Trojan.Rugmi.IFB
Threat Scorecard
EnigmaSoft Threat Scorecard
EnigmaSoft Threat Scorecards are assessment reports for different malware threats which have been collected and analyzed by our research team. EnigmaSoft Threat Scorecards evaluate and rank threats using several metrics including real-world and potential risk factors, trends, frequency, prevalence, and persistence. EnigmaSoft Threat Scorecards are updated regularly based on our research data and metrics and are useful for a wide range of computer users, from end users seeking solutions to remove malware from their systems to security experts analyzing threats.
EnigmaSoft Threat Scorecards display a variety of useful information, including:
Popularity Rank: The ranking of a particular threat in EnigmaSoft’s Threat Database.
Severity Level: The determined severity level of an object, represented numerically, based on our risk modeling process and research, as explained in our Threat Assessment Criteria.
Infected Computers: The number of confirmed and suspected cases of a particular threat detected on infected computers as reported by SpyHunter.
See also Threat Assessment Criteria.
| Popularity Rank: | 1,011 |
| Threat Level: | 80 % (High) |
| Infected Computers: | 7,537 |
| First Seen: | October 13, 2025 |
| Last Seen: | August 1, 2026 |
| OS(es) Affected: | Windows |
The detection of Trojan.Rugmi.IFB on your system indicates a potential security threat that requires immediate attention. Trojan-type threats are known for their ability to disguise themselves as legitimate programs, making them difficult to detect and remove. In this report, we will provide an overview of the threat, its operating methods, symptoms of infection, and a step-by-step guide on how to remove it from your system.
Table of Contents
What Is Trojan.Rugmi.IFB?
Trojan.Rugmi.IFB is a type of malware that can compromise the security of your system by allowing unauthorized access to your data and taking control of your computer. The name "Trojan" refers to the fact that this type of malware often disguises itself as a legitimate program, making it difficult to detect. The ".Rugmi.IFB" part of the name is a specific identifier used by security software to distinguish this particular threat from others.
How Trojan.Rugmi.IFB Operates
Trojan.Rugmi.IFB, like other Trojan-type threats, operates by exploiting vulnerabilities in your system's security. It can be spread through various means, including infected software downloads, suspicious email attachments, and compromised websites. Once installed, the malware can create backdoors, allowing hackers to access your system and steal sensitive information. It can also install additional malware, modify system settings, and disrupt the normal functioning of your computer.
Symptoms of Infection
The symptoms of a Trojan.Rugmi.IFB infection can vary, but common signs include slow system performance, frequent crashes, and unexpected changes to system settings. You may also notice unusual network activity, such as unfamiliar programs connecting to the internet or suspicious emails being sent from your account. In some cases, the malware may not exhibit any noticeable symptoms, making it difficult to detect without the use of security software.
How to Remove Trojan.Rugmi.IFB
- Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for internet access. This will make it easier to download and install removal tools.
- Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove the malware.
- Uninstall any suspicious programs that may be related to the infection. Be cautious when uninstalling programs, as some may be legitimate or required by your system.
- Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings that may have been installed by the malware.
- Reboot your system and perform another full scan with your anti-malware tool to ensure that the malware has been completely removed.
Conclusion
Removing Trojan.Rugmi.IFB from your system requires careful attention to detail and a thorough understanding of the removal process. By following the steps outlined in this report, you can help ensure that your system is free from this malicious threat. It is essential to remain vigilant and to continue monitoring your system for any signs of infection or suspicious activity. Regularly updating your security software and being cautious when downloading programs or opening email attachments can help prevent future infections and protect your sensitive data.
Analysis Report
General information
| Family Name: | Trojan.Rugmi.IFB |
|---|---|
| Signature status: | Hash Mismatch |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
07348670892df4814eaa780341d4053d
SHA1:
4c884108462ac1fd670f83c2e64bf0b87d126530
SHA256:
D65C5D3CC948FBA62021F127D36EFE743BF19EC8AD5FE5BBB4F532C40426C9AD
File Size:
2.55 MB, 2545928 bytes
|
|
MD5:
8256af68a409dd812e7a5fa401fac24d
SHA1:
f3637c3fd6357f0acd14019a5101c104f04632d9
SHA256:
E1BF8B7A723C8B7601F687001CC1962E734F9E7C8E7BAF83A4BA63F798A4C71D
File Size:
4.38 MB, 4379984 bytes
|
|
MD5:
c7b0257ef4b720eb280d4224185cc667
SHA1:
0e99a922c8236a2d552518431f003fd7ca77509f
SHA256:
CB896AD3C2419C369A8E98725CDCAE3EF360DCA9DDAD7DCCAD29AA4D2FD4E81D
File Size:
91.14 KB, 91136 bytes
|
|
MD5:
8dfee3544c2eb41d5bfda2780cfb5c33
SHA1:
2b0b3de06d0a92cbb0ecf3538c845389f8f1a314
SHA256:
FE9917A37A459E7DA257A7E4A5AAA27F61086CBB3A1DA589481070DB91DD79FA
File Size:
1.20 MB, 1204832 bytes
|
|
MD5:
25ffc700c2aa58a6afb107a2a89daeb8
SHA1:
0a33ab5370a339b3678fefdc511ceaff75c97ec2
SHA256:
B536BCEFA09FDD00C2AB1F7FA9E1972134DC21AFC11FD8CDE04C87181B9B4308
File Size:
1.67 MB, 1668848 bytes
|
Show More
|
MD5:
008d1d937cd8457697bd27c025afe07b
SHA1:
959f50a207a7db5a6ad091741abd84bdbbc7f247
SHA256:
32EB985CD4E26A3EB712DC714EAA4F987722E48117C2C589120CC70A4765B3C1
File Size:
131.58 KB, 131584 bytes
|
|
MD5:
59fd550d929db298b04bb2c8741b17cb
SHA1:
6973e79e2c0169d1c1cda78c47987323191ee0ab
SHA256:
89421ED44CACED972531F5BB34C1243C3D4374C866DE3D5C98647E2EC95FC65D
File Size:
856.06 KB, 856064 bytes
|
|
MD5:
ae46fd8db37b99c88c02e0d0b81a325e
SHA1:
e26b48b16b8f062bd26e7a303bc37adebbe3f331
SHA256:
3CE7ECE5CFC3F505726CD5F652BB91865180786C662D8BAAD9ECB1B2D4A8E88F
File Size:
125.90 KB, 125904 bytes
|
|
MD5:
1729fe2319bb887cb5406fc95c70effb
SHA1:
ba02265e89c0e321fa0446c2155079c4160fedd3
SHA256:
020400592352403B1E8D941CC4FD5B0A2777C8DD436E1D311EE0994C54CFBDAC
File Size:
1.67 MB, 1668848 bytes
|
|
MD5:
69d0bcc1c8b37049444f6fe09eb6bb94
SHA1:
47fe012fde1353da90f4ae2388a58934b1553a75
SHA256:
7C48B0DAE7C57BD4ED4E6D4622570C9CDD08A544E0D65486A4F17D0CCFA539CC
File Size:
383.87 KB, 383872 bytes
|
|
MD5:
894ccb2282375d35829461583ec515ee
SHA1:
e57d99cdf8a2a2323809a88af77743f61b9a30f9
SHA256:
0FF5D2C2FABE50C1DB5AE5004EAD851F71BC4E44CFC4AB4234A5C9A79BCE0BDD
File Size:
856.06 KB, 856064 bytes
|
|
MD5:
3a0220a51ea2cfa3a408f494b540b9a9
SHA1:
3e511b4f9ae6a6d9334126c35fa4578ee5e9bcb4
SHA256:
C63B57D5879A2B0F8647906098F322378D14D1988A4DCEA90ED6368A1D9C70A1
File Size:
1.41 MB, 1408048 bytes
|
|
MD5:
70bb69872bf4196404606a7d9e65dff0
SHA1:
2cfdc8724743e39377b670e8f73897d4bcf01ef1
SHA256:
EDEFE002D4E94720B5A5763DA67C0969238DDE8452281DD2A44C6D8DAC676C82
File Size:
4.63 MB, 4631144 bytes
|
|
MD5:
f89d556881bb6ed8021b764b89f5b277
SHA1:
2ae1379850219a8b12bcb411e27cbfb9bf9caa95
SHA256:
6B8C5524C52C5CBDB8CBD4E841BA59716D056330C540E9729FEEB9F235791D6A
File Size:
2.58 MB, 2584280 bytes
|
|
MD5:
7ea1a7568ffebf639f6d5fd9492b7da9
SHA1:
9347ff2cf26d124dbda3706cde1ddcae91bb70d1
SHA256:
E5726F48AA39234CB5C75309553B972490B86FB32A090B7124BC54B1B6594127
File Size:
669.80 KB, 669800 bytes
|
|
MD5:
ac2a7e1bcd2da120c58d180c0892b370
SHA1:
3ece21a2b0886988fc9e46ed098f278528af8fdd
SHA256:
163B8ABCC457E60A1FAAC8EC5021B97041CE8CC846623EF114E513F4826FEF56
File Size:
805.41 KB, 805408 bytes
|
|
MD5:
2787fe2e1b3cc18573f7f9dd03de37ed
SHA1:
656e736873d0dda7272688bc93956bbdbaa553bc
SHA256:
4C1993ED1571076AAA5A0D6DCDCF39BEBC2933C177493059372696833F83695F
File Size:
5.30 MB, 5298296 bytes
|
|
MD5:
4a0189726f850b3657fb9a38797c10f2
SHA1:
d47d21d668af02b51b16011d8cab094566c3abe8
SHA256:
E2EFF3E62586B0115CFEB3E0B5B8EE9ECC258B4E8861155121F757D8A3373582
File Size:
5.30 MB, 5298296 bytes
|
|
MD5:
1f621ff2c0b86303f67f74e9eb0add9e
SHA1:
471294819d9815607577e98ec9b188b247d45f11
SHA256:
F8B08BA8F95C7E5F9ED38F3F98B06782C5B29309CB2815DEDF6B222049592509
File Size:
2.50 MB, 2501736 bytes
|
|
MD5:
84a948c3f32213453c97bea3f9090bb9
SHA1:
20d8a0530d9d8200e2de385a5b01bc3c166de2ad
SHA256:
5B692529E03AF7163E77F7FFEFCFD52C3A099685D05C079CFA4A5A9DC8994CE7
File Size:
4.69 MB, 4694016 bytes
|
|
MD5:
79bc52af778440aaeb46b12a8bfef629
SHA1:
2e46c3ea87f814b798f70f4a86787119d2ee3890
SHA256:
108555481412A0E46348F0C38D2C0221429B5D65495170B42DF75754BCC3F9BC
File Size:
125.90 KB, 125904 bytes
|
|
MD5:
3d9947f62b3458128008140f5e59f935
SHA1:
fc71440518b67927fd3d9d72641c22fff6bb3dee
SHA256:
7063BF6F8D8E9862B38AE10B0A24DAD3B8856922464037BFFD346E2E07A16884
File Size:
5.25 MB, 5248360 bytes
|
|
MD5:
676409cbd84e11d0fde4880392e00c5b
SHA1:
e2331fb02e1544c604fcc4347eb78282dd4be67b
SHA256:
3DC123CF3EFD4378E51115EE95DDA470229CF1665FB7E5733146514AC7C88826
File Size:
1.27 MB, 1270184 bytes
|
|
MD5:
5e54a1e83e3595fad93c06fefdeed83b
SHA1:
0b9415b71b878c3643968add660a3edd29f27f7e
SHA256:
131AE6C9B2BE2FD6B3FBAD77C743AD22CF2D0669A83DCC24AA51EBC5D6CCFAA0
File Size:
603.38 KB, 603376 bytes
|
|
MD5:
db3e128f1088ddcf605075a8103140b5
SHA1:
cd725bf124d0a819129100022956621d8304754b
SHA256:
76534B9B175EE138B64ECBE4B17F9385037A820D335A445ECA82C039FAB82051
File Size:
125.90 KB, 125904 bytes
|
|
MD5:
5916102f379a08a4b36bba07f6bbb033
SHA1:
9eaa329805ff345d56f97fa90af3b915755fc022
SHA256:
003D789273694A2C0D2333DFC00CBC344E3680FDB28EB5640E3B49EE3D43E8BB
File Size:
5.30 MB, 5298296 bytes
|
|
MD5:
6b4d9095d5053be758884771f501aae2
SHA1:
6b29741d0fd0aa03af99891c577a1ee0fbf39ff4
SHA256:
36A65AB04F0234353FDD10ED08DED6A530A843277AF34E94D1346C12A6629F6F
File Size:
603.38 KB, 603376 bytes
|
|
MD5:
b7c1ed26b2c2b68a7ef0f59f60f15c7a
SHA1:
5bccbbb3a15eb76fc43a7dbec9693e0c54d841ad
SHA256:
E33E71789B6E8A95DC60383F6B2667838FCFFD6E1509BD73843E6B0DE8E82E32
File Size:
2.50 MB, 2501736 bytes
|
|
MD5:
7d78f979ab2d5070f9072ad06cef9a2b
SHA1:
ad787533811be82fb711eccc95848d22a481c84e
SHA256:
BC6C89CB99FBD3FCA8BDAB69CD7040156B9DF7398454A225EC79CE4FEE834FFD
File Size:
1.18 MB, 1184256 bytes
|
|
MD5:
d297fe804bdcd33bb43e120804e596f6
SHA1:
d7de50acf4f9c5f63a28cad7360cd0491417eb45
SHA256:
B3C55F0EB33BFA8CA2EFC6A5F6672366A0D1E191B8AABD2D37490D03F38462DC
File Size:
224.26 KB, 224256 bytes
|
|
MD5:
149ba0014e803221b63816183be3354a
SHA1:
dcb03e402e1fd9c0dec0da1a4ac12e024b47382c
SHA256:
2660A2851A7F9F3F798F8EADD78B9E58AED063393F96CCC58408AF2E1FE01989
File Size:
358.02 KB, 358024 bytes
|
|
MD5:
ba7a6f78312e58485007a7cb79a15d6d
SHA1:
4a0d520d95534d74834b53022f80b999364eb249
SHA256:
46C831B1838AC7BC8B362B7EAFB150B1105C4BF7392DD0ED6305163050520E81
File Size:
821.57 KB, 821568 bytes
|
|
MD5:
bdec1956f4775df17087584034231e85
SHA1:
da68a966d49af179eef5c2c13ddf6ba88a43c44e
SHA256:
780611A291824B2A97A9F1F8067CE7AF020F8E25B2726CD91B579625CA793A34
File Size:
163.46 KB, 163464 bytes
|
|
MD5:
cde5e94a11b89274af4a266cb8bdcddd
SHA1:
5c633b04aa385a5476924221a6b41d769f70c557
SHA256:
781F713994C2D58E65A2A9349229ACD1BCAB253E9E3204BD992175203B7D1F00
File Size:
821.83 KB, 821832 bytes
|
|
MD5:
58c379b09fbd79b57f97405fcc5d1229
SHA1:
acd399697dfb9489b7f6ad749f99dde89700aedd
SHA256:
E1AF4EDBBFB0DA471A852AF5C7B8A6B8F5721B7C4090603E11ECADEB6485EBFF
File Size:
4.63 MB, 4631144 bytes
|
|
MD5:
6d1482dbc5699ac43d20738510b31d88
SHA1:
041602788013ec068189e45629f7d21590a03fef
SHA256:
909B5FE257713B32576BAC6E6A41EED07C35470BE773D7311143178867702855
File Size:
2.50 MB, 2501736 bytes
|
|
MD5:
22748f2a605f8e9e20a1507499bf8944
SHA1:
65883741fb3e0529cbe849042902f3ec76be58a1
SHA256:
72C618A17BD3CEE3B7C32267C6F0EA0B8D2556E6B26A8254E1CD9EF7C79F0C28
File Size:
2.79 MB, 2786566 bytes
|
|
MD5:
5ca7abb3b785dd63aa18cbe6aa59d79e
SHA1:
5680fd1a841b4cbddfcc57cd0a494240f89e962d
SHA256:
1B4B4492FBA6213117433F024F46F9C3C38BC7B13E760087028A5EFEC763D855
File Size:
333.29 KB, 333288 bytes
|
|
MD5:
426eb2808241d344605acd90cfa96f21
SHA1:
4ae35554764083c291009eea64e4afda72ca4afd
SHA256:
9C88B92A4BD67A71451EC92B33FCDF307DF1D3898D49C161510AC8358683A311
File Size:
361.47 KB, 361472 bytes
|
|
MD5:
4481aa41bc074de5d066f862f1026f0f
SHA1:
93a0b7154d35e176e0013e15ce22aea4264413bc
SHA256:
6CFAA1563732081F52CC31D16761BC695EDABF9D59FAF5B7D2C69E1688BF15E9
File Size:
307.76 KB, 307760 bytes
|
|
MD5:
525e133c0f9ea0ce7d40c960d91c84b2
SHA1:
26593255352ab1b6bb51c8fdb989a41f58033745
SHA256:
CC4E599904CD9640C9CC835BB99DAD25F744D2B36AB0260204D81E69AC8432BB
File Size:
1.09 MB, 1091384 bytes
|
|
MD5:
eed95fce3c9c658f453be84e7588990b
SHA1:
27b139c2802038ee75a13dba5c96cae6f10b2f33
SHA256:
1DFBA7958F94D5A51BCD6D831FAC1CAC7A5AA1914C7430D13A757938B4592487
File Size:
1.13 MB, 1132848 bytes
|
|
MD5:
17d5018075cc00e23db76351d2384d04
SHA1:
4044493df6de00ed2b8149c0f8ad3931825e1706
SHA256:
C5BD69D4964C01E119F27BBB4A7F265E634270E9A91D40084B420C3AFDD6E7B0
File Size:
243.38 KB, 243376 bytes
|
|
MD5:
0570cd0cd4af807b13a9326c6a1c0afd
SHA1:
405b05dd1ec1113d9ae362bc45c4a79410e945ea
SHA256:
AEC8BEEA2AAD587EFA3069C572CD5A8C32348227EE0DCD08E17D44B2CEDE272F
File Size:
752.58 KB, 752576 bytes
|
|
MD5:
69d46150f15f020ef9bf2077f933c7f6
SHA1:
9739dd247aad0a72218f75e8016a4d03058477ae
SHA256:
19B2A19726E5CDBC36FC84D2590A7645A0C07E0CD665559DE8F61BCB3EECE000
File Size:
290.04 KB, 290040 bytes
|
|
MD5:
5c902de41f3b8b7ffdaed2ea4ec354aa
SHA1:
3e16053157cb3ee9e9021be33823d1f5962a8f59
SHA256:
B90F8204A8C94D0A15285D0B6DC9816735AE844623CCF4656B4A23A1117F0C8A
File Size:
2.34 MB, 2344104 bytes
|
|
MD5:
263ddc27ed78f36ce309f37de98ab519
SHA1:
67ddf9faf3164d43aa0ee0e6ed788ccabf57a791
SHA256:
3456CA18E2E07FDA4D4E42386CE17E0F5A7A7A3EBF4F7624F9C7BA1CCA332A52
File Size:
91.14 KB, 91136 bytes
|
|
MD5:
69ccf0eafa559e506b4e6e2773cbdb48
SHA1:
79969ff9b3907bd8ce65c28408d5412d37ef40fc
SHA256:
3BA8DEF47D369DFDF0C15CBEAF33BAA1677342C57DE97D1D659A120B6C64C792
File Size:
1.03 MB, 1030632 bytes
|
|
MD5:
669257bee6642abbe799cdc69cbd5f7e
SHA1:
e61d8446d4b60a9ce5616b056ebac8d2c50e6b40
SHA256:
9AE5B07548112C043DCB1F9EC82DF3029CB30204A190AB9CA848317A985882B6
File Size:
2.42 MB, 2415104 bytes
|
|
MD5:
b2be13c21e4090e5393a2305714a77fe
SHA1:
cbb793a08d3f2c8456dda21a7c1f55b64a30209b
SHA256:
BEEA37D5537526ECF3E9A719CF81ABCBF2FD3E2D7C13D3E1FC165AF72977C0F5
File Size:
1.07 MB, 1068248 bytes
|
|
MD5:
47866881482a79ab5136eb78bd8a67fb
SHA1:
81a177592a96f805c54ee8b7b6e0e944d50b9503
SHA256:
BE3BA9EFBD38CA0FF602357C05FFB7BED34F763C4E34C6DD7675BEF24B4814E4
File Size:
2.74 MB, 2744320 bytes
|
|
MD5:
cc03f505ab6687bedc70a7224ae84a54
SHA1:
df3f024eeffade787873b46c1e191f76829bb955
SHA256:
A746E57A6B6896758A82DE8BFEF0A5639693029DF4D0E7661F33369335797CE0
File Size:
171.01 KB, 171008 bytes
|
|
MD5:
5ca1d5bc957c36126d0fb1edc1fd40cf
SHA1:
101d840f872c7f027fc19eeaac6d8f2cf8178322
SHA256:
63ADD6827C442561D86DC443667689C06E233AEFD83171F5A58397CCCAFD93C4
File Size:
879.38 KB, 879384 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have relocations information
- File doesn't have resources
- File doesn't have security information
- File has exports table
- File has TLS information
- File is 32-bit executable
- File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
Show More
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Comments |
|
| Company Name |
Show More
|
| File Description |
Show More
|
| File Version |
Show More
|
| Internal Name |
Show More
|
| Legal Copyright |
Show More
|
| Legal Trademarks |
|
| Original Filename |
Show More
|
| Private Build | June 27, 2010 |
| Product Name |
Show More
|
| Product Version |
Show More
|
Digital Signatures
Digital Signatures
This section lists digital signatures that are attached to samples within this family. When analyzing and verifying digital signatures, it is important to confirm that the signature’s root authority is a well-known and trustworthy entity and that the status of the signature is good. Malware is often signed with non-trustworthy “Self Signed” digital signatures (which can be easily created by a malware author with no verification). Malware may also be signed by legitimate signatures that have an invalid status, and by signatures from questionable root authorities with fake or misleading “Signer” names.| Signer | Root | Status |
|---|---|---|
| AOMEI International Network Limited | COMODO RSA Certification Authority | Hash Mismatch |
| Planestate Software AB | COMODO RSA Code Signing CA | Hash Mismatch |
| Mirillis Sp. z o.o. | Certum Extended Validation Code Signing 2021 CA | Hash Mismatch |
| Adobe Inc. | DigiCert EV Code Signing CA (SHA2) | Hash Mismatch |
| ORANGE VIEW LIMITED | DigiCert High Assurance EV Root CA | Hash Mismatch |
Show More
| Nitro Software, Inc. | DigiCert SHA2 Assured ID Code Signing CA | Hash Mismatch |
| Audials AG | DigiCert Trusted G4 Code Signing RSA4096 SHA256 2021 CA1 | Hash Mismatch |
| Digital Wave Ltd | DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 | Hash Mismatch |
| HITPAW CO., LIMITED | DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 | Hash Mismatch |
| Kofax, Inc. | DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 | Hash Mismatch |
| Shenzhen Jiehao Software Co., Ltd. | DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 | Hash Mismatch |
| HITPAW CO., LIMITED | DigiCert Trusted Root G4 | Hash Mismatch |
| Hangzhou Shunwang Technology Co.,Ltd | DigiCert Trusted Root G4 | Hash Mismatch |
| STARDOCK SYSTEMS, INC. | DigiCert Trusted Root G4 | Hash Mismatch |
| Shenzhen Jiehao Software Co., Ltd. | DigiCert Trusted Root G4 | Hash Mismatch |
| ZOHO Corporation Private Limited | GlobalSign | Hash Mismatch |
| AOMEI International Network Limited | GlobalSign CodeSigning CA - G3 | Hash Mismatch |
| Nuance Communications, Inc. | Go Daddy Secure Certification Authority | Hash Mismatch |
| K7 Computing Pvt Ltd | K7 Computing Pvt Ltd | Hash Mismatch |
| Microsoft Corporation | Microsoft Code Signing PCA | Hash Mismatch |
| Microsoft Corporation | Microsoft Code Signing PCA 2011 | Hash Mismatch |
| K7 Computing Pvt Ltd | Microsoft Identity Verification Root Certificate Authority 2020 | Hash Mismatch |
| Microsoft Corporation | Microsoft Root Authority | Hash Mismatch |
| Microsoft Windows Software Compatibility Publisher | Microsoft Windows Third Party Component CA 2013 | Hash Mismatch |
| AOMEI International Network Limited | Sectigo Public Code Signing Root R46 | Hash Mismatch |
| Intel Corporation | Sectigo Public Code Signing Root R46 | Hash Mismatch |
| Ventis Media, Inc. | Sectigo Public Code Signing Root R46 | Hash Mismatch |
| Adobe Systems Incorporated | Symantec Class 3 Extended Validation Code Signing CA - G2 | Hash Mismatch |
| Safer Networking Ltd. | VeriSign Class 3 Code Signing 2004 CA | Hash Mismatch |
| Garena Online Pte Ltd | VeriSign Class 3 Public Primary Certification Authority - G5 | Hash Mismatch |
| The Qt Company Oy | thawte SHA256 Code Signing CA | Hash Mismatch |
File Traits
- dll
- HighEntropy
- imgui
- ntdll
- WriteProcessMemory
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 3,363 |
|---|---|
| Potentially Malicious Blocks: | 263 |
| Whitelisted Blocks: | 3,097 |
| Unknown Blocks: | 3 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- ConvertAd.D
- Farfli.TBA
- Kryptik.YB
- OpenSUpdater.L
- OpenSUpdater.MC
Show More
- Rugmi.FC
- Rugmi.FE
- Rugmi.FH
- Rugmi.GDA
- Rugmi.GI
- Rugmi.GM
- Rugmi.HB
- Rugmi.IFB
- Rugmi.LDA
- Rugmi.OH
- Rugmi.OO
- Rugmi.PG
- Rugmi.TB
- Rugmi.TD
- SecurityXploded.A
- Trojan.Downloader.Gen.AM
- Trojan.Downloader.Gen.AT
- Trojan.Downloader.Gen.CX
- Trojan.Downloader.Gen.DM
- Trojan.Downloader.Gen.DR
- Trojan.Downloader.Gen.EF
- Trojan.Downloader.Gen.EI
- Trojan.Downloader.Gen.FY
- Trojan.Downloader.Gen.HC
- Trojan.Downloader.Gen.HR
- Trojan.Downloader.Gen.J
- Trojan.Downloader.Gen.KN
- Trojan.Downloader.Gen.KW
- Trojan.Downloader.Gen.MF
- Trojan.Downloader.Gen.OC
- Trojan.Downloader.Gen.QD
- Trojan.Downloader.Gen.RZ
- Yunsip.B
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| c:\programdata\java\frameworswitch32.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144 |
| c:\programdata\java\log.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144 |
| c:\programdata\java\monitor.sym | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144 |
| c:\programdata\java\msvcp_win.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144 |
| c:\programdata\java\sampler.xml | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144 |
| c:\programdata\java\ucrtbase.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144 |
| c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.0.regtrans-ms | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\frameworswitch32.exe | Generic Write,Read Attributes |
Show More
| c:\users\user\appdata\local\temp\frameworswitch32.exe | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\log.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\log.dll | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\monitor.sym | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\monitor.sym | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\msvcp_win.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\msvcp_win.dll | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\sampler.xml | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\sampler.xml | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\ucrtbase.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\ucrtbase.dll | Synchronize,Write Attributes |
| c:\windows\syswow64\log\reg.log | Generic Read,Write Data,Write Attributes,Write extended,Append data |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Syscall Use |
Show More
|
| Process Shell Execute |
|
| Anti Debug |
|
| Process Manipulation Evasion |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\4c884108462ac1fd670f83c2e64bf0b87d126530_0002545928.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\f3637c3fd6357f0acd14019a5101c104f04632d9_0004379984.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\0e99a922c8236a2d552518431f003fd7ca77509f_0000091136.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\2b0b3de06d0a92cbb0ecf3538c845389f8f1a314_0001204832.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\0a33ab5370a339b3678fefdc511ceaff75c97ec2_0001668848.,LiQMAxHB
|
Show More
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\959f50a207a7db5a6ad091741abd84bdbbc7f247_0000131584.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\6973e79e2c0169d1c1cda78c47987323191ee0ab_0000856064.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\e26b48b16b8f062bd26e7a303bc37adebbe3f331_0000125904.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\ba02265e89c0e321fa0446c2155079c4160fedd3_0001668848.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\47fe012fde1353da90f4ae2388a58934b1553a75_0000383872.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\e57d99cdf8a2a2323809a88af77743f61b9a30f9_0000856064.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\3e511b4f9ae6a6d9334126c35fa4578ee5e9bcb4_0001408048.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\2cfdc8724743e39377b670e8f73897d4bcf01ef1_0004631144.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\2ae1379850219a8b12bcb411e27cbfb9bf9caa95_0002584280.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\9347ff2cf26d124dbda3706cde1ddcae91bb70d1_0000669800.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\3ece21a2b0886988fc9e46ed098f278528af8fdd_0000805408.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\656e736873d0dda7272688bc93956bbdbaa553bc_0005298296.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\d47d21d668af02b51b16011d8cab094566c3abe8_0005298296.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\471294819d9815607577e98ec9b188b247d45f11_0002501736.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\20d8a0530d9d8200e2de385a5b01bc3c166de2ad_0004694016.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\2e46c3ea87f814b798f70f4a86787119d2ee3890_0000125904.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\fc71440518b67927fd3d9d72641c22fff6bb3dee_0005248360.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\e2331fb02e1544c604fcc4347eb78282dd4be67b_0001270184.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\0b9415b71b878c3643968add660a3edd29f27f7e_0000603376.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\cd725bf124d0a819129100022956621d8304754b_0000125904.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\9eaa329805ff345d56f97fa90af3b915755fc022_0005298296.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\6b29741d0fd0aa03af99891c577a1ee0fbf39ff4_0000603376.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\5bccbbb3a15eb76fc43a7dbec9693e0c54d841ad_0002501736.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\ad787533811be82fb711eccc95848d22a481c84e_0001184256.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\d7de50acf4f9c5f63a28cad7360cd0491417eb45_0000224256.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\dcb03e402e1fd9c0dec0da1a4ac12e024b47382c_0000358024.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\4a0d520d95534d74834b53022f80b999364eb249_0000821568.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\da68a966d49af179eef5c2c13ddf6ba88a43c44e_0000163464.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\5c633b04aa385a5476924221a6b41d769f70c557_0000821832.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\acd399697dfb9489b7f6ad749f99dde89700aedd_0004631144.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\041602788013ec068189e45629f7d21590a03fef_0002501736.,LiQMAxHB
|
(NULL) C:\Users\Qmqvheck\AppData\Local\Temp\FrameworSwitch32.exe
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\5680fd1a841b4cbddfcc57cd0a494240f89e962d_0000333288.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\4ae35554764083c291009eea64e4afda72ca4afd_0000361472.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\93a0b7154d35e176e0013e15ce22aea4264413bc_0000307760.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\26593255352ab1b6bb51c8fdb989a41f58033745_0001091384.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\27b139c2802038ee75a13dba5c96cae6f10b2f33_0001132848.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\4044493df6de00ed2b8149c0f8ad3931825e1706_0000243376.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\405b05dd1ec1113d9ae362bc45c4a79410e945ea_0000752576.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\9739dd247aad0a72218f75e8016a4d03058477ae_0000290040.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\3e16053157cb3ee9e9021be33823d1f5962a8f59_0002344104.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\67ddf9faf3164d43aa0ee0e6ed788ccabf57a791_0000091136.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\79969ff9b3907bd8ce65c28408d5412d37ef40fc_0001030632.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\e61d8446d4b60a9ce5616b056ebac8d2c50e6b40_0002415104.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\cbb793a08d3f2c8456dda21a7c1f55b64a30209b_0001068248.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\81a177592a96f805c54ee8b7b6e0e944d50b9503_0002744320.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\df3f024eeffade787873b46c1e191f76829bb955_0000171008.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\101d840f872c7f027fc19eeaac6d8f2cf8178322_0000879384.,LiQMAxHB
|