See: https://urlquery.net/report.php?id=1455144998760
See: https://www.virustotal.com/en/url/cb417554b2fdec34b3f4bf7207cc3530e5d49366238a73c45b488e36ed521a57/analysis/1455145415/
The file analysis: https://www.virustotal.com/en/file/8d273da24a01b8eb76b779c7f8c8c5459305aef7cf1437aaa0dc1f254134d105/analysis/1455125407/
It is only 5 and 33 minutes old, but I see Avast does not have this dropper yet. :o
See: https://malwr.com/analysis/ODY0YmNjYzg4YzhjNDVkZGE5YzFkMWVjNWQyMmViMTc/
Malware is on a Moldovan server with outdated server software:
HTTP Server: nginx 1.0.15 Cent OS (Outdated) → http://toolbar.netcraft.com/site_report?url=http://212.56.214.67
polonus