Threat Database Trojans Trojan.Rugmi.DBA

Trojan.Rugmi.DBA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 3,980
Threat Level: 80 % (High)
Infected Computers: 318
First Seen: October 24, 2025
Last Seen: July 30, 2026
OS(es) Affected: Windows

The detection of Trojan.Rugmi.DBA on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, and it's essential to understand its nature and take steps to remove it.

What Is Trojan.Rugmi.DBA?

Trojan.Rugmi.DBA is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate or harmless. The name "Trojan" refers to the malware's ability to infiltrate a system by pretending to be something it's not, much like the legendary Trojan Horse of ancient Greece. Trojan horses can have various purposes, including data theft, system compromise, or the installation of additional malware.

How Trojan.Rugmi.DBA Operates

While specific details about Trojan.Rugmi.DBA's operation are not available, Trojan horses generally operate by exploiting vulnerabilities in software or tricking users into installing them. Once installed, they can create backdoors for remote access, steal sensitive information, or disrupt system operations. They might also download and install other types of malware, leading to further system compromise.

Trojan horses can be particularly dangerous because they often require user interaction to activate, such as opening an email attachment or running an executable file. This social engineering aspect makes them highly effective at bypassing traditional security measures that rely solely on signature-based detection.

Symptoms of Infection

The symptoms of a Trojan.Rugmi.DBA infection can vary widely depending on its intended purpose and the extent of the compromise. Common signs include unusual system behavior, such as unexpected pop-ups, slow performance, or frequent crashes. You might also notice unfamiliar programs or toolbars in your browser, or find that your browser's homepage has been changed without your consent.

In some cases, the presence of a Trojan horse might not be immediately apparent, as it may operate in the background without visible symptoms. This is why regular system scans with reputable antivirus software are crucial for detecting and removing hidden threats.

How to Remove Trojan.Rugmi.DBA

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for internet access to download removal tools.
  2. Download and run a full scan with a reputable anti-malware tool, such as SpyHunter, to detect and remove Trojan.Rugmi.DBA and any associated malware.
  3. Uninstall any recently installed programs that you don't recognize or that were installed around the time the malware was detected.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings changes made by the malware.
  5. Reboot your computer and run another full scan with your anti-malware tool to ensure that all traces of the malware have been removed.

Conclusion

Removing Trojan.Rugmi.DBA requires a combination of technical knowledge and the right tools. By following the steps outlined above and maintaining good cybersecurity practices, such as regularly updating your operating system and software, using strong antivirus protection, and being cautious with emails and downloads, you can protect your system from future threats. Remember, prevention is key, but swift action upon detection is crucial to minimizing the impact of a malware infection.

Analysis Report

General information

Family Name: Trojan.Rugmi.DBA
Signature status: Self Signed

Known Samples

MD5: 72f671fcc9b51580f832c8cbe02ae3ca
SHA1: 609b9a5bd9d11717a0192159337eb7e467e9caef
SHA256: 96BF592B2A197DB48F0269CBB5F1C5E344A7F084D3FE2C0DE5C2F07B063339CA
File Size: 855.82 KB, 855824 bytes
MD5: d937752fb184e9df3114fe5cc321a383
SHA1: 51db2c96d8732bfe5e178c113325d2fac6c086d9
SHA256: B2B4A817147933A0AA6DC93C3F60C7C371232E606AB64DDC7D51B3C629BBC86A
File Size: 267.81 KB, 267808 bytes
MD5: e6850c770137332c4184dd0118f080f3
SHA1: 11e2b4e99d60b1dc5bafd2ca4e9f4b48a3ffc02e
SHA256: FC98025A94EEB0CF2D09E579189C00985EC4DE5AAA269BA32BDD06ECBC57C384
File Size: 855.82 KB, 855824 bytes
MD5: 53cb78e2a1bfa12ffb9187d4484e26bc
SHA1: f37433d26fb21d4b50489ee162dd88299eb41b34
SHA256: 5EFF7B4684D4A007CD6E0CCD1EEB7867774CF3C2A22C39425503A4D3D34062BC
File Size: 855.82 KB, 855824 bytes
MD5: 70cf9b301327576553a09641334c69d4
SHA1: aec909c82ecbc6af7630066d3d697e0951022e05
SHA256: A61E1EB88334A59FF28BF4139205A483A9EA64757985F0AC6F8ABCA5E59ABACA
File Size: 855.82 KB, 855816 bytes
Show More
MD5: a3e62d49c8c7df10d4913360604e4c4a
SHA1: 75df1dba9d35a8cbbe65eba27fdeb13a4d64049f
SHA256: CDAF6C751B974C61317112EE081E37CFCA546824C660691BA51686C0AB46D587
File Size: 855.82 KB, 855816 bytes
MD5: 46d8dca5c162b084beb3ee73f931efc2
SHA1: a76e5868f611a69aa8c0cf1f15ecf94a40b3ebae
SHA256: 96A1405084C9326E2B378DD82A42EA0358C99EE81A9B1BD3A1CD57B394634475
File Size: 855.82 KB, 855824 bytes
MD5: 4f3682a210a873e38ed6a5cb09bce3c3
SHA1: 888b30229d43c318ccbe723ea5275c03d51bb651
SHA256: 37FBD8018735D470683996BAC770750154464182E971961563E896FF74D2784D
File Size: 855.82 KB, 855816 bytes
MD5: f5e9ee7445b3d73eaf6b93ccfe5b931d
SHA1: c5b69a6a008f7494a774fe5e03cd19a5a14c4ae7
SHA256: BEE589D01516A7825B6A9364159496C6B573B4691F5B0F4F11DE944450CDE7F6
File Size: 855.82 KB, 855824 bytes
MD5: 17d6f7d371f63bbaca0eb06bcc089f6b
SHA1: a8eafeb287e9de4b3f1adee440eb184d6055f3a7
SHA256: 2E973CD968D8F2A46A189473893D7886E35EF7D84FF533DB9E99FB98E7E6984E
File Size: 145.45 KB, 145448 bytes
MD5: 5bdad28ab6e93df014cb340e3cf9ffe8
SHA1: 1071172745bc02da7c633b7ba25b1059b2517f7b
SHA256: BB9741E05DD51B5CEE78D03D9EB29CD67FC40B63270374735BF865A5687ECC61
File Size: 855.82 KB, 855824 bytes
MD5: 1ade606013de7a15c9188d97a6968185
SHA1: 4dcc973a6d3d0f317e6f66e5c251c0b848dee908
SHA256: C9537A16DC6A63C18360758DB6288ED78FEA6905F434EDB20FE504F05A6DBA13
File Size: 855.82 KB, 855816 bytes
MD5: e156f7a82844f944671c798ce1e63c29
SHA1: f0da65c53b0c128a5f5e5a4af3f64ef733205ddd
SHA256: 04FB3E3A100843A646F8041AB17BA05449B4B9FEE9E36D65246FF6DABDE4A323
File Size: 855.82 KB, 855816 bytes
MD5: 8abb3910d85533e1c640b3149e16ccd1
SHA1: 4a9c0bdd6ce1fcfe0457232a3e85a446c78246bc
SHA256: 7141B3BFCA77FF39A0B40F1C12F501F49E4830F65FFDCDF4B848BC7D13DD46BF
File Size: 855.82 KB, 855816 bytes
MD5: 84c7935a73927ea7ef2d2dc32fe8fc6e
SHA1: a2f8814e979a987520fa0ad3146389bc5799b61d
SHA256: 01B0532CE0918E562CBDCDAD7C5CB0AC6E0448F2CAD8D41F667D23AA363B8CC2
File Size: 855.82 KB, 855824 bytes
MD5: b6a0cadd19b7510c181070af45bad9bb
SHA1: 359d2a61102bc3dca9a8ae86de4f6ffb23a47852
SHA256: EC40EB10DA3A5A17845E65F10F358FECD28CC660BA19582E443B851EF7686E2D
File Size: 855.82 KB, 855824 bytes
MD5: 2f5e462ed9edf5e35e9dc96acbf1fa11
SHA1: f2603fe481362b6da3714cc1e73b5d78b3aed097
SHA256: 68532E0D9B35A78E78BDD3F4E06D81B0337D5452D098618334481C5FC4246A87
File Size: 855.82 KB, 855816 bytes
MD5: 61a415af8a13067d498e12d41bd64e53
SHA1: 95f777a9c0e1c0d8bb2d86236de2c5ce4ceecafe
SHA256: 4C1C6FB8508867E7F9BFCC2667DDC3CEE778B71E88742BFB4875A32F72097351
File Size: 467.51 KB, 467512 bytes
MD5: 54eb2ae148d3d141cbbacbaf5dff8218
SHA1: 51aadbc78e2f76d6205d460f745e75e0191e3c62
SHA256: 5AC80755F1EAD939FA535012D89310503A8BDC6672A0DF0A882FEE99A922F4D2
File Size: 835.07 KB, 835072 bytes
MD5: 4df38cc570bb71a46ba3171b2674926a
SHA1: 0a8f2c0e4d0f033af840b416a8fbf7e2e758fe8f
SHA256: EA7F5246CD9942AA95ECDC188E9FFBE2FD18F99830F78BE86E242EE4C77B7770
File Size: 854.32 KB, 854321 bytes
MD5: d1250d547d2fbdd0e0e59228c70245b9
SHA1: 69f9c9c778d07ddfca7962737f394ccfd30a3d06
SHA256: D49F505D6414DD4461172298D217BD1A849CFB09F84E1CE66622D81919C13028
File Size: 6.29 MB, 6288203 bytes
MD5: 83b7eb1388e750efb348363e5dffcaa8
SHA1: ff7fad56b1b3a43a1553fd6be84e129513072165
SHA256: 44E121B587BCABF19562FCDEBA64E337D62D78C59F63D8685B53D608F61CF091
File Size: 855.82 KB, 855824 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
Show More
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments This installation was built with Inno Setup.
Company Name
  • Microsoft Corporation
  • TODO: <Company name>
File Description
  • Code Coverage Static Runtime
  • Microsoft Coverage Symbol Engine Interop
  • Stave Setup
  • TODO: <File description>
  • Visual Studio Crypto Info
File Version
  • 17.2.25126.612603
  • 17.0.36024.17 built by: d17.14
  • 17.0.35710.127 built by: d17.13
  • 8.9.0.0
  • 2, 1, 0, 21-d-5e94740
Internal Name
  • Microsoft.VisualStudio.Coverage.Symbols.dll
  • static_covrun32.dll
  • TSLogSDK.dll
  • VSCryptoInfo.dll
Legal Copyright
  • Copyright (C) 2020
  • © Microsoft Corporation. All rights reserved.
Original Filename
  • Microsoft.VisualStudio.Coverage.Symbols.dll
  • static_covrun32.dll
  • TSLogSDK.dll
  • VSCryptoInfo.dll
Product Name
  • Microsoft® Visual Studio®
  • Stave
  • TSLogSDK
Product Version
  • 17.2.25126.612603
  • 17.0.36024.17
  • 17.0.35710.127
  • 6.7
  • 2, 1, 0, 21-d-5e94740

Digital Signatures

Signer Root Status
Tenorshare Co., Ltd. DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch
Tenorshare Co., Ltd. DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Self Signed
Tenorshare Co., Ltd. DigiCert Trusted Root G4 Root Not Trusted
Tenorshare Co., Ltd. DigiCert Trusted Root G4 Hash Mismatch
Microsoft Corporation Microsoft Code Signing PCA 2011 Hash Mismatch

File Traits

  • Default Version Info
  • dll
  • fptable
  • x64

Block Information

Total Blocks: 2,824
Potentially Malicious Blocks: 0
Whitelisted Blocks: 2,824
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Rugmi.DB
  • Rugmi.DBA

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-ak2il.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-ak2il.tmp\bearthaick.nw Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-ak2il.tmp\brigbriet.wfi Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-ak2il.tmp\bugsplat64.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-ak2il.tmp\de-rel30.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-ak2il.tmp\lib_tscommunication_sdk.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-ak2il.tmp\lib_tsmp4framescansdk.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-ak2il.tmp\tslogsdk.dll Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\is-an06g.tmp\69f9c9c778d07ddfca7962737f394ccfd30a3d06_0006288203.tmp Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n) �v����Bx#��(�1`1�1HO5�0<.:@V�N$_�zk`k�ql(�{b��P���!�/����� ���3���������X�������.�m�Ù��gi�V����$�8წ���l�A�~�=�SB1_B��T�Vw���%���������AE��D��&��$�� RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
Show More
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
User Data Access
  • GetUserObjectInformation

Shell Command Execution

"C:\Users\Ogwbevyv\AppData\Local\Temp\is-AN06G.tmp\69f9c9c778d07ddfca7962737f394ccfd30a3d06_0006288203.tmp" /SL5="$19034C,5900481,121344,c:\users\user\downloads\69f9c9c778d07ddfca7962737f394ccfd30a3d06_0006288203"
"C:\Users\Ogwbevyv\AppData\Local\Temp\is-AK2IL.tmp\De-Rel30.exe"