The landing page has been tweaked and uses various obfuscation techniques. Sundown EK still remains a threat with exploits for IE, Flash, and Silverlight. The payload dropped in this case isnt ransomware but a two stage infection starting with a downloader which retrieves a banking Trojan. The initial dropped payload we captured in this particular new instance is Smoke Loader whose purpose is to retrieve additional malware. Both of those threats are detected by Malwarebytes Anti-Malware.”]

