| URL: | https://voicebeddingtaint.com |
| Full analysis: | https://app.any.run/tasks/dadb31f8-3aac-4715-8f00-42744c90ac8d |
| Verdict: | Malicious activity |
| Analysis date: | March 02, 2023, 12:07:39 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| MD5: | 3FF5D87CFFFAB7C31147E6A76EB05B8D |
| SHA1: | F3CEA5FFBDA107FDB98C632B595448AD81A91D1F |
| SHA256: | FBEEC2D17DF3F95AA1B814D141AF1670DDF547F20392D7B30D00E4ADA95B6CCC |
| SSDEEP: | 3:N8FHA8L2I:2i8L2I |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3432 | "C:\Program Files\Opera\opera.exe" "https://voicebeddingtaint.com" | C:\Program Files\Opera\opera.exe | Explorer.EXE | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera Internet Browser Exit code: 0 Version: 1748 Modules
| |||||||||||||||
| (PID) Process: | (3432) opera.exe | Key: | HKEY_CURRENT_USER\Software\Opera Software |
| Operation: | write | Name: | Last CommandLine v2 |
Value: C:\Program Files\Opera\opera.exe "https://voicebeddingtaint.com" | |||
| (PID) Process: | (3432) opera.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3432 | opera.exe | C:\Users\admin\AppData\Roaming\Opera\Opera\opr1A28.tmp | text | |
MD5:— | SHA256:— | |||
| 3432 | opera.exe | C:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xml | xml | |
MD5:— | SHA256:— | |||
| 3432 | opera.exe | C:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.ini | text | |
MD5:— | SHA256:— | |||
| 3432 | opera.exe | C:\Users\admin\AppData\Roaming\Opera\Opera\opr1A97.tmp | xml | |
MD5:— | SHA256:— | |||
| 3432 | opera.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\8A17Q5R2N6KXNJCEFQNR.temp | binary | |
MD5:FDBCDB294DED05EA01DCAA246B98C2C5 | SHA256:EAEC5A291DBC8E8760BAB0C1BB27CB801F671166CE85310FD173F54111357C4B | |||
| 3432 | opera.exe | C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat | binary | |
MD5:— | SHA256:— | |||
| 3432 | opera.exe | C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\opr1A18.tmp | text | |
MD5:0100E3D2A29941CEEF4E37312A7FA332 | SHA256:0C42C7737A5ABA75C8E2EA967E2A994542B2C641D0A370EDC41BC4D70A7CAC70 | |||
| 3432 | opera.exe | C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win | text | |
MD5:0100E3D2A29941CEEF4E37312A7FA332 | SHA256:0C42C7737A5ABA75C8E2EA967E2A994542B2C641D0A370EDC41BC4D70A7CAC70 | |||
| 3432 | opera.exe | C:\Users\admin\AppData\Roaming\Opera\Opera\opcert6.dat | binary | |
MD5:1AA8644C9261DC10F7247F6A145C1DD2 | SHA256:58A8933F65361633C6AB194000D312DC9D566F717B1A16814A0DBEE24A60EBE3 | |||
| 3432 | opera.exe | C:\Users\admin\AppData\Roaming\Opera\Opera\opcacrt6.dat | binary | |
MD5:59761E989F564F76A3A4B778DB7ABCF1 | SHA256:AF879942D234D85C0CE75921DBDDA50E2F6D135BD961F259106131751359052B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3432 | opera.exe | GET | 200 | 104.18.39.201:80 | http://crl.identrust.com/DSTROOTCAX3CRL.crl | US | der | 1.16 Kb | whitelisted |
3432 | opera.exe | GET | 200 | 23.37.41.57:80 | http://x1.c.lencr.org/ | NL | der | 740 b | whitelisted |
3432 | opera.exe | GET | 200 | 2.16.186.27:80 | http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgODT7uuLu9XOyEYZea2UiaUoQ%3D%3D | unknown | der | 503 b | shared |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3432 | opera.exe | 192.243.59.20:443 | voicebeddingtaint.com | DataWeb Global Group B.V. | US | malicious |
3432 | opera.exe | 107.167.110.216:443 | sitecheck2.opera.com | OPERASOFTWARE | US | malicious |
3432 | opera.exe | 185.26.182.93:443 | certs.opera.com | Opera Software AS | — | whitelisted |
3432 | opera.exe | 192.243.59.12:443 | voicebeddingtaint.com | DataWeb Global Group B.V. | US | malicious |
3432 | opera.exe | 185.26.182.94:443 | certs.opera.com | Opera Software AS | — | whitelisted |
— | — | 185.26.182.93:443 | certs.opera.com | Opera Software AS | — | whitelisted |
3432 | opera.exe | 2.16.186.27:80 | r3.o.lencr.org | Akamai International B.V. | DE | whitelisted |
3432 | opera.exe | 23.37.41.57:80 | x1.c.lencr.org | AKAMAI-AS | DE | suspicious |
3432 | opera.exe | 104.18.39.201:80 | crl.identrust.com | CLOUDFLARENET | — | unknown |
3432 | opera.exe | 142.250.184.238:443 | google.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
voicebeddingtaint.com |
| suspicious |
certs.opera.com |
| whitelisted |
sitecheck2.opera.com |
| whitelisted |
x1.c.lencr.org |
| whitelisted |
crl.identrust.com |
| whitelisted |
r3.o.lencr.org |
| shared |
google.com |
| malicious |
dns.msftncsi.com |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
3432 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
3432 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
3432 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
3432 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
3432 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
3432 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
3432 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
3432 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
3432 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
3432 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |