iTnews
  • Home
  • News
  • Technology
  • Security

Gumblar malware detected on ninemsn

By Liz Tay
Feb 16 2010 4:00PM
Follow google news

Microsoft's ad server dishes up malware links.

An infected banner advertisement on the ninemsn web site has been serving up unsuspecting users to the Gumblar malware exploit.

Gumblar malware detected on ninemsn

The web site, which is jointly owned by PBL Media and Microsoft, intermittently features a compromised in-house banner advertisement for the 75th anniversary of "Women's Weekly" magazine.

According to ninemsn hosting provider Hostworks, the advertisement did not originate on their systems and was served directly from a Microsoft ad server in the United States.

Users are at risk simply by loading the banner, which silently visits another web page that was listed as a Gumblar Zombie URL (site address) in late 2009.

iTnews approached IT security vendor Websense to analyse the advertisement.

Websense told iTnews that the target webpage is currently inactive but still carries "a degree of risk".

A successful attack would install malware that manipulates Google search result pages when viewed by Internet Explorer.

"Victims may see fake results that will redirect them to fradulent sites," Websense's ANZ senior marketing manager David Brophy explained.

The malicious code also attempts to steal FTP (file transfer protocol) logins and hijack any web sites controlled by an infected PC. Similar attacks were blamed for infections of sites hosted by local hosting company AussieHQ last year.

Google has blocked its search engine users from ninemsn's support pages, explaining that the site was listed for suspicious activity three times during the past 90 days.

Google spokesperson Annie Baxter explained:

"Google has set up a number of systems to scour our index for potentially dangerous sites, and we add a label to those that appear to be a vehicle for malware, to protect users who might visit them."

"If a webmaster has indeed removed the malicious content, the warning label will be removed shortly. Our scanners have very high accuracy," she said.

The malware reportedly involved 12 scripting exploits, was distributed by sexsplash.ru and hosted on two domains: jeans-studio.com and condoms.org.ua.

click to view full size image 

Ninemsn is reviewing the site, following a request for comment from iTnews.

"Ninemsn takes security very seriously and has checks and measures in place to ensure that our site and third party sites that are connected to ninemsn are safe for its audience," a spokesperson told iTnews.

"The instance raised yesterday is a rare occurrence and as soon as it is resolved ninemsn will request that the identified pages are cleared of their warning from Google," she said.

Paul Ducklin, who is the Asia Pacific head of technology at Sophos, told iTnews that the security vendor found no evidence of malware hosted on ninemsn.com.au, and agreed that the Google warning could be caused by a "dodgy banner ad".

"Banner ads which link on to malicious sites are, of course, a bad thing," he said.

It raised the question, he said, as to whether entire sites should be blocked if advertisements posted on the site are serving malware.

"This is a tricky question," he said. "Banner ads can appear almost anywhere on most sites which host ads - so in this case, that would mean blocking all of ninemsn.com.au, even though a good web security product ought to block the banner ads."

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Tags:
adexploitgumblarninemsnsecurityserverweekly

Related Articles

  • Marathon OAIC investigation finds Optus breached 51,000 customers' privacy Marathon OAIC investigation finds Optus breached 51,000 customers' privacy
  • US gov shortens cyber fix window to three days US gov shortens cyber fix window to three days
  • Anthropic releases Mythos-class model for public use Anthropic releases Mythos-class model for public use
  • Apple bumps up security in fresh operating system releases Apple bumps up security in fresh operating system releases
Join our WhatsApp Channel

Partner Content

Onel Consulting Strengthens Its White-Glove Services With Strategic COO Appointment
Promoted Content Onel Consulting Strengthens Its White-Glove Services With Strategic COO Appointment
Take control of your connectivity with Telstra’s Adaptive Networks Centre
Partner Content Take control of your connectivity with Telstra’s Adaptive Networks Centre
From test case to control tower: How DXC and ServiceNow are governing enterprise AI at scale
Promoted Content From test case to control tower: How DXC and ServiceNow are governing enterprise AI at scale
You meet the security standard. Shame no one can see it
Promoted Content You meet the security standard. Shame no one can see it

Sponsored Whitepapers

When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
High-volume data sources for AI-driven security analytics
High-volume data sources for AI-driven security analytics
How healthcare organisations can get more value from cloud
How healthcare organisations can get more value from cloud

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Defence says Palantir is "sandboxed" in its environment

Defence says Palantir is "sandboxed" in its environment

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Researchers build self-replicating AI worm with BYO LLM

Researchers build self-replicating AI worm with BYO LLM

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.