http://y.{BLOCKED}ws.su/p/c1.php

 Analysis by: Kenneth Guang Zheng Lee

 URL BLOCKING DATE/TIME: 02 May 2013 05:55:00 PM GMT-8
 RATING: HIGH
 DOMAIN: opennews.su
 CATEGORY: Disease Vector
 DESCRIPTION:

BKDR_LIFTOH.DLF connects to this URL to send and receive commands from a remote malicious user. It spreads by using two worms, which use multi-protocol instant messaging (IM) apps like Quiet Internet Pager and Digsby.