Threat Database Trojans Pushdo Trojan

Pushdo Trojan

By Domesticus in Trojans

Pushdo Trojan is a Trojan that included in a spam botnet. Pushdo Trojan uses a new domain name generation algorithm that is component of its back-up command-and-control mechanism. Pushdo Trojan is responsible for more than one million unique IPs and is growing by huge numbers of unique IPs every day. Pushdo Trojan can avoid both intrusion detection and prevention systems as well as most anti-malware tools by imitating legal connection attempts to benign websites to mislaed signature-based systems. Pushdo Trojan also tracks the security programs and firewall processes on affected computer systems, allowing cybercriminals to create new ways to avoid detection. Pushdo Trojan has a fall-back C&C mechanism that depends on a domain name generation algorithm (DGA). If Pushdo Trojan cannot successfully resolve any of the domains that are hard coded into it, it will start using the DGA in an attempt to connect to the currently active DGA C&C.

Related Posts

Trending

Most Viewed

Loading...