Cutwail

Malware

⚠️ Overview

Cutwail (also tracked as Pushdo or Pandex) is a long‑lived spam‑delivery botnet first documented in 2007 by security researchers at Arbor Networks and later extensively analyzed by the Shadowserver Foundation. It belongs to the botnet category, functioning primarily as a bulk email sender (spambot) and malware loader. The botnet is believed to be operated by a Russian‑language cybercriminal group that monetizes the infrastructure through pay‑per‑install (PPI) schemes and renting spam capacity to other threat actors.

🔧 Technical Capabilities

Cutwail propagates via drive‑by downloads, exploit kits (e.g., Blackhole, Magnitude), and malicious email attachments that drop the Pushdo loader. The loader installs the Core module, which communicates over HTTP/HTTPS with a tiered Command‑and‑Control (C2) infrastructure using encrypted or obfuscated configuration files (often hosted on compromised WordPress sites). Persistence is achieved through registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. Evasion techniques include polymorphic code generation, User‑Agent randomization, and domain generation algorithms (DGAs) to avoid static blocklists. The bot uses an SMTP engine to relay spam, often spoofing legitimate mail servers with forged headers. MITRE ATT&CK techniques include T1071.001 (Application Layer Protocol: Web Protocols), T1059.003 (Command and Scripting Interpreter: Windows Command Shell), and T1566.001 (Phishing: Spearphishing Attachment).

📜 History & Notable Incidents

Cutwail first emerged in 2007 and by 2010 was responsible for an estimated 45% of the world’s spam traffic, according to Cisco’s 2010 Annual Security Report. A major takedown attempt occurred in 2014 when Dutch police seized two C2 servers in a coordinated operation, but the botnet quickly recovered by migrating to new infrastructure. In 2021, researchers at Sophos reported a resurgence of Cutwail delivering the IcedID banking trojan and Pony stealer via malicious PDF attachments. No high‑profile victims have been publicly named, but the botnet has targeted industries such as finance, healthcare, and e‑commerce. No specific CVEs are directly tied to Cutwail; it relies on third‑party exploit kits (e.g., CVE‑2013‑0422 for Java) for initial infection.

🔍 Detection Indicators

Known file hashes include older samples with MD5 a3b1c2d3e4f5... (exact values vary by variant). Behavioral indicators: outbound SMTP connections on non‑standard ports (25, 587, 465) to dynamic DNS domains or IPs registered to bulletproof hosting providers. Network IOCs include HTTP GET requests for /gate.php or /conf.txt with custom User‑Agent strings such as Mozilla/5.0 (Windows NT 6.1; rv:30.0) Gecko/20100101 Firefox/30.0. Registry keys include HKCUSoftwareMicrosoftWindowsCurrentVersionRunsvchost and mutex names like GlobalPandex. The Shadowserver Foundation publishes live sinkhole data for Cutwail IPs.

☠️ Risk & Impact

The primary damage from Cutwail is the massive volume of spam carrying malware payloads, leading to secondary infections from ransomware (e.g., Locky, Ryuk) and info‑stealers. Financial losses stem from credential theft, fraudulent wire transfers, and the cost of cleaning infected systems. Affected sectors include global financial services, retail, and government agencies; the botnet has been observed sending spam in multiple languages, indicating a wide targeting scope.

🛡️ Mitigation

Defenses include blocking outbound SMTP from non‑mail servers, implementing email filtering with attachment sandboxing, and maintaining up‑to‑date endpoint protection with behavioral detection rules. MITRE ATT&CK ID T1566.001 (Spearphishing Attachment) can be mitigated with user awareness training and email security gateways. Regularly apply OS and software patches to close exploit‑kit delivery vectors. Network monitoring for DGA‑related DNS queries and sinkhole IPs (available from Shadowserver) is recommended.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.