Threat Database Trojans Trojan.Rugmi.HB

Trojan.Rugmi.HB

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 4,727
Threat Level: 80 % (High)
Infected Computers: 122
First Seen: March 6, 2026
Last Seen: July 18, 2026
OS(es) Affected: Windows

The detection of Trojan.Rugmi.HB on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, potentially leading to unauthorized access, data theft, and other malicious activities. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.Rugmi.HB?

Trojan.Rugmi.HB is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate or harmless. Trojans are often distributed through deceptive means, such as fake software updates, infected email attachments, or exploited vulnerabilities in software. Once installed, Trojans can perform a wide range of malicious activities, including data theft, system compromise, and the installation of additional malware.

How Trojan.Rugmi.HB Operates

Trojan.Rugmi.HB, like other Trojans, is designed to operate stealthily, avoiding detection by traditional security software. It may use various techniques to evade detection, such as code obfuscation, anti-debugging, and rootkit functionality. Once installed, the malware may communicate with its command and control (C2) server to receive instructions, upload stolen data, or download additional malware. The specific goals and behaviors of Trojan.Rugmi.HB are not well understood, but it is likely designed to generate revenue for its creators through malicious activities such as data theft, ransomware, or pay-per-install schemes.

Symptoms of Infection

Infected systems may exhibit a range of symptoms, including unusual network activity, slow system performance, and unexpected changes to system settings or files. Users may also notice suspicious pop-ups, redirects, or other unwanted behavior. However, some Trojans, including Trojan.Rugmi.HB, may not exhibit any noticeable symptoms, making them difficult to detect without the aid of security software.

  • Unexplained changes to system settings or files
  • Slow system performance or crashes
  • Suspicious network activity or unexpected connections
  • Unwanted pop-ups, redirects, or other browser-related issues

How to Remove Trojan.Rugmi.HB

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of the malware.
  3. Uninstall any suspicious programs or applications that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings.
  5. Reboot your system and perform a follow-up scan to ensure that the malware has been completely removed.

Conclusion

The detection of Trojan.Rugmi.HB on your system is a serious security issue that requires immediate attention. By understanding the nature of this threat and taking prompt action to remove it, you can help prevent further damage and protect your personal data. It is essential to remain vigilant and take proactive steps to prevent future infections, including keeping your operating system and software up to date, using reputable security software, and avoiding suspicious downloads and email attachments.

Analysis Report

General information

Family Name: Trojan.Rugmi.HB
Signature status: Hash Mismatch

Known Samples

MD5: f142ceceb8fa5d51b167d09a27d199be
SHA1: 04c077dc1d95c316ce820d1b0b624aa36257e1e4
SHA256: E2899AC504201322EE8F57B87A04C8A5CA737BAAD20C1F11A81C4515964D3218
File Size: 2.74 MB, 2744320 bytes
MD5: d3281d6700d0cdd0212fa62003c82df2
SHA1: 173359fc023e0c7a3e2e0b36bd46368a2d2533cf
SHA256: 23B4F0EEFA8EF061EF3448E5C75A8CB23619BAAE670F71B093A7AFB8B5050BED
File Size: 115.63 KB, 115632 bytes
MD5: 87810c9316fa37154f5a75ea06ac4742
SHA1: e5e68a054c564d8cf4e69c2f91b4409eb484cd8d
SHA256: BEEF9D676FC6CC9C7DD229D27264C8A3057FB0446DDEB87AF33D05F44B3357D6
File Size: 1.49 MB, 1492232 bytes
MD5: e854f222bed785a57657012e18b2c86f
SHA1: 494e58f297e6b07b811b3c0e2b29373e778990e1
SHA256: 8586A05D92D934451233323AE2A26EA6EC3945E2E2847438D563FB2247934B80
File Size: 2.74 MB, 2744320 bytes
MD5: e7c4234b1150939df5ec3f1893099f42
SHA1: 502f4fc18bd6186c45d4574123a814f9f17c06d3
SHA256: 0750DB848790636BEDEACBC968E4FB8A3B796944875ED6E8C3D545E7A351D8C7
File Size: 1.18 MB, 1184256 bytes
Show More
MD5: 2edc6494a6315e9fe5912bd8019d3bd7
SHA1: 74cb9f4a0b88d7d4810b354d9e758de345c3373b
SHA256: 77840452C2EC8D158E6E5374D913561CA540B40568CC761D08BF44C58B97FFD7
File Size: 2.74 MB, 2744320 bytes
MD5: ae4a60edf2bc72e829f9b2cc45854ae0
SHA1: 7a113bbc0069cb0425a75e8a51bd934c78edafd6
SHA256: 76777B07F22C3805FDBA0C03CD76568918DBA0B6C21D03D4C2D3D25EA21AF82B
File Size: 361.47 KB, 361472 bytes
MD5: 20ebae0e02f279336b3e7ff4fcf74572
SHA1: a81240887c53323c0afe7d1150d4780eccb1a8ab
SHA256: 2F493A47E6C6CD6270B443CDF6529552F9314628FFA22F0FC01EF04DA803751A
File Size: 1.67 MB, 1668848 bytes
MD5: 5e7ad30ee06454cafbac1d817063aab9
SHA1: 18eb46c47af0cf794c8cbf7315c4bd46e999d0e3
SHA256: 1132B7F88E0278A10A3FD9481AE88FDF6A2E9A548F89B7266AB824F778B23EE5
File Size: 171.01 KB, 171008 bytes
MD5: b90e0615d8037e0bfe2d8a75b19684ad
SHA1: 8fed55866e3c0a1cec4abd500d9ca0f2d2f5390f
SHA256: 4253952B2FEEA6C646242F406A17559834FCAD3811D0017E776A549574DDA283
File Size: 470.02 KB, 470016 bytes
MD5: 08d9d991fe9834e359eb64c165dee706
SHA1: 5dbe769a895f0f234a3185289049be0cfded8921
SHA256: 64628756C1CE9A1F57E6AAB7327DDE9E5D0EBB63EAE878F9F48D58FF45B98A7D
File Size: 1.41 MB, 1408048 bytes
MD5: d6b337fe3ba4403870ba16cd70db47f1
SHA1: 255b203f80fb17b38c5c376ff3db352700b22478
SHA256: 66600887758DC840C522BC7E3A99E306170FBF077CB5494508A0A8D411F5B103
File Size: 163.46 KB, 163464 bytes
MD5: ae858590d58c7623421789017d2162a5
SHA1: cf3ae58d0f947e57c42beabe13fd21c3085fd240
SHA256: 457989153C062BCF7544B0E0C25B9CD53798DF8AB3F496CEC117426C5CE23F6E
File Size: 1.49 MB, 1492232 bytes
MD5: 09ad521b8f0feea0355554bbd89c9b87
SHA1: 08d43c39c3ddfe34fadd260773281dfe5fcc0111
SHA256: 733FC8B3146261A879CB36D4E013BAB9A0B34E3F809E63F77778B734EC50432E
File Size: 185.42 KB, 185424 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Comments For more information visit https://libgit2.org/
Company Name
  • Microsoft Corporation
  • Python Software Foundation
  • The cURL library, http://curl.haxx.se/
  • The OpenSSL Project, http://www.openssl.org/
Company Short Name Microsoft
File Description
  • libcurl Shared Library
  • libgit2 - the Git linkable library
  • Microsoft Edge Embedded Browser WebView Loader
  • Microsoft® C/C++ OpenMP Runtime
  • NLEResou 动态链接库
  • OpenSSL shared library
  • Python Core
File Version
  • 14.44.35112.1
  • 7.41.0
  • 3.4.4
  • 1.8.4
  • 1.1.0e
  • 1.0.1901.177
  • 1, 3, 1, 5
Internal Name
  • git2-3f4182d.dll
  • libcurl
  • libssl-1_1
  • NLEResou
  • Python DLL
  • VCOMP140.DLL
  • VCOMP140D.DLL
  • WebView2Loader.dll
Last Change 70d3bcefea71de913f3be6ae4409066cb83e1911
Legal Copyright
  • ?1996 - 2015 Daniel Stenberg, <daniel@haxx.se>.
  • Copyright (C) 2010
  • Copyright (C) the libgit2 contributors. All rights reserved.
  • Copyright 1998-2016 The OpenSSL Authors. All rights reserved.
  • Copyright Microsoft Corporation. All rights reserved.
  • Copyright © 2001-2015 Python Software Foundation. Copyright © 2000 BeOpen.com. Copyright © 1995-2001 CNRI. Copyright © 1991-1995 SMC.
  • © Microsoft Corporation. All rights reserved.
License http://curl.haxx.se/docs/copyright.html
Official Build 1
Original Filename
  • git2-3f4182d.dll
  • libcurl.dll
  • libssl-1_1.dll
  • NLEResou.dll
  • python34.dll
  • VCOMP140.DLL
  • VCOMP140D.DLL
  • WebView2Loader.dll
Product Name
  • libgit2
  • Microsoft Edge Embedded Browser WebView Loader
  • Microsoft® Visual Studio®
  • NLEResou 动态链接库
  • Python
  • The cURL library
  • The OpenSSL Toolkit
Product Short Name Microsoft Edge Embedded Browser WebView Loader
Product Version
  • 14.44.35112.1
  • 7.41.0
  • 3.4.4
  • 1.8.4
  • 1.1.0e
  • 1.0.1901.177
  • 1, 3, 1, 5

Digital Signatures

Signer Root Status
ORANGE VIEW LIMITED DigiCert High Assurance EV Root CA Hash Mismatch
HITPAW CO., LIMITED DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch
HITPAW CO., LIMITED DigiCert Trusted Root G4 Hash Mismatch
Microsoft Corporation Microsoft Code Signing PCA 2011 Hash Mismatch
Microsoft Windows Software Compatibility Publisher Microsoft Windows Third Party Component CA 2013 Hash Mismatch
Show More
AOMEI International Network Limited Sectigo Public Code Signing Root R46 Hash Mismatch

File Traits

  • dll
  • HighEntropy
  • x86

Block Information

Total Blocks: 856
Potentially Malicious Blocks: 1
Whitelisted Blocks: 698
Unknown Blocks: 157

Visual Map

? ? ? ? 0 0 ? ? ? ? 0 0 ? ? ? 0 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 1 1 ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 ? 0 0 0 0 0 0 ? ? ? ? ? ? 0 0 ? ? 0 ? ? 0 0 0 0 0 ? 0 0 0 0 0 ? ? 0 ? ? ? 0 0 ? ? 0 ? 0 0 0 0 ? ? ? ? ? ? 0 0 ? 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 ? ? 0 0 ? 0 0 0 0 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? 0 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 ? ? ? ? ? ? 0 0 0 ? 0 0 0 ? ? ? ? ? 0 0 0 ? 0 ? 0 0 0 ? ? ? 0 0 ? 0 ? 0 0 0 ? ? ? 0 0 ? ? ? 0 0 0 ? ? ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? ? ? ? x 0 ? 0 0 ? 0 ? 0 ? 0 ? 0 ? ? ? ? ? ? ? ? ? 2 2 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 1 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 3 1 1 0 0 1 0 1 0 1 1 0 0 0 1 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.TJZ
  • Gamehack.JUA
  • Rugmi.HB
  • Rugmi.PG
  • Rugmi.TB
Show More
  • Trojan.Downloader.Gen.CX
  • Trojan.Downloader.Gen.DM
  • Trojan.Downloader.Gen.JO
  • Trojan.Downloader.Gen.QD
  • Trojan.Kryptik.Gen.DGK
  • Trojan.ShellcodeRunner.Gen.LN

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\04c077dc1d95c316ce820d1b0b624aa36257e1e4_0002744320.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\173359fc023e0c7a3e2e0b36bd46368a2d2533cf_0000115632.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\e5e68a054c564d8cf4e69c2f91b4409eb484cd8d_0001492232.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\494e58f297e6b07b811b3c0e2b29373e778990e1_0002744320.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\502f4fc18bd6186c45d4574123a814f9f17c06d3_0001184256.,LiQMAxHB
Show More
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\74cb9f4a0b88d7d4810b354d9e758de345c3373b_0002744320.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\7a113bbc0069cb0425a75e8a51bd934c78edafd6_0000361472.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\a81240887c53323c0afe7d1150d4780eccb1a8ab_0001668848.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\18eb46c47af0cf794c8cbf7315c4bd46e999d0e3_0000171008.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\8fed55866e3c0a1cec4abd500d9ca0f2d2f5390f_0000470016.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\5dbe769a895f0f234a3185289049be0cfded8921_0001408048.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\255b203f80fb17b38c5c376ff3db352700b22478_0000163464.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\cf3ae58d0f947e57c42beabe13fd21c3085fd240_0001492232.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\08d43c39c3ddfe34fadd260773281dfe5fcc0111_0000185424.,LiQMAxHB

Trending

Most Viewed

Loading...