logo

Ramnit – in-depth analysis

ID: 84dc16a3-d312-51be-beb0-a340044da46c

STIX ID: report--84dc16a3-d312-51be-beb0-a340044da46c

Feed Name: CERT Polska

Threat Score
75/100

Date Published: 2017-09-29

Date Updated: 2026-04-19

Author: Michał Praszmo

...
...

This report provides a detailed technical analysis of the Ramnit banking trojan, describing its multi-stage packing/unpacking, exploitation of older Windows privilege-escalation CVEs, persistence mechanisms, DGA-driven C2 domain generation and custom RC4/XOR-encrypted C2 protocol, modules enabling cookie theft, Man-in-the-Browser webinjects, and AV-evasion, and supplies IoCs (sample hashes and YARA references) and notes on a new variant observed in spam campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.