Waledac is a botnet which was deployed world wide for illegal operations. One of the 10 largest botnets in the US and a major
distributor of spam globally, Survey puts an estimate that Waledac has infected
hundreds of thousands of computers around the world. Waledac is capable of generating about 1.5 billion spam email
messages a day, and is well-known for its online pharmacy, phony
products, jobs, and penny stock spam scams. Waledac is considered to be the second version of the famous Storm. The worm may arrive on the computer as an attachment to spam email or via a link to a malicious Web site says Symantec. WALEDAC built its communication tactic by using an HTTP-based P2P communication network codenamed HTTP2P and uses a complex variation of known technologies, including RSA and AES encryption using OpenSSL, an eXtensible Markup Language (XML)-based message structure, bzip2 compression, and Base64 encoding says Trend micro. Botnets are deployed in a multitier architecture with the command and control center as the node. The CC is connected to, what is called as repeater nodes or tier of the Waledac botnet and is typically composed of infected
computers with public IP addresses reachable on TCP port
80.
As discussed in the earlier articles, botnets are the modern tools preferred by cyber criminals to carryout
a variety of cyber attacks, build on the distributed power of lakhs of
malware-infected recruited computers spread around the world to generate spam, carryout
denial-of-service attacks on selected websites, including malware deployment and management apart from click
frauds and other criminal activities. Waledac was believed to have the capacity to generate about 1.5 billion spam
emails per day. Waledac infection data is presented at sudosecure.net. The enclosed image courtesy blogs.technet and microsoft.com very clearly indicates the levels of infection present in India.













