Malware: Analysis of the Pushdo Trojan
December 29th, 2007 Posted/Linked by Shanmuga
"SecureWorks anti-malware guru Joe Stewart, a veteran reverse-engineer who spends the majority of his time breaking apart malware samples, said the control server that powers Pushdo is preloaded with about 421 different malware executables—waiting to be delivered to infected Windows machines.
The malware itself uses electronic greeting card lures—spammed to e-mail inboxes—to trick Windows users into launching the executable.
Once the Trojan is executed, Pushdo immediately reports back to an IP address embedded in the code and connects to a server that pretends to be an Apache Web server and listens on TCP port 80." Inside a Modern Malware Distribution System
If you enjoyed this post, make sure you subscribe to my RSS feed!
This entry was posted on Saturday, December 29th, 2007 at 7:00 am and is filed under Malware. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

















