Skip to content

Botnet

Aldibot

According to Trend Micro Encyclopia: ALDIBOT first appeared in late August 2012 in relevant forums.

Aldibot is a Windows botnet.

Background

Per the Trend Micro Threat Encyclopedia, ALDIBOT surfaced on relevant forums in late August 2012. Its variants are able to extract passwords from Mozilla Firefox, the Pidgin instant messenger, and the jDownloader download manager, then relay the harvested data to their command-and-control (C&C) servers.

The family can mount Distributed Denial of Service (DDoS) attacks across protocols such as HTTP, TCP, UDP, and SYN, and it can carry out flood attacks using Slowloris and at Layer 7.

It can also be configured as a SOCKS proxy, turning the compromised machine into a relay for arbitrary protocols.

In addition, ALDIBOT can download and run arbitrary files and update itself. Variants gather information from infected systems, including the hardware ID (HWID), host name, local IP address, and OS version. Acting as a backdoor, it executes commands issued by a remote attacker, fully compromising the affected host.


Source: Malpedia (Fraunhofer FKIE).