http://tools.{BLOCKED}ation.com/ib2/

 Analysis by: Jesa Golez

 URL BLOCKING DATE/TIME: 31 May 2012 10:30:00 PM GMT-8
 RATING: HIGH
 DOMAIN: ip2location.com
 CATEGORY: Disease Vector
 DESCRIPTION:

TROJ_RANSOM.BOV connects to this site to get the IP address, geographical location, city, and ISP of the affected system. Systems got infected with this malware when they visited the site of the French confectionery shop Lauderee. The variant was found to display a notification that impersonates the French National Gendarmerie and demands payment from affected users.