It all started when a website (a website made by our company) had been injected by encrypted javascripts out of no where. There is a simple pattern how this exploit works.
First indication is that a javascript that just pop out of no where in the head section of the webpage and another in the bottom of the body section.
Your site is likely to have a script that fetch infromation from GUMBLAR.CN using a javascript like gumblar.cn/rss?=1, i can't remember the whole pattern but it is somewhat like that.
Another symptom is that the acrobat reader will open when you have visited an infected site.
Try also looking at your image folder. It also does upload itself a image.php in image folders and an include.php, i still don't know what these files do but the image.php is in base encode 64.
Another thing is that all your javascript file had been injected with malicious functions in the bottom of the file.
How the exploit is done..
Though this are only theories, i think that this exploit make use of the vulnerability of the acrobat reader to pass in a worm at your system that gather information about the user (username,passwords,credit card account, etc.), so better patch up those antivirus and spyware to act against this exploit. I suggest users to try

malwarebytes to clean up your system.I'll go back to work now. I'll continue this later for the work around. Thank you for reading.
No comments:
Post a Comment