logo

Expired and exploited: Reviving a 30-year-old legacy domain for hijacking

ID: b2192109-2542-5f3b-83a9-105fa9f0b99a

STIX ID: report--b2192109-2542-5f3b-83a9-105fa9f0b99a

Feed Name: The Spamhaus Project

Threat Score
45/100

Date Published: 2024-05-10

Date Updated: 2026-04-30

Author: The Spamhaus Team

...
...

The report describes an investigation that found a domain using hijacked IP blocks routed from an Ashburn, VA data center (38.27.122.0/24, Fiberlink/Evoque). ARIN records linked that address space to several legitimate North American organizations, suggesting the domain is leveraging hijacked or misattributed infrastructure possibly for malicious activity or impersonation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.