Threat Database Viruses Win32:Virus/Ramnit.AF

Win32:Virus/Ramnit.AF

By Sumo3000 in Viruses

Threat Scorecard

Popularity Rank: 21,027
Threat Level: 80 % (High)
Infected Computers: 1,422
First Seen: December 5, 2011
Last Seen: August 22, 2026
OS(es) Affected: Windows

Win32:Virus/Ramnit.AF is a hazardous computer virus that uses rootkit technology to access a targeted computer system without being uninstalled by anti-malware software. Win32:Virus/Ramnit.AF allows remote attackers to gain access and control over the compromised PC. Win32:Virus/Ramnit.AF may be used by rogue security applications to infect the computer and swindles PC users out of their money. Win32:Virus/Ramnit.AF can download and install additional malware threats to the affected computer. Win32:Virus/Ramnit.AF can block security programs on the corrupted machine. It is recommended to remove Win32:Virus/Ramnit.AF immediately after detection.

Analysis Report

General information

Family Name: Trojan.Bitcoinminer.FDB
Signature status: No Signature

Known Samples

MD5: b8a84adac8d31dfa4cf29307ccee6227
SHA1: d785832065b06f65c2f316d3ac91f28c1ca8a28a
SHA256: 84558B46867B1DB32B23A158DC1339FFBBA33458EFB25E85BC8FA958B25CFABE
File Size: 1.60 MB, 1599084 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • .vmp0
  • 2+ executable sections
  • HighEntropy
  • No Version Info
  • x64