Pushdo Trojan Infects 11,000 Systems In 24 Hours
An anonymous reader writes Bitdefender has discovered that a new variant of the Trojan component, Pushdo, has emerged. 77 machines have been infected in the UK via the botnet in the past 24 hours, with more than 11,000 infections reported worldwide in the same period. The countries most affected so far by the Pushdo variant are India, Vietnam and Turkey. Since Pushdo has resurfaced, the public and private keys used to protect the communication between the bots and the Command and Control Servers have been changed, but the communication protocol remains the same.
What operating system does this software run on?
The way the article describes Pushdo, it sounds a lot like ZeuS - they use practically the same methods of operation (DGA to generate random domain names, fast-flux to stop anyone shutting down the C&C servers) and it seems that like ZeuS, Pushdo started from an initial codebase and was changed multiple times after being shut down.
Just shutdown No-IP servers. That should fix it.
"Somebody has to do something. It's just incredibly pathetic it has to be us."
--- Jerry Garcia
North Korea is least affected, due to their "Don't let anyone have computers, well they don't have electricity anyway" security policy.
Gamingmuseum.com: Give your 3D accelerator a rest.