Gumblar Botnet Resurges


Recommended Posts

<h2></h2>

Gumblar Botnet Resurges

Reactivation of Gumblar.cn domain could have ripple effect, researchers say

Nov 06, 2009 | 04:01 PM

By Tim Wilson

DarkReading Gumblar, a botnet that emerged as one of the Internet's largest earlier this year, is back, researchers said yesterday.

According to researchers at ScanSafe, a new iFrame injection is pointing once again to gumblar.cn -- the malware domain that originally earned Gumblar its name.

"The domain's reactivation occurred less than 24 hours ago, but it has ramifications that could stretch back for months," said ScanSafe researcher Gregg Conklin, in a blog. "Any sites compromised in the May Gumblar attacks that were not yet cleaned up (unfortunately an all-to-common occurrence) could now start becoming vectors of Gumblar infection once again. This is in addition to new compromises pointing to the newly-activated gumblar.cn and the already very active Gumblar compromises which are using compromised websites as malware hosts."

Details at Darkreading - http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=221600700&subSection=Attacks/breaches

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...