A Brief Gumblar Infrastructure Analysis
ID: a2c0fc4b-2342-54e7-afe0-2120986d56ca
STIX ID: report--a2c0fc4b-2342-54e7-afe0-2120986d56ca
Feed Name: Zscaler Security Research Blog
This report describes an active malicious infrastructure associated with the Gumblar botnet: compromised sites served obfuscated JavaScript and malicious PDFs that fetched payloads from fast-flux domains (multiple IPs and short TTLs) and C2 endpoints. Analysis identified shared name servers (hostdnssite.com / OnlineNIC), numerous related domains and IPs, low AV detection on the malicious PDF, and exploitation of PDF vulnerabilities (CVE-2008-2992, CVE-2009-0927), indicating a sustained multi-domain campaign supporting multiple malware families.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
