Kaspersky Lab has found a new malicious webpage in Portuguese. The site contains a download of an executable file called Trojan-Downloader.Win32.AutoIt.po and three additional binaries are downloaded from a compromised site in Brazil. This activity has also resulted in access to www.visa.com.br and another location, producing 404 errors because the files were hosted on yet another compromised site, which has apparently been cleared of the intrusion.”]
Source: https://securelist.com/japan-quake-malware-again/29783/