
SonicWALL UTM Research team received reports of a new variant of Ramnit malware spreading in the wild.
The Ramnit malware family is known for following capabilities:
The latest variant also incorporates Zeus-like Man-in-the-Browser (MitB) web inject functionality to steal Online Banking credentials. It is highly likely that some modules of the Zeus source code (leaked earlier this year) have been integrated into it.
The sample under investigation performs following activities on the infected system:
The infected executable files will have an additional section containing malicious code:
Subsequent attempts to reboot infected system in Safe Mode will result in Blue Screen of Death (BSoD) crash.
SonicWALL Gateway AntiVirus provides protection against this threat via following signatures:
Share This Article

An Article By
An Article By
Security News
Security News