File name:

RadiAnt-2025.1-Setup.exe

Full analysis: https://app.any.run/tasks/c865f11f-77ed-4776-8c3d-1cf5abafc14f
Verdict: Malicious activity
Analysis date: May 26, 2025, 19:04:23
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

F63627A88618C0DA2AE02D5DF98400BB

SHA1:

B379667CDA3106EFD06547BC2ABC6B7FA7E077A4

SHA256:

DB503877FC27F631613366AE9F82FDF5A89B1D78DDA0978714F849CB962CDACC

SSDEEP:

98304:bzSve9E5x0zLDOYvG3LTD1dZkeW6MOnNoJ1RcOa6XgwGRzr4OzG1ILKXxrkxbd08:mrBqWh5qpXhkzyM

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • RadiAnt-2025.1-Setup.exe (PID: 1804)
      • RadiAnt-2025.1-Setup.exe (PID: 5404)
    • Reads security settings of Internet Explorer

      • RadiAnt-2025.1-Setup.exe (PID: 5404)
      • RadiAntViewer.exe (PID: 6028)
    • Reads the date of Windows installation

      • RadiAnt-2025.1-Setup.exe (PID: 5404)
      • RadiAntViewer.exe (PID: 6028)
    • The process creates files with name similar to system file names

      • RadiAnt-2025.1-Setup.exe (PID: 1804)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • RadiAnt-2025.1-Setup.exe (PID: 1804)
    • Application launched itself

      • RadiAnt-2025.1-Setup.exe (PID: 5404)
      • RadiAntViewer.exe (PID: 6028)
    • There is functionality for taking screenshot (YARA)

      • RadiAnt-2025.1-Setup.exe (PID: 5404)
    • Process drops legitimate windows executable

      • RadiAnt-2025.1-Setup.exe (PID: 1804)
    • The process drops C-runtime libraries

      • RadiAnt-2025.1-Setup.exe (PID: 1804)
    • Creates a software uninstall entry

      • RadiAnt-2025.1-Setup.exe (PID: 1804)
  • INFO

    • Create files in a temporary directory

      • RadiAnt-2025.1-Setup.exe (PID: 5404)
      • RadiAnt-2025.1-Setup.exe (PID: 1804)
    • Reads the computer name

      • RadiAnt-2025.1-Setup.exe (PID: 5404)
      • RadiAnt-2025.1-Setup.exe (PID: 1804)
      • RadiAntViewer.exe (PID: 6028)
    • Checks supported languages

      • RadiAnt-2025.1-Setup.exe (PID: 5404)
      • RadiAnt-2025.1-Setup.exe (PID: 1804)
      • RadiAntViewer.exe (PID: 6028)
      • RadiAntViewer.exe (PID: 5216)
    • Process checks computer location settings

      • RadiAnt-2025.1-Setup.exe (PID: 5404)
      • RadiAntViewer.exe (PID: 6028)
    • Creates files in the program directory

      • RadiAnt-2025.1-Setup.exe (PID: 1804)
      • RadiAntViewer.exe (PID: 6028)
    • The sample compiled with english language support

      • RadiAnt-2025.1-Setup.exe (PID: 1804)
    • Creates files or folders in the user directory

      • RadiAnt-2025.1-Setup.exe (PID: 1804)
      • RadiAntViewer.exe (PID: 6028)
    • Checks proxy server information

      • RadiAntViewer.exe (PID: 6028)
    • Reads the software policy settings

      • RadiAntViewer.exe (PID: 6028)
    • Reads the machine GUID from the registry

      • RadiAntViewer.exe (PID: 6028)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:07:02 02:09:43+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 139776
UninitializedDataSize: 2048
EntryPoint: 0x3645
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2025.1.0.1600
ProductVersionNumber: 2025.1.0.1600
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Medixant
FileDescription: RadiAnt DICOM Viewer Installer
FileVersion: 2025.1.0.1600
LegalCopyright: Copyright (C) 2009-2025 Medixant
ProductName: RadiAnt DICOM Viewer
ProductVersion: 2025.1.0.1600
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
6
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start radiant-2025.1-setup.exe sppextcomobj.exe no specs slui.exe no specs radiant-2025.1-setup.exe radiantviewer.exe radiantviewer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
684"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1804"C:\Users\admin\AppData\Local\Temp\RadiAnt-2025.1-Setup.exe" /UAC:402DA /NCRC C:\Users\admin\AppData\Local\Temp\RadiAnt-2025.1-Setup.exe
RadiAnt-2025.1-Setup.exe
User:
admin
Company:
Medixant
Integrity Level:
HIGH
Description:
RadiAnt DICOM Viewer Installer
Exit code:
0
Version:
2025.1.0.1600
Modules
Images
c:\users\admin\appdata\local\temp\radiant-2025.1-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4944C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
5216"C:\Program Files\RadiAntViewer64bit\RadiAntViewer.exe" -tempcleanC:\Program Files\RadiAntViewer64bit\RadiAntViewer.exeRadiAntViewer.exe
User:
admin
Company:
Medixant
Integrity Level:
HIGH
Description:
RadiAnt DICOM Viewer (64-bit)
Exit code:
0
Version:
2025.1.0.1600
Modules
Images
c:\program files\radiantviewer64bit\radiantviewer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
5404"C:\Users\admin\AppData\Local\Temp\RadiAnt-2025.1-Setup.exe" C:\Users\admin\AppData\Local\Temp\RadiAnt-2025.1-Setup.exe
explorer.exe
User:
admin
Company:
Medixant
Integrity Level:
MEDIUM
Description:
RadiAnt DICOM Viewer Installer
Exit code:
0
Version:
2025.1.0.1600
Modules
Images
c:\users\admin\appdata\local\temp\radiant-2025.1-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6028"C:\Program Files\RadiAntViewer64bit\RadiAntViewer.exe"C:\Program Files\RadiAntViewer64bit\RadiAntViewer.exe
RadiAnt-2025.1-Setup.exe
User:
admin
Company:
Medixant
Integrity Level:
HIGH
Description:
RadiAnt DICOM Viewer (64-bit)
Exit code:
0
Version:
2025.1.0.1600
Modules
Images
c:\program files\radiantviewer64bit\radiantviewer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
7 680
Read events
7 639
Write events
41
Delete events
0

Modification events

(PID) Process:(1804) RadiAnt-2025.1-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\RadiAnt64
Operation:writeName:EstimatedSize
Value:
9674
(PID) Process:(1804) RadiAnt-2025.1-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\radiant
Operation:writeName:URL Protocol
Value:
(PID) Process:(1804) RadiAnt-2025.1-Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\RadiAnt Viewer
Operation:writeName:CheckUpdate
Value:
1
(PID) Process:(1804) RadiAnt-2025.1-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\RadiAnt Viewer
Operation:writeName:ProgramFolder64
Value:
C:\Program Files\RadiAntViewer64bit
(PID) Process:(1804) RadiAnt-2025.1-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\RadiAnt64
Operation:writeName:InstallLocation
Value:
C:\Program Files\RadiAntViewer64bit
(PID) Process:(1804) RadiAnt-2025.1-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\RadiAnt64
Operation:writeName:VersionMajor
Value:
2025
(PID) Process:(1804) RadiAnt-2025.1-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\RadiAnt64
Operation:writeName:VersionMinor
Value:
1
(PID) Process:(1804) RadiAnt-2025.1-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\RadiAnt64
Operation:writeName:MajorVersion
Value:
2025
(PID) Process:(1804) RadiAnt-2025.1-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\RadiAnt64
Operation:writeName:MinorVersion
Value:
1
(PID) Process:(1804) RadiAnt-2025.1-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\RadiAnt64
Operation:writeName:DisplayName
Value:
RadiAnt DICOM Viewer (64-bit)
Executable files
64
Suspicious files
35
Text files
13
Unknown types
0

Dropped files

PID
Process
Filename
Type
1804RadiAnt-2025.1-Setup.exeC:\Users\admin\AppData\Local\Temp\nsrAF2F.tmp\modern-wizard.bmpimage
MD5:89DD95BAED6A090F4216A67539BA3981
SHA256:063D0C9BA953C5A2140D163DFBBE18645774FCD224BCE9A16880BA37E8865D8F
1804RadiAnt-2025.1-Setup.exeC:\Program Files\RadiAntViewer64bit\gpuengine.dllexecutable
MD5:B2A8161D752AF1F3BDFABD52BE817987
SHA256:0A6780813AAEBB9BDBE0F320385D7801C33C23447F9B304B9C402A07B760B510
1804RadiAnt-2025.1-Setup.exeC:\Program Files\RadiAntViewer64bit\jpeg2000.dllexecutable
MD5:F1F9A21998976B6A49A4F2A6C4869503
SHA256:29C532F661AFE895A1F7E80076B0351F6F7B628C97AAE01BF066A7CD86293746
1804RadiAnt-2025.1-Setup.exeC:\Program Files\RadiAntViewer64bit\jpeg4.dllexecutable
MD5:CC6F286FDAFC213B531E5BAC99CEC852
SHA256:8FE0613DFD5936E49419D367F9F509C73CBD43BFBE7477A5E4AD2B44F6FEE087
1804RadiAnt-2025.1-Setup.exeC:\Program Files\RadiAntViewer64bit\jpeg2.dllexecutable
MD5:D3C13C74FC74457FA998D059EE59C3FB
SHA256:84F8ED4797A50227C02A70BC6CF780842A3A52C69A70F54EDFDDA4037AD4CE14
1804RadiAnt-2025.1-Setup.exeC:\Users\admin\AppData\Local\Temp\nsrAF2F.tmp\modern-header.bmpimage
MD5:BD54A4F993CCD7BFD21521826D989643
SHA256:D357B1684B8275F8F721337FCB4DB47F98CCC17A8473753ECCC80D646248C8D9
1804RadiAnt-2025.1-Setup.exeC:\Program Files\RadiAntViewer64bit\jpeg3.dllexecutable
MD5:249937AD03EEEABFFB33F055C4AAE26C
SHA256:6F1CEA3A7312581B5E66A4E5D68DE4BA3273CBD4D4B76826ADD2FE222CC820FB
1804RadiAnt-2025.1-Setup.exeC:\Users\admin\AppData\Local\Temp\nsrAF2F.tmp\nsDialogs.dllexecutable
MD5:1D8F01A83DDD259BC339902C1D33C8F1
SHA256:4B7D17DA290F41EBE244827CC295CE7E580DA2F7E9F7CC3EFC1ABC6898E3C9ED
1804RadiAnt-2025.1-Setup.exeC:\Program Files\RadiAntViewer64bit\api-ms-win-core-debug-l1-1-0.dllexecutable
MD5:624401F31A706B1AE2245EB19264DC7F
SHA256:58A8D69DF60ECBEE776CD9A74B2A32B14BF2B0BD92D527EC5F19502A0D3EB8E9
1804RadiAnt-2025.1-Setup.exeC:\Program Files\RadiAntViewer64bit\RadiAntViewer.exeexecutable
MD5:9DC63BC50CE184184C05883E08F3EF6B
SHA256:176CD88CDB63E032EBECA38E773AD4E0F955688E11FC68B296A35B9C0BA430DE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
21
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.209.214.100:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.209.214.100:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.19.126.226:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
632
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
632
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6592
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.19.126.226:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.209.214.100:80
www.microsoft.com
PT. Telekomunikasi Selular
ID
whitelisted
5796
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
6544
svchost.exe
20.190.159.0:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
google.com
  • 142.250.185.110
whitelisted
crl.microsoft.com
  • 2.19.126.226
  • 2.19.126.218
whitelisted
www.microsoft.com
  • 23.209.214.100
  • 23.35.229.160
whitelisted
login.live.com
  • 20.190.159.0
  • 20.190.159.68
  • 40.126.31.69
  • 20.190.159.131
  • 20.190.159.2
  • 20.190.159.128
  • 20.190.159.75
  • 40.126.31.2
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
activate.radiantviewer.com
  • 137.74.7.228
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted

Threats

No threats detected
No debug info