This web domain also seems to play a role in this scheme: https://www.virustotal.com/en/domain/tj.symcd.com/information/

We should understand that these redirects may be rather short lived and mitigating.
Going to the IP, 23.4.43.27, it automatticaly downloads woc3kreY.part
woc3kreY.part
Scan history

Scan new file
First uploaded2014-02-07 17:01:48 GMTFiletypedata
Last scanned2014-02-07 17:01:48 GMTFile size5 B

MD5 4842E206E4CFFF2954901467AD54169E

SHA1 80C9820FF2EFE8AA3D361DF7011AE6EEE35EC4F0

SHA256 2ACAB1228E8935D5DFDD1756B8A19698B6C8B786C90F87993CE9799A67A96E4E

See what I earlier reported on this: https://forum.avast.com/index.php?topic=170995.0

polonus