File name:

OperaSetup.exe

Full analysis: https://app.any.run/tasks/e25e0b88-cf71-4979-97ef-a3c1f155716d
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: June 06, 2025, 09:03:59
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
stealer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

E17DAEAEA1363F35A0059087EF369120

SHA1:

A8495D5F2B5E68256861F4BED595F3BA23E99CCC

SHA256:

DCFD6538F8E97480AC87174E6A3C99B16E8C5F089FC148AD8FE11AFD33B2E2A3

SSDEEP:

98304:+wyWSeMgt83dCAz3QaJJTNuUdAj5h4uMwV4imVhKBTSn8G+fgNaGWTFvncguDIMG:+UJn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • setup.exe (PID: 5960)
    • Steals credentials from Web Browsers

      • setup.exe (PID: 5960)
      • setup.exe (PID: 2852)
      • assistant_installer.exe (PID: 1764)
      • assistant_installer.exe (PID: 8068)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • OperaSetup.exe (PID: 7428)
      • setup.exe (PID: 2852)
      • setup.exe (PID: 5960)
      • Assistant_118.0.5461.41_Setup.exe_sfx.exe (PID: 7820)
      • setup.exe (PID: 2980)
    • Application launched itself

      • setup.exe (PID: 5960)
      • assistant_installer.exe (PID: 1764)
    • Starts itself from another location

      • setup.exe (PID: 5960)
    • Reads security settings of Internet Explorer

      • setup.exe (PID: 5960)
    • There is functionality for taking screenshot (YARA)

      • setup.exe (PID: 5960)
      • setup.exe (PID: 2852)
    • Process drops legitimate windows executable

      • Assistant_118.0.5461.41_Setup.exe_sfx.exe (PID: 7820)
  • INFO

    • Checks supported languages

      • OperaSetup.exe (PID: 7428)
      • setup.exe (PID: 2852)
      • setup.exe (PID: 5960)
      • setup.exe (PID: 2980)
      • Assistant_118.0.5461.41_Setup.exe_sfx.exe (PID: 7820)
      • assistant_installer.exe (PID: 1764)
      • assistant_installer.exe (PID: 8068)
    • The sample compiled with english language support

      • OperaSetup.exe (PID: 7428)
      • setup.exe (PID: 2852)
      • setup.exe (PID: 5960)
      • Assistant_118.0.5461.41_Setup.exe_sfx.exe (PID: 7820)
      • setup.exe (PID: 2980)
    • Create files in a temporary directory

      • OperaSetup.exe (PID: 7428)
      • setup.exe (PID: 5960)
      • setup.exe (PID: 2852)
      • setup.exe (PID: 2980)
      • Assistant_118.0.5461.41_Setup.exe_sfx.exe (PID: 7820)
    • Reads the computer name

      • setup.exe (PID: 5960)
      • assistant_installer.exe (PID: 1764)
    • Creates files or folders in the user directory

      • setup.exe (PID: 2852)
      • setup.exe (PID: 5960)
    • Checks proxy server information

      • setup.exe (PID: 5960)
    • Reads the software policy settings

      • setup.exe (PID: 5960)
      • slui.exe (PID: 2104)
    • Reads the machine GUID from the registry

      • setup.exe (PID: 5960)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:06:12 14:58:14+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.39
CodeSize: 238080
InitializedDataSize: 113152
UninitializedDataSize: -
EntryPoint: 0x213c0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 119.0.5497.70
ProductVersionNumber: 119.0.5497.70
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
FileVersion: 119.0.5497.70
ProductVersion: 119.0.5497.70
FileDescription: Opera installer SFX
CompanyName:
LegalCopyright: Opera Software 2025
Productname: Opera installer
Stream: Stable
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
133
Monitored processes
9
Malicious processes
2
Suspicious processes
3

Behavior graph

Click at the process to see the details
start operasetup.exe setup.exe setup.exe sppextcomobj.exe no specs slui.exe setup.exe assistant_118.0.5461.41_setup.exe_sfx.exe assistant_installer.exe assistant_installer.exe

Process information

PID
CMD
Path
Indicators
Parent process
1764"C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202506060904061\assistant\assistant_installer.exe" --versionC:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202506060904061\assistant\assistant_installer.exe
setup.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera Browser Assistant Installer
Exit code:
0
Version:
118.0.5461.41
Modules
Images
c:\users\admin\appdata\local\temp\.opera\opera installer temp\opera_package_202506060904061\assistant\assistant_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2104"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2852C:\Users\admin\AppData\Local\Temp\7zS40D59902\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win64 --annotation=prod=OperaDesktop --annotation=ver=119.0.5497.70 --initial-client-data=0x278,0x29c,0x2a0,0x280,0x2a4,0x7ffc89d98f08,0x7ffc89d98f14,0x7ffc89d98f20C:\Users\admin\AppData\Local\Temp\7zS40D59902\setup.exe
setup.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera Installer
Version:
119.0.5497.70
Modules
Images
c:\users\admin\appdata\local\temp\7zs40d59902\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2980"C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exe" --versionC:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exe
setup.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\.opera\opera installer temp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
5960C:\Users\admin\AppData\Local\Temp\7zS40D59902\setup.exe --server-tracking-blob=NzMyYTA4ZTRmZDc2NzMxMDJhMDhjYTQxZTViZjY5NjcxZjY2ODU2ZTk2NmE5NjMzODczYmIwZWJiMWM2ZjUzNDp7ImNvdW50cnkiOiJJTiIsImh0dHBfcmVmZXJyZXIiOiJodHRwczovL3d3dy5vcGVyYS5jb20vIiwiaW5zdGFsbGVyX25hbWUiOiJPcGVyYVNldHVwLmV4ZSIsInByb2R1Y3QiOiJvcGVyYSIsInF1ZXJ5IjoiL29wZXJhL3N0YWJsZS93aW5kb3dzP3V0bV9zb3VyY2U9YmluZyZ1dG1fbWVkaXVtPXBhJnV0bV9jYW1wYWlnbj1JTiUyNTIwLSUyNTIwUGVyZm9ybWFuY2UlMjUyME1heCUyNTIwLSUyNTIwRU4lMjUyMC0lMjUyME1LVCZ1dG1fY29udGVudD1WUE4lMjUyMC0lMjUyMFBlb3BsZSZ1dG1faWQ9bXNjbGtpZF85MjIwNDBmYzc0ZjIxNWZkMjYzNjI4YmVmOWU1YTdjZCZodHRwX3JlZmVycmVyPWh0dHBzJTNBJTJGJTJGd3d3LmJpbmcuY29tJTJGJnV0bV9zaXRlPW9wZXJhX2NvbSZ1dG1fbGFzdHBhZ2U9b3BlcmEuY29tJTJGcmVzdHJpY3RlZCZkbF90b2tlbj03NTUwODc1MyIsInRpbWVzdGFtcCI6IjE3NDkxOTE5ODEuMTAwOSIsInVzZXJhZ2VudCI6Ik1vemlsbGEvNS4wIChXaW5kb3dzIE5UIDEwLjA7IFdpbjY0OyB4NjQpIEFwcGxlV2ViS2l0LzUzNy4zNiAoS0hUTUwsIGxpa2UgR2Vja28pIENocm9tZS8xMzYuMC4wLjAgU2FmYXJpLzUzNy4zNiBFZGcvMTM2LjAuMC4wIiwidXRtIjp7ImNhbXBhaWduIjoiSU4lMjAtJTIwUGVyZm9ybWFuY2UlMjBNYXglMjAtJTIwRU4lMjAtJTIwTUtUIiwiY29udGVudCI6IlZQTiUyMC0lMjBQZW9wbGUiLCJpZCI6Im1zY2xraWRfOTIyMDQwZmM3NGYyMTVmZDI2MzYyOGJlZjllNWE3Y2QiLCJsYXN0cGFnZSI6Im9wZXJhLmNvbS9yZXN0cmljdGVkIiwibWVkaXVtIjoicGEiLCJzaXRlIjoib3BlcmFfY29tIiwic291cmNlIjoiYmluZyJ9LCJ1dWlkIjoiOGY5YmEyY2QtN2IwZS00NzZkLWJjZTYtMDcxNjgzYTMwNDAxIn0=C:\Users\admin\AppData\Local\Temp\7zS40D59902\setup.exe
OperaSetup.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera Installer
Version:
119.0.5497.70
Modules
Images
c:\users\admin\appdata\local\temp\7zs40d59902\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6032C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7428"C:\Users\admin\AppData\Local\Temp\OperaSetup.exe" C:\Users\admin\AppData\Local\Temp\OperaSetup.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Opera installer SFX
Version:
119.0.5497.70
Modules
Images
c:\users\admin\appdata\local\temp\operasetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7820"C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202506060904061\assistant\Assistant_118.0.5461.41_Setup.exe_sfx.exe"C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202506060904061\assistant\Assistant_118.0.5461.41_Setup.exe_sfx.exe
setup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Opera installer SFX
Exit code:
0
Version:
118.0.5461.41
Modules
Images
c:\users\admin\appdata\local\temp\.opera\opera installer temp\opera_package_202506060904061\assistant\assistant_118.0.5461.41_setup.exe_sfx.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
8068"C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202506060904061\assistant\assistant_installer.exe" --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktop --annotation=ver=118.0.5461.41 --initial-client-data=0x260,0x264,0x268,0x23c,0x26c,0x11a103c,0x11a1048,0x11a1054C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202506060904061\assistant\assistant_installer.exe
assistant_installer.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera Browser Assistant Installer
Exit code:
0
Version:
118.0.5461.41
Modules
Images
c:\users\admin\appdata\local\temp\.opera\opera installer temp\opera_package_202506060904061\assistant\assistant_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
4 818
Read events
4 815
Write events
3
Delete events
0

Modification events

(PID) Process:(5960) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(5960) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(5960) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
12
Suspicious files
25
Text files
6
Unknown types
1

Dropped files

PID
Process
Filename
Type
5960setup.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\Opera_119.0.5497.70_Autoupdate_x64[1].exe
MD5:
SHA256:
5960setup.exeC:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202506060904061\opera_package
MD5:
SHA256:
5960setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419der
MD5:EB764F19D79F7A0472D9A449CE70EDBB
SHA256:9938366EFD8D2E804F1923318BDD784494B5E6E9FC293BD66FD020067EB20D38
2852setup.exeC:\Users\admin\AppData\Local\Temp\Opera_installer_2506060904059142852.dllexecutable
MD5:E31627DA8871F8261D45C545E6E0F39A
SHA256:AC1EC373B6A0C95A421741CECF2C57E345F16BB0B5306009C870F2B35361D42A
5960setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\26C212D9399727259664BDFCA073966E_B7ED31D77D311A56FDCB56A0083B3E0Bbinary
MD5:58596562726CC92BAF122B7DF5B5B679
SHA256:A8349C71531C8AB180DDDC5A39882520AB17E17EB3B7215F8727E5E36CB2E978
2980setup.exeC:\Users\admin\AppData\Local\Temp\Opera_installer_2506060904061802980.dllexecutable
MD5:E31627DA8871F8261D45C545E6E0F39A
SHA256:AC1EC373B6A0C95A421741CECF2C57E345F16BB0B5306009C870F2B35361D42A
5960setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419binary
MD5:9EEB646947E7C35CCC8557977E95E48D
SHA256:45CB600ADC975B920C3EEBF9042B7753E1B96B8C557A98558525D8B29FA79995
5960setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8binary
MD5:1FBB37F79B317A9A248E7C4CE4F5BAC5
SHA256:9BF639C595FE335B6F694EE35990BEFD2123F5E07FD1973FF619E3FC88F5F49F
5960setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8binary
MD5:69B3F133FD248CBE855171618BEA90CD
SHA256:A48EFC516A878A55075852224920624051DB6ED76876E1116A1ACC7548902302
5960setup.exeC:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports\settings.datbinary
MD5:D03425DC66790EE3A4F52AD42DFCEC9D
SHA256:1D1E432BC6EB0CB04E8C54E19A6E5FFA9B64F36F433DF40319DD0A6C18814856
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
42
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5960
setup.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
whitelisted
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5960
setup.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
unknown
whitelisted
5960
setup.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnxLiz3Fu1WB6n1%2FE6xWn1b0jXiQQUdIWAwGbH3zfez70pN6oDHb7tzRcCEA17ZgsSl63KHstWnAbUez0%3D
unknown
whitelisted
5960
setup.exe
GET
200
142.250.185.131:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
5960
setup.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAsA6S1NbXMfyjBZx8seGIY%3D
unknown
whitelisted
5960
setup.exe
GET
200
142.250.185.131:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4608
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
472
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
20.190.159.71:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5960
setup.exe
82.145.216.19:443
autoupdate.opera.com
Opera Software AS
NO
whitelisted
5960
setup.exe
82.145.217.121:443
desktop-netinstaller-sub.osp.opera.software
Opera Software AS
NO
whitelisted
5960
setup.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.184.206
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
desktop-netinstaller-sub.osp.opera.software
  • 82.145.217.121
whitelisted
autoupdate.opera.com
  • 82.145.216.19
  • 82.145.216.46
  • 82.145.216.47
  • 82.145.216.20
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
features.opera-api2.com
  • 82.145.216.16
  • 82.145.216.15
  • 82.145.216.59
  • 82.145.216.58
malicious
api.config.opr.gg
  • 104.18.25.17
  • 104.18.24.17
unknown
c.pki.goog
  • 142.250.185.131
whitelisted
download.opera.com
  • 82.145.216.23
  • 82.145.216.49
  • 82.145.216.48
  • 82.145.216.24
whitelisted

Threats

No threats detected
No debug info