A malicious and remote javascript file was found inside the site content and is being used to distribute malware (from and other domains). Any user visiting the infected site could be compromised (desktop antivirus will flag it as JS:Cruzer-B, JS/Obfuscated, JS/Cruzer.C.gen, JS/TrojanDownloader.Agent.NKW and others, depending on the intermediary domains and AV product).


Domains used in this attack:<br /><br /><br />
(and many others)


Any web site (no specific target).


Clean up:

Malware dump (sample of malware):

<iframe src="" ..