Pushdo is a Windows malware family primarily classified as a downloader trojan and closely associated with the Cutwail spam ecosystem. Its core role is to contact embedded command infrastructure, profile the infected host, and retrieve additional malware selected by the operators. Pushdo has long been used as a flexible distribution platform for other criminal payloads, especially Cutwail, and has also been observed in broader affiliate-driven infection chains involving banking trojans, spambots, credential theft malware, and other follow-on payloads.
Pushdo has been distributed through spam campaigns, including fake e-card lures, and has also appeared as a secondary payload delivered by other malware such as Bebloh/Ursnif, Andromeda, and Trik. In some campaigns it was used to add infected systems to a spam botnet while simultaneously downloading further malware. The family is strongly linked to spam operations and has often been discussed alongside Cutwail, to the point that the names are sometimes conflated in operational reporting; however, Pushdo is best understood as the downloader component that commonly installs the Cutwail spambot.
On execution, Pushdo contacts one of several embedded controllers over HTTP, transmits host reconnaissance data, and receives one or more executable payloads. Reported host profiling includes the victim IP address, Windows version, administrator status, filesystem characteristics, execution count, and storage serial information. It also enumerates running processes and reports the presence of selected antivirus and personal firewall products to the controller, indicating an emphasis on operator telemetry and delivery optimization rather than direct security-tool termination. GeoIP-based filtering has been used on the backend to target or exclude infections by country and to tailor payload delivery geographically.
Pushdo has been associated with the delivery of Cutwail, Wigon, Neutrino Bot, and other malware families. In some observed chains, a rootkit component was dropped to conceal Pushdo and subsequently downloaded payloads. The family has also been tied to DGA-related command-and-control behavior in later reporting. Operationally, Pushdo has been linked to large spam botnet infrastructure and historically to hosting environments used by major cybercriminal botnets. It has been used against victims in multiple countries, including campaigns targeting Japan and European financial sectors as part of broader banking-trojan and spam operations.
Overall, Pushdo is a long-running criminal malware platform centered on malware delivery, spam enablement, and post-compromise payload staging on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The Wigon rootkit is dropped onto the system when Pushdo is first executed, and is used to hide the Pushdo process and any subsequent malware that Pushdo might download.
the author has now changed the request to be less fingerprintable. An example of the new request format is: GET /40e800142020202057202d4443574d414c393635393438366c0000003c66000000007600000002 HTTP/1.0
Pushdo will look at the names of all running processes and compare them to the following list of anti-virus and personal firewall process names
Pushdo keeps track of the IP address of the victim, whether or not that person is an administator on the computer, their primary hard drive serial number... whether the filesystem is NTFS... and the Windows OS version as returned by the GetVersionEx API call.
Various IP addresses on port TCP 80 - various domains - POST / -- [Pushdo.s checkin]
When executed, Pushdo reports back to one of several control server IP addresses embedded in it code. The server listens on TCP port 80, and pretends to be an Apache webserver.
Various IP addresses on various TCP ports - various domains - Tor traffic
178.136.218[.]52 port 80 - sillo[.]net - GET /1002.exe 31.135.125[.]26 port 80 - monsteradds[.]at - GET /x64.bin -- [Ursnif module download]
There are two types of seeded DGAs... Dynamically seeded DGAs: Dynamic DGAs use time-based seeds, making it difficult to predict domain names. Security researchers can anticipate domains generated by date-based seeds, enabling proactive blocking. However, unpredictable seeds like Google Trends or FX rates remain a challenge, even with access to the source code.
A Domain Generation Algorithm (DGA) creates numerous domain names, serving as meeting points for malware C&C servers. DGAs help malware evade security measures by generating new, random domains, making it challenging for victims to block or remove them during cyberattacks.
57 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in source links as related background on spam botnet activity.
Named as one of several major botnets with control servers hosted by McColo.
Pushdo is identified from post-infection check-in traffic, with multiple POST requests to various IP addresses and domains over TCP 80, consistent with botnet/loader communications following the malspam-delivered infection.
Malware family observed altering dynamically seeded DGA behavior by generating malicious domains significantly before and after expected dates to evade detection and complicate analysis.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.