search slide
search slide
pages bottom
Gumblar virus attack

is a that first appeared in 2009. It has been identified as one of the most malicious viruses in existence. It is characterized by re-directing user’s Google searches and is suspecting to come from flash and PDF files.

Personal

Visitors to an infected site will be redirected to an alternative site containing further Malware, which was once .cn, but has now switched to a variety of domains. The site sends the visitor an infected PDF that is opened by the visitor’s browser or Acrobat Reader. The PDF will then exploit a known in Acrobat to gain access to the user’s computer.

The virus will find clients such as FileZilla and Dreamweaver and download the clients’ stored . It also enabled promiscuous mode on the card, allowing it to sniff local traffic for details. It is one of the first viruses to incorporate an automated sniffer.

Servers

Using obtained from site admins, the host site will access a via and infect the . It will download large portions of the and inject malicious code into the ’s files before uploading the files back onto the . The code is inserted into any file that contains a tag, such as HTML, PHP, , ASP and ASPx files. The inserted PHP code contains base64-encoded that will infect that execute the code. In addition, some pages may have inline frames inserted into them. The virus will also modify .htacess and HOSTS files, and create images.php files in directories named ‘images’. The infection is not a -wide exploit. It will only infect sites on the that it has to.

Technorati Tags: , , , , , , , , , , ,

Leave a Reply

You must be logged in to post a comment.