- dotastoc.com/442417.js?sid=bWtuamJoX2NvZmZlZS1jODMuZG90YXN0b2MuY29t [212.95.56.102, Germany - Netdirekt E.k]
- mknjbhyju.exxl.pl/coffee-c83/xalei.html [209.51.196.244, Ohio - XLHost.com Inc]
- mknjbh_coffee-c83.dotastoc.com/index.html ?Ref=http%3A%2F%2Fwww.google.co.uk %2Fsearch%3Fhl%3Den%26q%3D[redacted]%26btnG%3DSearch%26meta%3D
- myth-busters.cn/go.php?id=2009-01&key=cd19f5036&p=1 [94.102.48.29, Netherlands - Ecatel]
- 09computerquickscan.com [multihomed at 78.46.118.1, 78.46.201.89, 78.46.251.41, 88.198.81.153, 88.198.120.177, Germany Hetzner Online AG]
Lots of suspect IP addresses there, 212.95.56.102 is the first step and also hosts these following domains that also look suspect:
- Anidmenonpderche.com
- Dotastoc.com
- Ewyuewssf.com
- Fishbiss.com
- Iggiksc.com
- Lur2cont.com
- Niuk.ru
- Pornokogu.com
- Uewiosdasda.com
Update: answers.com appear to have tracked down and removed the ad, although some other sites have been hit by a very similar attack.
No comments:
Post a Comment