[Malware Review] The new member of the Cutwail dinasty

We hope that you have updated your antivirus database signature because malware authors have surely done their work this week. During the past few days there we have seen a lot of new malware popping up on the web; however, today

Once the Trojan is successfully run on the system, it would  create copies of itself in the %SYSTEMROOT%System32 and %HOMEPATH%%USERNAME% folders, called reader_s.exe.  It would also add itself to the list of programs executed at each Windows startup and would deploy additional components to allow a remote attacker access to the infected machine.

The backdoor component in Trojan.Cutwail.Z also allows it to be automatically upgraded by its “master” from a remote location over the Internet. The Cutwail family is extremely prolific and each new variant of the Trojan includes additional features.

The Cutwail family, also known as Pushdo, is responsible for one of the largest active botnets. The total amount of “zombified” systems is impressive – they are used primarily for sending spam messages, but Cutwail is more than that. Other variants of the Trojan would even download third-party malicious files and install them on the already-infected machine.

Given the fact that Cutwail infections are extremely difficult to spot (the only visible symptom is increased Internet activity), you are advised to regularly scan your system with a freshly updated
antimalware solution.

Information in this article is available courtesy of BitDefender virus researcher Marius Vanta.

About the author


Bogdan Botezatu is living his second childhood at Bitdefender as senior e-threat analyst. When he is not documenting sophisticated strains of malware or writing removal tools, he teaches extreme sports such as surfing the web without protection or rodeo with wild Trojan horses. He believes that most things in life can be beat with strong heuristics and that antimalware research is like working for a secret agency: you need to stay focused at all times, but you get all the glory when you catch the bad guys.