Threat Database Trojans Trojan.Rugmi.IFA

Trojan.Rugmi.IFA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 26,396
Threat Level: 80 % (High)
Infected Computers: 9
First Seen: October 13, 2025
Last Seen: May 19, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Rugmi.IFA
Signature status: No Signature

Known Samples

MD5: eba3503a36a5a8c9fb708440a673a870
SHA1: de2a246c277080ca8839de8647ae638dc852aaa8
SHA256: 601E4616AEBCC1DC221D51B7130F443FCE53B373B8907C1350C2911D08F55268
File Size: 313.06 KB, 313064 bytes
MD5: 3191c8a02be379a7501c0ab2b08e1757
SHA1: 830fd06d5e372f2c4265e6daffd57d2df9b11f2b
SHA256: E6A069CDCA4C06305E1A4EBE1AE01F9C785F54E6A926197687E4D53F92097C0F
File Size: 6.31 MB, 6310912 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Comments win64PlayControl
File Description
  • CValiabl Dynamic Link Library
  • Win64_Base_Build20231106
File Version
  • 7, 4, 1, 67
  • 3, 2, 1, 5
Internal Name
  • CValiabl
  • PlayCtrl
Legal Copyright Copyright (C) 2009
Original Filename
  • CValiabl.dll
  • PlayCtrl.dll
Product Name
  • CValiabl Dynamic Link Library
  • PlayCtrl
Product Version
  • 7, 4, 1, 67
  • 3, 2, 1, 5

Digital Signatures

Signer Root Status
Wondershare Technology Group Co.,Ltd DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch
Wondershare Technology Group Co.,Ltd DigiCert Trusted Root G4 Hash Mismatch

File Traits

  • dll
  • x64

Block Information

Total Blocks: 16,712
Potentially Malicious Blocks: 10,989
Whitelisted Blocks: 5,714
Unknown Blocks: 9

Visual Map

x x 0 x 0 x x x x x x x x 0 x 0 x 0 x 0 0 x x x 1 x x x x 0 0 0 x x 0 x 0 x x 0 0 x x 0 x x x x x 0 x x x 0 x x x x x x x x 0 x 0 x x x x x x x x 0 x x x x 0 x x 0 x x x 0 x x 0 x 0 0 x x x x x x x 1 x x 0 0 0 0 x 0 x x x x x 0 0 x x 0 x x x x x x x x 0 x x x 0 0 0 x x x 0 x x x 0 x x x x 0 x 0 x x x x x x x 0 0 x x x x x 1 x x x x 0 x x 0 0 x x x x x x x x x x x x x 0 x x x 0 x x x 0 x x x x x x 0 x x x x x x x x x 0 x x 0 0 x x x 0 x 0 x 0 x x x 0 0 0 0 x x x 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x 0 x x x x x x x 0 0 x x x x x 0 x x x x x x x x 0 0 0 0 x x x x 0 x x x x x 0 0 x x x 0 x x x 0 x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 x x x x 0 x x x 0 0 x 0 0 0 x x x 0 x x x 0 x x 0 x x x x x x x x x 0 x x x x x x x x 0 0 x x x x x x x 0 x 0 x 0 x 0 x x x x 0 0 x x x x 0 0 x x 0 x x x 0 0 x x x x x x x x x x x x x x x x 0 x x x x 0 0 x x x x 0 0 x 0 x x x x x x x x x x x x x 0 x x x 0 x x x x x 0 0 x x x x 0 x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x 0 0 x x x x x x x x x x x x 0 x x x x x x 0 x x x x x x x x x x x x x x x x x x x 0 0 x x x x x 0 x 0 x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x 0 0 x x x x 0 x x x x 0 x x x x 0 x x x x x x x x x x x x x x 0 0 x 0 0 x 0 0 0 x 0 0 0 0 x x 0 x 0 x x x x x 0 x x 0 0 0 0 0 0 x x 0 x 0 x x 0 x x x x 0 x x x x 0 x 0 x x x 0 x x x x 0 x 0 x 0 x 0 x x x x x x x x x x x 0 x 0 x x x x x x x x x 0 x x x x x x x x x x x x x x 0 x x x 0 0 x x 0 x x x x x x x 0 0 0 x x x x x x x x x 0 0 x x x x x x x x x x x x x 0 x 0 x x x x x x x 0 x x x x x x x x x 0 0 x 0 x 0 x x 0 0 x x x x 0 x x x x x x x x x x 0 x x x 0 x x x x x x x x x x x 0 x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x 0 x x x x x 0 0 x x x x x x x x x x x 0 x x x x 0 x x x x 0 x x x x x x x x 0 x x x x x x 0 x 0 0 0 x 0 0 0 0 x x 0 x 0 x x x x x x x x 0 0 0 0 0 x 0 0 x x x x x x x x x 0 x x x 0 x x x 0 x 0 x 0 0 x 0 0 0 x x x x x x 0 x x x x x 0 x x x x x x x x 0 0 0 x x x 0 0 0 x 0 x x x 0 x x x 0 x 0 x x x x 0 x x x 0 x x x 0 x x x x x x x x 0 x x x x x x 0 x x x x 0 0 x x 0 0 x x 0 0 0 x 0 0 0 x x x x x x x x x x x x 0 x x x x x x x x x 0 x x x x x x 0 x x x x x x x 0 x x x x x x x 0 0 0 x 0 0 0 x x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 x x x 0 x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x 0 x 0 x 0 x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 x 0 x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 x x x x x 0 x 0 0 0 0 x 0 0 0 x 0 0 x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x x 0 x x 0 x 0 x x 0 x 0 x x x x x x x x 0 x x x x x x 0 x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x 0 x x 0 x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x 0 x 0 x x x x x x x x x x x 0 x x 0 x x x x x x x x x x x x x 0 x 0 x x 0 x 0 x x 0 x x x 0 x x x 0 x x x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x x x 0 x 0 x 0 x x x 0 x 0 x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 x x x x x x x x x x x x x 0 0 0 x x x x 0 x x 0 x x x x x x 0 x x x 0 x x x x x x x x x x x x x x x x 0 x x x x x 0 0 x 0 0 x 0 0 x x x x x x 0 x 0 x x 0 x 0 x x x x x x x x x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x 0 x x x x 0 0 0 0 0 0 0 x 0 x 0 x x x x x x x x x x x x x x x x x x x x x 0 x 0 0 x x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 x x 0 x x x
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Rugmi.IFA

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
Show More
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueryWnfStateNameInformation
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUpdateWnfStateData
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...