Threat Database Trojans Trojan.Rugmi.T

Trojan.Rugmi.T

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 10,877
Threat Level: 80 % (High)
Infected Computers: 219
First Seen: April 20, 2024
Last Seen: March 24, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Rugmi.T
Signature status: Hash Mismatch

Known Samples

MD5: bff3e6582eaaa19e4a64445e6227acae
SHA1: 8457207b21c08988d88943e99e067762fb8334be
SHA256: 3F24AE5A5CC02ACE74E0C432536F9B1575A0C534B22487D2BF89C28B9E13EE24
File Size: 1.31 MB, 1314424 bytes
MD5: 4dac10418e9a9bd9e11bf0d6411c3e9c
SHA1: 0c23c49ec6a53a52c7886c21ea8ae90c5ba45f9d
SHA256: 3E1E76EDE193A0F4E77F8EFAACCEB0D6D8809F1E675A18F3C630882ED0ADE5CD
File Size: 1.31 MB, 1314424 bytes
MD5: 011b27bc3c638afa0597108000337c39
SHA1: 2fb6095142dde0c2f053800eedd73ae92fafea3f
SHA256: BDC015DD72129CD6C69DF73D2A110448B70BC2DB958B98AED6465AA0AB459A82
File Size: 1.31 MB, 1314424 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name The Qt Company Ltd.
File Description C++ Application Development Framework
File Version 5.12.5.0
Legal Copyright Copyright (C) 2019 The Qt Company Ltd.
Original Filename Qt5Network.dll
Product Name Qt5
Product Version 5.12.5.0

Digital Signatures

Signer Root Status
The Qt Company Oy thawte SHA256 Code Signing CA Hash Mismatch

File Traits

  • dll
  • x64

Block Information

Total Blocks: 5,556
Potentially Malicious Blocks: 1,183
Whitelisted Blocks: 4,373
Unknown Blocks: 0

Visual Map

x x x x x 0 x 0 x 0 x 0 x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 x 0 0 0 0 1 0 x x x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 x 0 x 0 0 x 0 0 0 0 0 x 1 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 x x 0 x x 0 x x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 x x x x 0 x 0 x 0 1 0 0 0 x 0 x 0 0 0 0 x 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x x x 0 x x 0 x x x 0 0 0 1 0 0 x x 0 0 x 0 0 0 0 0 0 x 0 0 0 0 x x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 x x x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 0 0 0 0 0 x x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 x x 0 0 x 0 0 0 0 0 x 0 x x 0 0 0 0 0 x x 0 x 0 0 0 0 x 0 0 0 x 0 0 0 0 x 0 0 x x 0 x x x 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 1 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x 0 x 0 0 x 0 0 0 x 0 0 0 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 0 0 x x 0 x 0 0 0 0 0 0 x 0 x 0 0 0 0 x 0 x 0 0 x 0 0 0 0 0 x 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x x x x 0 0 0 0 0 x x x x 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 1 0 x 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 1 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 0 0 0 0 x 0 0 0 0 0 x 0 x 0 x x x x 0 0 x x x 0 0 0 0 0 x x x x 0 0 0 0 0 x 0 0 x x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 x x x x x x x x 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 x 0 x 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 x 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 x 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 x x x x x 0 x 0 x 0 0 x x x 0 x 0 x x 0 x 0 0 0 x x x 0 x 0 x 0 x 0 x 0 x 0 0 x 0 0 0 0 0 0 1 x 0 x x 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x 0 0 x 0 x x 0 x x 0 0 0 x 0 x x x 0 x 0 x 0 0 0 x 0 x 0 x 0 0 0 x 0 x 0 0 0 0 x 0 0 0 0 0 0 x x 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x x 0 x 0 0 0 0 1 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 x 0 0 x x x 0 0 x x 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 x x 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 x x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 x 0 x x x 0 x 0 0 0 0 0 0 x 0 0 0 0 0 x 0 x x 0 x 0 x x x 0 0 0 0 0 x x 0 x x 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 x 0 x 0 x 0 0 x x x 0 0 0 x 0 0 x 0 1 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 1 0 0 0 0 x 0 0 0 0 0 0 1 0 0 0 0 x 0 0 0 0 1 0 x x 0 0 0 0 0 0 x 0 x x 0 0 0 0 x 0 x 0 0 1 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 x x 0 0 0 x x x 0 0 0 0 0 x 0 0 0 x 0 0 x 0 0 0 x 0 0 0 0 x x x 0 x 0 0 x x x 0 x 0 0 0 0 x 0 0 x 0 0 0 0 x x x x x 0 x 0 0 x x 0 0 0 0 0 0 x 0 0 x x 0 0 x x x 0 x 0 x 0 x 0 x 0 0 0 x 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 0 0 x 0 x 0 x 0 x x 0 x 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 1 0 0 0 0 1 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 x 0 0 x x 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 1 0 0 0 0 0 x 0 0 0 x 0 x x 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 x 0 0 0 0 x 0 0 x 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Rugmi.BA
  • Rugmi.T

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
Show More
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Related Posts

Trending

Most Viewed

Loading...