Today I came across an interesting attack that injects malicious scripts at the very bottom of existing .js files.
Update: at the bottom of this post you’ll find information about how a security hole in Plesk Panel was used to infect websites. Comments are also worth reading.
Update (July 26, 2012): The attack has changed both the injected script and the domain generating algorithm. See details in my follow up article. Information about the Plesk security issues are still can be found in the current post and comments.
The script (surrounded by the /*km0ae9gr6m*/…/*qhk6sa6g1c*/ pair of comments ) looks like this:

Full source code can be found here
On Google diagnostic pages of infected sites you will currently see something like this
Malicious software is hosted on 2 domain(s), including ctonxidjqijsnzny .ru/, znycugibimtvplve .ru/.
I say “currently”, because the most interesting thing about this script is the built-in domain name generator.
Continue »»
Selected short messages and links you might have missed if you don’t follow me on Twitter.
ProFTPD, OpenX, reporting webspam, cross-platform malware … »»
Selected short messages and links you might have missed if you don’t follow me on Twitter.
Dec 28, 2009
LeaseWeb seems to have removed malicious servers from its network after my blog post about the “GNU GPL” scripts. (OVH still hosts hackers)
Dec 30, 2009
Good Guys Bring Down the Mega-D Botnet – respect @FireEye !
Jan 2, 2010
If you want more real-time experience, you can follow @UnmaskParasites on Twitter.
Related posts:
Last week, I wrote about the latest mutation of the website hack that has been active (mostly in form of iframe injection) throughout this year. I mentioned that for some reason all malicious domain names had been mapped to IP addresses on LeaseWeb and OVH networks. Moreover, LeaseWeb hosted a central site mdvhost .com (hidden behind reverse-proxies) for at least 3 months.
LeaseWeb reaction »»
Selected short messages and links you might have missed if you don’t follow me on Twitter.
Dec 23, 2009
Christmas theme: who-is-santa-2010 (dot) com – domain name of one scareware site
Dec 24, 2009
Response to my blog post from LeaseWeb
Dec 25, 2009
Sophos on the “GNU GPL” malicious script (Troj/JSRedir-AK)
If you want more real-time experience, you can follow @UnmaskParasites on Twitter.
Similar posts: