Targeted by the last MSRT from Microsoft, Ramdo is an evolution of Redyms. Being deployed in Affiliate mode you may have seen it in different Exploit Kit (here : mainly in Magnitude and Fiesta but also in Himan, Styx, FlashPack and the now disappeared Neutrino).
You'll see a nice analysis in the MSRT April 2014 – Ramdo post explaining for instance the calculation of the following domain and the 404
more here......http://malware.dontneedcoffee.com/2014/04/communizm-ramdoredyms-affiliate.html
You'll see a nice analysis in the MSRT April 2014 – Ramdo post explaining for instance the calculation of the following domain and the 404
more here......http://malware.dontneedcoffee.com/2014/04/communizm-ramdoredyms-affiliate.html