These seem to be the currently active domains used in the AsproxSQL Injection attack. Registrar of choice at the moment is Vivids Media GMBH (if they really exist) via Directi Internet Solutions (publicdomainregistry.com).
adupd.mobi
adwste.mobi
bnrupdate.mobi
cntrl62.com
config73.com
cont67.com
csl24.com
debug73.com
default37.com
get49.net
pid72.com
pid76.net
web923.com
Best advice to to block access to these sites and check your logs.
No comments:
Post a Comment