My list of Gumblar zombie URLs that I originally posted and updated in the Revenge of Gumblar Zombies article, have already reached the size of 600+ items, which makes the web page too heavy.
I decided to move this list to a separate page to make the original post less cluttered. At the same time the list should remain searchable via major search engines and webmasters of compromised sites will be able to find this page that contains a direct link to the post with Gumblar infection details and removal instructions.
Gumblar infection is pretty sophisticated and removing the malicious code is usually not enough to completely clean up your site. If this page contains a URL that was a part of the suspicious code injected into your sites’ web pages and .js files, make sure to read the following post.
604 items. Last update: March 15, 2010
If you find any other Gumblar URLs, don’t hesitate to post them in comments.
Related posts:
[...] This post was mentioned on Twitter by Denis, Gumblar. Gumblar said: Blog: List of Gumblar Zombie URLs | Unmask Parasites. Blog. http://bit.ly/4JH58v [...]
script src=http:// lou-ferrigno .info/ .smileys/sinbad.php >
script src=http: // granpiano.com .mx / flash/inicio.php >’);
script src=http: // 209.85.115 .10 / master_doc/i_js_style.php >’);
script src=http: // ar-global .com / images/register_with_us.php >’);
script src=http: // hazarastudents .com / forum/farsi_comments_receiver.php >’);
script src=http: // uznaipervim .ru / wp-content/wp-app.php >’);
script src=http: // connis-guzzi-shop .de / Master/20AL.php >’);
script src=http: // yalsosbor .ru / _fpclass/leaving.php >’);
script src=http: // nextv .co.jp / _archive/styles.php >’);
script src=http: // bar-kingsleddogadventures .ca / www_upload/whoweare.php >’);
script src=http: // nelliepratherfoundation .org / updates/temp.php >’);
script src=http:// soi-japan .com / cache/misc.php >’);
script src=http:// 7-eight .com / misc/new7logo1.php >’);
script src=http:// maaandhra .com / scripts/history.php >’);
script src=http:// sahrudayarajagiri .org / cgi-bin/photogallery.php >
script src=http:// red-devil-sport-club.gymdb .com / js/gmanage_gallery.php >’);
script src=http:// melstra-techniek .nl / images/contact.php >’);
script src=http:// miriquidi-coons .de / neu/ueberuns.php >’);
script src=http:// assurline .fr / cgi-bin/Thelem-assurances.php >’);
script src=http:// kardeskalemler .com / haziran2008/iletisimtesekkur.php >’);
script src=http:// hotelsathyam .co.in / _vti_bin/pudukkotai-sathyam-trichy-000999.php >’);
script src=http:// scho-seiler .net / extraschmuck/www.scho-seiler.net_sitemap.php >’);
script src=http:// fashiontouch .net / stratejet/database.php >’);
script src=http:// ragero .ru / rose/indexv.php >’);
script src=http:// pixforfree .net / upload.php >’);
script src=http:// sonyericsson.lua .pl / files/album_upload.php >’);
script src=http:// keman .org/ ehemure /default.php >’);
script src=http:// jazzlynx .net / PhotoAlbums/artistMouseover.php >
script src=http:// squirrelbird .net / images/button6.php >’);
script src=http:// proanalytics .cn / stats.txt>
mustafakutluay.k12. tr/ index.php
flashback.dp. ua/ enter/enter.php
delhicakesngifts. com/ the-cake-shop/fckeditor_php4.php
bip.centrumpluc.com. pl/ temp/dtree.php
eme.com. co/ images/postinfo.php
monsterbux.ax3. net/ admin/menu_top.php
beeaar. net/ images/gifimg.php
gentomdeerhounds .co. uk/ images/c2vg/stage-stars.php
Here is one more :-(
script src=hxxp://yellowpage-kr .com/ files/manager.php
still have that bugger on my site loading this
“Waiting for istockphoto-com.zylom.com.time-com.yoursuperpool.ru…”
SUUUCKS!!!