Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
dcm2niix.exe
|
PE32+ executable (console) x86-64, for MS Windows
|
initial sample
|
||
\Device\ConDrv
|
ASCII text, with very long lines (408), with CRLF line terminators
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\dcm2niix.exe
|
"C:\Users\user\Desktop\dcm2niix.exe"
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://neurojson.org)AnnotationFormathttps://github.com/NeuroJSON/jnifti/blob/master/JNIfTI_specific
|
unknown
|
||
https://github.com/NeuroJSON/jnifty
|
unknown
|
||
https://www.cognitiveatlas.org/task/id/trm_4c8a834779883/
|
unknown
|
||
http://json.orgSpecialA75DataTypeNameA75DBNameA75ExtendsA75SessionErrorA75GlobalMaxA75GlobalMinbase6
|
unknown
|
||
https://github.com/rordenlab/dcm2niix/issues/236
|
unknown
|
||
http://neurojson.org)
|
unknown
|
||
https://github.com/NeuroJSON/jnifti/blob/master/JNIfTI_specification.md
|
unknown
|
||
https://github.com/NeuroJSON/jsdata
|
unknown
|
||
https://pypi.org/project/jdata
|
unknown
|
||
https://github.com/NeuroJSON/bjdata/blob/master/Binary_JData_Specification.md
|
unknown
|
||
https://pypi.org/project/bjdatahttps://github.com/NeuroJSON/jniftyJavaScripthttps://github.com/Neuro
|
unknown
|
||
http://teem.sourceforge.net/nrrd/format.html
|
unknown
|
||
https://pypi.org/project/bjdata
|
unknown
|
||
http://json.org
|
unknown
|
There are 4 hidden URLs, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
D35DBA9000
|
stack
|
page read and write
|
||
2741B0F8000
|
heap
|
page read and write
|
||
2741AFD0000
|
heap
|
page read and write
|
||
7FF7D2010000
|
unkown
|
page readonly
|
||
7FF7D1F57000
|
unkown
|
page readonly
|
||
7FF7D200E000
|
unkown
|
page read and write
|
||
2741B0E8000
|
heap
|
page read and write
|
||
2741B0C9000
|
heap
|
page read and write
|
||
7FF7D1F57000
|
unkown
|
page readonly
|
||
2741B0CC000
|
heap
|
page read and write
|
||
2741B0F8000
|
heap
|
page read and write
|
||
7FF7D1EA1000
|
unkown
|
page execute read
|
||
7FF7D1F84000
|
unkown
|
page read and write
|
||
2741B0C0000
|
heap
|
page read and write
|
||
2741B1E0000
|
heap
|
page read and write
|
||
7FF7D1EA1000
|
unkown
|
page execute read
|
||
7FF7D1EA0000
|
unkown
|
page readonly
|
||
2741B1C0000
|
heap
|
page read and write
|
||
D35FB0F000
|
stack
|
page read and write
|
||
D35EB5F000
|
stack
|
page read and write
|
||
7FF7D2006000
|
unkown
|
page read and write
|
||
2741B3D0000
|
heap
|
page read and write
|
||
7FF7D1F83000
|
unkown
|
page write copy
|
||
7FF7D1F83000
|
unkown
|
page write copy
|
||
7FF7D2010000
|
unkown
|
page readonly
|
||
7FF7D1EA0000
|
unkown
|
page readonly
|
||
2741B0D7000
|
heap
|
page read and write
|
There are 17 hidden memdumps, click here to show them.