File name:

electrum-dogecoin-win10-setup.exe.virus

Full analysis: https://app.any.run/tasks/e96001dd-8be8-4e54-81aa-1635b796af88
Verdict: Malicious activity
Analysis date: January 21, 2025, 00:52:51
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

7EF9206824A18C9E887073DE9B455EE4

SHA1:

48ABE8E11FD3458C5724DA3FC641EE3109716D2A

SHA256:

AA146CB25BC47F33AF75BB032930339223447657E316FA8EC81AB628A8DD5CE0

SSDEEP:

196608:Wam2k2HMNBSTYnFoPq/hvolo7t28jmN8BXwAMjLeZ4YJdO3V6m7pKYhNraU4cUjv:u2k7NBFJi+tPjecwO4YLSDpKYL4cmSra

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • electrum-dogecoin-win10-setup.exe.virus.exe (PID: 6384)
    • The process drops C-runtime libraries

      • electrum-dogecoin-win10-setup.exe.virus.exe (PID: 6384)
    • Process drops legitimate windows executable

      • electrum-dogecoin-win10-setup.exe.virus.exe (PID: 6384)
    • Process drops python dynamic module

      • electrum-dogecoin-win10-setup.exe.virus.exe (PID: 6384)
    • The process creates files with name similar to system file names

      • electrum-dogecoin-win10-setup.exe.virus.exe (PID: 6384)
    • Creates a software uninstall entry

      • electrum-dogecoin-win10-setup.exe.virus.exe (PID: 6384)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • electrum-dogecoin-win10-setup.exe.virus.exe (PID: 6384)
  • INFO

    • The sample compiled with english language support

      • electrum-dogecoin-win10-setup.exe.virus.exe (PID: 6384)
    • Reads the computer name

      • electrum-dogecoin-win10-setup.exe.virus.exe (PID: 6384)
    • Checks supported languages

      • electrum-dogecoin-win10-setup.exe.virus.exe (PID: 6384)
    • Create files in a temporary directory

      • electrum-dogecoin-win10-setup.exe.virus.exe (PID: 6384)
    • Creates files in the program directory

      • electrum-dogecoin-win10-setup.exe.virus.exe (PID: 6384)
    • Creates files or folders in the user directory

      • electrum-dogecoin-win10-setup.exe.virus.exe (PID: 6384)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:12:16 00:50:50+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 25088
InitializedDataSize: 118784
UninitializedDataSize: 1024
EntryPoint: 0x3384
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
Comments: The installer for Electrum-DOGE
CompanyName: Electrum-DOGE
FileDescription: Electrum-DOGE Installer
FileVersion: Electrum-DOGE
InternalName: Electrum-DOGE Installer
LegalCopyright: 2013-2018 Electrum Technologies GmbH
LegalTrademarks: Electrum-DOGE is a trademark of Electrum Technologies GmbH
OriginalFileName: Electrum-DOGE.exe
ProductName: Electrum-DOGE Installer
ProductVersion: Electrum-DOGE
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
119
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start electrum-dogecoin-win10-setup.exe.virus.exe electrum-dogecoin-win10-setup.exe.virus.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6244"C:\Users\admin\AppData\Local\Temp\electrum-dogecoin-win10-setup.exe.virus.exe" C:\Users\admin\AppData\Local\Temp\electrum-dogecoin-win10-setup.exe.virus.exeexplorer.exe
User:
admin
Company:
Electrum-DOGE
Integrity Level:
MEDIUM
Description:
Electrum-DOGE Installer
Exit code:
3221226540
Version:
Electrum-DOGE
Modules
Images
c:\users\admin\appdata\local\temp\electrum-dogecoin-win10-setup.exe.virus.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6384"C:\Users\admin\AppData\Local\Temp\electrum-dogecoin-win10-setup.exe.virus.exe" C:\Users\admin\AppData\Local\Temp\electrum-dogecoin-win10-setup.exe.virus.exe
explorer.exe
User:
admin
Company:
Electrum-DOGE
Integrity Level:
HIGH
Description:
Electrum-DOGE Installer
Exit code:
0
Version:
Electrum-DOGE
Modules
Images
c:\users\admin\appdata\local\temp\electrum-dogecoin-win10-setup.exe.virus.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
244
Read events
233
Write events
11
Delete events
0

Modification events

(PID) Process:(6384) electrum-dogecoin-win10-setup.exe.virus.exeKey:HKEY_CLASSES_ROOT\bitcoin
Operation:writeName:URL Protocol
Value:
(PID) Process:(6384) electrum-dogecoin-win10-setup.exe.virus.exeKey:HKEY_CLASSES_ROOT\bitcoin
Operation:writeName:DefaultIcon
Value:
"C:\Program Files (x86)\Electrum-DOGE\electrum.ico, 0"
(PID) Process:(6384) electrum-dogecoin-win10-setup.exe.virus.exeKey:HKEY_CLASSES_ROOT\lightning
Operation:writeName:URL Protocol
Value:
(PID) Process:(6384) electrum-dogecoin-win10-setup.exe.virus.exeKey:HKEY_CLASSES_ROOT\lightning
Operation:writeName:DefaultIcon
Value:
"C:\Program Files (x86)\Electrum-DOGE\electrum.ico, 0"
(PID) Process:(6384) electrum-dogecoin-win10-setup.exe.virus.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Electrum-DOGE
Operation:writeName:DisplayName
Value:
Electrum-DOGE
(PID) Process:(6384) electrum-dogecoin-win10-setup.exe.virus.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Electrum-DOGE
Operation:writeName:UninstallString
Value:
C:\Program Files (x86)\Electrum-DOGE\Uninstall.exe
(PID) Process:(6384) electrum-dogecoin-win10-setup.exe.virus.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Electrum-DOGE
Operation:writeName:DisplayVersion
Value:
Electrum-DOGE
(PID) Process:(6384) electrum-dogecoin-win10-setup.exe.virus.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Electrum-DOGE
Operation:writeName:URLInfoAbout
Value:
https://github.com/c4pt000/electrum-dogecoin
(PID) Process:(6384) electrum-dogecoin-win10-setup.exe.virus.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Electrum-DOGE
Operation:writeName:Publisher
Value:
Electrum Technologies GmbH
(PID) Process:(6384) electrum-dogecoin-win10-setup.exe.virus.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Electrum-DOGE
Operation:writeName:DisplayIcon
Value:
C:\Program Files (x86)\Electrum-DOGE\electrum.ico
Executable files
93
Suspicious files
204
Text files
211
Unknown types
0

Dropped files

PID
Process
Filename
Type
6384electrum-dogecoin-win10-setup.exe.virus.exeC:\Program Files (x86)\Electrum-DOGE\Qt5Multimedia.dllexecutable
MD5:091CD90206794A3EFF2C16F8747A47D1
SHA256:916653DE6EC324A156A49AF83D11B17B7E338E97D8DB629D5A8BE8B57E0EA639
6384electrum-dogecoin-win10-setup.exe.virus.exeC:\Program Files (x86)\Electrum-DOGE\MSVCP140.dllexecutable
MD5:ECEFF9C92E14B580EA84365F3D60F7DE
SHA256:265591A709A5DB413D73C95B538DA321EDEACB40059BDCEB142F997A3D458B49
6384electrum-dogecoin-win10-setup.exe.virus.exeC:\Program Files (x86)\Electrum-DOGE\Qt5Network.dllexecutable
MD5:2E3DB1CD1EC59D08706438258E86EA30
SHA256:37275F3EA79D15A2792BF21F71F1DF825F201CF8B33AA1F94CA93D62D76B216C
6384electrum-dogecoin-win10-setup.exe.virus.exeC:\Program Files (x86)\Electrum-DOGE\Qt5Gui.dllexecutable
MD5:5B0F3D5B1B29B5E650375093C7AFA243
SHA256:80016776EFEA2B2A838C3FFA4C82E5F146BAFF68C36073C0C34668809D1C4297
6384electrum-dogecoin-win10-setup.exe.virus.exeC:\Program Files (x86)\Electrum-DOGE\Qt5QmlModels.dllexecutable
MD5:78E8091FEB2E6CE5646459DB0EA9E465
SHA256:065C8D687DC74964123F4BB06319565B163B164AB09DADC1EB6929EE19755735
6384electrum-dogecoin-win10-setup.exe.virus.exeC:\Program Files (x86)\Electrum-DOGE\Qt5DBus.dllexecutable
MD5:431E75DD83B3B2FF1954300CC7F43060
SHA256:B9BCA43F52D5BFBF014D1C2643516B54EEBB5B07D1DFCA8F4C266628EF9D121A
6384electrum-dogecoin-win10-setup.exe.virus.exeC:\Users\admin\AppData\Local\Temp\nsm834E.tmp\UserInfo.dllexecutable
MD5:E167F9A565781A30C03FF10370033319
SHA256:A912514823DF595BA3A048099D3B89E925A4D41742AFC67E772060952892F312
6384electrum-dogecoin-win10-setup.exe.virus.exeC:\Program Files (x86)\Electrum-DOGE\Qt5PrintSupport.dllexecutable
MD5:83FB40D5AB3108F18832B78574404B62
SHA256:74E737DDA4F666C28F9543BDE9CEE526A18D0088A780B497AD7C1772B3CADD4E
6384electrum-dogecoin-win10-setup.exe.virus.exeC:\Program Files (x86)\Electrum-DOGE\Qt5Svg.dllexecutable
MD5:EF0D5A2DC1D7A921F2BB0EB3EEF2E481
SHA256:ADE28D4CBAC1E033468CB48F380352F0DF7FBBCE03261C48827B8A5ED7A1548E
6384electrum-dogecoin-win10-setup.exe.virus.exeC:\Program Files (x86)\Electrum-DOGE\Qt5Qml.dllexecutable
MD5:7CDA5037206A57CADD50B5F032876A8E
SHA256:E45F26EBBC2B0499E0E90F1666FD13F1BB2BED1073E828D30B6A3A70599D4BC9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
24
DNS requests
14
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6808
SIHClient.exe
GET
200
23.209.214.100:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6808
SIHClient.exe
GET
200
23.209.214.100:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6484
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
1176
svchost.exe
40.126.32.76:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
1076
svchost.exe
2.18.97.227:443
go.microsoft.com
Akamai International B.V.
FR
whitelisted
1176
svchost.exe
40.126.32.72:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
6808
SIHClient.exe
4.245.163.56:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6808
SIHClient.exe
23.209.214.100:80
www.microsoft.com
PT. Telekomunikasi Selular
ID
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.142
whitelisted
login.live.com
  • 40.126.32.76
  • 40.126.32.133
  • 40.126.32.134
  • 40.126.32.74
  • 40.126.32.136
  • 40.126.32.140
  • 40.126.32.68
  • 20.190.160.17
  • 40.126.32.72
  • 20.190.160.14
  • 20.190.160.22
whitelisted
go.microsoft.com
  • 2.18.97.227
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
www.microsoft.com
  • 23.209.214.100
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted
arc.msn.com
  • 20.31.169.57
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
fd.api.iris.microsoft.com
  • 20.74.19.45
whitelisted
nexusrules.officeapps.live.com
  • 52.111.227.11
whitelisted

Threats

No threats detected
No debug info