Trojan, HTML/Redirector.MA, not detected?

See: http://www.virustotal.com/url-scan/report.html?id=8f84c2dd3a0b2f19e95ddd30428a6320-1319811368
and http://www.virustotal.com/file-scan/report.html?id=70ef44ce4c907320adc5c9c7b89b76fffe97a2b8b0cf2a7367122307e8c6c144-1319818881
But blocked by google as with malware: known for fake av hosting, see:
http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=http%3A%2F%2Fspmartinelli.com%2F5k6an5x%2Findex.html&client=googlechrome&hl=nl

polonus

404 (Page Not Found) Error

http://jsunpack.jeek.org/dec/go?report=bde778af57ac3d6ca641eec973268654a974978f
http://jsunpack.jeek.org/dec/go?report=f95a3dc2b9f7617ceeb785b651ee1a08bf2bbaf2

Hi Dim@rik,

The site redirects to -P3nlhclust404.shr.prod.phx3.secureserver.net, and what is out there if one gets access, is shown here: http://xml.ssdsandbox.net/ip?ip=72.167.191.65 (quite a collection of nasties there, links to analyses)

polonus

Hi Polonus,

really :frowning:

http://www.ip-adress.com/ip_tracer/72.167.191.65