Author Topic: Resurrected gumblar botnet active like never before!  (Read 1687 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Resurrected gumblar botnet active like never before!
« on: December 04, 2009, 03:12:10 PM »
Hi malware fighters,

Gumblar botnet active again

The resurrected Gumblar-botnet now functions with over 78.000 infected machines as never before, within a month the number of infestations tripled. AV-vendow Kaspersky Lab analyzed over 600MB of data and discovered over 2000 "infectors", machines that are hosting malicious php-files and the malicious 'payloads' gumblar virus uses. Gumblar uses stolen FTP-data to place malcode files unto websites.

Furthermore over 76.000 'redirectors' were found, machines with links to redirect to malicious sites. In the Netherlands there are 15 infectors and over 1900 redirectors active. "When you compare statistics to those of one month ago, you could easily establish how the threat is spreading and where it is heading", according to Kaspersky Lab's Michael. Next to the fact that the number of infections increases, the number of countries with infections rose,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

YoKenny

  • Guest
Re: Resurrected gumblar botnet active like never before!
« Reply #1 on: December 04, 2009, 03:28:12 PM »