iFrame malware through php overwrite after hack

http://urlquery.net/report.php?id=1548220 redirecting to Host: habboigratis dot altervista dot org
also see: http://sakrare.ikyon.se/log.php?id=2653
See: http://sitecheck.sucuri.net/results/www.verrahmt.de
on how the hack was done: http://e107.org/e107_plugins/forum/forum_viewtopic.php?242961 (post reply for glogin from Moc)
also see http://evuln.com/labs/iframe/habboigratis.altervista.org/
IDS → Detected RedKit exploit kit URL pattern

polonus

VirusTotal
https://www.virustotal.com/nb/file/fa5e7950e862692222ca4509c465079d80f29cd8de3b77cd0998d7d57c0d11fd/analysis/1363976558/