Threat Database Trojans Trojan.Rugmi.ODA

Trojan.Rugmi.ODA

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Rugmi.ODA
Signature status: Hash Mismatch

Known Samples

MD5: 0a5c807cb24af810ad53dfb8881b12f7
SHA1: 6b4b72036d0a49014982235182c7efa36d62814c
SHA256: 95A3F8CB32109AD65CCA12CBC23E3419B30D1272D3A73D109DEBB0C9BE8EB908
File Size: 396.19 KB, 396192 bytes
MD5: ad076d3573488b34bcba52617790dae2
SHA1: 50e30d72aaff814a8c8ff4b606fd592cb25f6788
SHA256: 96DF0047DE8DA60B95E4FC0C5A947866AE75FB43BB2560FB3D9A0E76212E695B
File Size: 396.19 KB, 396192 bytes
MD5: 64a5a928ae8db5fe64a64e0f8661ef01
SHA1: 4e58a72fc08057bfcb063e810257f858548d749b
SHA256: D911F5BD424AEE33D4D78394ECD3EFE68D01F523A8869A37154522BC923293F4
File Size: 756.64 KB, 756640 bytes
MD5: 90d0f4892530936439ce3dfd80a5bfad
SHA1: 96d8c3ec0890d194296a0eb575baf9892c4a1e30
SHA256: 1733D1CFCDA0EF9D56C157FAC9E48DAB8CBB03C9C90AB3BAA08E6A3560B1B08F
File Size: 396.19 KB, 396192 bytes
MD5: fb90d6b81ceaae07d277a22f9abc4b04
SHA1: f186ca4c0c8bde6cd4116ccbed7b587467746281
SHA256: CC460BE6447EB189DC679BFC2F13134554F4FD1655AEC6D3D62D432F8473DEF0
File Size: 396.19 KB, 396192 bytes
Show More
MD5: bec74631f62c566aeb68384bb6b04225
SHA1: 91e42cce4bb8462c647278fe607c7525a417ab97
SHA256: 7252E4279CAEE4C9DB221D9B07EF4CC4C4662477A1A7445F31DEE7C7D121D1D6
File Size: 396.19 KB, 396192 bytes
MD5: 37c279beb3aaee5a25baa4132a6ec8d7
SHA1: dc48d316c38b570d927012d1cee93816ae7c8fcc
SHA256: F9A3E94B66CEA8BFEAAAA5C9F6D295B7B3A06348E5EFCFF27019451A3CBF1F10
File Size: 396.19 KB, 396192 bytes
MD5: 88cc097881671afeb22f3bd75e0291be
SHA1: 0de412d6a286479c78e98d2c24c3f7ad03d03c10
SHA256: EC7BDAD83B292D61AAEF18A170B8526E9866888F0340D2F9FACC71ECD4B5FE95
File Size: 396.19 KB, 396192 bytes
MD5: 6df157185eb4cb6ea329589123812b79
SHA1: 4f27dcf0c61c6e7a51100588af8674a5ecb69dc4
SHA256: 5CD1C369FA048FF6FF1868D2E34F80F8D14B8AF1ED44525ECA40D68B4E1E03C2
File Size: 396.19 KB, 396192 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Comments
  • Intel(R) Integrated Performance Primitives. Image Processing. DLLs dispatcher
  • Intel(R) OMP Performance Library version 5.0.20101208 for IA-32 architecture built on 2010-12-08 22:08:43 UTC.
Company Name
  • Intel Corporation
  • Intel Corporation.
File Description
  • Intel(R) OMP Runtime Library
  • ippi-7.0.dll is the ippIP dispatcher
File Version
  • 20101208
  • 7,0,205,1054
Internal Name
  • ippi-7.0.dll
  • libiomp5md.dll
Legal Copyright
  • Copyright (C) 1997-2010, Intel Corporation. All rights reserved.
  • Copyright(C) Intel Corporation, 1999-2011
Original Filename
  • ippi-7.0.dll
  • libiomp5md.dll
Product Name
  • Intel(R) OMP Runtime Library
  • ippIP. Intel(R) Integrated Performance Primitives. Image Processing.
Product Version
  • 7.0 build 205.58
  • 5.0

Digital Signatures

Signer Root Status
Intel(R) Software Products Equifax Secure Certificate Authority Hash Mismatch

File Traits

  • 2+ executable sections
  • dll
  • HighEntropy
  • x86

Block Information

Total Blocks: 233
Potentially Malicious Blocks: 8
Whitelisted Blocks: 205
Unknown Blocks: 20

Visual Map

x x 0 0 0 ? ? ? 0 ? ? ? ? ? ? ? 0 0 0 ? 0 0 ? 0 0 x ? 0 x ? 0 0 ? ? ? x ? 0 0 x ? ? x 0 x 2 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 3 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 2 2 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 1 0 0 0 1 0 0 2 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\6b4b72036d0a49014982235182c7efa36d62814c_0000396192.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\50e30d72aaff814a8c8ff4b606fd592cb25f6788_0000396192.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\4e58a72fc08057bfcb063e810257f858548d749b_0000756640.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\96d8c3ec0890d194296a0eb575baf9892c4a1e30_0000396192.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\f186ca4c0c8bde6cd4116ccbed7b587467746281_0000396192.,LiQMAxHB
Show More
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\91e42cce4bb8462c647278fe607c7525a417ab97_0000396192.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\dc48d316c38b570d927012d1cee93816ae7c8fcc_0000396192.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\0de412d6a286479c78e98d2c24c3f7ad03d03c10_0000396192.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\4f27dcf0c61c6e7a51100588af8674a5ecb69dc4_0000396192.,LiQMAxHB

Trending

Most Viewed

Loading...