File name:

MicroDicom-2024.1-x64.exe

Full analysis: https://app.any.run/tasks/b56e4997-adb6-4ae0-b9d4-57da51f6f20c
Verdict: Malicious activity
Analysis date: August 22, 2024, 05:46:24
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

B6C0E66F052F28887211A1A0EE12994B

SHA1:

805981F2C9FBC74DC60D35D89B438E0C39B6474E

SHA256:

38E49B889CE3102AA49E2095591CB490D5FC27E7069FB89924689B6AF03F675D

SSDEEP:

98304:LFhiddI4FLZ8rKUDdUDklirWSedooitasCpWWdRs7cy8Vj/k4fOZ0H3u/50P+OoO:wy6LxeP0gVReCxcqEkXX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • MicroDicom-2024.1-x64.exe (PID: 6716)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • MicroDicom-2024.1-x64.exe (PID: 6716)
    • The process creates files with name similar to system file names

      • MicroDicom-2024.1-x64.exe (PID: 6716)
    • Executable content was dropped or overwritten

      • MicroDicom-2024.1-x64.exe (PID: 6716)
    • Creates a software uninstall entry

      • MicroDicom-2024.1-x64.exe (PID: 6716)
  • INFO

    • Creates files in the program directory

      • MicroDicom-2024.1-x64.exe (PID: 6716)
      • mDicom.exe (PID: 6300)
    • Create files in a temporary directory

      • MicroDicom-2024.1-x64.exe (PID: 6716)
      • mDicom.exe (PID: 6300)
    • Manual execution by a user

      • msedge.exe (PID: 6280)
      • mDicom.exe (PID: 6300)
    • Reads the computer name

      • MicroDicom-2024.1-x64.exe (PID: 6716)
      • mDicom.exe (PID: 6300)
      • identity_helper.exe (PID: 8028)
    • Checks supported languages

      • MicroDicom-2024.1-x64.exe (PID: 6716)
      • mDicom.exe (PID: 6300)
      • identity_helper.exe (PID: 8028)
    • Application launched itself

      • msedge.exe (PID: 6280)
    • Reads Microsoft Office registry keys

      • msedge.exe (PID: 6280)
    • Reads Environment values

      • identity_helper.exe (PID: 8028)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:08:01 02:43:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26112
InitializedDataSize: 141824
UninitializedDataSize: 2048
EntryPoint: 0x348f
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
169
Monitored processes
33
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start microdicom-2024.1-x64.exe msedge.exe mdicom.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs microdicom-2024.1-x64.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
232"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=6484 --field-trial-handle=2276,i,3009794244805864672,16333888888242085186,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1164"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=5180 --field-trial-handle=2276,i,3009794244805864672,16333888888242085186,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5400"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3512 --field-trial-handle=2276,i,3009794244805864672,16333888888242085186,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6264"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x300,0x304,0x308,0x2f4,0x310,0x7fffd30e5fd8,0x7fffd30e5fe4,0x7fffd30e5ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6280"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument https://www.microdicom.com/C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6300"C:\Program Files\MicroDicom\mDicom.exe" C:\Program Files\MicroDicom\mDicom.exe
explorer.exe
User:
admin
Company:
MicroDicom
Integrity Level:
MEDIUM
Description:
MicroDicom DICOM Viewer (64-bit)
Version:
2024.1.0.5132
Modules
Images
c:\program files\microdicom\mdicom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6648"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=2780 --field-trial-handle=2276,i,3009794244805864672,16333888888242085186,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6664"C:\Users\admin\AppData\Local\Temp\MicroDicom-2024.1-x64.exe" C:\Users\admin\AppData\Local\Temp\MicroDicom-2024.1-x64.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\microdicom-2024.1-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6672"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2272 --field-trial-handle=2276,i,3009794244805864672,16333888888242085186,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6696"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2424 --field-trial-handle=2276,i,3009794244805864672,16333888888242085186,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
11 197
Read events
11 072
Write events
120
Delete events
5

Modification events

(PID) Process:(6716) MicroDicom-2024.1-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\RegisteredApplications
Operation:delete valueName:MicroDicom
Value:
(PID) Process:(6716) MicroDicom-2024.1-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\RegisteredApplications
Operation:delete valueName:MicroDicom
Value:
(PID) Process:(6716) MicroDicom-2024.1-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mDicom.exe
Operation:writeName:Path
Value:
C:\Program Files\MicroDicom
(PID) Process:(6716) MicroDicom-2024.1-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\mDicom64.exe\SupportedTypes
Operation:writeName:.dcm
Value:
(PID) Process:(6716) MicroDicom-2024.1-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\mDicom64.exe\SupportedTypes
Operation:writeName:.dcm30
Value:
(PID) Process:(6716) MicroDicom-2024.1-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\mDicom64.exe\SupportedTypes
Operation:writeName:.bmp
Value:
(PID) Process:(6716) MicroDicom-2024.1-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\mDicom64.exe\SupportedTypes
Operation:writeName:.gif
Value:
(PID) Process:(6716) MicroDicom-2024.1-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\mDicom64.exe\SupportedTypes
Operation:writeName:.jpeg
Value:
(PID) Process:(6716) MicroDicom-2024.1-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\mDicom64.exe\SupportedTypes
Operation:writeName:.jpe
Value:
(PID) Process:(6716) MicroDicom-2024.1-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\mDicom64.exe\SupportedTypes
Operation:writeName:.jpg
Value:
Executable files
9
Suspicious files
67
Text files
46
Unknown types
1

Dropped files

PID
Process
Filename
Type
6716MicroDicom-2024.1-x64.exeC:\Program Files\MicroDicom\licenses\license.txttext
MD5:351952C5990DFAD3414854B56482E44E
SHA256:6F9BEEF75238B9B2C675214FE16BA970FFA6F02AA45ED50432E276F45ECD649F
6716MicroDicom-2024.1-x64.exeC:\Users\admin\AppData\Local\Temp\nswDE77.tmp\advsplash.dllexecutable
MD5:1871AF84805057B5EBC05EE46B56625D
SHA256:62B3DB0446750CA9FD693733EEC927ACC1F50012A47785343286E63B650B7621
6716MicroDicom-2024.1-x64.exeC:\Program Files\MicroDicom\licenses\EULA.txttext
MD5:7B11D4A9863C46F7DD99C818BCF2DC25
SHA256:9DE357A6644B877F3F79A485631A95D7528F5656C00492149974407439F1E03B
6716MicroDicom-2024.1-x64.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\MicroDicom DICOM Viewer (64-bit)\MicroDicom DICOM Viewer Help.lnklnk
MD5:68D288F845FD6CBA8DD4AA57A9F42905
SHA256:075C5A71B0503443081BECDC960E3827CCF9CA2D430AE113542210A072FAB5DF
6716MicroDicom-2024.1-x64.exeC:\Users\admin\AppData\Local\Temp\nswDE77.tmp\nsDialogs.dllexecutable
MD5:48F3E7860E1DE2B4E63EC744A5E9582A
SHA256:6BF9CCCD8A600F4D442EFE201E8C07B49605BA35F49A4B3AB22FA2641748E156
6280msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.datbinary
MD5:02DDA7725803EF3F8FFB664727286EB7
SHA256:802408FEB482A3538AD2FB3D61696F4335418874B563929EBF014CEEA8825F25
6280msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF120a68.TMP
MD5:
SHA256:
6716MicroDicom-2024.1-x64.exeC:\Users\admin\AppData\Local\Temp\nswDE77.tmp\ShellExecAsUser.dllexecutable
MD5:552CBA3C6C9987E01BE178E1EE22D36B
SHA256:1F17E4D5FFE7B2C9A396EE9932AC5198F0C050241E5F9CCD3A56E576613D8A29
6280msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
6280msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF120a78.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
71
DNS requests
76
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2360
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6976
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
7772
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5880
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
2120
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3540
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3540
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3260
svchost.exe
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2360
svchost.exe
20.190.159.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2360
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
6696
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6280
msedge.exe
239.255.255.250:1900
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.206
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
  • 51.104.136.2
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
login.live.com
  • 20.190.159.4
  • 20.190.159.0
  • 20.190.159.68
  • 40.126.31.71
  • 40.126.31.73
  • 40.126.31.69
  • 20.190.159.23
  • 20.190.159.64
  • 20.190.159.2
  • 20.190.159.73
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
www.microdicom.com
  • 35.215.88.130
unknown
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
business.bing.com
  • 13.107.6.158
whitelisted
edge-mobile-static.azureedge.net
  • 13.107.246.45
whitelisted

Threats

No threats detected
Process
Message
MicroDicom-2024.1-x64.exe
ExecShellAsUser: got desktop
MicroDicom-2024.1-x64.exe
ExecShellAsUser: elevated process detected
MicroDicom-2024.1-x64.exe
ExecShellAsUser: thread finished
MicroDicom-2024.1-x64.exe
ExecShellAsUser: DLL_PROCESS_DETACH