IOC Report
dcm2niix.exe

loading gif

Files

File Path
Type
Category
Malicious
dcm2niix.exe
PE32+ executable (console) x86-64, for MS Windows
initial sample
\Device\ConDrv
ASCII text, with very long lines (408), with CRLF line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\dcm2niix.exe
"C:\Users\user\Desktop\dcm2niix.exe"
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
http://neurojson.org)AnnotationFormathttps://github.com/NeuroJSON/jnifti/blob/master/JNIfTI_specific
unknown
https://github.com/NeuroJSON/jnifty
unknown
https://www.cognitiveatlas.org/task/id/trm_4c8a834779883/
unknown
http://json.orgSpecialA75DataTypeNameA75DBNameA75ExtendsA75SessionErrorA75GlobalMaxA75GlobalMinbase6
unknown
https://github.com/rordenlab/dcm2niix/issues/236
unknown
http://neurojson.org)
unknown
https://github.com/NeuroJSON/jnifti/blob/master/JNIfTI_specification.md
unknown
https://github.com/NeuroJSON/jsdata
unknown
https://pypi.org/project/jdata
unknown
https://github.com/NeuroJSON/bjdata/blob/master/Binary_JData_Specification.md
unknown
https://pypi.org/project/bjdatahttps://github.com/NeuroJSON/jniftyJavaScripthttps://github.com/Neuro
unknown
http://teem.sourceforge.net/nrrd/format.html
unknown
https://pypi.org/project/bjdata
unknown
http://json.org
unknown
There are 4 hidden URLs, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
D35DBA9000
stack
page read and write
2741B0F8000
heap
page read and write
2741AFD0000
heap
page read and write
7FF7D2010000
unkown
page readonly
7FF7D1F57000
unkown
page readonly
7FF7D200E000
unkown
page read and write
2741B0E8000
heap
page read and write
2741B0C9000
heap
page read and write
7FF7D1F57000
unkown
page readonly
2741B0CC000
heap
page read and write
2741B0F8000
heap
page read and write
7FF7D1EA1000
unkown
page execute read
7FF7D1F84000
unkown
page read and write
2741B0C0000
heap
page read and write
2741B1E0000
heap
page read and write
7FF7D1EA1000
unkown
page execute read
7FF7D1EA0000
unkown
page readonly
2741B1C0000
heap
page read and write
D35FB0F000
stack
page read and write
D35EB5F000
stack
page read and write
7FF7D2006000
unkown
page read and write
2741B3D0000
heap
page read and write
7FF7D1F83000
unkown
page write copy
7FF7D1F83000
unkown
page write copy
7FF7D2010000
unkown
page readonly
7FF7D1EA0000
unkown
page readonly
2741B0D7000
heap
page read and write
There are 17 hidden memdumps, click here to show them.