opera_1160_int_setup.exe

Opera Software ASA

This is a self-extracting archive and installer. The file has been seen being downloaded from www.opera.com and multiple other hosts.
Publisher:
Opera Software ASA  (signed and verified)

MD5:
b78ff639f50df92ffcb351cf89ea35eb

SHA-1:
b1f270487b9450d4aac8a0caaf918173dc153d3d

SHA-256:
be0be275804d9fab12b25cf7e01ba5ae7f71d6f0752adc6599e0c0c8607f3a5d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/2/2024 5:27:52 PM UTC  (today)

File size:
10.1 MB (10,627,848 bytes)

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\opera_1160_int_setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/27/2010 2:00:00 AM

Valid to:
1/29/2013 1:59:59 AM

Subject:
CN=Opera Software ASA, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Opera Software ASA, S=Oslo, C=NO

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
13C8351AECE71C731158980F575F4133

File PE Metadata
Compilation timestamp:
7/22/2007 5:33:09 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:6u6b5OYcHOFbvPEoq8j6hib2+/0z4tdcMpeKGposdOK5Ful:6NAZudfiwuEdcqbGptOK5FC

Entry address:
0x11DE6

Entry point:
55, 8B, EC, 6A, FF, 68, E0, 49, 41, 00, 68, E0, 1D, 41, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 28, 41, 41, 00, 59, 83, 0D, 64, 97, 41, 00, FF, 83, 0D, 68, 97, 41, 00, FF, FF, 15, 2C, 41, 41, 00, 8B, 0D, 40, 93, 41, 00, 89, 08, FF, 15, 30, 41, 41, 00, 8B, 0D, 3C, 93, 41, 00, 89, 08, A1, 34, 41, 41, 00, 8B, 00, A3, 60, 97, 41, 00, E8, 1C, 01, 00, 00, 39, 1D, 90, 91, 41, 00, 75, 0C, 68, 6E, 1F, 41, 00, FF, 15, 38, 41...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
73 KB (74,752 bytes)

The file opera_1160_int_setup.exe has been discovered within the following program.

Air Assault  by Media Contact LLC
is a casual video games distributed through the GameTop.com download portal. The trial verison of the game in some cases drops an icon on the user's desktop 'Online Free Games' which links to a partner portal such as onlinefreegames.com.
www.GameTop.com
6% remove it
 
Powered by Should I Remove It?

The file opera_1160_int_setup.exe has been seen being distributed by the following 14 URLs.

http://www.opera.com/download/.../?id=34226&location=413&nothanks=yes&sub=marine

ftp://opera.vc.ukrtel.net/mirror/opera/win/1160/.../Opera_1160_int_Setup.exe

http://get.geo.opera.com/pub/opera/win/1160/.../Opera_1160_int_Setup.exe

http://dw.uptodown.com/dwn/Dof5M94dckTVhwf8rHg1U0W9CuhmtkjWM_D2Vqo-pFuu388QE_E2L8vgZ8CgVWt_vf0oH5_rcmWTNLj2Iz6nO6JIusQje5yb5O62z2ym4qQC-zKnRxo1TaOhP9sFkn0a/1E-365ADqkEDCuBl_ogDr_BypF3uNRK5ZcHiKT62Ckqm9B2IXnMgqM7Pqm9hbVtzssgWCv8HmljvGYK4Zo23qRZWRe34xmGyin8-Pqn0nGfRjHVvuSqLnvlm4AO26osA/9X3kNEjNlsTZZ465agQ7inS1SOGgKsXMORdILD32nU9C9padSPawISmm3VrOT5nqphQTtg8uZlSTfU07Pf3RBK1aBjFWYG3fDidWPjo3tOQZhWMCcBikw5OH6CigVBun/.../

http://get7.opera.com/pub/opera/win/1160/.../Opera_1160_int_Setup.exe

http://mirrors.fe.up.pt/pub/opera/win/1160/.../Opera_1160_int_Setup.exe