avast! the only one to detect JS:ScriptIP-inf [Trj]

See MX VW detection: Up(nil): unknown_html RIPE ru b dot kazakov at rt-center dot ru 37.0.123.188 to 37.0.123.188 mercurialvapor8allegro dot org htxp://mercurialvapor8allegro.org/
Re: https://www.virustotal.com/nl/url/93633c628bf687d926c9a4d21a450cf20058a1e28d8ff5440387e64e1070f193/analysis/1406468463/
avast!

polonus

https://www.virustotal.com/en/file/cc2a5229ea5d970465712f01538159da951d88b69f0bebec15a8fbf5b62ff542/analysis/1406469604/

http://killmalware.com/mercurialvapor8allegro.org/

http://sitecheck.sucuri.net/results/mercurialvapor8allegro.org/

Hi Pondus,

See script attached - https://www.mywot.com/en/scorecard/w.cnzz.com?utm_source=addon&utm_content=popup
Not trusted because w.cnzz dot com/q_stat.php%3Fid%3D1000001593%26l%3D2’ type=‘text/javascript’%3E%3C/script%3E")); launches a trojan downloader.
Then there is an external link to htxps://www.mallpayment.com/risk/index.js
This is a scam site right at the end of the source code, scam site with a very bad web rep: https://www.mywot.com/en/scorecard/mallpayment.com?utm_source=addon&utm_content=popup

So really good that avast! protects their users against this ;D

Damian