Site is hosted at:
http://mail.rqys.com.au/pagi.asp?4959322000000
This redirects to:
https://eoficina.e.telefonica.net/sites/1204/Org300690/pwe/pwe/images/comprovativo2910002938104.exe
this is a trojan/Downloader, which after being run downloads files from:
https://eoficina.e.telefonica.net/sites/1204/Org300690/pwe/pwe/images/01.exe
https://eoficina.e.telefonica.net/sites/1204/Org300690/pwe/pwe/images/02.exe
https://eoficina.e.telefonica.net/sites/1204/Org300690/pwe/pwe/images/03.exe
www.szkolabg.org/cutenews/.../wab.php
And downloads itself again from the same address:
https://eoficina.e.telefonica.net/sites/1204/Org300690/pwe/pwe/images/comprovativo2910002938104.exe
There is a counter of the number of infections at:
200.13.244.245/cw-assenda/bin/ru/contador.asp
Virustotal report:
http://www.virustotal.com/file-scan/report.html?id=657e03e2668f4bba9c117b4e244d90d2756053ea0b707aaabfcd670b59a1c641-1301648128