tetanus.dll

The library tetanus.dll has been detected as malware by 12 anti-virus scanners. The file has been seen being downloaded from filedropper.com and multiple other hosts.
MD5:
c65a08059fed4ee026cd232c019411d6

SHA-1:
6f14807ffdb7785418a61b325b3845419e854461

SHA-256:
4aac1cdb37286f27c2e7d2e1389a0bb6f4b94b7fc502ff48e052702baed6455a

Scanner detections:
12 / 68

Status:
Malware

Analysis date:
1/13/2025 4:12:33 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Trojan.Heur2.CTR.2039fAO4@aaNxATni
290

AegisLab AV Signature
Gen.Troj.Heur2!c
2.1.4+

Arcabit
Trojan.Heur2.CTR.E7ECC3
1.0.0.672

AVG
Win32/Blacked
2017.0.2768

Bitdefender
Gen:Trojan.Heur2.CTR.2039fAO4@aaNxATni
1.0.20.555

Bkav FE
HW32.Packed
1.3.0.7744

Emsisoft Anti-Malware
Gen:Trojan.Heur2.CTR.2039fAO4@aaNxATni
8.16.04.20.03

F-Secure
Gen:Trojan.Heur2.CTR.2039fAO4@aaNxATni
11.2016-20-04_4

G Data
Gen:Trojan.Heur2.CTR.2039fAO4@aaNxATni
16.4.25

MicroWorld eScan
Gen:Trojan.Heur2.CTR.2039fAO4@aaNxATni
17.0.0.333

Qihoo 360 Security
HEUR/QVM36.0.Malware.Gen
1.0.0.1120

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
23.00.65.16418

File size:
417 KB (427,008 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\users\{user}\downloads\tetanus.dll

File PE Metadata
Compilation timestamp:
4/19/2016 1:29:26 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
6144:fPhTaYL1htCEe04R2ENuc1UEfB6sCN5IFQJuZgXwAtYD3PHVN4g2s90PYeAB3p:fP/L1htCEeaoucRB6mQJ6qqfn4w0Q7N

Entry address:
0x10F2B1

Entry point:
68, 7E, C6, 42, 92, 9C, 60, E9, 1C, A2, FF, FF, 66, F7, D6, 0F, B7, 72, 1A, 60, F7, D7, 66, 0F, BE, F9, 0F, B6, F8, 8D, 74, 16, 1C, 9C, 5F, 8B, 7D, 08, E9, 85, 28, FF, FF, 9C, 60, 0F, 90, C0, 9C, AC, 9C, 04, 7C, 9C, E8, 52, 4C, 00, 00, 52, E9, A5, E3, FF, FF, C0, C0, 02, 8D, 64, 24, 34, 0F, 85, 3D, AB, FF, FF, F5, 60, F6, D8, E8, 47, B9, FF, FF, B8, 1F, A4, B7, 3C, A6, 39, DA, D9, 45, 17, 70, FC, 55, F5, 4E, E4, 40, 7A, E4, 4D, AA, 9F, F9, CB, 31, 17, 78, DC, 3F, AD, 02, 1F, 7B, BB, 1A, FA, E3, 74, C9, 05...
 
[+]

Entropy:
7.9239  (probably packed)

Code size:
229 KB (234,496 bytes)

The file tetanus.dll has been seen being distributed by the following 2 URLs.

Remove tetanus.dll - Powered by Reason Core Security