
Image by elmada via FlickrGumblar, the massive iframe injection attack that made and sustained front page security news in early 2009, appears to still be going strong. Only slightly altered in its approach, the ongoing attack is still injecting malicious domains into sites on a fairly large scale, each site having the intention of spreading malware to the end user.
Gumblar domains were previously injected into iframes of otherwise benign sites using stolen FTP credentials. The new domains are likely still injected using stolen credentials but are now using obfuscated scripts to generate a formulaic Russian domain. The obfuscated scripts are appended to javascript files and html files within script tags and create rather lengthy domain names.
The second level domains for these are plentiful. Amazingly, the following list is incomplete and will likely remain so with the constant generation of new redirection domains:
18-plus.ru | bluejackmusic.ru | mozg-testing.ru | thegiftsale.ru |
airseasite.ru | blueseaguide.ru | mozgilla.ru | thelaceweb.ru |
allnewface.ru | brownbagbar.ru | musicboxpro.ru | thelifetag.ru |
allpropro.ru | brynetka.ru | mygreatsale.ru | themobisite.ru |
ampsguide.ru | carswebnet.ru | newhavenparks.ru | thetruehelp.ru |
authentictype.ru | cobalttrueblue.ru | newlifeworld.ru | toplinemarine.ru |
avattop.ru | cometruestar.ru | pastanotherlife.ru | truelifefamily.ru |
b-i-o-v.ru | counterbest.ru | recentmexico.ru | urlnext.ru |
battop.ru | cyberprotech.ru | red-wolf.ru | videosaleonline.ru |
beeeo.ru | easylifedirect.ru | saletradeonline.ru | viewhomesale.ru |
before-this-life.ru | easytabletennis.ru | seasilvercoop.ru | votrelib.ru |
beofree.ru | ezpoh.ru | shoozi.ru | warbest.ru |
bestage.ru | funwebmail.ru | simplehomelink.ru | webdesktopnet.ru |
bestbio.ru | gametopsite.ru | simpleworldhouse.ru | weblessnet.ru |
bestbondsite.ru | genuinecolors.ru | sitesages.ru | webnetenglish.ru |
bestseasilver.ru | genuinehollywood.ru | sugaryhome.ru | webpowerguide.ru |
bi-test.ru | genuinehollywood.ru | superhighest.ru | webworldshop.ru |
biltop.ru | greatsalecenter.ru | superore.ru | whosaleonline.ru |
bio-age.ru | guidebat.ru | superseatoddy.ru | wintersaleonline.ru |
bio-free.ru | halfsite.ru | superseawind.ru | worldhighspeed.ru |
bio-oib.ru | homesaleplus.ru | supertruelife.ru | worldsouth.ru |
bio-tube.ru | homesitedesigns.ru | supertruelife.ru | worldwebworld.ru |
bio-z.ru | huntalong.ru | susance.ru | xboxliveweb.ru |
bionaft.ru | huzzahwebdesign.ru | teenwebdesign.ru | yourasite.ru |
biovoz.ru | inother.ru | theanotherlife.ru | yourauthentic.ru |
biozavr.ru | lagworld.ru | theantimatrix.ru | yourhotelsite.ru |
biozov.ru | maxserviceworld.ru | theatticsale.ru | yourtagheuer.ru |
bitest.ru | mindgameworks.ru | theaworld.ru | yourtruegame.ru |
bluejackin.ru | mingleas.ru | thechocolateweb.ru | yourtruemate.ru |
Though the groupings here are obviously all .ru domains, other researchers indicate countless other domains being used in the same way. Many are using dynamic dns 2lds while others have a similar structure to the domains above, only with .cn TLDs, as was the original gumblar.cn. Others appear to have no theme and are using .cz, .dk, .de, .nl, and several other country code TLDs. The IPs behind these domains are just as widespread and varied. This list is also likely incomplete:
188.138.24.133 | 77.68.44.169 | 89.110.147.181 | 91.121.86.130 |
188.40.118.68 | 78.31.107.49 | 89.149.202.142 | 91.121.88.218 |
188.72.199.24 | 78.41.156.236 | 89.149.244.211 | 91.121.96.181 |
188.72.211.253 | 80.69.74.73 | 91.121.1.99 | 92.48.124.212 |
195.242.98.212 | 82.165.194.22 | 91.121.108.53 | 92.48.78.252 |
212.117.165.149 | 82.165.47.29 | 91.121.112.227 | 94.228.219.11 |
213.186.57.19 | 82.192.88.35 | 91.121.121.6 | 94.23.11.38 |
213.251.164.84 | 82.98.231.25 | 91.121.142.111 | 94.23.14.110 |
213.251.184.114 | 84.16.227.72 | 91.121.166.221 | 94.23.199.154 |
217.160.110.21 | 84.201.9.32 | 91.121.167.41 | 94.23.206.229 |
217.23.5.27 | 85.14.202.210 | 91.121.211.226 | 94.23.211.214 |
62.212.74.148 | 85.184.10.80 | 91.121.24.139 | 94.23.4.164 |
62.250.9.105 | 85.25.152.241 | 91.121.4.99 | 94.23.89.95 |
62.4.85.229 | 85.25.73.243 | 91.121.49.129 | 95.168.170.89 |
62.75.184.40 | 87.106.247.193 | 91.121.7.26 | 95.211.10.130 |
62.75.218.192 | 87.118.90.76 | 91.121.74.84 | 95.211.4.193 |
77.37.19.43 | 89.105.199.130 | 91.121.79.191 |
The full unobfuscated domains look something like this, containing popular domain name snippets in an effort to appear legitimate:
foxsports-com.google.cn.spiegel-de.avattop.ru
yomiuri-co-jp.google.cz.playstation-com.yourtagheuer.ru
theplanet-com.1133.cc.nikkansports-com.bestnewhaven.ru
The full URLs will include file requests similar to:
:8080/ts/in.cgi?pepsi[variable numbers]
:8080/cache/readme.pdf
:8080/cache/flash.swf
:8080/filez/java.html
:8080/filez/Show.class
:8080/filez/win.jpg
The files are designed to exploit vulnerabilities in Acrobat, Flash, and Office, and redirect to the final domain for download of the actual malware, which consistently appears to be Bredolab.
The Bredolab downloader has been tied to Gumblar from the beginning and is still being served by the malicious domains, ultimately serving up rogue AV and information theft end-goal malware. The information theft malware is to grab the FTP credentials to perpetuate the whole cycle. Bredolab has also been found in mass spam campaigns since late last year, attached to emails purporting to represent DHL, UPS, Facebook, Western Union, ISPs fake ecard senders and “potential girlfriends.”
You may have come across one like:
Because of the measures taken to provide safety to our clients, your password has been changed.
You can find your new password in attached document.
Thanks,
The Facebook Team
If many benign sites are hosting the final malware download due to the highjacking mechanism, blocking the redirection attempts would to be the best course of action. It is necessary for the owners of the highjacked sites to clean up the injected redirection domains or malicious files, and the end user to keep their software updated in an effort to negate exploits.
The Pepsi Challenge
Many of the files requested on the redirect domains have something similar to
“:8080/ts/in.cgi?pepsi18”:
18-plus.ru:8080/ts/in.cgi?pepsi18
inother.ru:8080/ts/in.cgi?pepsi18
test-health.ru:8080/ts/in.cgi?pepsi18
I just find this amusing, because one of the Gumblar sites reported here hosted “/rimages/coke.php”. It’s nice that we have a choice of malicious beverage and, while I prefer Coke, it seems Pepsi is the choice of the new “Rumblar” generation of domains.
Matt Sully
Director
Threat Research & Analysis