logo

A Brief Gumblar Infrastructure Analysis

ID: a2c0fc4b-2342-54e7-afe0-2120986d56ca

STIX ID: report--a2c0fc4b-2342-54e7-afe0-2120986d56ca

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report describes an active malicious infrastructure associated with the Gumblar botnet: compromised sites served obfuscated JavaScript and malicious PDFs that fetched payloads from fast-flux domains (multiple IPs and short TTLs) and C2 endpoints. Analysis identified shared name servers (hostdnssite.com / OnlineNIC), numerous related domains and IPs, low AV detection on the malicious PDF, and exploitation of PDF vulnerabilities (CVE-2008-2992, CVE-2009-0927), indicating a sustained multi-domain campaign supporting multiple malware families.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.