See: http://cybercrime-tracker.net/index.php?s=0&m=40&search=POSCardStealer
Even more dangerous on the verge of XPocalyps now: https://www.virustotal.com/nl/url/5252e165e19496844a4d1f74768557fe0bded5548d7e7dc04ba08ddc1d0e2c6b/analysis/
https://www.virustotal.com/nl/ip-address/31.170.161.96/information/ IP qualifies to be blocked!
See: http://urlquery.net/report.php?id=9779496 IDS for current event rule: 2017135 – ET CURRENT_EVENTS PHISH Remax – function Validate (current_events.rules)
kraken virus tracker classification info: autos-mark dot comlu dot com,31.170.161.96,Criminals,
Criminals means only to say active malcode up.
For IP badness history see attached.
pol