Due to the high demand for Windows 10, Microsoft is releasing it gradually. This especially applies to certain countries. The official Microsoft Brazil website confirms it (left image). Cybercriminals from Brazil have taken advantage of this and are running a spam campaign identical to the official design offering a fake option for users to “get your copy now”.
When the victim clicks on “Instalador Windows 10″ (Windows 10 Installer), it downloads to the system encoded VBE script. This is a base64 encoded script, using legit Motobit software for encoding. Once running, it drops the main Trojan-spy component into the system. They also use funny Brazilian Portuguese slang right inside of the code.