Researchers documented Ramnit as a Zeus-like banking trojan, worm, and file infector that was distributed through the Blackhole exploit kit and equipped with rootkit capabilities, spam-sending functions, and aggressive persistence. Analysis of multiple samples showed the malware dropping several components, installing a fake "Mi cor soft Windows Service", injecting into svchost.exe, and in some cases infecting executable and HTML files by appending malicious code. One sample was tied more closely to botnet and spam activity, while another emphasized file infection, a combination that made reliable cleanup difficult and led researchers to recommend full system rebuilds rather than partial remediation.
The reporting also showed that Ramnit used resilient command-and-control methods, including communications over port 443 with a custom encoded protocol rather than SSL and large fallback domain lists to find active servers. Separate reverse engineering of the malware's domain generation algorithm (DGA) found that Ramnit generated variable-length .com domains using a simple linear congruential generator and multiple observed 32-bit seeds, including 0xEF214BBF, 0x28488EEA, 0x4BFCBC6A, and 0x79159C10. Investigators linked parts of the infrastructure to pharma spam operations, noted overlap with previously documented Ramnit C2 servers, and reported that while one command server had been sinkholed, other infrastructure remained active.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
A technical analysis reverse engineered Ramnit's domain generation algorithm, showing it used a linear congruential generator to create .com domains with 8 to 19 character second-level names. The report also published Python code to reproduce the DGA and identified multiple seeds observed in the wild.
Reverse-engineering reported that Ramnit DGA seed 0x79159C10 was first used in April 2014. Samples using this seed were later observed on Malwr, VirusTotal, and in Sophos detections.
Reverse-engineering indicated that Ramnit DGA seed 0x4BFCBC6A probably first appeared in early 2013. Sophos associated several Ramnit variants, including Ramnit-B and Ramnit-FS, with this seed.
Later reverse-engineering reported that Ramnit samples associated with DGA seed 0x28488EEA were first used in March 2012. Samples tied to this seed were seen on Malwr, SonicWall, Sophos, and Lavasoft.
Analysis documented Ramnit samples being distributed through the Blackhole exploit kit rather than Facebook-themed lures. The report detailed persistence, rootkit behavior, spam activity, file infection, and command-and-control infrastructure, noting one C2 had been sinkholed while another remained active.
A VirusTotal submission for the infected file VirusTotalUpload2.exe showed 37 of 43 antivirus engines detecting it. The sample was identified with MD5 25f6ee42d37e3f2f7dbe795e836d52e2.
Ramnit was first seen as a Zeus-like malware family used to spy on infected users. Later analysis described it as combining trojan, worm, file-infector, and rootkit capabilities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.