The final page automatically starts downloading malware.
The attackers are purely relying on social engineering techniques, to get the user to load the software package.
No drive-by exploits are being used thus far.
So far they firm has noted 9,541 connections to malicious domains.
This helps avoiding reputation and blacklist based security solutions.
source: www.techworm.net