File name:

MicroDicom-2024.1-win32.exe

Full analysis: https://app.any.run/tasks/a45c0cbd-3e39-4d72-bf98-355cdc8ae72a
Verdict: Malicious activity
Analysis date: March 27, 2024, 15:42:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

884D7210DBF948544935D6CB1101C831

SHA1:

576620ED7536E01A8C454F631FB7BCF854BF88D8

SHA256:

F27119C8643134BA4864C85694C7AFD8B9781F8A74CC669E760DEAD4AE6D8B73

SSDEEP:

98304:sFhiddI4FLZ8rfUDdUDklirWSedooitasCpWWdRs7cy8Vj/k4fOZ0H3u/50P+OoJ:Qy6LxeJxRcKJRFSGwokPytI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • MicroDicom-2024.1-win32.exe (PID: 2408)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • MicroDicom-2024.1-win32.exe (PID: 2408)
    • The process creates files with name similar to system file names

      • MicroDicom-2024.1-win32.exe (PID: 2408)
    • Creates a software uninstall entry

      • MicroDicom-2024.1-win32.exe (PID: 2408)
  • INFO

    • Reads the computer name

      • MicroDicom-2024.1-win32.exe (PID: 2408)
      • mDicom.exe (PID: 2372)
    • Checks supported languages

      • MicroDicom-2024.1-win32.exe (PID: 2408)
      • mDicom.exe (PID: 2372)
    • Create files in a temporary directory

      • MicroDicom-2024.1-win32.exe (PID: 2408)
      • mDicom.exe (PID: 2372)
    • Creates files in the program directory

      • MicroDicom-2024.1-win32.exe (PID: 2408)
      • mDicom.exe (PID: 2372)
    • Manual execution by a user

      • msedge.exe (PID: 1656)
      • mDicom.exe (PID: 2372)
    • Application launched itself

      • msedge.exe (PID: 1656)
    • Reads the machine GUID from the registry

      • MicroDicom-2024.1-win32.exe (PID: 2408)
      • mDicom.exe (PID: 2372)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:08:01 02:43:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26112
InitializedDataSize: 141824
UninitializedDataSize: 2048
EntryPoint: 0x348f
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
11
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start microdicom-2024.1-win32.exe msedge.exe mdicom.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs microdicom-2024.1-win32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
712"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2164 --field-trial-handle=1324,i,152761424236100123,2671054301115459441,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
748"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6baef598,0x6baef5a8,0x6baef5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
764"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1592 --field-trial-handle=1324,i,152761424236100123,2671054301115459441,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
880"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1648 --field-trial-handle=1324,i,152761424236100123,2671054301115459441,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1624"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2180 --field-trial-handle=1324,i,152761424236100123,2671054301115459441,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1656"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://www.microdicom.com/C:\Program Files\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2124"C:\Users\admin\AppData\Local\Temp\MicroDicom-2024.1-win32.exe" C:\Users\admin\AppData\Local\Temp\MicroDicom-2024.1-win32.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\microdicom-2024.1-win32.exe
c:\windows\system32\ntdll.dll
2240"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1288 --field-trial-handle=1324,i,152761424236100123,2671054301115459441,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2320"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1468 --field-trial-handle=1324,i,152761424236100123,2671054301115459441,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2372"C:\Program Files\MicroDicom\mDicom.exe" C:\Program Files\MicroDicom\mDicom.exe
explorer.exe
User:
admin
Company:
MicroDicom
Integrity Level:
MEDIUM
Description:
MicroDicom DICOM Viewer (32-bit)
Version:
2024.1.0.8421
Modules
Images
c:\program files\microdicom\mdicom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\avifil32.dll
Total events
5 247
Read events
5 188
Write events
54
Delete events
5

Modification events

(PID) Process:(2408) MicroDicom-2024.1-win32.exeKey:HKEY_CURRENT_USER\Software\RegisteredApplications
Operation:delete valueName:MicroDicom
Value:
(PID) Process:(2408) MicroDicom-2024.1-win32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\RegisteredApplications
Operation:delete valueName:MicroDicom
Value:
(PID) Process:(2408) MicroDicom-2024.1-win32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mDicom.exe
Operation:writeName:Path
Value:
C:\Program Files\MicroDicom
(PID) Process:(2408) MicroDicom-2024.1-win32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\mDicom32.exe\SupportedTypes
Operation:writeName:.dcm
Value:
(PID) Process:(2408) MicroDicom-2024.1-win32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\mDicom32.exe\SupportedTypes
Operation:writeName:.dcm30
Value:
(PID) Process:(2408) MicroDicom-2024.1-win32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\mDicom32.exe\SupportedTypes
Operation:writeName:.bmp
Value:
(PID) Process:(2408) MicroDicom-2024.1-win32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\mDicom32.exe\SupportedTypes
Operation:writeName:.gif
Value:
(PID) Process:(2408) MicroDicom-2024.1-win32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\mDicom32.exe\SupportedTypes
Operation:writeName:.jpeg
Value:
(PID) Process:(2408) MicroDicom-2024.1-win32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\mDicom32.exe\SupportedTypes
Operation:writeName:.jpe
Value:
(PID) Process:(2408) MicroDicom-2024.1-win32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\mDicom32.exe\SupportedTypes
Operation:writeName:.jpg
Value:
Executable files
7
Suspicious files
10
Text files
38
Unknown types
35

Dropped files

PID
Process
Filename
Type
2408MicroDicom-2024.1-win32.exeC:\Users\admin\AppData\Local\Temp\nsw2AC5.tmp\System.dllexecutable
MD5:
SHA256:
2408MicroDicom-2024.1-win32.exeC:\Users\admin\AppData\Local\Temp\nsw2AC5.tmp\splash.bmpimage
MD5:
SHA256:
2408MicroDicom-2024.1-win32.exeC:\Users\admin\AppData\Local\Temp\nsw2AC5.tmp\advsplash.dllexecutable
MD5:
SHA256:
2408MicroDicom-2024.1-win32.exeC:\Users\admin\AppData\Local\Temp\nsw2AC5.tmp\modern-wizard.bmpimage
MD5:
SHA256:
2408MicroDicom-2024.1-win32.exeC:\Users\admin\AppData\Local\Temp\nsw2AC5.tmp\nsDialogs.dllexecutable
MD5:
SHA256:
2408MicroDicom-2024.1-win32.exeC:\Users\admin\AppData\Local\Temp\nsw2AC5.tmp\nsProcess.dllexecutable
MD5:
SHA256:
2408MicroDicom-2024.1-win32.exeC:\Program Files\MicroDicom\mDicom.chmbinary
MD5:
SHA256:
2408MicroDicom-2024.1-win32.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\MicroDicom DICOM Viewer (32-bit)\MicroDicom DICOM Viewer Help.lnkbinary
MD5:
SHA256:
2408MicroDicom-2024.1-win32.exeC:\Program Files\MicroDicom\mDicom.exeexecutable
MD5:
SHA256:
2408MicroDicom-2024.1-win32.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\MicroDicom DICOM Viewer (32-bit)\MicroDicom DICOM Viewer (32-bit).lnkbinary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
15
DNS requests
15
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
1656
msedge.exe
239.255.255.250:1900
unknown
2320
msedge.exe
35.215.88.130:443
www.microdicom.com
GOOGLE
US
unknown
2320
msedge.exe
131.253.33.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2320
msedge.exe
13.107.43.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2320
msedge.exe
172.217.23.106:443
fonts.googleapis.com
GOOGLE
US
whitelisted
2320
msedge.exe
172.64.147.188:443
kit.fontawesome.com
CLOUDFLARENET
US
unknown

DNS requests

Domain
IP
Reputation
www.microdicom.com
  • 35.215.88.130
unknown
edge.microsoft.com
  • 131.253.33.239
  • 13.107.22.239
whitelisted
config.edge.skype.com
  • 13.107.43.16
whitelisted
fonts.googleapis.com
  • 172.217.23.106
whitelisted
kit.fontawesome.com
  • 172.64.147.188
  • 104.18.40.68
whitelisted
fonts.gstatic.com
  • 142.250.185.99
whitelisted
www.bing.com
  • 104.126.37.163
  • 104.126.37.152
  • 104.126.37.160
  • 104.126.37.136
  • 104.126.37.170
  • 104.126.37.139
  • 104.126.37.145
  • 104.126.37.161
  • 104.126.37.153
whitelisted

Threats

No threats detected
Process
Message
MicroDicom-2024.1-win32.exe
ExecShellAsUser: got desktop
MicroDicom-2024.1-win32.exe
ExecShellAsUser: elevated process detected
MicroDicom-2024.1-win32.exe
ExecShellAsUser: thread finished
MicroDicom-2024.1-win32.exe
ExecShellAsUser: DLL_PROCESS_DETACH