Malware Signature

The following table shows a list of malware samples and the corresponding botnet C&C (ip:port) associated with Worm.Ramnit

Database Entry


Malware:Worm.Ramnit
First seen:2015-12-17 19:38:15 UTC
Last seen:2023-01-31 09:20:36 UTC

Malware Samples


The table below documents all malware samples associated with this malware family.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2023-01-31 09:20:36a7c67beb5d904f6c1c8f2accdb4893faVirustotal results 58 / 69 (84.06%) Worm.Ramnit38.45.124.106:8848
2016-06-11 12:14:38080f19520d6a7f651525eb690204489bn/aWorm.Ramnit24.158.5.82:443
2016-06-11 12:14:38080f19520d6a7f651525eb690204489bn/aWorm.Ramnit24.158.5.82:443
2016-06-11 08:22:51702d585b299f65dc830e0ae5ca1c168dn/aWorm.Ramnit178.183.120.96:443
2016-06-11 08:22:51702d585b299f65dc830e0ae5ca1c168dn/aWorm.Ramnit178.183.120.96:443
2015-12-20 19:18:23b2d2d142bd7177a1faff6f8f6a0b38a1Virustotal results 49/53 (92.45%) Worm.Ramnit204.95.99.204:443
2015-12-20 19:18:23b2d2d142bd7177a1faff6f8f6a0b38a1Virustotal results 49/53 (92.45%) Worm.Ramnit204.95.99.204:443
2015-12-18 12:40:444d13ed977df4cec195ba5176e10f848aVirustotal results 48/53 (90.57%) Worm.Ramnit204.95.99.205:443
2015-12-18 12:40:444d13ed977df4cec195ba5176e10f848aVirustotal results 48/53 (90.57%) Worm.Ramnit204.95.99.205:443
2015-12-18 09:59:1075c29ba0a2c57c36d912b85c952c0681Virustotal results 49/54 (90.74%) Worm.Ramnit204.95.99.204:443
2015-12-18 09:59:1075c29ba0a2c57c36d912b85c952c0681Virustotal results 49/54 (90.74%) Worm.Ramnit204.95.99.204:443
2015-12-17 19:38:15dee2e7cc6c86aec6271c31ab9c88a1f5Virustotal results 49/54 (90.74%) Worm.Ramnit204.95.99.204:443
2015-12-17 19:38:15dee2e7cc6c86aec6271c31ab9c88a1f5Virustotal results 49/54 (90.74%) Worm.Ramnit204.95.99.204:443