Pushdo is a Windows malware family primarily known as a downloader trojan that has long been associated with the Cutwail spam ecosystem. Its core role is to contact embedded command infrastructure, profile the infected host, and retrieve additional malware for execution. Pushdo has been used both as a standalone distribution platform and as an intermediate payload in larger criminal infection chains, frequently leading to installation of the Cutwail spambot and, in some campaigns, other malware families.
Pushdo has historically been distributed through spam campaigns, including fake e-card lures and later malspam waves using attachment-based social engineering. It has also appeared as a follow-on payload delivered by other malware such as Bebloh and Ursnif, and has been observed in broader botnet delivery ecosystems including Trik. In Japanese-targeted banking-trojan campaigns, Bebloh/Shiotob was observed delivering Pushdo alongside Ursnif, after which infected systems could participate in spam operations.
On execution, Pushdo reports to one of several embedded controllers over HTTP, submits host telemetry, and requests payloads selected by the operator. Reported host data has included victim IP address, Windows version, administrator status, filesystem characteristics, execution count, and storage serial information. Pushdo also enumerates running processes and reports the presence of selected antivirus and personal firewall products to its controller, supporting operator reconnaissance and defense-evasion tuning rather than direct termination of security tools. Historical analysis also linked Pushdo deployments with the Wigon rootkit, which was used to conceal Pushdo and subsequently downloaded malware.
Pushdo is closely tied to Cutwail: it has repeatedly been described as the installer or downloader component that adds infected systems to the Cutwail spam botnet. Cutwail itself became one of the largest spam botnets of its era, and Pushdo served as an important feeder mechanism for that infrastructure. Researchers have also observed Pushdo delivering or being delivered alongside other malware in multi-stage criminal campaigns, underscoring its role as a flexible malware distribution service within affiliate-driven ecosystems.
The malware has also been associated with domain-generation behavior in some reporting, indicating efforts to improve command-and-control resilience and complicate disruption. Operationally, Pushdo has been linked to long-running spam and malware-delivery activity and to infrastructure historically associated with major botnet operators. Its enduring significance lies in its function as a modular downloader that bridges initial compromise and large-scale secondary payload deployment, especially spam bot enrollment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The Wigon rootkit is dropped onto the system when Pushdo is first executed, and is used to hide the Pushdo process and any subsequent malware that Pushdo might download.
crypters, which are also referred to as loaders or packers, are applications designed to encrypt and obfuscate malware to evade detection by antivirus (AV) scanners and hinder analysis.
Pushdo will look at the names of all running processes and compare them to the following list of anti-virus and personal firewall process names
Pushdo keeps track of the IP address of the victim, whether or not that person is an administator on the computer, their primary hard drive serial number... whether the filesystem is NTFS... and the Windows OS version as returned by the GetVersionEx API call.
Various IP addresses on port TCP 80 - various domains - POST / -- [Pushdo.s checkin]
When executed, Pushdo reports back to one of several control server IP addresses embedded in it code. The server listens on TCP port 80, and pretends to be an Apache webserver.
Various IP addresses on various TCP ports - various domains - Tor traffic
178.136.218[.]52 port 80 - sillo[.]net - GET /1002.exe 31.135.125[.]26 port 80 - monsteradds[.]at - GET /x64.bin -- [Ursnif module download]
There are two types of seeded DGAs... Dynamically seeded DGAs: Dynamic DGAs use time-based seeds, making it difficult to predict domain names. Security researchers can anticipate domains generated by date-based seeds, enabling proactive blocking. However, unpredictable seeds like Google Trends or FX rates remain a challenge, even with access to the source code.
67 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in source links as related background on spam botnet activity.
Named as one of several major botnets with control servers hosted by McColo.
Pushdo is identified from post-infection check-in traffic, with multiple POST requests to various IP addresses and domains over TCP 80, consistent with botnet/loader communications following the malspam-delivered infection.
Malware family observed altering dynamically seeded DGA behavior by generating malicious domains significantly before and after expected dates to evade detection and complicate analysis.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.