Gaudox Botnet v1.1.0.1
Gaudox HTTP Loader
Gaudox is a sophisticated HTTP loader developed entirely from scratch in C/C++ with some Assembly code. It is designed to operate without dependencies such as C-Runtime, .NET Framework, or Java VM. Gaudox has been rigorously tested and is compatible with all Windows versions from Windows XP SP2 to Windows 10 (both 32-bit and 64-bit). The bot is built with highly efficient and stable code, capable of handling thousands of connections simultaneously.
Features
Usermode Rootkit:
- Hides all bot resources and prevents access from the explorer process.
- Does not drop any files to disk; code is embedded in the bot file and injected into the target process from memory.
- Includes self-protection to prevent hooks from being removed by third-party programs or security tools.
- Currently functional on 32-bit systems.
Persistence/Watchdog:
- Prevents removal by bot killers, security tools, or user actions.
- Supports process protection on both 32-bit and 64-bit systems, with maximum compatibility on 32-bit systems.
Traffic Encrypted:
- Obfuscates communication between the bot and the control panel to prevent man-in-the-middle attacks.
Anti-Analysis/Research:
- Prevents analysis by researchers or unauthorized users using various methods:
- Code obfuscation to prevent static analysis.
- Detection of debuggers and avoidance of virtualized environments.
- Additional methods not specified.
Commands