opera_autoupdate.exe

  • File Path: C:\Program Files\Opera\81.0.4196.31\opera_autoupdate.exe
  • Description: Opera auto-updater

Hashes

Type Hash
MD5 8641BB5E51E42DDBF0020BC4589528F4
SHA1 4A5D9FF7BBDDA4A495C903F52AFF4266C0361EED
SHA256 0E9F53F349FE466EA8F0727EB5E6E891C7305E8BB2510A8E7A841AB8D016701E
SHA384 3178CBD53DFA9353219B83E259B49FFEE4FB695AF439CF25193464B1A3A69E832A5B2AAE81399E7CFB3E3F55B745D6F1
SHA512 00EE26B4D26CDFA472374A16E4C1C2A16452FD99758B4532FBF278E2DD3AA3600BBE46133827BD0AF04CA0F86ADC813D189BBB3E56702FA19C8C314E9690E23A
SSDEEP 49152:vqip++jtUI4514se2B3MUsX3ETp6BZ0umIfUBhlVCtE5CAoeYRAOXkO0oK+FA9Ur:dp4Y9mcBSum1zOXkVa2Bu
IMP 309DEBD1A14ED3337CEA591F35AB6455
PESHA1 912C82B43B84227949D6F6F180FB49713B566603
PE256 82654784E983FB54B22DA7D7EE2FF2B8A0EC7EFDE1FBB00767DF8EE468CB4CC5

Runtime Data

Child Processes:

opera_autoupdate.exe

Open Handles:

Path Type
(RW-) C:\Program Files\Opera\81.0.4196.31\icudtl.dat File
(RW-) C:\Users\user File
(RW-) C:\Users\user\opera_autoupdate.log File
\BaseNamedObjects__ComCatalogCache__ Section
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db Section
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db Section
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2 Section
\BaseNamedObjects\NLS_CodePage_1252_3_2_0_0 Section
\BaseNamedObjects\NLS_CodePage_437_3_2_0_0 Section
\Sessions\1\BaseNamedObjects\windows_shell_global_counters Section

Loaded Modules:

Path
C:\Program Files\Opera\81.0.4196.31\opera_autoupdate.exe
C:\Windows\System32\ADVAPI32.dll
C:\Windows\System32\combase.dll
C:\Windows\SYSTEM32\dbghelp.dll
C:\Windows\System32\KERNEL32.DLL
C:\Windows\System32\KERNELBASE.dll
C:\Windows\System32\msvcp_win.dll
C:\Windows\System32\msvcrt.dll
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\System32\OLEAUT32.dll
C:\Windows\System32\RPCRT4.dll
C:\Windows\System32\sechost.dll
C:\Windows\System32\SHELL32.dll
C:\Windows\System32\ucrtbase.dll
C:\Windows\System32\USER32.dll
C:\Windows\System32\win32u.dll

Signature

  • Status: Signature verified.
  • Serial: 0D31C23EB2249CE611B953FB16EA0D25
  • Thumbprint: 373CD800B048D39CE2057A09937093EA73BCDE5F
  • Issuer: CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US
  • Subject: CN=Opera Software AS, O=Opera Software AS, L=Oslo, C=NO, SERIALNUMBER=916 368 127, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=NO

File Metadata

  • Original Filename:
  • Product Name: Opera auto-updater
  • Company Name: Opera Software
  • File Version: 81.0.4196.31
  • Product Version: 81.0.4196.31
  • Language: English (United States)
  • Legal Copyright: Copyright Opera Software 2021
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 1/74
  • VirusTotal Link: https://www.virustotal.com/gui/file/0e9f53f349fe466ea8f0727eb5e6e891c7305e8bb2510a8e7a841ab8d016701e/detection

Possible Misuse

The following table contains possible examples of opera_autoupdate.exe being misused. While opera_autoupdate.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma image_load_uipromptforcreds_dlls.yml - Image\|endswith: '\opera_autoupdate.exe' DRL 1.0
sigma image_load_wmi_module_load.yml - '\opera_autoupdate.exe' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.