Malwarebytes ' systems detected infections originating from the popular adult site Xtube , which is ranked number 786 in the US by Alexa. The malicious website has an estimated 25 million visits.
Unlike other attacks that have been circulating online recently, this one does not use malicious ads to endanger website users.
Instead, it injects a malicious snippet of code directly into the site itself (dynamic, on-the-fly injection). The code points to domains that are constantly changing:
The domain jsloggery.com, for example, serves as a redirect domain that leads to pages containing an exploit kit.
The final step of the attack is landing on websites containing the Neutrino Exploit Kit.
The payload is detected by Malwarebytes Anti-Malware as Trojan.MSIL.ED.
Malwarebytes has already warned the administrators of Xtube. If you are familiar with the website, you would do well to avoid visiting it until the site's code is patched.
Source: secnews.gr

