See: https://www.virustotal.com/nl/url/90145a931c3172d375ff809fc0462f079cf3540872e7030cf84ee50817e3c05e/analysis/1415188664/
Blacklisted and suspicious file detected: http://quttera.com/detailed_report/s3-us-west-2.amazonaws.com
Infested with malware: http://sitecheck.sucuri.net/results/s3-us-west-2.amazonaws.com
Suspicious conditional redirect. Details: http://sucuri.net/malware/entry/MW:HTA:7
Redirects users to:htx://aws.amazon.com/s3/
Missed here: http://zulu.zscaler.com/submission/show/e92f0503fee3dd4206d0d931920b2e65-1415188720
86% of users remove it: http://www.shouldiremoveit.com/Re-Markable-102107-program.aspx
Not alerted here: https://urlquery.net/report.php?id=1415188882320
100 blacklisted external links: http://quttera.com/detailed_report/s3-us-west-2.amazonaws.com
Suspicious: a0.awsstatic.com/chrome/js/1.0.75/jquery.1.9.js
Severity: Potentially Suspicious
Reason: Detected procedure that is commonly used in suspicious activity.
Details: Too low entropy detected in string [[‘=%26=%26=%26ontrue=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%261=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=’]] of length 244 which point to obfuscation or shellcode.
Threat dump: http://jsunpack.jeek.org/?report=3986727bef7046a63bf29003f7e1331d00696eb7
Threat dump MD5: A650300281863AD0059976B4381A21A9
File size[byte]: 92621
File type: ASCII
Page/File MD5: 839D874FA6EF205E8BE864B39FA1949B
Scan duration[sec]: 9.248000
x-amz-id-2 with bucket-response and get-object-response No Content
IP badness: http://www.herdprotect.com/ip-address-54.240.248.82.aspx
pol