A PHISH or something worse?

See Unknown html malcode: https://www.virustotal.com/nl/url/23c4405d8cfe9aa355ba78b6f641dbf4bf43dca2c108c568f9aef3f6848c53d2/analysis/1423411581/
Website Malware malware-entry-mwanomalysp8 htxp://adminreg.moy.su
List of referenced blacklisted domains/hosts: 2
-ucounter.ucoz.net * Infested with malware: http://sitecheck.sucuri.net/results/all-cheats.ucoz.net
-adminreg.moy.su
Ulightbox → http://packetstormsecurity.com/files/109868/Upnorthwebs-Lightbox-SQL-Injection.html
See: https://tools.digitalpoint.com/cookie-search?cookie_domain=.ucounter.ucoz.net
Connections timerd out: https://urlquery.net/report.php?id=1423411903572
Download for main site = GIF89a!,S; → http://jsunpack.jeek.org/?report=c3d4a90ec9c887fa8485111bc68fe1d31c5d064f

I get HTTP/1.1 204 No Content
Server: nginx/1.6.2
Date: Sun, 08 Feb 2015 16:19:46 GMT
Connection: close
See: http://whois.domaintools.com/moy.su
IP badness history: https://www.virustotal.com/nl/ip-address/193.109.247.236/information/

polonus