[Infowarrior] - Analysis of a Modern Malware Distribution System

Richard Forno rforno at infowarrior.org
Mon Dec 24 16:04:53 UTC 2007


Pushdo - Analysis of a Modern Malware Distribution System

    * URL: http://www.secureworks.com/research/threats/pushdo
    * Date: December 17, 2007
    * Author: Joe Stewart

Recently, Sophos published a blog entry detailing the trouble they are
having with the Pushdo trojan, a fairly new and prolific threat being
circulated in fake "E-card" emails. From their description, it is clear that
the author(s) of Pushdo are making a concerted effort to spread their
malware far and wide. But what exactly is Pushdo, and how does it work? We
decided to take a closer look at this malware family.

Pushdo is usually classified as a "downloader" trojan - meaning its true
purpose is to download and install additional malicious software. There are
dozens of downloader trojan families out there, but Pushdo is actually more
sophisticated than most, but that sophistication lies in the Pushdo control
server rather than the trojan.


< - >

http://www.secureworks.com/research/threats/pushdo/




More information about the Infowarrior mailing list