Also, two ways that hackers use to compromise this site were discovered, one is by injecting a hidden script that redirects the user to certain malicious URLs, while the second is through an iFRAME and the same hidden script . URLs contain scripts that download and run variants of SINOWAL. The two malicious websites are hosted on a single IP located in San Diego, California.
Source: www.vnunet.es

