See: http://urlquery.net/report.php?id=7517000
Site infested with Troj/Brogger-B?
Site has script from non-verified sources - SSL code insecurities.
Code hick-up: wXw.tesouro.fazenda.gov.br/templates/tesnac/javascript/jquery-1.6.2.min.js benign
[nothing detected] (script) wXw.tesouro.fazenda.gov.br/templates/tesnac/javascript/jquery-1.6.2.min.js
status: (referer=wXw.tesouro.fazenda.gov.br/)saved 91556 bytes 7622c9ac2335be6dcd3ab8b47132e94089cef931
info: ActiveXDataObjectsMDAC detected Microsoft.XMLHTTP
info: [decodingLevel=0] found JavaScript
suspicious: multiple XSS vulnerabilities possible._Did not follow redirect to https://wxw.stn.fazenda.gov.br/wxw.tesouro.gov.br/wxw.tesouro.gov.br/wxw.tesouro.gov.br/wxw.tesouro.gov.br/wxw.tesouro.gov.br
This code there is vulnerable → /pt/component/ninjarsssyndicator/?feed_id=1&format=raw" to vreate Joomla RSS feeds.
to http://www.exploit-db.com/exploits/11740/ → attempt logs: http://www.lecnef.org/component/ninjarsssyndicator/?feed_id=2&format=raw
polonus