Sucuri also says it contains malware:
web site: attractions(DOT)uptake(DOT)com
status: Site infected with malware
web trust: Not Blacklisted
warn: Wordpress version outdated: Upgrade required.
Make that link to -http://sucuri.net/malware/malware-entry-mwiframehd5 non-click-through, please, because the avast Webshields flags HTML:iFrame-EE[Trj] and rightly so. Even at descriptions of malcode or look-ups the avast shields may sound the alarm as the non-munged code example gets recognized, nothwithstanding the fact that it does not infect from there. Similar happened to me on several occasions when visiting jsunpack online service to analyze script or trying to open a particular piece of malcode on a URL through my malzilla browser. We know why this is, my friend, but the unaware forum visitor that click that description link may panick because he does not understand the avast shield reaction,
I do not see any iFrame that goes to -nuotoll.com,
see: http://www.google.com/safebrowsing/diagnostic?site=nuotoll.com/ as spg SCOTT pointed out in the image from SUCURI’s he provided for us. For nuotoll dot com unmasked parasites informs that under certain circumstances third parties could add malicious code to legit sites for which Google Safe Browsing delivers this alert,
I assume you could give a reaction on the blog they have going: http://blog.sucuri.net/
It qualifies somewhere under misdetection or false positive. At least it needs explanation.
I see sucuri as one of the better website monitoring scanning services, but they also meet with mistakes, omissions and have to clean out their daily dirt. Never take any detection for granted, always check with other scanners or go directly to the code as you do. That is the lesson we can take here.
Thank you very much, spg SCOTT, for diving into this issue and for the insight gained.
But we also should praise the young Donovansrb10 for starting this thread on this apparent new threat here. He sort of has put his HTML-homework to a good purpose if he stumbled upon a sucuri misdetection,
The file 'attractions.uptake.com.htm' has been determined to be 'FALSE POSITIVE'.In particular this means that this file is not malicious but a false alarm.Our analysts named the threat HTML/Rce.Gen.The term "HTML/" denotes a script-virus that is able to infect the system using a HTML script.Detection will be removed from our virus definition file (VDF) with one of the next updates.