URLs and sub domains distributing the malware or acting as a redirector:
Domain firmhansy.ru is at: 31.31.204.60 (expired.reg.ru)