There have been numerous unrelated web-sites intrusions lately. The result is that a malicious script (usually a modification of Trojan-Downloader.JS.Psyme) is put on the server in place of the original index* file, so that when a user visits the web-site the script is immediately executed. This means that a hacker (whoever or whatever s/he/it may be) has had access to the servers logins+passwords at least to some of them. But this scenario isnt at all likely according to system logs, no tampering with system services have been registered.”]
Source: https://securelist.com/malicious-hackers-or-careless-users/30300/

