October 20, 2009, 10:00AM

Gumblar: Back and Better than Ever

One of the great things about the Internet is that things can live on indefinitely. Unfortunately, that long life expectancy applies to malware, as well.

The Gumblar botnet, which has been active for several months now but had quieted down somewhat, is making a comeback in a big way. IBM ISS's X-Force research team has been following Gumblar's activity and has found that the malware's creators have refined its capabilities and added some new exploits to increase its effectiveness.

 

Gumblar activityGumblar activity

Gumblar's main infection method has been to compromise legitimate Web sites and then serve malware to unsuspecting visitors to those sites. That attack vector hasn't changed; it's simply become more efficient, the X-Force found.

So what’s different this time around?  In previous versions of Gumblar, the malicious scripts and payload were hosted on a remote server.  Iframe code was injected into the compromised website, and it redirected visitors to their rogue server (gumblar.cn).  This time around, they are placing the malicious scripts and payload directly on the compromised host, which gives them a decentralized and redundant attack vector, spread across thousands of legitimate websites around the world.

The uploaded scripts are placed carefully to match existing file structures currently on the websites.  Heavy obfuscation is used in an attempt to evade some existing security measures.

Gumblar is using a different set of exploits in this iteration, as well. The malware is relying on a combination of PDF, Adobe Reader and Microsoft Office Web Components exploits to attack the machines of visitors who stumble on the compromised Web sites. Gumblar also still seems to be using its old, reliable method of searching infected machines for any FTP credentials they might have stored and then using those to compromise more Web sites, leading to an endless circle of infections and site compromises.

Shorten URL: Click to copy short URL. Click to copy to clipboard or post to Twitter

Comments

I could dispute a lot about the history of essays writing, but I would recognize that the paper writing service can write the superb online term paper always. Is that right?
It will take a long time to improve a writing skillfulness. But oftentimes, different persons have no time. If you are willing to save your time and money and have the superior quality essay buying paper, you should search for the trustworthy research papers writing service and buy papers right there. After this, your A+ grade is gained.

Post new comment

The content of this field is kept private and will not be shown publicly.

Kaspersky Lab Channel and Alliance Partners

 

 

Copyright © 2010 threatpost.com | Terms of Service | Privacy