Why the javascript malware is detected included on another URL?

See here: http://siteinspector.comodo.com/public/reports/634010
Avast rightly detects according to: http://vscan.urlvoid.com/analysis/9872cf009b67bb057ee99f467d18a4cb/aW5kZXg=/
Sucuri gives this info: Malware found in the URL:
-http://www.ph-kaffeemaschinen.de/
blacklisted javascript: http://sucuri.net/malware/entry/MW:IFRAME:HD202
and http://sucuri.net/malware/malware-entry-mwjs488

polonus

according to this…the first URL goes to the second…you find the same piture in top right corner

http://urlquery.net/report.php?id=8705
http://urlquery.net/report.php?id=8706

wepawet will not scan those URLs ?

Jotti: http://virusscan.jotti.org/en/scanresult/aac0e4ebf4d77f8823c6dea1b70f54192d6afe1c

Hi Pondus,

So it is a straight redirect from the one to the other site. OK, but some other information on the urlQuery report is very important, namely what malware is detected: Detected Blackhole exploit kit v1.2 HTTP GET request
That is very helpful information, you gave us here through the urlQuery report.
More on the changed parameters for this malware is published here: http://xylibox.blogspot.com/2011/09/blackhole-exploit-kit-v120.html (linksource: XyliBox blog)

polonus