See IP 5.9.148.201 → ttps://www.virustotal.com/nl/url/569cef6e1d0f7fc5c72a9dad84f7cb10c0e46ab88025b01d61456fc24314e9f7/analysis/1393690395/
Nothing here: http://urlquery.net/report.php?id=9728679
Threats that came from IP in the past - AlienvaultScanSpam threat danger level 2; DShield Block List - threat danger level 3; Community & Advanced - threat danger level 3 - years ago - bogons - threat danger level 1. → artforms dot ro,5.9.148.201,ns1.oxiahosting dot com,Parked/expired,
See: http://jsunpack.jeek.org/?report=1c9c54742a25728e46a9d2c75eb4e139e1e331d7
See: wXw.artforms.ro/js/fileuploader.js benign
[nothing detected] (script) wXw.artforms.ro/js/fileuploader.js
status: (referer=wXw.artforms.ro/)saved 39998 bytes 24d17f7e5ab79b5316af302eb083177095580888
info: [iframe] wXw.artforms.ro/js/javascript:false;
info: [decodingLevel=0] found JavaScript
suspicious:

polonus