File name:

OperaGXSetup.exe

Full analysis: https://app.any.run/tasks/9cd8001b-64a9-4f67-ac65-f6d5f60ae22d
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: August 11, 2024, 18:37:45
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
stealer
crypto-regex
ai-domain
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

EC2309C2F7E08AB8D0D48FEEB83A4BA1

SHA1:

3C9EA72A94BAE181A8E03F0848B192AAB62E9BDD

SHA256:

E10BD5C22D6099474EEF78A06B2675539F32F0FF6956721C984C56674A67627E

SSDEEP:

98304:0wyWSeMgtDPSookXf7Y0LiryIgVhO0GvMjmGoAcVgShPcOAIVI4JuIXa1B9U0gQi:0Z/LCPwh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • opera.exe (PID: 2064)
    • Actions looks like stealing of personal data

      • opera.exe (PID: 2064)
    • Steals credentials from Web Browsers

      • opera.exe (PID: 2064)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • OperaGXSetup.exe (PID: 6420)
      • setup.exe (PID: 6476)
      • setup.exe (PID: 6528)
      • setup.exe (PID: 6628)
      • setup.exe (PID: 6924)
      • Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe (PID: 420)
      • setup.exe (PID: 6948)
      • installer.exe (PID: 5744)
      • installer.exe (PID: 6148)
      • installer.exe (PID: 8256)
      • installer.exe (PID: 8548)
      • opera_autoupdate.exe (PID: 8176)
      • installer.exe (PID: 8388)
      • opera.exe (PID: 7164)
    • Drops the executable file immediately after the start

      • OperaGXSetup.exe (PID: 6420)
      • setup.exe (PID: 6528)
      • setup.exe (PID: 6476)
      • setup.exe (PID: 6628)
      • setup.exe (PID: 6924)
      • Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe (PID: 420)
      • setup.exe (PID: 6948)
      • installer.exe (PID: 6148)
      • installer.exe (PID: 5744)
      • installer.exe (PID: 8256)
      • installer.exe (PID: 8548)
      • opera_autoupdate.exe (PID: 8176)
      • installer.exe (PID: 8388)
      • opera.exe (PID: 7164)
    • Application launched itself

      • setup.exe (PID: 6476)
      • setup.exe (PID: 6924)
      • assistant_installer.exe (PID: 5116)
      • installer.exe (PID: 6148)
      • opera.exe (PID: 2064)
      • opera_autoupdate.exe (PID: 8176)
      • opera_autoupdate.exe (PID: 7952)
      • installer.exe (PID: 8256)
    • Starts itself from another location

      • setup.exe (PID: 6476)
    • Reads security settings of Internet Explorer

      • setup.exe (PID: 6476)
      • installer.exe (PID: 6148)
      • opera.exe (PID: 8096)
    • Checks Windows Trust Settings

      • setup.exe (PID: 6476)
    • Searches for installed software

      • installer.exe (PID: 6148)
    • Reads the date of Windows installation

      • installer.exe (PID: 6148)
      • opera.exe (PID: 2064)
    • Creates a software uninstall entry

      • installer.exe (PID: 6148)
    • Reads Mozilla Firefox installation path

      • opera.exe (PID: 2064)
    • The process executes via Task Scheduler

      • opera_autoupdate.exe (PID: 8176)
    • Connects to unusual port

      • opera.exe (PID: 4436)
    • Found regular expressions for crypto-addresses (YARA)

      • opera.exe (PID: 460)
      • opera.exe (PID: 4436)
      • opera.exe (PID: 2064)
  • INFO

    • Create files in a temporary directory

      • setup.exe (PID: 6476)
      • OperaGXSetup.exe (PID: 6420)
      • setup.exe (PID: 6528)
      • setup.exe (PID: 6628)
      • setup.exe (PID: 6924)
      • setup.exe (PID: 6948)
      • Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe (PID: 420)
      • installer.exe (PID: 6148)
      • installer.exe (PID: 5744)
      • opera.exe (PID: 2064)
      • installer.exe (PID: 8256)
      • installer.exe (PID: 8548)
      • opera_autoupdate.exe (PID: 8176)
      • installer.exe (PID: 8388)
    • Checks supported languages

      • OperaGXSetup.exe (PID: 6420)
      • setup.exe (PID: 6476)
      • setup.exe (PID: 6528)
      • setup.exe (PID: 6628)
      • setup.exe (PID: 6924)
      • Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe (PID: 420)
      • setup.exe (PID: 6948)
      • assistant_installer.exe (PID: 5116)
      • assistant_installer.exe (PID: 6028)
      • installer.exe (PID: 5744)
      • installer.exe (PID: 6148)
      • opera_crashreporter.exe (PID: 6684)
      • opera.exe (PID: 2064)
      • opera.exe (PID: 460)
      • opera.exe (PID: 4436)
      • opera.exe (PID: 6324)
      • opera.exe (PID: 6964)
      • opera.exe (PID: 1116)
      • opera_gx_splash.exe (PID: 1236)
      • opera.exe (PID: 6816)
      • opera.exe (PID: 6396)
      • opera.exe (PID: 6140)
      • opera.exe (PID: 1164)
      • opera.exe (PID: 6724)
      • opera.exe (PID: 6868)
      • opera.exe (PID: 7084)
      • opera.exe (PID: 7012)
      • opera.exe (PID: 6664)
      • opera.exe (PID: 5464)
      • opera.exe (PID: 6928)
      • opera.exe (PID: 6588)
      • opera.exe (PID: 6480)
      • opera.exe (PID: 5744)
      • opera.exe (PID: 1664)
      • opera.exe (PID: 6920)
      • opera.exe (PID: 6476)
      • opera.exe (PID: 1536)
      • opera.exe (PID: 6560)
      • opera.exe (PID: 3036)
      • opera.exe (PID: 7200)
      • opera.exe (PID: 7232)
      • opera.exe (PID: 7216)
      • opera.exe (PID: 7240)
      • opera.exe (PID: 7256)
      • opera.exe (PID: 7248)
      • opera.exe (PID: 7264)
      • opera.exe (PID: 7208)
      • opera.exe (PID: 7272)
      • opera.exe (PID: 7224)
      • opera.exe (PID: 7296)
      • opera.exe (PID: 7284)
      • opera.exe (PID: 7320)
      • opera.exe (PID: 7344)
      • opera.exe (PID: 7328)
      • opera.exe (PID: 7336)
      • opera.exe (PID: 7352)
      • opera.exe (PID: 7432)
      • opera.exe (PID: 7608)
      • opera.exe (PID: 8000)
      • opera.exe (PID: 7632)
      • opera.exe (PID: 7760)
      • opera.exe (PID: 7484)
      • opera.exe (PID: 7976)
      • opera.exe (PID: 8016)
      • opera.exe (PID: 7928)
      • opera.exe (PID: 7212)
      • opera.exe (PID: 7312)
      • opera.exe (PID: 7304)
      • opera.exe (PID: 7508)
      • opera.exe (PID: 7528)
      • opera.exe (PID: 7520)
      • opera.exe (PID: 8116)
      • opera.exe (PID: 8092)
      • opera_autoupdate.exe (PID: 7952)
      • opera_autoupdate.exe (PID: 7512)
      • opera_autoupdate.exe (PID: 8176)
      • opera.exe (PID: 8288)
      • opera_autoupdate.exe (PID: 7316)
      • opera.exe (PID: 8264)
      • opera.exe (PID: 1452)
      • installer.exe (PID: 8256)
      • opera.exe (PID: 8984)
      • opera.exe (PID: 8908)
      • installer.exe (PID: 8548)
      • opera.exe (PID: 8740)
      • opera.exe (PID: 8776)
      • opera.exe (PID: 8816)
      • opera.exe (PID: 8856)
      • opera.exe (PID: 8864)
      • opera.exe (PID: 8976)
      • opera.exe (PID: 9076)
      • opera.exe (PID: 9128)
      • installer.exe (PID: 8388)
      • opera.exe (PID: 8436)
      • opera.exe (PID: 7796)
      • opera.exe (PID: 7744)
      • opera.exe (PID: 7644)
      • opera.exe (PID: 8096)
      • opera.exe (PID: 6396)
      • opera.exe (PID: 8144)
      • opera.exe (PID: 7252)
      • opera.exe (PID: 6916)
      • opera.exe (PID: 7000)
      • opera.exe (PID: 6624)
      • opera.exe (PID: 6008)
      • opera.exe (PID: 7676)
      • opera.exe (PID: 7848)
      • opera.exe (PID: 7284)
      • opera.exe (PID: 8048)
      • opera.exe (PID: 8432)
      • opera.exe (PID: 7932)
      • opera.exe (PID: 7228)
      • opera.exe (PID: 7788)
      • opera.exe (PID: 7164)
      • opera.exe (PID: 8772)
      • opera.exe (PID: 8804)
    • Reads the computer name

      • setup.exe (PID: 6476)
      • setup.exe (PID: 6924)
      • assistant_installer.exe (PID: 5116)
      • installer.exe (PID: 6148)
      • opera.exe (PID: 2064)
      • opera.exe (PID: 460)
      • opera.exe (PID: 4436)
      • opera_gx_splash.exe (PID: 1236)
      • opera.exe (PID: 6920)
      • opera.exe (PID: 5744)
      • opera_autoupdate.exe (PID: 7952)
      • opera_autoupdate.exe (PID: 8176)
      • installer.exe (PID: 8256)
      • opera.exe (PID: 8096)
      • opera.exe (PID: 8772)
    • Creates files or folders in the user directory

      • setup.exe (PID: 6476)
      • setup.exe (PID: 6528)
      • installer.exe (PID: 6148)
      • setup.exe (PID: 6924)
      • opera.exe (PID: 2064)
      • opera.exe (PID: 4436)
      • opera_autoupdate.exe (PID: 8176)
      • opera.exe (PID: 8096)
      • opera.exe (PID: 8772)
    • Checks proxy server information

      • setup.exe (PID: 6476)
      • opera.exe (PID: 2064)
      • opera_autoupdate.exe (PID: 7952)
      • opera_autoupdate.exe (PID: 8176)
      • opera.exe (PID: 8096)
    • Reads the machine GUID from the registry

      • setup.exe (PID: 6476)
      • opera.exe (PID: 2064)
      • opera_autoupdate.exe (PID: 7952)
      • opera_autoupdate.exe (PID: 8176)
      • opera_autoupdate.exe (PID: 7512)
      • opera_autoupdate.exe (PID: 7316)
      • opera.exe (PID: 8772)
    • Reads the software policy settings

      • setup.exe (PID: 6476)
    • Process checks computer location settings

      • opera.exe (PID: 2064)
      • opera.exe (PID: 1116)
      • opera.exe (PID: 6816)
      • opera.exe (PID: 1664)
      • opera.exe (PID: 7084)
      • opera.exe (PID: 6868)
      • opera.exe (PID: 6928)
      • opera.exe (PID: 6588)
      • opera.exe (PID: 6476)
      • opera.exe (PID: 3036)
      • opera.exe (PID: 6480)
      • opera.exe (PID: 1536)
      • opera.exe (PID: 6560)
      • opera.exe (PID: 7352)
      • opera.exe (PID: 7344)
      • opera.exe (PID: 1452)
      • opera.exe (PID: 8984)
      • opera.exe (PID: 9128)
      • opera.exe (PID: 7932)
      • opera.exe (PID: 8048)
    • The process uses the downloaded file

      • opera.exe (PID: 8096)
      • opera.exe (PID: 2064)
    • Reads CPU info

      • opera.exe (PID: 2064)
    • May use AI service

      • opera.exe (PID: 460)
      • opera.exe (PID: 4436)
      • opera.exe (PID: 2064)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:06:12 14:59:19+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.39
CodeSize: 238080
InitializedDataSize: 92672
UninitializedDataSize: -
EntryPoint: 0x213c0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 112.0.5197.60
ProductVersionNumber: 112.0.5197.60
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
FileVersion: 112.0.5197.60
ProductVersion: 112.0.5197.60
FileDescription: Opera installer SFX
CompanyName:
LegalCopyright: Opera Software 2024
Productname: Opera installer
Stream: Stable
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
256
Monitored processes
118
Malicious processes
7
Suspicious processes
2

Behavior graph

Click at the process to see the details
start operagxsetup.exe setup.exe setup.exe setup.exe setup.exe setup.exe opera_gx_assistant_73.0.3856.382_setup.exe_sfx.exe assistant_installer.exe assistant_installer.exe no specs installer.exe installer.exe UIAutomationCrossBitnessHook32 Class no specs THREAT opera.exe opera_crashreporter.exe no specs THREAT opera.exe no specs THREAT opera.exe opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera_gx_splash.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs comppkgsrv.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera_autoupdate.exe opera.exe no specs opera_autoupdate.exe opera_autoupdate.exe no specs opera_autoupdate.exe no specs installer.exe opera.exe no specs opera.exe no specs installer.exe opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs installer.exe opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe opera.exe no specs opera.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
420"C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202408111837541\assistant\Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe"C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202408111837541\assistant\Opera_GX_assistant_73.0.3856.382_Setup.exe_sfx.exe
setup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Opera installer SFX
Exit code:
0
Version:
73.0.3856.382
Modules
Images
c:\users\admin\appdata\local\temp\.opera\opera gx installer temp\opera_package_202408111837541\assistant\opera_gx_assistant_73.0.3856.382_setup.exe_sfx.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
460"C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe" --type=gpu-process --start-stack-profiler --with-feature:cashback-assistant=on --with-feature:address-bar-dropdown-autocompleted-domains=off --with-feature:address-bar-dropdown-unfiltered-full=off --with-feature:amazon-new-ids=on --with-feature:cashback-assistant=on --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-structured-partners=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:game-servers=off --with-feature:gx-post-mortem=on --with-feature:gx-reactinator=on --with-feature:gx-spotlight=on --with-feature:gx-video-to-phone=on --with-feature:in-house-autocomplete-send=on --with-feature:lucid-mode-hide-text=on --with-feature:panic-button=on --with-feature:password-generator=off --with-feature:play-again=on --with-feature:run-at-startup-default=on --with-feature:sd-suggestions-external=on --with-feature:session-restore-attribution=on --with-feature:side-profiles=on --with-feature:sitecheck-age=on --with-feature:tiktok-panel=on --with-feature:ui-compositor-multithreaded=on --with-feature:installer-experiment-test=off --with-feature:installer-bypass-launcher=on --ab_tests=GXCTest50-test:DNA-99214_GXCTest50 --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAEAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --field-trial-handle=1840,i,2652411095046580629,17912505256702664292,262144 --disable-features=CertificateTransparencyAskBeforeEnabling --variations-seed-version --mojo-platform-channel-handle=1836 /prefetch:2C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe
opera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera GX Internet Browser
Version:
112.0.5197.60
Modules
Images
c:\users\admin\appdata\local\programs\opera gx\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\programs\opera gx\112.0.5197.60\opera_elf.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shcore.dll
1116"C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe" --type=renderer --user-agent="Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 OPR/112.0.0.0 (Edition std-2)" --with-feature:cashback-assistant=on --with-feature:address-bar-dropdown-autocompleted-domains=off --with-feature:address-bar-dropdown-unfiltered-full=off --with-feature:amazon-new-ids=on --with-feature:cashback-assistant=on --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-structured-partners=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:game-servers=off --with-feature:gx-post-mortem=on --with-feature:gx-reactinator=on --with-feature:gx-spotlight=on --with-feature:gx-video-to-phone=on --with-feature:in-house-autocomplete-send=on --with-feature:lucid-mode-hide-text=on --with-feature:panic-button=on --with-feature:password-generator=off --with-feature:play-again=on --with-feature:run-at-startup-default=on --with-feature:sd-suggestions-external=on --with-feature:session-restore-attribution=on --with-feature:side-profiles=on --with-feature:sitecheck-age=on --with-feature:tiktok-panel=on --with-feature:ui-compositor-multithreaded=on --with-feature:installer-experiment-test=off --with-feature:installer-bypass-launcher=on --ab_tests=GXCTest50-test:DNA-99214_GXCTest50 --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=11 --field-trial-handle=3580,i,2652411095046580629,17912505256702664292,262144 --disable-features=CertificateTransparencyAskBeforeEnabling --variations-seed-version --mojo-platform-channel-handle=3592 /prefetch:1C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera GX Internet Browser
Exit code:
0
Version:
112.0.5197.60
Modules
Images
c:\users\admin\appdata\local\programs\opera gx\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\programs\opera gx\112.0.5197.60\opera_elf.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
1164"C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --enable-quic --with-feature:cashback-assistant=on --with-feature:address-bar-dropdown-autocompleted-domains=off --with-feature:address-bar-dropdown-unfiltered-full=off --with-feature:amazon-new-ids=on --with-feature:cashback-assistant=on --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-structured-partners=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:game-servers=off --with-feature:gx-post-mortem=on --with-feature:gx-reactinator=on --with-feature:gx-spotlight=on --with-feature:gx-video-to-phone=on --with-feature:in-house-autocomplete-send=on --with-feature:lucid-mode-hide-text=on --with-feature:panic-button=on --with-feature:password-generator=off --with-feature:play-again=on --with-feature:run-at-startup-default=on --with-feature:sd-suggestions-external=on --with-feature:session-restore-attribution=on --with-feature:side-profiles=on --with-feature:sitecheck-age=on --with-feature:tiktok-panel=on --with-feature:ui-compositor-multithreaded=on --with-feature:installer-experiment-test=off --with-feature:installer-bypass-launcher=on --ab_tests=GXCTest50-test:DNA-99214_GXCTest50 --field-trial-handle=3096,i,2652411095046580629,17912505256702664292,262144 --disable-features=CertificateTransparencyAskBeforeEnabling --variations-seed-version --mojo-platform-channel-handle=3232 /prefetch:8C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera GX Internet Browser
Exit code:
0
Version:
112.0.5197.60
Modules
Images
c:\users\admin\appdata\local\programs\opera gx\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\programs\opera gx\112.0.5197.60\opera_elf.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shcore.dll
1236"C:\Users\admin\AppData\Local\Programs\Opera GX\112.0.5197.60\opera_gx_splash.exe" --instance-name=5dd08f40413fd477cb25fa615ff02371C:\Users\admin\AppData\Local\Programs\Opera GX\112.0.5197.60\opera_gx_splash.exeopera.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\programs\opera gx\112.0.5197.60\opera_gx_splash.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1452"C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe" --type=renderer --extension-process --user-agent="Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 OPR/112.0.0.0 (Edition std-2)" --with-feature:cashback-assistant=on --with-feature:address-bar-dropdown-autocompleted-domains=off --with-feature:address-bar-dropdown-unfiltered-full=off --with-feature:amazon-new-ids=on --with-feature:cashback-assistant=on --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-structured-partners=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:game-servers=off --with-feature:gx-post-mortem=on --with-feature:gx-reactinator=on --with-feature:gx-spotlight=on --with-feature:gx-video-to-phone=on --with-feature:in-house-autocomplete-send=on --with-feature:lucid-mode-hide-text=on --with-feature:panic-button=on --with-feature:password-generator=off --with-feature:play-again=on --with-feature:run-at-startup-default=on --with-feature:sd-suggestions-external=on --with-feature:session-restore-attribution=on --with-feature:side-profiles=on --with-feature:sitecheck-age=on --with-feature:tiktok-panel=on --with-feature:ui-compositor-multithreaded=on --with-feature:installer-experiment-test=off --with-feature:installer-bypass-launcher=on --ab_tests=GXCTest50-test:DNA-99214_GXCTest50 --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=28 --field-trial-handle=5616,i,2652411095046580629,17912505256702664292,262144 --disable-features=CertificateTransparencyAskBeforeEnabling --variations-seed-version --mojo-platform-channel-handle=7524 /prefetch:2C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera GX Internet Browser
Exit code:
0
Version:
112.0.5197.60
Modules
Images
c:\users\admin\appdata\local\programs\opera gx\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\programs\opera gx\112.0.5197.60\opera_elf.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
1536"C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe" --type=renderer --extension-process --user-agent="Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 OPR/112.0.0.0 (Edition std-2)" --with-feature:cashback-assistant=on --with-feature:address-bar-dropdown-autocompleted-domains=off --with-feature:address-bar-dropdown-unfiltered-full=off --with-feature:amazon-new-ids=on --with-feature:cashback-assistant=on --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-structured-partners=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:game-servers=off --with-feature:gx-post-mortem=on --with-feature:gx-reactinator=on --with-feature:gx-spotlight=on --with-feature:gx-video-to-phone=on --with-feature:in-house-autocomplete-send=on --with-feature:lucid-mode-hide-text=on --with-feature:panic-button=on --with-feature:password-generator=off --with-feature:play-again=on --with-feature:run-at-startup-default=on --with-feature:sd-suggestions-external=on --with-feature:session-restore-attribution=on --with-feature:side-profiles=on --with-feature:sitecheck-age=on --with-feature:tiktok-panel=on --with-feature:ui-compositor-multithreaded=on --with-feature:installer-experiment-test=off --with-feature:installer-bypass-launcher=on --ab_tests=GXCTest50-test:DNA-99214_GXCTest50 --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=23 --field-trial-handle=6720,i,2652411095046580629,17912505256702664292,262144 --disable-features=CertificateTransparencyAskBeforeEnabling --variations-seed-version --mojo-platform-channel-handle=6888 /prefetch:2C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera GX Internet Browser
Exit code:
0
Version:
112.0.5197.60
Modules
Images
c:\users\admin\appdata\local\programs\opera gx\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\programs\opera gx\112.0.5197.60\opera_elf.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
1664"C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe" --type=renderer --user-agent="Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 OPR/112.0.0.0 (Edition std-2)" --with-feature:cashback-assistant=on --with-feature:address-bar-dropdown-autocompleted-domains=off --with-feature:address-bar-dropdown-unfiltered-full=off --with-feature:amazon-new-ids=on --with-feature:cashback-assistant=on --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-structured-partners=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:game-servers=off --with-feature:gx-post-mortem=on --with-feature:gx-reactinator=on --with-feature:gx-spotlight=on --with-feature:gx-video-to-phone=on --with-feature:in-house-autocomplete-send=on --with-feature:lucid-mode-hide-text=on --with-feature:panic-button=on --with-feature:password-generator=off --with-feature:play-again=on --with-feature:run-at-startup-default=on --with-feature:sd-suggestions-external=on --with-feature:session-restore-attribution=on --with-feature:side-profiles=on --with-feature:sitecheck-age=on --with-feature:tiktok-panel=on --with-feature:ui-compositor-multithreaded=on --with-feature:installer-experiment-test=off --with-feature:installer-bypass-launcher=on --ab_tests=GXCTest50-test:DNA-99214_GXCTest50 --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=13 --field-trial-handle=4400,i,2652411095046580629,17912505256702664292,262144 --disable-features=CertificateTransparencyAskBeforeEnabling --variations-seed-version --mojo-platform-channel-handle=4412 /prefetch:1C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera GX Internet Browser
Version:
112.0.5197.60
Modules
Images
c:\users\admin\appdata\local\programs\opera gx\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\programs\opera gx\112.0.5197.60\opera_elf.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
2064"C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe" --start-maximizedC:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe
installer.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera GX Internet Browser
Version:
112.0.5197.60
Modules
Images
c:\users\admin\appdata\local\programs\opera gx\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\programs\opera gx\112.0.5197.60\opera_elf.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shcore.dll
3036"C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe" --type=renderer --extension-process --user-agent="Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 OPR/112.0.0.0 (Edition std-2)" --with-feature:cashback-assistant=on --with-feature:address-bar-dropdown-autocompleted-domains=off --with-feature:address-bar-dropdown-unfiltered-full=off --with-feature:amazon-new-ids=on --with-feature:cashback-assistant=on --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-structured-partners=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:game-servers=off --with-feature:gx-post-mortem=on --with-feature:gx-reactinator=on --with-feature:gx-spotlight=on --with-feature:gx-video-to-phone=on --with-feature:in-house-autocomplete-send=on --with-feature:lucid-mode-hide-text=on --with-feature:panic-button=on --with-feature:password-generator=off --with-feature:play-again=on --with-feature:run-at-startup-default=on --with-feature:sd-suggestions-external=on --with-feature:session-restore-attribution=on --with-feature:side-profiles=on --with-feature:sitecheck-age=on --with-feature:tiktok-panel=on --with-feature:ui-compositor-multithreaded=on --with-feature:installer-experiment-test=off --with-feature:installer-bypass-launcher=on --ab_tests=GXCTest50-test:DNA-99214_GXCTest50 --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=24 --field-trial-handle=7188,i,2652411095046580629,17912505256702664292,262144 --disable-features=CertificateTransparencyAskBeforeEnabling --variations-seed-version --mojo-platform-channel-handle=7196 /prefetch:2C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera GX Internet Browser
Exit code:
0
Version:
112.0.5197.60
Modules
Images
c:\users\admin\appdata\local\programs\opera gx\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\programs\opera gx\112.0.5197.60\opera_elf.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
Total events
32 971
Read events
31 516
Write events
1 436
Delete events
19

Modification events

(PID) Process:(6476) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6476) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6476) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(6476) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6476) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6476) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6476) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(6924) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Opera Software
Operation:writeName:Last Opera GX Stable Install Path
Value:
C:\Users\admin\AppData\Local\Programs\Opera GX\
(PID) Process:(6148) installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Opera Software
Operation:writeName:Last Opera GX Stable Install Path
Value:
C:\Users\admin\AppData\Local\Programs\Opera GX\
(PID) Process:(6148) installer.exeKey:HKEY_CLASSES_ROOT\Opera GXStable
Operation:writeName:FriendlyTypeName
Value:
Opera GX Web Document
Executable files
27
Suspicious files
735
Text files
528
Unknown types
67

Dropped files

PID
Process
Filename
Type
6528setup.exeC:\Users\admin\AppData\Local\Temp\Opera_installer_2408111837535716528.dllexecutable
MD5:1E6485E90130BB0CFFD2AE2CA7FEF2A2
SHA256:907CB59383443CE62FDCD2EB90E4BF32CF3A0DE6078E708F694DFC7BD7166B5B
6476setup.exeC:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable\Crash Reports\settings.datbinary
MD5:8748DEBF0EE1AF9233CF98990D00F1D8
SHA256:2B8741FDF23220826E561992485BFC0AD1891A14DACD41DB24BB7BE1B65C9017
6476setup.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\AH8CR9J5\Opera_GX_112.0.5197.60_Autoupdate_x64[1].exe
MD5:
SHA256:
6476setup.exeC:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202408111837541\opera_package
MD5:
SHA256:
6420OperaGXSetup.exeC:\Users\admin\AppData\Local\Temp\7zS4190063E\setup.exeexecutable
MD5:607FB47AD9D20BB16F90E4A38C93BBFE
SHA256:8A82AE5C857123CC6972B93828F3A6202C0DB4D325EA6D5B1E36DCFB290C1E09
6628setup.exeC:\Users\admin\AppData\Local\Temp\Opera_installer_2408111837540716628.dllexecutable
MD5:1E6485E90130BB0CFFD2AE2CA7FEF2A2
SHA256:907CB59383443CE62FDCD2EB90E4BF32CF3A0DE6078E708F694DFC7BD7166B5B
6476setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419der
MD5:0ED88438AB23359FB43D8ED172FE4810
SHA256:6B17D4ECE9B51144B82FA6BA7604D8043EB68B199EA428C790024726A0F7EB00
6476setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8binary
MD5:410701B94BAFFA84746AA1E8D5F53505
SHA256:B1B8174B9A6A0D8D48C7E90FA2E57BAFD37BCE9AE0FE2BB3A3E85C1E873DBEE5
6476setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419binary
MD5:BB2DC30AC0A4E924C74DA7E43DBAD426
SHA256:4ECAE486C2D1D8521BFD3975E869E5321A3C552466BA7FCF0585967CC0539DE0
6476setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12der
MD5:7FB5FA1534DCF77F2125B2403B30A0EE
SHA256:33A39E9EC2133230533A686EC43760026E014A3828C703707ACBC150FE40FD6F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
31
TCP/UDP connections
159
DNS requests
136
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6476
setup.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
unknown
whitelisted
6476
setup.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnxLiz3Fu1WB6n1%2FE6xWn1b0jXiQQUdIWAwGbH3zfez70pN6oDHb7tzRcCEAfyOr5A1UWlCmQhXhy%2Bwwk%3D
unknown
whitelisted
6476
setup.exe
GET
200
216.58.206.67:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
6476
setup.exe
GET
200
216.58.206.67:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
6476
setup.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAsA6S1NbXMfyjBZx8seGIY%3D
unknown
whitelisted
6476
setup.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
unknown
whitelisted
2456
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6476
setup.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEA55q9FkBjzsPoBm2GCDxI4%3D
unknown
whitelisted
4008
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adwnx6ioy2mddvi5spvpvunsztxq_3038/jflookgnkcckhobaglndicnbbgbonegd_3038_all_cqlrbk2m45u6pnxawsb34vvfla.crx3
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4016
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3888
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
3904
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
6476
setup.exe
82.145.217.121:443
desktop-netinstaller-sub.osp.opera.software
Opera Software AS
NO
unknown
6476
setup.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
6476
setup.exe
185.26.182.123:443
autoupdate.geo.opera.com
Opera Software AS
unknown
6476
setup.exe
185.26.182.111:443
features.opera-api2.com
Opera Software AS
whitelisted
6476
setup.exe
104.18.25.17:443
api.config.opr.gg
CLOUDFLARENET
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 20.73.194.208
  • 4.231.128.59
whitelisted
google.com
  • 172.217.16.206
whitelisted
desktop-netinstaller-sub.osp.opera.software
  • 82.145.217.121
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
autoupdate.geo.opera.com
  • 185.26.182.123
  • 185.26.182.124
  • 82.145.216.19
  • 82.145.216.20
whitelisted
features.opera-api2.com
  • 185.26.182.111
  • 185.26.182.93
  • 185.26.182.112
  • 185.26.182.118
  • 185.26.182.94
  • 185.26.182.106
  • 82.145.216.16
  • 82.145.216.15
malicious
api.config.opr.gg
  • 104.18.25.17
  • 104.18.24.17
unknown
c.pki.goog
  • 216.58.206.67
whitelisted
download.opera.com
  • 82.145.216.24
  • 82.145.216.23
whitelisted
download5.operacdn.com
  • 104.18.10.89
  • 104.18.11.89
malicious

Threats

No threats detected
Process
Message
assistant_installer.exe
[0811/183919.022:INFO:assistant_installer_main.cc(169)] Running assistant installer with command line "C:\Users\admin\AppData\Local\Temp\.opera\Opera GX Installer Temp\opera_package_202408111837541\assistant\assistant_installer.exe" --version