File name:

OperaSetup.exe

Full analysis: https://app.any.run/tasks/a0cba891-378a-4766-b06e-2426bf31f571
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: November 24, 2024, 06:48:29
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
stealer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

15F5F9FE9173CEB7FEE527522625D77E

SHA1:

41975F44A1B31B87B328090625BB9328D834D047

SHA256:

EE998C231F2FF22191502E248D610ACC910DA336CE693A7C0A1A24E1E033473C

SSDEEP:

98304:SwyWSeMgtTTuMGEf5puMfEhZ8Oa9MUglZU580e1RCVn+S5eYKMnDzOHbVwYZWXuF:S8fEF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • setup.exe (PID: 3796)
      • setup.exe (PID: 5732)
      • setup.exe (PID: 6428)
      • setup.exe (PID: 6452)
      • assistant_installer.exe (PID: 6816)
      • assistant_installer.exe (PID: 6836)
      • installer.exe (PID: 6912)
      • installer.exe (PID: 6936)
      • assistant_installer.exe (PID: 7136)
      • assistant_installer.exe (PID: 7160)
      • assistant_installer.exe (PID: 6176)
      • assistant_installer.exe (PID: 6224)
      • opera.exe (PID: 5964)
      • opera_crashreporter.exe (PID: 2008)
      • opera_crashreporter.exe (PID: 6296)
      • browser_assistant.exe (PID: 6268)
      • opera.exe (PID: 6572)
      • opera.exe (PID: 6744)
      • opera.exe (PID: 6264)
      • opera.exe (PID: 6740)
      • opera_crashreporter.exe (PID: 3744)
      • opera.exe (PID: 5696)
      • opera.exe (PID: 6828)
      • opera.exe (PID: 1572)
      • opera.exe (PID: 6900)
      • opera_crashreporter.exe (PID: 7088)
      • opera_crashreporter.exe (PID: 6164)
      • opera_crashreporter.exe (PID: 6816)
      • browser_assistant.exe (PID: 364)
      • opera.exe (PID: 6260)
      • opera_crashreporter.exe (PID: 5592)
    • Steals credentials from Web Browsers

      • setup.exe (PID: 3796)
      • setup.exe (PID: 5732)
      • setup.exe (PID: 6452)
      • assistant_installer.exe (PID: 6836)
      • assistant_installer.exe (PID: 6816)
      • setup.exe (PID: 6428)
      • installer.exe (PID: 6912)
      • installer.exe (PID: 6936)
      • assistant_installer.exe (PID: 7160)
      • assistant_installer.exe (PID: 7136)
      • assistant_installer.exe (PID: 6224)
      • assistant_installer.exe (PID: 6176)
      • opera.exe (PID: 5964)
      • opera_crashreporter.exe (PID: 2008)
      • opera_crashreporter.exe (PID: 6296)
      • opera.exe (PID: 6264)
      • opera_crashreporter.exe (PID: 3744)
      • opera.exe (PID: 6572)
      • opera_crashreporter.exe (PID: 6816)
      • opera.exe (PID: 6744)
      • opera_crashreporter.exe (PID: 7088)
      • opera.exe (PID: 6900)
      • opera.exe (PID: 1572)
      • browser_assistant.exe (PID: 6268)
      • opera_crashreporter.exe (PID: 6164)
      • browser_assistant.exe (PID: 364)
      • opera_crashreporter.exe (PID: 5592)
    • Changes the autorun value in the registry

      • assistant_installer.exe (PID: 7136)
      • opera.exe (PID: 6264)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • OperaSetup.exe (PID: 5548)
      • setup.exe (PID: 5732)
      • setup.exe (PID: 3796)
      • setup.exe (PID: 1688)
      • setup.exe (PID: 6428)
      • setup.exe (PID: 6452)
      • Assistant_114.0.5282.21_Setup.exe_sfx.exe (PID: 6780)
      • installer.exe (PID: 6936)
      • installer.exe (PID: 6912)
      • assistant_installer.exe (PID: 7136)
    • Application launched itself

      • setup.exe (PID: 3796)
      • setup.exe (PID: 6428)
      • assistant_installer.exe (PID: 6816)
      • installer.exe (PID: 6912)
      • assistant_installer.exe (PID: 6176)
      • assistant_installer.exe (PID: 7136)
      • browser_assistant.exe (PID: 6268)
      • opera.exe (PID: 6264)
      • opera.exe (PID: 1572)
    • Reads security settings of Internet Explorer

      • setup.exe (PID: 3796)
      • installer.exe (PID: 6912)
    • Starts itself from another location

      • setup.exe (PID: 3796)
    • Checks Windows Trust Settings

      • setup.exe (PID: 3796)
      • installer.exe (PID: 6912)
    • Process drops legitimate windows executable

      • Assistant_114.0.5282.21_Setup.exe_sfx.exe (PID: 6780)
      • assistant_installer.exe (PID: 7136)
    • Reads the date of Windows installation

      • installer.exe (PID: 6912)
    • Creates a software uninstall entry

      • installer.exe (PID: 6912)
    • Searches for installed software

      • installer.exe (PID: 6912)
  • INFO

    • Create files in a temporary directory

      • OperaSetup.exe (PID: 5548)
      • setup.exe (PID: 5732)
      • setup.exe (PID: 3796)
      • setup.exe (PID: 1688)
      • setup.exe (PID: 6428)
      • setup.exe (PID: 6452)
      • installer.exe (PID: 6912)
      • Assistant_114.0.5282.21_Setup.exe_sfx.exe (PID: 6780)
      • installer.exe (PID: 6936)
      • opera.exe (PID: 6264)
    • Checks supported languages

      • OperaSetup.exe (PID: 5548)
      • setup.exe (PID: 3796)
      • setup.exe (PID: 5732)
      • setup.exe (PID: 1688)
      • setup.exe (PID: 6428)
      • setup.exe (PID: 6452)
      • assistant_installer.exe (PID: 6816)
      • assistant_installer.exe (PID: 6836)
      • installer.exe (PID: 6912)
      • Assistant_114.0.5282.21_Setup.exe_sfx.exe (PID: 6780)
      • installer.exe (PID: 6936)
      • assistant_installer.exe (PID: 7136)
      • assistant_installer.exe (PID: 7160)
      • assistant_installer.exe (PID: 6176)
      • assistant_installer.exe (PID: 6224)
      • opera.exe (PID: 6264)
      • browser_assistant.exe (PID: 6268)
      • opera.exe (PID: 5964)
      • opera_crashreporter.exe (PID: 2008)
      • opera_crashreporter.exe (PID: 6296)
      • opera.exe (PID: 6572)
      • browser_assistant.exe (PID: 364)
      • opera_crashreporter.exe (PID: 3744)
      • opera.exe (PID: 6744)
      • opera.exe (PID: 6828)
      • opera.exe (PID: 6740)
      • opera.exe (PID: 5696)
      • opera.exe (PID: 6900)
      • opera.exe (PID: 1572)
      • opera_crashreporter.exe (PID: 7088)
      • opera_crashreporter.exe (PID: 6816)
      • opera.exe (PID: 6260)
      • opera_crashreporter.exe (PID: 5592)
      • opera_crashreporter.exe (PID: 6164)
    • Reads the computer name

      • setup.exe (PID: 3796)
      • setup.exe (PID: 6428)
      • assistant_installer.exe (PID: 6816)
      • installer.exe (PID: 6912)
      • assistant_installer.exe (PID: 6176)
      • assistant_installer.exe (PID: 7136)
      • opera.exe (PID: 6264)
      • opera.exe (PID: 5964)
      • browser_assistant.exe (PID: 6268)
      • opera.exe (PID: 6572)
      • opera.exe (PID: 6740)
      • opera.exe (PID: 5696)
      • opera.exe (PID: 1572)
      • opera.exe (PID: 6900)
      • opera.exe (PID: 6744)
      • opera.exe (PID: 6260)
    • Creates files or folders in the user directory

      • setup.exe (PID: 3796)
      • setup.exe (PID: 5732)
      • setup.exe (PID: 6428)
      • installer.exe (PID: 6912)
      • assistant_installer.exe (PID: 7136)
      • opera.exe (PID: 6264)
      • opera.exe (PID: 1572)
    • Reads the machine GUID from the registry

      • setup.exe (PID: 3796)
      • installer.exe (PID: 6912)
      • opera.exe (PID: 6264)
      • opera.exe (PID: 1572)
    • Reads the software policy settings

      • setup.exe (PID: 3796)
      • installer.exe (PID: 6912)
    • Checks proxy server information

      • setup.exe (PID: 3796)
      • opera.exe (PID: 6264)
      • opera.exe (PID: 1572)
    • Sends debugging messages

      • assistant_installer.exe (PID: 6816)
      • assistant_installer.exe (PID: 7136)
      • assistant_installer.exe (PID: 6176)
    • Manual execution by a user

      • assistant_installer.exe (PID: 6176)
    • Process checks computer location settings

      • opera.exe (PID: 6264)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:06:12 14:58:14+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.39
CodeSize: 238080
InitializedDataSize: 113152
UninitializedDataSize: -
EntryPoint: 0x213c0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 114.0.5282.222
ProductVersionNumber: 114.0.5282.222
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
FileVersion: 114.0.5282.222
ProductVersion: 114.0.5282.222
FileDescription: Opera installer SFX
CompanyName:
LegalCopyright: Opera Software 2024
Productname: Opera installer
Stream: Stable
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
198
Monitored processes
75
Malicious processes
29
Suspicious processes
3

Behavior graph

Click at the process to see the details
start operasetup.exe setup.exe setup.exe setup.exe setup.exe setup.exe assistant_114.0.5282.21_setup.exe_sfx.exe assistant_installer.exe assistant_installer.exe installer.exe installer.exe UIAutomationCrossBitnessHook32 Class no specs assistant_installer.exe assistant_installer.exe assistant_installer.exe assistant_installer.exe opera.exe browser_assistant.exe opera.exe opera_crashreporter.exe opera_crashreporter.exe browser_assistant.exe opera.exe opera.exe opera.exe opera_crashreporter.exe opera.exe opera.exe opera_crashreporter.exe opera.exe opera.exe opera_crashreporter.exe opera_crashreporter.exe opera.exe opera_crashreporter.exe opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera_gx_splash.exe no specs unsecapp.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
364C:\Users\admin\AppData\Local\Programs\Opera\assistant\browser_assistant.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktop --annotation=ver=114.0.5282.21 --initial-client-data=0x290,0x294,0x298,0x26c,0x29c,0xd0da50,0xd0da5c,0xd0da68C:\Users\admin\AppData\Local\Programs\Opera\assistant\browser_assistant.exe
browser_assistant.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera Browser Assistant
Version:
114.0.5282.21
Modules
Images
c:\users\admin\appdata\local\programs\opera\assistant\browser_assistant.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1488"C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --enable-quic --with-feature:cashback-assistant=on --with-feature:address-bar-dropdown-autocompleted-domains=on --with-feature:address-bar-dropdown-cities=on --with-feature:address-bar-dropdown-keyword-ads=on --with-feature:address-bar-keywords-monetization=on --with-feature:amazon-new-ids=on --with-feature:amp-requests-stats=on --with-feature:aria-command-line-in-extension=on --with-feature:aria-command-line-react=on --with-feature:capital-one-cashback-protection=on --with-feature:cashback-assistant=on --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-cms-configuration=on --with-feature:continue-shopping-explore=off --with-feature:continue-shopping-structured-partners=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:lucid-mode-hide-text=on --with-feature:native-crypto-wallet=on --with-feature:opera-startpage-special=on --with-feature:password-generator=off --with-feature:proxy-switcher-ui-default-visible=on --with-feature:realtime-impressions-reporting=on --with-feature:sd-suggestions-external=on --with-feature:session-restore-attribution=on --with-feature:shopping-corner=on --with-feature:sitecheck-age=on --with-feature:specific-keywords=on --with-feature:startpage-content-phase-1=off --with-feature:startpage-opening-animation=off --with-feature:startpage-sync-banner-ref=on --with-feature:installer-experiment-test=off --with-feature:installer-bypass-launcher=on --field-trial-handle=6244,i,822286292445418201,1747623319583521571,262144 --disable-features=CertificateTransparencyAskBeforeEnabling --variations-seed-version --mojo-platform-channel-handle=7584 /prefetch:8C:\Users\admin\AppData\Local\Programs\Opera\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Version:
114.0.5282.222
1572"C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --show-intro-overlay --start-maximizedC:\Users\admin\AppData\Local\Programs\Opera\opera.exe
installer.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera Internet Browser
Version:
114.0.5282.222
Modules
Images
c:\users\admin\appdata\local\programs\opera\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1576"C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --type=renderer --with-feature:cashback-assistant=on --with-feature:address-bar-dropdown-autocompleted-domains=on --with-feature:address-bar-dropdown-cities=on --with-feature:address-bar-dropdown-keyword-ads=on --with-feature:address-bar-keywords-monetization=on --with-feature:amazon-new-ids=on --with-feature:amp-requests-stats=on --with-feature:aria-command-line-in-extension=on --with-feature:aria-command-line-react=on --with-feature:capital-one-cashback-protection=on --with-feature:cashback-assistant=on --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-cms-configuration=on --with-feature:continue-shopping-explore=off --with-feature:continue-shopping-structured-partners=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:lucid-mode-hide-text=on --with-feature:native-crypto-wallet=on --with-feature:opera-startpage-special=on --with-feature:password-generator=off --with-feature:proxy-switcher-ui-default-visible=on --with-feature:realtime-impressions-reporting=on --with-feature:sd-suggestions-external=on --with-feature:session-restore-attribution=on --with-feature:shopping-corner=on --with-feature:sitecheck-age=on --with-feature:specific-keywords=on --with-feature:startpage-content-phase-1=off --with-feature:startpage-opening-animation=off --with-feature:startpage-sync-banner-ref=on --with-feature:installer-experiment-test=off --with-feature:installer-bypass-launcher=on --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=12 --field-trial-handle=3876,i,822286292445418201,1747623319583521571,262144 --disable-features=CertificateTransparencyAskBeforeEnabling --variations-seed-version --mojo-platform-channel-handle=3888 /prefetch:1C:\Users\admin\AppData\Local\Programs\Opera\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Version:
114.0.5282.222
1688"C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exe" --versionC:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exe
setup.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\.opera\opera installer temp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
2008C:\Users\admin\AppData\Local\Programs\Opera\114.0.5282.222\opera_crashreporter.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win64 --annotation=prod=OperaDesktop --annotation=ver=114.0.5282.222 --initial-client-data=0x2a8,0x2ac,0x2b0,0x2a4,0x2b4,0x7ff816f2f700,0x7ff816f2f710,0x7ff816f2f720C:\Users\admin\AppData\Local\Programs\Opera\114.0.5282.222\opera_crashreporter.exe
opera.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera crash-reporter
Exit code:
0
Version:
114.0.5282.222
Modules
Images
c:\users\admin\appdata\local\programs\opera\114.0.5282.222\opera_crashreporter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2008"C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --enable-quic --with-feature:cashback-assistant=on --with-feature:address-bar-dropdown-autocompleted-domains=on --with-feature:address-bar-dropdown-cities=on --with-feature:address-bar-dropdown-keyword-ads=on --with-feature:address-bar-keywords-monetization=on --with-feature:amazon-new-ids=on --with-feature:amp-requests-stats=on --with-feature:aria-command-line-in-extension=on --with-feature:aria-command-line-react=on --with-feature:capital-one-cashback-protection=on --with-feature:cashback-assistant=on --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-cms-configuration=on --with-feature:continue-shopping-explore=off --with-feature:continue-shopping-structured-partners=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:lucid-mode-hide-text=on --with-feature:native-crypto-wallet=on --with-feature:opera-startpage-special=on --with-feature:password-generator=off --with-feature:proxy-switcher-ui-default-visible=on --with-feature:realtime-impressions-reporting=on --with-feature:sd-suggestions-external=on --with-feature:session-restore-attribution=on --with-feature:shopping-corner=on --with-feature:sitecheck-age=on --with-feature:specific-keywords=on --with-feature:startpage-content-phase-1=off --with-feature:startpage-opening-animation=off --with-feature:startpage-sync-banner-ref=on --with-feature:installer-experiment-test=off --with-feature:installer-bypass-launcher=on --field-trial-handle=7340,i,822286292445418201,1747623319583521571,262144 --disable-features=CertificateTransparencyAskBeforeEnabling --variations-seed-version --mojo-platform-channel-handle=7920 /prefetch:8C:\Users\admin\AppData\Local\Programs\Opera\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Version:
114.0.5282.222
2076"C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --type=renderer --with-feature:cashback-assistant=on --with-feature:address-bar-dropdown-autocompleted-domains=on --with-feature:address-bar-dropdown-cities=on --with-feature:address-bar-dropdown-keyword-ads=on --with-feature:address-bar-keywords-monetization=on --with-feature:amazon-new-ids=on --with-feature:amp-requests-stats=on --with-feature:aria-command-line-in-extension=on --with-feature:aria-command-line-react=on --with-feature:capital-one-cashback-protection=on --with-feature:cashback-assistant=on --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-cms-configuration=on --with-feature:continue-shopping-explore=off --with-feature:continue-shopping-structured-partners=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:lucid-mode-hide-text=on --with-feature:native-crypto-wallet=on --with-feature:opera-startpage-special=on --with-feature:password-generator=off --with-feature:proxy-switcher-ui-default-visible=on --with-feature:realtime-impressions-reporting=on --with-feature:sd-suggestions-external=on --with-feature:session-restore-attribution=on --with-feature:shopping-corner=on --with-feature:sitecheck-age=on --with-feature:specific-keywords=on --with-feature:startpage-content-phase-1=off --with-feature:startpage-opening-animation=off --with-feature:startpage-sync-banner-ref=on --with-feature:installer-experiment-test=off --with-feature:installer-bypass-launcher=on --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=16 --field-trial-handle=4796,i,822286292445418201,1747623319583521571,262144 --disable-features=CertificateTransparencyAskBeforeEnabling --variations-seed-version --mojo-platform-channel-handle=4816 /prefetch:1C:\Users\admin\AppData\Local\Programs\Opera\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Version:
114.0.5282.222
2280"C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --enable-quic --with-feature:cashback-assistant=on --with-feature:address-bar-dropdown-autocompleted-domains=on --with-feature:address-bar-dropdown-cities=on --with-feature:address-bar-dropdown-keyword-ads=on --with-feature:address-bar-keywords-monetization=on --with-feature:amazon-new-ids=on --with-feature:amp-requests-stats=on --with-feature:aria-command-line-in-extension=on --with-feature:aria-command-line-react=on --with-feature:capital-one-cashback-protection=on --with-feature:cashback-assistant=on --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-cms-configuration=on --with-feature:continue-shopping-explore=off --with-feature:continue-shopping-structured-partners=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:lucid-mode-hide-text=on --with-feature:native-crypto-wallet=on --with-feature:opera-startpage-special=on --with-feature:password-generator=off --with-feature:proxy-switcher-ui-default-visible=on --with-feature:realtime-impressions-reporting=on --with-feature:sd-suggestions-external=on --with-feature:session-restore-attribution=on --with-feature:shopping-corner=on --with-feature:sitecheck-age=on --with-feature:specific-keywords=on --with-feature:startpage-content-phase-1=off --with-feature:startpage-opening-animation=off --with-feature:startpage-sync-banner-ref=on --with-feature:installer-experiment-test=off --with-feature:installer-bypass-launcher=on --field-trial-handle=3144,i,822286292445418201,1747623319583521571,262144 --disable-features=CertificateTransparencyAskBeforeEnabling --variations-seed-version --mojo-platform-channel-handle=3516 /prefetch:8C:\Users\admin\AppData\Local\Programs\Opera\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Version:
114.0.5282.222
2828"C:\Users\admin\AppData\Local\Programs\Opera\opera.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --enable-quic --with-feature:cashback-assistant=on --with-feature:address-bar-dropdown-autocompleted-domains=on --with-feature:address-bar-dropdown-cities=on --with-feature:address-bar-dropdown-keyword-ads=on --with-feature:address-bar-keywords-monetization=on --with-feature:amazon-new-ids=on --with-feature:amp-requests-stats=on --with-feature:aria-command-line-in-extension=on --with-feature:aria-command-line-react=on --with-feature:capital-one-cashback-protection=on --with-feature:cashback-assistant=on --with-feature:continue-on-booking=on --with-feature:continue-on-shopping-via-amp=off --with-feature:continue-shopping=on --with-feature:continue-shopping-2=on --with-feature:continue-shopping-5=on --with-feature:continue-shopping-cms-configuration=on --with-feature:continue-shopping-explore=off --with-feature:continue-shopping-structured-partners=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:lucid-mode-hide-text=on --with-feature:native-crypto-wallet=on --with-feature:opera-startpage-special=on --with-feature:password-generator=off --with-feature:proxy-switcher-ui-default-visible=on --with-feature:realtime-impressions-reporting=on --with-feature:sd-suggestions-external=on --with-feature:session-restore-attribution=on --with-feature:shopping-corner=on --with-feature:sitecheck-age=on --with-feature:specific-keywords=on --with-feature:startpage-content-phase-1=off --with-feature:startpage-opening-animation=off --with-feature:startpage-sync-banner-ref=on --with-feature:installer-experiment-test=off --with-feature:installer-bypass-launcher=on --field-trial-handle=6052,i,822286292445418201,1747623319583521571,262144 --disable-features=CertificateTransparencyAskBeforeEnabling --variations-seed-version --mojo-platform-channel-handle=6060 /prefetch:8C:\Users\admin\AppData\Local\Programs\Opera\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Version:
114.0.5282.222
Total events
10 081
Read events
9 927
Write events
145
Delete events
9

Modification events

(PID) Process:(3796) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3796) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3796) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(6428) setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Opera Software
Operation:writeName:Last Stable Install Path
Value:
C:\Users\admin\AppData\Local\Programs\Opera\
(PID) Process:(6912) installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Opera Software
Operation:writeName:Last Stable Install Path
Value:
C:\Users\admin\AppData\Local\Programs\Opera\
(PID) Process:(6912) installer.exeKey:HKEY_CLASSES_ROOT\OperaStable
Operation:writeName:FriendlyTypeName
Value:
Opera Web Document
(PID) Process:(6912) installer.exeKey:HKEY_CLASSES_ROOT\OperaStable
Operation:writeName:URL Protocol
Value:
(PID) Process:(6912) installer.exeKey:HKEY_CLASSES_ROOT\.opdownload\OpenWithProgIDs
Operation:writeName:OperaStable
Value:
(PID) Process:(6912) installer.exeKey:HKEY_CLASSES_ROOT\.htm\OpenWithProgids
Operation:writeName:OperaStable
Value:
(PID) Process:(6912) installer.exeKey:HKEY_CLASSES_ROOT\.html\OpenWithProgids
Operation:writeName:OperaStable
Value:
Executable files
27
Suspicious files
519
Text files
167
Unknown types
23

Dropped files

PID
Process
Filename
Type
3796setup.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\Opera_114.0.5282.222_Autoupdate_x64[1].exe
MD5:
SHA256:
3796setup.exeC:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202411240648351\opera_package
MD5:
SHA256:
3796setup.exeC:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports\settings.datbinary
MD5:12EB180EFB782C701608EF7CAA9937A7
SHA256:E2D358FC50C65D39C852B0FABA09C125DAE7F3923CA92B7205F65522A397D369
3796setup.exeC:\Users\admin\AppData\Local\Temp\Opera_installer_2411240648342063796.dllexecutable
MD5:90F1C76397815E9755E2C266F79C5A4B
SHA256:6BAE4A4046069B92479A475DA99B408A2FD767E921E43EEBE2CEEA0FA8B330C5
3796setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\59D76868C250B3240414CE3EFBB12518_17DD39A60A87A85D0DDEF9FD164BB3E9binary
MD5:2008425BC0097D91BFE626F19C888AAE
SHA256:7480EAFBAADD142C13E537275DE7A8DBE211C4889D31BCF4A0201B3B97B4C3C8
3796setup.exeC:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeexecutable
MD5:7E293EA90477B4293D42B35B9A7EEFBC
SHA256:61325BF8DB458C0F321B7D3E0A0B968313556E84CD74EF062B1AB8F4D37F1AF3
1688setup.exeC:\Users\admin\AppData\Local\Temp\Opera_installer_2411240648349091688.dllexecutable
MD5:90F1C76397815E9755E2C266F79C5A4B
SHA256:6BAE4A4046069B92479A475DA99B408A2FD767E921E43EEBE2CEEA0FA8B330C5
3796setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419binary
MD5:AC894F673C170C046204C05085F7B0EE
SHA256:0F65BCADFA1D755EAB866A51B64FA460C025479E4BC55B055CC644C35A022C3C
6428setup.exeC:\Users\admin\AppData\Local\Temp\Opera_installer_2411240648457156428.dllexecutable
MD5:90F1C76397815E9755E2C266F79C5A4B
SHA256:6BAE4A4046069B92479A475DA99B408A2FD767E921E43EEBE2CEEA0FA8B330C5
3796setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\59D76868C250B3240414CE3EFBB12518_17DD39A60A87A85D0DDEF9FD164BB3E9der
MD5:A9FE4C2269DCC4C8C48EDD4754C9C4C2
SHA256:AFFD16C74104498FF6E118054A8A352C0C75285937F1C42F3C7CFE64B4F397C5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
19
TCP/UDP connections
165
DNS requests
201
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
3796
setup.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3796
setup.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnxLiz3Fu1WB6n1%2FE6xWn1b0jXiQQUdIWAwGbH3zfez70pN6oDHb7tzRcCEAfyOr5A1UWlCmQhXhy%2Bwwk%3D
unknown
whitelisted
3796
setup.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
unknown
whitelisted
3876
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5892
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5064
SearchApp.exe
104.126.37.139:443
www.bing.com
Akamai International B.V.
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
40.126.32.133:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.bing.com
  • 104.126.37.139
  • 104.126.37.163
  • 104.126.37.136
  • 104.126.37.162
  • 104.126.37.144
  • 104.126.37.160
  • 104.126.37.155
  • 104.126.37.137
  • 104.126.37.153
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 95.101.149.131
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
google.com
  • 142.250.186.174
whitelisted
login.live.com
  • 40.126.32.133
  • 20.190.160.20
  • 20.190.160.22
  • 40.126.32.72
  • 40.126.32.136
  • 40.126.32.76
  • 20.190.160.17
  • 40.126.32.68
whitelisted
autoupdate.opera.com
  • 185.26.182.123
  • 185.26.182.124
  • 82.145.216.19
  • 82.145.216.47
  • 82.145.216.20
  • 82.145.216.46
whitelisted
desktop-netinstaller-sub.osp.opera.software
  • 82.145.217.121
whitelisted
autoupdate.geo.opera.com
  • 185.26.182.123
  • 185.26.182.124
  • 82.145.216.19
  • 82.145.216.47
  • 82.145.216.20
  • 82.145.216.46
whitelisted

Threats

PID
Process
Class
Message
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (whatismyipaddress .com)
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (whatismyipaddress .com)
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (whatismyipaddress .com)
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (whatismyipaddress .com)
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (whatismyipaddress .com)
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (whatismyipaddress .com)
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (whatismyipaddress .com)
Process
Message
assistant_installer.exe
[1124/064905.035:INFO:assistant_installer_main.cc(177)] Running assistant installer with command line "C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202411240648351\assistant\assistant_installer.exe" --version
assistant_installer.exe
[1124/064923.738:INFO:assistant_installer_main.cc(177)] Running assistant installer with command line "C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202411240648351\assistant\assistant_installer.exe" --installfolder="C:\Users\admin\AppData\Local\Programs\Opera\assistant" --copyonly=0 --allusers=0
assistant_installer.exe
[1124/064923.847:INFO:assistant_installer.cc(322)] Setting up the registry
assistant_installer.exe
[1124/064923.972:INFO:assistant_installer.cc(382)] Creating scheduled task
assistant_installer.exe
[1124/064924.050:INFO:assistant_installer.cc(281)] Running Assistant
assistant_installer.exe
[1124/064924.050:INFO:assistant_installer_main.cc(177)] Running assistant installer with command line "C:\Users\admin\AppData\Local\Programs\Opera\assistant\assistant_installer.exe" --installfolder="C:\Users\admin\AppData\Local\Programs\Opera\assistant" --run-assistant --allusers=0