ddtank_multihack_version_1_6_verified.exe

The application ddtank_multihack_version_1_6_verified.exe has been detected as a potentially unwanted program by 8 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from ddlstorntvs.maynemyltf.netdna-cdn.com.
MD5:
f55fd4ad06f74e53afb671eaa460dae1

SHA-1:
28ca86454a0e1eb7698bcdd94ee13cda856af834

SHA-256:
b98ff165219743157d9e8177a96d8dc995716f7181e994b347363094084d1156

Scanner detections:
8 / 68

Status:
Potentially unwanted

Analysis date:
11/25/2024 6:39:52 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Adware-gen [Adw]
160518-2

Emsisoft Anti-Malware
Application.Bundler.LT
11.5.0.6191

ESET NOD32
multiple threats
8.0.319.0

F-Secure
Riskware.Application.Bundler.LT
5.15.96

McAfee
Program.Artemis!E50423C905E2
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.223.2382.0

Norman
Application.Bundler.LT
28.05.2016 15:32:18

Reason Heuristics
Adware.Generic.AT (M)
16.6.22.14

File size:
332.2 KB (340,180 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\ddtank_multihack_version_1_6_verified.exe

File PE Metadata
Compilation timestamp:
12/5/2009 8:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:8QquQEmdG3fbapK7bLWBYc+xkaEJ/4TtjwTZG1ZkPuZUgYxabB3AJW4:iEmdGzZPLoqkBoEdG1OPEYkFx4

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file ddtank_multihack_version_1_6_verified.exe has been seen being distributed by the following URL.

Remove ddtank_multihack_version_1_6_verified.exe - Powered by Reason Core Security