See: https://www.virustotal.com/nl/url/13eecce9e20badd33b16dbb5c21419a84730cccc234ccbeaccdc93f06b456bbd/analysis/1422051830/
No detection: http://quttera.com/detailed_report/carrieres.patrimoine.free.fr
Namo WebEditor v5.0 exploitable php shell uploads - keylogger: http://iranhack.org/acc/thread-718.html
Apache/ProXad exploitable: phpse.php upload. Excessive server header proliferation risk: Apache/ProXad [Sep 23 2014 15:26:28]
<html>
<head>
<title>CARRIERES PATRIMOINE</title>
<meta name="description" content="Makes a menu frame, a header frame, and a footer frame. Hyperlinks in the menu frame are targeted to the main frame.">
<meta name="generator" content="Namo WebEditor v5.0(Trial)">
</head>
<frameset rows="1*" cols="306, 75%" border="0">
<frame name="contents" scrolling="yes" marginwidth="30" marginheight="14" namo_target_frame="detail" src="essai2.htm" noresize>
<frameset rows="14%, 86%">
<frame name="header" scrolling="no" marginwidth="5" marginheight="15" src="noname2.htm">
<frame name="preambule" scrolling="yes" marginwidth="25" marginheight="50" src="noname3.htm">
</frameset>
<noframes>
<body bgcolor="white" text="black" link="blue" vlink="purple" alink="red">
<p>You need a browser that supports frame to veiw this page.</p>
</body>
</noframes>
</frameset>
</html>
→ http://jsunpack.jeek.org/?report=78acacd3a45893831f4032c2314829ec216fd050
See Recent reports on same IP/ASN/Domain: http://urlquery.net/report.php?id=1422052946967
Likely hostile IP…
polonus