is primarily a spam bot, one of the few spam botnets whose growth was
not hampered by the McColo shutdown earlier this year. As a matter of fact, the sudden
shut down of big spammers like Srizbi and Rustock helped Donbot climb the
spam botnet rankings. In this article I am going discuss different aspects of Donbot, first as a malware and then in the
later half I will try to shed some light on its command and control architecture.
Lets start with a particular donbot sample (273a07dccdfff421bfde652912f02e32). Like its peer botnets (Ozdok, Xarvester etc), Donbot is also a template based spam bot. Everything from the subject line to the mailing list, the message body, and the User Agents to be used in the SMTP headers are retrieved from the CnC server.


