Malicious suspicious defacement on website!

found on 144 websites.
2 detections on VT:
One malicious file detected: index.html
Severity: Malicious
Reason: Detected known malicious content.
Details: Threat detected according to previously retrieved information
File size[byte]: 57754
File type: ASCII
Page/File MD5: DC14FD90739734A11C2D31C76C5701B8
Scan duration[sec]: 0.001000 View code attached

Sucuri scan gives: Unable to properly scan your site

IP badness history:


Detected IP in here:

DrWeb detects as SCRIPT.Virus


Vulnerable is WordPress Version
Version does not appear to be latest 4.1.2 - update now.

Received data GET: HTTP/1.1 200 OK
Date: Sun, 26 Apr 2015 15:16:12 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding
Connection: close
Content-Type: text/html

<TITLE>HostMonster - Web hosting</TITLE>
<style type="text/css">
body {
	margin-top: 0px;
.style2 {font-family: Arial, Helvetica, sans-serif; color: #033b73}

<BODY bgcolor="#FFFFFF">
<table border="1" align="center" cellpadding="0" cellspacing="0" bordercolor="b7dc73" bgcolor="#EFEFEF">
	<TABLE width="790" border=0 align="center" cellPadding=0 cellSpacing=0>
          <TD width=163><img height=98 src="" width=163></TD>
          <TD vAlign=top>
            <TABLE cellSpacing=0 cellPadding=0 width="100%" border=0>
                <TD><img height=31 src="" width=627></TD></TR>
                  <TABLE cellSpacing=0 cellPadding=0 width="627" border=0>
                      <TD width="627" background="">
		        <div style="visiblity: hidden; height: 67px; width: 1px;" /></TD>

<!-- SHTML Wrapper - Bounce Sniffer -->
<!-- Main site not installed -->
<div align="center">
                  <h3 class="style2">There is no website configured at this address.</h3>
                  <p class="style2"><font size=-1>
You are seeing this page because there is nothing configured for the site you have requested.
<font size=-2>If you think you are seeing this page in error, please contact the site administrator or datacenter
responsible for this site.</font>


		  <table cellspacing="8" width="65%">
   <td width="49%" height="50" onMouseOver="'; background-color: #ffffff ; border: Solid 1px #b7dc73  ';'#5f9c00'" onMouseOut="'; background-color: #ffffff ; border: Solid 1px #b7dc73 ';'#033a72'" onClick="if(!='_blank')location.href=this.firstChild.href" style="border: 1px solid #b7dc73; padding: 4px; font-family: 'Arial'; font-weight: bold; font-size: 16px; text-align: center; background-color: #ffffff;"><a href="" style="color: #033a72; text-decoration: none; white-space: nowrap; cursor: pointer;">Login to your Account</a>
   <td height="40" onMouseOver="'; background-color: #ffffff ; border: Solid 1px #b7dc73  ';'#5f9c00'" onMouseOut="'; background-color: #ffffff ; border: Solid 1px #b7dc73 ';'#033a72'" onClick="if(!='_blank')location.href=this.firstChild.href" style="border: 1px solid #b7dc73; padding: 4px; font-family: 'Arial'; font-weight: bold; font-size: 16px; text-align: center; background-color: #ffffff;"><a href="" style="color: #033a72; text-decoration: none; white-space: nowrap; cursor: pointer;">Support Center</a>
<tr><td bgcolor="#b7dc73">
  <div align="right" class="style2">&copy; 2009</div></td>

  var gaJsHost = ("https:" == document.location.protocol) ? "https://ssl." : "http://www.";
  document.write("<scr"+"ipt src='" +gaJsHost+ "'></scr"+"ipt>");
  var pageTracker = _gat._getTracker("UA-9156498-2");
<!--- $Id: default.shtml,v 1.10 2010/06/01 20:03:46 sj Exp $ --->


Kleissner’s VirusTracker states there is active and up malware there:
themoviemonk dot com,,ns2.hostmonster dot com,Criminals, is a bad zone, main domain scan: Found mail servers with inconsistent reverse DNS entries. You should fix them if you are using those servers to send email. →
Reverse entries for MX records.
htxp:// → SaferChrome: Insecure login: Password will be transmited in clear to htxp:// detected (see report) Login padlock icon
Alerts (1)
Insecure login (1)
Password will be transmited in clear to htxp://,Ghosted,

polonus (volunteer website security analyst and website error-hunter)

detection confirmed and added by Norman/BlueCoat HackScript.B

F-Secure detection added as Trojan.JS.Agent.JOE

Thanks, Pondus, we have detection now.
