File name:

electrum-doge-setup-1.4.2.exe

Full analysis: https://app.any.run/tasks/d95061cf-b408-4717-ad15-52a6f4ea519f
Verdict: Malicious activity
Analysis date: March 29, 2025, 12:03:49
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

9E4FF0070305560C2F454F500D211EE1

SHA1:

80A7C1664DEDCB7BD9B479F3091AAAFFC570B11C

SHA256:

D3C18C41E7AACC9595B25A989DB8538AAF3BB02F73E43706F802F3A62E56757B

SSDEEP:

786432:N/+9MUZKCwQW6HEp3/loxAUotLB5wyVuMO8z5LZau9LcpaWnV:NG9MUZKfQWQg3/ymUot15wyVuOnZ9cIy

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • electrum-doge-setup-1.4.2.exe (PID: 7448)
      • Electrum Doge.exe (PID: 8056)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • electrum-doge-setup-1.4.2.exe (PID: 7448)
    • The process creates files with name similar to system file names

      • electrum-doge-setup-1.4.2.exe (PID: 7448)
    • Starts CMD.EXE for commands execution

      • electrum-doge-setup-1.4.2.exe (PID: 7448)
    • Get information on the list of running processes

      • electrum-doge-setup-1.4.2.exe (PID: 7448)
      • cmd.exe (PID: 7736)
    • Drops 7-zip archiver for unpacking

      • electrum-doge-setup-1.4.2.exe (PID: 7448)
    • Process drops legitimate windows executable

      • electrum-doge-setup-1.4.2.exe (PID: 7448)
    • Creates a software uninstall entry

      • electrum-doge-setup-1.4.2.exe (PID: 7448)
    • Application launched itself

      • Electrum Doge.exe (PID: 8056)
    • Reads security settings of Internet Explorer

      • electrum-doge-setup-1.4.2.exe (PID: 7448)
    • There is functionality for taking screenshot (YARA)

      • electrum-doge-setup-1.4.2.exe (PID: 7448)
  • INFO

    • Checks supported languages

      • electrum-doge-setup-1.4.2.exe (PID: 7448)
      • Electrum Doge.exe (PID: 6040)
      • Electrum Doge.exe (PID: 2908)
      • Electrum Doge.exe (PID: 8056)
      • Electrum Doge.exe (PID: 8176)
    • The sample compiled with english language support

      • electrum-doge-setup-1.4.2.exe (PID: 7448)
    • Create files in a temporary directory

      • electrum-doge-setup-1.4.2.exe (PID: 7448)
      • Electrum Doge.exe (PID: 8056)
    • Creates files or folders in the user directory

      • electrum-doge-setup-1.4.2.exe (PID: 7448)
      • Electrum Doge.exe (PID: 8056)
      • Electrum Doge.exe (PID: 2908)
    • Manual execution by a user

      • Electrum Doge.exe (PID: 8056)
    • Reads the computer name

      • Electrum Doge.exe (PID: 8056)
      • Electrum Doge.exe (PID: 8176)
      • Electrum Doge.exe (PID: 2908)
      • electrum-doge-setup-1.4.2.exe (PID: 7448)
    • Checks proxy server information

      • Electrum Doge.exe (PID: 8056)
      • slui.exe (PID: 5728)
    • Reads the machine GUID from the registry

      • Electrum Doge.exe (PID: 8056)
    • Process checks computer location settings

      • Electrum Doge.exe (PID: 6040)
      • Electrum Doge.exe (PID: 8056)
    • Reads Environment values

      • Electrum Doge.exe (PID: 8056)
    • Reads the software policy settings

      • slui.exe (PID: 5728)
    • Reads product name

      • Electrum Doge.exe (PID: 8056)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:12:15 22:26:14+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 473088
UninitializedDataSize: 16384
EntryPoint: 0x338f
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.4.1.0
ProductVersionNumber: 1.4.1.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
FileDescription: Electrum Doge desktop wallet
FileVersion: 1.4.1
LegalCopyright: Copyright © 2025 Electrum Doge
ProductName: Electrum Doge
ProductVersion: 1.4.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
132
Monitored processes
10
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start electrum-doge-setup-1.4.2.exe cmd.exe no specs conhost.exe no specs tasklist.exe no specs find.exe no specs electrum doge.exe electrum doge.exe no specs electrum doge.exe electrum doge.exe no specs slui.exe

Process information

PID
CMD
Path
Indicators
Parent process
2908"C:\Users\admin\AppData\Local\Programs\Electrum Doge\Electrum Doge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --user-data-dir="C:\Users\admin\AppData\Roaming\doge-wallet-desktop" --mojo-platform-channel-handle=2136 --field-trial-handle=1808,i,17887198194036381113,3036303140353865125,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8C:\Users\admin\AppData\Local\Programs\Electrum Doge\Electrum Doge.exe
Electrum Doge.exe
User:
admin
Company:
GitHub, Inc.
Integrity Level:
MEDIUM
Description:
Electrum Doge
Version:
1.4.1
Modules
Images
c:\users\admin\appdata\local\programs\electrum doge\electrum doge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5728C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6040"C:\Users\admin\AppData\Local\Programs\Electrum Doge\Electrum Doge.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\doge-wallet-desktop" --app-user-model-id="Electrum Doge" --app-path="C:\Users\admin\AppData\Local\Programs\Electrum Doge\resources\app.asar" --enable-sandbox --first-renderer-process --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --mojo-platform-channel-handle=2460 --field-trial-handle=1808,i,17887198194036381113,3036303140353865125,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:1C:\Users\admin\AppData\Local\Programs\Electrum Doge\Electrum Doge.exeElectrum Doge.exe
User:
admin
Company:
GitHub, Inc.
Integrity Level:
LOW
Description:
Electrum Doge
Version:
1.4.1
Modules
Images
c:\users\admin\appdata\local\programs\electrum doge\electrum doge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
7448"C:\Users\admin\AppData\Local\Temp\electrum-doge-setup-1.4.2.exe" C:\Users\admin\AppData\Local\Temp\electrum-doge-setup-1.4.2.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Electrum Doge desktop wallet
Exit code:
0
Version:
1.4.1
Modules
Images
c:\users\admin\appdata\local\temp\electrum-doge-setup-1.4.2.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7736cmd /c tasklist /FI "USERNAME eq %USERNAME%" /FI "IMAGENAME eq Electrum Doge.exe" | %SYSTEMROOT%\System32\find.exe "Electrum Doge.exe"C:\Windows\SysWOW64\cmd.exeelectrum-doge-setup-1.4.2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
7748\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7812tasklist /FI "USERNAME eq admin" /FI "IMAGENAME eq Electrum Doge.exe" C:\Windows\SysWOW64\tasklist.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
7824C:\WINDOWS\System32\find.exe "Electrum Doge.exe"C:\Windows\SysWOW64\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (grep) Utility
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\find.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
8056"C:\Users\admin\AppData\Local\Programs\Electrum Doge\Electrum Doge.exe" C:\Users\admin\AppData\Local\Programs\Electrum Doge\Electrum Doge.exe
explorer.exe
User:
admin
Company:
GitHub, Inc.
Integrity Level:
MEDIUM
Description:
Electrum Doge
Version:
1.4.1
Modules
Images
c:\users\admin\appdata\local\programs\electrum doge\electrum doge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
8176"C:\Users\admin\AppData\Local\Programs\Electrum Doge\Electrum Doge.exe" --type=gpu-process --user-data-dir="C:\Users\admin\AppData\Roaming\doge-wallet-desktop" --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAABgAAAAAAAAAGAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1804 --field-trial-handle=1808,i,17887198194036381113,3036303140353865125,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:2C:\Users\admin\AppData\Local\Programs\Electrum Doge\Electrum Doge.exeElectrum Doge.exe
User:
admin
Company:
GitHub, Inc.
Integrity Level:
LOW
Description:
Electrum Doge
Version:
1.4.1
Modules
Images
c:\users\admin\appdata\local\programs\electrum doge\electrum doge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
2 814
Read events
2 784
Write events
12
Delete events
18

Modification events

(PID) Process:(7448) electrum-doge-setup-1.4.2.exeKey:HKEY_CURRENT_USER\SOFTWARE\f63847d5-ec2a-595f-a172-862a9648e0a3
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Local\Programs\Electrum Doge
(PID) Process:(7448) electrum-doge-setup-1.4.2.exeKey:HKEY_CURRENT_USER\SOFTWARE\f63847d5-ec2a-595f-a172-862a9648e0a3
Operation:writeName:KeepShortcuts
Value:
true
(PID) Process:(7448) electrum-doge-setup-1.4.2.exeKey:HKEY_CURRENT_USER\SOFTWARE\f63847d5-ec2a-595f-a172-862a9648e0a3
Operation:writeName:ShortcutName
Value:
Electrum Doge
(PID) Process:(7448) electrum-doge-setup-1.4.2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\f63847d5-ec2a-595f-a172-862a9648e0a3
Operation:writeName:DisplayName
Value:
Uninstall Electrum Doge
(PID) Process:(7448) electrum-doge-setup-1.4.2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\f63847d5-ec2a-595f-a172-862a9648e0a3
Operation:writeName:UninstallString
Value:
"C:\Users\admin\AppData\Local\Programs\Electrum Doge\Uninstall Electrum Doge.exe" /currentuser
(PID) Process:(7448) electrum-doge-setup-1.4.2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\f63847d5-ec2a-595f-a172-862a9648e0a3
Operation:writeName:QuietUninstallString
Value:
"C:\Users\admin\AppData\Local\Programs\Electrum Doge\Uninstall Electrum Doge.exe" /currentuser /S
(PID) Process:(7448) electrum-doge-setup-1.4.2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\f63847d5-ec2a-595f-a172-862a9648e0a3
Operation:writeName:DisplayVersion
Value:
1.4.1
(PID) Process:(7448) electrum-doge-setup-1.4.2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\f63847d5-ec2a-595f-a172-862a9648e0a3
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Local\Programs\Electrum Doge\uninstallerIcon.ico
(PID) Process:(7448) electrum-doge-setup-1.4.2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\f63847d5-ec2a-595f-a172-862a9648e0a3
Operation:writeName:NoModify
Value:
1
(PID) Process:(7448) electrum-doge-setup-1.4.2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\f63847d5-ec2a-595f-a172-862a9648e0a3
Operation:writeName:NoRepair
Value:
1
Executable files
23
Suspicious files
191
Text files
49
Unknown types
0

Dropped files

PID
Process
Filename
Type
7448electrum-doge-setup-1.4.2.exeC:\Users\admin\AppData\Local\Temp\nslF8CA.tmp\app-64.7z
MD5:
SHA256:
7448electrum-doge-setup-1.4.2.exeC:\Users\admin\AppData\Local\Temp\nslF8CA.tmp\7z-out\icudtl.dat
MD5:
SHA256:
7448electrum-doge-setup-1.4.2.exeC:\Users\admin\AppData\Local\Temp\nslF8CA.tmp\7z-out\LICENSES.chromium.html
MD5:
SHA256:
7448electrum-doge-setup-1.4.2.exeC:\Users\admin\AppData\Local\Temp\nslF8CA.tmp\System.dllexecutable
MD5:0D7AD4F45DC6F5AA87F606D0331C6901
SHA256:3EB38AE99653A7DBC724132EE240F6E5C4AF4BFE7C01D31D23FAF373F9F2EACA
7448electrum-doge-setup-1.4.2.exeC:\Users\admin\AppData\Local\Temp\nslF8CA.tmp\7z-out\chrome_100_percent.pakbinary
MD5:ACD0FA0A90B43CD1C87A55A991B4FAC3
SHA256:CCBCA246B9A93FA8D4F01A01345E7537511C590E4A8EFD5777B1596D10923B4B
7448electrum-doge-setup-1.4.2.exeC:\Users\admin\AppData\Local\Temp\nslF8CA.tmp\nsDialogs.dllexecutable
MD5:466179E1C8EE8A1FF5E4427DBB6C4A01
SHA256:1E40211AF65923C2F4FD02CE021458A7745D28E2F383835E3015E96575632172
7448electrum-doge-setup-1.4.2.exeC:\Users\admin\AppData\Local\Temp\nslF8CA.tmp\nsis7z.dllexecutable
MD5:80E44CE4895304C6A3A831310FBF8CD0
SHA256:B393F05E8FF919EF071181050E1873C9A776E1A0AE8329AEFFF7007D0CADF592
7448electrum-doge-setup-1.4.2.exeC:\Users\admin\AppData\Local\Programs\Electrum Doge\uninstallerIcon.icoimage
MD5:C48C02955BB533C9E28C33B9570665FF
SHA256:AC72EF57289D9837F770933A9592E4A25BC3919027B4D615C603A42ED5284C0B
7448electrum-doge-setup-1.4.2.exeC:\Users\admin\AppData\Local\Temp\nslF8CA.tmp\7z-out\LICENSE.electron.txttext
MD5:4D42118D35941E0F664DDDBD83F633C5
SHA256:5154E165BD6C2CC0CFBCD8916498C7ABAB0497923BAFCD5CB07673FE8480087D
7448electrum-doge-setup-1.4.2.exeC:\Users\admin\AppData\Local\Temp\nslF8CA.tmp\7z-out\locales\af.pakbinary
MD5:7E51349EDC7E6AED122BFA00970FAB80
SHA256:F528E698B164283872F76DF2233A47D7D41E1ABA980CE39F6B078E577FD14C97
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
23
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7664
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7664
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5496
MoUsoCoreWorker.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
20.198.162.76:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
SG
whitelisted
6544
svchost.exe
40.126.32.74:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
7664
SIHClient.exe
20.12.23.50:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7664
SIHClient.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
google.com
  • 142.250.186.174
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.176
  • 23.48.23.143
whitelisted
client.wns.windows.com
  • 20.198.162.76
whitelisted
login.live.com
  • 40.126.32.74
  • 20.190.160.20
  • 20.190.160.130
  • 20.190.160.132
  • 20.190.160.14
  • 40.126.32.134
  • 20.190.160.4
  • 40.126.32.136
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted
electrum-doge.online
  • 146.185.233.58
unknown

Threats

No threats detected
No debug info