Unknown html malware - website is known infection source!

See: https://www.virustotal.com/nl/url/1c21ed3d656ec185afc5131aa94d62990076e767aa4acc047ab7b07d194efef4/analysis/1421674525/
DrWeb gives site as a known infection source.
IDS alerts here: https://urlquery.net/report.php?id=1421534629735 for ET CURRENT_EVENTS SUSPICIOUS csrss.exe in URI
Re: http://doc.emergingthreats.net/bin/view/Main/2016702

Suspicious domain detected. Details: http://sucuri.net/malware/malware-entry-mwblacklisted35

IP badness history: https://www.virustotal.com/nl/ip-address/89.248.225.50/information/ & http://totalhash.com/network/ip:89.248.225.50
On server.exe → You can read more about this also at http://en.wikipedia.org/wiki/Bifrost_(trojan_horse) as it covers this trojan horse virus in detail.
Malware launched from IP: http://www.herdprotect.com/ip-address-89.248.225.50.aspx
https://malwr.com/analysis/YWQ4MWNkNzVmNzllNDgzYjhjZWZkNGY0MmRlMzczYTc/
For PHISHING going on from there, read earlier posted: https://forum.avast.com/index.php?topic=154248.20

polonus