Malware Help. Org | Blog

PC security, privacy, anonymity and anti-malware Resource


Malware: Analysis of the Pushdo Trojan

December 29th, 2007 Posted/Linked by Shanmuga

mho0006.jpg"SecureWorks anti-malware guru Joe Stewart, a veteran reverse-engineer who spends the majority of his time breaking apart malware samples, said the control server that powers Pushdo is preloaded with about 421 different malware executables—waiting to be delivered to infected Windows machines.

The malware itself uses electronic greeting card lures—spammed to e-mail inboxes—to trick Windows users into launching the executable.

Once the Trojan is executed, Pushdo immediately reports back to an IP address embedded in the code and connects to a server that pretends to be an Apache Web server and listens on TCP port 80." Inside a Modern Malware Distribution System

If you enjoyed this post, make sure you subscribe to my RSS feed!

Share or Bookmark this Post:
  • E-mail this story to a friend!
  • Facebook
  • Digg
  • StumbleUpon
  • Reddit
  • Google
  • Live
  • Technorati
  • del.icio.us
  • YahooMyWeb
  • Furl
  • Ma.gnolia
  • TwitThis
  • Propeller
  • Mixx
  • SphereIt


This entry was posted on Saturday, December 29th, 2007 at 7:00 am and is filed under Malware. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.


Possibly related


Leave a Reply

Tags


More News, Articles from elsewhere