ttdrecord.dll

  • File Path: C:\Windows\SysWOW64\ttdrecord.dll
  • Description: Time Travel Debugging Recording Manager

Hashes

Type Hash
MD5 FBE8BAB4F4D2133AB08C38A4A10346D1
SHA1 4C127FC831E693170D60452D49CE15F2A85A66B3
SHA256 25DBF344E4C251EC40E034E3AF53CE797191D1DFE59D1DB477352AE2F03A8E52
SHA384 ED4A6A8D0ACD5D2E084A9B68D0A94075FDF15150F2FE07DDF039E6896FEB1441D7D6359A6C971F8A6F687E537BC85820
SHA512 6765B9A893E1ACBCD23D45E44FEB9660146E6B70BCBEE2BB22E932133236741C17508F21CE17AD2BA7334F2297CDAF0D435F5549E200CC38FCDB81AE62461C30
SSDEEP 12288:O47b8H+gzeCSzcRaUm8hcyGewRhXQUSKr7+fYn:Oj+3CSzckUmAlwR5QUSKr0Yn
IMP 46DF26B41C6C89D6DDD2043C39862EC3
PESHA1 083D07108970AF76C766E097AE1A1361A59C9914
PE256 CAEEA18C10EAE7FA1C6484F7D22FD50F62A826A04DE140727B7407060F0D2B50

DLL Exports:

Function Name Ordinal Type
ExecuteTTTracerCommandLine 1 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 330000026551AE1BBD005CBFBD000000000265
  • Thumbprint: E168609353F30FF2373157B4EB8CD519D07A2BFF
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: TTDRecord.dll
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/71
  • VirusTotal Link: https://www.virustotal.com/gui/file/25dbf344e4c251ec40e034e3af53ce797191d1dfe59d1db477352ae2f03a8e52/detection/

Possible Misuse

The following table contains possible examples of ttdrecord.dll being misused. While ttdrecord.dll is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma image_load_tttracer_mod_load.yml - '\ttdrecord.dll' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.