Webpage defacement: http://www.zone-h.org/mirror/id/23773450
and https://www.uploady.com/download/sgJah5LMznk/hMf5rkxGL1_dX_kI (view taken via webproxy)
File detected: index.html
Severity: Potentially Suspicious
Reason: Detected procedure that is commonly used in suspicious activity.
Details: Too low entropy detected in string [['%0A http://labs.sucuri.net/db/malware/malware-entry-mwdefaced01?v03
also see: http://www.unphp.net/decode/49f0accc99c73698fcb8f5730eb44534/
Threat dump MD5: C8D90E08240F17FD7304583C908F1B30
File size[byte]: 196376
File type: ASCII
Page/File MD5: 7F5E6B1FD63D05055D9B5F568A1817DC
Scan duration[sec]: 0.475000
General IP badness (GoDaddy abuse): https://www.virustotal.com/nl/ip-address/182.50.149.1/information/
polonus