December 4, 2009, 10:53AM

Gumblar Continues to Spread, Thousands of Sites Infected

Months after it first appeared on the scene, the Gumblar malware continues to infect thousands of servers across the Internet and is closing in on nearly 80,000 servers pointing to the hosts that are serving the malware.

In just the last month, the number of servers redirecting users to the Gumblar malware hosts has increased in a big way. In a blog post on Viruslist, Kaspersky Lab malware analyst Michael Molsner gives the details:

We've now analyzed more than 600 MB of collected data related to the recent resurrection of the Gumblar threat. Overall, we've identified 2000+ Infectors (computers hosting the malicious *.php files and payload) and 76100+ 'Redirectors' (computers with links leading back to the malicious sites). Most Infectors are also part of the group of Redirectors, they serve one *.php file and additionally contain the link to another Infector in their own entry page.

Gumblar is a serious problem right now, but it's important to note that it's just one of several similar malware threats right now, including Zeus and Clampi.


Shorten URL: Click to copy short URL. Click to copy to clipboard or post to Twitter

Comments

If only Anti Virus Vendors could actually name the malware correctly that would be going somewhere.

My Tips: Standard Naming, More Malware information, even on "Zoo Malware".

Post new comment

The content of this field is kept private and will not be shown publicly.

Kaspersky Lab Channel and Alliance Partners

 

 

Copyright © 2010 threatpost.com | Terms of Service | Privacy