FILEMembers
FILE

2008-Vintage Pushdo Downloader Resurfaces With Named C2 Signatures

An eighteen-year-old Win32 downloader flagged by 59 of 76 AV engines carries named Snort and ET signatures confirming Pushdo botnet check-in traffic, even as its lone sandbox run returned an inconclusive verdict. The record's actor attribution to a ransomware operator doesn't match the observed spam-downloader behaviour.

Jul 8, 2026, 10:45 (UTC+9)Last seenJul 8, 2026Severity100ByCTX TeamActorPinchy SpiderSodinokibiIOC29RegionsDE

A Win32 downloader carrying an eighteen-year-old compile timestamp surfaced in detection feeds eleven days ago, and once it started talking, it said something specific: named Snort and Emerging Threats signatures identify its outbound traffic as Pushdo botnet check-in behaviour, not generic malware noise. The binary's PE header reads 2008-09-12; its first appearance in detection telemetry is 2026-06-27 — a gap of roughly eighteen years that is consistent with a decade-old Cutwail/Pushdo builder…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence