I mentioned some days ago that there seems to be a parallel SQL injection attack to Asprox with all the hallmarks of being Chinese. Over the past day or so, mo98g.cn has appeared on some infected sites (often alongside Asprox) making a call to mo98g.cn/q.js which is hosted on 222.122.128.5 in South Korea.
The back end seems not to be working at present, so maybe the server has been cleaned up. In any case, this is another domain to block or check your logs for.
No comments:
Post a Comment