| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2023-Mar-03 17:54:03 |
| Detected languages |
English - United States
|
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.0 |
| Suspicious | The PE is possibly packed. |
Unusual section name found: .itext
Unusual section name found: .didata |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Info | The PE's resources present abnormal characteristics. | The binary may have been compiled on a machine in the UTC-6 timezone. |
| Malicious | The PE's digital signature is invalid. |
Signer: Softouch Development
Issuer: Sectigo Public Code Signing CA R36 The file was modified after it was signed. |
| Malicious | VirusTotal score: 43/71 (Scanned on 2026-03-17 01:54:41) |
AVG:
Other:Malware-gen [Trj]
AhnLab-V3: Infostealer/Win.ACRStealer.R716531 Alibaba: TrojanDownloader:Win32/Rugmi_AGen.da4dcc70 Antiy-AVL: Trojan/Win32.Rugmi Avast: Other:Malware-gen [Trj] Avira: TR/Redcap.ntnqp Bkav: W32.AIDetectMalware CAT-QuickHeal: Trojan.Ghanarava.17576491727c38d0 CTX: dll.trojan.rugmi CrowdStrike: win/malicious_confidence_100% (W) Cylance: Unsafe DeepInstinct: MALICIOUS DrWeb: Trojan.Loader.2608 ESET-NOD32: Win32/TrojanDownloader.Rugmi_AGen.AL trojan Elastic: malicious (high confidence) F-Secure: Trojan.TR/Redcap.ntnqp Fortinet: W32/Rugmi_AGen.AL!tr.dldr GData: Win32.Trojan.Agent.F3ANAA Google: Detected Ikarus: Trojan-Downloader.Win32.Rugmi K7AntiVirus: Trojan-Downloader ( 005c7f8e1 ) K7GW: Trojan-Downloader ( 005c7f8e1 ) Kaspersky: HEUR:Trojan.Win32.LOADER.gen Lionic: Trojan.Win32.Rugmi.4!c Malwarebytes: Trojan.HijackLoader MaxSecure: Trojan.Malware.196649231.susgen McAfeeD: ti!264FF65ECCF5 Microsoft: Trojan:Win32/Rugmi.HG!MTB Paloalto: generic.ml Panda: Trj/Chgt.AD Rising: Downloader.Rugmi!1.1337F (CLASSIC) Skyhigh: Artemis!Trojan Sophos: Mal/Generic-S Symantec: ML.Attribute.HighConfidence Tencent: Malware.Win32.Gencirc.10c3cfd1 TrellixENS: Artemis!230313B9885A TrendMicro: TROJ_GEN.R002C0DHG25 TrendMicro-HouseCall: TROJ_GEN.R002C0DHG25 VBA32: TScope.Trojan.Delf Varist: W32/ABApplication.IYWH-9197 VirIT: Trojan.Win32.DelphGen.IPD Yandex: Trojan.DL.Rugmi_AGen!V8E2N69hzfo alibabacloud: Trojan[downloader]:Win/Rugmi_AGen.AE |
| e_magic | MZ |
|---|---|
| e_cblp | 0x50 |
| e_cp | 0x2 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0xf |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0x1a |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 10 |
| TimeDateStamp | 2023-Mar-03 17:54:03 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0xf3400 |
| SizeOfInitializedData | 0x1ec00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000F4E68 (Section: .itext) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0xf5000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x11f000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x1247e9 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0 |
| SizeofStackCommit | 0 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| kernel32.dll |
EnterCriticalSection
SetFilePointer GetACP CloseHandle LocalFree GetCurrentProcessId SuspendThread TlsAlloc GetTickCount QueryPerformanceFrequency IsDebuggerPresent GetFullPathNameW VirtualFree HeapAlloc GetStartupInfoW ExitProcess InitializeCriticalSection GetCPInfoExW GetThreadPriority GetCurrentProcess SetThreadPriority VirtualAlloc RtlUnwind GetCPInfo GetCommandLineW GetSystemInfo ResumeThread GetProcAddress LeaveCriticalSection EnumSystemLocalesW GetStdHandle GetVersionExW VerifyVersionInfoW GetModuleHandleW TryEnterCriticalSection FreeLibrary HeapCreate HeapDestroy ReadFile LCMapStringW GetDiskFreeSpaceW VerSetConditionMask GetUserDefaultUILanguage FindFirstFileW TlsFree SetLastError WaitNamedPipeW GetModuleFileNameW GetLastError GetCommTimeouts SetCommTimeouts lstrlenW QueryPerformanceCounter SetEndOfFile CompareStringW CreateThread HeapFree WideCharToMultiByte MultiByteToWideChar FindClose LoadLibraryW LoadLibraryA ResetEvent SetEvent CreateFileW GetLocaleInfoW GetVersion RaiseException FormatMessageW SwitchToThread GetExitCodeThread GetLocalTime WaitForSingleObject GetCurrentThread WriteFile ExitThread DeleteCriticalSection GetDateFormatW TlsGetValue SetErrorMode IsValidLocale TlsSetValue LoadLibraryExW GetSystemDefaultUILanguage EnumCalendarInfoW LocalAlloc GetCurrentThreadId UnhandledExceptionFilter VirtualQuery CreateEventW VirtualQueryEx GetThreadLocale Sleep SetThreadLocale |
|---|---|
| user32.dll |
CallNextHookEx
CharLowerBuffW CharUpperW PeekMessageW GetSystemMetrics SetWindowLongW PostMessageW MessageBoxW SetParent CharUpperBuffW SendMessageTimeoutW GetWindowThreadProcessId CharNextW MsgWaitForMultipleObjects GetClassNameW LoadStringW UnhookWindowsHookEx SetWindowsHookExW SetWindowPos |
| oleaut32.dll |
SafeArrayPutElement
VariantInit VariantClear SysFreeString SafeArrayAccessData SysReAllocStringLen SafeArrayCreate SysAllocStringLen SafeArrayUnaccessData SafeArrayPtrOfIndex SafeArrayGetUBound SafeArrayGetLBound VariantCopy VariantChangeType |
| advapi32.dll |
RegQueryValueExW
RegCloseKey RegOpenKeyExW |
| kernel32.dll (delay-loaded) |
EnterCriticalSection
SetFilePointer GetACP CloseHandle LocalFree GetCurrentProcessId SuspendThread TlsAlloc GetTickCount QueryPerformanceFrequency IsDebuggerPresent GetFullPathNameW VirtualFree HeapAlloc GetStartupInfoW ExitProcess InitializeCriticalSection GetCPInfoExW GetThreadPriority GetCurrentProcess SetThreadPriority VirtualAlloc RtlUnwind GetCPInfo GetCommandLineW GetSystemInfo ResumeThread GetProcAddress LeaveCriticalSection EnumSystemLocalesW GetStdHandle GetVersionExW VerifyVersionInfoW GetModuleHandleW TryEnterCriticalSection FreeLibrary HeapCreate HeapDestroy ReadFile LCMapStringW GetDiskFreeSpaceW VerSetConditionMask GetUserDefaultUILanguage FindFirstFileW TlsFree SetLastError WaitNamedPipeW GetModuleFileNameW GetLastError GetCommTimeouts SetCommTimeouts lstrlenW QueryPerformanceCounter SetEndOfFile CompareStringW CreateThread HeapFree WideCharToMultiByte MultiByteToWideChar FindClose LoadLibraryW LoadLibraryA ResetEvent SetEvent CreateFileW GetLocaleInfoW GetVersion RaiseException FormatMessageW SwitchToThread GetExitCodeThread GetLocalTime WaitForSingleObject GetCurrentThread WriteFile ExitThread DeleteCriticalSection GetDateFormatW TlsGetValue SetErrorMode IsValidLocale TlsSetValue LoadLibraryExW GetSystemDefaultUILanguage EnumCalendarInfoW LocalAlloc GetCurrentThreadId UnhandledExceptionFilter VirtualQuery CreateEventW VirtualQueryEx GetThreadLocale Sleep SetThreadLocale |
| Attributes | 0x1 |
|---|---|
| Name | kernel32.dll |
| ModuleHandle | 0x101080 |
| DelayImportAddressTable | 0x101090 |
| DelayImportNameTable | 0x1010bc |
| BoundDelayImportTable | 0x1010e8 |
| UnloadDelayImportTable | 0x101108 |
| TimeStamp | 1970-Jan-01 00:00:00 |
| Ordinal | 1 |
|---|---|
| Address | 0xfc640 |
| Ordinal | 2 |
|---|---|
| Address | 0x11014 |
| Ordinal | 3 |
|---|---|
| Address | 0x6e4a4 |
| Ordinal | 4 |
|---|---|
| Address | 0xee350 |
| Ordinal | 5 |
|---|---|
| Address | 0xee308 |
| Windows 8 |
| Windows 8.1 |
| Windows 10 |
| Windows 11 |
| Observer is not supported |
| Cannot have multiple single cast observers added to the observers collection |
| The object does not implement the observer interface |
| No single cast observer with ID %d was added to the observer collection |
| No multi cast observer with ID %d was added to the observer collection |
| Invalid date string: %s |
| Invalid time string: %s |
| Invalid time Offset string: %s |
| Must wait on at least one event |
| Cannot call BeginInvoke on a TComponent in the process of destruction |
| 32-bit Edition |
| 64-bit Edition |
| Windows |
| Windows Vista |
| Windows Server 2008 |
| Windows 7 |
| Windows Server 2008 R2 |
| Windows 2000 |
| Windows XP |
| Windows Server 2003 |
| Windows Server 2003 R2 |
| Windows Server 2012 |
| Windows Server 2012 R2 |
| Windows Server 2016 |
| Windows Server 2019 |
| Windows Server 2022 |
| Timespan too long |
| The duration cannot be returned because the absolute value exceeds the value of TTimeSpan.MaxValue |
| Value cannot be NaN |
| Negating the minimum value of a Timespan is invalid |
| Invalid Timespan format |
| Timespan element too long |
| Argument out of range |
| Argument must not be nil |
| Item not found |
| Duplicates not allowed |
| Insufficient RTTI available to support this operation |
| Parameter count mismatch |
| Type '%s' is not declared in the interface section of a unit |
| VAR and OUT arguments must match parameter type exactly |
| %s (Version %d.%d, Build %d, %5:s) |
| %s Service Pack %4:d (Version %1:d.%2:d, Build %3:d, %5:s) |
| Stream write error |
| Thread creation error: %s |
| Thread Error: %s (%d) |
| Cannot terminate an externally created thread |
| Cannot wait for an externally created thread |
| Cannot call Start on a running or suspended thread |
| Cannot call CheckTerminated on an externally created thread |
| Cannot call SetReturnValue on an externally create thread |
| Parameter %s cannot be a negative value |
| Input buffer exceeded for %s = %d, %s = %d |
| Invalid argument |
| Length of Strings and Objects arrays must be equal |
| Source and Destination arrays must not be the same |
| Class %s is not intended to be constructed |
| Invalid Timeout value: %s |
| SpinCount out of range. Must be between 0 and %d |
| ''%s'' is not a valid component name |
| Invalid property value |
| Invalid property path |
| Invalid property value |
| List capacity out of bounds (%d) |
| List count out of bounds (%d) |
| List index out of bounds (%d) |
| Out of memory while expanding memory stream |
| %s has not been registered as a COM class |
| Error reading %s%s%s: %s |
| Stream read error |
| Property is read-only |
| %s.Seek not implemented |
| Operation not allowed on sorted list |
| %s not in a class registration group |
| Property %s does not exist |
| Invalid destination index (%d) |
| Invalid code page |
| Invalid encoding name |
| No mapping for the Unicode character exists in the target multi-byte code page |
| Invalid StringBaseIndex |
| Ancestor for '%s' not found |
| Cannot assign a %s to a %s |
| CheckSynchronize called from thread $%x, which is NOT the main thread |
| Class %s not found |
| A class named %s already exists |
| List does not allow duplicates ($0%x) |
| A component named %s already exists |
| String list does not allow duplicates |
| Cannot create file "%s". %s |
| Cannot open file "%s". %s |
| Invalid stream format |
| Wed |
| Thu |
| Fri |
| Sat |
| Sunday |
| Monday |
| Tuesday |
| Wednesday |
| Thursday |
| Friday |
| Saturday |
| Invalid source array |
| Invalid destination array |
| Character index out of bounds (%d) |
| Start index out of bounds (%d) |
| Invalid count (%d) |
| Dec |
| January |
| February |
| March |
| April |
| May |
| June |
| July |
| August |
| September |
| October |
| November |
| December |
| Sun |
| Mon |
| Tue |
| %s (%s, line %d) |
| Abstract Error |
| Access violation at address %p in module '%s'. %s of address %p |
| System Error. Code: %d. |
| %s%s |
| A call to an OS function failed |
| Jan |
| Feb |
| Mar |
| Apr |
| May |
| Jun |
| Jul |
| Aug |
| Sep |
| Oct |
| Nov |
| Too many custom variant types have been registered |
| Could not convert variant of type (%s) into type (%s) |
| Overflow while converting variant of type (%s) into type (%s) |
| Variant overflow |
| Invalid argument |
| Invalid variant type |
| Operation not supported |
| Unexpected variant error |
| External exception %x |
| Assertion failed |
| Interface not supported |
| Exception in safecall method |
| Object lock not owned |
| Monitor support function not initialized |
| Feature not implemented |
| Method called on disposed object |
| No argument for format '%s' |
| Variant method calls not supported |
| Read |
| Write |
| Execution |
| Invalid access |
| Error creating variant or safe array |
| Variant or safe array index out of bounds |
| Variant or safe array is locked |
| Invalid variant type conversion |
| Invalid variant operation |
| Invalid NULL variant operation |
| Invalid variant operation (%s%.8x) |
| %s |
| Custom variant type (%s%.4x) is out of range |
| Custom variant type (%s%.4x) already used by %s |
| Custom variant type (%s%.4x) is not usable |
| Range check error |
| Integer overflow |
| Invalid floating point operation |
| Floating point division by zero |
| Floating point overflow |
| Floating point underflow |
| Invalid pointer operation |
| Invalid class typecast |
| Access violation at address %p. %s of address %p |
| Access violation |
| Stack overflow |
| Control-C hit |
| Privileged instruction |
| Exception %s in module %s at %p. |
| %s%s |
| Application Error |
| Format '%s' invalid or incompatible with argument |
| <unknown> |
| '%s' is not a valid integer value |
| '%s' is not a valid floating point value |
| '%d.%d' is not a valid timestamp |
| Invalid argument to time encode |
| Invalid argument to date encode |
| Out of memory |
| I/O error %d |
| File not found |
| Invalid filename |
| Too many open files |
| File access denied |
| Read beyond end of file |
| Disk full |
| Invalid numeric input |
| Division by zero |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| FileVersion (#2) | 1.0.0.0 |
| ProductVersion (#2) | 1.0.0.0 |
| Resource LangID | English - United States |
|---|
No comments yet.