ae770d41a918ead12001bd
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0001O.tmp
compressed
MD5: 96721f28261afef36e8c999ff52d5ac9
SHA256: e651020afa1a5c8320550694933817049093d13adce73eea8eef45c7c97619c7
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0001L.tmp
compressed
MD5: f3b3810c573e76b4ca54491714d92776
SHA256: 075adf78a8d07375bf6963462cc46efa46e821a75ea16440a3bdbd7079beddb2
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0001F.tmp
compressed
MD5: 172d2a121534b71cfc4b5cb954979b9d
SHA256: ee39fae2ba21ceae7ef13a0285206df507e4a531d93518d7bb2354234edfa952
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0001M.tmp
compressed
MD5: f2014f19584ca23724298afe3e16f70b
SHA256: f73e0106e237b9d1f3968d97f366bcb55b35cb0d0edb707a0e37e1e7a3a0f378
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0001K.tmp
compressed
MD5: f9d7c76c1232c7ec9d7a63e92c776a45
SHA256: 3c6917c8c8e4637a830cf269eed68a04ac8540c35fb62f476e53aef7294fdfe0
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0001G.tmp
compressed
MD5: c2989bae7e79f62719aaf3ff5042b39b
SHA256: 95bd1e94c67c7065173a3f19d623756c146d3a6994f4cc68400189c8bf7ffb8f
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0001N.tmp
compressed
MD5: 11e60c3c2a83b41c59afaa564cd61bbb
SHA256: 9e9f9ed36b2348a6596f1fc48e40544849663448d1b3acf8e00c8c5768269973
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0001H.tmp
image
MD5: 299ffc90a77a2e8660f7f16273d11578
SHA256: 9ad264073fda1ca0e7ef2f6dd775ba968d2312ec6f503b635dadefe7c36210b7
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0001B.tmp
image
MD5: 10c4c9acde5ac981f5b89f49f6f37b9f
SHA256: 0578e9a89f9f3c211e04bcc46458b752b591b21fa2e31847ff4f7ee9ce492cdc
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00019.tmp
compressed
MD5: 830621d2f0279419dac53a29610bf01c
SHA256: e44386750b8ff9c4d1d86e8c2d9dfb04a9d4291b2634c82bae5784e39b9b9f32
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0001C.tmp
image
MD5: 58c889e8cbd9ae8d291934b7a165b403
SHA256: 8794321f2a8fb5af507f3f7ab64b6c0186a31d00d51ee77705227ade48584081
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00014.tmp
compressed
MD5: 10ab9912e6c3ac8fa06c7d0a1963b3b6
SHA256: 821765ba013d88da44a1fdcec5213586dac19ef446d806768e706da79f0aa847
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0001D.tmp
compressed
MD5: e469732592ef0016222af3f838e0ad76
SHA256: 099cfc08bf89a13e9e69908e57bf4dfd417a2379fe282b66767d5dee88d796fa
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00018.tmp
compressed
MD5: 2bdb8ae52df1a765eec77bf12b983508
SHA256: 5d6c0b6a895a15e02bfdebc3e6bfa8b19f3dced9533ead70d8489880515f7977
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\global_history.dat
text
MD5: 2da892fbe2d0b18314b85fa20e1c7569
SHA256: 20a902a2fdad3e4e3b5bb97924f2f07cdaa396ac9385b53a9d3840e5f9a5d0bc
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00017.tmp
compressed
MD5: 7028ac8a3d0ef9ef0fade367b91a690f
SHA256: 6b4473a216c8fe772b3fbf639ca994853ca096c0d9bff7776d3da4f62b719aaf
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00016.tmp
image
MD5: f3d993ee4ca4037793e82039f7518187
SHA256: 92e9955979c28af617651b41d530ce29290e17881e595b9071f04efec4ded3e0
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0001A.tmp
compressed
MD5: 33601c73181caf58099c08d49fc6c724
SHA256: a077a11b1e62ee8a40bb7a55504825d1aa7789586c4d8f7c4b4259301a5a538c
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0000Z.tmp
image
MD5: c07526f28ca75ac4c1785511c8a4c23a
SHA256: e51811609f1004388855ecb1d04bc92381d524b3ce25afc773bd0bb2e7b248d2
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0000V.tmp
compressed
MD5: 524d71ac7b3d4ee7af06725ed04edf89
SHA256: ace0b199d39a474f4ef2f552ed11f9ef0ba47f83654801b2d11cb1f29e31f3f2
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0000X.tmp
compressed
MD5: ab0e962612de6c730137ab64330c788d
SHA256: cee9838cc5d59b315d11912d4db3aa3bde6a57c8bc5dbf3f6478604ee64d4f5b
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0000S.tmp
compressed
MD5: 6da54cb4c4f1102e51a50e0b7312b2da
SHA256: 76127ab43e3018bcdc35c79ff8abbca942b3197fa91a2896f8a6142652efac40
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00011.tmp
html
MD5: 65a348d6cc2489239685518b37373cfb
SHA256: f2dad65252df35341569429fd94d14b500a27995c77ebb458d6c2166d892a7ab
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00010.tmp
image
MD5: 283181737907ef5262549640b94fc251
SHA256: 295a11c5a28b48c77c20e0f1f0231abf6f355b81076bc305f69570036a8720af
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0000Y.tmp
compressed
MD5: 65cbb6a1d213cf9d49b052c7d94d9afb
SHA256: 22eb168f23318d15f80e4dad59c65fd23612a62443dafb60b32a5e0100dec24b
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00013.tmp
compressed
MD5: e5482c4354b483f3d106f4aa48c3cc0a
SHA256: 0cd21bdd84ed888385500e373bd4f595e9bdcfe172647657a65dffbad59498d4
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00012.tmp
compressed
MD5: 5594bcfe2a61b4519339cb7193fea463
SHA256: f9da2e667b2357ad88641340ed31358383b76889eace2615071cd25d120ff4be
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0000R.tmp
compressed
MD5: 348fbdd6c0fd83acfd390fa9cc127596
SHA256: 5874a897424027f25efdc7142d4d8a4341d9a9f6362ac79bead10db6356dae2b
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0000O.tmp
image
MD5: 9421912336119bba7801a5b35528d2b4
SHA256: 135e731d7e44b7a5de75f6f776059583f0038dc4572a1f81b21bf2a79f258029
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0000U.tmp
compressed
MD5: 87236153d3cb999244740f926bb98a7c
SHA256: 7a2bac7993994fe9d5ddbee72d73bcea8ede95045327e54d0047ee93418b1506
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0000W.tmp
compressed
MD5: c6f603512db766598e98be3ead5b65cd
SHA256: 6112550ee3eaa40ab48e9575ac4b964db7cef7ade9612e2708a070144e60155e
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0000T.tmp
compressed
MD5: 6235b321530b6e9e4b4fee82cdf940dd
SHA256: 7ad58b8a07a8e668891fd59dc5116b7438352afc5c3f11fbdbc7ad1670f1d164
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0000P.tmp
compressed
MD5: f529ce613d8baf3f3cccfd46f03a084d
SHA256: ad0cc939bf160d744317828d29614b37cde0ba0ef08365d8f8b919fe89df3caf
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0000Q.tmp
compressed
MD5: be0026e2819aa0806ca7402cd2bd3485
SHA256: 070bd971e1862c551f04c0d68a2c88fc32d5f0affb7e23d214de5835cd8cb82e
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0000M.tmp
compressed
MD5: f021f3d488e1de798245092b6b4e984c
SHA256: 0622ade9422ba9b7267ae6ec4aa56da547e868494c3641cfd9f369e4236e66ba
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0000G.tmp
image
MD5: eeec7df9b69ce571d93f4a7737fd47fa
SHA256: 32d05b089d4778b07f99688db918401be28dd6e35526584fd799aa3d7596edbe
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0000H.tmp
compressed
MD5: 6a008391d7aa02dd6e40002a3526d7f2
SHA256: 9b971c7aa06acc460b750910e70924fad0ecf94203dbd3a922d3b06ac7c47478
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0000N.tmp
compressed
MD5: 16b0f4424b0366cd177e5c07237bed49
SHA256: 873567fbdb5891e4acaaf9b5b2082a4257c483d35ad7acd591d82b26d87907c8
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0000L.tmp
compressed
MD5: 0d177ec3c8ae4f3ad2e3295db65ec3dd
SHA256: d5c274cceca5f95da17376cce48b7d030eb669554432c96c9a0f7d10d7d340ae
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0000J.tmp
image
MD5: 6bbcb8e999e5e3d47a2b71ca8d99c00c
SHA256: 79668b8fcf81f287d35cc21ff6d2ed73e47234371b29e8fabd83668bbae003ad
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0000I.tmp
text
MD5: 961da4f3d315d924e88728a3bccb2112
SHA256: c9f072faa27e7dba0555c7e5ee40f96f89a1993b86a7be826912b7d457d25cae
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0000K.tmp
compressed
MD5: 064b1e400444c32813e524d68e18aa59
SHA256: b95cd183457f7541bff40d869f5ab341e3bb62225329871268fad15647bd7ca1
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0000F.tmp
text
MD5: a5175faf6dc24adc7eda4f9cfc721b47
SHA256: 0a034dc9c0d0d4fa4c0dbcf6faf7f39ae166cd73fe807f8dca40891c409a56e8
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\opr1E83.tmp
––
MD5:  ––
SHA256:  ––
3660
opera.exe
C:\Users\admin\AppData\Local\Temp\FAP1CFB.tmp
––
MD5:  ––
SHA256:  ––
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\g_0000\opr0000E.tmp
swf
MD5: ec77319b7f855b510d56cc13901e7ad1
SHA256: fe13002dd714607ad5c44289429da33869c7ab45317586b08d3f5a9a9dc95c2b
3660
opera.exe
C:\Users\admin\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol
sol
MD5: b650071bea3726b2114863ae2ec80ad5
SHA256: cdef8b37b280fa048f0af15ebf8c7fb2bb58eda09d175eaf55fefff35acbdeda
3660
opera.exe
C:\Users\admin\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sxx
sol
MD5: b650071bea3726b2114863ae2ec80ad5
SHA256: cdef8b37b280fa048f0af15ebf8c7fb2bb58eda09d175eaf55fefff35acbdeda
3660
opera.exe
C:\Users\admin\AppData\Local\Temp\FAP1837.tmp
––
MD5:  ––
SHA256:  ––
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\global_history.dat
text
MD5: 6dfc462ca128d82fd0ae8dccd3685d5a
SHA256: 4acca63a66afea9b0415a9d9af730e1f66ac898eca37a98d35b39c2c1b53a675
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\assoc002\sesn\opr0000D.000
odttf
MD5: 8bfa1a6062a9860f70f711697fe93e59
SHA256: d3ada7e9dd17edb9057118d5c60d43236ac9e69dc25af30c170e2c75e1c723d2
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0000D.tmp
woff
MD5: a7850001a3cb4e55c7de566f8f65013e
SHA256: 7c6e3db2973ec267a3de28c71b995f6f382a0750b79e9f4a38e4429ed6be0d5e
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0000C.tmp
woff
MD5: 382640c6d4fc077862b9012f7758f6a1
SHA256: 986f2f43aafd09b1cb9f2eac9c8ac66b9fb28574c2c87b1895d47791aba386be
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\assoc002\sesn\opr0000C.000
odttf
MD5: 9173172627165f5ae8bf5749fcff015a
SHA256: 69ee38faebdadecafd699577908aac97587b88a5aed9d49584a21dbbd8678002
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0000B.tmp
woff
MD5: a6503395b88994edf66230fc6a045f3d
SHA256: 32e7c8c5113827847b1c8cc068fbf72bf2035db696319ec2a80e708446da3623
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0000A.tmp
compressed
MD5: 61dcccbe709859ee75513ce934386024
SHA256: 3fa2e8ebc1533b1935868127b9208e7f77a9b232e1b3b4811ccb51a6856a3179
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\assoc002\sesn\opr0000B.000
odttf
MD5: 683693b15abb7829c13d4f3c46dafd73
SHA256: 99440f5290a3c7608eef46eeead7d0556f5e2b3b221087692fe04d38b5679e24
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr0000A.tmp
compressed
MD5: c46364ba66f22575fe0261f9a7025bf6
SHA256: eaf7c3980d2e2b7f32d617879dd4bc738b7614172f559fd88e910b8fde78b35d
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00008.tmp
ttf
MD5: b3d9968f1b30b144a098398fcc64f0c0
SHA256: d0254109393de88b34258266c6a1f7ad4d3ff10e3d71a301cedcb6037ec35745
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\assoc002\sesn\opr00009.000
odttf
MD5: 683693b15abb7829c13d4f3c46dafd73
SHA256: 99440f5290a3c7608eef46eeead7d0556f5e2b3b221087692fe04d38b5679e24
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00009.tmp
woff
MD5: a6503395b88994edf66230fc6a045f3d
SHA256: 32e7c8c5113827847b1c8cc068fbf72bf2035db696319ec2a80e708446da3623
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00007.tmp
woff
MD5: bedcda61b048f7da07fcbb976d5a0b15
SHA256: 34bf5ccfb50c40caa80ded69ea2eafcf9dba2c5d57eae27ccfd3816e3ca82530
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\assoc002\sesn\opr00007.000
odttf
MD5: b44a51b053756a40cdb4a05ed85e853e
SHA256: f5dfa41f3585782ba45ab6b09758f490ad1d533adf60eca5383989d6528f779c
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\assoc002\sesn\opr00006.000
odttf
MD5: 9173172627165f5ae8bf5749fcff015a
SHA256: 69ee38faebdadecafd699577908aac97587b88a5aed9d49584a21dbbd8678002
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00005.tmp
ttf
MD5: 3fcb6333c47c305ac51b8f995c8ebf1a
SHA256: 05940b1bd3571b9471470fd73ddbca9641cdef1233edb6417ece057b62aa828e
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00006.tmp
woff
MD5: 382640c6d4fc077862b9012f7758f6a1
SHA256: 986f2f43aafd09b1cb9f2eac9c8ac66b9fb28574c2c87b1895d47791aba386be
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00004.tmp
compressed
MD5: e165c17a79d57f87e757bb3ed9306118
SHA256: 2c4ad5d8be2cb507f4863752237125a84023bbaee4a9da683a8946b34959e492
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\assoc002\sesn\opr00002.000
ttf
MD5: 37783551d834b4cdcb137ea2649bafb9
SHA256: 643d022c9d5eb0bbe3dd5b6f7038005fdb14f8301cdcc66cbe6999abc980a8e6
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00002.tmp
woff
MD5: fee66e712a8a08eef5805a46892932ad
SHA256: ba0c59deb5450f5cb41b3f93609ee2d0d995415877ddfa223e8a8a7533474f07
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\assoc002\sesn\opr00003.000
otf
MD5: 2c76b42575ff294e3a86a8131fc66771
SHA256: 6c26bda61603d7b89157ff4a8d2d5aca8b578c4c767cc2670567edd24c357d55
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00003.tmp
woff
MD5: 186800b93f2def943aaf5e8311c95c78
SHA256: 2987bbe36581d97fca0ef5dfe014aa752286ce0dd6be998e9ec55fcfe7bfd613
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00002.tmp
woff
MD5: 2d406408f9c6179ab8c903f9c32c464e
SHA256: 6a2a6408764bef5df215ff6e4ff1a7deed92031014b99e00b9b4eaf1ec69f508
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win
text
MD5: 44702a874096b63cd2d4200d412be8c5
SHA256: 964e7bd9dee04f478a3c3bc103219c1f2d029bf16f73dd3e519ae91c6757b455
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\opr1289.tmp
––
MD5:  ––
SHA256:  ––
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win.bak
text
MD5: 0100e3d2a29941ceef4e37312a7fa332
SHA256: 0c42c7737a5aba75c8e2ea967e2a994542b2c641d0a370edc41bc4d70a7cac70
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\live-nba.stream.idx
text
MD5: d6cd822280316682dc8886c5ed030e0c
SHA256: 26b4c37581ad071609baca9adc69bfd711bb3dc6e026d96a5c7928d1e8897159
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\https%3A%2F%2F1079020916.rsc.cdn77.org%2Fimages%2Fnba-logo.png
image
MD5: f2399d019d8b98209b1dc53a6b28eeee
SHA256: f654757da622939b3a418925beb268a7e809e6a255b78def0b5b2474839cd63b
3660
opera.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\16ec093b8f51508f.customDestinations-ms~RF1208b3.TMP
binary
MD5: 9be9ccc710d3048cfd9bfa594a41206a
SHA256: 85766104413f074c4d5a44fe7a2472002a0b99dc59d4224db4cd1e19072d2903
3660
opera.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\16ec093b8f51508f.customDestinations-ms
binary
MD5: 9be9ccc710d3048cfd9bfa594a41206a
SHA256: 85766104413f074c4d5a44fe7a2472002a0b99dc59d4224db4cd1e19072d2903
3660
opera.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\S4KD4BA1XE0HANVX6Z70.temp
––
MD5:  ––
SHA256:  ––
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcacrt6.dat
binary
MD5: 7f5dcbf9f067f258078d5071195d5c51
SHA256: fec0be3946fe4780375cee50eb647bea4fb130af228e473fe442b39ff19d0492
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat
binary
MD5: b7f56a221d99c36dfc874342d5cdf274
SHA256: 781755bb80731a025ef63124d5c90058902ee10cdc1e1e829a07f68d48d72b75
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00001.tmp
––
MD5:  ––
SHA256:  ––
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\optrust.dat
binary
MD5: 1aa8644c9261dc10f7247f6a145c1dd2
SHA256: 58a8933f65361633c6ab194000d312dc9d566f717b1a16814a0dbee24a60ebe3
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat
binary
MD5: 9cb710ffc0be5408e7b53158fa88a780
SHA256: 3d1c83518d090b8bc851deb2cb75af0eaa6cbdd4d5c72c7147c1ffa697ff6870
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opuntrust.dat
binary
MD5: 1aa8644c9261dc10f7247f6a145c1dd2
SHA256: 58a8933f65361633c6ab194000d312dc9d566f717b1a16814a0dbee24a60ebe3
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat
binary
MD5: c231ce06258cac1a27b7797c5c6119b8
SHA256: 354657e42dc273494d4acd52e6c9f5e4c89868c4825de9d9b02f1338e2464ec4
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcert6.dat
binary
MD5: 1aa8644c9261dc10f7247f6a145c1dd2
SHA256: 58a8933f65361633c6ab194000d312dc9d566f717b1a16814a0dbee24a60ebe3
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opicacrt6.dat
binary
MD5: 82f1a2b1176a5ecc457d32301e2ad833
SHA256: a783052804dd4c232be2ed3dc00c430cb67a20370890e235562ed2b27b5a602e
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcacrt6.dat
binary
MD5: 59761e989f564f76a3a4b778db7abcf1
SHA256: af879942d234d85c0ce75921dbdda50e2f6d135bd961f259106131751359052b
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xml
xml
MD5: 73d1408704bccd9142e5f520535261b7
SHA256: 40b0acf7ba27a3637c8b78fba12b6b5bf90277d5717ba59b6c354291b6db1a45
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\oprFBC4.tmp
––
MD5:  ––
SHA256:  ––
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.ini
text
MD5: a446b1a8d21b10e8d4d96cf2f2eb9662
SHA256: 4d4b397b4aa9d3680ea9706c4e2b18d126814c6cd3777de397ce9e94d9487012
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\oprFB27.tmp
––
MD5:  ––
SHA256:  ––
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win
text
MD5: 0100e3d2a29941ceef4e37312a7fa332
SHA256: 0c42c7737a5aba75c8e2ea967e2a994542b2c641d0a370edc41bc4d70a7cac70
3660
opera.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\oprFB07.tmp
––
MD5:  ––
SHA256:  ––
3660
opera.exe
C:\Users\admin\AppData\Local\Opera\Opera\cache\CACHEDIR.TAG
text
MD5: e717f92fa29ae97dbe4f6f5c04b7a3d9
SHA256: 5bbd5dcbf87fd8cd7544c522badf22a2951cf010ad9f25c40f9726f09ea2b552

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
33
TCP/UDP connections
125
DNS requests
46
Threats
0

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
3660 opera.exe GET 200 192.35.177.64:80 http://crl.identrust.com/DSTROOTCAX3CRL.crl US
der
whitelisted
3660 opera.exe GET 200 66.225.197.197:80 http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl US
der
whitelisted
3660 opera.exe GET 200 151.139.128.14:80 http://crl.comodoca.com/COMODORSACertificationAuthority.crl US
der
whitelisted
3660 opera.exe GET 200 151.139.128.14:80 http://crl.usertrust.com/AddTrustExternalCARoot.crl US
der
whitelisted
3660 opera.exe GET 200 151.139.128.14:80 http://ocsp.comodoca4.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBQAU7Bfe6xSRj1%2Bo83zCN%2BY2wTgIAQU1LD0%2FU%2BcQqRs3D0u7ltBGMmtA%2FYCEQDSVJWT1OLxShV3sbdg0rEr US
der
whitelisted
3660 opera.exe GET 200 93.184.220.29:80 http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQQX6Z6gAidtSefNc6DC0OInqPHDQQUD4BhHIIxYdUvKOeNRji0LOHG2eICEAJvJGeK%2FtwlV70AH1C0Bso%3D US
der
whitelisted
3660 opera.exe GET 200 93.184.220.29:80 http://crl3.digicert.com/DigiCertGlobalRootCA.crl US
der
whitelisted
3660 opera.exe GET 200 93.184.220.29:80 http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTPJvUY%2Bsl%2Bj4yzQuAcL2oQno5fCgQUUWj%2FkK8CB3U8zNllZGKiErhZcjsCEAwYRnF7eZBhU2LgcspZxrA%3D US
der
whitelisted
3660 opera.exe GET 200 172.217.22.99:80 http://crl.pki.goog/gsr2/gsr2.crl US
der
whitelisted
3660 opera.exe GET 200 151.139.128.14:80 http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR64T7ooMQqLLQoy%2BemBUYZQOKh6QQUkK9qOpRaC9iQ6hJWc99DtDoo2ucCEAwlX%2BWwe0xUZK7sA79up6Y%3D US
der
whitelisted
3660 opera.exe GET 200 172.217.22.35:80 http://ocsp.pki.goog/GTSGIAG3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT27bBjYjKBmjX2jXWgnQJKEapsrQQUd8K4UJpndnaxLcKG0IOgfqZ%2BuksCEGP04nWBbUL75ThIZuPamrU%3D US
der
whitelisted
3660 opera.exe GET 200 151.139.128.14:80 http://ocsp.comodoca4.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQAU7Bfe6xSRj1%2Bo83zCN%2BY2wTgIAQU1LD0%2FU%2BcQqRs3D0u7ltBGMmtA%2FYCECpNJaw%2FqAVZDxAFL0VG%2Bnc%3D US
der
whitelisted
3660 opera.exe GET 200 208.93.230.18:80 http://st.chatango.com/flash/flashgroup.swf US
swf
unknown
3660 opera.exe GET 200 151.139.128.14:80 http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR64T7ooMQqLLQoy%2BemBUYZQOKh6QQUkK9qOpRaC9iQ6hJWc99DtDoo2ucCEDVcoTH82eAUPv6eGMIxtds%3D US
der
whitelisted
3660 opera.exe GET 304 208.93.230.18:80 http://st.chatango.com/flash/flashgroup.swf US
swf
unknown
3660 opera.exe GET 200 172.217.22.35:80 http://ocsp.pki.goog/GTSGIAG3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT27bBjYjKBmjX2jXWgnQJKEapsrQQUd8K4UJpndnaxLcKG0IOgfqZ%2BuksCECbIFwaq3sOhhfH36eieRuU%3D US
der
whitelisted
3660 opera.exe GET 200 104.18.21.226:80 http://ocsp2.globalsign.com/gsorganizationvalsha2g2/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBQMnk2cPe3vhNiR6XLHz4QGvBl7BwQUlt5h8b0cFilTHMDMfTuDAEDmGnwCDDyctXofSIyNofdpTg%3D%3D US
der
whitelisted
3660 opera.exe GET 200 104.18.20.226:80 http://crl.globalsign.net/root.crl US
der
whitelisted
3660 opera.exe GET 200 208.93.230.27:80 http://live-nba-stream.chatango.com/clonegroup US
html
suspicious
3660 opera.exe GET 200 208.93.230.27:80 http://live-nba-stream.chatango.com/images/favicon.ico US
image
suspicious
3660 opera.exe GET 200 208.93.230.27:80 http://live-nba-stream.chatango.com/h5/gz/configurator/create_group_h5_d.html US
html
suspicious
3660 opera.exe GET 200 208.93.230.18:80 http://st.chatango.com/cfg/nc/r.json?1557901733860 US
text
unknown
3660 opera.exe GET 200 208.93.230.27:80 http://live-nba-stream.chatango.com/h5/gz/r0327191219/iMG.html US
html
suspicious
3660 opera.exe GET –– 208.93.230.27:80 http://live-nba-stream.chatango.com/images/html5/yrws.gif US
––
––
suspicious
3660 opera.exe GET –– 208.93.230.27:80 http://live-nba-stream.chatango.com/images/html5/transp.png US
––
––
suspicious
3660 opera.exe GET 200 208.93.230.27:80 http://live-nba-stream.chatango.com/images/html5/checks.gif US
image
suspicious
3660 opera.exe GET 200 208.93.230.22:80 http://ust.chatango.com/profileimg/sp/sp_athena/thumb.jpg US
image
unknown
3660 opera.exe GET 200 208.93.230.22:80 http://ust.chatango.com/profileimg/sp/sp_artemis/thumb.jpg US
image
unknown
3660 opera.exe GET 200 208.93.230.22:80 http://ust.chatango.com/profileimg/sp/sp_poseidon/thumb.jpg US
image
unknown
3660 opera.exe GET 200 208.93.230.22:80 http://ust.chatango.com/profileimg/sp/sp_zeus/thumb.jpg US
image
unknown
3660 opera.exe GET 200 208.93.230.22:80 http://ust.chatango.com/profileimg/sp/sp_atlas/thumb.jpg US
image
unknown
3660 opera.exe GET 200 208.93.230.22:80 http://ust.chatango.com/profileimg/sp/sp_apollo/thumb.jpg US
image
unknown
3660 opera.exe GET 200 208.93.230.22:80 http://ust.chatango.com/profileimg/sp/sp_prometheus/thumb.jpg US
image
unknown

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
3660 opera.exe 185.125.230.221:443 MAROSNET Telecommunication Company LLC RU unknown
3660 opera.exe 185.26.182.112:443 Opera Software AS –– suspicious
3660 opera.exe 185.26.182.93:443 Opera Software AS –– unknown
3660 opera.exe 192.35.177.64:80 IdenTrust US malicious
3660 opera.exe 66.225.197.197:80 CacheNetworks, Inc. US whitelisted
3660 opera.exe 104.19.195.151:443 Cloudflare Inc US shared
3660 opera.exe 195.181.170.18:443 Datacamp Limited DE unknown
3660 opera.exe 208.93.230.18:443 Chatango LLC US unknown
3660 opera.exe 31.13.90.36:443 Facebook, Inc. IE whitelisted
3660 opera.exe 67.202.94.93:443 Steadfast US unknown
3660 opera.exe 93.184.220.66:443 MCI Communications Services, Inc. d/b/a Verizon Business US whitelisted
3660 opera.exe 216.58.205.232:443 Google Inc. US whitelisted
3660 opera.exe 151.139.128.14:80 Highwinds Network Group, Inc. US suspicious
3660 opera.exe 93.184.220.29:80 MCI Communications Services, Inc. d/b/a Verizon Business US whitelisted
–– –– 93.184.220.29:80 MCI Communications Services, Inc. d/b/a Verizon Business US whitelisted
–– –– 172.217.22.99:80 Google Inc. US whitelisted
3660 opera.exe 172.217.22.35:80 Google Inc. US whitelisted
3660 opera.exe 93.184.220.70:443 MCI Communications Services, Inc. d/b/a Verizon Business US whitelisted
3660 opera.exe 104.16.86.20:443 Cloudflare Inc US shared
3660 opera.exe 198.134.112.241:443 Webair Internet Development Company Inc. US suspicious
3660 opera.exe 185.59.220.29:443 Datacamp Limited DE malicious
3660 opera.exe 2.18.232.65:443 Akamai International B.V. –– whitelisted
3660 opera.exe 2.16.186.74:443 Akamai International B.V. –– whitelisted
3660 opera.exe 104.111.240.148:443 Akamai International B.V. NL unknown
3660 opera.exe 157.240.20.19:443 Facebook, Inc. US whitelisted
3660 opera.exe 2.16.186.65:443 Akamai International B.V. –– whitelisted
3660 opera.exe 31.13.64.21:443 Facebook, Inc. IE whitelisted
3660 opera.exe 172.217.16.142:443 Google Inc. US whitelisted
3660 opera.exe 208.93.230.18:80 Chatango LLC US unknown
3660 opera.exe 205.185.208.52:443 Highwinds Network Group, Inc. US unknown
3660 opera.exe 104.31.65.244:443 Cloudflare Inc US unknown
–– –– 104.31.65.244:443 Cloudflare Inc US unknown
3660 opera.exe 104.31.14.157:443 Cloudflare Inc US unknown
3660 opera.exe 185.125.230.216:443 MAROSNET Telecommunication Company LLC RU suspicious
3660 opera.exe 2.16.186.9:443 Akamai International B.V. –– whitelisted
3660 opera.exe 104.28.24.78:443 Cloudflare Inc US unknown
3660 opera.exe 104.24.112.37:443 Cloudflare Inc US unknown
–– –– 104.24.112.37:443 Cloudflare Inc US unknown
–– –– 172.217.16.142:443 Google Inc. US whitelisted
–– –– 157.240.1.18:443 Facebook, Inc. US whitelisted
3660 opera.exe 216.58.206.14:443 Google Inc. US whitelisted
–– –– 104.18.58.156:443 Cloudflare Inc US suspicious
3660 opera.exe 104.18.58.156:443 Cloudflare Inc US suspicious
3660 opera.exe 93.186.225.193:443 VKontakte Ltd RU unknown
3660 opera.exe 104.18.21.226:80 Cloudflare Inc US shared
3660 opera.exe 104.18.20.226:80 Cloudflare Inc US shared
3660 opera.exe 208.93.230.27:80 Chatango LLC US suspicious
3660 opera.exe 208.93.230.22:80 Chatango LLC US unknown

DNS requests

Domain IP Reputation
live-nba.stream 185.125.230.221
185.125.230.53
unknown
sitecheck2.opera.com 185.26.182.112
185.26.182.93
185.26.182.94
185.26.182.111
whitelisted
certs.opera.com 185.26.182.93
185.26.182.94
whitelisted
crl.identrust.com 192.35.177.64
whitelisted
crl4.digicert.com 66.225.197.197
whitelisted
1079020916.rsc.cdn77.org 195.181.170.18
suspicious
cdnjs.cloudflare.com 104.19.195.151
104.19.199.151
104.19.198.151
104.19.196.151
104.19.197.151
whitelisted
www.facebook.com 31.13.90.36
whitelisted
platform.twitter.com 93.184.220.66
whitelisted
st.chatango.com 208.93.230.18
208.93.230.28
208.93.230.22
208.93.230.16
208.93.230.24
208.93.230.26
unknown
whos.amung.us 67.202.94.93
67.202.94.94
67.202.94.86
unknown
www.googletagmanager.com 216.58.205.232
whitelisted
crl.comodoca.com 151.139.128.14
whitelisted
crl.usertrust.com 151.139.128.14
whitelisted
ocsp.comodoca4.com 151.139.128.14
whitelisted
ocsp.digicert.com 93.184.220.29
whitelisted
crl3.digicert.com 93.184.220.29
whitelisted
crl.pki.goog 172.217.22.99
whitelisted
ocsp.pki.goog 172.217.22.35
whitelisted
ocsp.comodoca.com 151.139.128.14
whitelisted
syndication.twitter.com 104.244.42.200
104.244.42.72
104.244.42.136
104.244.42.8
whitelisted
cdn.syndication.twimg.com 93.184.220.70
whitelisted
1886290197.rsc.cdn77.org 185.59.220.29
suspicious
cdn.jsdelivr.net 104.16.86.20
104.16.88.20
104.16.87.20
104.16.89.20
104.16.85.20
whitelisted
muqson0kgr.com 198.134.112.241
198.134.112.244
198.134.112.243
198.134.112.242
suspicious
static.nfl.com 2.18.232.65
unknown
www.nba.com 104.111.240.148
whitelisted
neulionms-a.akamaihd.net 2.16.186.74
2.16.186.65
whitelisted
static.xx.fbcdn.net 157.240.20.19
whitelisted
scontent-amt2-1.xx.fbcdn.net 31.13.64.21
unknown
www.google-analytics.com 172.217.16.142
whitelisted
tommyjones.site 104.31.65.244
104.31.64.244
suspicious
code.jquery.com 205.185.208.52
whitelisted
cax.tellerium.website 104.31.14.157
104.31.15.157
unknown
telerium.tv 185.125.230.216
185.125.230.219
185.125.230.223
185.125.230.224
185.125.230.236
194.48.152.18
194.48.152.115
194.48.152.116
suspicious
neulionmdnyc-a.akamaihd.net 2.16.186.9
2.16.186.24
whitelisted
swarm.video 104.28.24.78
104.28.25.78
unknown
static.tellerium.com 104.24.112.37
104.24.113.37
unknown
telerium.net 104.18.58.156
104.18.59.156
malicious
graph.facebook.com 157.240.1.18
whitelisted
clients6.google.com 216.58.206.14
whitelisted
vk.com 93.186.225.193
93.186.225.197
87.240.129.133
87.240.182.224
87.240.190.67
whitelisted
crl.globalsign.net 104.18.20.226
104.18.21.226
whitelisted
ocsp2.globalsign.com 104.18.21.226
104.18.20.226
whitelisted
live-nba-stream.chatango.com 208.93.230.27
208.93.230.29
208.93.230.23
suspicious
ust.chatango.com 208.93.230.22
208.93.230.18
208.93.230.24
208.93.230.16
208.93.230.26
208.93.230.28
unknown

Threats

No threats detected.

Debug output strings

No debug info.