ThreatFox IOC Database

You are viewing the ThreatFox database entry for sha256_hash 889e73e46d757542ddcd03300909b596cba48c149f97e28adeef916ee917dc16.

Database Entry


IOC ID:1775026
IOC: 889e73e46d757542ddcd03300909b596cba48c149f97e28adeef916ee917dc16
IOC Type :sha256_hash
Threat Type :payload
Malware: Rugmi
Malware alias:Penguish
Confidence Level : Confidence level is high (100%)
Is compromised? : False
First seen:2026-03-24 19:58:07 UTC
Last seen:never
UUID:ba39b269-27a0-11f1-9af6-42010aa4000a
Reporter Lenny_3BO
Reward 5 credits from ThreatFox
Tags:ClickFix DLL-sideloading InstallShield msi

Avatar
Lenny_3BO
Rugmi MSI installer (Colugo v3.29). InstallShield 2020. Extracts 10 files then intentionally fails (Error 2728). Trojanized WebView2Loader.dll decrypts router-layer.lock. 5/76 VT.