File name:

RadiAnt-2025.1-Setup.exe

Full analysis: https://app.any.run/tasks/c865f11f-77ed-4776-8c3d-1cf5abafc14f
Verdict: Malicious activity
Analysis date: May 26, 2025, 19:04:23
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

F63627A88618C0DA2AE02D5DF98400BB

SHA1:

B379667CDA3106EFD06547BC2ABC6B7FA7E077A4

SHA256:

DB503877FC27F631613366AE9F82FDF5A89B1D78DDA0978714F849CB962CDACC

SSDEEP:

98304:bzSve9E5x0zLDOYvG3LTD1dZkeW6MOnNoJ1RcOa6XgwGRzr4OzG1ILKXxrkxbd08:mrBqWh5qpXhkzyM

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Application launched itself

      • RadiAnt-2025.1-Setup.exe (PID: 5404)
      • RadiAntViewer.exe (PID: 6028)
    • Reads security settings of Internet Explorer

      • RadiAnt-2025.1-Setup.exe (PID: 5404)
      • RadiAntViewer.exe (PID: 6028)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • RadiAnt-2025.1-Setup.exe (PID: 1804)
    • Executable content was dropped or overwritten

      • RadiAnt-2025.1-Setup.exe (PID: 5404)
      • RadiAnt-2025.1-Setup.exe (PID: 1804)
    • Reads the date of Windows installation

      • RadiAnt-2025.1-Setup.exe (PID: 5404)
      • RadiAntViewer.exe (PID: 6028)
    • There is functionality for taking screenshot (YARA)

      • RadiAnt-2025.1-Setup.exe (PID: 5404)
    • Process drops legitimate windows executable

      • RadiAnt-2025.1-Setup.exe (PID: 1804)
    • Creates a software uninstall entry

      • RadiAnt-2025.1-Setup.exe (PID: 1804)
    • The process drops C-runtime libraries

      • RadiAnt-2025.1-Setup.exe (PID: 1804)
    • The process creates files with name similar to system file names

      • RadiAnt-2025.1-Setup.exe (PID: 1804)
  • INFO

    • Reads the computer name

      • RadiAnt-2025.1-Setup.exe (PID: 5404)
      • RadiAnt-2025.1-Setup.exe (PID: 1804)
      • RadiAntViewer.exe (PID: 6028)
    • Create files in a temporary directory

      • RadiAnt-2025.1-Setup.exe (PID: 5404)
      • RadiAnt-2025.1-Setup.exe (PID: 1804)
    • Checks supported languages

      • RadiAnt-2025.1-Setup.exe (PID: 5404)
      • RadiAnt-2025.1-Setup.exe (PID: 1804)
      • RadiAntViewer.exe (PID: 6028)
      • RadiAntViewer.exe (PID: 5216)
    • Process checks computer location settings

      • RadiAnt-2025.1-Setup.exe (PID: 5404)
      • RadiAntViewer.exe (PID: 6028)
    • Creates files in the program directory

      • RadiAnt-2025.1-Setup.exe (PID: 1804)
      • RadiAntViewer.exe (PID: 6028)
    • The sample compiled with english language support

      • RadiAnt-2025.1-Setup.exe (PID: 1804)
    • Checks proxy server information

      • RadiAntViewer.exe (PID: 6028)
    • Reads the software policy settings

      • RadiAntViewer.exe (PID: 6028)
    • Reads the machine GUID from the registry

      • RadiAntViewer.exe (PID: 6028)
    • Creates files or folders in the user directory

      • RadiAnt-2025.1-Setup.exe (PID: 1804)
      • RadiAntViewer.exe (PID: 6028)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:07:02 02:09:43+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 139776
UninitializedDataSize: 2048
EntryPoint: 0x3645
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2025.1.0.1600
ProductVersionNumber: 2025.1.0.1600
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Medixant
FileDescription: RadiAnt DICOM Viewer Installer
FileVersion: 2025.1.0.1600
LegalCopyright: Copyright (C) 2009-2025 Medixant
ProductName: RadiAnt DICOM Viewer
ProductVersion: 2025.1.0.1600
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
6
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start radiant-2025.1-setup.exe sppextcomobj.exe no specs slui.exe no specs radiant-2025.1-setup.exe radiantviewer.exe radiantviewer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
684"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1804"C:\Users\admin\AppData\Local\Temp\RadiAnt-2025.1-Setup.exe" /UAC:402DA /NCRC C:\Users\admin\AppData\Local\Temp\RadiAnt-2025.1-Setup.exe
RadiAnt-2025.1-Setup.exe
User:
admin
Company:
Medixant
Integrity Level:
HIGH
Description:
RadiAnt DICOM Viewer Installer
Exit code:
0
Version:
2025.1.0.1600
Modules
Images
c:\users\admin\appdata\local\temp\radiant-2025.1-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4944C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
5216"C:\Program Files\RadiAntViewer64bit\RadiAntViewer.exe" -tempcleanC:\Program Files\RadiAntViewer64bit\RadiAntViewer.exeRadiAntViewer.exe
User:
admin
Company:
Medixant
Integrity Level:
HIGH
Description:
RadiAnt DICOM Viewer (64-bit)
Exit code:
0
Version:
2025.1.0.1600
Modules
Images
c:\program files\radiantviewer64bit\radiantviewer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
5404"C:\Users\admin\AppData\Local\Temp\RadiAnt-2025.1-Setup.exe" C:\Users\admin\AppData\Local\Temp\RadiAnt-2025.1-Setup.exe
explorer.exe
User:
admin
Company:
Medixant
Integrity Level:
MEDIUM
Description:
RadiAnt DICOM Viewer Installer
Exit code:
0
Version:
2025.1.0.1600
Modules
Images
c:\users\admin\appdata\local\temp\radiant-2025.1-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6028"C:\Program Files\RadiAntViewer64bit\RadiAntViewer.exe"C:\Program Files\RadiAntViewer64bit\RadiAntViewer.exe
RadiAnt-2025.1-Setup.exe
User:
admin
Company:
Medixant
Integrity Level:
HIGH
Description:
RadiAnt DICOM Viewer (64-bit)
Exit code:
0
Version:
2025.1.0.1600
Modules
Images
c:\program files\radiantviewer64bit\radiantviewer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
7 680
Read events
7 639
Write events
41
Delete events
0

Modification events

(PID) Process:(1804) RadiAnt-2025.1-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\RadiAnt64
Operation:writeName:EstimatedSize
Value:
9674
(PID) Process:(1804) RadiAnt-2025.1-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\radiant
Operation:writeName:URL Protocol
Value:
(PID) Process:(1804) RadiAnt-2025.1-Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\RadiAnt Viewer
Operation:writeName:CheckUpdate
Value:
1
(PID) Process:(1804) RadiAnt-2025.1-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\RadiAnt Viewer
Operation:writeName:ProgramFolder64
Value:
C:\Program Files\RadiAntViewer64bit
(PID) Process:(1804) RadiAnt-2025.1-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\RadiAnt64
Operation:writeName:InstallLocation
Value:
C:\Program Files\RadiAntViewer64bit
(PID) Process:(1804) RadiAnt-2025.1-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\RadiAnt64
Operation:writeName:VersionMajor
Value:
2025
(PID) Process:(1804) RadiAnt-2025.1-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\RadiAnt64
Operation:writeName:VersionMinor
Value:
1
(PID) Process:(1804) RadiAnt-2025.1-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\RadiAnt64
Operation:writeName:MajorVersion
Value:
2025
(PID) Process:(1804) RadiAnt-2025.1-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\RadiAnt64
Operation:writeName:MinorVersion
Value:
1
(PID) Process:(1804) RadiAnt-2025.1-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\RadiAnt64
Operation:writeName:DisplayName
Value:
RadiAnt DICOM Viewer (64-bit)
Executable files
64
Suspicious files
35
Text files
13
Unknown types
0

Dropped files

PID
Process
Filename
Type
5404RadiAnt-2025.1-Setup.exeC:\Users\admin\AppData\Local\Temp\nsuA84A.tmp\UAC.dllexecutable
MD5:ADB29E6B186DAA765DC750128649B63D
SHA256:2F7F8FC05DC4FD0D5CDA501B47E4433357E887BBFED7292C028D99C73B52DC08
1804RadiAnt-2025.1-Setup.exeC:\Users\admin\AppData\Local\Temp\nsrAF2F.tmp\UAC.dllexecutable
MD5:ADB29E6B186DAA765DC750128649B63D
SHA256:2F7F8FC05DC4FD0D5CDA501B47E4433357E887BBFED7292C028D99C73B52DC08
1804RadiAnt-2025.1-Setup.exeC:\Program Files\RadiAntViewer64bit\api-ms-win-core-debug-l1-1-0.dllexecutable
MD5:624401F31A706B1AE2245EB19264DC7F
SHA256:58A8D69DF60ECBEE776CD9A74B2A32B14BF2B0BD92D527EC5F19502A0D3EB8E9
1804RadiAnt-2025.1-Setup.exeC:\Program Files\RadiAntViewer64bit\jpeg2000.dllexecutable
MD5:F1F9A21998976B6A49A4F2A6C4869503
SHA256:29C532F661AFE895A1F7E80076B0351F6F7B628C97AAE01BF066A7CD86293746
1804RadiAnt-2025.1-Setup.exeC:\Users\admin\AppData\Local\Temp\nsrAF2F.tmp\nsDialogs.dllexecutable
MD5:1D8F01A83DDD259BC339902C1D33C8F1
SHA256:4B7D17DA290F41EBE244827CC295CE7E580DA2F7E9F7CC3EFC1ABC6898E3C9ED
1804RadiAnt-2025.1-Setup.exeC:\Program Files\RadiAntViewer64bit\jpeg2.dllexecutable
MD5:D3C13C74FC74457FA998D059EE59C3FB
SHA256:84F8ED4797A50227C02A70BC6CF780842A3A52C69A70F54EDFDDA4037AD4CE14
1804RadiAnt-2025.1-Setup.exeC:\Program Files\RadiAntViewer64bit\jpeg3.dllexecutable
MD5:249937AD03EEEABFFB33F055C4AAE26C
SHA256:6F1CEA3A7312581B5E66A4E5D68DE4BA3273CBD4D4B76826ADD2FE222CC820FB
1804RadiAnt-2025.1-Setup.exeC:\Program Files\RadiAntViewer64bit\api-ms-win-core-console-l1-1-0.dllexecutable
MD5:07EBE4D5CEF3301CCF07430F4C3E32D8
SHA256:8F8B79150E850ACC92FD6AAB614F6E3759BEA875134A62087D5DD65581E3001F
1804RadiAnt-2025.1-Setup.exeC:\Program Files\RadiAntViewer64bit\api-ms-win-core-console-l1-2-0.dllexecutable
MD5:57193BFBCCEFE3D5DF8C1A0D27C4E8D4
SHA256:F5025E74DE2C1C6EA74E475B57771AC32205E6F1FA6A0390298BBE1F4049AC5D
1804RadiAnt-2025.1-Setup.exeC:\Program Files\RadiAntViewer64bit\api-ms-win-core-datetime-l1-1-0.dllexecutable
MD5:557405C47613DE66B111D0E2B01F2FDB
SHA256:913EAAA7997A6AEE53574CFFB83F9C9C1700B1D8B46744A5E12D76A1E53376FD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
21
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.19.126.226:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
GET
200
23.209.214.100:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
ID
binary
868 b
whitelisted
GET
200
23.209.214.100:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
ID
binary
868 b
whitelisted
632
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
419 b
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
632
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
407 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6592
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.19.126.226:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.209.214.100:80
www.microsoft.com
PT. Telekomunikasi Selular
ID
whitelisted
5796
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
6544
svchost.exe
20.190.159.0:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
google.com
  • 142.250.185.110
whitelisted
crl.microsoft.com
  • 2.19.126.226
  • 2.19.126.218
whitelisted
www.microsoft.com
  • 23.209.214.100
  • 23.35.229.160
whitelisted
login.live.com
  • 20.190.159.0
  • 20.190.159.68
  • 40.126.31.69
  • 20.190.159.131
  • 20.190.159.2
  • 20.190.159.128
  • 20.190.159.75
  • 40.126.31.2
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
activate.radiantviewer.com
  • 137.74.7.228
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted

Threats

No threats detected
No debug info