Threat Database Trojans Trojan.Rugmi.LDB

Trojan.Rugmi.LDB

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Rugmi.LDB
Signature status: Hash Mismatch

Known Samples

MD5: c245cef8af53cdff9c6b7786563ad618
SHA1: 6baa9ac4bcad3ed5f4609d56edd8ebcbb4f279b6
SHA256: AD38ED196CA91B4B34284A4CF3258C40176C60D6C078786EF58C45A88E772D8F
File Size: 1.27 MB, 1270184 bytes
MD5: 8c7f532af958b2aecde2e90fbf58f185
SHA1: 2e3e0446fb53b65e45f0ece9c716940c3d8e4cbf
SHA256: 716E9296ACB22B1815B0920849FF6EAF4A592FEBA179039F64F2D19A3ABE5763
File Size: 154.62 KB, 154624 bytes
MD5: 029980f5e584b3d941d4c8c7f94eb8dd
SHA1: 8051f2f00519a043254f359404c66376d1ffda42
SHA256: 58DE8F7B9823D00CC2FD67467FB8044DC94D5F7CDF585381E7AF8A7D93443B7C
File Size: 1.51 MB, 1508400 bytes
MD5: 3f65c803c972afef86349f63e1f4f515
SHA1: 7301e725c1e54a5bd33e45e37c0a0221931af927
SHA256: 92B9F44DA00482F270F992414211B4274CCF7D0AD10EE64C9323336DAC96BBC6
File Size: 303.57 KB, 303568 bytes
MD5: d6215a72dbc0a46ddc70df45cb249b44
SHA1: 2917c838cf6f141cfca055ab5eb9079f0de5f912
SHA256: C667804C6CF8026ED357792A64311E8C5EEF65A9C4728812D70E963D5CFACBB2
File Size: 2.50 MB, 2501736 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name
  • BugSplat, LLC
  • Microsoft Corporation
File Description
  • Crash Handling Module
  • Crash reporting module, BugSplat.DLL
  • Microsoft Instrumentation Engine
  • Microsoft® Disassembler
File Version
  • 15.1.0.2022032203
  • 14.44.35207.1
  • 3, 3, 1, 0
  • 1.4.0.2
Internal Name
  • BugSplat.DLL
  • CrashRpt
  • MicrosoftInstrumentationEngine_x86
  • MSVCDIS140.DLL
Legal Copyright
  • Copyright 2003-2013 The CrashRpt Project Authors
  • Copyright BugSplat, LLC (C) 2015
  • © Microsoft Corporation. All rights reserved.
Legal Trademarks Microsoft® is a registered trademark of Microsoft Corporation.
Original Filename
  • BugSplat.DLL
  • CrashRpt.dll
  • MicrosoftInstrumentationEngine_x86.dll
  • MSVCDIS140.DLL
Product Name
  • BugSplat Dynamic Link Library
  • CrashRpt
  • Microsoft® Visual Studio®
Product Version
  • 15.1.0.2022032203
  • 14.44.35207.1
  • 3, 3, 1, 0
  • 1.4.0.2
Special Build 0

Digital Signatures

Signer Root Status
Planestate Software AB COMODO RSA Code Signing CA Hash Mismatch
BugSplat LLC Go Daddy Secure Certification Authority Hash Mismatch
Microsoft Corporation Microsoft Code Signing PCA 2011 Hash Mismatch

File Traits

  • dll
  • HighEntropy
  • x86

Block Information

Total Blocks: 7,027
Potentially Malicious Blocks: 3,310
Whitelisted Blocks: 3,717
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 x x 0 x 0 0 0 x 0 0 0 x x 0 x 0 0 0 0 1 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 x x 0 0 x x x x x x x 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x 2 x x x 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 x x x x 0 x 0 0 x 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 1 x x x x 0 0 x x x 0 0 x x 0 0 0 0 0 x 0 0 0 x 0 x x 0 0 x 0 0 0 0 0 0 x x x 0 0 0 x 0 0 x 0 0 0 0 x x x x 0 x x x 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 2 0 x 0 0 0 x 0 x 0 x 0 0 0 0 x 0 0 0 0 0 0 0 2 x 0 0 0 0 0 0 0 0 0 x 0 x x 0 x 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x 0 x x x x x 0 x x x 0 0 0 0 0 0 x 0 x 0 0 0 0 x 0 0 x x 0 x 0 0 x 0 x 0 0 0 x x x 0 0 0 0 1 1 0 x x 0 x x x x 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 1 x 0 x 0 0 0 x 0 0 0 0 0 0 0 0 x x x 0 x x x x x x 0 0 x x 0 x 0 0 0 0 0 x 0 0 0 0 x 0 x x x x x x x x 0 x x x x 0 x x 0 x 0 0 0 0 0 x 0 0 0 x 0 0 x 0 0 x x 0 0 0 0 0 x x 0 0 1 0 0 0 0 x 0 0 0 0 x x 0 0 0 0 x x x x 0 x 0 x 0 x x x 0 0 0 x x x x x x x 0 x x 0 0 0 x x x x 0 0 x x x 0 1 x x 0 0 0 0 0 0 x 0 0 0 0 0 0 x x x x x 0 x x 0 0 0 x x x 0 0 0 x 0 x x x x x 0 x x 0 0 0 0 0 x 0 x x 0 x x 0 0 x 0 x x 0 0 0 0 0 0 0 0 x 0 0 x 0 x 0 0 x 0 x 0 0 x 0 x 0 0 x 0 x x 0 0 x 0 x x 0 0 x 0 x x x 0 0 x 0 x x x 0 0 x 0 x x x 0 0 x 0 x 0 0 x 0 x x 0 0 x 0 x 0 0 x 0 x 0 0 x 0 x 0 0 x 0 x 0 0 x 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x x x x 0 0 0 x x x x x x x x x x x 0 0 x x x 0 0 x x x x x x 0 x x 0 x x 0 x x 0 x x x x 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 x x 0 x x x x 0 x x 0 0 x x x x 0 0 x 0 x x 0 0 0 0 0 x x x x 0 x 0 0 0 0 x x 0 0 x x x x x x x x x x x x x 0 x x 0 x x x x x x x x x x 0 0 0 x x x x 0 x x x x x 0 x x x x x x x x x 0 x x x x x 0 x x 0 x x x 0 x x x x x 0 x x 0 0 0 0 x x x x x 0 x 0 x x 0 x x x x x x x x x x x x 0 x 0 x x x x x x x x x x x x x x 0 x x 0 x x x 0 0 x 0 x x 0 x x x 0 0 0 0 x x x 0 0 0 x x x x 0 0 0 0 x 0 0 x x x x 0 0 x x x 0 0 0 x x x 0 0 0 x x x 0 0 0 x x x 0 0 0 0 0 0 0 x 0 0 0 0 0 x x x x x 0 x x 0 x 0 0 0 0 x 0 x 0 x x x 0 0 0 1 0 x 0 0 x x 0 0 0 x 0 x x x 0 x x x 0 x x 0 x 0 0 0 0 0 0 0 0 0 x 0 x x 1 x x x x x x x x x x x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x x x x x 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x x 0 0 x 0 0 0 x x 0 x x x 0 x x x x x x x x x 0 x x 0 0 x 0 x 0 x 0 x 0 0 x x x x x x 0 0 0 0 0 x x x x x x 1 x x x 0 0 x x x x x 0 0 x x x x x 0 0 x x x x x x x x 0 0 x x x x x 0 0 x x x x x 0 0 x x x x x 0 x 0 0 x x x x x 0 0 x x x x x x 0 x x x x 0 x x x x x x 0 0 x x x x x x x 0 x 0 x x x x 0 x x x x 0 0 x 0 0 x x x x 1 x 0 0 x x x x x x 0 x 0 x x x x 0 0 0 0 0 x x 0 0 0 x x 0 0 x x x x x 0 x 0 x x 0 0 x 0 0 x x x x x 0 x 0 x 0 x x 0 x x x x 0 x x x 0 x x x x x x 0 x 0 x x 0 0 x 0 0 x x x x x 0 x x x 0 x 0 x x 0 0 0 0 0 x x x 0 x x x x x x 0 0 x x 0 0 x 0 0 0 x x x 0 x x 0 x x x x x x x x 0 x x x x 0 0 x x x 0 x 0 x 0 x x x 0 x x x x x x x 0 0 0 0 0 0 0 0 0 x x x x 0 x x x x 0 x x x 0 0 0 0 x x x 0 0 x x 0 x x x x x x x x x x x x x x x x x 1 0 0 0 0 x x x x 0 x 0 x x x x 0 x x x x x 0 x 0 x 0 x x 0 x x x x x x x 0 0 0 0 0 x x 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 x x 0 0 0 x x 0 x x x 0 x x x x x 0 0 x x x x x 0 0 x 0 0 x x x x x x 0 0 x x x x x x x x x x x x x x x x x 0 x x x x 0 0 x x 0 x 0 x x x x x 0 0 x x x 0 0 x x x 0 x x x x x x 0 0 0 x x 0 x x x x x x x x x x x x 0 0 x x x x x x 0 0 0 0 0 x 0 x 0 x x x 0 x x x x x 0 0 0 0 x x x x x 0 x x x x x 0 x x x x 0 x x 0 x x 0 x x 0 x x 0 x 0 0 x x x x x x 0 x x x x 0 x x x x 0 x x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x 0 0 0 x 0 0 0 0 0 x 0 0 0 x x x 0 0 x x x 0 x 0 0 0 0 x x 0 0 0 x x 0 0 0 x x x 0 x x x x x x x x x x 0 0 x x x x x x x x x x x x x x x 0 0 x x 0 x x x x x 0 0 0 x x 0 x 0 0 0 0 x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x x 0 0 x x x x x x x x x x x 0 0 0 x x x x x x 0 x x x 0 0 x x 0 0 x x 0 x x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Rugmi.GI
  • Rugmi.LDB
  • Rugmi.OO
  • Rugmi.TB

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\6baa9ac4bcad3ed5f4609d56edd8ebcbb4f279b6_0001270184.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\2e3e0446fb53b65e45f0ece9c716940c3d8e4cbf_0000154624.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\8051f2f00519a043254f359404c66376d1ffda42_0001508400.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\7301e725c1e54a5bd33e45e37c0a0221931af927_0000303568.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\2917c838cf6f141cfca055ab5eb9079f0de5f912_0002501736.,LiQMAxHB

Trending

Most Viewed

Loading...