69
Comodo Threat Intelligence Lab SPECIAL REPORT: SEPTEMBER 2017 – RANSOMWARE PHISHING ATTACKS LURE EMPLOYEES, BEAT MACHINE LEARNING TOOLS: Part III of the Evolving IKARUSdilapidated and Locky Ransomware Series If Your Copier / Scanner Calls, Don’t Answer (Until You Know It’s Really Them)

Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

Embed Size (px)

Citation preview

Page 1: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

Comodo Threat Intelligence LabSPECIAL REPORT:

S E P T E M B E R 2 0 1 7 – R A N S O M WA R E P H I S H I N G AT TA C K S L U R E E M P L O Y E E S ,

B E AT M A C H I N E L E A R N I N G T O O L S :

Part III of the Evolving IKARUSdilapidated and Locky Ransomware Series

If Your Copier / Scanner Calls, Don’t Answer (Until You Know It’s Really Them)

Page 2: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

2S P E C I A L R E P O R T

THREAT RESEARCH LABS

September 2017 Special Report (Part III of IKARUS/Locky Ransomware Series)

A late September wave of new ransomware attacks has occurred, building on attacks first

discovered by the Comodo Threat Intelligence Lab this summer. This newest campaign

mimics your vendors and even your trusty office copier/scanner/printer from industry

leader Konica Minolta. It uses social engineering to engage victims and is carefully

designed to slip past machine learning algorithm-based tools from leading cybersecurity

vendors, infect your machines, encrypt their data, and extract a bitcoin ransom.

Ransom demand in September 18-21, 2017 attacks.

This new, 3rd wave of related 2017 ransomware attacks uses a botnet of zombie computers

(usually connected to networks through well-known ISPs) to coordinate a phishing attack

which sends the emails to victims’ accounts. As with the 1st and 2nd waves, in early and

late August 2017 respectively, this campaign utilizes a Locky ransomware payload.

Page 3: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

3S P E C I A L R E P O R T

THREAT RESEARCH LABS

The larger of the two attacks in this 3rd Locky ransomware wave is presented as a scanned

document emailed to you from your organization’s scanner/printer (but is actually from

an outside hacker-controlled machine). Employees today scan original documents at the

company scanner/printer and email them to themselves and others as a standard practice,

so this malware-laden email looks quite innocent but is anything but harmless (and most

definitely is not from your organization’s Konica Minolta copier/scanner).

Email with subject “Message KM_C224e” looks like an email coming from the Konica Minolta (KM) C224e copier machine. As with real emailed scans, there is no text in the body of the email.

One element of the sophistication here is that the hacker-sent email includes the scanner/

printer model number that belongs to the Konica Minolta C224e, one of the most popular

models among business scanner/printers, commonly used in European, South American,

North American, Asian, and other global markets.

The Konica Minolta C224e.

Page 4: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

4S P E C I A L R E P O R T

THREAT RESEARCH LABS

September 18, 2017: Debut of “.ykcol” and Other Tricks

Both campaigns started on September 18, 2017, and appear to have effectively ended on

September 21, 2017. These two attacks differ. One is imitating an email coming from your

office copier /scanner machine (featuring the subject, “Message from KM_C224e”),

while the second one is designed to appear as an email related to a question about the

status of a vendor invoice (featuring the subject, “Status of invoice”).

In contrast to the initial 2017 IKARUSdilapidated Locky campaign (which distributed

malware with the “.diablo” extension and a Visual Basic Script (and has a “.vbs”

extension)), and the 2nd later in August in which the “.lukitus” extension via JavaScript

files were used, both September attacks have interesting variations aimed to not only fool

users with social engineering, but also to fool security administrators and their machine

learning algorithms and signature-based tools.

The encrypted documents in both September attacks have a “.ykcol” extension and the

“.vbs” files are distributed via email. This shows that malware authors are developing and

changing methods to reach more users and bypass security approaches that use machine

learning and pattern recognition.

Page 5: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

5S P E C I A L R E P O R T

THREAT RESEARCH LABS

Global Threat

Here is a heat map of the first new attack on September 18, 2017, featuring the “Message

from KM_C224e” subject line followed by the source countries of the machines used in

the botnet to send the emails:

Country Sum - Count Of Emails

Vietnam (VN) 26,985

Mexico (MX) 14,793

India (IN) 6,190

Indonesia (ID) 4,154

Page 6: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

6S P E C I A L R E P O R T

THREAT RESEARCH LABS

ISPs in general were co-opted heavily in this attack. This illustrates the sophistication of

the attack as well as endpoint cyber-defense inadequacies and ineffective network and

website security. Here are the leading range owners detected in the “Message from

KM_C224e” attack:

Range Owner Sum - Count Of Emails

Vietnam Posts and Telecommunications (VNPT) 26,985

VDC 14,793

Lusacell 6,190

Cablemas Telecomunicaciones SA de CV 4,154

Turk Telekom 2,168

Cablevision SA de CV 2,207

The smaller of the 2 prongs in this September campaign sends phishing emails with

the subject, “Status of invoice” and appears to be from a local vendor, even including

a greeting of “Hello,” a polite request to view the attachment, a signature, and contact

details from a fictitious vendor employee.

Example of “Status of invoice” phishing email in September 2017 IKARUSdilapidated attack.

Page 7: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

7S P E C I A L R E P O R T

THREAT RESEARCH LABS

When the attachment is clicked, it appears as a compressed file to be unpacked:

Here you can see a sample of the scripting, which is quite different than that used in

the attacks earlier in August 2017:

Page 8: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

8S P E C I A L R E P O R T

THREAT RESEARCH LABS

Here is another view of the “ransom note” which then appears:

The ransom demand range of .5 bitcoins to 1 bitcoin in both new cases mirrors that of the

August attacks. On September 18, 2017 the value of 1 bitcoin equaled just over $4,000.00

US Dollars (and 3,467.00 Euros).

This heat map illustrates detections of the September 18, 2017 attack featuring the “Status

of invoice” subject line. The Americas, Europe, India, and Southeast Asia were impacted

heavily, but Africa, Australia, and many islands were also hit by these attacks.

Page 9: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

9S P E C I A L R E P O R T

THREAT RESEARCH LABS

The Scope

The phishing and Trojan experts from the Comodo Threat Intelligence Lab (part of

Comodo Threat Research Labs) detected and analyzed more than 110,000 instances of

phishing emails at Comodo-protected endpoints within just the first three days of this

September 2017 campaign.

The attachments were read at Comodo-protected endpoints as “unknown files,” put into

containment, and denied entry until they were analyzed by Comodo’s technology and, in

this case, the lab’s human experts.

The Lab’s analysis of emails sent in the “Message from KM_C224e” phishing campaign

revealed this attack data: 19,886 different IP addresses were used from 139 different

country code top-level domains.

The “Status of invoice” attack utilized 12,367 different IP addresses from 142 country

code domains. There are a total of 255 top level country code domains maintained by the

Internet Assigned Numbers Authority (IANA), meaning both of these new attacks targeted

over half of the nation states on earth.

“These types of attacks utilize both botnets of servers and individuals’ PCs and

new phishing techniques using social engineering for unsuspecting office workers

and managers. This enables a very small team of hackers to infiltrate thousands of

organizations and beat A.I. and machine learning-dependent endpoint protection tools,

even those leading in Gartner’s recent Magic Quadrant.” said Fatih Orhan, head of the

Comodo Threat Intelligence Lab and Comodo Threat Research Labs (CTRL). “Because

the new ransomware appears as an unknown file, it takes a 100% ‘default deny’ security

posture to block or contain it at the endpoint or network boundary; it also requires human

eyes and analysis to ultimately determine what it is – in this case, new ransomware.”

Attack Data – A Deeper Dive

Diving into the data of the September 18-21, 2017 wave of attacks a bit deeper, the

Appendices below includes more details on the machines used in the attacks.

Page 10: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

AppendixNOTE: To compare the details of these September 2017 attacks with the two

IKARUSdilapidated campaigns of August 2017, see Part I and II of the Comodo Intelligence Lab

Special Report entitled, “SPECIAL REPORT: AUGUST 2017 – IKARUSdilapidated: Locky Ransomware

Family Back with a New Email Phishing Campaign Attack.” As the malware payload and ransom

elements are the same in all the August and September attacks, please see the original

Part I report to review those elements.

These special reports from the Lab (as well as other reports and updates)

are available to subscribers of Comodo Threat Intelligence Lab Updates.

Subscribe for free at: comodo.com/lab

THREAT RESEARCH LABS

Page 11: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

11S P E C I A L R E P O R T

THREAT RESEARCH LABS

Appendix A: “Message KM_C224e” Attack

Country Sum - Count Of Emails

VN 26,985 MX 14,793 IN 6,190 ID 4,154 CO 4,063 BR 3,837 TR 3,297 BO 1,615 AR 1,536 BD 1,123 PH 1,014 IR 986 TH 938 VE 774 IT 734 IL 622 PK 606 ES 565 PL 543 US 522 DO 511 EC 509 LA 455 MK 433 GT 413 KE 403 PE 390 DE 349 ZW 307 MN 295 PA 283 KH 282 BG 268 RS 263 JO 242 GR 235 MY 218 CL 215 RO 200 NI 191 HN 190 GB 174 ZM 174 CI 161 UY 157 FR 146

Country Sum - Count Of Emails

MM 137 ZA 133 NG 127 BE 125 SA 124 SG 121 CR 113 HR 107 NP 104 AU 103 BA 97 MA 93 EG 75 LY 71 CA 62 PS 57 AO 55 NL 52 ME 50 OM 49 CH 48 SV 48 AL 45 BT 44 JM 44 PY 43 UA 41 AT 40 SK 40 HU 38 UG 38 SC 34 MZ 33 DZ 31 KW 31 LB 30 CY 29 MU 27 HT 26 AF 23 DK 23 KR 23 TW 23 KY 21 LT 21 TZ 21

Country Sum - Count Of Emails

CD 20 PT 20 GH 19 GQ 19 NA 18 NZ 18 IE 16 NO 16 ML 14 SI 14 CN 12 ST 12 WS 10 CW 8 HK 8 PG 8 CM 7 FJ 7 IQ 7 LU 6 MT 6 BF 5 BW 5 JP 5 NC 5 RW 5 CZ 4 GE 4 TT 4 AG 3 BQ 3 KZ 3 MO 3 MV 3 TN 3 UZ 3 AE 2 BN 2 MG 2 VU 2 LK 1 LV 1 MH 1 MR 1 RE 1 SE 1 XK 1

Total Result 85,419

Page 12: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

12S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

Vietnam Posts and Telecommunications(VNPT) 18,824VDC 4,288Iusacell 3,558Cablemas Telecomunicaciones SA de CV 2,697Turk Telekom 2,618Cablevision, S.A. de C.V. 2,207Airtel Broadband 2,057Viettel Corporation 1,700Telmex Colombia S.A. 1,447Telmex 1,441Axtel 1,327Mega Cable, S.A. de C.V. 1,231CMC Telecom Infrastructure Company 961UNE 920No Range Owner 863TATA Communications 583FPT Telecom Company 545PT Indosat Tbk. 534Cablevision 522PT Telkom Indonesia 513Alestra, S. de R.L. de C.V. 487True Internet 465Mexico Red de Telecomunicaciones, S. de R.L. de C. 459FASTNET 449Bolivia S. A. 448Bharti Airtel 444Unitel 444Vivo 442Tv Azteca Sucursal Colombia 409Claro Dominican Republic 371Bezeq International 367Philippine Long Distance Telephone 365Telefonica Celular de Bolivia S.A. 339Cablemas Telecomunicaciones (merida) 335Telefonica Venezolana 324DCTV Cable Network Broadband Services 323Virtua 303Bharti Broadband 295ETB 283Telefonica de Argentina 272SHATEL DSL Network 271Aamra Networks Limited 264Telecom Italia 252Aria Shatel Company Ltd 248Telefonica del Peru 248Oi Internet 246CANTV 244COTAS 243Global Village Telecom 242Mahanagar Telephone Nigam Ltd. 235Internet Service Provider 231Blizoo DOOEL Skopje 227Ecuadortelecom S.A. 221

Navega.com S.A. 220Tellcom Iletisim Hizmetleri A.s. 220NSS S.A. 219MPLS ADSL Broadband 202Transtelco S.A. 201Fastweb 200Vietnam Posts and Telecommunications (VNPT) 191PERN AS Content Servie Provider, Islamabad, Pakist 189Three Indonesia 186Eastern Telecoms Phils., Inc. 185Baru Hosting 183VietNam Telecom National 177Oi Velox 176Airtel 171Neda Gostar Saba Data Transfer Company Private Joi 170afczas 166National Telecommunication Corporation HQ 1663BB Broadband 164TM Net 163Orange Polska 161PT Media Sarana Data 160In2cable.com (India) 158Media Commerce Partners S.A 157TRD ROBI DOOEL 153SINET, Cambodia’s specialist Internet and Telecom 152Cote d’Ivoire Telecom 151Syscon Infoway Pvt. 151Comteco Ltda 150Cotas Ltda. 148D-Vois Broadband Pvt 135Administracion Nacional de Telecomunicaciones 134ACCESSKENYA GROUP LTD is an ISP serving 131RailTel Corporation of India Ltd. 128Chi nhanh MienBac-Cong ty CP Ha Tang Vien Thong CM 126Net Uno, C.A. 126ONECOM 124Mongolia Telecom 123TRICOM 123Vodafone Ono 121S.A. E.s.p 120CTBC 118Information Society S.A. 114PT Tele Globe Global 114Bharti Airtel Ltd., Telemedia Services 111Assign for BuddyBB customers 110Entel S.A. - EntelNet 110Telefonica de Espana 109Transworld Associates (Pvt.) Ltd. 109Internet by Sercomtel S.A. 107Global Iletisim Hizmetleri A.S. 106Tata Indicom 106Telecomunicacoes Ltda 105SingNet Pte Ltd 103

Page 13: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

13S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

PT. Cyberindo Aditama 100012 Smile Communications 98Neuviz Net 98Time Warner Cable 96Proximus Skynet 95IPNXng 94Satnet 94Asianet 92Delta Infocom Limited 92S.A. E.s.p. 92TELEKOM SRBIJA a.d. 92Mob Telecom 90Galaxy Brasil Ltda 88Nepal Telecom 87S.I Group 86Vivacom 86Universidad De Antioquia 84Tele Globe Global, PT 83Comcast Cable 82EMCATEL 82Pars Online PJS 82B.Net Hrvatska d.o.o 81Deutsche Telekom AG 81Jazz Telecom S.A. 81Natural Fenosa Telecomunicaciones Guatemala S.A. 81Varnion Technology Semesta, PT 81Angel Drops Ltd 80Linkdotnet-Jordan 77Micom-network-corporate-cust 77Vodafone DSL 77Sify Limited 76Tata Teleservices Maharashtra Ltd 76Olo del Peru S.A.C 75Telefonica Data S.A. 75AXS Bolivia S. A. 74BDCOM Online Limited 74Cyfrowy Polsat MVNO mobile broadband services 74DSL-Elektronika d.o.o. 74Cablevision S.A. de C.V. 73Citinet LLC 73PT Solnet Indonesia 73Viewqwest Pte Ltd 72Cablecolor S.A. 71Cotel Ltda. 71Gtel Tijuana 71Kabel Deutschland 71Libyan Telecom and Technology 70Netnam Company 70Southern Online Bio Technologies Ltd 70SOLNET-Customer-Serial 69Telstra Internet 69Orange Espana 66Tata Teleservices ISP 66

RCS & RDS Business 65VTR Banda Ancha S.A. 65Telecom Argentina S.A. 64Telefonos del Noroeste, S.A. de C.V. 64Clouditalia Telecomunicazioni S.p.A. 63Batelco Jordan 62Empresa De Telecomunicaciones De Pereira S.A. 62Telone 62CS LoxInfo 61Meghbela Broadband 61Vodafone Spain 61Jogja Medianet 60Redes y Telecomunicaciones 60Telecentro S.A. 59PT. Net2Cyber Indonesia 58Dishnet Wireless Limited. Broadband Wireless 57Telefonia Celular de Nicaragua SA. 57Triple Play Broadband Private Limited 57Md. Abdul Awual t/a Cyber Way Technology 56delDSL Internet Pvt. Ltd. 55Jupiter Telecomunicacoes e Informatica Ltda 54Wifirst S.A.S. 54MNC Playmedia 53TalkTalk 53Vodafone Italia DSL 53Nova Rede de Telecomunicacoes Ltda 52TurkNet Iletisim Hizmetleri A.S 52UPC Romania SRL 51Azteca Sucursal Colombia 49kasatech informatica 49Telgua 49Honesty Net Solution (I) Pvt 48Konecta de Mexico, S. de R.L. de C.V. 48YOU Broadband & Cable India Ltd. 48Skyline Semesta, PT 47TE Data 46BRAC BDMail Network 45Orange Israel 45SaudiNet 45Comcast Business Communications 44Dai IP tinh cho khach hang xDSL 44DrukNet ISP 44Maxcom Telecomunicaciones, S.A.B. de C.V. 44PT. Usaha Adisanggoro 44Quest Consultancy Pvt Ltd 44Tim Celular S.A. 44PT Quantum Tera Network 43Techtel LMDS Comunicaciones Interactivas S.A. 43Telkom Internet 43UPC Polska 43ADN Telecom Ltd 42Crnogorski Telekom a.d.Podgorica 42Telconet S.A 42

Page 14: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

14S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

Afrihost 41Beam Telecom 41LINKNET 41TELEKOM SRBIJA, ADSL users 41Wsp Servicos de Telecomunicacoes Ltda 41Cable Onda 40Jordan Tv Cable & Internet Services Co 40Operbes, S.A. de C.V. 40S De Rl De Cv 40Ver Tv S.A. 40Ifx Networks Colombia 38Itelkom S.A.S 38OTEnet S.A. 38Tellas S.A. 38Akton d.o.o. Network 37PT.Mora Telematika Indonesia 37Telematix/ Enitel 37D-VoiS Broadband Private Limited 36Dinhubkominfo Pemprov. Jawa Tengah 36Dishnet Wireless Limited 36Global Crossing Colombia S.A. 36PURISCAL 36TVCabo Angola 36Cablevision Red SA de CV 35Comilla Online 35Movistar Chile 35Polkomtel Sp. z o.o. 35PT Hyperindo Media Perkasa 35Superonline Iletisim Hizmetleri A.S. 35Tehran Kar Ara 35INDO Internet, PT 34Nacional De Telecomunicaciones - Cnt Ep 34PADINET - Padi Internet 34PT. Palapa Media Indonesia 34Verizon FiOS 34Wananchi-ke 34Broadband Pacenet Pvt. 33Cable Tica 33CPS 33Indosatm2 33KNK Telekomunikasyon Iletisim Elektrik Sanayi Tica 33NETCEN Teknoloji Ltd. Sti. 33NETLIFE 33Pt Selaras Citra Terabit 33Tata Mobile 33TVCABO - Comunicacoes Multimedia, Lda. 33WIND Telecomunicazioni S.p.A 33Delhi Gsm Ip Pool 32Media Antar Nusa PT. 32PT DES Teknologi Informasi 32Pt. Matrixnet Global Indonesia 32TeleCable 32Vsat- Telecomunicacoes Ltda 32

X-Link Limited 32Charter Communications 31Diogo Cassio Cabral Me 31IDS Bangladesh. IP Transit provider. Dhaka, Bangla 31L E M Telecomunicacoes Ltda -me 31Sul Americana Tecnologia e Informatica Ltda. 31Axtel - Recursos WiMAX 30Cyprus Telecommuncations Authority 30IFX Corporation 30Israel Local Authorities Data Processing Center Lt 30Metro Net, S.A.P.I. de C.V. 30Milleni.com 30PT Comtronics Systems 30Telecable Economico S.A. 30Centennial Cayman Corp Chile S.A 29Globalreach eBusiness Networks, Inc. 29IPStaticMarocTelecom 29Servnet Mexico, S.A. de C.V. 29Telecentro S.A. - Clientes Residenciales 29Cablemas Telecomunicaciones (tijuana) 28Is Net Elektonik Bilgi Uretim Dagitim Ticaret ve I 28Luis Antonio Palomino Dagdug 28PT. Pasifik Satelit Nusantara 28Equipos Y Sistemas S.A. 27Hireach Broadband Private Ltd 27Kenyan Post & Telecommunications Company / Telkom 27PT iForte Global Internet 27PT. Bangun Abadi Teknologi Indonesia 27Safaricom 27Telecomunicaciones MOVILNET 27Zajil Telecom 27Access Haiti S.A. 26Blizoo Media and Broadband 26BT 26COOLLINK 26Gtd Internet S.A. 26Inwi Mobile 26Smart Link Communication 26Telecel S.A. 26Telefonica Movistar 26Three 26Universitas Ahmad Dahlan 26Yota De Nicaragua 26Bangladesh Online Ltd 25Compuservice.Net Internet Provider LTDA-ME 25Ctbc Multimidia Data Net S/a 25Etisalat Misr 25Internet Thailand Company Limited 25Megacable Comunicaciones de Mexico, S.A. de C.V. 25Melsa-i-net 25Telecom Ltd 25Bharti Cellular Ltd. Mumbai 24Cable & Wireless Jamaica 24

Page 15: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

15S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

Center Prestadora Servicos S/C Ltda 24Cogetel Online 24CONECEL 24Daisy Communications Ltd 24Fixed IP for cable modem customers 24Globe Telecom 24Hotel Paramount 24Level 3 Communications 24Pt Bina Informatika Solusi 24SFR 24Toseh Ertebatat Homa (Private Joint Stock) 24Vung dia chi IP cap cho dich vu IPTV tai Ha Noi 24Wana Corporate 24B.b.g Campelo Me 23Etihad Atheeb Telecom Company 23Inetku-PBM 23Korea Telecom 23Telecomunicacoes Ltda. 23Wateen Telecom 23AlwaysOn Network Bangladesh 22Comcel Guatemala S.A. 22Golden Telecom LLC 22IP Teknologi Komunikasi, PT. 22Mobily 22Pulse Telesystems Pvt Ltd 22Serbia BroadBand-Srpske Kablovske mreze d.o.o. 22Tiscali SpA 22Velco Globalnetwork 22Wan & Lan Internet Pvt 22Apollo Online Services Pvt ltd 21Augere Wireless Broadband Bangladesh Limited 21Blicnet d.o.o. 21BTC Broadband Service 21Cablemodem-ip-dinamica - Generico Ip Cmts Prg 21Communication Solutions Ltd. 21Completel 21ConnectIB IP Space 21COTELCAM 21EarthLink 21Maria Irma Salazar 21PT Maxindo Mitra Solusi, Jl Kelapa Puan Raya Blok 21PT Rahajasa Media Internet 21Reliance Communications 21Telefonica Moviles El Salvador S.A. de C.V. 21Thiel e Da Rosa Ltda 21TRUE, The Real Unix Experts 21Universitas Negeri Semarang 21Virtex Ltda 21Vodafone Italia 21VTX Services SA 21XFone 21ZONE Technologies Ltd 21Consulnetworks Ltda. 20

e-Novations ComNet 20FLOW 20Hostlocation Ltda 20L. Garcia Comunicacoes ME 20National Information Technology Authority Uganda 20Play 20Sodetel S.a.l. 20TM International Bangladesh 20TRIPLEPLAY INTERACTIVE NETWORK PVT LTD 20BeotelNet-ISP d.o.o 19Corporacion Nacional De Telecomunicaciones - Cnt E 19Etisalat Afghan 19EWE-Tel GmbH 19Excellmedia 19Greater Amman Municipality 19INFV+ 19Intelvision Ltd 19Inversiones Apolo S.A. de C.V. 19Konnet Informatica Ltda 19Mediacom Cable 19Panda Network 19Paratus-Telecom 19PT Remala Abadi 19RAHANET Network 19RCS 19Sspnet Com De Equip. De Tele Informatica 19Systel Systemy Teleinformatyczne M. Linscheid Spol 19Tecnowind S.A. 19Telecom Eireli 19TOT 19Triple Play Teleservices Private Limited 19Vectra Broadband 19Vodafone Ghana 19WHS Telecom Serv. Telecomunicacoes LTDA 19Yashtel 19Contabo GmbH 18Cromtel Prod Impex Srl 18Fernando Nagel e Cia. Ltda. 18LCR Telecom NV 18Mahbub Morshed t/a Mahi Enterprise 18Nikem Net 18PrimaNet - PT. Khasanah Timur Indonesia 18PT. Hipernet Indodata 18Software Technology Parks of India - Bangalore 18Solusindo Bintang Pratama, PT 18Suddenlink Communications 18Telekom Austria 18UAB Bite Lietuva 18Vodafone India 18ADA Holding - ADA AIR sh.p.k. 17Bayan Telecommunications Inc. 17E-SBL.NET sp. z o.o. 17Empresa de Infovias S.A. 17

Page 16: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

16S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

Imatech Networks, S.A. de C.V. 17INB Informatica ltda 17Media Sac 17Office of the basic education commission 17Pacifico Cable S.A. 17PSA S.r.l. 17Ramiro Alfonso Gomez Caicedo 17Syd Energi Bredbaand A/S 17Telecom Namibia 17Telefonica Germany 17TelOne(formerly ZPTC) 17TOPNET 174ALB shpk 16Bluebird Network 16Broadband ISP, FTTH and Cable Service Provider 16BSW 16Cablenet S.A 16Digital Network Associates Private Limited 16Epm Telecomunicaciones 16Global Tecnologia Ltda Me 16ICS Advanced Technologies 16Intelligent Technologies S.A. 16Maxis Broadband Sdn Bhd 16MetroCast 16Mobilink Mobile Internet 16Orange Polska Mobile 16Protel I-Next, S.A. de C.V. 16Redes y Comunicaciones de Michoacan S.A. de C.V. 16Tecmidiaweb Ltda 16Telecable Central, S.A. 16UNICS Ltd 16Wind Telecomunicazioni 16Aamra technologies limited 15blueconnect 15Cable and Wireless (Seychelles) Limited 15Cooperativa Telefonica Pinamar Ltda. 15Costra S.A. 15El Salvador Network, S. A. 15Empresa de Recursos Tecnologicos S.A E.S.P 15Fiber customers 15HiNet 15Internet Access & Telecom Carrier Service Provider 15Jastel Network co.Ltd 15MTN Uganda 15MWEB 15ONO 15PT NIDS Indonesia 15Rasaneh Avabarid Private Joint Stock Company 15RCN 15Satellite Connection 15Symbolics 15Teknotel Telekomunikasyon Sanayi Ve Ticaret A.s. 15TPG Internet 15

XFone 018 15Y Sistemas S.A. 152Bite s.r.l. 14Afribone Backbone + WLL 14ARSAT - Empresa Argentina de Soluciones Satelitale 14Atel Telecom 14BBBell s.r.l. 14Brasileira De Telecomunicadoes Sa-embratel 14Bucharest, Romania 14Coolnet New Communication Provider 14In2cable (India) Ltd. 14INEA Network 14Internet Group Ltd 14Jordan Data Communications Company LLC 14KPN 14Maroc Telecom 14Metronet telekomunikacije d.d. 14Optisprint 14Provedor De Acesso A Internet Ltda 14PT Arana Teknologi Indonesia 14PT. Supernet Advance Teknologi 14PT.Insan Sarana Telematika 14Ranks ITT 14Sapthagiri College of Medical Sciences,Banglore 14Soluciones en Telecomunicaciones, S.A. 14Teledifusora S.A. 14The Houses Television C.A. 14UPC Hungary 14Vodacom 14Voztelecom network 14Ziggo 14Acier Airport Steel 13AlphaLink 13Asre Enteghal Dadeha 13BCI Telecommunication Advanced Technology Company 13Broadlink Nepal 13CityOnline Services Ltd 13CNS Systems s.r.o. 13Columbus Networks USA 13Comclark Cable 13conecta telecom ltda 13Convergenze S.p.A. 13GETESA (Orange Equatorial Guinea) 13Iceberk 13Infocom-ug 13Informatica E Provedor Ltda 13Informatica y Telecomunicaciones S.A. 13Ingenieria e Informatica Asociada Ltda (IIA Ltda) 13Invitel Tavkozlesi Zrt. 13J E Provedor de Rede de Comunicacao Ltda 13KurumsalLanmix 13Line Telecomunicacoes Ltda 13Linktel Telecomunicacoes Do Brasil Ltda 13

Page 17: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

17S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

Liquid Telecommunications Operations Limited 13Neunet S.A. 13Orange Slovensko a.s. 13PON Services 13PT Jembatan Citra Nusantara 13PT Mega Mentari Mandiri 13SACI 13SAT-TRAKT Telecommunications 13T-2, d.o.o. 13Tanzania Telecommunications 13Telecom Ltda 13TIGO COLOMBIA 13V Telecoms Berhad 13Virgin Media 13World Internetwork Co.,Ltd , Thailand. 13ADISTA SAS 12Areca Business Center Srl 12ASRE ENTEGHAL DADEHA - Broadband Services 12Cablecom GmbH 12CJONLINE ISP India 12Clientes Guayaquil 12Companhia Santomense de Telecomunicacoes 12Elkuds University 12Empresa De Informatica E Telecomunicacoes 12G TEL Comunicacion, S.A.P.I. de C.V. 12Global Crossing Comunicacoes Do Brasil Ltda. 12IACTCOM 12Indian Institute Of Logis 12Logic Pro Tecnologia 12MauritiusTelecom 12Mundivox LTDA 12Network Ltda 12Norfolk Hotel 12One Macedonia 12Orion Telekom Tim d.o.o.Beograd 12PT. Cahaya Buana Raksa 12PT. Lintas Data Prima 12Rebapnet Telecomunicacoes 12Rede Connect Telecom 12salt Lake,Sector-V,Electronic Complex 12Shiraz Hamyar Co. 12Tecnologia E Equipamentos 12Telecable de Asturias,SA 12Telenor d.o.o. Beograd 12Tomato Web (Pvt) Limited 12Triple C Computation Ltd. 12Wds Telecom Ltda. Me 121telecom Servicos De Tecnologia Em Internet Ltda 11AUGERE-Pakistan 11Be Un Limited 11BRACNet Limited 11Britis Telecom LTDA 11Chi nhanh HCM-Cong ty CP Ha Tang Vien Thong CMC 11

Digital Cable Television ltd 11Digital Ocean 11E Aguiari Provedor De Internet 11Empresa de Telecomunicaciones de Pereira S.A. E.S. 11Fivenetwork Solution India Pvt Ltd Internet 11Grupo Hidalguense de Desarrollo, S.A. de C.V. 11hellas online Electronic Communications S.A. 11Informatica Ltda 11Jazztel Mobile 11Level 3 Colombia S.A. 11LINKdotNET Telecom Limited 11Lynet Internett AS 11Malaysian Research & Education Network 11MNI Telecom S.A. 11Neamul Haque Khan t/a Mazeda Networks Limited 11Netia SA 11Ngs-adsl Users Shz 11OCPT 11PARO SA 11PT Cyberplus Media Pratama 11PT Sampoerna Telemedia Indonesia 11PT. Cross Network Indonesia 11SAGLAYICI Teknoloji Bilisim Yayincilik Hiz. Ticare 11SaskTel 11Servicos De Telecomunicao Ltda 11Shree Cable 11Sixsigma Networks Mexico, S.A. de C.V. 11Skyware Sp. z o.o. 11StarHub Cable Vision Ltd 11Stetnet Telecom 11Telecom Ltda. 11Television Internacional, S.A. de C.V. 11ABSOLUT SOLUTIONS d.o.o. 10Adylnet Telecom 10Almenara On Line Ltda 10China Telecom jiangsu 10Cooperativa de Electricidad y Servicios Publicos d 10Departemen Energi dan Sumber Daya Mineral 10Eastern Telecom Philippines Inc. 10Euskaltel S.A. 10Intech Online Private Limited 10Jasa Terpadu Telematika 10Kabel BW 10M-net 10Ministry of Finance 10New Group Telecomunicacoes LTDA 10Nour Communication Co.Ltd - Nournet 10Paknet Limited Merged into PTCL 10Panamaserver.com 10Plim Telecom 10PT Comunicacoes 10PT Parsaoran Global Datatrans 10QSC AG 10

Page 18: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

18S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

S.A. De C.v. 10SamoaTel Limited 10Satnet Cuenca Cable Modems 10Satnet Uio 10Servicos de Internet LTDA 10Subhi Muhideen Al Qabani trading as Wideband Est 10TEISA 10Tele2 Telecommunication GmbH 10The Blue Zone East / Jordan 10TRI.ph AS Inter-Island Information Systems, Inc. 10UnionCOM 10Vodafone New Zealand 10VOO 10Asmanfaraz Sepahan Isdp (pjs) 9Autonomous System Number for Nexlinx 9Bcl South 9CenturyLink 9Comunicacao E Informatica Epp 9Content Deliferi Network 9Forthnet 9Grahamedia Informasi, Pt. 9Hito S.a.p.i. 9Level 3 Argentina S.A. 9Link3 Technologies Ltd. 9LulinNet 9Micropic Ltda 9National Institute of Technology, Srinagar 9Oasis-sprl 9OptiMax COmmunication Ltd 9Pt Indonesia Comnets Plus 9Rasana Pishtaz Network 9Rede Brasileira de Comunicacao Ltda 9SAN JOSE 9Satnetcom Balikpapan PT. 9Sky Broadband 9Skylogic S.p.A. 9Soares & Lira Ltda 9Tecnowireless Telecom Ltda 9Unitymedia NRW GmbH 9Universidad Francisco De Paula Santander 9A. L. A. Informatica Ltda. 8Abastecedora de Conectividad, S.A. de C.V. 8Agencia Aduanera de America en Mexico S.C. 8Alcoa Aluminio S/A 8Asretelecom-ardabil Isp 8Azadnetrasaneh Private Joint Stock Company 8Batista Dos Santos E Cia Ltda Me 8Bayanat NOC IP range 8BSkyB Broadband Ireland 8Call U Communications Ltd. 8Cbeyond Communications 8Citycom Networks Pvt Ltd 8Fiber @ Home Limited 8

FORTHnet SA 8Globalnet.hn 8IndoInternet Network 8Integrated Measurement Systems 8Interjato Servicos de Telecomunicacoes Ltda. 8Javne adrese za ADSL korisnike 8MyKRIS Asia Sdn Bhd 8New Wave Communications 8Operateur Mobile en Cote d’Ivoire Telecom 8Pakistan Telecommunication Company Limited 8Pardis Ettela Resaan Sepehr 8Politechnika Czestochowska 8PT Duta Medialink 8PT Fiber Networks Indonesia 8Pt. Linknet 8Railtelibwcustomers 8Red Intercable Digital S.A. 8Sabanet Qom 8Satnet Cuenca Cor 8Telecom Ltda Epp 8Teletrans SA 8The Communication Authoity of Thailand, CAT 8Tripleplay Broadband Pvt Ltd 8United Telecommunication Services (UTS) 8Universal Assistance Sociedad Anonima 8Universitas Jember 8Universitas Udayana 8WHS Telecom Serv. Telecomunicacoes LTDA 8Worldcall Telecom Limited 8ZAMTEL 8A Multihomed ISP Company 7Alfanumeric S.A. 7Americatel Peru S.A. 7Bharti Airtel Limited 7Colinanet Srl. 7Computech Tecnologia Ltda. 7Connect Internet Services Limited 7countrywide 7Digital Servicos De Informatica E Comercio 7Embratel 7Evergy S.A. 7Global Tech Internet Banda Larga EPP - ltda 7Globe Telecoms 7Grameen Cybernet Ltd. Bangladesh. 7Ha Noi Post and Telecom Company 7Infoline - Comunicacoes e Informacoes Eletronicas 7Internet Union Spolka Akcyjna 7Ipko Telecommunications 7KOBA Sp. z o.o. 7MyRepublic Ltd (Singapore) 7Netvigator 7Networks Ltda 7Newcom Limited 7

Page 19: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

19S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

OnNet Telecomunicacoes LTDA - ME 7Planet Online Laos 7PowerTel 7Procono S.A. 7PT. Eka Mas Republik 7PT. First Media, Tbk 7Rangsit University 7Rg Silveira Ltda 7Silica Networks Argentina S.A. 7SOL-Customer-MIX 7Supply Net Servicos Ltda - ME 7Tarin General Trading and Setting Up Internet Devi 7Telecall Brasil Servicos de Telecomunicacoes Lt 7Telecom Ltda Me 7Telefonica Empresas 7Telefonica Movil De Chile S.A. 7Tri Telecom 7TTCLDATA 7UPC Austria GmbH 7ZON Tv Cabo 7Ampernet Telecomunicacoes LTDA 6Belnet Snina, s.r.o. 6Communications 6Corporacion Politecnica Nacional De Colombia 6COTES Ltda. 6De Comunicaciones Y Transportes Coordinacion De La 6Dtpnet Nap 6Five network Broadband Solution Pvt Ltd 6Freitas Servicos de Internet Ltda 6Guineanet 6HostSlim Global Services BV 6Hoteli Zivogosce d.d. 6Intercampo Empreendimentos Tecnologicos Ltda 6Interdomain Routing 6Lafaiete Provedor de Internet e Telecomunic Ltda 6Luxembourg Online S.A. 6Mobiltel Ead 6MTN Nigeria 6neojaime oliveira ribeiro me 6Pogliotti & Pogliotti Construcciones S.A. 6Primesoftex 6PT Mitra Akses Globalindo 6R R Multimidia Ltda - Me 6Rainbow communications India Pvt Ltd 6SingleHop 6Soares & Aguiar Ltda Me 6Sulanet SA / Insetec Group 6UltraNet - Vicente Juliano M Carvalho ME 6Vasai Cable Pvt. Ltd. 6Vex Net Telecon 6Webnet Solucoes Em Internet Ltda 6Wnetsistem Comercio e Servicos de Informatica Ltd 6& Aguiar Ltda Me 5

Agni Systems Limited 5AgresteNet Com e Serv LTDA - ME 5AIS Mobile 5Algerian Academic Research Network 5Amnet IT Services Pty 5Cable El Salvador S.A. De C.v. 5Cable Video Color SRL 5Co.pa.co. 5Conesul Telecomunicacoes Ltda 5Conjoinix Technologies Pvt. Ltd. 5Conrado Cagnoli 5Cooperativa Telefonica Carlos Tejedor Ltda. 5Digicel (PNG) Ltd 5Directnet Prestacao de Servicos Ltda. 5Dodo Australia 5EARTH TELECOMMUNICATION (Pvt) 5FERO Agnieszka Budner 5ICNC LLC 5Informatica e Telecomunicacoes Ltda. 5Intech Online Pvt Ltd 5Internet Solutions 5Latam Brasil Ltda 5Lintas Data Prima, PT 5Marcatel Com, S.A. de C.V. 5MTNRW 5Offratel Ap 5ONATEL/FasoNet’s 5Orange 5Rise Asia Technology Limited 5Sarnica-Net 5Selectcom Telecom 5Telecom Services (DLI/WLL) Provider 5Telefonica Publica y Privada S.A. 5Telekom Romania Communication S.A 5TeliaSonera AB 5Telkom 5TelkomInternetBroadband 5Telrad Telecommunication and Electronic Industries 5Terrakom d.o.o. 5TerraNet sal 5Vale Ltda 5Vocus Communications 5Wlenet Informatica manutencao 5Afghan Wireless 4All Net Informatica Ltda 4AMWireless Uruguay SA 4Arya Sepehr Ettelarasan Tehran 4Auro International School Of Hospitality Managemen 4Bartlomiej Sztefko trading as Bartlomiej Sztefko G 4Bharti Airtel Ltd., TELEMEDIA Services, for SMB cu 4Brennercom S.p.A. 4Broadband Plus 4BSNL 4

Page 20: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

20S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

Btc-gate1 4Click Tecnologia e Telecomunicacao Ltda 4CMPak Limited 4Columbus Networks Panama 4Comercio De Telefonia E Comunicacao Ltda 4Comunicaciones S.A 4Connect Network 4Customers Procono 4Cyta Hellas 4Dadeh Gostar Asr Novin P.J.S. Co. 4Domtel Telecom Dariusz Dombek 4EDIS GmbH 4ENERGOTEL a.s. 4Etisalat 4Ewinet C.A. 4Frontiir Co. Ltd 4Gabriel Fernandes Galvao Informatica - ME 4Gigacable de Aguascalientes, S.A. de C.V. 4Global Crossing Argentina - Backbone 4Grupo Empresarial Mexicano en Telecomunicaciones 4Hathway 4Inter-Island Information Systems, Inc 4ISP External Zone 4Jordan Telecommunications Company 4JSC Silknet 4Lao Telecom Communication, LTC 4Loxley Wireless Co., Ltd. 4Madritel 4Magyar Telekom 4Melita plc 4Microdata de Lucelia Servicos de Provedores Ltda 4Middle East Internet Company Limited 4Multinet Pakistan Pvt. Ltd. 4NET LTDA 4Net Servicos De Informatica Ltda - Me 4Net1 4NetJat Provedor de Acesso a Internet 4Netspeed Ltda 4Nettlinx Limited 4Network Operations Center 4NextGenTel AS 4Orolix Desenvolvimento de Software Ltda. 4Philippine Long Distance Telephone Company 4PrimeTel Services Inc. 4PT Net2Cyber Indonesia 4PT. DATA Utama Dinamika 4PT. Indomaya Wira Sejahtera 4Pt. Uninet Media Sakti 4R Cable 4RINGO S.A.’s customers in Douala. 4Sc Multimedia Network Srl 4Servico Comunicacao Multimidia Ltda 4Sikka Infratech Pvt. Ltd 4

Software Company 4Spark New Zealand 4Sulcom Informatica Ltda 4Symphonet Sdn Bhd 4Telecom Personal 4Telecommunication Services of Trinidad and Tobago 4Telecomunicacoes Ltda 4Telgo Telecomunicacoes Goias Ltda. 4Tevisat, S.A. 4Tiscali UK Limited 4True Broadband Service 4Univers Net Com SRL 4Universitas Mercu Buana Yogyakarta 4University of Santo Tomas 4Via Real Internet Equipamentos de Informatica Ltda 4Vihaan Telecommunication Pvt. Ltd. 4Wnet telecom pvt ltd 4013 Netvision 32DAY Telecom LLP 3Access Telecom (BD) Ltd 3Acer Telecomunicacoes ltda 3Acesso Comunicacoes Ltda - Me 3ACN DSL 3Adelphia Comunicacoes S.A. 3Agentia de Administrare a Retelei Nationale de Inf 3Amazonia Publicidade Ltda 3AmberIT Limited 3Angkor Data Communication 3Argentina S.A. 3Asses. em Servicos de Inform. e Telecom. Ltda 3AT&T Wireless 3AVAST Software s.r.o. 3Bharti Telenet Ltd.mumbai 3Bom Tempo Informatica Ltda 3Cameroon Telecommunications Network 3Chiang Mai University 3Comercio De Inform E Telecomunicacoes Ltda 3Companhia de Telecomunicacoes de Macau SARL 3Customer wireless connectivity link addresses 3CV Argon Data Interkoneksi 3Datec-PNG 3Derkom Spolka Jawna Dariusz Klimczuk 3Dhivehi Raajjeyge Gulhun (Dhiraagu) 3Digicel Antigua 3Digital Network Associates Pvt 3Eircom 3Engenharia 3Exe Net Cable & Wireless Accounts 3Fibra Telecom Ltda - EPP 3Formatto Net Ltda 3Gas Natural Fenosa Telecomunicaciones Costa Rica S 3GPON Services 3Hellas On Line S.A. 3

Page 21: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

21S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

Inalambrico Dedicado S.A. De C.v. 3Indusind Media and Communications Ltd. 3Infocom Ltd 3Informatica Ltda - Me 3Infortel Telecomunicacoes e Servicos Ltda. 3Ingelcom Ltda 3Internet Initiative Japan Inc. 3Internet Solution & Service Provider Co., Ltd. 3Intervip Networks Ltda. 3Invistanet Provedor de Acesso Ltda ME 3Janaja Servicos Ltda 3Jasa Terpadu Telematika (Jasatel) 3KurumsalLanAvrupa 3Leased line service 3Megacarrier Telecomunicaciones S.A de C.V. 3Metrotel SA ESP 3Monte Alto Net Ltda 3Nayatel (Pvt) Ltd 3Net.com Telecomunicacoes Ltda 3Network for Learning 3NGI SpA 3Office Master Com. e Prestacao de Servicos LTDA 3Oi Fixo 3Orbit Telecom Technology Co. Ltd 3Pronet sh.p.k. 3PSTN Telecom Oparetor 3PT Diara Kencana Indonesia 3PT Indosat Tbk 3Qualitynet 3R e R Informatica LTDA 3Radius Telecoms, Inc. 3Rasa Internet Services 3Retecal Sociedad Operadora de Telecomunicaciones 3Servicos De Telecomunicacoes Ltda 3Sikka Broadband Pvt. 3Sikka Cable 3Siticable Network Limited 3Srm Easwari Engineering College 3Technologies S.a.c. 3Telecom E Informatica Ltda 3Telefonia Bonairiano N.V. 3Tennet Telecom Srl 3Tiscalinet 3UNIMOS 3Universitas Pattimura 3UPC Ireland 3Uzbektelekom Joint Stock Company 3Verizon Wireless 3Videotron Ltee 3Vietnam Technology and Telecommunication JSC 3Villages around Stara Zagora 3Vodafone Net Iletisim Hizmetleri A.s 3WiBand Communications 3

Worldcall Broadband Limited 3YUnet International d.o.o. 3ZOL GPON Home Users 3012 Smile 2116 Madhav Darshan 2Aftab IT Limited. 2Alexandre Lacerda Rodrigues ME 2AMX Paraguay SA 2Banco Central de Reserva 2Bittel Telecom Pvt Ltd 2Branch of Netnam Company in Ho Chi Minh City 2Bright Technologies Limited 2Brightview ltd 2Cablemodem-ip-dinamica - Generico 2Centre de Calcul el-Khawarizmi - CCK 2Chiang Mai Vocational College 2Claro Peru 2Clean Net Telecom Ltda 2Click Internet Turbo 2Cogent Communications 2Commission on Science and Technology for 2Coop. Telef. de San Vicente Ltda. 2Costarricense 2CTITECH Tecnologia da Informacao Ltda. 2DOCSIS clents in Pripor 2DOCSIS clents in Radishani 2DOZE 2Drustvo za telekomunikacije Orion telekom doo Beog 2Electronic Box 2EMI Net Telecomunicacoes Ltda 2Entel PCS Telecomunicaciones S.A. 2ESCOM Ltd. - Haskovo 2Eskisehir Bilisim Iletisim San. ve Tic. A.S. 2Esv Electronics Service Venezuela 2Ethernet Xpress Pvt. Ltd. 2Fastel Sarana Indonesia PT 2Free SAS 2Global Telecommunication Service Provider 2GO p.l.c. 2Gpon Pool 2GramBangla Systems Limites, Internet and Data Comm 2Hellas On Line SA - DSL 2Herault Telecom 2Ho Chi Minh City Post and Telecom Company 2Honesty Net Solutions (India) Pvt. Ltd. 2Hoshin Multimedia Center Inc 2Hosting Internet Hizmetleri Sanayi ve Ticaret Anon 2IFX Networks Venezuela C.A. 2Information Technology Company (ITC) 2Informatica Ltda 2Infracom Italia S.p.A. 2Integral University,Lucknow 2Internet Para Todos - Gobierno de La Rioja 2

Page 22: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

22S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

IriisNet communication Pvt Ltd 2Joao M. S. de Almeida junior & Cia ltda 2Kavish online services private limited 2LINKBG Dobrich NET 2M & M Telecomunicacoes Ltda 2M1 Ltd 2MacroLAN 2Md. Shariful Islam T/A BRISK SYSTEMS 2Meteor Mobile Broadband 2Mumbai Gsm Ip Pool 2N&G Tecnologia LTDA 2Naja Telecomunicacoes Ltda. 2NC Numericable S.A. 2Nepal Telecommunications Corporation Cellular Mobi 2Net Infinito Telecom 2Net Onze Provedor de Acesso a Internet Ltda 2Netcom Enterprises Pvt Ltd 2NetSol Connect 2Networks Ltda -me 2Next Telecomunicacoes do Brasil LTDA 2Nos Comunicacoes, S.A. 2Nova Net Telecomunicacoes Ltda 2O2 Czech Republic 2Oklahoma State University 2Omantel 2OPTICCOM- BULGARIA Ltd. 2Optus 2Orange Madagascar 2Orion Telekom , CDMA Users 2Philippine Telegraph and Telephone Corporation 2PlusNet Technologies Ltd 2Pombonet Telecomunicacoes e Informatica 2PredialNet 2Priston Net Telecom 2Provedor de Internet Ltda. 2PT Naraya Telematika 2PT. Saranainsan Mudaselaras 2Pt. Sekawan Global Komunika 2PT. Smartlink Global Media. 2Pustekkom 2R Cable y Telecomunicaciones Galicia, S.A. 2Radiant Communications Limited 2RCS & RDS 2Rede De Telecomunicacoes Carajas Ltda 2Redes Integrales S.A. 2Rey de Occidente, S.A. de C.V. 2Rodolfo Romao De Oliveira Neto & Cia Ltda 2SA Telecable 2Sabanet Tehran 2Sampark Estates Pvt. Ltd. 2Sat Film 2Servcom Sp. z o.o. 2Serviciul de Telecomunicatii Speciale 2

SevenStar Broadband 2Shahrad Net Company Ltd. 2Shirl Broadband 2Simbanet-as 2Simpur ISP 2Slovak Telecom 2Sociedad Cooperativa Popular Limitada de Comodoro 2Solucoes Em Informatica Ltda 2SRI International 2Supernet Limited Transit 2Surfplanet GmbH 2Tabriz 2Taiwan Academic Network (TANet) Information Center 2Tech Solutions 2Telecom Italia Sparkle of North America 2telecomplus 2Telecomunicacoes Do Brasil Ltda. 2Telecomunicacoes Servicos De Internet Ltda 2Telenor doo Serbia address space for mobile access 2TK Telekom sp. z o.o. 2Tolima Digital 2UAB Cgates 2UniNet(Inter-university network) 2University of Malaya 2University of Southern California 2Valau Dos Santos - Me 2Vietel - CHT Compamy 2VipNET 2Vivas Network Ltda-ME 2Wantok Network Limited 2Wconect Wireless Informatica LTDA - ME 2WideOpenWest 2Windstream Communications 2Younet Internet 2ZTS Echostar Studio 2A. P. Oliveira & Cia. S/c. Ltda. 1AAPT Limited 1Accesskenya Group Ltd 1Acesso Telecomunicacoes LTDA 1Actual Network Internet Ltda 1Adamo Telecom Iberia S.A. 1Albanian Satellite Communications sh.p.k. 1Alfa Solutions Ltd 1Alpha Tel S.A. 1Altarede de Teresopolis Provedor de Internet Ltda 1America Online 1Aniruddha skyline web service 1Ankhnet Informations Pvt. Ltd. 1ANTIK Telecom s.r.o 1Araujosat Comercio De Antenas Ltda Me 1Aries Networks Grup Srl 1Astral Bucharest Docsis N 1Audianet Sentra Data, PT 1

Page 23: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

23S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

AWACOM Sp. z o.o., Bydgoszcz, Poland 1Benemerita Universidad Autonoma de Puebla 1BeotelNet ISP 1Bozorg Net-e Aria 1Braila Docsis 1Braudes e Sa Ltda 1BrByte Telecom 1Brcentral.net Ltda 1Broad Band Telecom Services Ltd 1BT Italia S.p.A. 1BT Public Internet Service 1BTTB 1Cable & Wireless Users 1CallU Telecomunication Ltd. 1Catanduva sistemas a cabo ltda. 1China Telecom Guangdong 1China Telecom Shanghai 1Chunghwa Telecom 1Claro S/A 1Clicfacil Computadores, Servicos e Telecomunicacoes 1Click.com telecomunicacoes ltda-me 1Clouditalia Communication S.p.A. 1Cogeco Cable 1Colombia Telecomunicaciones S.A. Esp 1Columbus Networks Dominicana 1Com De Equip. De Tele Informatica 1Computer Newspaper Services 1ConnectBD Ltd. Internet Service provider 1Core - Reserved 1Core infrastructure 1Core network 1Corporacion Digitel C.A. 1Cox Communications 1Cyber Info Provedor de Acesso LTDA ME 1D.M.Giandomenigo Informatica Ltda-ME 1D2V ISP 1DCC Kavarna 1Dedicado - Generico 1Delhi Packet Core Network 1Dev Italia srl 1DGNet Telecom 1DigitalOcean 1Direct Internet 1Disenadores Informaticos Y Tecnologicos, S.l. 1Distributel Communications 1Dora Telekomunikasyon Hizletleri A.S. 1Dos Santos & Cia. Ltda. 1Dos Santos Campelo Me 1E L Da Silva Servicos De Redes E Comunicacaoes M 1E.I. du Pont de Nemours and Co. 1Ebone Network (PVT.) Limited 1Echostar Cable Modem Network 1Edatel S.A. E.s.p 1

Emirates 1Emirates Integrated Telecommunications Company PJS 1Eutelsat S.A. 1F.H.U. Intersiec Urszula Kolodziej 1F/X Wireless Technology Solutions Pvt. 1Far EasTone Telecommunication Co., Ltd. 1Fast Telecommunications Company W.L.L. 1Federacion de Cooperativas Ltda. 1Firma Tonetic Krzysztof Adamczyk 1Free Mobile SAS 1Frionline 1General Telecommunication Organization 1Global Broadband Solution societe de droit america 1Global Crossing Peru S.A. 1Gomti Cable Network Pvt Ltd 1GPON - Sofia 1GPTC Autonomous System, Tripoli Libya 1GulfNet KSA 1Gyorfi E Gyorfi Ltda 1H1 TELEKOM d.d. 1Help Line 1Hexabyte 1Himeji Cable Television Corporation 1HiperNET Servico de Comunicacao LTDA ME 1Hong Kong Broadband Network Ltd 1ICPNET Cable 1IHS Telekomunikasyon Ltd 1ImpSat Argentina 1Indotrans Data, PT 1Industrias Gessy Lever Ltda 1INEXA - Flavio Jose Penso Junior - ME 1Info Ltda 1INFONET Services Corporation 1Informatica E Telecomunicacoes Ltda - Me 1Inode Telekommunikationsdienstleitung GesmbH 1Instalnet Szabat Rydzewski Spolka Jawna 1Integrated Telecom Co. Ltd 1Internet Banda Larga 1Internet de Banda Ampla 1Internet Maxima Tecnologia Ltda 1Iomart Hosting Limited 1Iran Meteorological Organization 1Iradio Comercio e Manutencao de Maquinas LTDA 1Islamic Azad University of Mashhad 1ISP tai POP Ha Noi 1jn cabral & cia ltda me 1Junior E Cia Ltda 1K2 Telecom e Multimidia LTDA ME 1Kappa Internet Services Private Limited 1Karvy Consultants 1Kbrod.net Ltd. 1KENYAWEB 1Klinikum Oldenburg gGmbH 1

Page 24: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

24S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

Kopings Kabel-TV AB 1Krosnienskie Centrum Informatyczne KROSOFT 1La Docta.com S.A. 1LAN clents in Veles 1Lanka Bell’s 1Lembaga Penerbangan dan Antariksa Nasional (LAPAN) 1Lenilson Francisco da Silva 1Libantelecom 1Life Servicos de Comunicacao Multimidia Ltda. 1Link Telecom (NZ) Ltd 1M. N. Redes de Comunicacoes Ltda. 1Massive Telecom SRL 1Mauritanian Telecommunication Company 1Media Commerce Peru S.a.c 1Meghbela Skywave Cablenet Private Limited 1Melo Telecomunicacoes Ltda 1MetroNet Bangladesh Limited 1MetroNet Bangladesh Limited, Fiber Optic Based Met 1MGOC10K01Plan 1Minasnet Servicos de Provedor de Internet Ltda 1Monika Superserv SRL 1Mosaico Telecom & Clinitec 1MTS 1Multimedia Polska S. A. 1Mykris Asia Sdn Bhd, Network Service Provider, Pen 1Nakorn Ratchasima Rajabhat University 1Net 1Net 4 U Services Pvt Ltd 1Net Ltda. 1Net Turbo Telecom 1Neterra Ltd. 1Netiwan SAS 1Netline Peru SA 1NetNam 1New Century InfoComm Tech Co. 1Nexlinx ISP Pakistan 1NGCOM 1Noroestecom Telecomunicacoes Ltda 1Novatec Telecom Ltda ME 1NTT DATA Service for Zirzile partner 1Nuevatel PCS de Bolivia S.A. 1OBO 1Ogaki Cable Television Co.,Inc. 1Omani Qatari Telecommunications Company SAOC 1Onda Internet 1Orion Telekom Tim d.o.o 1Orlandonet Ltd 1PaintWeb Internet Ltda 1Pardaz Gostar Ertebatat Berelian Limited Liability 1Pardazesh Pishrafteh Rasaneie Company PJS 1Pawel Kowalski BGCOM 1Po Turbhe 1Pontenet Teleinformatica Ltda. 1

Posta dhe telekomi i Kosoves 1Prefeitura Municial de Alfenas 1PRESNET s.r.o. 1Prime Link Communication, PT 1Primus Telecommunications Canada 1Processamento de Dados Ltda. 1Pronet Telekom 1PROTONET Adrian Ludyga 1Providers Eirelli-ME 1Przedsiebiorstwo Handlowo Uslugowe Kamdex Grzegor 1PT Jala Lintas Media 1PT Pemuda Berkarya Indonesia 1PT Sumber Data Indonesia 1PT Transtech Communication Media 1PT. Arsen Kusuma Indonesia 1PT. Bumi Merbabu Permai 1PT. Cipta Informatika Cemerlang 1PT. First Media, Tbk. 1PT. Global Inti Corporatama 1PT. Global Komunika Dewata 1PT. Mora Telematika Indonesia 1PT. Universal Broadband 1Qnet Telecom 1R-KOM Regensburger Telekommunikations GmbH & Co KG 1R.V. Provedor de Internet Ltda ME 1Radore Veri Merkezi Hizmetleri A.S. 1Rafael Orssatto & Cia Ltda 1Ragtek Ltda 1rede exitus ltda 1Republika Srpska 1Reunicable 1Rodrigues Romao Filho Me 1ROTOP 1Routit BV 1RSAWEB Internet Services 1S.N. Radiocomunicatii S.A. 1Sabanet network in Qazvin 1Salzburg AG 1Satellite Cable Tv Network Pvt. Ltd. 1Satnet Gye Coorp 1Satnet Uio Cable Modems 1Serrana Telecomunicacoes Ltda 1Sinal BR Telecom LTDA 1Sonic Wireless 1Starnetrans Srl 1Styrelsen for it og laering 1Summit Communications Ltd. 1SUPER NOVA TELECOM 1Supercable 1Supercable Telecomunicaciones 1Syiah Kuala University (Unsyiah) 1Symphony Communication PLC. 1SystemsFox prestacao de servicos LTDA 1

Page 25: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

25S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

T.M.A Serv SRL 1Taiwan Infrastructure Network Technologie 1TaNET West s.r.o. 1Tche Provedor De Internet Ltda 1Technical University of Lodz Computer Centre 1Telecom & It Ltda 1Telecom S/a 1Telefonica Moviles Guatemala S.A. 1Telemidia Sistema de Telecomunicacao Ltda 1Telenet N.V. 1Telinea d.o.o. 1Telnet Communication Limited 1TERRARICANET 1Toya sp. z o.o. 1UAB Baltnetos komunikacijos 1Umniah Mobile Company 1Uninet-th 1Uniredes Telecomunicacoes E Informatica Ltda Me 1Universidad Nacional Autonoma de Mexico 1University of the Philippines Los Banos 1UPC Austria 1UPC Norge 1UPC Romania CLUJ-NAPOCA 1UPC Telekabel 1UPC-NL LGi internal CGNAT for IPv4-IPv6 AFTR 1

Vertixo B.V. 1Vetorialnet Informatica E Servicos De Comunicacao 1Vianna Mehl Servicos de Telecomunicacoes Voip L 1Viewqwest Megapop 1VIRTUAL TELECOM A. Sergiel, D. Ladniak Spolka Jaw 1VisaoNet Telecom LTDA 1Vmax Net Telecomunicacoes Do Brasil Ltda 1Vodacom Tanzania 1Vodafone Czech Republic a.s. 1Vodafone Omnitel B.V. 1Vodafone Portugal 1Vodafone Qatar Q.S.C. 1Wan Interco for customers 1Wananchi Group Kenya 1Way.com Provedor Banda Larga Ltda-me 1Web Concepts (Pvt) Ltd 1wilhelm.tel 1Windhoek BRAS02 IP Pool 1Windstream Hosted Solutions, LLC 1Wireless Comm Services LTDA 1Witribe Pakistan Limited 1XC Networks 1xDSL Services of HaNoi 1Xplornet Communications 1YUnet International 1ZOL Zimbabwe Assignments 1

Total Result 85,419

Page 26: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

26S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

lawusa.com 16,891 nsoft.it 6,837 newarkha.org 5,845 imco-inc.com 3,365 nlex.com 2,819 jlburke.com 2,595 rp-printers.co.uk 2,145 aagcorpus.com 2,078 fdfltd.com 1,477 enclos.com 1,331 bcp.co.uk 1,172 shapearts.org.uk 981 brakemasters.com 880 martinflyer.com 695 gulfcoastmed.com 687 terrus.com 649 bakerswaste.co.uk 511 sverigedemokraterna.se 501 allitt.co.uk 482 ferro.com.tr 475 wyatthomes.co.uk 470 intuition.co.uk 455 superiorpetroleum.com 449 cnta.es 433 usyouthsoccer.org 429 plymouthyarn.com 423 numberone.com.br 421 perry.k12.ia.us 411 griefnet.org 382 tombryant.org 375 obinet.com 363 pusateris.com 363 ost.edu 352 eliteislands.com 350 townofmanteo.com 346 kelloggsupplyco.com 344 dtp.com.tr 331 deerland.ca 330 woburnpd.com 299 surpluscenter.com 295 karmod.com 283 waterline.ch 279 llanover.com 278 quantatec.com.br 277 alteropower.ru 271 beachbook.com 256 kingsburyclub.com 256 getonit.co.uk 249 liggettgroup.com 244 aspenpress.com 241 jrtr.org 240 surfsponge.com 236

islandxpertees.com 228 markeire.com 226 sonicburst.net 226 rossi.ch 214 bell-litho.com 208 ballethispanico.org 201 cfeamerica.com 201 redarenatur.com 200 sylvesterservices.com 194 whitedove.uk.com 193 ajplast.co.th 189 sd.se 186 akyapidizayn.com 184 anadolubasinmerkezi.com 180 oguz.com.tr 179 imcoconstruction.com 172 casanz.org.au 167 acmorgannwg.org.uk 159 cts411.com 157 microplastics.com 156 akyoltercume.com 152 cvomfs.com 151 akbank-dsg.com 147 greggruth.com 145 sauguspd.com 141 dancorinc.com 135 gruppofeg.it 133 apologeticspress.org 129 deanefreight.com 125 esko.dk 119 bergmann.de 116 eii-1.com 109 hatz.com.au 108 lupprians.com 107 gruppofeg.com 105 jenkins.uk.net 102 wjelectrical.co.uk 102 integritysolnw.com 100 alpinoto.com 99 usamines.com 98 sdu.nu 95 seltechaero.com 95 agaoglukimya.com 92 crosswear.co.uk 89 lupprians.co.uk 89 gba.co.za 88 milanis.it 88 pna-inc.com 88 edwardbukaty.com 87 ccssite.org 86 saraytuz.com 85 autovan.co.uk 80

Page 27: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

27S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

altinkent.com 79 tarimak.com 78 armiya.com 77 cefnlea.co.uk 77 ak-es.net 76 alfatransport.com 76 spiculum.com 76 codefoundry.com 75 kapadokyafashionproductions.com 74 alpininsaat.com 73 argepakambalaj.com 73 nrpd.org 73 bilgitas.com 71 reddrumtackle.com 70 scansail.de 70 teamsrl.it 69 adadt.com 67 primecre.com 63 drwebhosting.com 62 GNG.CH 61 vicaragecourt.com 61 bedfordva.gov 60 colourgro.co.uk 58 sandwelltraining.com 57 akaambalaj.com 56 broomheads.co.uk 56 fbs.com.tr 55 gwcindia.in 55 medyapark.com.tr 55 ablukaalarm.com 54 capitalpcc.co.uk 54 laborkimya.com 54 karizma.com.tr 53 argeyikama.com 52 springfieldareahba.com 52 CUPPLESINC.COM 51 ajanskarakalem.com 50 pitsurf.com 50 sylvanks.com 49 portsmouthoh.org 47 scoresontheboard.com 47 ubismail.net 47 us-amines.com 47 altinseramik.com 46 wjbeitler.com 45 aldaydinlatma.com 44 hctf.ca 44 maykimya.com 44 alikilic.net 43 lacomms.com 43 logicbox.net 43 rand-associates.co.uk 43

altuasansor.com 42 cfaulknerengineering.com 42 cliltd.co.uk 42 missimo.com 42 bidonss.net 41 euclidindustries.com 41 mercankalip.com 41 chholdings.com 40 hillviewretirement.org 40 kingsburyclubmedfield.com 40 maldenpd.com 40 tailoradio.it 40 urorad.net 40 vei-austin.com 40 a2zfethiye.com 39 admetalspinners.co.uk 39 tezhukuk.com 39 johnaustin.co.uk 38 sultangida.com.tr 38 capricornimports.co.uk 37 sheldonbosley.co.uk 37 sunbeamfostering.com 37 dori.com.tr 36 fikrinmerkezi.com 36 goksm.com 36 whiteoakuw.com 35 acarmakinacnc.com 34 teknikcivi.com 34 3dmimari.net 33 abirmetal.com 33 akanyapi.com 33 altkatsanat.com 33 fdr.on.ca 33 flblind.org 32 hermitage-hotel.co.uk 32 ukmkimya.com 32 vikoser.com 32 antikipek.com 31 bmslimited.net 31 brightstreet.biz 31 corolla-light.com 31 housingcollaborative.org 31 artasgranit.com 30 brcga.org 30 prestigeaustralia.com.au 30 rtzco.com 30 ahkohio.com 29 aydan-ltd.com.tr 29 paymentct.com 29 schreiner-versicherungen.de 29 adrgroup.com 28 anilmatbaa.com 28

Page 28: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

28S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

oddy.net 28 sdkuriren.se 28 activasatis.com.tr 27 blbcorreduria.com 27 cesas.com.tr 27 chiphisigma.com 27 coastalimpressions.com 27 eski1ask.com 27 martysgmc.com 27 megagrp.com 27 monicaricci.it 27 postacikurye.com 27 saugus-ma.gov 27 aketiket.com 26 antalyamikro.com 26 gnrturizm.com 26 nichegenerics.com 26 samko.com.tr 26 global-offers.com 25 ioma.com.tr 25 premoe.net 25 principal-medical.co.uk 25 gordionkonutlari.com 24 infosource.com.tw 24 jdconcrete.com.au 24 marmaramuh.com 24 sharpwin.com 24 sozmenelektrik.com 24 ssf-group.co.uk 24 tanplaza.com 24 ustatur.com 24 zeysinturizm.com 24 alanyahomes.com 23 bloomsbury-law.com 23 erkockalip.com 23 fourseasonsinduck.com 23 rcs.com.ph 23 terminalistanbul.com 23 avezinsaat.com 22 bisarcosmetic.com 22 comquest.com.ph 22 docharity.ie 22 newpig.com.au 22 nichegenerics.ie 22 p-d.co.uk 22 saecircuits.com 22 securitygates.co.uk 22 sultanhouse.com 22 unoxuk.com 22 7yildizturizm.com 21 aydinlarg.com 21 boergerlaw.com 21

century21halikarnas.com 21 deltamuhendislik.com.tr 21 ecbh.org 21 feg.it 21 masteringworld.com 21 resolutionstech.com 21 srstekstil.com 21 sussexsurveyors.com 21 izlee.org 20 kollerdirect.ch 20 pmgstone.com.au 20 safalojistik.com 20 thecoastlandtimes.net 20 umpasseramik.com.tr 20 artuklu.com 19 bayraktarhukuk.com 19 confexuk.com 19 estetikspor.com 19 gokcemobilya.com 19 mcfflex.com.tr 19 powertrans.com.tr 19 ramostur.com.tr 19 sahinsmmm.com 19 statistixl.com 19 trio-max.com 19 aclmekanik.com 18 ayi.org 18 ctek.ch 18 dana.ru 18 fwgrab.com 18 gulnayin.com 18 knightandrennie.com 18 law-tm.com 18 redmintcomms.co.uk 18 reyline.com 18 syncopatemedia.com 18 thinksmart.co.th 18 3dbouwteam.be 17 akmatek.com 17 alphafinancialadvisors.com 17 austexeng.com.au 17 barcelos.co.za 17 demirergroup.com 17 ekolej.net 17 ekom.com.tr 17 muratmetal.com 17 progresstr.com 17 senayapidenetim.com.tr 17 solucion-es.com.mx 17 ajanskaraca.com.tr 16 bcrp.ca 16 bernard.bg 16

Page 29: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

29S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

cestur.com 16 erenfisto.com 16 fosforix.com 16 houseoftrimble.com 16 idesm.com.au 16 jonesandbrown.com 16 one-vision.it 16 vicarscrossdentalpractice.co.uk 16 winetram.co.za 16 alfayapim.com 15 birthday-suits.com 15 cambridge-residential.co.uk 15 cersanasansor.com 15 cukurovam.com 15 guraybilgisayar.com 15 hayvancilik.org 15 inkamakina.com 15 klf-insurance.com 15 londiniumedu.com 15 madenlim.com 15 petrosa.net 15 pridefostering.com 15 proserpio.it 15 scope-india.com 15 sykoraconsulting.com 15 thesuffolkgroup.com 15 5percangol.hu 14 alogluservis.com 14 argebilgisayar.com 14 atlanticexhibition.com 14 canikli.com 14 cellsys.co.za 14 chunkychode.com 14 debigroup.com 14 delkoconstruction.com 14 erkaplan.com.tr 14 hafodmastering.co.uk 14 iwanskimasonry.com 14 macroc.com 14 maxtekno.com 14 sahper.com 14 tahaoffice.com 14 taveks.com 14 teamweb.it 14 twoogroup.com 14 akpas.com.tr 13 altayisi.com 13 beitlerlogistics.com 13 bgexcavating.com 13 bostonkitchen.com 13 brightgreenhydrogen.org.uk 13 darino.us 13

efajans.com 13 ehconline.org 13 elithizmet.com.tr 13 furkanpimapen.com 13 haspetrol.com.tr 13 human-performance.com.au 13 lanplus.co.uk 13 morplastik.com 13 sgseniors.com 13 tadhamoncapital.com 13 xkobi.com 13 alaybeyoglu.com.tr 12 anadoluconta.com.tr 12 artuz.com 12 brunton.co.nz 12 formulachemicals.com.au 12 garantiturizm.com 12 izmer2000.com 12 mahirelektronik.com 12 maselhotel.com 12 oztoksa.com 12 pasifikintl.com 12 rutas.com.tr 12 tmsvinc.com 12 travelpoint.com.tr 12 anthonysofringwood.co.uk 11 aplussigorta.com 11 archy.com.tr 11 atinch.com 11 ctekag.ch 11 ebastir.com 11 guneycelikhalat.com.tr 11 koknarkoyu.com 11 m-c.com.tr 11 majormusic.com.tr 11 mid-michnet.com 11 mzpartners.co.uk 11 niskozmetik.com 11 orenda.com.tr 11 ozderin.net 11 ozlemkimya.com 11 pslconstruction.net 11 siringul.com 11 sparktr.com 11 tomthefreak.com 11 ulusoyambalaj.com 11 vernoncourtreporters.com 11 arsmakina.com.tr 10 batucephe.com.tr 10 becketts1945.com 10 buraksen.com 10 c-s.co.uk 10

Page 30: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

30S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

cemregiyim.com 10 cipoandbaxx.com 10 deanster.com 10 denizelektronik.com.tr 10 devran.k12.tr 10 dpi.com.tr 10 erce.com.tr 10 erser.com.tr 10 fotoremzi.com 10 fumokozmetik.com 10 greengrey.com.tr 10 gursoft.com.tr 10 haanyapi.com 10 impulseajans.com 10 irmethospital.com 10 ismobebe.com 10 istanbulviva.com 10 karalmetal.com 10 kivancsigorta.com 10 kolcakmobilya.com 10 manisaseyahat.com 10 mybsg.net 10 nadgeebynature.com.au 10 neontekstil.com 10 o2.com.tr 10 orass.com 10 ozalpertekstil.com 10 pakdus.com 10 rebuildchristchurch.co.nz 10 rpprinters.co.uk 10 saltanlar.com 10 santrabil.net 10 schroeder1.net 10 sertekshali.com 10 ucuzcorap.com 10 uludagzeytin.com 10 akinsen.com 9 arca.com.tr 9 arcmaintenance.net 9 as-fe.com 9 atoskimya.com.tr 9 avantiwealth.com 9 azaksu.com 9 babilgrup.com 9 bahadirmakina.com.tr 9 benimse.com.tr 9 cagceviri.com 9 cremetekstil.com 9 demhali.com 9 destinaotel.com 9 diyetcity.com 9 dogahospital.com 9

dorabase.com 9 duyguvida.com 9 eksisguvenligi.com 9 elichemoil.com 9 fiberlogistics.com 9 fullksk.com 9 grafmat.com 9 ileryemek.com 9 iloglu.com 9 isiktour.com 9 juntunenenterprises.com 9 mgenerji.com 9 muratince.net 9 n340.com 9 osmanli-grup.com 9 ovayapi.com 9 tmpcco.com 9 versorgungskompass.de 9 weger.com.tr 9 written4.com 9 yavuzcanotomotiv.com 9 zeostek.com 9 aksoydemir.com 8 akstainsaat.com 8 aktasled.com.tr 8 ankateknik.com.tr 8 arigumruk.com.tr 8 armadabilgisayar.com 8 balcimakina.com.tr 8 basaran-symes.com 8 cevaplar.org 8 ci-ltd.co.uk 8 daglitransport.com 8 efeshaliyikama.com 8 emirganhotel.com 8 engsol.co.ug 8 floridaway.com 8 guidesinturkey.com 8 gulpa.net 8 innovativecurbs.com 8 iskarmakine.com 8 istanbulteknikmakina.com 8 izmit.bel.tr 8 kabataslilar.org.tr 8 kartallardamper.com.tr 8 kaynakmarble.com 8 kcmitre10.com.au 8 kontrolnoktasi.com 8 metcotek.com 8 mimag.com.tr 8 modeltekstil.com 8 odonnellfamily.co.uk 8

Page 31: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

31S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

rekare.com 8 safirarms.com 8 sahilinsaat.com 8 sdkvinnor.se 8 seyriistanbul.com 8 sparktemizlik.com 8 sportsgiyim.com 8 tataroglu.com 8 taymarble.com 8 theanchorageinn.com 8 ucyuzreklam.com 8 ulusallojistik.com 8 woburnfd.com 8 abantcamp.com 7 acatrans.com 7 acomp.com.hk 7 adamekanik.com 7 adtmarble.com 7 akmar.org 7 akmerkezcicek.com 7 alkarnakliyat.com 7 alpbilge.com 7 alpetgida.com 7 ambergas.com 7 anadolubasin.com 7 antmimarlik.com 7 artevetta.com 7 avenkalip.com 7 bamabay.com 7 basaraniselbiseleri.com 7 bentspor.com 7 boblandau.com 7 camlicaboru.com 7 canmimarlik.com 7 comodo.od.ua 7 destan.com.tr 7 dijifotolab.com 7 dostboya.com 7 ernasuca.com 7 halantex.pl 7 hizmar.com 7 iqvision.com.au 7 ira.com.tr 7 irmak.org 7 isimtescil.net 7 k-e-b.com 7 kaserer.de 7 libracem.com 7 liderkimya.net 7 macoyun.com 7 maesta.com.tr 7 mayasar.net 7

merthukuk.net 7 mevsimtriko.com 7 mgreene.co.uk 7 midwestpa.com 7 mimagenerji.com 7 mipatex.com 7 napchan.com 7 nysa.com.tr 7 obus-target.com 7 ocosec.org 7 ozkaryapi.com 7 pepper.net 7 phibio.de 7 plasmatip.net 7 powerinsaat.com 7 relaxia.it 7 renksel.com.tr 7 tirannakliyat.com 7 tirser.com 7 torbey.com.tr 7 ungsvenskarna.se 7 unyemaden.com 7 vipisitme.com 7 vuslatdergisi.com 7 acilimteknik.com 6 afcbuilding.com 6 agrega.com.tr 6 akyuzlernakliyat.com 6 altunisik.com.tr 6 aricilarcarpet.com 6 arifizgidizayn.com 6 arnida.com.tr 6 artimedyareklamcilik.com 6 arusaturizm.com 6 aspakhijyen.com 6 baharentacar.com 6 berkaisguvenligi.com 6 berkamakina.com.tr 6 betonmaksan.com 6 beyorme.com 6 bezirhaneotel.com 6 bildikmuhendislik.com.tr 6 boozermail.com 6 camlica.net 6 carexpress.com.tr 6 carpexkurumsal.com 6 cicekbilgisayar.com 6 coskunnakliyat.com 6 ct.com.tr 6 ctbilgisayar.com 6 demircelik.com 6 deriisi.com 6

Page 32: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

32S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

dfm.com.tr 6 doktorvip.com 6 dorukhaberlesme.com 6 dursunbey.bel.tr 6 erdemhali.com 6 erseteknoloji.com 6 esinderyapi.com.tr 6 etaservis.com 6 etiklife.com 6 fabregas.com.tr 6 fairweatherfoods.com 6 farinelunion.com 6 fbsdanismanlik.com 6 ferinoks.com 6 ficke.org 6 fiyakaajans.com 6 gfsturkiye.com 6 gizemturizm.com 6 gokhanege.com 6 goldperdesistemleri.com 6 grandemirhotel.com 6 groupmerlin.com 6 gunaygumrukleme.com 6 gunduzofset.com 6 hukukarastirma.com 6 karekupajans.com 6 kolaykapak.com 6 kot1.com 6 kriptoiletisim.com.tr 6 kuzeybalik.com 6 lazer-mark.com 6 marasanahtarci.com 6 modatextile.com 6 muzcevredanismanlik.com 6 myseaturkey.com 6 ncIstanbul.com.tr 6 nizamsogutma.com 6 objekta-immobilien.de 6 odevevi.com 6 orhanmarble.com 6 pinartasarim.com 6 pozitifplus.com 6 praticaforyou.com 6 promarbilgisayar.com 6 rejuviturkiye.com 6 sedamatbaasi.com 6 sefmavi.com 6 selcukluekk.com 6 siglanlar.com.tr 6 so-cashmere.com 6 stagglaw.com 6 staleymail.com 6

station31.org 6 stneots-tc.gov.uk 6 tarikmakina.com.tr 6 techrota.com 6 teknikeller.gen.tr 6 tetyazilim.com 6 toloman.com 6 tpne.nl 6 unallarltd.com 6 unitragen.com 6 whiteoakinnandsuites.com 6 yertan.com 6 zes.com.tr 6 a1budgetskips.co.uk 5 acfpd.org 5 alfahavacilik.com.tr 5 alkaturizm.com.tr 5 alpe.com.tr 5 an-ka.com 5 aplusyapi.com 5 appma.com.au 5 archangelpartners.com 5 artenreklam.com.tr 5 asel-grup.com 5 atakalibrasyon.com 5 ateg.com.tr 5 atuluk.com 5 aysekazanci.com 5 aytacengin.com 5 batupatent.com.tr 5 bestturizm.com 5 bildiksigorta.com 5 cankayabelde.com.tr 5 canplastik.com.tr 5 cemalkeler.com 5 centralhospital.com.tr 5 chinalinetravel.com 5 choccom.com 5 clovamarble.com 5 cmsteknik.com 5 coco.com.tr 5 cohoelectric.com 5 corecasys.com 5 cruiseclubofamerica.org 5 czmteknik.com 5 denizegzost.com 5 dersanleather.com 5 dilekoto.com.tr 5 dogaspor.com.tr 5 durucev.com 5 dwgatesengineering.com 5 embigida.com 5

Page 33: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

33S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

emsapansiyon.com 5 emsgumrukleme.com 5 erogluotomat.com 5 estelgsm.com 5 fcbp.dk 5 financialadvisors.net.au 5 forsbayrak.com 5 forumemlak.com 5 gitex.com.tr 5 gmgdisticaret.com 5 gumush.com 5 guvercinlerimiz.com 5 hns.com.tr 5 ilgiyonetim.com.tr 5 inchiletisim.com 5 inncityhotel.com 5 isportfoy.com 5 istanbulruhsagligi.com 5 kentyapidenetim.com 5 keremambalaj.net 5 kirmaci.net 5 kizkalesinde.com 5 kusgroup.com 5 logodijital.com 5 maisgida.com 5 masna.com.tr 5 maxi.com.tr 5 mekatronikelektrik.com 5 menzara.com 5 merkezdavet.com 5 mesaaluminyum.com 5 nbsbilisim.com.tr 5 nettaelektronik.com 5 nouvart.net 5 ocaktrans.com 5 onurexpress.com 5 onurparklife.com 5 organizedergi.com 5 oscarrentacar.com 5 otantikotel.com 5 ozlermakina.com 5 ozusta.com.tr 5 pardis.com.tr 5 parkwestgc.com 5 pasaportpier.com 5 paslanmazelek.com 5 perlavista.com 5 prizmabilgisayar.net 5 publicit.co.uk 5 rchmenukabi.com 5 reyhantekstil.com.tr 5 rhyazilim.com 5

rutson.com.tr 5 safakdemircelik.com 5 salihbebe.com 5 semantekstil.com.tr 5 seyhanosgb.com 5 sisteknik.com 5 sivassrt.com 5 sobekculture.com 5 sprechtraining.at 5 stardekor.com 5 stilproduction.com 5 sunmatbaa.com 5 tekiniplik.com 5 teknovend.com.tr 5 temamakina.com.tr 5 thehydrogenoffice.com 5 troytarim.com 5 uysalambalaj.com 5 uzmanklima.com.tr 5 vigrxvigrx.com 5 vk2001.com 5 wheeltec.com.hk 5 yedipunto.com 5 yinfo.org.tr 5 zafergrup.com 5 zeylandavm.com 5 zulalelektrik.com 5 abcmaker.com 4 acrylicteeth.com 4 activeklamp.com 4 adamor.com.tr 4 adrdanismanlik.com 4 adstasarim.com 4 agarastirma.com.tr 4 akaraluminyum.com 4 akdenizav.net 4 aktaslarmakina.com 4 alanyabalikavi.com 4 alemdaroto.com.tr 4 altinkozamobilya.com 4 amarlatours.com 4 anameric.com 4 anatolianballoons.com 4 ankaraarcelik.com 4 apesan.com.tr 4 apt.com.tr 4 aquakamp.com 4 ariktekin.com 4 aselektrikklima.com 4 asfe.com.tr 4 asikunefeleri.com 4 atalayemlak.com.tr 4

Page 34: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

34S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

atbotomasyon.com 4 atlasproser.com 4 atlasturizm.com 4 avukatportal.org 4 aybeymakina.com 4 aystekstil.com 4 baharparke.com 4 besatas.com.tr 4 beykap.com 4 beyondenergy.com.tr 4 beyondsteel.com.tr 4 bilgibilisim.com.tr 4 bilgikursu.com 4 birhekimoglu.com 4 birimplastik.com 4 bisad.org 4 bltgiyim.com.tr 4 boucher.me 4 bsm.com.tr 4 bykleber.com.tr 4 caliskanvize.com 4 can-textile.net 4 canakhotel.com 4 carepark.com.tr 4 carpetanatolia.com 4 cesanmakina.com 4 chelebi.com.tr 4 cihanins.com 4 dadas.com.tr 4 datapc.net 4 decoformmobilya.com 4 dehateks.com 4 denimse.com 4 devekaya.com 4 dibopetfood.com 4 didimseyahat.com 4 dimaks.com.tr 4 doguakdeniz.com 4 dogusmuhasebe.net 4 dostboya.com.tr 4 dsygkitabevi.com 4 duyuticaret.com 4 ekizlojistik.com 4 electrajeans.com 4 elmundo.com.tr 4 elsamad.com 4 emrecelik.com 4 enmegien.com 4 equinsaturkiye.com 4 erkmar.com 4 ersinofset.com 4 etkitanitim.com 4

fdl.co.nz 4 formulreklam.com 4 furkanpen.com.tr 4 future-land.com 4 gas-impex.com 4 gda.com.tr 4 ggmtanturk.com 4 globaldanismanlik.net 4 greenowlcafe.co.uk 4 hakimtur.net 4 hasankaradeniz.av.tr 4 hasimoglunakliyat.com 4 havatur.com 4 hunkar1950.com 4 hurdametal.com 4 ictkimya.com 4 imecoglobal.com 4 istanbulpaintballarena.com 4 izmakelektrik.com 4 jbrashear.com 4 johnparkinsonagency.co.uk 4 kalipdestek.com 4 kanalg.tv 4 karahancer.com 4 kassajans.com 4 kisiselgelisimonline.com.tr 4 klassis.com.tr 4 kopuzturizm.com 4 korusu.net 4 kulvaryapi.com.tr 4 kutluyapi.biz 4 larahadrianushotel.com 4 laserbilgisayar.com 4 mahirates.com 4 marasotokiralama.net 4 masterdoviz.com 4 matexgiyim.com 4 mekaplastik.com.tr 4 meridyenpatent.com.tr 4 merkezseramik.com 4 mittem.com.tr 4 negatif.com.tr 4 nevvalsevindi.com 4 ogunfiltre.com 4 okeanos.com.tr 4 opascompany.com 4 ovo.com.tr 4 oylat.com.tr 4 ozdemirplaza.com 4 panoto.com 4 parksistem.net 4 plaskil.com 4

Page 35: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

35S P E C I A L R E P O R T

THREAT RESEARCH LABS

plipens.com 4 proteknik.com.tr 4 publicasid.com 4 racingedge.biz 4 rlegemen.com 4 royalhometekstil.com 4 sadida.net 4 sadikmetal.com.tr 4 sahinpompa.com 4 sahorganizasyon.com 4 sahracable.com 4 sahyapisan.com 4 sandikkafesimalati.com 4 santic.com.tr 4 sarkomkompresor.com 4 savanayapi.com 4 scgfoods.com 4 schlussel-pvc.com 4 sdofis.com 4 seferoglu.com.tr 4 selgroup.com 4 senolnakliyat.com 4 separotomotiv.com 4 seselektronik.com.tr 4 sevgiliyehediye1.com 4 siberplastik.com.tr 4 simbay.net 4 simesgrup.com 4 sirvanemlak.com 4 skonseptdanismanlik.com 4 softplaykids.com 4 solmazlarplastik.com 4 spotkamera.com 4 ststurizm.com 4 sutcan.com 4 taksicenter.com 4 technovatan.com 4 tekisogluhurda.com 4 teknik-bilgisayar.com 4 teknik-muhendislik.com 4 teknikatools.com 4 teknikelektrik.net 4 teknobank.com.tr 4 teknobend.com 4 ter-bo.nl 4 terrabilisim.com.tr 4 thismyweb.com 4 tisortler.org 4 tmpromosyon.com 4 trademac.net 4 tutgareklam.com 4 ugurlutrafik.com 4

unallarisi.com 4 unallojistik.com 4 uniquesourcing.com 4 ustaara.net 4 vgsdevekusu.com 4 vipmakina.com.tr 4 vipponholidays.com 4 waaland.com 4 wyatthomes.com 4 yamacambalaj.com.tr 4 yelkenisi.com.tr 4 yoyoevents.com.tr 4 ypctur.com 4 yvesfreydiamonds.com 4 3esan.com 3 3k1pr.com 3 abc-muhendislik.com 3 abreklamcilik.com 3 aconotomasyon.com 3 adaisitme.com.tr 3 admetalspinners.com 3 ailedestekevi.com 3 ajansyakamoz.com 3 akarsumarble.com 3 akbayteknikservis.com 3 akdenizorman.com 3 akepak.com 3 akkozceviz.com 3 akorgc.com 3 akreditetercume.com 3 aksaarms.com 3 akyazi.bel.tr 3 aligul.com 3 allwayslimousine.com 3 alomarangoz.com 3 alpaymuhendislik.com 3 alpinainsaat.com.tr 3 altinay.web.tr 3 anadoluform.com 3 anamasyay.com.tr 3 anewlooklawncare.com 3 ankarayayinevi.com 3 ansamed.com.tr 3 antalyaboat.com 3 aplusbilisim.com 3 aresarchitecture.com 3 argesmatbaa.com 3 argkonsantre.com 3 arihidrolik.com 3 arimoda.com 3 armonisalonlari.com 3 arsgeo.com 3

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

Page 36: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

36S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

arustek.com.tr 3 arybilgisayar.com 3 asdogunakliyat.com 3 asiloglubaklava.net 3 askinarsunan.com 3 astecbilgisayar.com 3 astimosb.org.tr 3 ataskin.nl 3 auro.com.tr 3 austintechs.net 3 avantajmarket.com.tr 3 avortekstil.com 3 avrotours.com 3 ayasoft.com 3 aybarlar.com.tr 3 ayisigimedya.com 3 aykarelektrik.com 3 ayklas.com 3 aynuralgroup.com 3 aztteknik.com 3 badeks.com 3 baeroturk.com 3 bahcesehir.com.tr 3 bahcesehirbotanik.com 3 balcibehcet.com 3 basarel.com.tr 3 bellateks.com 3 benda.com.tr 3 besatas.com 3 beyazsoft.com 3 beymersan.com.tr 3 beysu.com 3 bgteknoloji.com 3 biceris.com.tr 3 bilenpetrol.com 3 bilisimrisk.com 3 biryazi.com 3 blackseashipsupply.com 3 blumekanik.com 3 bskanadolu.com 3 burakkimya.com 3 bursacaki.com 3 bursayetkinhukuk.com 3 byztek.com 3 cagdasreklam.com.tr 3 cam-is.com 3 caninsesi.com 3 caninusdental.com 3 capoon.com 3 caytiryakileri.net 3 ccgroupco.com 3 ccsite.org 3

celikev.net 3 celikins.com 3 cepucuz.com 3 cevahirtelekom.com 3 ceyhunemlak.com.tr 3 cihanorme.com 3 cilsancikolata.com 3 compagniadelmobile.it 3 coventgarden.uk.com 3 craftyapi.com 3 creatiwiz.com 3 cruise-club.com 3 dalamanrentacar.com 3 datamak.com 3 datekstekstil.com.tr 3 decktropic.com 3 dekagroup.net 3 demamekanik.com 3 denizdekor.com 3 depetente.com.tr 3 desmaturizm.com 3 detaypen.com 3 dinlermobilya.com 3 dizivfilm.com 3 dogrulukgalvano.com 3 dokmeoglu.com 3 doksalmakina.com 3 doktorsefkat.com 3 dokuzogluism.com 3 donmezgida.com 3 drsdijital.com 3 dual.com.tr 3 efeselektrik.com 3 efsenturizm.com 3 ekipboya.com 3 elitperlapalace.com 3 elmakisi.com.tr 3 embay.com.tr 3 engaz.com.tr 3 enkamekanik.com 3 entercomputer.net 3 entransnakliyat.com 3 erciyesambalaj.com 3 erdalyolcu.com 3 erdemsan.com.tr 3 erdoganevginsekerleme.com 3 erisimmarket.com 3 erkedizayn.com 3 etcyapi.com 3 eximterms.com 3 expertim.net 3 eynar.com 3

Page 37: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

37S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

eyupoglusmmm.com 3 EZOGELINEMLAK.com 3 fasakimya.com 3 fatihkollektif.com 3 ferro-steel.com 3 fidestravel.net 3 FORUMSERIK.com 3 foshanglobal.com 3 fotoremzi.com.tr 3 fumocosmetics.com 3 furkanofsetmatbaa.com 3 gazianteptabela.com 3 gediz.com.tr 3 gelerdenizcilik.com 3 giyimtoptancisi.com 3 gorkememlakofisi.com 3 grafiktasarimevi.com 3 gudertour.com 3 gultekinturizm.com 3 gunay.info 3 gurbilgisayar.com 3 gursuisi.com 3 guvenotel.com 3 guvercinevi.net 3 hakankutlu.com 3 hakanorman.com.tr 3 haritaforum.com 3 hasanguner.com 3 hazirsitepaketi.com 3 haznedardoviz.com 3 hg-grup.com.tr 3 hijyenurunleri.com 3 hitityazilim.com 3 houdiard.com 3 ideanova.com.tr 3 ifturkmen.com 3 imajpc.net 3 imod.org.tr 3 imzakurumsal.com 3 ipekmatbaa.com 3 iskendermobilya.com 3 ismetdigital.com 3 ismetkalkan.com 3 istanbulutinsaat.com.tr 3 itcoglobal.com 3 iwt.com.tr 3 izmiryetkiliservisi.com 3 jjsestate.com 3 kalafat.com.tr 3 kalkavangroup.com 3 kaltem.com.tr 3 kardelengrup.com 3

kayatarim.com 3 keiratrade.com 3 kentbis.com 3 kobidanisma.com 3 kryteknik.com 3 kureselanahaber.com 3 kuyrukcuoglu.com 3 kuzeyihtiyac.com 3 laser-t.com 3 latifbati.com 3 lennonassociates.com 3 letoonhospital.com.tr 3 lidermed.com.tr 3 maceraofisi.com 3 mail.cliltd.co.uk 3 maksimize.net 3 MARKAGARANTI.com 3 markizethotel.com 3 marmarayapidekorasyon.com 3 mavisu.com.tr 3 mayissigorta.com 3 med-kem.com 3 mehmetcirik.com 3 meraksitesi.com 3 meraninsaat.net 3 misket.com.tr 3 mngelectronic.com 3 moduldisplay.com 3 moodtekstil.com 3 moos.com.tr 3 mostarpark.com 3 mozaikotel.com 3 mrcookies.com 3 mskinsaat.com.tr 3 multimed.com.tr 3 multimedyateknoloji.com 3 murenguler.com 3 MURTAZAOGLU.com 3 nettalya.com.tr 3 ngsteknik.com 3 nichegenerics.co.uk 3 nilsyfashionlab.com 3 ntakip.com 3 omm.com.tr 3 onlinedergi.net 3 onureltelekom.com 3 onurotomotiv.net 3 onurtrafik.com 3 orbit-tr.com 3 ozanil.com 3 ozipeklirulman.com 3 ozman.biz 3

Page 38: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

38S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

ozsis.com.tr 3 ozturkparke.com 3 palyacopalyaco.com 3 pegasus-pr.com 3 pesteliinsaat.com 3 phillipstree.com 3 polipan.net 3 polomutfak.com 3 prairiefinancial.net 3 premiershipping.ru 3 profiautomation.com 3 projesu.com.tr 3 qurancomplex.gov.sa 3 radyoz.net 3 rase.com.tr 3 rebay.com.tr 3 regent.com.tr 3 remax-extra.com 3 rmenetworks.com 3 roxy-world.ro 3 safakyapi.com 3 safaun.com 3 safirmakina.com 3 sahinguvenlik.com.tr 3 sahinlerpetrol.com.tr 3 samsungundem.com 3 sanatkirtasiyem.com 3 sandimatur.com 3 sarlnaf.com 3 saroshotel.com 3 sasayapi.com 3 sdnet.se 3 sedareklam.com 3 sekerdavet.com 3 seleksan.com 3 semeka.com.tr 3 semyacht.com 3 serda.com.tr 3 serefoto.com 3 serhatararnakliyat.com 3 serkantunali.com 3 setvana.com 3 sevimmermer.com.tr 3 seyritatil.com 3 shamiso.net 3 signsec.com 3 simsekotomotiv.com.tr 3 sinangin.com 3 sistembir.com 3 sistemkoli.com 3 smarttechbilisim.com 3 softeb.com.tr 3

sorurobotu.com 3 soylu-makina.com 3 sporlabtr.com 3 starbilgisayar.net 3 studyin-uk.com.tr 3 suarem.com 3 sultanahmethouse.com 3 suufle.com 3 taksibul.com.tr 3 talyamed.com 3 tasarimelektronik.com.tr 3 tatilbultur.com 3 teamsrl.net 3 TECHSTOR.COM.TR 3 tekstilotel.com 3 temalar.com 3 TERLIGINIZ.com 3 thelinghouse.com 3 tozmatik.com 3 trans-map.com 3 tresamigos.tv 3 tsmmadencilik.com 3 tugceinsaat.net 3 turkiyeicinhizmet.com 3 tursanseramik.com 3 tuzenosgb.com 3 u1esans.com 3 ucurtmamedya.com 3 ukdreamer.com 3 ultatrans.com 3 ulusalsavunma.org 3 umuterdogan.com 3 unlimited-holidays.com 3 utaxmarmara.com 3 uzaybilgisayar.com.tr 3 vardarinsaat.com 3 vatanforklift.com 3 velinda.net 3 versanboya.net 3 viagreen.com.tr 3 violaburo.com 3 vipotokirala.com 3 viramar.com.tr 3 vitamuhendislik.com 3 voyage-expo.com 3 winsaeminyapi.com 3 yadigar.info 3 yakutray.com 3 yalinpetrol.com.tr 3 yamanlarotel.com 3 yanginguvenligi.com 3 yasarlarsigorta.com 3

Page 39: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

39S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

yasarsark.com 3 yasinpolat.com 3 yenibirlik.com.tr 3 yenikusakturizm.com 3 yenilikosgb.com 3 ytong.com.tr 3 yucerkalip.com 3 yukselgumrukleme.com 3 zafersaat.com 3 zayiflamabandi.net 3 zeko.com.tr 3 zersigorta.net 3 ziimy.com.tr 3 1207antalyaspor.org.tr 2 304plus.com 2 3he.com.tr 2 3ndepolama.com.tr 2 50v8.com 2 abcdemir.com 2 abrates.com.tr 2 abusahiy.com 2 acaroglu.com.tr 2 ad-sar.com 2 aderans.com.tr 2 adresofis.com 2 afbamak.com 2 afdtex.com 2 aflexterlik.com 2 aishinistanbul.com 2 ajans7.com 2 akad.tc 2 akcgrup.com 2 akelwool.com 2 akelzemin.com 2 akerhediyelik.com 2 aksisgrup.com.tr 2 aksubanyo.com.tr 2 aktepeyikim.com 2 ALBHolding.com 2 alfatechmakina.com 2 alternatiftesisat.com 2 altinkentinsaat.com 2 altinorsmetal.com 2 anderapark.com 2 antikcemre.com 2 antper.com.tr 2 arcalmak.com 2 archi-metric.com 2 arestasigorta.com 2 arkusinsaat.com 2 asbisiklet.com 2 ascamasirlik.com 2

aselinsaat.com 2 asfenplastik.com 2 asinsaat.com 2 askinturlojistik.com 2 aslanevdeneve.com 2 aslankardeslerltd.com 2 aslicoban.com 2 asterion.com.tr 2 asyaorganik.com 2 asyazilim.com 2 atilganelektronik.com 2 atisyapi.com 2 atlasgumrukleme.com 2 ats-grup.com 2 ats-muhendislik.com 2 atsinsaat.net 2 avcilaragirnakliyat.com 2 avcimobilya.com 2 avpro.com.au 2 avsatis.com 2 aydinizolasyon.com 2 aydogduyapi.com 2 ayekip.com 2 ayformofset.com 2 ayhanyildiz.net 2 aykatemizlik.com 2 ayklojistik.com 2 aykorelektrik.com 2 aykuttekin.com 2 ayneyn.com.tr 2 ayrenparts.com 2 aysanelektrik.net 2 aysantarim.com.tr 2 aytam.com.tr 2 aytekmuh.com 2 ayzereklam.com 2 azimhirdavat.com 2 azizceylan.com 2 babymol.com.tr 2 bakisreklam.com 2 bandirmalazer.com.tr 2 banyopark.com 2 barisegs.com 2 basaranakademi.com 2 batmanram.com 2 bebekbakimi.org 2 believeacademy.com 2 bell-blis.com 2 berainsaat.com 2 berktrade.com 2 besiadturkey.com 2 besirlimakina.com 2

Page 40: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

40S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

besok.com.tr 2 bestartikel.de 2 betest.com.tr 2 beyazgrp.com 2 beyazinsaat.com.tr 2 beyoglugroup.com 2 bfmasansor.com 2 bggrup.net 2 bigbiz.com.tr 2 birikimmuhendislik.com 2 birlikenerji.com 2 biyotip.com.tr 2 bkjenerator.com 2 bkymuhendislik.com 2 bluetuanahotel.com 2 boraersavas.com 2 borsamalzeme.com 2 boyut-mimarlik.com.tr 2 bpyapi.com 2 bugrabilmez.com 2 buraktasimacilik.com 2 bursaerp.com 2 buse-metal.com 2 byajans.com 2 cakmakkaya.com 2 canak.org 2 cantaimalati.net 2 canyapi.net 2 capahalat.com 2 cavdar.com.tr 2 cctvtamiri.com 2 cegam.com.tr 2 cekmeceyayinlari.com 2 celenmed.com 2 celeste.com.tr 2 celikkasa.com.tr 2 cemalbaysal.com 2 cempayasli.com 2 cemresupply.com 2 cemturgumruk.com 2 cengizticaret.com.tr 2 cenkalyans.com 2 cetinplastic.com 2 cevikotoservis.com 2 chameleonreklam.com 2 cicekevler.com 2 cihanbilgisayar.net 2 cimentas.com 2 cimteknik.com 2 cmyk.com.tr 2 contaz.com 2 cosmoplex.com.tr 2

creaup.com 2 cruisesearcher.com 2 csl.com.tr 2 cu.com.tr 2 cumorsan.com 2 debba.com.tr 2 decowallduvarkagidi.com 2 degersoy.com 2 degirmencioglugrup.com 2 dekasinsaat.com 2 demirkollojistik.com 2 demkakimya.com 2 dempiteknik.com 2 denizciler.biz 2 designkara.com 2 devaxemlakinsaat.com 2 die-loewis.at 2 digikon.com.tr 2 digitalfuel.co.za 2 dilaver.com.tr 2 dilekmedya.com 2 dilercan.com 2 DINLEME-CIHAZLAR.com 2 divrigi.bel.tr 2 dnmsigorta.com 2 dogaetmangal.com 2 dogrubilgi.com 2 dostlarzuccaciye.com 2 drg.com.tr 2 drn.com.tr 2 dscbilisim.com 2 dukkantere.com 2 edebiyatdunyasi.com 2 eforevdeneve.com 2 eforyapisistemleri.com.tr 2 egebalikavi.com 2 egemerkezkimya.com 2 ekobil.net 2 ektayapi.com 2 elitbaskibeton.com 2 elkoasansor.com 2 elsekurumsal.com 2 elsis-elektrik.com.tr 2 ema-research.com 2 emg-as.com 2 eminetekin.com 2 emirdekoratif.com 2 empatiinsaat.com 2 entemaenerji.com 2 environinteriors.com 2 eradanismanlik.com 2 eratsport.com 2

Page 41: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

41S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

erbimobilya.com 2 erdata.com.tr 2 erenmakine.com 2 erer.com.tr 2 ergunpetrol.com 2 erkanelektrik.com.tr 2 erketech.com 2 ermuh.com.tr 2 erpaoyuncak.com.tr 2 ertarman.com 2 esas-sco.com.tr 2 esassco.com.tr 2 espial.com.tr 2 esustrade.com 2 etcltd.com.tr 2 eteekmen.com 2 ethos.com.tr 2 etliogullari.com 2 faafshoes.com 2 farukturan.com 2 fatihyapidenetim.com.tr 2 fbrlpg.com.tr 2 fethiyerental.com 2 fevzialtuntas.com 2 fikirart.com 2 fikirfabrikasireklam.com 2 filmmakinesi.com 2 filmyurdu.com 2 firstclass.com.mx 2 flashpanelcit.com 2 forshotel.com 2 fotoyenileme.com 2 funnivarium.com 2 gamayapim.com 2 gaziantepdekor27.com 2 gaziantepfuarstand.net 2 gecemhome.com 2 gencocompany.com 2 gencoglugroup.com 2 genpasan.com 2 gerkap.com.tr 2 gezimix.com 2 gilkes.com.tr 2 gizemzeytin.com 2 globallmarka.com 2 gokmen-sigorta.com 2 goktepebilisim.com 2 golge.org 2 gotrade.ie 2 grandoriatours.com 2 groosy.com 2 groupmrt.com 2

grupobelpa.com 2 guanyu-forging.com 2 gulnursozmen.com 2 gultasinsaat.com 2 gumdas.com 2 gumusforklift.com 2 gumusyel.com 2 guneliekmek.net 2 gunesparkevleri.com 2 guneytip.com 2 guntulupeker.com 2 gurbuzelektrik.com 2 gurgenlimakina.com 2 GURKANKAYA.COM 2 guvenagac.com 2 guvenckumlama.com.tr 2 guvenerltd.com.tr 2 guvenprefabrik.com 2 habibyenisu.com 2 harmantime.com 2 hasankolcu.com 2 hasankorkmazemlak.com 2 hashimigroup.com 2 hazarsilver.com 2 hegsan.com.tr 2 helgunnakliyat.com 2 henaisi.com 2 hizaaksesuar.com 2 hizmetvinc.com 2 holidaymedya.com 2 hotelsaphir.com 2 humraltan.com 2 huneroto.com 2 hvacgroup.com.tr 2 iconyapi.com 2 idc.web.tr 2 idealbarkod.com 2 idealchoice.co 2 idifo.com 2 idsnet.com.au 2 ijmgroup.com.au 2 ikdgrup.com 2 iler.com.tr 2 ilkson.com 2 ilkumut.biz 2 imajdoor.com.tr 2 inanoglu.com 2 inanotomasyon.com 2 info-protech.com 2 infosource.com.hk 2 iphoneariza.com 2 ipmbilgisayar.com 2

Page 42: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

42S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

istanbulagro.com 2 istanbullounge2.com.tr 2 istanbulmarka.net 2 istmall.com.tr 2 izciler.com.tr 2 izmiracerservisi.net 2 izteam.com 2 kabes.com.tr 2 kahramanoto.com 2 kalelilojistik.com 2 karacasan.com 2 karadagyapi.com 2 karakaspetrol.com.tr 2 karakoyaparts.com 2 karbir.com.tr 2 kardeslertelorme.com 2 kareajans.com.tr 2 karinaenerji.com 2 karincanakliyat.com 2 karmenmutfak.com 2 kartasaydinlatma.com 2 katechristie.co.nz 2 kavaklidere.bel.tr 2 kaynakhane.com 2 kcmkompresor.com 2 kentofset.com.tr 2 kerimogluinsaat.com 2 keyifhavuz.com 2 khazirgroup.com 2 knkaydinlatma.com 2 kocaelitarim.com 2 KOCATRANS.com 2 koksallarinternet.com 2 kolektifler.net 2 komesanplastik.com 2 kontip.com.tr 2 kopitoebruk.com 2 koysofrasi.net 2 koyumatciftligi.com 2 kreateks.com 2 kremgrup.com 2 kucuklerotomotiv.com.tr 2 kurumsalguvenlik.org 2 kusinsaat.com 2 kuzeybilgisayar.com 2 kuzeytrans.com 2 legobebe.com 2 lochlaggan.com 2 logosigorta.com 2 lotussea.com 2 lucabros.com 2 luleburgazosgb.com 2

lundqvistpehrsson.com 2 lynecotedesigner.com 2 marble.com.tr 2 markakids.com 2 marmaraiplik.net 2 marmaratour.com 2 matbaamarket.net 2 maviaybodrum.com 2 mavimar.com 2 mavran.com 2 maydos.com.tr 2 mckimya.com 2 medikalstore.com 2 medyayesilmavi.com 2 megasulama.com 2 mehmetgumus.com 2 mekaakiskan.com 2 melscouture.com 2 mesanark.com 2 metetdoner.com 2 metropol-nakliyat.com 2 mimgrup.com.tr 2 minyatip.com 2 misan.com.tr 2 missronn.com 2 mobiltreyler.com 2 mobosel.com 2 modernfinans.com.tr 2 mordizaynperde.com 2 morten.com 2 motosohbet.net 2 mrcelektrik.com 2 msautomotiveparts.com 2 mustafaberker.com 2 nejattezologullari.com 2 netay.net 2 nevadent.com.tr 2 nevzatraf.com 2 nezirnak.com 2 nicecomteknoloji.com 2 niceturkiye.net 2 nikahsekeri.org 2 nilufergunesenerji.com 2 nisantriko.com 2 nitronas.com 2 niyazstores.com.mv 2 nls.hu 2 nofossilfuel.com 2 ntgroup.org 2 nurcollection.net 2 obermaiselstein.de 2 odtu-mebiva.org.tr 2

Page 43: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

43S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

oguncelik.com 2 okskimya.com 2 oktayturk.com 2 okusluk.com 2 okyanusbilgisayar.com 2 olcummarket.com 2 omoistanbul.org.tr 2 orgusantel.com.tr 2 ormanci.com.tr 2 ortam.net 2 otoon6.com 2 otoritetekstil.com.tr 2 otovinn.com 2 outdooracademy.org 2 ovamtur.com 2 oyunjax.com 2 ozaskar.com 2 ozerler.com.tr 2 ozoren.com.tr 2 ozplastik.com 2 ozsimseklertasimacilik.com 2 ozyurtotoaksesuar.com 2 paradisetransfer.com 2 paranteztur.com.tr 2 patrad.com 2 paykom.net 2 pecadosweb.com 2 pehlivanltd.com 2 petrolgazetesi.com 2 piir.net 2 pimsam.com 2 pinarkimya.com 2 piramidmetal.com 2 piramitcnc.com 2 pixelmedya.com 2 plastpark.com 2 polathirdavat.com 2 possistem.com.tr 2 poyri.com 2 pozitifmuhasebe.com 2 pratikutu.com 2 prodactr.com 2 proQloud.com 2 proseskontrol.com 2 protal.com.tr 2 protekpompa.com 2 pruvatanitim.com.tr 2 pstk.com 2 ptjandpartners.co.uk 2 ramoy.com 2 referansyonetim.com.tr 2 reklammagnet.com 2

remax-win-ist.com 2 resimtekstil.com 2 restorandestek.com 2 retayapi.com 2 reymar.com.tr 2 rimtour.com 2 rolekselektromekanik.com 2 sabunbazlari.com 2 sadetatil.com 2 sagatr.com 2 sampiyonbilardo.com 2 samsunelektronik.com 2 sanatmerdiven.com 2 sancakdekorasyon.com 2 sanimsan.com 2 sanliurfaotokurtarma.com 2 santragame.com 2 sanver.com.tr 2 sarayweb.com 2 sarikayaboya.com 2 sarpmar.com 2 savanatur.com 2 savantconsulting.co.za 2 sayginlartransport.com.tr 2 scsgida.com.tr 2 seastarotel.com 2 sekeroglugrup.com 2 selcuknakliyat.com.tr 2 selimoglu.org 2 selkap.com 2 senkronisi.com 2 sentezelektrik.com 2 sentidoseastarhotel.com 2 serkanacar.org 2 serkanertem.com 2 severoglugrup.com 2 sevgibahcesianaokulu.net 2 sgldizayn.net 2 sharpcoder.se 2 sidemekanik.com.tr 2 sidsplace.com 2 sigortaladik.com 2 sigortaniyaptir.com 2 SIGORTAPOL.com 2 simgepen.com 2 sirmuzik.com.tr 2 sistemgeridonusum.com 2 sistemgrupteknoloji.com 2 sistemtrans.com 2 skeathlaw.com 2 skippyskiphire.co.uk 2 smarineservice.com 2

Page 44: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

44S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

soliva.com.tr 2 solmazgida.com 2 sonexson.com 2 sonitrolncf.com 2 sonmargroup.com 2 sosyalbidunya.com 2 SOSYALMATIK.com 2 sprcreative.com 2 srsmedikal.com 2 ssgmakina.com 2 starkturizm.com 2 stilpanc.com.tr 2 surorganizasyon.com 2 talescon.com 2 tamnot.com.tr 2 tanmusavirlik.com 2 taskinelektrik.com 2 tatilvizem.com 2 tefsiroku.com 2 teknikbileme.com.tr 2 teknikbilimlermerkezi.com 2 teknikgranit.com 2 teknikraf.com 2 teksanmetal.com 2 tektas.biz 2 tenkametal.com 2 tesaglobal.com 2 texmotor.com 2 thelingfamily.us 2 timvanderveenlaw.com 2 toprakpazarlama.com 2 torosgida.com.tr 2 tpidenetim.com 2 trikomaks.com.tr 2 tt.tuluklar.com 2 ttvinc.com 2 tunalimuhendislik.com 2 tuncmuhendislik.net 2 turkcan.info 2 turkerambalaj.com 2 turkishcarpetcenter.com 2 tutd.org.tr 2 uclerltd.com.tr 2 ucuzlook.com 2 ugandarugby.com 2 umpassigorta.com.tr 2 unfatesisat.com 2 usaburada.com 2 uskudardoviz.com 2 valentinediamond.com 2 vdmvize.com 2 velinda.com.tr 2

venusreklamcilik.com 2 villadanlin.com 2 volkanozkoc.com 2 vsrmuhendislik.com 2 vtsmobil.com 2 vuralelektrik.com 2 wearekeep.co.uk 2 webinsa.com 2 wovenhistory.com 2 yasarmakina.net 2 yasindemir.net 2 ycp.com.tr 2 yeldatekstil.com 2 yenibasim.com 2 yetersizbellek.com 2 yigitambalaj.com 2 yilancioglu.com.tr 2 yildirimcncotomat.com 2 yildizkovan.com.tr 2 yucellerelektrik.com 2 yukselay.com.tr 2 yuzdeyuztasarim.com.tr 2 ze-ce.com 2 zebilnakliyat.com 2 7-24alisveris.com 1 7-24paca.com 1 888oilpump.com 1 abadturizm.com 1 abcfinancialadvisors.com.au 1 abdullahorak.com 1 abgsigorta.com.tr 1 absambalaj.com 1 abudik.com 1 actilia.co.uk 1 adagroupsigorta.com 1 adbox.com.tr 1 adibellitel.com 1 adilpanjur.com 1 adresesaglik.com 1 adresmimarlik.com 1 advertentieplanet.nl 1 afclab.com 1 afcmetal.com.tr 1 affinageturkiye.com 1 afsinhotel.com.tr 1 agstekstil.com 1 agyapiteknik.com 1 ahmetkayar.com.tr 1 airportist.com 1 airportrecords.net 1 ajansdk.com 1 ajansmark.com 1

Page 45: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

45S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

ajansreklamci.com 1 ak-gida.com.tr 1 akademiktisat.net 1 akayelektronik.net 1 akaylaroto.com 1 akcakiraz.bel.tr 1 akcansatur.com 1 akcetasarim.net 1 akceyemek.com 1 akerdefter.com 1 akgun-elektrik.com.tr 1 akinciyumurta.com 1 akisticaret.com 1 akkozametal.com.tr 1 akkraft.com 1 akmanboya.com 1 aknuryapi.com 1 akray.net 1 aksemmuhendislik.com.tr 1 aksinsaat.com.tr 1 aksumadencilik.com 1 aktifhayatmedikal.com 1 alacamelektronik.com 1 alanyagazete.com 1 alcatcelik.com 1 aldorauk.com 1 alfa-ct-project.com 1 alfaelektrik.com 1 alhazmakine.com 1 aliortul.net 1 alisverisgurmesi.com 1 aliural.com 1 alkanlar.com 1 almahogroup.com 1 alpyapidenetim.com.tr 1 altatextile.com 1 altinbanyoaksesuarlari.com 1 altinvaraksanat.com 1 aluglax.com 1 aluteknik.com 1 alysigorta.com 1 amerepro.com 1 anadolukaratasimacilik.com 1 anadolumermer.com 1 andem.com.tr 1 ANEMONMUCEVHERAT.com 1 ankaambalaj.com 1 ANKARAREIKI.com 1 ansajans.com 1 anseloto.com 1 apsent.com 1 ararsanbulursun.com 1

arceliksaticisi.com 1 archiedata.nl 1 ardaalyans.com 1 ardakurutemizleme.com 1 ardegrup.com 1 ardemmed.com 1 areamakina.com 1 arempa.com.tr 1 argeontur.com 1 arifoglu.net 1 arikanbilgisayar.com 1 aristonyetkiliservisi.com 1 armadenizcilik.com 1 arminbilisim.com 1 arsdisli.com 1 arsistem.net 1 artemotomasyon.com 1 artevetta.com.tr 1 artiboya.net 1 artyalitim.com 1 aryalojistik.com.tr 1 asberk.com.tr 1 asilgida1.com 1 askagida.com 1 aslanaytakograf.com 1 aslanelektrik.org 1 aslankayasigorta.com.tr 1 aslanlartrans.com 1 asterazi.com 1 asudeoptik.com.tr 1 atakoynakliyat.net 1 atatopluyemek.com.tr 1 atayangin.com 1 ateslergroup.com 1 atesoglufirinekipmanlari.com 1 atestic.com 1 atesveates.com 1 atilacicek.com.tr 1 atisanambalaj.com 1 atlantisfm.com.tr 1 atlasgaz.com 1 atliotomotiv.com 1 atolyekanepe.com 1 atomyazilim.net 1 atonenerji.com 1 atrialtd.com.tr 1 avedikyan.com 1 avrupaelektrik.com.tr 1 avtradeleasingireland.ie 1 aycelikinsaat.com 1 aydinbentonit.com 1 aydinbeyoglu.com 1

Page 46: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

46S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

aydinhidrolik.com 1 aydinlarcam.com 1 aydinnakliyat.com.tr 1 aygelektrik.com 1 aykutbalci.net 1 aymaviyesil.com 1 aysgrup.com 1 aytim.com.tr 1 ayvansaray.com 1 bademlergida.com 1 balansmatik.com 1 bankalarbirligi.org 1 banthouse.com 1 barinpimapen.com 1 basaketiket.com 1 basaktemizlik.com 1 baseyapi.com.tr 1 baskentltd.com.tr 1 batista.com.tr 1 bay-kon.com 1 bayrammuhendislik.com 1 bektastente.com 1 belmap.com 1 bemaozelguvenlik.com.tr 1 beraatkumas.net 1 betultekstil.com 1 beyendik.com 1 bi-ka.org 1 bigdel.com 1 bilcap.com 1 biltechbilgisayar.net 1 bionicinc.com 1 birgi.com 1 biyoart.com.tr 1 bizimkofte.com.tr 1 bktmakina.com 1 bogazicielektrik.com.tr 1 borahotel.com.tr 1 boralsan.com 1 borazanyumurta.com 1 bostanoglukomur.com 1 bozdaglar.com 1 bsnyapi.com.tr 1 buffnme.com 1 bugratour.com 1 buharmakinesi.com 1 bumera.com.tr 1 buraketiket.net 1 buridavulda.com 1 burkar.com.tr 1 byoguzhan.com 1 c-ertac.com 1

cadirci.com 1 cakirtekstil.com 1 cakirtorna.com 1 caliskansosyalhizmetler.com 1 camfrogsamsun.com 1 camlicacevre.com 1 camlicakagit.com 1 camp34.com 1 can-tur.com 1 canakkaletelekom.com.tr 1 canerpetrol.com.tr 1 cankayaimar.com.tr 1 cankayaofset.com 1 cantaimalati.com 1 canteknoloji.com 1 cappadoccia.com 1 cappafe.com 1 casinoliman.com 1 cates.gov.tr 1 cc-tour.net 1 celik-yapi.com 1 celikkardesler.com.tr 1 cembars.com 1 cembermakinesi.net 1 cemgrup.net 1 cemozturk.com.tr 1 cemrecerceve.com 1 cerciller.com 1 cetamuhendislik.com 1 cetinelmuhendislik.com 1 cetinpansiyon.com 1 chdotomasyon.com 1 check4mail.net 1 chellfleet.com 1 ciftliksarkuteri.com 1 cihaninsaat.net 1 cinar-insaat.com 1 cinevipsinemalari.com 1 cinevizyon.com.tr 1 ciraksan.com.tr 1 circleconsultancy.com 1 cmsturk.com 1 cngturk.com 1 connect-es.com 1 copmatik.com 1 cornext.ch 1 cotanak.net 1 cozumbu.com.tr 1 crossfittaxim.com 1 crsbina.com 1 csdizayn.com 1 csksondaj.com 1

Page 47: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

47S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

danimarkatdv.org 1 darulerkam.org 1 date.com.tr 1 degirmeninsaat.com 1 degistekstil.com 1 delamar.com.tr 1 delbonopartners.com 1 demasu.com.tr 1 denizevim.com 1 dentsa.com 1 dersservisi.com 1 dersveral.com 1 desibeltech.com 1 detayreklamcilik.com 1 dijitalmimar.com 1 dilaegitim.com 1 dita.com.tr 1 dizayncevre.com 1 dmmakina.com 1 dogusdizayn.com 1 donetrade.com 1 doremitur.com 1 dotekstil.com 1 dumakgroup.com 1 durmazhavuz.com 1 durmus.com.tr 1 dursunsigorta.com 1 dwcap.co.uk 1 e-mey.com 1 e-ticaretpaketi.com 1 ebrarahsapyapi.com 1 ecesaray.com 1 ecmyland.com 1 edelsa.com.tr 1 efeisi.com 1 efsaneoyun.com 1 egemengida.com 1 egestore.com 1 egiticininegitimi.gen.tr 1 egopsikiyatri.com 1 ekapano.com.tr 1 ekbirholding.com 1 elitereklam.com.tr 1 elitkurye.com.tr 1 ellilerinsaat.com 1 elsi.com.tr 1 emexotel.com 1 emikro.com.tr 1 emirexport.com 1 emirotomotiv.org 1 emregemigida.com 1 emreylmz.net 1

emsapalace.com 1 engelsizsanat.org 1 enopan.net 1 ensarbrode.com 1 enternetbilisim.com 1 envytextile.com 1 epar.com.tr 1 epostl.com 1 eproyazilim.com 1 erapalet.com 1 eresan.com.tr 1 ergecevre.com 1 erginmakine.com 1 erka-insaat.com.tr 1 erkaymakina.com 1 ersautu.com 1 erseletiket.com 1 erteknikcivata.com 1 ervin.com.tr 1 ERZINCANCICEKCISI.com 1 eselektronik.com 1 esineldiven.com 1 eskisehirli.com 1 evariyorum.com 1 evimpansiyonagri.com 1 evrenkaraelmas.com 1 eyardim.net 1 eydi.com.tr 1 eynel.com 1 fagokece.com 1 faktoring.com.tr 1 fatihsaygili.com 1 fatihusta.com.tr 1 favorifilmizle.com 1 fctasarim.com 1 fermolive.com 1 ferruhfiliz.com 1 fetihboya.com 1 fiberkablolama.net 1 filmionlineseyret.com 1 firatelektrik.com.tr 1 firincioglu.com 1 firmak.com 1 fishbein.org 1 fosforlumarket.com 1 fox-body.com 1 frigo.uz 1 fullobje.com 1 galvanokimya.com 1 garfi.net 1 gayaltd.com 1 gayaltd.com.tr 1

Page 48: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

48S P E C I A L R E P O R T

THREAT RESEARCH LABS

gazikonagi.com 1 gecermobilya.com 1 gencler.com.tr 1 genclider.com 1 ginolugrup.com 1 girayelektrik.com 1 giresunfirma.com 1 globalconnectiontz.com 1 gokhanhidrolik.com 1 golyazinakliyat.com 1 gonengulinsaat.com 1 gorkempoli.com 1 gozdecocuklar.com 1 granitsitesi.com 1 grenstudio.com 1 groupenerji.com 1 groupprogress.com 1 guclumatbaa.com 1 guldemkimya.com 1 gunaypano.com.tr 1 gundogdular.com.tr 1 gunesmedical.com 1 guneysu.net 1 gurdemirplastik.com.tr 1 gurogullari.com 1 gursellaminasyon.com 1 guventicaret.com 1 haberdosya.com 1 hakankarman.com 1 haktanhukuk.com 1 haliciinsaat.com 1 halkpen.com 1 hamzaertas.com 1 harputplastik.com 1 hasbirlik.com.tr 1 hateker.com 1 havuzvesauna.com 1 hdt.com.tr 1 healthwaytr.com 1 hemas.com.tr 1 hisarcivata.com 1 hodhodtravel.com.tr 1 host-ota.com 1 htmturkey.com 1 hukukavukat.com 1 icywave.com 1 idkgrup.com 1 idriskasap.com 1 ikev.org 1 iksad.org 1 ilacevi.com 1 imkendustri.com 1

inanceyuboglu.com 1 industryline.net 1 innoactive.com.tr 1 insaatfuarlari.com 1 inter.tc 1 ipekfantazitekstil.com.tr 1 ipekliler.org.tr 1 iro.org.tr 1 isiksaglik.com 1 isimanlamibul.com 1 isimtescil.com 1 istanbuldinamik.com 1 istanbulhandicraftcenter.com 1 istanbulsporenvanteri.com 1 istanbulucuzlukpazari.com.tr 1 istifyapi.com.tr 1 itumhk.com 1 ivmebilisim.com 1 iyidenkgeldi.com 1 iyifikirtanitim.com 1 izmirpsikolog.net 1 jenmak.com 1 jetboatantalya.com 1 jetbodrum.com 1 kaanendustri.com 1 kafkassam.com 1 kahramanmarascicekci.com 1 kalkan-kalkan.com 1 kandemirkopyalama.com 1 karakasturizm.com 1 kardeslerbilisim.net 1 kardeslertemizlik.net 1 karebigbag.com 1 kariyersokagi.com 1 karmamakina.com 1 karostur.com 1 karpismaniye.com.tr 1 karteksgroup.com 1 kastamonumimozacicekcilik.com 1 katlav.com 1 kavustur.com.tr 1 kayapinar.av.tr 1 kaymazlar.com.tr 1 kayraiplik.com 1 kazancimining.com 1 kdtm.com.tr 1 kebankasap.com 1 kibda.com 1 kibristransfer.com 1 kidabilgisayar.com.tr 1 kilicasansor.com 1 kilicinan.com 1

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

Page 49: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

49S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

kimpaticaret.com 1 kir-bahcesi.com 1 kirgaz.com.tr 1 klasteknik.com 1 kmit.com.au 1 KOCAKSYAPI.com 1 kokselvinc.com 1 komurcuoglugroup.com 1 konakyeri.com 1 konmaksan.com 1 kontrolmuh.com 1 koseogullari.com.tr 1 krempark.com 1 kriter.com.tr 1 kucukdahiler.com 1 kultursanat.org 1 kurarazkargo.com 1 kurmakyapi.com 1 kursathoca.com 1 kusaktekstil.com 1 kutlumakina.com.tr 1 lasido.com.tr 1 laviron.com 1 lazca.org 1 lbdmuhendislik.com 1 ledistanbul.com.tr 1 ledsanat.com 1 lemasfilter.com 1 lemazi.com 1 lemisglobal.com 1 liderotobus.com 1 littlemusicclub.com 1 livamedikal.com 1 longlineus.com 1 lotus7.club 1 lsmimarlik.com.tr 1 ltstelekom.com 1 ltsyazilim.com 1 m-arslan.com 1 magnesiaweb.com 1 makaratatlisi.com 1 makdis.com 1 maksiminsaat.com 1 maktas.com.tr 1 malatyasafakofset.com 1 maralinsaat.net 1 marka-reklam.net 1 marmarameslekkursu.com 1 marmiad.org 1 martsigorta.com 1 martysbuickgmc.com 1 marysmeals.at 1

masdisticaret.com 1 masisan.com 1 masterbt.com 1 matbaamakineleri.com 1 maviguzelsanatlar.com 1 mavimi.com 1 maviyilmazlar.com 1 maxenbibi.nl 1 mbox.com.tr 1 me-hayapi.com 1 megaboya.com 1 megamarine.com.tr 1 mehmetvolkanaksoy.com 1 mengeninsesi.com 1 meritotokiralama.com 1 mersinisg.com 1 mertcivata.com 1 mertkavi.com 1 mesetmimarlik.com.tr 1 metaltekmutfak.com 1 metimsan.com 1 mevcert.com.tr 1 meyainsaat.com 1 microfiber.com.tr 1 midasstudio.com 1 migfed.com 1 mijid.org 1 mikrosan.com 1 mikroticaret.com 1 miksen.org.tr 1 milliarge.com 1 miractaahhut.com.tr 1 mj-support.com 1 modernist.com.tr 1 monparnas.com 1 morcilek.net 1 mossa.com.tr 1 mseyapi.com 1 msg.co 1 msygrup.com 1 muffleyware.com 1 muhasebecom.com 1 mujdatozkan.com 1 mustafatig.com 1 mygulet.com 1 myhamam.com.tr 1 mykteknoloji.com 1 mymoonkaraokebar.com 1 mzekiosmancik.com 1 nak-kargo.com 1 nazif.org 1 nesilbilgisayar.com 1

Page 50: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

50S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

netcraft.co.za 1 nickservice.com 1 nikrotek.com 1 niobetasarim.com 1 nocomment.com.tr 1 nostaljiburada.com 1 noteks.com.tr 1 novacasa.com.tr 1 nurulex.com 1 oemoil.com 1 office-inn.com 1 ofissanmobilya.com.tr 1 ogrenmeli.com 1 oguzcandurutas.com 1 oguzyazici.com 1 okfagrup.com 1 olamturkey.com 1 olyphia.nl 1 ondermatbaasi.com 1 onelmatbaa.com 1 onlinedestek.com 1 opkol.com.tr 1 optimum.gen.tr 1 orgamed.web.tr 1 organikdizayn.com 1 oyacetinkaya.com 1 oz-kaetiket.com 1 ozaktas.com 1 ozalkocak.com.tr 1 ozalpgroup.net 1 ozdemirorme.com 1 ozelatolye.com 1 ozelhukuk.com 1 ozelipekyoluhastanesi.com 1 ozenkimya.net 1 ozenprofil.com.tr 1 ozgulozgule.com 1 ozgunpano.com 1 oziltekstil.com 1 ozlergrup.com 1 ozsahinambalaj.com 1 ozsubasi.com 1 oztanelektrik.com 1 panagiotopoulos.biz 1 parkaden.com.tr 1 patentmuhendisi.com 1 pdmcelik.com.tr 1 pektechnic.com 1 pencereburada.com 1 pendikesnaf.com 1 perspektifgrup.com 1 pestcheck.com.tr 1

petshinesisli.com 1 pinarbasimatbaacilik.com 1 piramitgrup.com.tr 1 plastim.net 1 pocanofset.com 1 poztech.com.tr 1 pratikpc.com 1 prestijkodlama.com 1 pro-sales.ch 1 progum.com.tr 1 promarket.com.tr 1 prusasanat.com 1 purbeckpeloton.co.uk 1 pusulaonline.com 1 queensgarden.net 1 radyodogu.com 1 rahmiyilmaz.com.tr 1 ratoss.com.tr 1 reelkimya.com 1 regagroup.com 1 remaskablo.com 1 remax-yenicem-ist.com 1 remzitekeli.com.tr 1 retroyapi.com.tr 1 revakosgb.com 1 rokmakina.com 1 romhser.com 1 rtaturizm.com 1 rubadecor.com 1 sabir.com.tr 1 sahrademir.com 1 sahseramik.com.tr 1 sahyap.com 1 saltaselektrik.com 1 sampolinsaat.com 1 samsuntekstil.com 1 sanitamax.com 1 sarikadi57.com 1 sass.com.tr 1 sasun.org 1 saunavehavuz.com 1 say-med.com 1 sayardan.com 1 sayginoto.com.tr 1 saygireklam.com 1 sayintabela.com 1 schreiner-rabe.de 1 sdfmobilya.com 1 seckinbalikcilik.com 1 sector.com.tr 1 sehaenerji.com.tr 1 selbim.com 1

Page 51: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

51S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

seldus.net 1 selkaguvenlik.com 1 selpaltd.com 1 semaalemdar.com 1 semihaberksoy.com 1 semtakimya.com 1 senkrongrup.com 1 serdardegerli.com 1 serefsanlioglu.com 1 serenayinsaat.com.tr 1 sergazltd.com 1 serhastekstil.com.tr 1 serinsogutma.com 1 serkamermer.com.tr 1 serkozmetik.com 1 serpantine.com 1 serva.com.tr 1 seryapim.com 1 sevvalinsaat.com.tr 1 sexshopmersin.com 1 seyhantip.com 1 seyitoglu.net 1 sezerler.com.tr 1 sezgintay.com.tr 1 sezgold.com 1 sezigayrimenkul.com 1 siberplastik.com 1 simamobilya.com.tr 1 simetrimatbaacilik.com 1 sinerjigida.com 1 sinerjimuhasebe.com 1 sirinakbulut.com 1 sis-cons.com 1 sistemicmimarlik.com 1 sistemortopedi.com.tr 1 sistemtercume.com 1 skzlojistik.com 1 smmmtanzerozkan.com 1 sosyaliklim.org 1 soylumefrusat.com 1 sraydinlatma.com 1 staddan.com 1 starbaca.com 1 stepinsaat.com 1 sterimate.com 1 stkimya.com.tr 1 stomadenta.com 1 suleymanozkaya.com 1 sunbeamfostering.co.uk 1 surotel.com 1 sweetjax.com 1 taksiduraklari.net 1

talentrich.org 1 tansav.com.tr 1 TAPAMARKET.com 1 tapasan.com 1 tarikyildiz.com 1 tasdemirlerun.com.tr 1 tat-mak.com 1 tata.com.tr 1 tayfuntrade.com 1 tcs.com.tr 1 tdpeyzaj.com 1 tebim.com.tr 1 tekbilgi.net 1 tekbirhali.com 1 tekinalpgroup.com 1 tekiselektrik.com 1 teknikaaluminyum.com 1 tekniktr.com 1 teknikyatirim.com 1 teknobookbilisim.com 1 teknogrand.com.tr 1 teknopolitan.com 1 teknopoll.net 1 teknoriumbilisim.com 1 teknosepet.com 1 teknostil.com.tr 1 teknotel.net 1 temelofset.com 1 tennure.com 1 teperaf.com 1 terlik.com.tr 1 teslamuhendislik.net 1 theiselaw.com 1 tijda.com.tr 1 timurtaskomur.com 1 tinkdavet.com 1 tknelektrik.com 1 tlslojistik.com 1 topdemir.com.tr 1 toprakkirtasiye.com 1 topraktrading.com 1 trabzonturkuaz.com 1 travelmodus.com 1 trio.gs 1 truvagroup.de 1 tspik.com 1 tttsd.org.tr 1 tuluklar.com 1 turksal.com 1 turkuazmarine.com 1 turteknesi.com 1 tusemco.com 1

Page 52: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

52S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

tut-al.com 1 tykonpharma.com 1 ucuncu-goz.com 1 ufcotomotive.com 1 ufukguvenliksistemleri.com 1 ugurcan.org 1 ulkugulu.com 1 uluerinsaat.com.tr 1 ulusalsavunma.com 1 umpasseramik.com 1 umsteknik.com 1 umurkaya.com 1 umutbarak.com 1 universaldecoration.com 1 usertrust.com 1 uskovski.com 1 ustduzey.com.tr 1 uyaryapi.com 1 uygarboya.com 1 uygunofset.com 1 uzelyatcilik.com 1 uzmanmermer.com 1 v-pills-penisbuyutucu.com 1 vangolu.com.tr 1 vatannakliyat.com 1 vedatgececi.com 1 venusmakine.com 1 venustasarim.com 1 VESTELSERVISIGEBZE.com 1 viptasarim.net 1 viradenizcilik.com 1 vitoxguvenlik.com 1 vizyonmatbaa.com 1 vizyonproduction.net 1 vizyonweb.com 1

volansjeans.com 1 volber.com.tr 1 volgaveteriner.com 1 waffle.com.tr 1 webhero.nl 1 webklavuzu.com 1 weldergrup.com 1 wilcomfg.com 1 wouthuis.nl 1 x5.tC 1 xn--tekyap-u9a.com 1 xyajans.com 1 yagmurorman.com 1 yalovaorganica.com 1 yapimmimarlik.com.tr 1 yaprakpsikoloji.com 1 yavuzreklam.net 1 yaziada.com 1 yazmiyor.com 1 yetenekticaret.com 1 yigitgida.com.tr 1 yildizyakamoz.com 1 yilkap.com 1 yilmazpetrol.net 1 yilmazvinc.com.tr 1 yonforklift.com 1 yongazetesi.com 1 yukseluzhan.com 1 zekimusavirlik.com 1 zenginofset.com 1 zeybeklaw.com 1 znskimya.com 1 zproduksiyon.com 1 zsistem.net 1 zymaydinlatma.com 1

Total Result 85,419

Page 53: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

53S P E C I A L R E P O R T

THREAT RESEARCH LABS

Appendix B: “Status of invoice” Attack

Country Sum - Count Of Emails

VN 6,895 IN 4,148 MX 1,982 TR 1,147 BR 1,063 ID 931 BD 761 IR 731 CO 724 AR 406 IT 385 PK 331 TH 284 BO 274 KE 234 ES 221 PL 185 ZW 174 PH 158 IL 152 MK 132 VE 132 BG 119 DE 114 US 107 GR 105 KH 101 RS 96 JO 91 CI 88 EC 85 ZA 85 DO 83 RO 79 LA 74 NP 65 MY 59 NG 59 GB 57 MN 53 GT 50 PE 48 UY 47 MA 46

Country Sum - Count Of Emails

NI 42 PA 40 CL 38 EG 36 FR 36 SA 36 SG 36 MM 34 HN 33 HR 30 AL 29 LB 27 AU 26 BE 24 CM 24 TN 24 TZ 24 MZ 23 PS 23 NL 22 SK 20 UG 19 DZ 18 JM 18 LY 18 BA 17 PY 17 CD 16 CR 16 OM 16 UA 16 AT 14 KW 14 BT 13 ME 13 SV 13 ZM 13 CN 12 HU 12 CA 10 MU 10 BN 9 CH 9 LK 9

Page 54: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

54S P E C I A L R E P O R T

THREAT RESEARCH LABS

Country Sum - Count Of Emails

NA 9 AF 8 AO 8 GQ 8 SD 8 BW 7 CW 7 GH 7 JP 7 KY 7 RW 7 MT 6 SC 6 ET 5 LT 5 PT 5 AE 4 BF 4 CY 4 DK 4 IQ 4 MG 4 ML 4 TW 4 BH 3 IE 3 KR 3

Country Sum - Count Of Emails

LU 3 MV 3 NZ 3 UZ 3 CV 2 CZ 2 HK 2 MD 2 MR 2 SI 2 BJ 1 CG 1 FI 1 FJ 1 GA 1 GE 1 GM 1 KZ 1 LS 1 MO 1 MW 1 NE 1 QA 1 RU 1 SE 1 SO 1 ST 1

Total Result 24,302

Page 55: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

55S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

Vietnam Posts and Telecommunications(VNPT) 4,155Airtel Broadband 1,546VDC 1,315Turk Telekom 868Viettel Corporation 657Iusacell 461CMC Telecom Infrastructure Company 367Telmex 348Bharti Airtel 345No Range Owner 282SHATEL DSL Network 231Cablevision, S.A. de C.V. 220TATA Communications 219Telmex Colombia S.A. 217Cablemas Telecomunicaciones SA de CV 215FPT Telecom Company 215FASTNET 211Axtel 201True Internet 199UNE 176Mega Cable, S.A. de C.V. 172Agni Systems Limited 171Telecom Italia 159Aria Shatel Company Ltd 155PT Indosat Tbk. 153Vivo 149Cablevision 137Asianet 122Tellcom Iletisim Hizmetleri A.s. 117Fastweb 106Mahanagar Telephone Nigam Ltd. 104Syscon Infoway Pvt. 104MPLS ADSL Broadband 99Airtel 98Bharti Broadband 97In2cable.com (India) 96Bezeq International 94ONECOM 93D-Vois Broadband Pvt 92Tv Azteca Sucursal Colombia 92Global Village Telecom 90Aamra Networks Limited 87Telefonica de Argentina 87Bolivia S. A. 86Neda Gostar Saba Data Transfer Company Private Joi 86Alestra, S. de R.L. de C.V. 85PT Telkom Indonesia 85Cote d’Ivoire Telecom 83Oi Internet 78Three Indonesia 75Virtua 74Bharti Airtel Ltd., Telemedia Services 73PERN AS Content Servie Provider, Islamabad, Pakist 72

Mexico Red de Telecomunicaciones, S. de R.L. de C. 70Unitel 68ACCESSKENYA GROUP LTD is an ISP serving 67Blizoo DOOEL Skopje 66Tata Teleservices Maharashtra Ltd 62DCTV Cable Network Broadband Services 60National Telecommunication Corporation HQ 60Pars Online PJS 57CANTV 55Claro Dominican Republic 55ETB 54Tata Teleservices ISP 54Honesty Net Solution (I) Pvt 51Oi Velox 51VietNam Telecom National 50NSS S.A. 49Meghbela Broadband 47Telefonica Celular de Bolivia S.A. 47Administracion Nacional de Telecomunicaciones 45Jazz Telecom S.A. 45PT. Cyberindo Aditama 44Tata Indicom 44Nepal Telecom 43Philippine Long Distance Telephone 43Telefonica Venezolana 43Telone 43Vivacom 43Chi nhanh MienBac-Cong ty CP Ha Tang Vien Thong CM 41TRD ROBI DOOEL 41Southern Online Bio Technologies Ltd 40Ecuadortelecom S.A. 39RailTel Corporation of India Ltd. 39Beam Telecom 38Orange Polska 38SINET, Cambodia’s specialist Internet and Telecom 38Batelco Jordan 37BSNL 36Hathway 36Vodafone India 36PTCL 35Ranks ITT 35TM Net 35Delta Infocom Limited 34Telefonica de Espana 34Angel Drops Ltd 33COTAS 33Internet by Sercomtel S.A. 33ADN Telecom Ltd 32Global Iletisim Hizmetleri A.S. 32BDCOM Online Limited 31Cablemas Telecomunicaciones (merida) 31SingNet Pte Ltd 31Telefonica Data S.A. 31

Page 56: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

56S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

Vodafone Italia DSL 31CTBC 30Telecom Argentina S.A. 30Vodafone Ono 30D-VoiS Broadband Private Limited 29Eastern Telecoms Phils., Inc. 29Entel S.A. - EntelNet 29Hireach Broadband Private Ltd 29Internet Service Provider 29TE Data 29PT Media Sarana Data 28S.I Group 28Tehran Kar Ara 28Cyfrowy Polsat MVNO mobile broadband services 27Dishnet Wireless Limited. Broadband Wireless 27Telefonica del Peru 27Kabel Deutschland 26MTN Nigeria 26X-Link Limited 26BRAC BDMail Network 25Information Society S.A. 25Tellas S.A. 25Transworld Associates (Pvt.) Ltd. 25Universidad De Antioquia 25Bharti Cellular Ltd. Mumbai 24EMCATEL 24Tata Mobile 24TRICOM 24Vodafone DSL 24Vodafone Spain 24Wan & Lan Internet Pvt 24Comteco Ltda 23Vietnam Posts and Telecommunications (VNPT) 23Wateen Telecom 23Bangladesh Online Ltd 22Baru Hosting 22Delhi Gsm Ip Pool 22Deutsche Telekom AG 22Empresa De Telecomunicaciones De Pereira S.A. 22Md. Abdul Awual t/a Cyber Way Technology 22Navega.com S.A. 22Telecomunicacoes Ltda 22Broadband Pacenet Pvt. 21Cogetel Online 21Cotas Ltda. 21Galaxy Brasil Ltda 21Maroc Telecom 21Mob Telecom 213BB Broadband 20Gtel Tijuana 20Kenyan Post & Telecommunications Company / Telkom 20RCS & RDS Business 20Serbia BroadBand-Srpske Kablovske mreze d.o.o. 20

Sify Limited 20Vodacom 20VTR Banda Ancha S.A. 20Citinet LLC 19Milleni.com 19Orange Espana 19OTEnet S.A. 19PT Tele Globe Global 19UPC Polska 19Viewqwest Pte Ltd 19CityOnline Services Ltd 18CS LoxInfo 18Mobily 18Orange Israel 18Reliance Communications 18Tanzania Telecommunications 18Transtelco S.A. 18Augere Wireless Broadband Bangladesh Limited 17Blizoo Media and Broadband 17Dai IP tinh cho khach hang xDSL 17Libyan Telecom and Technology 17Linkdotnet-Jordan 17Mongolia Telecom 17Net Uno, C.A. 17Redes y Telecomunicaciones 17TELEKOM SRBIJA a.d. 17Telkom Internet 17TM International Bangladesh 17Triple Play Broadband Private Limited 17TVCABO - Comunicacoes Multimedia, Lda. 17Comcast Cable 16Comilla Online 16DSL-Elektronika d.o.o. 16Pulse Telesystems Pvt Ltd 16Vectra Broadband 16Cablevision S.A. de C.V. 15delDSL Internet Pvt. Ltd. 15Media Commerce Partners S.A 15Mobilink Mobile Internet 15Proximus Skynet 15Railtelibwcustomers 15Time Warner Cable 15Tripleplay Broadband Pvt Ltd 15Vung dia chi IP cap cho dich vu IPTV tai Ha Noi 15Wsp Servicos de Telecomunicacoes Ltda 15AXS Bolivia S. A. 14B.Net Hrvatska d.o.o 14BT 14Cable & Wireless Jamaica 14Cotel Ltda. 14Empresa de Infovias S.A. 14Euskaltel S.A. 14Information Technology Company (ITC) 14

Page 57: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

57S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

IPStaticMarocTelecom 14MNC Playmedia 14Neuviz Net 14Nova Rede de Telecomunicacoes Ltda 14S.A. E.s.p 14Dishnet Wireless Limited 13DrukNet ISP 13KNK Telekomunikasyon Iletisim Elektrik Sanayi Tica 13Nettlinx Limited 13S.A. E.s.p. 13Smart Link Communication 13Telecentro S.A. - Clientes Residenciales 13Vodafone Italia 13Wananchi-ke 13012 Smile Communications 12Cable Onda 12COOLLINK 12EARTH TELECOMMUNICATION (Pvt) 12IDS Bangladesh. IP Transit provider. Dhaka, Bangla 12INDO Internet, PT 12Polkomtel Sp. z o.o. 12TeleCable 12Varnion Technology Semesta, PT 12Vasai Cable Pvt. Ltd. 12Yashtel 12ZOL Zimbabwe Assignments 12Autonomous System Number for Nexlinx 11China Telecom jiangsu province backbone 11Comcast Business Communications 11Intech Online Private Limited 11Megacable Comunicaciones de Mexico, S.A. de C.V. 11PT Quantum Tera Network 11Rasaneh Avabarid Private Joint Stock Company 11Shree Cable 11Techtel LMDS Comunicaciones Interactivas S.A. 11Telefonia Celular de Nicaragua SA. 11UPC Romania SRL 114ALB shpk 10afczas 10Afrihost 10AlwaysOn Network Bangladesh 10Global Tecnologia Ltda Me 10Metro Net, S.A.P.I. de C.V. 10Olo del Peru S.A.C 10Quest Consultancy Pvt Ltd 10SOLNET-Customer-Serial 10Telecel S.A. 10Telecomunicacoes Ltda. 10TELEKOM SRBIJA, ADSL users 10Telstra Internet 10Toseh Ertebatat Homa (Private Joint Stock) 10Ver Tv S.A. 10WIND Telecomunicazioni S.p.A 10

Abastecedora de Conectividad, S.A. de C.V. 9CMPak Limited 9Digital Network Associates Private Limited 9Fivenetwork Solution India Pvt Ltd Internet 9Idea Cellular 9Interdomain Routing 9Itelkom S.A.S 9Jordan Telecommunications Company 9KENYAWEB 9Mahbub Morshed t/a Mahi Enterprise 9Makedonski Telekom AD-Skopje 9Malaysian Research & Education Network 9Maxcom Telecomunicaciones, S.A.B. de C.V. 9Netnam Company 9OCPT 9Orange 9Orange Polska Mobile 9Orange Slovensko a.s. 9PON Services 9PT Excelcomindo Pratama 9PT Solnet Indonesia 9PT. Net2Cyber Indonesia 9Sampark Estates Pvt. Ltd. 9Sul Americana Tecnologia e Informatica Ltda. 9Superonline Iletisim Hizmetleri A.S. 9Telecommunication Infrastructure Company 9Telematix/ Enitel 9Tim Celular S.A. 9TOT 9TPG Internet 9Aamra technologies limited 8Akton d.o.o. Network 8AUGERE-Pakistan 8Bcl South 8Bharti Airtel Limited 8Bharti Airtel Ltd., TELEMEDIA Services, for SMB cu 8BRACNet Limited 8Cablecolor S.A. 8Cameroon Telecommunications Network 8CPS 8Crnogorski Telekom a.d.Podgorica 8Doruk Iletisim ve Otomasyon Sanayi ve Ticaret A.S. 8EWE-Tel GmbH 8hellas online Electronic Communications S.A. 8Internet Access & Telecom Carrier Service Provider 8Internet Solutions 8Internet Thailand Company Limited 8Inwi Mobile 8Iran Cell Service and Communication Company 8Jordan Tv Cable & Internet Services Co 8kasatech informatica 8Libantelecom 8Nacional De Telecomunicaciones - Cnt Ep 8

Page 58: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

58S P E C I A L R E P O R T

THREAT RESEARCH LABS

NETCEN Teknoloji Ltd. Sti. 8Ngs-adsl Users Shz 8Protel I-Next, S.A. de C.V. 8Przedsiebiorstwo Handlowo Uslugowe Kamdex Grzegor 8PT Maxindo Mitra Solusi, Jl Kelapa Puan Raya Blok 8PURISCAL 8Rainbow communications India Pvt Ltd 8Siticable Network Limited 8Summit Communications Ltd. 8Symphonet Sdn Bhd 8Tiscali SpA 8TurkNet Iletisim Hizmetleri A.S 8YUnet International d.o.o. 8Axtel - Recursos WiMAX 7Britis Telecom LTDA 7Broadband ISP, FTTH and Cable Service Provider 7Costra S.A. 7Cyprus Telecommuncations Authority 7Ebone Network (PVT.) Limited 7Empresa de Telecomunicaciones de Pereira S.A. E.S. 7Forthnet 7FORTHnet SA 7Hexabyte 7IFX Corporation 7Ifx Networks Colombia 7IndoInternet Network 7Informatica E Provedor Ltda 7Netcomm Argentina SRL 7NETLIFE 7Oasis-sprl 7Panda Network 7Safaricom 7Serviciul de Telecomunicatii Speciale 7Sikka Broadband Pvt. 7Sky Broadband 7Skyline Semesta, PT 7Skylogic S.p.A. 7Teknotel Telekomunikasyon Sanayi Ve Ticaret A.s. 7Telconet S.A 7Tele Globe Global, PT 7Telecom Namibia 7Telefonica Movistar 7TRUE, The Real Unix Experts 7United Telecommunication Services (UTS) 7Wind Telecomunicazioni 7Yota De Nicaragua 7YOU Broadband & Cable India Ltd. 7Zajil Telecom 7ZOL GPON Home Users 7Asiatech xDSL Network 6Broadlink Nepal 6BT Italia S.p.A. 6BTC Broadband Service 6

CallU Telecomunication Ltd. 6Charter Communications 6Corporacion Nacional De Telecomunicaciones - Cnt E 6Daisy Communications Ltd 6Digital Cable Television ltd 6Equipos Y Sistemas S.A. 6Ethernet Xpress Pvt. Ltd. 6Etisalat Misr 6Fiber customers 6Five network Broadband Solution Pvt Ltd 6Grameen Cybernet Ltd. Bangladesh. 6Infracom Italia S.p.A. 6Iomart Hosting Limited 6IP Core MPLS 6Israel Local Authorities Data Processing Center Lt 6Jupiter Telecomunicacoes e Informatica Ltda 6L E M Telecomunicacoes Ltda -me 6Level 3 Communications 6Micom-network-corporate-cust 6Micropic Ltda 6MTN Uganda 6Newcom Limited 6OptiMax COmmunication Ltd 6PADINET - Padi Internet 6Paknet Limited Merged into PTCL 6Palestine Telecommunications Company (PALTEL) 6Pardis Ettela Resaan Sepehr 6PT NIDS Indonesia 6QSC AG 6R Cable y Telecomunicaciones Galicia, S.A. 6Redes y Comunicaciones de Michoacan S.A. de C.V. 6SAT-TRAKT Telecommunications 6SaudiNet 6SFR 6Simpur ISP 6Sodetel S.a.l. 6Solusindo Bintang Pratama, PT 6Sspnet Com De Equip. De Tele Informatica 6StarHub Cable Vision Ltd 6TalkTalk 6Telecentro S.A. 6Telecom Ltda Epp 6Telecommunication Company of Tehran 6United States Air Force 6Via Real Internet Equipamentos de Informatica Ltda 6Virgin Media 6Vsat- Telecomunicacoes Ltda 6XFone 018 6Abissnet sh.a. 5Angkor Data Communication 5Apollo Online Services Pvt ltd 5Arrownet Pvt.Ltd 5Asiatech DSL Broadband Services 5

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

Page 59: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

59S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

Asmanfaraz Sepahan Isdp (pjs) 5Assign for BuddyBB customers 5BeotelNet-ISP d.o.o 5Btc-gate1 5Cable Tica 5Chi nhanh HCM-Cong ty CP Ha Tang Vien Thong CMC 5Comcel Guatemala S.A. 5CONECEL 5Creolink 5Dialog Telekom Plc 5Eskisehir Bilisim Iletisim San. ve Tic. A.S. 5Evergy S.A. 5Excellmedia 5Fariya Networks Pvt. 5Fiber @ Home Limited 5Fixed IP for cable modem customers 5Freitas Servicos de Internet Ltda 5Fureai Channel Inc. 5Geocity Network Solutions Pvt Ltd 5GO p.l.c. 5Gtd Internet S.A. 5Ha Noi Post and Telecom Company 5Hotel Paramount 5Infocom-ug 5ipNX NIGERIA LIMITED 5Is Net Elektonik Bilgi Uretim Dagitim Ticaret ve I 5Javne adrese za ADSL korisnike 5Jordan Data Communications Company LLC 5JP Posta Srbije Beograd 5K2 Telecom e Multimidia LTDA ME 5Liquid Telecommunications Operations Limited 5Metronet telekomunikacije d.d. 5Multinet Pakistan Pvt. Ltd. 5National Information Technology Authority Uganda 5Natural Fenosa Telecomunicaciones Guatemala S.A. 5ONO 5Orange Internet 5Orion Telekom Tim d.o.o.Beograd 5Pakistan Telecommunication Company Limited 5PARO SA 5Proimage Engineering and Communication Co.,Ltd. 5PT. Hipernet Indodata 5Pt. Linknet 5SAGLAYICI Teknoloji Bilisim Yayincilik Hiz. Ticare 5Sc Netfil Srl 5Shiraz Hamyar Co. 5Simbanet-as 5Sociedad Cooperativa Popular Limitada de Comodoro 5Soluciones en Telecomunicaciones, S.A. 5Sudatel 5Swift Online Border 5Tecmidiaweb Ltda 5Telecom Ltda. 5

Telekom Romania Communication S.A 5Telemasters 5Television Internacional, S.A. de C.V. 5Telgua 5Tiscali UK Limited 5Unitymedia NRW GmbH 5Universitas Negeri Semarang 5UPC Austria GmbH 5Verizon FiOS 5Vodafone Ghana 5WHS Telecom Serv. Telecomunicacoes LTDA 5Wicom Networks LLC 5Ziggo 5ZONE Technologies Ltd 5A Multihomed ISP Company 4ABSOLUT SOLUTIONS d.o.o. 4Afghantelecom Government Communication Network 4Africa Online Uganda 4Alfanumeric S.A. 4AmberIT Limited 4ardebil telecommunication company 4Areca Business Center Srl 4Bangladesh Telecommunications Company Limited (BTC 4Bayan Telecommunications Inc. 4Bluebird Network 4Brasileira De Telecomunicacoes Sa-embratel 4Broad Band Telecom Services Ltd 4Broadband Plus 4BTTB 4Cablevision Red SA de CV 4Center Prestadora Servicos S/C Ltda 4CJONLINE ISP India 4Claro Peru 4Clouditalia Telecomunicazioni S.p.A. 4CNS Systems s.r.o. 4Colombia Telecomunicaciones S.A. Esp 4Comclark Cable 4Convergenze S.p.A. 4Cooperativa Telefonica Pinamar Ltda. 4COTES Ltda. 4Ctbc Multimidia Data Net S/a 4Customer wireless connectivity link addresses 4Dialog Axiata PLC. 4Digital Network Associates Pvt 4Directnet Prestacao de Servicos Ltda. 4dos Santos Informatica 4Embratel 4Etihad Atheeb Telecom Company 4FLOW 4GETESA (Orange Equatorial Guinea) 4Golden Telecom LLC 4GramBangla Systems Limites, Internet and Data Comm 4Grameenphone Ltd. 4

Page 60: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

60S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

Grupo Hidalguense de Desarrollo, S.A. de C.V. 4Guineanet 4HEC 4IACTCOM 4ICS Advanced Technologies 4Informatica y Telecomunicaciones S.A. 4Infostrada IUnet 4Intelligent Technologies S.A. 4Kabel BW 4KPNQWest Italia S.p.a. 4L. Garcia Comunicacoes ME 4Line Telecomunicacoes Ltda 4LINKdotNET Telecom Limited 4Linx Telecommunications B.V. 4M-net 4Maria Irma Salazar 4MauritiusTelecom 4Mercantile Communications Pvt. Ltd 4Metrotel SA ESP 4MNI Telecom S.A. 4Mobiltel Ead 4Mobinnet WiMAX Network 4MTN Business Solutions 4MTNRW 4Mundivox LTDA 4National Institute of Technology, Srinagar 4Netia SA 4Nour Communication Co.Ltd - Nournet 4ONATEL/FasoNet’s 4One Macedonia 4Operbes, S.A. de C.V. 4Orange Madagascar 4Orbit Telecom Technology Co. Ltd 4Pakistan Telecommuication company limited 4Paratus-Telecom 4PJSC Fars Telecommunication Company 4Play 4PT Comtronics Systems 4PT DES Teknologi Informasi 4PT Jembatan Citra Nusantara 4PT Jovimaro Karya Agung 4PT Solusi Aksesindo Pratama 4PT. Cahaya Buana Raksa 4PT.Insan Sarana Telematika 4Quadrant Televentures Limited 4Radore Veri Merkezi Hizmetleri A.S. 4Rajesh Patel Net Services Pvt. 4Ramiro Alfonso Gomez Caicedo 4RCN 4RCS 4Romtelecom Data Network 4SaiGon Tourist cable Televition Company 4salt Lake,Sector-V,Electronic Complex 4

Satnet 4Servicos De Telecomunicacoes Ltda 4Servico Comunicacao Multimidia Ltda 4Sikka Cable 4Telecable Central, S.A. 4Telecom Ltda 4Telenet N.V. 4TelkomInternetBroadband 4Thiel e Da Rosa Ltda 4TOPNET 4Tri Telecom 4TTCLDATA 4TVCabo Angola 4TVCABO Beira 4UniNet(Inter-university network) 4Universitas Udayana 4Vainavi Industies Ltd 4Vex Net Telecon 4Virtex Ltda 4Vodafone Net Iletisim Hizmetleri A.s 4Wifirst S.A.S. 4Y Sistemas S.A. 4116 Madhav Darshan 32Bite s.r.l. 3A. L. A. Informatica Ltda. 3ABCOM Shpk 3Acer Telecomunicacoes ltda 3Adamo Telecom Iberia S.A. 3AgresteNet Com e Serv LTDA - ME 3Algerian Academic Research Network 3America Online 3Asre Enteghal Dadeha 3Atel Telecom 3Azteca Sucursal Colombia 3BBBell s.r.l. 3Belnet Snina, s.r.o. 3Bharti Telenet Ltd.mumbai 3Bittel Telecom Pvt Ltd 3blueconnect 3BroadLink Networks and Communications 3BruNet - Telekom Brunei Berhad 3Cablenet S.A 3Call U Communications Ltd. 3Clientes Guayaquil 3Co.pa.co. 3Communication Solutions Ltd. 3Contabo GmbH 3Core infrastructure 3Corporacion Digitel C.A. 3CrazyDomains 3Cromtel Prod Impex Srl 3Den Digital Entertainment Pvt. Ltd. AS ISP india 3Dhivehi Raajjeyge Gulhun (Dhiraagu) 3

Page 61: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

61S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

Diogo Cassio Cabral Me 3Domtel Telecom Dariusz Dombek 3ESCOM Ltd. - Haskovo 3Ethiopian Telecommunication Corporation 3Etisalat Afghan 3Fanava Group 3Fibra Telecom Ltda - EPP 3G TEL Comunicacion, S.A.P.I. de C.V. 3GlobalNet S.A 3HiNet 3Hostlocation Ltda 3Hoteli Zivogosce d.d. 3HTT 3HYPERIA Ltd 3ICPNET Cable 3IHS Telekomunikasyon Ltd 3Imatech Networks, S.A. de C.V. 3IncoNet Data Management sal 3Indian Institute Of Logis 3Indusind Media and Communications Ltd. 3INEA Network 3Informatica e Telecomunicacoes Ltda. 3Instalnet Szabat Rydzewski Spolka Jawna 3Intech Online Pvt Ltd 3Intelvision Ltd 3Interjato Servicos de Telecomunicacoes Ltda. 3Internet Group Ltd 3IPNXng 3Islamic Azad University of Mashhad 3Jazztel Mobile 3KIRZ Service Provider 3Kottayam Cable Channel Distributors Pvt LTD 3KPN 3Kuresel Beta Teknoloji Telekomunikasyon Sanayi Tic 3Lao Telecom Communication, LTC 3lazernet.com.br ltda me 3LCR Telecom NV 3LINKNET 3Luxembourg Online S.A. 3Media Antar Nusa PT. 3Mediacom Cable 3Movistar Chile 3Nastek Ltd. 3Neterra Ltd. 3Netiwan SAS 3NGCOM 3Oi Fixo 3Optisprint 3Orange Slovensko, a.s. 3PT Mega Mentari Mandiri 3PT. Lintas Data Prima 3PT. Palapa Media Indonesia 3PT. Pasifik Satelit Nusantara 3

PT. Supernet Advance Teknologi 3PT. Usaha Adisanggoro 3PT.Mora Telematika Indonesia 3R Cable 3Rede Connect Telecom 3Redes Integrales S.A. 3Satellite Connection 3Servnet Mexico, S.A. de C.V. 3SmartLink Broadband Services Pvt 3SOL-Customer-MIX 3Srm Easwari Engineering College 3Stetnet Telecom 3Sulanet SA / Insetec Group 3Supernet Limited Transit 3Surfix Tecnologia Em Internet Ltda 3Syd Energi Bredbaand A/S 3Tecnologia E Equipamentos 3TEISA 3Tele2 Telecommunication GmbH 3Telecom Eireli 3Telecom Services (DLI/WLL) Provider 3telecomplus 3Telefonica Germany 3Telefonos del Noroeste, S.A. de C.V. 3Terrakom d.o.o. 3TERRARICANET 3The Blue Zone East / Jordan 3The British College 3Tikona Digital Networks Pvt 3Tomato Web (Pvt) Limited 3Triple C Computation Ltd. 3Umniah Mobile Company 3UnionCOM 3UPC Hungary 3UPC Ireland 3Uzbektelekom Joint Stock Company 3Velco Globalnetwork 3VOO 3Wan Interco for customers 3Wds Telecom Ltda. Me 3wilhelm.tel 3XFone 3Zain Sudan 31telecom Servicos De Tecnologia Em Internet Ltda 2Accesskenya Group Ltd 2ADA Holding - ADA AIR sh.p.k. 2Albanian Satellite Communications sh.p.k. 2Algar Telecom 2All Net Informatica Ltda 2Almenara On Line Ltda 2AlphaLink 2ARSAT - Empresa Argentina de Soluciones Satelitale 2Asansol Engineering College, Asansol 2

Page 62: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

62S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

Asiatech Inc. 2Asretelecom-ardabil Isp 2Associacao Rede Nacional de Ensino e Pesquisa 2AUNA 2Batelco ADSL service 2Bell Canada 2BHARTI Airtel Ltd. TELEMEDIA SERVICES 2Branch of Netnam Company in Ho Chi Minh City 2Cable and Wireless (Seychelles) Limited 2Cable El Salvador S.A. De C.v. 2Cablecom GmbH 2Cablemas Telecomunicaciones (tijuana) 2Cablemodem-ip-dinamica - Generico Ip Cmts Prg 2Centennial Cayman Corp Chile S.A 2Citycom Networks Pvt Ltd 2Claro S/A 2Click Tecnologia e Telecomunicacao Ltda 2Colinanet Srl. 2Commission on Science and Technology for 2Completel SAS 2Compuservice.Net Internet Provider LTDA-ME 2Coolnet New Communication Provider 2Cooperativa de Electricidad y Servicios Publicos d 2Corporacion Politiecnica Nacional De Colombia 2Cukurova University 2CVMultimedia 2CyberNet de Guatemala S.A. 2Cyta Hellas 2Dadeh Gostar Asr Novin P.J.S. Co. 2Data Office of qom for adsl users 2Derkom Spolka Jawna Dariusz Klimczuk 2Dev Italia srl 2Digital Entertainment Networks 2Digital Ocean 2Dinhubkominfo Pemprov. Jawa Tengah 2E Remussi Ltda-me 2EarthLink Iraq 2East Azarbayjan Telecommunication company -Tabriz 2Edutel BV 2El Salvador Network, S. A. 2Elkuds University 2Emirates 2Empresa De Informatica E Telecomunicacoes 2Empresa de Recursos Tecnologicos S.A E.S.P 2Epm Telecomunicaciones 2EUROTEL Ltd 2Federacion de Cooperativas Ltda. 2Fonte Informatica ltda 2Globacom Limited 2Global Crossing Comunicacoes Do Brasil Ltda. 2Globalreach eBusiness Networks, Inc. 2Globe Telecoms 2Goran Net ISP Ltd. 2

Greater Amman Municipality 2Grupo Empresarial Mexicano en Telecomunicaciones 2Gurunanak Institute for technology, Panihati, Kolk 2H1 TELEKOM d.d. 2Hellas On Line S.A. 2Hellas On Line SA - DSL 2Hosting Internet Hizmetleri Sanayi ve Ticaret Anon 2Hrvatski Telekom d.d. 2I T Tecnologia e Informacao Ltda 2iCONNECT 2Ikatelnet 2INB Informatica ltda 2Inetku-PBM 2Infoline - Comunicacoes e Informacoes Eletron 2Ingenieria e Informatica Asociada Ltda (IIA Ltda 2Internap Network Services Corporation 2Internet Maxima Tecnologia Ltda 2Inversiones Apolo S.A. de C.V. 2IRIB (Islamic Republic of Iran Broadcasting) 2J E Provedor de Rede de Comunicacao Ltda 2Jastel Network co.Ltd 2Kappa Internet Services Private Limited 2Korea Telecom 2Krzysztof Klaptocz NetService 2KurumsalLanAvrupa 2Latam Brasil Ltda 2Level 3 Colombia S.A. 2Link3 Technologies Ltd. 2Lintas Data Prima, PT 2LIWEST Kabelfernsehen Errichtungs- und Betriebs Ge 2Luis Antonio Palomino Dagdug 2M1 Connect Pte Ltd 2Magyar Telekom 2Marisol Bastidas 2Maxis Broadband Sdn Bhd 2Maxus Energy Corporation 2Meghbela Skywave Cablenet Private Limited 2Melsa-i-net 2Metronet (UK) Limited 2MetroNet Bangladesh Limited, Fiber Optic Based Met 2Microscan Computers Private Limited 2Mobile Telecommunications Company 2MobileOne 2MTN NS Cameroon 2MTN SA 2MTS 2Nakorn Ratchasima Rajabhat University 2National Academic Network and Information Center 2Neo Telecoms S.A.S. 2Neostrada Plus 2NEOTEL 2Nepal Telecommunications Corporation Cellular Mobi 2Net1 2

Page 63: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

63S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

Netjacarei Telecon Ltda 2NetSol Connect 2Netup S.A. 2Network Access Provider and Internet Service Provi 2New Wave Communications 2NGI SpA 2Nikem Net 2NKN Core Network 2OBO 2OmanMobile Telecommunication company LLC 2Omni Telecomunicacoes Ltda 2Oshakati BRAS01 IP Pool 2Pasargad Network 2Pecsi Tudomanyegyetem 2PlusNet Technologies Ltd 2PowerTel 2Primenet Global Ltd. 2Primesoftex 2Provedor De Acesso A Internet Ltda 2PSTN Telecom Oparetor 2PT Comunicacoes 2PT Cyber Network Indonesia 2PT Hyperindo Media Perkasa 2PT iForte Global Internet 2Pt Indonesia Comnets Plus 2PT Mitra Akses Globalindo 2PT Rahajasa Media Internet 2PT Sampoerna Telemedia Indonesia 2Pt Selaras Citra Terabit 2PT Sumber Data Indonesia 2PT. Arsen Kusuma Indonesia 2PT. Cross Network Indonesia 2PT. Excelcomindo Pratama 2PT. First Media, Tbk 2Qnet Telecom 2R R Multimidia Ltda - Me 2R. K. Communications 2R.s.n It Video Survilliance Pvt Ltd 2Rasana Pishtaz Network 2Red Intercable Digital S.A. 2Rodolfo Romao De Oliveira Neto & Cia Ltda 2S De Rl De Cv 2SA Telecable 2Sabanet Ahvaz Network 2Saigon Postel Corporation 2Sat-Trakt d.o.o. 2Satnet Uio 2SC NextGen Communications SRL 2Selectcom Telecom 2Servicos de Internet LTDA 2Seven Eyes For Marketing Ltd 2SevenStar Broadband 2Shahrad Net Company Ltd. 2

Soares & Lira Ltda 2Software Technology Parks of India - Bangalore 2Spoldzielnia Telekomunikacyjna OST 2Starnet S.r.l 2STLGHANA 2Sulcom Informatica Ltda 2SUPER NOVA TELECOM 2Syiah Kuala University (Unsyiah) 2TELECABLE CENTRO OCCIDENTE S.A. de C.V. 2Telecom Internet 2Telecom Ltda Me 2Telecommunication Company of Azarbayejan Gharbi 2Telecommunication Company of Khorasan Shomali 2Telecomunicacoes Do Parana Ltda 2Telefonia Dialog sp.z.o.o. 2Telefonica Movil De Chile S.A. 2Telefonica Moviles El Salvador S.A. de C.V. 2Telekom Austria 2Telenor Hungary 2Telnet Communication Limited 2Telrad Telecommunication and Electronic Industries 2Treasure Island Colocation, LLC 2TRI.ph AS Inter-Island Information Systems, Inc. 2TRIPLEPLAY INTERACTIVE NETWORK PVT LTD 2True Broadband Service 2TV SAT 2002 SRL 2UAB Bite Lietuva 2UNICS Ltd 2Universal Assistance Sociedad Anonima 2Universitas Ahmad Dahlan 2UPC Romania FOCSANI 2Via Cast Solucoes em Telecomunicacoes Ltda 2Videotron Ltee 2VietNam Data Communication Company 2VipNET 2Vodacom Business Cameroon 2Vodafone D2 GmbH 2Vox Telecom - Dynamic ADSL IP Allocation 2Voztelecom network 2VozTelecom Sistemas, S.L. 2Wana Corporate 2Welcome Italia S.p.A 2WiBand Communications 2WIN DSL s.a.r.l 2World Internetwork Co.,Ltd , Thailand. 2Xtranet 2YUnet International 2Zaklad Uslug Komputerowych EXE 2ZAMTEL 2ZOL Customers on ZTE Mobile WiMAX Platform 2Zx Online Ltd 2(DELTA TELECOM INTERNET) Anjos Informatica Ltda 1& Ziquinatti Ltda 1

Page 64: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

64S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

21 st Century Technologies Limited 12DAY Telecom LLP 13c, Subiksha Complex 1A D Communication 1Aarian Intasel Service Private Limited 1ABCom Internet Services Network 1ABCOM-Business-clients , HFC-Infrastructure 1Adylnet Telecom 1Aerojet Propulsion Division 1Agence Tunisienne d’Internet 1Agence Tunisienne Internet - ATI 1Agentia de Administrare a Retelei Nationale de Inf 1Air I.T. Infrastructure Private Limited 1Airtel Rwanda 1Aivivid ICT 1Akceycom Limited. 1ALAJUELA 1Alfa Solutions Ltd 1Ampernet Telecomunicacoes Ltda 1AMWireless Uruguay SA 1AMX Paraguay SA 1Ani Network Pvt Ltd 1Aniruddha skyline web service 1Ankhnet Informations Pvt. Ltd. 1AP-MEDIA s.c. 1Arobase Telecom 1Arya Sepehr Ettelarasan Tehran 1Asiatech Data Transfer Inc. PLC 1Asiatech DSL Broadband Service 1Asintelvision 1Asses. em Servicos de Inform. e Telecom. Ltda 1Assigned to Lagos POP at Odulami 1Assigned to Meditel 3G dynamic users 1Asta-net Customers 1Astral Bucharest Docsis N 1AT&T Services 1AT&T U-verse 1AT&T Wireless 1ATI - Agence Tunisienne Internet 1ATM S.A. 1Atria Convergence Technologies Pvt. Ltd. 1AWAL-CORP 1AZAD P2P 1B.b.g Campelo Me 1B.Net Hrvatska d.o.o. 1Badan Narkotika Nasional 1Baguer S.A. 1Balticum TV network (Klaipeda) 1BCI Telecommunication Advanced Technology Company 1Benemerita Universidad Autonoma de Puebla 1Bergon Internet Ltd. 1BH Telecom d.d. Sarajevo 1Bleta Sh.p.k 1

Bom Tempo Informatica Ltda 1BPP ING d.o.o. 1Broadlink 1BSW 1BTS Communications (BD) Ltd 1BUSHEHR temporary TELECOM CO for ADSL users 1Cablemas Telecomunicaciones (cozumel) 1Cablemodem-ip-dinamica - Generico Ip Cmts Hmc 1Cabovisao, televisao por cabovisao, sa 1CallPlus Services Limited 1CELL-C 1Central Institute for Research on Cotton Technolog 1CERIST 1Chandra Net Pvt. Limited, India 1Channel Dristi Network 1Chile S.A. 1China Telecom Jiangxi 1Chinguitel SA 1Cisco Systems Ironport Division 1CITIC Telecom International CPC Limited 1Clicfacil Computadores, Servicos e Telecomunicacoes 1Client-wimax-business Site 1CNS Infotel Services Pvt. Ltd. 1Cogent Communications 1ColoCrossing 1Columbus Networks USA 1Com De Equip. De Tele Informatica 1Com Equip Info Ltda 1Comercio De Antenas Ltda Me 1Comercio De Telefonia E Comunicacao Ltda 1Companhia de Telecomunicacoes de Macau SARL 1Companhia Santomense de Telecomunicacoes 1Completel 1Computech Tecnologia Ltda. 1Computer Center 1Conesul Telecomunicacoes Ltda 1Cong ty CP Truyen thong quoc te Incom 1Conjoinix Technologies Pvt. Ltd. 1Connect Internet Services Limited 1Connect Network 1ConnectIB IP Space 1Cooperativa Telefonica Del Viso 1countrywide 1Cung cap dich vu Internet khach hang quan Go Vap 1Cung cap dich vu Internet khach hang quan Nha Be 1Cung cap dich vu Internet khach hang quan Tan Binh 1Dadeh Pardazan Sabz Alborz Co.(P.J.S.) 1Dadehaye Donyaye Door Co.(P.J.S) 1Dagupan Urban Satellite Vision 1Dehradun Enet Solutions Private Ltd 1Departemen Energi dan Sumber Daya Mineral 1Digital Servicos De Informatica E Comercio 1Digitel Italia SpA 1

Page 65: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

65S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

Direct On PC Ltd Hub 1DOCSIS clents in Lisice 1Dora Telekomunikasyon Hizletleri A.S. 1DornaNet 1DSL Subscriber block 1DTAC 1Dtpnet Nap 1DYNAMIC ADRRESS POOL xDSL 1E-Infrastructure and Entertainment India Pvt. Ltd 1e-Novations ComNet 1Easy Connect- ISP 1Ecom Service Ad 1Elxire Data Services Pvt. Ltd. 1Emirates Integrated Telecommunications Company PJS 1Emirates Telecommunications Corporation 1ENERGOTEL a.s. 1Entel PCS Telecomunicaciones S.A. 1Enterprise of Telecommunications Lao 1EUN 1Euroweb Romania SA 1Ewinet C.A. 1Exetel 1Exponential-e 1Ez Runner Systems LTD IP Space 1Farahnet 1Fast Telecommunications Company W.L.L. 1Fastel Sarana Indonesia PT 1FERO Agnieszka Budner 1Fhp Telecomunicacao E Com Varejista De Produtos De 1Fidelity Access Networks, LLC 1Free Mobile SAS 1Free SAS 1Frontier Communications 1Frontiir Co. Ltd 1G-Mobile Corporation 1Gamtel Co 1Gas Natural Fenosa Telecomunicaciones Costa Rica S 1Geolink-access 1Gerrys Information Technology Pvt Ltd. 1Gigabit S.a.l 1Gigacable de Aguascalientes, S.A. de C.V. 1Glo-Online Networks 1Global Broadband Solution societe de droit america 1Global Crossing Colombia S.A. 1Global Crossing Peru S.A. 1Global Telecom Ltda 1Globe Telecom 1Goldsurf Internet Ltd 1GPON Services 1GPTC Autonomous System, Tripoli Libya 1Grahamedia Informasi, Pt. 1Grameen Communications 1Grameenphone GPRS GrameenBank 1

GTS Hungary Telecommunications Limited Liability C 1Hamedan Data comunication company 1Hanoi Telecom Joint Stock Company - HCMC Branch 1Hi3G Access AB 1Home Systems Pvt.ltd 1HONDA MOTOR Co. 1Honesty Net Solutions (India) Pvt. Ltd. 1Hosh Ertebat Zarandieh (Zarandieh Communication In 1Hotel Princess 1Iceberk 1ICNC LLC 1In2cable (India) Ltd. 1Indian Veterinary Research Institute, Izzatnagar 1Indosatm2 1Inel Internacional Dooel Kavadarci 1Infocom Ltd 1InfoLink 1Informatica Ltda 1Infotechnet Informatica e Assistencia Tecnica Ltda 1Integral University,Lucknow 1Integrated Measurement Systems 1Intellihome Tavkozlesi Szolgaltato Kft 1Internet Cable Provider 1Internet Ltda Me 1Inweb Adriatico s.r.l 1ip range assign for the Internet Cable Service in 1IP Teknologi Komunikasi, PT. 1iPi 1Ipko Telecommunications 1Iran Telecommunication Company PJS 1Ivatel Redes e Internet LTDA 1Ixsforall, Inc. 1Jacobi International 1Jamia Millia Islamia University, New Delhi 1Java Online, PT. 1Jawaharlal Nehru University 1Jogja Medianet 1Jozef Woch Cybernet WMW 1JPR Digital 1JSC Silknet 1Jump Management SRL 1Karvy Consultants 1Kenya Education Network 1KurumsalLanmix 1LAN clents in Veles 1Leased line service 1LeaseWeb B.V. 1lefke avrupa universitesi kktc 1Level 3 Argentina S.A. 1Link Provedor De Internet Ltda - Me 1Link Telecom Net 1LINKBG Dobrich NET 1Liquid Zimbabwe 1

Page 66: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

66S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

Luis Ctv S.A. 1Lukovit NET 1LulinNet 1Lusaka-WiMAX-Customers 1M & M Telecomunicacoes Ltda 1M.A. Informatica Ltda. 1M/s Ortel Communications 1MacroLAN 1Madritel 1Malawi Telecommunications Ltd (MTL) 1Mauritel ADSL Service 1Max tech media and communications pvt ltd 1Media Operator Sp. z o.o. 1Mega-Net Markwas Marek 1Melita plc 1Mersin University 1MetroCast 1Microsoft Azure 1Microtell Informatica - Comercio & Prestacao De S 1Middle East Internet Company Limited 1Ministry of Finance 1MNET10 BG Block 1MNR Broadband Services Pvt. Ltd. 1Mohali 1mokhaberat razavi 1MOVITEL 1MTC-Vodafone Bahrain 1MTN Cote d’Ivoire S.A 1MTN Network Solutions Pty Ltd 1MTN RwandaCell 1Multidisiplin Company Express Ltd 1Myanma Posts and Telecommunications 1MyKRIS Asia Sdn Bhd 1MyRepublic Ltd (Singapore) 1Naja Telecomunicacoes Ltda. 1NatCoWeb Corp. 1National Institute of Design,Ahmedabad 1NAWRAS ISP lease line customers 1Nayatel (Pvt) Ltd 1NC Numericable S.A. 1Neamul Haque Khan t/a Mazeda Networks Limited 1NEOTEL-MKD Autonomous System 1Net 1Net Infinito Telecom 1NET LTDA 1Net Servicos De Informatica Ltda - Me 1Netcom Enterprises Pvt Ltd 1NetJat Provedor de Acesso a Internet 1Netline Peru SA 1Network Operations Center 1Network-Platforms 1Neunet S.A. 1New Century InfoComm Tech Co. 1

New Telesystems - TV, Ltd. 1NORLAND TECHNOLOGY LIMITED IP Space 1North Corporate P2P Fiber Customer 1Northeast Dataa Network Pvt Ltd 1O2 Czech Republic 1OFIS 1OGERO 1Omani Qatari Telecommunications Company SAOC 1Omantel 1OOREDOO 1OPTICCOM- BULGARIA Ltd. 1OPTINET 1Orange-NIGER 1Orion Telekom Tim ADSL Users 1Orion Telekom Tim d.o.o 1Orolix Desenvolvimento de Software Ltda. 1Ortigas Cntr 1Pakistan Software Export Board 1Pardaz Gostar Ertebatat Berelian Limited Liability 1Pars Fonoun Ofogh Information Technology and Commu 1Pascani 1Payamavaran Javan Company Ltd. 1PCCW IMSBiz 1PCextreme B.V. 1Pipex Internet Ltd 1Pontenet Teleinformatica Ltda. 1Popular De Internet Ltda 1Posta dhe telekomi i Kosoves 1PrimaNet - PT. Khasanah Timur Indonesia 1Priston Net Telecom 1Procono S.A. 1Pronet sh.p.k. 1Provedor De Internet Ltda - Me 1Provedor de Telecomunicacoes Ltda. 1Provincia di Reggio nell’Emilia 1PSA S.r.l. 1Pt Bina Informatika Solusi 1PT Cyberplus Media Pratama 1PT Delta Nusantara Networks 1PT Indosat Tbk 1Pt Metrasat 1PT Remala Abadi 1PT. Andalas Media Informatika 1PT. Bangun Abadi Teknologi Indonesia 1PT. Bumi Merbabu Permai 1Pt. Matrixnet Global Indonesia 1PT. Mora Telematika Indonesia 1Pustekkom 1Qendra Nderuniversitare e Sherbimeve dhe Rrjeti Te 1QIS College of Engg,Vengamukkapalem Ongole, Andhra 1Qualitynet 1R & H Comercio De Informatica Ltda-me 1RAHANET Network 1

Page 67: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

67S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

Rangsit University 1RCS & RDS 1RCS & RDS Residential 1Readylink Internet Services Limited 1Regus Business Centre SA 1Retecal Sociedad Operadora de Telecomunicaciones 1Rodrigo Camozzato Fiel & Cia ME 1Rodrigues Romao Filho Me 1Route Way Telecomunicacoes e Servicos EIRELI - 1Roveri Opcao Provedor de Acesso a Internet Ltda ME 1RSAWEB Internet Services 1RSONet 1S.A 1S.N. Radiocomunicatii S.A. 1S.R da Silva Telecomunicacoes 1Sabanet network in Qazvin 1Sabanet network in Shiraz 1Sabanet Qom 1Salzburg AG 1Sapthagiri College of Medical Sciences,Banglore 1Sari System Bandarabas Company 1SaskTel 1Satnet Cuenca Cable Modems 1Satnet Cuenca Cor 1SC Lithuanian Radio and TV Center 1Sc Multimedia Network Srl 1Sdn Telecom Pvt Ltd 1SendGrid 1Servicos De Telecomunicao Ltda 1Seven Star Internet Service Provider 1SG IT Infotech Pvt. Ltd. 1Shabakeh Gostar Dorna Cooperative Co. 1shahid beheshti university 1Shahrad Net DSL Broadband Services 1Shivansh Infotech pvt Ltd 1Shri Sadguru Broadnet Service 1Shrisai Enterprises 1Signal Comunicacao Multimidia Ltda Me 1Simbanet (T) Ltd 1Simply Computers 1Sinal BR Telecom LTDA 1SKYCC 1Skytelecom , Transit provider and ISP in Vientiene 1Skyware Sp. z o.o. 1smartphone 1Smile Internet Gold 1Snowball Effect CC 1Solucoes E Tecnologia Ltda 1Somali-Optical-Networks 1SOTELMA 1South Central Communications 1SOUTH EAST ASIA TELECOM (Cambodia) Co., LTD 1Spacetel Benin SA 1

Spectranet Ltd 1SpeedOnline.Net.Pvt.Ltd. 1Spoldzielnia Mieszkaniowa w Grudziadzu 1Srinagar Technology Consultants Pvt. 1Sripatum Univeristy is one university in Thailand 1Sspnet Sistemas E Solucoes De Provimentos Ltda 1Stimo Niedzielski Spolka Jawna 1STXCitinet, Leading Internet & VOIP Service Provid 1Suite Software 1Suporte Tecnologia e Instalacoes Ltda. 1Swami Samarth Medical And General Store 1Symbolics 1Symphony Communication PLC. 1SysEleven GmbH 1Systel Systemy Teleinformatyczne M. Linscheid Spol 1Systems Solutions & development Technologies Limit 1T-2, d.o.o. 1T-Mobile Austria GmbH 1T-Mobile Czech Republic a.s. 1T-mobile Polska Spolka Akcyjna 1Tabriz 1Tbroad Dongnam Broadcasting co.,Ltd 1TCNet Informatica e Telecomunicacoes LTDA 1Technologies S.a.c. 1Tecnologia 1Tecnowind S.A. 1Telarus Pty Ltd. xDSL Provider, Australia 1Telbrax Ltda 1Tele2 Nederland 1Telecable de Asturias,SA 1Telecable Economico S.A. 1Telecall Brasil Servicos de Telecomunicacoes Lt 1Telecom Italia Mobile 1Telecom Italia Sparkle of North America 1Telecom Ltd 1Telecom Personal 1Telecommunication Company of Ardebil 1Telecommunication Company of Kerman 1Telecommunication Company of Khorasan 1Telecommunication Company of Kordestan 1Telecommunication Company of Qom 1Telecommunication Company of Yazd 1telecommunication Of west Azarbayjan 1Telecomunicaciones MOVILNET 1Telecomunicacoes de Mocambique (TDM) 1Telecomunicacoes Do Brasil Ltda - Epp 1Telecomunicacoes Netcoro Ltda 1Telefonia Publica y Privada S.A. 1Telekom Slovenije d.d. 1Teletalk Bangladesh Ltd. 1TelexAir Telecom Pvt Ltd 1TeliaSonera Finland Oyj 1Telip S.A. de C.V. 1

Page 68: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

68S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of EmailsRange Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

TelOne(formerly ZPTC) 1TeNeT Scientific Production Enterprise LLC 1TerraNet sal 1The Communication Authoity of Thailand, CAT 1The Houses Television C.A. 1TIGO COLOMBIA 1tigo-rw-as 1Tiscalinet 1TMW Telecom 1Triple Play Teleservices Private Limited 1Truemove 1TrustPower Ltd 1Tunisiana 1U Mobile Sdn Bhd 1U.p. Communication Services Pvt Ltd 1UAB Baltnetos komunikacijos 1Uganda Telecom 1Universidad Central de Venezuela 1Universidad Nacional Autonoma de Mexico 1Universidade Estadual Paulista 1Universidade Federal Fluminense (UFF) 1University of Santo Tomas 1UPC NL 1UPC Romania BUCURESTI FIBER 1use for ADSL users 1V Telecoms Berhad 1VALAHIA University of Targoviste 1Velocity1 Limited 1Versatel Deutschland 1Vianet Communications Pvt. Ltd 1Vihaan Telecommunication Pvt. Ltd. 1VIKING SRL 1Vimpelcom Lao Co 1

Virtual Net Telecomunicacoes LTDA 1Viva Kuwait 1Vocus Connect International Backbone 1Vodacom-lesotho 1Vodafone New Zealand Broadband 1Vodafone Omnitel B.V. 1Vodafone Portugal 1Vodafone Turkey 3G IP Pool 1Vodafonespainnetwork 1Volia Kharkov 1Wamika Broadband 1Wananchi Group Kenya 1Wataniya Telecom 1WBS, Wireless Business Solutions 1Web Concepts (Pvt) Ltd 1Webnet Solucoes Em Internet Ltda 1WHS Telecom Serv. Telecomunicacoes LTDA 1WideOpenWest 1Wiericke B.V. 1Windstream Nuvox 1Wireless Business Solutions (Pty) Ltd, iBurst 1Wireless S/A 1Wish Net Private Limited 1Witribe Pakistan Limited 1Wow Solutions and Systems Pvt Ltd 1Yadkin Valley Telephone 1Yahoo Japan Corporation 1YokozunaNET 1YTL Communications Sdn Bhd 1Zajil International Telecom Company W.L.L. 1ZeXoTeK IT-Services GmbH 1Zimbabwe Online 1Zimbabwe OnLine (Private) 1ZON Tv Cabo 1

Total Result 24,302

Page 69: Comodo Threat Intelligence Lab · PDF fileComodo Threat Intelligence Lab SPECIAL REPORT: ... A late September wave of new ... designed to slip past machine learning algorithm-based

Comodo_LockyRansomwareReport_PartIII_092717

About Comodo The Comodo organization is a global innovator of cybersecurity solutions, protecting critical information across the digital landscape. Building on its unique position as the world’s largest certificate authority, Comodo authenticates, validates and secures networks and infrastructures from individuals to mid-sized companies to the world’s largest enterprises. Comodo provides complete end-to-end security solutions across the boundary, internal network and endpoint with innovative technologies solving the most advanced malware threats, both known and unknown. With global headquarters in Clifton, New Jersey, and branch offices in Silicon Valley, Comodo has international offices in China, India, the Philippines, Romania, Turkey, Ukraine and the United Kingdom. For more information, visit comodo.com.

Comodo and the Comodo brand are trademarks of the Comodo Group Inc. or its affiliates in the U.S. and other countries. Other names may be trademarks of their respective owners. The current list of Comodo trademarks and patents is available at comodo.com/repository.

Keep up to date with the Latest Comodo News: Blog: https://blog.comodo.com/ Twitter: @ComodoNews LinkedIn: https://www.linkedin.com/company/comodo

About The Comodo Threat Intelligence Lab The Comodo Threat Intelligence Lab (the Lab) monitors, filters and contains, and analyzes malware, ransomware, viruses and other “unknown” potentially dangerous files 24x7x365 in over 190 countries around the world. With 5 offices spread across the Americas, Asia and Europe (and staff covering over 190 countries), the Lab is made up of more than 120 IT security professionals, ethical hackers, computer scientists and engineers (all full-time Comodo Lab employees) analyzing millions of potential pieces of malware, phishing, spam or other malicious/unwanted files and emails every day. The Lab also works with trusted partners in academia, government and industry to gain additional insights into known and potential threats.

The Lab is a key part of the Comodo Threat Research Labs (CTRL), whose mission is to use the best combination of cybersecurity technology and innovations, machine learning-powered analytics, artificial intelligence and human experts and insights to secure and protect Comodo customers, business and public sector partners and the public community.

Comodo Group, Inc. | 1255 Broad Street, Clifton, NJ 07013 US Tel: +1 (888) 266-6361 | Tel: +1 (703) 581-6361 | Fax: +1 (973) 777-4394

69

THREAT RESEARCH LABS

S P E C I A L R E P O R T