Description:
A hidden iframe was identified inside an encoded block of javascript. It loads content from remote web sites in attempt to exploit a specific specific browser vulnerabilities (from exploit packs). In some variations, the browser is redirected to blackhat seo spam sites. It is also known as "Exploit:HTML/IframeRef.AA" or "Iframes" by some anti virus products.
Note that every PHP, HTML and JS file could get compromised by this malware.
Affecting: Any web site. Often on outdated WordPress, Joomla and osCommerce sites.
Clean up: You can also sign up with us and let our team remove the malware for you.
Loads malware from multiple sources:
Malware dump (sample of malware):