Same malcode and more malware found up here: http://urlquery.net/report.php?id=1430830715074 Where VT results go silent: https://www.virustotal.com/nl/url/eb9d21f6ca0f75f34faa1561b3bf0f2b3c7b51d78663e8a06f4edc486f8f2669/analysis/ Sucuri finds outdated CMS: Outdated WordPress Found Security Updates WordPress Under 4.2 Web application version: WordPress version: WordPress 4.1.1 Wordpress version from source: 4.1.1 Wordpress Version 4.1 based on: htxp://www.otoportali.com/wp-includes/js/autosave.js All in One SEO Pack version: 2.2.5.1 WordPress theme: htxp://www.otoportali.com/wp-content/themes/otomobil/ Version does not appear to be latest 4.2.1 - update now.
PHP vuln: http://www.cvedetails.com/vulnerability-list/vendor_id-74/product_id-128/version_id-160394/year-2014/opov-1/PHP-PHP-5.5.8.html
Vulnerable: User Enumeration is possible The first two user ID’s were tested to determine if user enumeration is possible. User ID 1 : admin User ID 2 : None
linked javascripts:http://www.otoportali.com/wp-content/themes/otomobil/includes/js/jquery.min.js?ver=1.4.2 -http://www.otoportali.com/wp-content/themes/otomobil/includes/js/jquery.tools.js?ver=1.4.2 -http://www.otoportali.com/wp-content/themes/otomobil/includes/js/jcarousellite.js?ver=1.0.1 -http://www.otoportali.com/wp-content/themes/otomobil/includes/js/superfish.js?ver=1.0 -http://www.otoportali.com/wp-content/themes/otomobil/includes/js/custom.js?ver=1.0 -http://adserver.reklamstore.com/reklamstore.js * -http://adserver.reklamstore.com/reklamstore.js //pagead2.googlesyndication.com/pagead/show_ads.js -http://adserver.reklamstore.com/reklamstore.js -//mc.yandex.ru/metrika/watch.js -http://cdn.reklamnative.com/reklamnative/js/render.v1.js **
Website IP badness history: https://www.virustotal.com/nl/ip-address/77.223.134.131/information/ Consider also: http://urlquery.net/report.php?id=1430682789064 with malcode on same IP address.
polonus (volunteer website security analyst and website error-hunter)