Suspended webpage is a PHISH and holds suspicious code...

Re: https://app.webinspector.com/public/reports/show_website?result=3&site=http%3A%2F%2Fcardillacprint.com
Re: http://killmalware.com/cardillacprint.com/
Consider: https://aw-snap.info/file-viewer/?tgt=http%3A%2F%2Fcardillacprint.com%2F&ref_sel=GSP2&ua_sel=ff&fs=1
Listed here: http://comments.gmane.org/gmane.comp.security.phishings/89462
Re: http://toolbar.netcraft.com/site_report?url=http%3A%2F%2Fcardillacprint.com%2F
Avast flags this url as belonging to a PHISH: -https://gator2011.hostgator.com/404.html
Website blocked
by Blockulicious
The website “fwdssp.com” has been blocked for your safety.
Category of threat : Malicious:URL = -http://fwdssp.com/?dn=referer_detect&pid=5POL4F2O4
URL : -http://fwdssp.com
Detected on le 27/08/2015 à 06:23:06 (-100)
Site allowing ABP acceptable ads: 1: < !DOCTYPE html PUBLIC> < ///html data-adblockkey=“MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBAKX74ixpzVyXbJprcLfbH4psP4+L2entqri0lzh6pkAaXLPIcclv6DQBeJJjGFWrBIF6QMyFwXT5CCRyjS2penECAwEAAQ==_FnTO9U147jFDSpI4d8FbL+W6tRyZ9ED9P/7Q4g1hZ3W3ncY1pa8ul+dsdNW1zwlA/HJkVVm1FZDZZeVPB54Omw==”
Read how a page could so be hijacked: https://gist.github.com/sehrgut/2cf3179185c915788a82

polonus

A second website with likewise 0 iFrame → http://www.domxssscanner.com/scan?url=http%3A%2F%2Fbuykidsswimwear.com%2Fcgi-sys%2Fsuspendedpage.cgi
So this seems an ongoing phishing campaign.

pol