Here's a nasty bunch of sites being used in injection attacks, all hosted on 5.9.188.54:
nfexfkloawuqlaahsyqrxo.qlvyeviexqzrukyo.waw.pl
nqvzrpyoossmr.qlvyeviexqzrukyo.waw.pl
xfynhovgofzsqueuuprplvv.qlvyeviexqzrukyo.waw.pl
lgrfuqfwz.qlvyeviexqzrukyo.waw.pl
zlqfrypzqyubsedrzugeaf.urblvhnfxzrozzlz.waw.pl
qxggipnnfmnihkic.ru
mvuvchtcxxibeubd.ru
5.9.188.54 is a Hetzner IP address (no surprise there) suballocated to:
inetnum: 5.9.188.32 - 5.9.188.63
netname: LLC-CYBERTECH
descr: LLC "CyberTech"
country: DE
admin-c: AG6373-RIPE
tech-c: AG6373-RIPE
status: ASSIGNED PA
mnt-by: HOS-GUN
source: RIPE # Filtered
person: Alexey Galaev
address: LLC "CyberTech"
address: Grizodubova street 4 , build.2
address: 125252 Moscow
address: RUSSIAN FEDERATION
phone: +660812703752
nic-hdl: AG6373-RIPE
remarks: -------------------------
remarks: Vpsville.ru working 24x7
remarks: -------------------------
remarks: For abuse use admin@vpsville.ru
abuse-mailbox: admin@vpsville.ru
mnt-by: HOS-GUN
source: RIPE # Filtered
You might want to block the whole 5.9.188.32/27 range.. you should certainly block 5.9.188.54 if you can.
No comments:
Post a Comment