I agree with you Ylap every detail of it. This scheme runs through IFrames, and it is Russians that run this show. You may trust a particular site, but their download site may be hacked. You can use a cryptographically signed checksum RedHatPackageManager
at http://www.rpm.org/ This guarantees the package you install is the same as the author intended it to be. You can also check in Windows the used Verisign certificate. Right click on the icon, and then on certificate, and more info… An invalid certificate will show up as a red X.
Be on the alert my friend, and stay clear from A24 or 666!