Here is the place where I record some tactics about wargame, systems, and other security issues.


Botnets Timeline

Table 1 presents a timeline of some important bots and some of their main features.

YearNameArchitecture/protocolEstimated sizeCommentsRefs.
1993EggDropCentralized/IRC-Recognized as one of the first popular IRC bots[38]
1998GTbotCentralized-IRC-based bot that uses mIRC scripts[7,21,40]
2002SDbotCentralized/IRC-Uses its own IRC client for better efficiency. Can also use instant-messaging programs and has reached more than 4000 variants [7,20,40,41]
AgobotCentralized/IRC-Robust, modular, flexible and uses a persistent C&C channel [7,19,42]
2003SpybotCentralized-Derived from Agobot with more features[7,16,18]
SinitP2P-Use random scanning to find others peers [41,43]
2004BagleCentralized230,000 [41,44]
ForbotCentralized-Derived from Agobot[45]
PhatbotP2P-Based on the WASTE P2P network[7,41]
2006SpamThruP2P12,000 SpamThru uses a custom P2P protocol to share information with other peers[46]
NugacheP2P160,000 Connect to a predefined list of peers[47,48]
JrbotCentralized-IRC-Based bot with a persistent channel[7]
RxbotCentralized/IRC-IRC-Based bot with a persistent channel[49]
Rustock Centralized/HTTP150,000Bot responsible for 30 billion messages per day, the largest botnet observed in 2010. Was deactivated in 2011.[46,50,51]
2007StormCentralized160,000Was considered one of most powerful botnets, with high processing power, capable of disconnecting entire countries[46,48,52,53]
PeacommP2P160,000Storm variant based on Kademlia network[48,52,53]
PushdoCentralized/HTTP175,000 Encrypts C&C messages and capable of sending 4.500 messages in an hour per bot[50,54]
SrizbiCentralized/HTTP400,000In 2008, it was one of the main botnets responsible for sending spam, approximately 50% of all traffic, approximately 80 to 60 billion messages per day[46,55]
Zeus/ZbotCentralized/HTTP3,6 millionsAllows the creation of new bots, with more than 3000 variants[56–58]
Mega-DP2P500,000Became responsible for 1/3 of all spam traffic, was shut down in 2008[50,59]
2008LethicCentralized260,000Initially discovered in 2008, mainly involved in pharmaceutical and replica spam, was responsible for 8–10% of all the spam sent worldwide.[44]
AsproxCentralized/HTTP15,000In addition to sending spam, it is able to perform SQL Injection on legitimate websites[60]
BobaxCentralized/HTTP/UDP185,000Employs dynamic DNS and an algorithm for generating domains[41,46]
KrakenCentralized400,000A variant of Bobax[61,62]
TorpigCentralized180,000Typically targets bank account, credit-card data and also steals a variety ofother personal information[63]
ConfickerP2P10,5 millionsIn 2009, a coalition of security researchers was created to study Conficker, although some researchers do not consider it a bot/botnet[64,65]
2009WaledacP2P80,000Successor of the Storm bot, was used for sending spam (7000 posts per day), shut off in 2010[50,66,67]
DonbotCentralized/TCP125,000It uses a specific protocol for the C&C server using TCP ports above 2200[50]
2010FestiCentralized/HTTP-Sends an HTTP request message to the C&C, which responds with encrypted templates of spam and/or a list of addresses[44]
2011TDL-4P2P4,5 millionsHas infected up to 4.5 million PCs in 2011, identified as one of the most sophisticated threats today. "It is virtually indestructible", according to security researchers[68]

