Malicious or suspicious?

See: http://killmalware.com/institutoedinburgh.com/#
Flagged more times: https://www.virustotal.com/nl/url/066ae6892cf55be827a50e7bfcf954e9469be2e9cbc96828d75a675a4d088bc5/analysis/1411592112/
ISSUE DETECTED DEFINITION INFECTED URL
Website Malware mwjs-iframe-injected691?v24 htxp://institutoedinburgh.com ( View Payload )
Website Malware mwjs-iframe-injected691?v24 htxp://institutoedinburgh.com/404javascript.js ( View Payload )
Website Malware MW:BLK:2 htxp://institutoedinburgh.com ( View Payload )
Known javascript malware. Details: http://labs.sucuri.net/db/malware/mwjs-iframe-injected691?v24

Coming Soon Page

infested with malware.

pol

Another one flagged thrice at VT: https://www.virustotal.com/nl/url/3bff32b1a53f02cd113b680db79afc6fa91f107629e681daf2560367389730c6/analysis/1411661177/
Web Server Details
Scan for: htxp://www.downbucket16.biz
Hostname: wXw.downbucket16.biz
IP address: 96.45.83.233

System Details:
Running on: DNSME
Powered by: PHP/5.3.27

List of scripts included
htxp://html5shim.googlecode.com/svn/trunk/html5.js

IP Badness history: https://www.virustotal.com/nl/ip-address/96.45.82.193/information/
Detections via herd protect: http://www.herdprotect.com/ip-address-96.45.82.193.aspx
This is not helping towards security: http://sameid.net/ip/96.45.82.193/ 117 site on one and the same IP.

Malware from IP: http://safeweb.norton.com/report/show?url=downbucket16.biz see attached

pol

The file Norton reports - some PUP crap
https://www.virustotal.com/en/file/e4a01266d28d87d0f8198cf077f538ccd4cf2cc616d4c30abdf0c45abb62d3eb/analysis/1411662508/

Norman Shark autoadded signature as Troj_Generic.VUZDB

F-Secure added detection as Application.Agent.GA