Safe
Legitimate Opera GX browser installer; zero tier-1 detections, consistent RAG history, normal unpacking behaviour.
a31da45190f84af871…3129d25703The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The file exhibits the classic signature of a legitimate commercial installer: zero malicious detections across 71 engines including all major tier-1 vendors (Kaspersky, BitDefender, ESET-NOD32, Fortinet, Avast, AVG, Avira, DrWeb, Emsisoft, F-Secure, GData), a filename matching Opera GX's official distribution pattern, and a prior safe verdict on the same imphash. The T1055 process-injection heuristic is expected behaviour for self-extracting archives and installers that unpack child processes; the absence of malicious sandbox verdicts and zero malicious dropped children confirm this is routine unpacking, not evasion. No external intelligence (YARA, CIRCL, MalwareBazaar) corroborates any threat.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
0/71 engines malicious; tier1Malicious=0; 16 tier-1 engines (Kaspersky, BitDefender, ESET-NOD32, Fortinet, Avast, AVG, Avira, DrWeb, Emsisoft, F-Secure, GData, Ikarus) all silent
similarHashes: imphash e59d00b0d9... matched prior OperaGXSetup.exe verdicted 'safe' (ai:low_trust_engines_only) on 2026-06-11
Filename OperaGXSetup.exe + hasInstallerHint=true + no brandMismatch — consistent with legitimate Opera GX browser distribution
T1055 (Process Injection) heuristic fired but droppedChildren.hasMaliciousChild=false; child process unanalyzed (verdict=null); no malicious sandbox verdicts
PE entropy 7.999938, no packers, likelyPacked=false, overlay tag (self-extracting archive pattern) — benign installer characteristics
- Zero malicious detections across 71 engines; 16 tier-1 vendors all clean
- Prior safe verdict on identical imphash (OperaGXSetup.exe, 2026-06-11)
- Filename and installer pattern consistent with legitimate Opera GX distribution
- No malicious sandbox verdicts; dropped child not flagged malicious
- No external intelligence hits (YARA, CIRCL, MalwareBazaar)
This file is safe. It is the legitimate Opera GX browser installer. You may download and install it without concern.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- C:\Users\<USER>\AppData\Local\Temp\7zS8B7DB8A3\installer.exe
- C:\Users\user\AppData\Local\Temp\7zS4D888107
- C:\Users\user\AppData\Local\Temp\7zS4D888107\installer.exe
Files this sample writes at runtime
This file drops 1 child at runtime. None are currently flagged malicious in our cache.
- 41f6858a706267dbf378…f1d8b1Never scannednever seen before
YARA + heuristic rules that fired
A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.
MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.
Evidence"C:\Users\user\Desktop\OperaGXSetup.exe"
0 detections across 75 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Barely seen in the wild and first surfaced recently. This is the footprint of targeted malware the AV industry hasn't signatured yet — extra scrutiny is warranted.
Forensic fingerprint
- File name
- OperaGXSetup.exe
- Size
- 3.94 MB
- MIME type
- application/x-msdownload
- Detected type
- Win32 EXE
- SHA-256
- a31da45190f84af871648f71500133439e9bfb122dac1ca50a43893129d25703
- MD5
- dc69e9ab5000e2866e5a2446f4fd0850
- SHA-1
- 9c47d909db77b1c321c5ff0a8fb81fee6f3598b7
- PE imphash
- e59d00b0d90522ee1a983f13d4ff7e50
- First seen (VT)
- 6/11/2026, 10:12:43 AM
- Last analysis (VT)
- 6/11/2026, 10:12:43 AM
- First scan (MalwareTips)
- 6/11/2026, 10:13:42 AM
- Last scan (MalwareTips)
- 6/11/2026, 10:48:34 AM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.