Does Avast detect cclub11.exe here?

See: htxp://112.185.254.215/loader/cclub11.exe unknown execuletable?
Re: https://www.virustotal.com/en-gb/url/684904e4debed1d98f7944b04a4f769be4f1262f3d354a2d05c9ed4c7d9ffc99/analysis/1434308828/
Consider: http://7feeds.com/listfeed-malc0de.com_el_rss_el_-1401884028
Malware - detected → http://urlquery.net/report.php?id=1434308949312 → application/octet-stream
Quttera → Quttera Labs - domain is Malicious.
Site risk 9 red out of 10: http://toolbar.netcraft.com/site_report?url=http%3A%2F%2F112.185.254.215
It is a Zusy variant Avast should detect as Win32:Malware-gen!

polonus

https://www.virustotal.com/nb/file/7a263fce484f591d7967008121cd6d52df291ff6a547c84429090047878ddd0b/analysis/1434313241/

Advanced heuristic and reputation engines
F-Secure Deepguard Suspicious:W32/Malware!Online
Symantec reputation Suspicious.Insight

https://www.metascan-online.com/en/scanresult/file/d2918e74cc9847c6bf68972530cb4aa6

Hi Pondus,

This means it is Rogue/Ransomware as being described here: https://forums.malwarebytes.org/index.php?/topic/111408-fraudtoolwin32securityshieldekc/
And Avast recently had no detection I guess from these results: https://www.virustotal.com/en-gb/file/612610de48db6d0f91dc0054acb5c8fc12a15e42ff8f75051c4a57de6d501625/analysis/

polonus