MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 da0db01417df6ccfe6df054b08663ed59d377c065740a7a83921c033dbebb29e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 4 File information Comments

SHA256 hash: da0db01417df6ccfe6df054b08663ed59d377c065740a7a83921c033dbebb29e
SHA3-384 hash: 5663c8431bb2b8052770297a09e296276d167fc3c744524a08d0539e993b7a19733481fc1d82aa809f87e025b77ad268
SHA1 hash: 3b1b4d47c24789fcfab017504e085990dabf4208
MD5 hash: 416b67c98e1b73ab2b04fd2e79f72c12
humanhash: blue-west-six-winter
File name:DG.dll
Download: download sample
File size:2'741'760 bytes
First seen:2026-07-30 16:51:28 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash a9c0aa7b5c77e3957bc498a510488efc
ssdeep 49152:mDgpyCSMilg2hfzIVp63zJX7PO2SqpQesymTUc+YtHa3UqjgUoqVIm5vBbvh6WR3:aRCjizFJXLO7qpQk
TLSH T1E9C57D1FB75681A1C19AC136CE978686E2F278018F76DB9B2AD62F4E0F777D1086C311
TrID 48.4% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
19.1% (.EXE) Win64 Executable (generic) (6522/11/2)
14.7% (.EXE) Win16 NE executable (generic) (5038/12/1)
5.9% (.EXE) OS/2 Executable (generic) (2029/13)
5.8% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
dhash icon c13030070f3030c1
Reporter Alex_sev
Tags:Downloader exe rugmi

Intelligence


File Origin
# of uploads :
1
# of downloads :
174
Origin country :
AU AU
Vendor Threat Intelligence
No detections
Result
Verdict:
Clean
Maliciousness:
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context anti-debug explorer fingerprint keylogger lolbin masquerade microsoft_visual_cc
Verdict:
Unknown
File Type:
dll x64
First seen:
2026-07-22T12:49:00Z UTC
Last seen:
2026-07-22T18:39:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Trojan.Rugmi
Status:
Malicious
First seen:
2026-07-22 15:28:35 UTC
File Type:
PE+ (Dll)
Extracted files:
196
AV detection:
12 of 36 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Unpacked files
SH256 hash:
da0db01417df6ccfe6df054b08663ed59d377c065740a7a83921c033dbebb29e
MD5 hash:
416b67c98e1b73ab2b04fd2e79f72c12
SHA1 hash:
3b1b4d47c24789fcfab017504e085990dabf4208
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Check_OutputDebugStringA_iat
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments