This is purely a case of state sponsored case malware, it was search warrant backing up the domain name spotted to be infected.
Infection runs in Onionland on FreeHosting website(s) in 2013, with the purpose to aim child porn suspects with the method of mass-driven by download. The court documentation was spotted recently in 2014 to legitimate the usage of mass-infection technique for the purpose to search (investigation details) by the regular search warrant signed by district court of Nebraska, US.
Details of malware, its distribution & purpose here............http://www.kernelmode.info/forum/viewtopic.php?f=16&t=3432
Infection runs in Onionland on FreeHosting website(s) in 2013, with the purpose to aim child porn suspects with the method of mass-driven by download. The court documentation was spotted recently in 2014 to legitimate the usage of mass-infection technique for the purpose to search (investigation details) by the regular search warrant signed by district court of Nebraska, US.
Details of malware, its distribution & purpose here............http://www.kernelmode.info/forum/viewtopic.php?f=16&t=3432