Analysis by: Kenneth Guang Zheng Lee

 URL BLOCKING DATE/TIME: 02 May 2013 06:55:00 PM GMT-8
 RATING: HIGH
 DOMAIN: richlab.pl
 CATEGORY: Disease Vector
 DESCRIPTION:

BKDR_LIFTOH.DLF connects to this URL to send and receive commands from a remote malicious user. It spreads by using two worms, which use multi-protocol IM apps like Quiet Internet Pager and Digsby.