The site is hosted at:
http://210.18.21.12.sify.net/images/view.asp?4959322000000 (210.18.21.12)
This redirects to:
http://70.168.253.213/includes/DOC2421995221142442.exe
this is a Trojan/Downloader, which after being run downloads files from:
http://www.neslhk.com/obr/biling/a.gif
http://www.neslhk.com/obr/biling/b.gif
http://www.neslhk.com/obr/biling/li.gif
The following requests for this trojan are returning 404:
http://www.naturesunshinegt.com/plugins/system/legacy/wab.php
http://www.colegiometas.com.br/hwid.ini
A fake receipt is stored at:
http://70.46.79.251/PSP/PSP/comprovativo.html