Seen yesterday: https://www.virustotal.com/nl/url/6e3717252c996dd7b2e78b08c28a1b16a32eafc62e0ed3b38759eff7c115dbca/analysis/1424956195/
index
Severity: Suspicious
Reason: Detected suspicious redirection to external web resources at HTTP level.
Details: Detected HTTP redirection to htxp://rgaiow894.biz/.
File size[byte]: 0
File type: Unknown
Page/File MD5: 00000000000000000000000000000000
Scan duration[sec]: 0.001000
Exploitable: /home;jsessionid=2F23209706F897BAB3328A48000F70BF
/rule/readme;jsessionid=2F23209706F897BAB3328A48000F70BF
/age/readme ;jsessionid=2F23209706F897BAB3328A48000F70BF
/policy/readme;jsessionid=2F23209706F897BAB3328A48000F70BF
/join/;jsessionid=2F23209706F897BAB3328A48000F70BF View logged requests!
Listed at Spamhaus: http://www.spamhaus.org/query/domain/rgaiow894.biz
→ http://whois.domaintools.com/afsd784iud.biz
Re: http://urlquery.net/report.php?id=1424306445152 (for the redirect)
a guaranteed: http://www.phishtank.com/index.php/tutorials-mainmenu-48/phish_detail.php?phish_id=2985655
pol