Threat Database Ransomware Avaddon.BB Ransomware

Avaddon.BB Ransomware

By CagedTech in Ransomware

Threat Scorecard

Popularity Rank: 8,863
Threat Level: 100 % (High)
Infected Computers: 22
First Seen: July 25, 2023
Last Seen: March 7, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Avaddon.BB Ransomware
Signature status: No Signature

Known Samples

MD5: 87061949de399f78b58af9708325b26f
SHA1: 799812e1298d307b6f2fd36657dd4de0506760b9
SHA256: E3CA57C58C4A80A92BB88A6282D340ADEC889A64FAD2758CEA2DE580861EACBB
File Size: 493.57 KB, 493568 bytes
MD5: d30f69e9582171ef0cac7e00d77e6da6
SHA1: 5cc7bd02be59c1669009494879ed5844c808f1ca
SHA256: 5744D86DB75F32FEB213E6A3DEF6FFC6F4DAAB0D635FC5CDFA31C9829B152766
File Size: 494.59 KB, 494592 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Microsoft Corporation
File Description
  • Win32 Cabinet Self-Extractor
  • Самоизвлечение CAB-файлов Win32
File Version
  • 11.00.17763.1 (WinBuild.160101.0800)
Internal Name
  • Wextract
Legal Copyright
  • © Microsoft Corporation. All rights reserved.
  • © Корпорация Майкрософт. Все права защищены.
Original Filename
  • WEXTRACT.EXE
  • WEXTRACT.EXE .MUI
Product Name
  • Internet Explorer
Product Version
  • 11.00.17763.1

File Traits

  • No Version Info
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 3
Potentially Malicious Blocks: 0
Whitelisted Blocks: 2
Unknown Blocks: 1

Visual Map

? 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Dacic.O
  • Glupteba.P
  • Protux.D
  • Upatre.VC
  • VtFlooder.R

Trending

Most Viewed

Loading...