This week, we started detecting new modifications of the scripts injected by this attack. The general idea of the malware is the same, but the domain name and obfuscation has changed slightly. The saskmade[.]net domain was registered just a week ago on Oct 19, 2018, specifically for this campaign. It is currently hosted on a server with the IP 185212212212131162162.162. The redirect chain ends on some page (e.g. hxxps://bnewsb[.]com) with aggregated ads posing as news”]
Source: https://blog.sucuri.net/2018/10/saskmade-net-redirects.html

