Reported: Up(nil): unknown_html_RFI_shell ARIN US abuse at theplanet.com 74.53.96.214 to 74.53.96.214 ihatequotes dot net htxp://ihatequotes.net/terms-of-service
See: https://www.virustotal.com/id/url/61a8e9362a1f4763aedf51c57a0b87bf67e47ae2566e7af6a5c96db73d751f18/analysis/1368529609/
and
http://minotauranalysis.com/search.aspx?q=a3f3fa30a90a988b0ed6e3373f15d721
Only 1 detection for Mal/FBJack-A from Sophos: https://www.virustotal.com/id/file/78d178fa7b7f6dbf364df7fd9ce733b308db19b22194e5b3c1801469c3bf90b1/analysis/
No alerts given here: http://urlquery.net/report.php?id=2452407
Detected here: http://evuln.com/tools/malware-scanner/ihatequotes.net/
Malicious script found to be benign here: http://zulu.zscaler.com/submission/show/685003c6beab6d8b8a6a684425deed6d-1368530819
See: http://vurldissect.co.uk/default.asp?url=http%3A%2F%2Fihatequotes.net%2Fwp-content%2Fthemes%2Fihq%2Fjs%2Fmootools.svn.js&btnvURL=Dissect&selUAStr=1&selServer=1&ref=&cbxSource=on&cbxBlacklist=on
Two attacks in one:
http://blog.unmaskparasites.com/2010/10/06/two-malware-trends-combined-in-one-attack/
Spam campaign malware that avast should detect as JS:Crypt-A [Trj]
polonus