Resolved predhost.in to 198.199.109.163
Server: Predhost.in
Gate file: /sm/index.php
Logging into
hxxp://predhost.in/sm/guest.php
with guest:guest works. Anyone want to test if the sqli got fixed?
Hosting infos: http://whois.domaintools.com/198.199.109.163
Related md5s (Search on malwr.com to download samples)
Smokeloader: 4c438005e17b968813f3df1fb2e15f4a