From: SANS Internet Storm Center Alert
The de-obfuscated URL goes to (dont click!!) js.pceb.cc, which resolves to 22.214.171.124, which is - surprise surprise - the address range of INHoster in Ukraine. Although we are wary of excessive block-lists, we have repeatedly recommended in the past that you block this range 126.96.36.199 - 188.8.131.52
Now look who else resides on that IP address:
184.108.40.206 outpostsupport.com (Win32/TrojanProxy.Daemonize)
Just mentioned these characters the other day ... you can add the following entry to your HOSTS file, until the next update.
127.0.0.1 js.pceb.cc #[Trojan.Win32.Rootkit.E]