Threat Database Trojans Trojan.Rugmi.DD

Trojan.Rugmi.DD

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 12,465
Threat Level: 80 % (High)
Infected Computers: 51
First Seen: November 1, 2025
Last Seen: August 18, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Rugmi.DD
Signature status: Hash Mismatch

Known Samples

MD5: 71d2f3c36626ec54f4db7bf896e4aa55
SHA1: 5bfb36a66a70da6a238032cc784d77fbe6e66508
SHA256: F5BCC76672C7FC7399DD645FDAB829169B3DBCD60ED8DB351BD2F68F7DFFFE9D
File Size: 96.41 KB, 96408 bytes
MD5: a92ec5d7be2dd296f9dd761a581e4e04
SHA1: 1dc0596a09a1e9c8ea957c46d183d2f0cdc8730a
SHA256: F883B0ADC4F422566AC2D117CD49DAC6D40296F168ED60962AC14F575D98B60C
File Size: 94.20 KB, 94200 bytes
MD5: 4da9495c058244f1cbb96341c647f4b8
SHA1: 531c6b43a324c8f139bbbb13c22f092ece8b621a
SHA256: 756CE2BDDFF9FD4FC5D356141A9F8F45BC4B8CEF43726CFC8DB8229DD59A9A0F
File Size: 2.14 MB, 2140648 bytes
MD5: be9adce65be4f04f366ea12df117803b
SHA1: 4282eeef6ea228e2c5eb1a042ae726f322860472
SHA256: 7E1E08B386269B59F7B97FD1A0184B4DDE1785A7F85C75C41950A05AF24A3242
File Size: 70.68 KB, 70680 bytes
MD5: 231accbccf91ce0c3c3d409e09ee577c
SHA1: d0c49ea1acfa1a0f51ab581c08105949b477d5d1
SHA256: 0995749CF202695609176A7EB085602B934369CF7440309C7A3BA507A82B6C1B
File Size: 70.68 KB, 70680 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name
  • Nuance Communications, Inc.
  • The OpenSSL Project, https://www.openssl.org/
  • Zhuhai Kingsoft Office Software Co.,Ltd
File Description
  • kprt
  • OpenSSL library
  • PaperPort Utilities Library
  • TAMInstance模块
File Version
  • 2018,02,27,1
  • 14.5.15069.1503
  • 12,9,0,21549
  • 1.1.1q
Internal Name
  • krpt
  • libcrypto
  • MAXUTIL
  • TAMInstance
Legal Copyright
  • (c) 1995-2015, Nuance Communications, Inc.
  • Copyright 1998-2022 The OpenSSL Authors. All rights reserved.
  • Copyright©2025 Kingsoft Corporation. All rights reserved.
Legal Trademarks Nuance, ScanSoft, Recognita, OmniPage, PaperPort, Power PDF, and OmniPage Capture SDK are registered trademarks of Nuance Communications, Inc. in the United States and/or other countries.
Original Filename
  • krpt.dll
  • libcrypto
  • MAXUTIL.DLL
  • TAMInstance.dll
Product Name
  • PaperPort
  • The OpenSSL Toolkit
  • WPS Office
Product Version
  • 14.5
  • 12,9,0,21549
  • 9, 0, 5, 0
  • 1.1.1q

Digital Signatures

Signer Root Status
JUST OKAY LIMITED DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch
Zhuhai Kingsoft Office Software Co., Ltd. DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch
JUST OKAY LIMITED DigiCert Trusted Root G4 Hash Mismatch
Zhuhai Kingsoft Office Software Co., Ltd. DigiCert Trusted Root G4 Hash Mismatch
Nuance Communications, Inc. Go Daddy Secure Certification Authority Hash Mismatch
Show More
Hangzhou Shunwang Technology Co.,Ltd VeriSign Class 3 Public Primary Certification Authority - G5 Hash Mismatch
Hangzhou Shunwang Technology Co.,Ltd VeriSign Class 3 Public Primary Certification Authority - G5 Hash Mismatch

File Traits

  • dll
  • x86

Block Information

Total Blocks: 296
Potentially Malicious Blocks: 2
Whitelisted Blocks: 288
Unknown Blocks: 6

Visual Map

0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 ? ? x x ? ? ? ? 1 0 1 0 1 0 1 0 1 0 1 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 1 0 1 1 0 0 2 2 2 3 1 0 1 0 1 0 0 0 0 2
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Trojan.Downloader.Gen.AGR

Files Modified

File Attributes
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.0.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\5bfb36a66a70da6a238032cc784d77fbe6e66508_0000096408.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\1dc0596a09a1e9c8ea957c46d183d2f0cdc8730a_0000094200.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\531c6b43a324c8f139bbbb13c22f092ece8b621a_0002140648.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\4282eeef6ea228e2c5eb1a042ae726f322860472_0000070680.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\d0c49ea1acfa1a0f51ab581c08105949b477d5d1_0000070680.,LiQMAxHB