Unknown _html_RFI_shell malcode on site...

See: https://www.virustotal.com/nl/url/661c2feac505e9fceb80d7654aa22e849d4bfc5b34d8d5a0af20bf14b1c073dc/analysis/1381073696/
and https://www.virustotal.com/nl/file/7dc62ff88808e98c42d8f21cf86e6dc44509e131fc8545b30121ccd1c2274ac7/analysis/1381010634/
http://urlquery.net/report.php?id=6388765
But we know the site is vulnerable because of outdated WordPress version 3.6
Insecure see: https://asafaweb.com/Scan?Url=fastmarketcash.com%2Fpenny-stock-egghead
About the one at hand read: http://vagosec.org/2013/09/wordpress-php-object-injection/

polonus