To confirm TwinHeadedEagles analysis from the point of scanning the initial insecure link you produced, consider:
That this was an insecure connection a priori, content-security-policy and cache-control headers insecure with no header response and that autocomplete settings did not apply due to an overriding factor such as the insecure connection here.
See: https://www.virustotal.com/nl/url/9327dba6048752b51c9d8e1d76cf2b6df7a34efdd4fae7ff51ac4c9e3abe2d8d/analysis/
Malware detected here: http://urlquery.net/report.php?id=1429538091866
Quttera blacklisted domain. PHP/5.4.39-0+deb7u2 → http://www.intelligentexploit.com/view-details.html?id=21223
Pingback vulnerable.
polonus