Tuesday, 26 November 2013
Something evil on 46.19.139.236
Posted on 08:29 by Unknown
46.19.139.236 (Private Layer Inc, Switzerland) seems to be serving up some sort of Java exploit kit via injection attacks which is utilising hijacked legitimate domains, but the domains in use seem to rotate pretty quickly and I haven't got a copy of the payload, but VirusTotal has some examples. These are the domains that I can find running from this IP:
ihavefound.boostprep.com
Subscribe to:
Post Comments (Atom)
0 comments:
Post a Comment