here (22.214.171.124 and 126.96.36.199, also Edis) that seem to be used in injection attacks. I can identify the following domains linked to 188.8.131.52:
Injecting some of the same sites as the domains on the above IPs is jstoredirect.net which is currently offline but was hosted on 184.108.40.206 which is also Edis (can you see the pattern yet?) so I would assume that they are linked. In the few days that jstoredirect.net was online it managed to infect over 1500 sites.