
“One particular example is a Web site selling Halloween costumes. The deobfuscation returned by ThreatSeeker shows that the JavaScript has multiple layers of obfuscation,” the company said in an alert.
“The script contacts a malicious server in the .biz TLD. Within the ThreatSeeker network, we have seen almost ten thousand sites infected with the same obfuscation technique.”
Another technique involves building a redirect into a popular web site. Websense has detected over 13,000 such script injections in popular sites.