A few days after our keylogger post was released on Dec 8th, 2017, the Cloudflare[.]solutions domain was taken down. This was not the end of the malware campaign, however; attackers immediately registered a number of new domains. Since mid-December, msdns[.]online has infected over a thousand websites, though the majority are reinfections from sites that have already been compromised. The attack uses functions and hook names that suggest what their purpose is. An almost identical script is loaded, however, it does not include any obfuscation.”]
Source: https://blog.sucuri.net/2018/01/cloudflare-solutions-keylogger-returns-on-new-domains.html

