Malicious hackers or careless users?
There have been numerous unrelated web-sites intrusions lately. The result is that a malicious script (usually a modification of Trojan-Downloader.JS.Psyme) is put on the server in place of the original index* file, so that when a user visits the web-site the script is immediately executed. During the script execution a known/patched Microsoft IE vulnerability is exploited, which leads to the user's PC getting infected with a Trojan spy. Inside the script, links to the Trojan usually (but not always) refer to some "sp.php".
[ Read more ]