http://u.{BLOCKED}on.pl/p/c1.php

 Analysis by: Kenneth Guang Zheng Lee

 URL BLOCKING DATE/TIME: 02 May 2013 06:55:00 PM GMT-8
 RATING: HIGH
 DOMAIN: eastmoon.pl
 CATEGORY: Disease Vector
 DESCRIPTION:

BKDR_LIFTOH.DLF connects to this URL to send and receive commands from a remote malicious user. It spreads by using two worms, which use multi-protocol instant messaging (IM) apps like Quiet Internet Pager and Digsby.