On 2017-03-30 06:28:52 UTC, suspect-networks.io received the following abuse complaint from dspruell on the IP address 89.45.67.178.


89.45.67.178
dspruell
2017-03-30 06:28:52
other
Fast Serv Inc. d.b.a. QHoster.com hosting malicious redirectors in 89.45.67.0/24 related to "Good Man" injections pushing traffic to EKs. Sites like the following supporting this traffic flow:

jokertube.org. IN A 89.45.67.50 2017-03-10T10:28:09.000-0800 2017-03-10T15:55:28.000-0800 43
jokertube.org. IN A 89.45.67.178 2017-03-10T16:42:50.000-0800 2017-03-29T11:40:13.000-0700 202

89.45.67.50 AS44901 | BG | BELCLOUD, - Fast Serv Inc.
89.45.67.178 AS44901 | BG | BELCLOUD, - Fast Serv Inc.

JOKERTUBE.ORG 2017-01-20 Namesilo, LLC securefastserver.com good man [email protected]

Various examples of other threat activity on same provider:

https://www.google.com/search?q=%22belcloud%22+%22malware%22+OR+%22exploit%22&ie=utf-8&oe=utf-8