Threat Database Trojans Trojan.Rugmi.LB

Trojan.Rugmi.LB

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 12
First Seen: November 1, 2024
Last Seen: February 27, 2026
OS(es) Affected: Windows

Your system has been detected to be infected with Trojan.Rugmi.LB, a type of malicious software that can cause significant harm to your computer and compromise your personal data. It is essential to understand the nature of this threat and take immediate action to remove it from your system.

What Is Trojan.Rugmi.LB?

Trojan.Rugmi.LB is a Trojan-type threat, which means it is a type of malware that disguises itself as a legitimate program or file to gain unauthorized access to a computer system. Trojans can be used to steal sensitive information, install additional malware, or provide a backdoor for remote access to the infected system. The name "Trojan.Rugmi.LB" suggests that it is a unique variant of a Trojan, but its specific characteristics and behaviors may not be well-documented.

How Trojan.Rugmi.LB Operates

Trojan.Rugmi.LB, like other Trojans, operates by exploiting vulnerabilities in software or tricking users into installing it. Once installed, it can communicate with its command and control servers to receive instructions and transmit stolen data. It may also attempt to download and install additional malware or create backdoors for remote access. The exact mechanisms used by Trojan.Rugmi.LB are not known, but it is likely to use common Trojan tactics such as social engineering, drive-by downloads, or exploiting software vulnerabilities.

Symptoms of Infection

Systems infected with Trojan.Rugmi.LB may exhibit a range of symptoms, including slow performance, unexpected crashes, and unusual network activity. You may also notice unfamiliar programs or icons on your desktop, or receive unexpected pop-ups and alerts. In some cases, the Trojan may attempt to hide its presence, making it difficult to detect without the use of specialized security software. If you suspect that your system is infected, it is essential to take immediate action to remove the threat.

How to Remove Trojan.Rugmi.LB

  1. Boot your system in Safe Mode with Networking to prevent the Trojan from loading and to allow for easier removal.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect and remove Trojan.Rugmi.LB and any related malware.
  3. Uninstall any suspicious programs or applications that may be related to the Trojan.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform a follow-up scan with your anti-malware tool to ensure that the threat has been fully removed.

Conclusion

Removing Trojan.Rugmi.LB from your system requires careful attention to detail and the use of specialized security software. By following the steps outlined above, you can help to ensure that your system is free from this malicious threat and prevent further damage to your computer and personal data. It is also essential to take steps to prevent future infections, including keeping your operating system and software up to date, using strong antivirus protection, and being cautious when opening email attachments or clicking on links from unknown sources.

Analysis Report

General information

Family Name: Trojan.Rugmi.LB
Signature status: Hash Mismatch

Known Samples

MD5: e73790b1250a799b41dfde872f5bf679
SHA1: a35e93208d7aaec88f9daa928d1ea15f40b2246b
SHA256: 69F8BE0035EC70F291214BF805E0A0B3CFF5AEBC9EC70C165BEE3EABF00D4895
File Size: 311.45 KB, 311448 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Alexander Roshal
File Description RAR decompression library
File Version 7.1.0
Legal Copyright Copyright © Alexander Roshal 1993-2024
Original Filename Unrar.dll
Product Name RAR decompression library
Product Version 7.1.0

Digital Signatures

Signer Root Status
win.rar GmbH DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch

File Traits

  • dll
  • HighEntropy
  • x86

Block Information

Total Blocks: 985
Potentially Malicious Blocks: 159
Whitelisted Blocks: 816
Unknown Blocks: 10

Visual Map

x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? x ? 0 x ? ? ? ? ? ? x ? x 0 0 0 0 x 0 0 0 0 0 1 x x x 0 0 0 0 0 x x 0 0 x 0 0 x x x 0 x x x x x 0 x x 0 0 x 0 0 0 0 x 0 x 0 0 0 0 x 0 x 0 0 0 x 0 0 x 0 0 0 x 0 0 x x 0 0 0 0 x 0 0 0 0 0 0 x 0 x 0 0 x 0 x 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 x x 0 x x x 0 0 0 x x x x x x 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 x x x 0 x x x x 0 0 x 0 x x x 0 x 0 x 0 0 0 0 0 0 0 x x x 0 x x 0 0 0 0 x 0 0 0 0 0 x x 0 0 0 x 0 x x 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 x 0 x x 0 0 x x x 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 x 0 x x 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 x 0 0 0 x 0 0 x x x x 0 0 0 x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x x x 0 0 x 0 0 0 0 x 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 x x x x x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x x 0 x 0 x 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 1 2 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 1 2 3 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 2 2 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 1 0 1 1 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Rugmi.JC

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\a35e93208d7aaec88f9daa928d1ea15f40b2246b_0000311448.,LiQMAxHB

Trending

Most Viewed

Loading...