How exploit kit evolves from particular site & avast webshield protects us!

Previous malware launched like this: htxp://
Latest alive variant: htxp://
With accompanying VT report: htxps://
Avast does not detect yet, but better would be to block / through the avast shield, because malware is being spread from there continously,
and indeed the avast webshiled blocks it flagging JS;ScriptSH-inf[Trj]. So we are being protected!
An older example of this: hxtp://
See why, then see here: htxp://
Via urlquery we are getting the following alerts: Detected BlackHole exploit kit HTTP GET request & Detected Live BlackHole exploit kit
Some malicious previous detections for this IP through: htxp://
