See: https://www.virustotal.com/nl/url/fe057cd46f6ce9044cd10abf8cb99c74ed3682c9b667fa98a9cb9e3594072d29/analysis/1431518111/
and https://www.virustotal.com/nl/file/29960bdb15f774db170634ccf3ef07c2eaaef94fd0e20fef9a2066bb8d03d1f0/analysis/1431461326/
See: http://online.drweb.com/result/?lng=en&chromeplugin=1&url=http%3A%2F%2Fsoftdl.360tpcdn.com%2FXunlei7%2FThunder_7.9.36.4940.exe
SUSPICIOUS: htxp://softdl.360tpcdn.com/Xunlei7/Thunder_7.9.36.4940.exe redirects to htxp://101.226.11.88/softdl.360tpcdn.com/Xunlei7/Thunder_7.9.36.4940.exe
blocked with this list: https://lists.malwarepatrol.net/cgi/getfile?receipt=f1417692233&product=8&list=dansguardian
Backdoor trojan: https://www.threatcrowd.org/listMalware.php?antivirus=Win32.Fujac
polonus