following previous post, a new injected script has emerged that resolves to same IP.
v.js retrieves another iframe src www.vieio.cn/i.htm.
This exploitation kit tries to avoid detection by splitting each respective exploit into 2 files. One .htm and .js