Threat Database Trojans W32/Ramnit.E

W32/Ramnit.E

By GoldSparrow in Trojans

Threat Scorecard

Popularity Rank: 21,067
Threat Level: 90 % (High)
Infected Computers: 302
First Seen: September 21, 2011
Last Seen: August 1, 2026
OS(es) Affected: Windows

W32/Ramnit.E is a dangerous Trojan infection that infects Windows executable files and HTML files and tries to enable remote attackers gain access to the targeted PC. W32/Ramnit.E opens a back door by connecting to a remote server. With the help of this back door, remote attackers can instruct the compromised PC to download and execute files. W32/Ramnit.E drops some malicious files and makes other changes in the corrupted system. W32/Ramnit.E creates an invisible default web browser process and injects code to it. W32/Ramnit.E and back door functionality appears in the web browser process context, most likely in an attempt to bypass a firewall. Delete W32/Ramnit.E as quickly as possible.

File System Details

W32/Ramnit.E may create the following file(s):
# File Name Detections
1. %Temp%\a75wef8e0e7.exe
2. %Temp%\02c9c3c35bdx5.exe
3. %Temp%\2010yo.exe
4. %Temp%\alerfa.exe
5. %Temp%\aqfitrlxi2.exe
6. %Temp%\8gmsed-bd.exe
7. %Temp%\al3erfa3.exe
8. %Temp%\1iowieoo.exe
9. %Temp%\aler3fa.exe
10. %Temp%\alerfa322.exe
11. %Temp%\56493.exe
12. %Temp%\ae0965a7157cd.exe
13. %Temp%\17dkf.exe
14. %Temp%\472a10e2ebxd9.exe
15. %Temp%\alerfa2.exe

Registry Details

W32/Ramnit.E may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\Software\Win32/ramnit.gen!A

Analysis Report

General information

Family Name: Trojan.Ramnit.VA
Signature status: No Signature

Known Samples

MD5: f7759cca7403c7281f9b0ba5b342152b
SHA1: c7af7e2251e9750367e9c57f01b57bb6b629cfec
SHA256: 4D4084765BD26E55CF689AD231C1EEAA835E5815C5CA9857771BFBC6EEA33A3D
File Size: 183.12 KB, 183124 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Macromedia, Inc.
File Description Macromedia Flash Player 7.0 r14
File Version 7,0,14,0
Internal Name Macromedia Flash Player 7.0
Legal Copyright Copyright © 1996-2003 Macromedia, Inc.
Legal Trademarks Macromedia Flash Player
Original Filename SAFlashPlayer.exe
Product Name Shockwave Flash
Product Version 7,0,14,0

File Traits

  • 2+ executable sections
  • HighEntropy
  • x86

Block Information

Total Blocks: 35
Potentially Malicious Blocks: 35
Whitelisted Blocks: 0
Unknown Blocks: 0

Visual Map

x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Ramnit.V