Ramnit – in-depth analysis
ID: 84dc16a3-d312-51be-beb0-a340044da46c
STIX ID: report--84dc16a3-d312-51be-beb0-a340044da46c
Feed Name: CERT Polska
Threat Score
This report provides a detailed technical analysis of the Ramnit banking trojan, describing its multi-stage packing/unpacking, exploitation of older Windows privilege-escalation CVEs, persistence mechanisms, DGA-driven C2 domain generation and custom RC4/XOR-encrypted C2 protocol, modules enabling cookie theft, Man-in-the-Browser webinjects, and AV-evasion, and supplies IoCs (sample hashes and YARA references) and notes on a new variant observed in spam campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
