Another IFRAME injection domain: banner82
banner82[dot]com
hxxp://www.google.com/search?q=banner82.com (don’t visit unless javascript and prefetch are disabled)
Looks like fast-flux dns as it’s IP addresses keep changing.
BLOCK IMMEDIATELY.
If your web server is infected, please read the following:
http://www.experts-exchange.com/Security/Vulnerabilities/Q_23408074.html
