48
Comodo Threat Intelligence Lab SPECIAL REPORT: AUGUST 2017 – IKARUSdilapidated Locky Part II: 2nd Wave of Ransomware Attacks Uses Your Scanner/Printer, Post Office Billing Inquiry

Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

  • Upload
    vudat

  • View
    226

  • Download
    2

Embed Size (px)

Citation preview

Page 1: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

Comodo Threat Intelligence LabSPECIAL REPORT:

A U G U S T 2 0 1 7 – I K A R U S d i l a p i d a t e d L o c k y P a r t I I :

2nd Wave of Ransomware Attacks Uses Your Scanner/Printer, Post Office Billing Inquiry

Page 2: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

2S P E C I A L R E P O R T

THREAT RESEARCH LABS

Locky Ransomware August 2017 Special Report Part II

A second wave of new but related IKARUSdilapidated Locky ransomware attacks has

occurred, building on the attacks discovered by the Comodo Threat Intelligence Lab (part

of Comodo Threat Research Labs) earlier in the month of August 2017. This late August

campaign also uses a botnet of “zombie computers” to coordinate a phishing attack which

sends emails appearing to be from your organization’s scanner/printer (or other legitimate

source) and ultimately encrypts the victims’ computers and demands a bitcoin ransom.

Page 3: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

3S P E C I A L R E P O R T

THREAT RESEARCH LABS

The larger of the two attacks in this wave presents as a scanned image emailed to

you from your organization’s scanner/printer. As many employees today scan original

documents at the company scanner/printer and email them to themselves and others,

this malware-laden email will look very innocent.

The sophistication here includes even matching the scanner/printer model number to

make it look more common as the Sharp MX2600N is one of the most popular models of

business scanner/printers in the market.

This second wave August 2017 phishing campaign carrying IKARUSdilapidated Locky

ransomware is, in fact, two different campaigns launched 3 days apart. The first (featuring

the subject “Scanned image from MX-2600N”) was discovered by the Lab to have

commenced primarily over 17 hours on August 18th and the second (a French language

email purportedly from the French post office featuring a subject including “FACTURE”)

was executed over a 15-hour period on August 21st, 2017. Each continued beyond those

surges but in much lesser quantities.

In contrast to the initial 2017 IKARUSdilapidated Locky campaign which distributed

malware with the “.diablo” extension and a script that is a Visual Basic Script (and has a

“.vbs” extension), both new attacks have interesting variations to not only fool users with

social engineering , but also to fool security administrators and their machine learning

algorithms and signature-based tools.

The encrypted documents have a “.lukitus” extension. The first is distributing “.vbs” files

via email, but the second one is distributing JavaScript or “.js” files. This shows that the

malware authors are evolving and changing methods to reach more users and bypass

security methods.

Page 4: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

4S P E C I A L R E P O R T

THREAT RESEARCH LABS

Both English and French language phishing approaches are used in these two new attacks,

which were launched from, and impacted, numerous countries around the world. Here is a

heat map of the first attack on August 18th featuring the “Scanned Image” subject line.

Interestingly, 27% of the 54,048 IP addresses used in the “Scanned Image” attack were

also used in the first IKARUSdilapidated Locky attacks on August 9th-11th, 2017 and

the top source countries of the of the botnet “zombie computers” remained the same:

Vietnam, Turkey, India and Mexico. Considering some of the computers taken over in early

August were Internet Service Providers (ISPs), it is a bit surprising that the vulnerabilities

were not addressed in the week+ since the first attack and botnet takeover.

Country Sum - Count Of Emails

Vietnam (VN) 17,061

India (IN) 9,591

Mexico (MX) 4,193

Turkey (TR) 3,535

Page 5: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

5S P E C I A L R E P O R T

THREAT RESEARCH LABS

ISPs in general were co-opted heavily in this attack which points to both the sophistication

of the attack and inadequate cyber-defense at their endpoints. Here are the leading range

owners detected in the “Scanned image from MX-2600N” attack:

Range Owner Sum - Count Of Emails

Vietnam Posts and Telecommunications (VNPT) 11,551

Airtel Broadband 3,302

VDC 2,946

Turk Telekom 2,795

Viettel Corporation 1,067

Iusacell 1053

The French language attack (see below) presents as a “FACTURE” message which translates

to a BILL or BILLING inquiry from a laposte.net email address (which is a domain used by a

popular French post office company).

Page 6: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

6S P E C I A L R E P O R T

THREAT RESEARCH LABS

When the attachment is clicked it appears as a compressed file to be unpacked:

Here you can see a sample of the scripting, which is quite different than that used in the

attacks earlier in the month:

Page 7: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

7S P E C I A L R E P O R T

THREAT RESEARCH LABS

This second, smaller attack is captured in the below heat map and shows many European

and Southern Asia hot spots, but minimal activity in United States and Russia:

17% of the IPs used in this attack were also used in the August 9th-11th IKARUSdilapidated

Locky attacks, so the response to the takeover of those machines has been slow.

The Comodo Threat Intelligence Lab team was able to quickly verify the two new

ransomware attacks via detections at Comodo-protected endpoints at the front edge

of each new attack. As users clicked on the attachments in these innocuous emails, they

were read as “unknown files,” denied entry to the infrastructure, and put into containment,

where they were analyzed by Comodo’s machine learning-powered technology and,

ultimately, by the lab’s human experts.

The Lab’s analysis of emails sent in the ‘Scanned image’ phishing campaign revealed this

attack data: 8,886 different IP addresses being used from 127 different country code top-level

domains maintained by the Internet Assigned Numbers Authority (IANA). The narrower

“FACTURE” attack utilized 1657 different IP addresses from 74 country code domains.

As with the early August attacks, when the Lab team checked the IP range owners, we see

that most of them are telecom companies and ISPs. This tells us that yet again the

Page 8: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

8S P E C I A L R E P O R T

THREAT RESEARCH LABS

IP addresses belong to infected, now compromised computers (also called “zombie

computers”). This campaign used a large bot network (or botnet), and had a sophisticated

command and control server architecture.

The simulation of an internal scanner/printer, a second attack just a few days later, and

the use of local language elements and a post office domain also continues the trend of

increasing sophistication, organization and capability of new ransomware attacks and adds

more credence to the call to act on the recommendation of security experts everywhere:

“Adopt a default deny security posture” and thereby deny new, ‘unknown’ files entry into

your IT infrastructure until you’re sure they are good, safe files.

“This first follow-up ransomware phishing attack so soon after the sophisticated August

9th-11th attack, showed us how dedicated they are at getting better at these types of

attacks.” said Fatih Orhan, head of the Comodo Threat Intelligence Lab and Comodo Threat

Research Labs (CTRL). “Another more targeted variant coming just 3 days later confirms

their capability to scale up and to plan and execute multiple targeted campaigns and as with

August 9th, when machine learning algorithms and artificial intelligence couldn’t identify

these new unknown malware files, the default deny posture with containerization of unknown

files was critical to protect customers. The Lab’s human experts from around the world were

also needed to analyze and identify the code in the files and render a white list or black list

verdict. As with the new ransomware detected earlier this month, there was dangerous,

new ransomware attacking large numbers of endpoints in a coordinated pair of attacks

essentially lasting just 17 and 15 hours respectively. Using ‘default deny’ security posture

with containment of unknown files is what protected users’ endpoints from this new variant

of a dangerous threat.”

Orhan went on to say, “Botnets of compromised “zombie computers” from ISPs are a

particularly effective means of attack for criminals to both scale their ransomware attacks

and to broadly bombard specific targets in a short-burst type of campaign. The attacks

were over so quickly that only preventative measures would have made any real difference.

Detection and response would have been too late here.”

Attack Data – A Deeper Dive

Diving into the data of this second wave of IKARUSdilapidated attacks a bit deeper, the

Appendices that follow include more detail on the machines used in the attacks.

Page 9: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

AppendixNOTE: To compare the detail of these August 18 and 21, 2017 attacks with the original

IKARUSdilapidated campaign of August 9, 10, and 11, see Part I of this Comodo Intelligence Lab

Special Report entitled, “SPECIAL REPORT: AUGUST 2017 – IKARUSdilapidated: Locky Ransomware

Family Back with a New Email Phishing Campaign Attack.” As the malware payload and ransom

elements are the same in all three attacks, please see the original report to review those elements.

This special report from the Lab (as well as other reports and updates)

is available to subscribers of Comodo Threat Intelligence Lab Updates.

Subscribe for free at: comodo.com/lab

THREAT RESEARCH LABS

Page 10: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

10S P E C I A L R E P O R T

THREAT RESEARCH LABS

Appendix A: “Scanned image from MX-2600N” Attack

Country Sum - Count Of Emails

VN 17,061 IN 9,591 MX 4,193 TR 3,535 BR 2,428 ID 1,926 CO 1,795 KE 1,041 BD 873 BO 802 IR 652 PK 582 TH 502 AR 501 IT 410 KH 407 ZW 387 PL 385 IL 384 CL 361 PH 345 RS 279 BG 270 ES 259 N/L* 257 LA 252 MK 239 GR 237 VE 225 TZ 172 US 167 ZA 160 RO 146 UY 141 GT 132 UA 130 CI 125 BA 119 MY 119 PE 103 JO 101 EC 99

Country Sum - Count Of Emails

NG 94 BE 93 DE 89 MA 89 DO 85 MV 84 HR 78 GB 76 CR 65 HN 59 NL 58 AO 57 NP 56 SA 55 AL 53 KW 48 AU 47 LB 45 BT 43 MM 43 MZ 43 GH 41 PG 38 SG 38 ME 34 CD 33 KZ 33 NA 32 EG 31 JM 31 FR 30 CA 29 PA 29 PS 28 TN 28 ZM 28 BN 27 UG 26 CY 25 NI 25 SK 23 SI 22

Country Sum - Count Of Emails

TW 21 DZ 20 GE 18 AM 17 CW 16 LT 16 LY 15 PY 15 CM 14 MG 13 HU 12 IE 11 RW 10 SV 10 MT 9 MU 9 BW 8 ET 8 GQ 8 JP 8 KY 8 HK 5 ML 5 CH 4 CN 4 IQ 4 KG 4 PT 4 AT 3 CZ 3 SS 3 DK 2 KR 2 MN 2 MO 2 AW 1 AZ 1 BQ 1 BZ 1 CV 1 OM 1 SE 1 UZ 1

Total Result 54,205*N/L: No Location

Page 11: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

11S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

Vietnam Posts and Telecommunications(VNPT) 11,551Airtel Broadband 33,02VDC 2,946Turk Telekom 2,795Viettel Corporation 1,067Iusacell 1,053CMC Telecom Infrastructure Company 903No Range Owner 812Bharti Airtel 783Cablemas Telecomunicaciones SA de CV 661Cablevision, S.A. de C.V. 564Vivo 547Asianet 472Telmex 466TATA Communications 455Axtel 436Telmex Colombia S.A. 399Mahanagar Telephone Nigam Ltd. 390Tellcom Iletisim Hizmetleri A.s. 390UNE 382FPT Telecom Company 337True Internet 334PT Indosat Tbk. 331Syscon Infoway Pvt. 328ONECOM 306D-Vois Broadband Pvt 289Mega Cable, S.A. de C.V. 289Aria Shatel Company Ltd 277Bolivia S. A. 257Tata Teleservices Maharashtra Ltd 256Unitel 252FASTNET 227Southern Online Bio Technologies Ltd 227In2cable.com (India) 218Aamra Networks Limited 193ACCESSKENYA GROUP LTD is an ISP serving 192Tv Azteca Sucursal Colombia 191Oi Internet 182Kenyan Post & Telecommunications Company / Telkom 180Telecom Italia 173Bharti Broadband 167Cablevision 163Philippine Long Distance Telephone 159Bezeq International 154MPLS ADSL Broadband 153PT Telkom Indonesia 153Virtua 150Transtelco S.A. 148Reliance Communications 147Airtel 145ETB 142Administracion Nacional de Telecomunicaciones 139Alestra, S. de R.L. de C.V. 135

S.I Group 135Telefonica Empresas 135Vodafone India 135Sify Limited 131Vivacom 129Dishnet Wireless Limited 125Neda Gostar Saba Data Transfer Company Private Joi 123PERN AS Content Servie Provider, Islamabad, Pakist 121Fastweb 120Wan & Lan Internet Pvt 116Cote d’Ivoire Telecom 114Global Village Telecom 113Information Society S.A. 113Cogetel Online 112COTAS 112SINET, Cambodia’s specialist Internet and Telecom 112Comcast Cable 111Tata Teleservices ISP 110Telefonica Celular de Bolivia S.A. 110Blizoo DOOEL Skopje 107Itelkom S.A.S 105NSS S.A. 104Bharti Airtel Ltd., Telemedia Services 103ZOL Zimbabwe Assignments 101Yashtel 99Mexico Red de Telecomunicaciones, S. de R.L. de C. 98Safaricom 98PT. Cyberindo Aditama 96Three Indonesia 96Comteco Ltda 95DCTV Cable Network Broadband Services 95CTBC 90Mob Telecom 89Wateen Telecom 89Oi Velox 88AXS Bolivia S. A. 87Gtel Tijuana 85Varnion Technology Semesta, PT 85Delta Infocom Limited 84Dhivehi Raajjeyge Gulhun (Dhiraagu) 84Telefonica de Argentina 82CANTV 81National Telecommunication Corporation HQ 81Tanzania Telecommunications 81VietNam Telecom National 81Wananchi-ke 81Meghbela Broadband 80S.A. E.s.p. 79Cyfrowy Polsat MVNO mobile broadband services 78Media Commerce Partners S.A 76S.A. E.s.p 75Toseh Ertebatat Homa (Private Joint Stock) 72United States Air Force 72

Page 12: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

12S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

Telefonica Venezolana 70Tata Indicom 69Telone 69Orange Israel 68SHATEL DSL Network 67TRD ROBI DOOEL 67MTN Nigeria 66Tata Mobile 66Wsp Servicos de Telecomunicacoes Ltda 65DSL-Elektronika d.o.o. 64Honesty Net Solution (I) Pvt 64RailTel Corporation of India Ltd. 643BB Broadband 63Neuviz Net 62Universidad De Antioquia 62Vectra Broadband 62Vietnam Posts and Telecommunications (VNPT) 62Quest Consultancy Pvt Ltd 61CS LoxInfo 60Fixed IP for cable modem customers 60Jazz Telecom S.A. 60Transworld Associates (Pvt.) Ltd. 60Ingenieria e Informatica Asociada Ltda (IIA Ltda 59Ecuadortelecom S.A. 58Telefonica del Peru 58WorldStream 58Orange Polska 57TTCLDATA 57Vodafone Ono 57EMCATEL 56OTEnet S.A. 56B.Net Hrvatska d.o.o 55Claro Dominican Republic 55Global Iletisim Hizmetleri A.S. 55Natural Fenosa Telecomunicaciones Guatemala S.A. 55Angel Drops Ltd 54BDCOM Online Limited 54Pars Online PJS 53Vasai Cable Pvt. Ltd. 53VTR Banda Ancha S.A. 53Konecta de Mexico, S. de R.L. de C.V. 52MWEB 52Serbia BroadBand-Srpske Kablovske mreze d.o.o. 52X-Link Limited 51012 Smile Communications 50SaudiNet 50Tele Globe Global, PT 50Vung dia chi IP cap cho dich vu IPTV tai Ha Noi 50YUnet International d.o.o. 50Malaysian Research & Education Network 49Net Uno, C.A. 49Cotas Ltda. 47delDSL Internet Pvt. Ltd. 47

Delhi Gsm Ip Pool 47Proximus Skynet 47Eastern Telecoms Phils., Inc. 46Intech Online Private Limited 46Telefonos del Noroeste, S.A. de C.V. 46TurkNet Iletisim Hizmetleri A.S 46Via Real Internet Equipamentos de Informatica Ltda 46Aamra technologies limited 45Azteca Sucursal Colombia 45Bittel Telecom Pvt Ltd 45Broadband Pacenet Pvt. 45KENYAWEB 45Nepal Telecom 45Telenor d.o.o. Beograd 45IFX Corporation 44Railtelibwcustomers 44RCS & RDS Business 44D-VoiS Broadband Private Limited 43DrukNet ISP 43Neamul Haque Khan t/a Mazeda Networks Limited 43PT Tele Globe Global 43Satellite Connection 43TVCABO - Comunicacoes Multimedia, Lda. 43Entel S.A. - EntelNet 42Triple Play Broadband Private Limited 42MNC Playmedia 40Primesoftex 40Cotel Ltda. 39Jupiter Telecomunicacoes e Informatica Ltda 39DOCSIS clents in Pripor 38Telefonica Data S.A. 38KurumsalLanmix 37SingNet Pte Ltd 37Hireach Broadband Private Ltd 36V Telecoms Berhad 36Apollo Online Services Pvt ltd 35Centennial Cayman Corp Chile S.A 35L E M Telecomunicacoes Ltda -me 35Polkomtel Sp. z o.o. 35Superonline Iletisim Hizmetleri A.S. 35Cyprus Telecommuncations Authority 34Empresa de Recursos Tecnologicos S.A E.S.P 34Pt Selaras Citra Terabit 34Beam Telecom 33Crnogorski Telekom a.d.Podgorica 33Deutsche Telekom AG 33Internet Service Provider 33Liquid Telecommunications Operations Limited 33PT Media Sarana Data 33PT.Mora Telematika Indonesia 33Vodafone DSL 33Vodafone Italia 33TM Net 32

Page 13: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

13S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

UPC Polska 32Vodafone Italia DSL 32Broadband ISP, FTTH and Cable Service Provider 31CPS 31Israel Local Authorities Data Processing Center Lt 31OCPT 31Skyline Semesta, PT 31TVCabo Angola 31Blizoo Media and Broadband 30Empresa De Telecomunicaciones De Pereira S.A. 30Empresa de Telecomunicaciones de Pereira S.A. E.S. 30Informatica Ltda 30Oi Fixo 30Siticable Network Limited 30TRICOM 30ADN Telecom Ltd 29Cablecolor S.A. 29Fundacio Privada per a la Xarxa Lliure, Oberta i N 29PT Remala Abadi 29Bharti Airtel Ltd., TELEMEDIA Services, for SMB cu 28Golden Telecom LLC 28Milleni.com 28Netia SA 28PT DES Teknologi Informasi 28TE Data 28Tecnologia 28Tehran Kar Ara 28Telecomunicacoes Ltda. 28Broadband Plus 27Cable & Wireless Jamaica 27Dataline LLC 27Hexabyte 27INDO Internet, PT 27Panda Network 27Simpur ISP 27Telstra Internet 27Zajil Telecom 27Inwi Mobile 26Supernet Limited Transit 26Digital Network Associates Private Limited 25IACTCOM 25Net Tecnologia Integrada 25Protel I-Next, S.A. de C.V. 25PT. Pasifik Satelit Nusantara 25SINET SRL 25SOL-Customer-MIX 25TELEKOM SRBIJA a.d. 25Windhoek BRAS02 IP Pool 25Autonomous System Number for Nexlinx 24BSNL 24Empresa De Informatica E Telecomunicacoes 24Global Crossing Comunicacoes Do Brasil Ltda. 24Informatica y Telecomunicaciones S.A. 24

LCR Telecom NV 24Maxcom Telecomunicaciones, S.A.B. de C.V. 24Movistar Chile 24Pt Indonesia Comnets Plus 24Simbanet-as 24TalkTalk 24Teknotel Telekomunikasyon Sanayi Ve Ticaret A.s. 24TeNeT Scientific Production Enterprise LLC 24afczas 23Bell Canada 23Cable Tica 23CNS Systems s.r.o. 23Inetku-PBM 23IPStaticMarocTelecom 23Linkdotnet-Jordan 23Nettlinx Limited 23PT Solnet Indonesia 23SAN JOSE 23Telecomunicacoes Ltda 23TOT 23Tripleplay Broadband Pvt Ltd 23Voztelecom network 23Galaxy Brasil Ltda 22Global Tecnologia Ltda Me 22Mahbub Morshed t/a Mahi Enterprise 22Mediacom Cable 22Micropic Ltda 22Mobilink Mobile Internet 22Paratus-Telecom 22Pascani 22PT Sumatera Global Mediatek 22Pulse Telesystems Pvt Ltd 22Telekom Slovenije d.d. 22TELEKOM SRBIJA, ADSL users 22Telrad doo ISP 22Vodafone Net Iletisim Hizmetleri A.s 22Comilla Online 21Fast Telecommunications Company W.L.L. 21Global Broadband Solution societe de droit america 21Maroc Telecom 21Neterra Ltd. 21Orange Espana 21Orange Polska Mobile 21Orange-jordan 21SaiNet 21Shree Cable 21Tim Celular S.A. 21UNICS Ltd 21Vodacom 21ABCOM Shpk 20Augere Wireless Broadband Bangladesh Limited 20COLT Technology Services Group Limited 20Conesul Telecomunicacoes Ltda 20

Page 14: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

14S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

Indosatm2 20SA Telecable 20Smart Link Communication 20Soluciones en Telecomunicaciones, S.A. 20Techtel LMDS Comunicaciones Interactivas S.A. 20Telecom Ltda Me 20Unetvale Servicos e Equipamentos LTDA 20Vex Net Telecon 20WHS Telecom Serv. Telecomunicacoes LTDA 20Bharti Cellular Ltd. Mumbai 19Comunicaco E Informatica Epp 19Cromtel Prod Impex Srl 19Datec-PNG 19Digicel (PNG) Ltd 19Eskisehir Bilisim Iletisim San. ve Tic. A.S. 19Forthnet 19ITELKOM 19LulinNet 19Media Antar Nusa PT. 19ONO 19PrimaNet - PT. Khasanah Timur Indonesia 19Ranks ITT 19Redes y Telecomunicaciones 19TRIPLEPLAY INTERACTIVE NETWORK PVT LTD 19Vodafone Ghana 19Wana Corporate 19Blicnet d.o.o. 18CallU Telecomunication Ltd. 18Caucasus Online LLC 18CityOnline Services Ltd 18Comcel Guatemala S.A. 18Cyta Hellas 18Ha Noi Post and Telecom Company 18Hathway 18Neotel Macedonia 18Satnet 18SOLNET-Customer-Serial 18STLGHANA 18Telekom Romania Communication S.A 18TM International Bangladesh 18Universitas Ahmad Dahlan 18A Multihomed ISP Company 17candor infosolution Pvt Ltd 17COOLLINK 17EUROTEL Ltd 17INFV+ 17National Information Technology Authority Uganda 17Netcom Enterprises Pvt Ltd 17Norfolk Hotel 17Olo del Peru S.A.C 17PT Maxindo Mitra Solusi, Jl Kelapa Puan Raya Blok 17Tecmidiaweb Ltda 17TPG Internet 17

Triple C Computation Ltd. 17Ver Tv S.A. 17XFone 018 174ALB shpk 16Conjoinix Technologies Pvt. Ltd. 16NETLIFE 16PT. Citra Sari Makmur 16PT. Net2Cyber Indonesia 16SOL-BD 16Telgua 16United Telecommunication Services (UTS) 16Vital Teknoloji Telekomunikasyon Bilgisayar Hizmet 16AUGERE-Pakistan 15BH Telecom d.d. Sarajevo 15Britis Telecom LTDA 15Ifx Networks Colombia 15Intelligent Technologies S.A. 15JSC Kazakhtelecom, Almaty Affiliate 15Libyan Telecom and Technology 15LINKdotNET Telecom Limited 15Multinet Pakistan Pvt. Ltd. 15Net1 15PT. Bangun Abadi Teknologi Indonesia 15R. C. A. Sistemas Ltda. 15Telecom Eireli 15Wamika Broadband 15XFone 15Yota De Nicaragua 15Asre Enteghal Dadeha 14Auro International School Of Hospitality Managemen 14Cable & Wireless Panama 14Co.pa.co. 14Netcomm Argentina SRL 14Operbes, S.A. de C.V. 14Stetnet Telecom 14Telecable Economico S.A. 14Telkom Internet 14Wireless Business Solutions (Pty) Ltd, iBurst 14BSW 13Ixsforall, Inc. 13NuevatelVL 13PT Cyber Network Indonesia 13Ramiro Alfonso Gomez Caicedo 13Romtelecom Data Network 13Seven Star Internet Service Provider 13Sul Americana Tecnologia e Informatica Ltda. 13Telecom Ltda. 13Tellas S.A. 13Tiscali UK Limited 13Triolan 13UNIDATA S.p.A. 13University Pop 13A. C. Vera Filho Telecomunicacoes E Informatica - 12

Page 15: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

15S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

EARTH TELECOMMUNICATION (Pvt) 12IDS Bangladesh. IP Transit provider. Dhaka, Bangla 12IndoInternet Network 12ISP External Zone 12Orbit Telecom Technology Co. Ltd 12PT Quantum Tera Network 12PT. Dutakom Wibawa Putra 12Pt. Linknet 12R Cable y Telecomunicaciones Galicia, S.A. 12Tanzania-e-Government-Agency 12Telecall Brasil Servicos de Telecomunicacoes Lt 12Telecentro S.A. - Clientes Residenciales 12Viasat Communications 12Wds Telecom Ltda. Me 12Dishnet Wireless Limited. Broadband Wireless 11Fastel Sarana Indonesia PT 11Freitas Servicos de Internet Ltda 11GNC-Alfa CJSC 11Gpon Pool 11Greater Amman Municipality 11Grupo Hidalguense de Desarrollo, S.A. de C.V. 11L. Garcia Comunicacoes ME 11Provedor De Internet Ltda Me 11Sapthagiri College of Medical Sciences,Banglore 11Sulanet SA / Insetec Group 11Telecom Cordeiropolis Ltda. 11UPC Ireland 11Wan Interco for customers 11WIND Telecomunicazioni S.p.A 11xDSL Services of HaNoi 11Amazonia Telecom Ltda. - Me 10Core infrastructure 10Globalwave Telecom 10Grameen Cybernet Ltd. Bangladesh. 10Informatica Ltda. - Epp. 10Internet by Sercomtel S.A. 10Liquid Zimbabwe 10Luis Antonio Palomino Dagdug 10Md. Abdul Awual t/a Cyber Way Technology 10MTNRW 10neojaime oliveira ribeiro me 10Netnam Company 10Pakistan Software Export Board 10PlusNet Technologies Ltd 10Terrakom d.o.o. 10Tesat Sp. z o.o 10The Communication Authoity of Thailand, CAT 10UPC Romania SRL 10Worldcall Broadband Limited 10Accesskenya Group Ltd 9Afrihost 9B.b.g Campelo Me 9Commission on Science and Technology for 9

Completel 9Compania. Garantizadora Telecheque Ltda. 9Derkom Spolka Jawna Dariusz Klimczuk 9Equipos Y Sistemas S.A. 9Hotel Paramount 9Hrvatski Telekom d.d. 9HTT 9JSC Kazakhtelecom, East Kazakhstan Affiliate 9Rainbow communications India Pvt Ltd 9SAGLAYICI Teknoloji Bilisim Yayincilik Hiz. Ticare 9SaveCom Internation Inc. 9Sodetel S.a.l. 9Tri Telecom 9Wireless Comm Services LTDA 9A. L. A. Informatica Ltda. 8ABCOM-Business-clients , HFC-Infrastructure 8Bcl South 8Ethiopian Telecommunication Corporation 8GETESA (Orange Equatorial Guinea) 8GO p.l.c. 8Ingenieria Ip Bestel 8Kabel Deutschland 8Linktel Telecomunicacoes Do Brasil Ltda 8MauritiusTelecom 8Multidisiplin Company Express Ltd 8Navega.com S.A. 8Noroestecom Telecomunicacoes Ltda 8Provedor De Acesso A Internet Ltda 8Pt Bina Informatika Solusi 8PT. Hipernet Indodata 8Rasulov Rasul Akhliman-Ogli PE 8Servnet Mexico, S.A. de C.V. 8Spice-net-tz 8Srm Easwari Engineering College 8Symbolics 8Telemasters 8TRUE, The Real Unix Experts 8VipNET 8ZONE Technologies Ltd 8Agentia de Administrare a Retelei Nationale de Inf 7Auspice Infratel Pvt. Ltd. 7Axtel - Recursos WiMAX 7Bharti Airtel Limited 7Bharti Telenet Ltd.mumbai 7BRACNet Limited 7BT 7Cablevision S.A. de C.V. 7Ethernet Xpress Pvt. Ltd. 7Internet Initiative Japan Inc. 7Internet Solutions 7Ipko Telecommunications 7KNK Telekomunikasyon Iletisim Elektrik Sanayi Tica 7Pakistan Telecommunication Company Limited 7

Page 16: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

16S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

PT Tirta Karya Buana 7PT. Cakramedia Indocyber 7Sampark Estates Pvt. Ltd. 7Servicos De Telecomunicao Ltda 7Splius 7Telecable de Asturias,SA 7Telecom Namibia 7Telecom Services (DLI/WLL) Provider 7UAB Bite Lietuva 7ZOL GPON Home Users 7Alcoa Aluminio S/A 6Cablemas Telecomunicaciones (merida) 6Cablemas Telecomunicaciones (tijuana) 6Colinanet Srl. 6Commercial radio-broadcasting company Cable operat 6Digital Network Associates Pvt 6Entel PCS Telecomunicaciones S.A. 6Epm Telecomunicaciones 6Fariya Networks Pvt. 6In2cable (India) Ltd. 6ipNX NIGERIA LIMITED 6Magyar Telekom 6Mercantile Communications Pvt. Ltd 6MNET Internet provider 6MTN Network Solutions Pty Ltd 6Multimedia Polska S. A. 6Nacional De Telecomunicaciones - Cnt Ep 6Newcom Limited 6Ngs-adsl Users Shz 6Rogers Cable 6Servicos em Informatica Ltda 6Telecom Ltd 6Telefonica de Espana 6Telekom Srbija 6TGN 6Tikona Digital Networks Pvt 6Universal Video Cable Srl 6Universitas Negeri Semarang 6Vip mobile d.o.o. 6Wifirst S.A.S. 6116 Madhav Darshan 5Aamra Outsourcing Ltd. 5Agni Systems Limited 5blueconnect 5Citycom Networks Pvt Ltd 5Concerotel-Botswana 5Coop. Limitada De Consumo De Electricidad De Salto 5Daisy Wholesale Limited 5Defferrari Informatica Ltda. 5HoChiMinh City Post and Telecom Company 5ICPNET Cable 5Ikatelnet 5Internet Bandwidth 5

JSC Kazakhtelecom 5Level 3 Communications 5LINKNET 5Media Sac 5Myhosting 5Nayatel (Pvt) Ltd 5New Century InfoComm Tech Co. 5OGERO 5Orange Madagascar 5PredialNet 5PROTONET Adrian Ludyga 5PT Hyperindo Media Perkasa 5PT. Cahaya Buana Raksa 5PT. Palapa Media Indonesia 5PT.Insan Sarana Telematika 5S.N. Radiocomunicatii S.A. 5Sat-Trakt d.o.o. 5SEACOM Limited 5Starhub Internet Pte 5Telrad Telecommunication and Electronic Industries 5Think Systems UK Ltd 5TRI.ph AS Inter-Island Information Systems, Inc. 5Twowin Co., Limited 5Ucom LLC 5Wow Solutions and Systems Pvt Ltd 5Zamtel Copperbelt Cluster PoP Assignments 5CJONLINE ISP India 4Digicel Jamaica 4Etihad Atheeb Telecom Company 4FORTHnet SA 4Globalreach eBusiness Networks, Inc. 4HiNet 4Lemon Tree Hotels Ltd 4MTN Network Solutions (Cameroon) 4Net Telecom 4OJSC Kyrgyztelecom 4PON Services 4Proimage Engineering and Communication Co.,Ltd. 4PT Comtronics Systems 4PT. Eka Mas Republik 4Saber Informatica LTDA 4Sc Multimedia Network Srl 4Servicos de Internet LTDA 4SolNet ADSL Business Pool 4Telecom Argentina S.A. 4Telecom Italia Sparkle of North America 4Telecomunicaciones MOVILNET 4Telefonica Germany 4TIGO COLOMBIA 4Vainavi Industies Ltd 4Access Telecom (BD) Ltd 3Africa Online Uganda 3ALAJUELA 3

Page 17: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

17S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

Argentina S.A. 3Arrownet Pvt.Ltd 3Beykent University 3Bloomsbury Computing Consortium (Birkbeck Geology) 3Btc-gate1 3Cable Onda 3Charter Communications 3China Unicom AnHui 3CMPak Limited 3Ctc. Corp S.A. (telefonica Empresas) 3Dai IP tinh cho khach hang xDSL 3Dominioz Servicos de Telecomunicacoes Ltda 3Grupo Empresarial Mexicano en Telecomunicaciones 3GTS Hungary Telecommunications Limited Liability C 3HTT Telecom SA 3IFX Networks Venezuela 3Internet Thailand Company Limited 3Invitel Tavkozlesi Zrt. 3Jamii Telecommunications Limited 3JSC Kazakhtelecom, Karaganda Affiliate 3Kappa Internet Services Private Limited 3KNet 3Link3 Technologies Ltd. 3M-net 3Metro Net, S.A.P.I. de C.V. 3Multitel 3News and Entertainment Network Corp 3PT Comunicacoes 3PT Diara Kencana Indonesia 3Pt. Matrixnet Global Indonesia 3Public niversity Corporation Oita Prefectural Coll 3Rajesh Patel Net Services Pvt. 3RCS 3Sikka Broadband Pvt. 3StarHub Cable Vision Ltd 3Telnet Communication Limited 3Three 3True Broadband Service 3Villages around Stara Zagora 3Volia 3Albanian Satellite Communications sh.p.k. 2AMWireless Uruguay SA 2Atel Telecom 2Bangladesh Submarine Cable Company Limited (BSCCL) 2Bharti Telesonic 2Bouygues Telecom 2BRAC BDMail Network 2Chi nhanh MienBac-Cong ty CP Ha Tang Vien Thong CM 2ColoCrossing 2Companhia de Telecomunicacoes de Macau SARL 2Cooperativa Telefonica Carlos Tejedor Ltda. 2Digi Spain Telecom SL 2Dtpnet Nap 2

Edatel S.A. E.s.p 2Etisalat 2Euroweb Romania SA 2Gleydson Barbosa Carneiro ME 2Google 2Gulfsat 2H1 TELEKOM d.d. 2HEC 2hellas online Electronic Communications S.A. 2HYPERIA Ltd 2Infolink Tecnologia E Telecomunicacoes 2Intech Online Pvt Ltd 2Interdomain Routing 2Interhost Communication Solutions Ltd. 2JP Posta Srbije Beograd 2JPR Digital 2Karvy Consultants 2kasatech informatica 2Mada ALArab LTD 2MetroCast 2MyRepublic Ltd (Singapore) 2Net-blade Comunicacoes ltda 2NETCEN Teknoloji Ltd. Sti. 2NetCologne GmbH 2NetJat Provedor de Acesso a Internet 2Oasis-sprl 2Onda Internet 2Orion Telekom Tim d.o.o 2Orion Telekom Tim d.o.o.Beograd 2Parmount Hotel 2Pasargad Network 2Planetarium LTDA 2POWERCOM 2PT Excelcomindo Pratama 2PT Indosat Tbk 2PT. First Media, Tbk. 2PT. Lintas Data Prima 2PTCL 2PURISCAL 2salt Lake,Sector-V,Electronic Complex 2Servcom Sp. z o.o. 2Shiraz Hamyar Co. 2Sikka Cable 2SKYCC 2Solucoes Em Internet E Rede Ltda - Me 2Subisu Cablenet (Pvt) Ltd, Baluwatar, Kathmandu, N 2Symphonet 2SystemsFox prestamo de servicos LTDA 2TB Link Telecomunicacoes Ltda. 2Telarus Pty Ltd. xDSL Provider, Australia 2Telenor A/S 2Telkomsel 2Telmex Servicios Empresariales S.A. 2

Page 18: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

18S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

TelOne(formerly ZPTC) 2Time Warner Cable 2Tomato Web (Pvt) Limited 2Triple Play Teleservices Private Limited 2Unitymedia NRW GmbH 2Virgin Media 2VIRTUAL TELECOM A. Sergiel, D. Ladniak Spolka Jaw 2Vmax Net Telecomunicacoes Do Brasil Ltda 2Vodafone Czech Republic a.s. 2Vodafone Omnitel B.V. 2Vodafone Qatar Q.S.C. 2Waves S.a.l 2Wish Net Private Limited 2Worldcall Telecom Limited 2yip telecom 22DAY Telecom LLP 1Ace Data Centers 1Acer Telecomunicacoes ltda 1Adelphia Comunicacoes S.A. 1Adisoftronics 1Al-Jazeera Al-Arabiya Company for Communication an 1AltaNet Telecom e Informatica LTDA-ME 1AlwaysOn Network Bangladesh 1Ambit Microsystem Corporation 1Angkor Data Communication 1Apn - Processamento de Dados e Solucoes em Intern 1Apogee Telecom 1Apps@ Idea Cellular Ltd. 1Asansol Engineering College, Asansol 1Asiacell Communications LLC 1Asiatech DSL Broadband Services 1Asta-net Customers 1AT&T Internet Services 1Atria Convergence Technologies Pvt. Ltd. Broadband 1B.Net Hrvatska d.o.o. 1Belize Telemedia Limited 1Bol-co-tz-as 1Bozorg Net-e Aria 1Branch of Netnam Company in Ho Chi Minh City 1Bredband2 AB 1BTC Broadband Service 1BTTB 1CableTEL DOOEL Macedonia Triple Play Clients 1Capsule Networks 1Chandra Net Pvt. Limited, India 1Chi nhanh HCM-Cong ty CP Ha Tang Vien Thong CMC 1China Telecom fujian 1Com De Equip. De Tele Informatica 1Comunicacao Virtual Ltda 1CONECEL 1Connect Communications 1Corporacion Digitel C.A. 1Customers Procono 1

Cyber Info Provedor de Acesso LTDA ME 1CYTA 1Delta Telecom Ltd 1Den Digital Entertainment Pvt. Ltd. AS ISP india 1DigitalOcean 1Direct On PC 1Dodo Australia 1Dolphin IT Pty Ltd 1E Cia Ltda 1EarthLink Iraq 1ecotel communication ag 1Etisalat Misr 1Evergy S.A. 1Ez Runner Systems LTD IP Space 1Far EastTone Telecommunication Co. 1Fiberpipe communications pvt. ltd. 1Fixed wireless broadband 1Free SAS 1Ganesha Internet Services India Private Limited 1Gigaclear PLC 1Global Tech Internet Banda Larga EPP - ltda 1GoDaddy.com, LLC 1Gtd Internet S.A. 1Gudlavalleru Engineering College 1Gurunanak Institute for technology, Panihati, Kolk 1Hellas On Line S.A. 1Hetzner Online GmbH 1Ho Chi Minh City Post and Telecom Company 1Hoshin Multimedia Center Inc 1Hosting Internet Hizmetleri Sanayi ve Ticaret Anon 1Idea Cellular 1IHS Telekomunikasyon Ltd 1Inel Internacional Dooel Kavadarci 1Infocom-ug 1Informatica e Telecomunicacoes Ltda. 1Infranet Solutions 1Integral University 1Integrated Measurement Systems 1Internet 5.8 Provedor E Informatica Ltda-me 1IP Core MPLS 1IPS - Keysquare 1Iran Cell Service and Communication Company 1ISInternetSolutions 1Javne adrese za ADSL korisnike 1Jordan Tv Cable & Internet Services Co 1JTL 1Kyushu Telecommunication Network Co.,Inc. 1Lafaiete Provedor de Internet e Telecomunic Ltda 1Leasedline service 1Libantelecom 1Link Telecom Net 1Lintas Data Prima, PT 1LIQUID BROADBAND (Pt-Pt FIBRE) 1

Page 19: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

19S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

M & M Telecomunicacoes Ltda 1M1 Connect Pte Ltd 1Magic Net D.o.o. 1Makedonski Telekom AD-Skopje 1Medical University of Warsaw, Faculty of Pharmacy 1Melita plc 1Melsa-i-net 1MetroNet Bangladesh Limited, Fiber Optic Based Met 1MTN NIGERIA Communication limited 1Mumbai Gsm Ip Pool 1NC Numericable S.A. 1Net Group 1Net Infinito Telecom 1NETPLAY INC. is an internet gaming provider 1Netsoft, PT 1Network Operations Center 1Nippontec Telecomunicacoes 1Nos Comunicacoes, S.A. 1Office of the basic education commission 1OMNITEL Net 1Orange Armenia CJSC 1Pacifico Cable S.A. 1PaintWeb Internet Ltda 1Pakistan Telecommuication company limited 1PhilCom Corporation 1Phoenix IT Services Ltd 1Provedor Ltda 1Provider Servicos de Comunicao Multimedia LT 1PT Sampoerna Telemedia Indonesia 1PT. Arsen Kusuma Indonesia 1PT. Core Mediatech (D-NET) 1R Cable 1Rangsit University 1RCS & RDS Residential 1Realmove Company Limited 1Red Intercable Digital S.A. 1Rede Winet Telecom 1Rotop Internet Provider 1Sabanet network in Shiraz 1Sabanet Tehran 1Sat Film 1Sc Netfil Srl 1Scientific -Industrial Firm Volz Ltd 1Setarnet 1SevenStar Broadband 1Shabakah Net 1Shri Sai Agencies 1Sky Broadband 1

Solusindo Bintang Pratama, PT 1Speednet Telecomunicacoes Ltda ME 1StarHub Internet 1Super Automobiles Ltd 1Supply Net Servicos Ltda - ME 1Symphony Communication PLC. 1T-Mobile Czech Republic a.s. 1Telecel S.A. 1Telecom Ltda Epp 1Telecommunication Infrastructure Company 1Telecomunicacoes Do Brasil Ltda. 1Telecomunicacoes Ltda 1Telefonia Bonairiano N.V. 1Telekom Austria 1Telenor doo Serbia address space for mobile access 1Television Internacional, S.A. de C.V. 1TELGAM S.A. 1Telgo Telecomunicacoes Goias Ltda. 1TelkomInternetBroadband 1Temp object 1TEO LT 1TOPNET 1touch Lebanon 1Ttsl-isp Division 1Turksat Uydu-Net Internet 1UniNet(Inter-university network) 1Unitymedia 1Uzbektelekom Joint Stock Company 1VEGA South Branch 1Verat D.O.O. Internet Service Provider 1Vietel - CHT Compamy 1Viettel-cm-as 1Viewqwest Pte Ltd 1Virtex Ltda 1Vm Openlink 1VOO 1Vox Telecom (Pty) Ltd 1Wananchi Online 1WBS, Wireless Business Solutions 1West Internet Banda Larga 1WIFIWEB s.r.l. 1wilhelm.tel 1Wimax Clients 1Witribe Pakistan Limited 1Yawl Telecomunicaco e Rep. de Informatica Ltda 1YOU Broadband & Cable India Ltd. 1zicom Next Spolka Z Ograniczona Odpowiedzialnoscia 1

Total Result 54,205

Page 20: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

20S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

lawusa.com 10,066nsoft.it 3,968newarkha.org 3,419imco-inc.com 2,060nlex.com 1,662aagcorpus.com 1,568jlburke.com 1,503rp-printers.co.uk 1,331fdfltd.com 896enclos.com 825bcp.co.uk 741correctcare.com 708matthews.com.au 648shapearts.org.uk 610advancedweb.net 588brakemasters.com 514martinflyer.com 473terrus.com 431gulfcoastmed.com 401pikecac.org 365bakerswaste.co.uk 340allitt.co.uk 315garysan.com 312sverigedemokraterna.se 308solaresflorida.com 297numberone.com.br 296perry.k12.ia.us 291intuition.co.uk 286wyatthomes.co.uk 276hhschools.org 269tombryant.org 262usyouthsoccer.org 261plymouthyarn.com 259heddenchong.com 250ost.edu 248griefnet.org 246fullcirclefeedback.com 244superiorpetroleum.com 243c-s.co.uk 227cnta.es 223obinet.com 221kelloggsupplyco.com 219eliteislands.com 210pusateris.com 209deerland.ca 207woburnpd.com 201alteropower.ru 194kingsburyclub.com 189townofmanteo.com 188surpluscenter.com 178beachbook.com 176waterline.ch 176

llanover.com 171quantatec.com.br 170bcinternational.org 161karmod.com 150ahk-howa.com 144sonicburst.net 143aspenpress.com 141liggettgroup.com 140surfsponge.com 140islandxpertees.com 139broomheads.com 138getonit.co.uk 134ptfcu.org 132whitedove.uk.com 132markeire.com 131cfeamerica.com 126rossi.ch 126sylvesterservices.com 123amerepro.com 119jrtr.org 118sd.se 117ajplast.co.th 110ballethispanico.org 110bell-litho.com 110acmorgannwg.org.uk 104cvomfs.com 104cts411.com 103casanz.org.au 102microplastics.com 97sauguspd.com 96uwcr.org 94greggruth.com 90dancorinc.com 89eii-1.com 80gruppofeg.it 79esko.dk 73imcoconstruction.com 72wjelectrical.co.uk 72usamines.com 71integratec.biz 68sdu.nu 68gba.co.za 67hatz.com.au 64integritysolnw.com 63bergmann.de 61akyapidizayn.com 60crosswear.co.uk 59apologeticspress.org 57fjetland.com 56ugl.it 56seltechaero.com 55lupprians.com 54

Page 21: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

21S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

ccssite.org 53akbank-dsg.com 52gruppofeg.com 49newlifeprovidence.com 49edwardbukaty.com 48jenkins.uk.net 48lupprians.co.uk 47nrpd.org 45pna-inc.com 45brandvaughan.co.uk 44abrasivburada.com 43ferro.com.tr 43itregister.com.au 43teamsrl.it 43autovan.co.uk 42bedfordva.gov 42codefoundry.com 42spiculum.com 40springfieldareahba.com 40cefnlea.co.uk 39drwebhosting.com 39gng.ch 38vicaragecourt.com 38reddrumtackle.com 37sandwelltraining.com 37argepakambalaj.com 36cupplesinc.com 36gwcindia.in 36primecre.com 36scansail.de 33broomheads.co.uk 32cliltd.co.uk 32colourgro.co.uk 32laborkimya.com 32cypressintegrated.com 31dtp.com.tr 31pitsurf.com 31wjbeitler.com 31bmslimited.net 30admetalspinners.co.uk 29logicbox.net 29sylvanks.com 29us-amines.com 29scoresontheboard.com 28capitalpcc.co.uk 27fdr.on.ca 27johnaustin.co.uk 27kapadokyafashionproductions.com 27chholdings.com 25gdl-logistics.com 25hctf.ca 25hillviewretirement.org 25

maldenpd.com 25tailoradio.it 25teknikcivi.com 25vei-austin.com 25adadt.com 24ajanskarakalem.com 24alpinoto.com 24portsmouthoh.org 24rtzco.com 24talassoterapi.com 24zeynep.com.tr 24ahkohio.com 23kingsburyclubmedfield.com 23lacomms.com 23missimo.com 23premoe.net 23samko.com.tr 23sheldonbosley.co.uk 23urorad.net 23adrgroup.com 22cfaulknerengineering.com 22hermitage-hotel.co.uk 22inkamakina.com 22martysgmc.com 22paymentct.com 22prism-design.co.uk 22schreiner-versicherungen.de 22whiteoakuw.com 22altinkent.com 21billlang.org 21brcga.org 21corolla-light.com 21fortestech.com 21housingcollaborative.org 21medyapark.com.tr 21saugus-ma.gov 21ak-es.net 20anilmatbaa.com 20chiphisigma.com 20scheurich-gmbh.de 20ubismail.net 20alfatransport.com 19alpininsaat.com 19argeyikama.com 19atmconsultants.com.au 19deltamuhendislik.com.tr 19flblind.org 19goksm.com 19newpig.com.au 19sacvalley.org 19karizma.com.tr 18oddy.net 18

Page 22: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

22S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

priasoft.com 18redarenatur.com 18akaambalaj.com 17euclidindustries.com 17fourseasonsinduck.com 17prestigeaustralia.com.au 17rand-associates.co.uk 17saecircuits.com 17solartimeltd.com 17aldaydinlatma.com 16annoushka.com 16BrightStreet.biz 16capricornimports.co.uk 16confexuk.com 16dana.ru 16dori.com.tr 16sultangida.com.tr 16visioncareathome.co.uk 16ablukaalarm.com 15ak-der.com 15altkatsanat.com 15avezinsaat.com 15bloomsbury-law.com 15boergerlaw.com 15estetikspor.com 15itgeneration.ca 15milanis.it 15nichegenerics.com 15pmgstone.com.au 15sunbeamfostering.com 15alphafinancialadvisors.com 14klf-insurance.com 14masteringworld.com 14megagrp.com 14rcs.com.ph 14senayapidenetim.com.tr 14twoogroup.com 14akanyapi.com 13cambridge-residential.co.uk 13ctek.ch 13frontporchcafe.net 13gatewaysportsclub.com 13jdconcrete.com.au 13lund-pedersen.dk 13mancia.net 13muratmetal.com 13principal-medical.co.uk 13resolutionstech.com 13sharpwin.com 13ssf-group.co.uk 13syncopatemedia.com 13vicarscrossdentalpractice.co.uk 13

altinseramik.com 12antikipek.com 12barcelos.co.za 12beitlerlogistics.com 12bernard.bg 12comquest.com.ph 12docharity.ie 12ecbh.org 12human-performance.com.au 12infosource.com.tw 12izmit.bel.tr 12monicaricci.it 12mybsg.net 12nichegenerics.ie 12oym.com.sv 12sdkuriren.se 12statistixl.com 12thecoastlandtimes.net 12unoxuk.com 123dbouwteam.be 113dmimari.net 115percangol.hu 11alaybeyoglu.com.tr 11alchem-merseyside.co.uk 11alogluservis.com 11artasgranit.com 11beyazinsaat.com.tr 11brightgreenhydrogen.org.uk 11coastalimpressions.com 11mercankalip.com 11sykoraconsulting.com 11tal-dani.net 11aketiket.com 10alikilic.net 10atlantisvalley.com 10century21halikarnas.com 10destinaotel.com 10financialadvisors.net.au 10fwgrab.com 10hafodmastering.co.uk 10kizilay.org.tr 10kollerdirect.ch 10mzpartners.co.uk 10noktaalarm.com 10postacikurye.com 10scope-india.com 10tanplaza.com 10tarotgarden.com 10teamweb.it 10tezhukuk.com 10thesuffolkgroup.com 10thinksmart.co.th 10

Page 23: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

23S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

woburnfd.com 10a2zfethiye.com 9abirmetal.com 9altuasansor.com 9aplussigorta.com 9aydinlarg.com 9bayraktarhukuk.com 9bgexcavating.com 9bherville.com 9cesas.com.tr 9darino.us 9ekom.com.tr 9figureone.com 9gnrturizm.com 9houseoftrimble.com 9idesm.com.au 9jonesandbrown.com 9kusaktekstil.com 9macroc.com 9mid-michnet.com 9MSPCapital.co.uk 9procolor.com.tr 9securitygates.co.uk 9solucion-es.com.mx 9vernoncourtreporters.com 9versorgungskompass.de 9zeysinturizm.com 9a1budgetskips.co.uk 8antalyamikro.com 8arsmakina.com.tr 8bcrp.ca 8becketts1945.com 8brass.ru 8cellsys.co.za 8cukurovam.com 8dcmtekstil.com.tr 8deanster.com 8delkoconstruction.com 8erkockalip.com 8feg.it 8fotoremzi.com 8innovativecurbs.com 8invisionsite.com 8iwanskimasonry.com 8mcfflex.com.tr 8odonnellfamily.co.uk 8ozalpertekstil.com 8parcher.net 8proserpio.it 8reyline.com 8rpprinters.co.uk 8sussexsurveyors.com 8

trilliamllc.com 8ukmkimya.com 8winetram.co.za 8activasatis.com.tr 7adatip.net 7ajanskaraca.com.tr 7akstainsaat.com 7bostonkitchen.com 7ci-ltd.co.uk 7dayscrapmetal.com 7dorabase.com 7ehconline.org 7erce.com.tr 7garantiturizm.com 7maxi.com.tr 7pridefostering.com 7schroeder1.net 7thehydrogenoffice.com 7tomthefreak.com 7top-tech.us 7trio-max.com 7uludag.com 7weger.com.tr 7yelkenisi.com.tr 7zes.com.tr 7acikgrup.com 6alanyahomes.com 6alpe.com.tr 6apsaegis.co.uk 6argkonsantre.com 6artuklu.com 6aybeyhidrolik.com 6camlicaboru.com 6chunkychode.com 6debigroup.com 6dekagroup.net 6direkreklam.com 6formulachemicals.com.au 6global-offers.com 6gnc.com.hk 6hayvancilik.org 6ioma.com.tr 6irmethospital.com 6kaserer.de 6kaynakmarble.com 6koknarkoyu.com 6kontrolnoktasi.com 6lanplus.co.uk 6londiniumedu.com 6madenlim.com 6meyainsaat.com 6mikronmakina.net 6

Page 24: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

24S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

modatextile.com 6morplastik.com 6mothdust.com 6nadgeebynature.com.au 6o2.com.tr 6oztoksa.com 6pasifikintl.com 6perlavista.com 6pilatus-intl.com 6powertrans.com.tr 6progresstr.com 6redmintcomms.co.uk 6tahaoffice.com 6terrabilisim.com.tr 6ultimate-pilates.co.uk 6yukselteknik.com 6abantcamp.com 5abmetiket.com 5aclmekanik.com 5akpas.com.tr 5ambergas.com 5anthonysofringwood.co.uk 5austexeng.com.au 5azaksu.com 5bamabay.com 5bilgitas.com 5cahootrecruitment.co.uk 5cipoandbaxx.com 5ctekag.ch 5demiroren.com.tr 5denizelektronik.com.tr 5dursunbey.bel.tr 5entspringfield.com 5freeenergycorp.com 5furkanpimapen.com 5gokcemobilya.com 5gulpa.net 5izlee.org 5majormusic.com.tr 5metcotek.com 5n340.com 5napchan.com 5nysa.com.tr 5orass.com 5petrosa.net 5promarket.com.tr 5realestateobx.com 5rebuildchristchurch.co.nz 5rekare.com 5sahper.com 5santrabil.net 5seyriistanbul.com 5

sgseniors.com 5solmazgida.com 5terminalistanbul.com 5tudorlawns.co.uk 5ulusoyambalaj.com 5unitragen.com 5vikoser.com 5written4.com 5yavuzcanotomotiv.com 5zeylandavm.com 5acfpd.org 4acomp.com.hk 4aderans.com.tr 4akdenizorman.com 4alerosi.com 4almetal-tr.com 4altunisik.com.tr 4anatolianballoons.com 4ankaajans.com 4apesan.com.tr 4archangelpartners.com 4archy.com.tr 4arigumruk.com.tr 4armadenizcilik.com 4asel-grup.com 4asinsaat.com 4asterion.com.tr 4atauni.edu.tr 4ateg.com.tr 4ayi.org 4baharentacar.com 4baratin.co.uk 4boblandau.com 4boozermail.com 4boucher.me 4brunton.co.nz 4cankayabelde.com.tr 4ccgroupco.com 4coastalhomecare.co.uk 4comodo.od.ua 4corecasys.com 4cremetekstil.com 4dogaspor.com.tr 4dokuzogluism.com 4dpi.com.tr 4ekolej.net 4engsol.co.ug 4estelgsm.com 4evolution-media.de 4fairweatherfoods.com 4frontporchcafe.com 4frontporchcafeonline.com 4

Page 25: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

25S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

fumokozmetik.com 4greenowlcafe.co.uk 4ileryemek.com 4ins-scandinavia.com 4iqvision.com.au 4iro.org.tr 4juntunenenterprises.com 4kalipdestek.com 4kcmitre10.com.au 4maesta.com.tr 4marmaramuh.com 4mavimar.com 4mayasar.net 4maytekstil.com 4meshferg.com 4mgreene.co.uk 4modeltekstil.com 4morten.com 4nettaelektronik.com 4niramak.com.tr 4orenda.com.tr 4osmanli-grup.com 4outerbanksinternet.com 4ozipeklirulman.com 4ozlemkimya.com 4ozusta.com.tr 4pepper.net 4peronmoduler.com 4pinarkimya.com 4pslconstruction.net 4publicit.co.uk 4rutas.com.tr 4rutson.com.tr 4sagatr.com 4sandimatur.com 4selgroup.com 4semttarim.com 4sertekshali.com 4sparktr.com 4staleymail.com 4stneots-tc.gov.uk 4temamakina.com.tr 4troytarim.com 4universaldecoration.com 4vipponholidays.com 4viramar.com.tr 4xkobi.com 43he.com.tr 3adatrafik.com 3afcbuilding.com 3affinageturkiye.com 3akinsen.com 3

akmatek.com 3akmerkezcicek.com 3aksinsaat.com.tr 3alemdaroto.com.tr 3anadoluconta.com.tr 3ankateknik.com.tr 3arcmaintenance.net 3ardakurutemizleme.com 3arifizgidizayn.com 3arimoda.com 3arkiletisim.com 3artevetta.com.tr 3artimedyareklamcilik.com 3artuz.com 3asdogunakliyat.com 3aslanelektrik.org 3atik.com.tr 3atoskimya.com.tr 3aydinizolasyon.com 3aydinnakliyat.com.tr 3aykar.com.tr 3balarisianaokulu.com 3bentspor.com 3birthday-suits.com 3bltgiyim.com.tr 3bsckurye.com.tr 3bsm.com.tr 3burakkimya.com 3cakirtekstil.com 3caliskanvize.com 3camfrogsamsun.com 3can-textile.net 3canplastik.com.tr 3ccsite.org 3celik-yapi.com 3cihanins.com 3cilsancikolata.com 3compagniadelmobile.it 3cruiseclubofamerica.org 3ctbilgisayar.com 3datekstekstil.com.tr 3demhali.com 3demircelik.com 3denimse.com 3deriisi.com 3digitalfuel.co.za 3doguakdeniz.com 3drpa.org.au 3efsenturizm.com 3ekapano.com.tr 3elichemoil.com 3elsi.com.tr 3

Page 26: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

26S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

emsgumrukleme.com 3enesnakliyat.com 3enmegien.com 3epar.com.tr 3erdemsan.com.tr 3fabrikadekor.com 3fcbp.dk 3fdl.co.nz 3feniksbilisim.com 3ficke.org 3floridaway.com 3globallmarka.com 3goldperdesistemleri.com 3grafmat.com 3grupobelpa.com 3guneskilit.com 3guraybilgisayar.com 3gurbuzelektrik.com 3gursoft.com.tr 3haanyapi.com 3havatur.com 3hemas.com.tr 3henaisi.com 3hgd.co.uk 3hijyenurunleri.com 3hitityazilim.com 3hizmar.com 3hns.com.tr 3ilkson.com 3infosource.com.hk 3istekotomotiv.com.tr 3jbrashear.com 3johnparkinsonagency.co.uk 3k-e-b.com 3kanver.org 3karacasan.com 3karalmetal.com 3keremambalaj.net 3kivancsigorta.com 3klassis.com.tr 3kolaykapak.com 3korusu.net 3laviron.com 3lennonassociates.com 3liderkimya.net 3mesaaluminyum.com 3mevsimtriko.com 3mgenerji.com 3midwestpa.com 3mossa.com.tr 3msg.co 3nisantriko.com 3

nurulex.com 3onurparklife.com 3optimum.gen.tr 3orbit-tr.com 3ovayapi.com 3ozkaryapi.com 3ozlermakina.com 3plaskil.com 3profiautomation.com 3proteknik.com.tr 3rase.com.tr 3reymar.com.tr 3rimtour.com 3robocoating.com 3sdkvinnor.se 3semhidrolik.com 3semih.us 3separotomotiv.com 3seselektronik.com.tr 3seviletek.com 3shamiso.net 3siringul.com 3somoco.biz 3sonitrolncf.com 3stagglaw.com 3starbilgisayar.net 3tarikmakina.com.tr 3tat-mak.com 3tetyazilim.com 3theanchorageinn.com 3thelinghouse.com 3tmpcco.com 3torbey.com.tr 3travelpoint.com.tr 3turkcafe.net 3ucuzcorap.com 3ugurcan.org 3uludagzeytin.com 3ulutour.com.tr 3unallarltd.com 3unyemaden.com 3whiteoakinnandsuites.com 3woxxiehotel.com 3wyatthomes.com 3yamacambalaj.com.tr 3yuzdeyuztasarim.com.tr 3zafergrup.com 3zeko.com.tr 3zumbaunited.com.au 3abadturizm.com 2abaski.com 2abreklamcilik.com 2

Page 27: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

27S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

acarmakinacnc.com 2acatrans.com 2aconotomasyon.com 2admetalspinners.com 2adtmarble.com 2afcmetal.com.tr 2agarastirma.com.tr 2airportist.com 2ajansorganize.com 2akkozceviz.com 2aksisgrup.com.tr 2aksoydemir.com 2alfaelektrik.com 2alfahavacilik.com.tr 2altinay.web.tr 2altinkozamobilya.com 2amarlatours.com 2anewlooklawncare.com 2ankarayayinevi.com 2antmimarlik.com 2appma.com.au 2apt.com.tr 2arca.com.tr 2areamakina.com 2argeontur.com 2ariorman.com 2armadora.com.tr 2arnida.com.tr 2artevetta.com 2as-fe.com 2asfe.com.tr 2aslanevdeneve.com 2asudeoptik.com.tr 2atakalibrasyon.com 2atilganelektronik.com 2atisyapi.com 2atuluk.com 2austintechs.net 2avores.com 2avpro.com.au 2ayasoft.com 2aybarlar.com.tr 2aysekazanci.com 2aystekstil.com 2ayzereklam.com 2aztteknik.com 2bahadirmakina.com.tr 2bektastente.com 2belemirperde.com 2benimse.com.tr 2berkaisguvenligi.com 2berkamakina.com.tr 2

betest.com.tr 2beysu.com 2bfmasansor.com 2bildikmuhendislik.com.tr 2biltechbilgisayar.net 2bkjenerator.com 2bogazicielektrik.com.tr 2bumera.com.tr 2cadhousetr.com 2cag-han.com 2cagceviri.com 2cagrigrup.com 2camlica.net 2camlicakagit.com 2canakhotel.com 2cantaimalati.com 2cappadoccia.com 2caprioloshoes.com 2carexpress.com.tr 2cc-tour.net 2cembars.com 2cersanasansor.com 2cevahirtelekom.com 2cevaplar.org 2chameleonreklam.com 2cimteknik.com 2citycenterhotel.com.tr 2cmsteknik.com 2cmyk.com.tr 2compert.ch 2connect-es.com 2coventgarden.uk.com 2datalinebilgisayar.com 2datamak.com 2degersoy.com 2dekoraktifyapi.com 2denizciler.biz 2dersanleather.com 2desiprint.com.tr 2destan.com.tr 2die-loewis.at 2dilaver.com.tr 2dilmun.com.tr 2dimaks.com.tr 2dinlermobilya.com 2dizaynonur.com.tr 2dogan-yapi.com.tr 2dogusdizayn.com 2dual.com.tr 2ducablanca.com 2dwgatesengineering.com 2e-mey.com 2

Page 28: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

28S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

efeselektrik.com 2efsaneoyun.com 2ekinelektronik.com 2ekipboya.com 2elmundo.com.tr 2emexotel.com 2emniyetgida.net 2emreaytas.com 2energyandtransit.com 2engaz.com.tr 2eproyazilim.com 2erbimobilya.com 2erkalip.com 2erogluotomat.com 2erseteknoloji.com 2ersinofset.com 2etken.com.tr 2etkitanitim.com 2etliogullari.com 2eximterms.com 2eynar.com 2fabfatih.com.tr 2fasakimya.com 2ferinoks.com 2fevzialtuntas.com 2firmak.com 2forsbayrak.com 2fotoremzi.com.tr 2galvanokimya.com 2gda.com.tr 2gecemhome.com 2gencler.com.tr 2gilkes.com.tr 2gramerser.com.tr 2gudertour.com 2gulnursozmen.com 2gumush.com 2gunesmedical.com 2gunesparkevleri.com 2guvenerltd.com.tr 2hakankarman.com 2halantex.pl 2hasankolcu.com 2hasmakvinc.com 2haspetrol.com.tr 2hepgur.com 2herkulmakina.com 2hks.com.tr 2hmsindustry.com 2holidaymedya.com 2htmturkey.com 2hyqualcabinets.com.au 2

ictkimya.com 2idealchoice.co 2ideanova.com.tr 2ideaotomasyon.com 2ikrambeder.com 2imajdoor.com.tr 2impulseajans.com 2inter.tc 2istanbullounge2.com.tr 2istanbulpaintballarena.com 2kahramankimya.com 2kalkavangroup.com 2kaptanlar.com.tr 2karekupajans.com 2karmaaku.com 2karmenmutfak.com 2karsancammozaik.com 2kava.com.tr 2knotisse.com 2kolcakmobilya.com 2kopuzturizm.com 2koysofrasi.net 2kreateks.com.tr 2kusgroup.com 2kuzeytrans.com 2logotek.com.tr 2ltsyazilim.com 2maceraofisi.com 2macoyun.com 2makdis.com 2markaakademi.com 2martiinkay.com.tr 2masna.com.tr 2mavisu.com.tr 2maxbetvip.net 2mimgrup.com.tr 2mipatex.com 2miryildiz.com 2misan.com.tr 2misket.com.tr 2mittem.com.tr 2moduldisplay.com 2mokitoys.com 2muratince.net 2nasuhoglu.com 2negatif.com.tr 2nejattezologullari.com 2neontekstil.com 2niyazstores.com.mv 2nizamsogutma.com 2obus-target.com 2ocosec.org 2

Page 29: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

29S P E C I A L R E P O R T

THREAT RESEARCH LABS

ogunfiltre.com 2okankoleji.com 2onurotomotiv.net 2onurtrafik.com 2opascompany.com 2ormanci.com.tr 2orsagemi.com 2oscarrentacar.com 2ostimlazer.com 2otantikotel.com 2ovamtur.com 2ozdemirplaza.com 2ozgulozgule.com 2pardis.com.tr 2pasaportpier.Com 2paykom.net 2phillipstree.com 2pinky-tr.com 2plastinfo.com.tr 2polipan.net 2possistem.com.tr 2powerinsaat.com 2pozitifplus.com 2prairiefinancial.net 2pro-sales.ch 2proQloud.com 2pstk.com 2ptjandpartners.co.uk 2qpck.net 2qurancomplex.gov.sa 2radyoz.net 2relaxia.it 2renksel.com.tr 2reyhantekstil.com.tr 2riyazussalihin.com 2rolekselektromekanik.com 2roosen.dk 2ruzgarambalaj.com 2sadida.net 2safaun.com 2safirarms.com 2sakaryasamsung.com 2samsuntekstil.com 2sanitamax.com 2santic.com.tr 2sanver.com.tr 2sarkomkompresor.com 2sasayapi.com 2sass.com.tr 2sayginlartransport.com.tr 2saygireklam.com 2sayintabela.com 2

scgfoods.com 2sdmotor.se 2seaandsuntours.com 2seleksan.com 2selimoglu.org 2semantekstil.com.tr 2senkrongrup.com 2serefoto.com 2serkanertem.com 2seyditekstil.com 2sezerler.com.tr 2siberplastik.com.tr 2sidemekanik.com.tr 2sienkakupeste.com 2sirvanemlak.com 2sis-cons.com 2sisteknik.com 2sistempark.net 2sivitebesirim.com 2skeathlaw.com 2skippyskiphire.co.uk 2skzlojistik.com 2smarttechbilisim.com 2sosyalbidunya.com 2sparktemizlik.com 2sporlabtr.com 2sportsgiyim.com 2sprechtraining.at 2ssgmakina.com 2sterimate.com 2ststurizm.com 2sturgeonmail.com 2suarem.com 2sunaryapi.com 2sunbeamfostering.co.uk 2supernalbur.com 2talescon.com 2tdtm.com.tr 2techstor.com.tr 2teknikraf.com 2teknostil.com.tr 2tekstilotel.com 2ter-bo.nl 2the-goodes.co.uk 2toloman.com 2trans-iowa.org 2tresamigos.tv 2tunalimuhendislik.com 2turkerambalaj.com 2turnikemedya.com 2tutgareklam.com 2ufukelektronik.com.tr 2

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

Page 30: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

30S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

ultatrans.com 2umsteknik.com 2ungsvenskarna.se 2urlakilincemlak.com 2uzmanklima.com.tr 2valentinediamond.com 2vavsanat.com 2vdmvize.com 2venit.org 2vitamuhendislik.com 2voyage-expo.com 2vsrmuhendislik.com 2waffle.com.tr 2wearekeep.co.uk 2wheeltec.com.hk 2yalcinkayahali.com.tr 2yasarmakina.net 2yedipunto.com 2yenilikosgb.com 2yertan.com 2yetenekticaret.com 2yetkinmutfak.com 2yigitambalaj.com 2yildiz.av.tr 2yildizavize.com 2ypctur.com 2yvesfreydiamonds.com 2zaferticaret.com 2zenginofset.com 2zeostek.com 2ziimy.com.tr 22be.com.tr 12elesya.gen.tr 12soft.org 1304plus.com 13genbilgisayar.com 13ndepolama.com.tr 13treklam.com 141gemi.com 150v8.com 1888oilpump.com 1abc-muhendislik.com 1abcfinancialadvisors.com.au 1abcmaker.com 1abdullahorak.com 1abrates.com.tr 1absambalaj.com 1acilimteknik.com 1acilsatilik.org 1actilia.co.uk 1ad-sar.com 1adaisitme.com.tr 1

adamor.com.tr 1adanetbilisim.com 1adbox.com.tr 1adibellitel.com 1adrdanismanlik.com 1adresmimarlik.com 1adstasarim.com 1afbamak.com 1aferez.org 1afkuzeykumascilik.com 1aflexterlik.com 1afsinhotel.com.tr 1agsteknoloji.com 1ahmetkayar.com.tr 1ahsapbasamak.org 1ahsenhali.com 1ailedestekevi.com 1aiptekturkiye.com 1ajansdk.com 1ak-gida.com.tr 1akademiktisat.net 1akadtekstil.com 1akaraluminyum.com 1akaryapi.com 1akayelektronik.net 1akbayteknikservis.com 1akcayasansor.com 1akcayendustri.com 1akdemdanismanlik.com 1akelwool.com 1akinyildiz.com 1akisticaret.com 1akkuslarmakina.com 1akmanboya.com 1akmar.org 1akmesemusavirlik.com 1akngrup.com 1aknuryapi.com 1akreditetercume.com 1aksaarms.com 1aksumadencilik.com 1aktaslarmakina.com 1aktasymm.com.tr 1aktifhayatmedikal.com 1aktifreklam.com.tr 1akustikdanismanlik.com 1alfaled.com.tr 1alfayapim.com 1aligul.com 1aliozcanhoca.com 1aliural.com 1allwayslimousine.com 1

Page 31: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

31S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

almanyavizeofisi.com 1alpaymuhendislik.com 1alsancakkopyalama.com 1altatextile.com 1altinkentinsaat.com 1altinorsmetal.com 1altosis.com 1alucoform.com.tr 1aluteknik.com 1an-ka.com 1anadolubasin.com 1anadolukaratasimacilik.com 1anadolumermer.com 1anahtarproje.com 1angorarozet.com.tr 1animmatbaa.com 1ankaambalaj.com 1ankamedya.com.tr 1ankaraarcelik.com 1ANKARAREIKI.com 1ansamed.com.tr 1antimpex.com 1aplan.com.tr 1aplusbilisim.com 1apsent.com 1aquakamp.com 1aramisyayinevi.com 1ardaalyans.com 1ardaisg.com 1ardegrup.com 1ardemmed.com 1arensy.com.tr 1aresarchitecture.com 1aresgumus.com 1arestasigorta.com 1argebilgisayar.com 1argemyazilim.com 1arifoglu.net 1arikanbilgisayar.com 1ariktekin.com 1aristonyetkiliservisi.com 1arkadas.org 1arkusinsaat.com 1armadabilgisayar.com 1armadaosgb.com 1armutluun.com.tr 1arnavutkoyweb.com 1arsaarnavutkoy.com 1arsekkimya.com 1arsgeo.com 1arslanbulut.com 1arti2fotograf.com 1

arti90studio.com 1artiaile.com 1arusaturizm.com 1arustek.com.tr 1arzuyildiz.com 1asaltemizlik.com 1asbisiklet.com 1aselinsaat.com 1aselyayincilik.com 1asikunefeleri.com 1askinturlojistik.com 1aslanaytakograf.com 1aslicoban.com 1asmcreatives.com 1asmotomotiv.com.tr 1astam.com.tr 1astecbilgisayar.com 1astimosb.org.tr 1asvale.net 1asyaozalit.com 1atabilgic.com 1atakoynakliyat.net 1atalayemlak.com.tr 1atasarimgroup.com 1atayangin.com 1atbotomasyon.com 1ateslergroup.com 1atesveates.com 1atilacicek.com.tr 1atilgan.biz 1atlantiksan.com.tr 1atlantisfm.com.tr 1atlasturizm.com 1atolye3.com.tr 1atolyekanepe.com 1atsinsaat.net 1atsmimarlik.com 1atulukcevre.com 1aurainvestgroup.com 1auro.com.tr 1AVANTAJGIDA.com 1avantajmarket.com.tr 1avcilaragirnakliyat.com 1avcimobilya.com 1avenkalip.com 1avmarket.org 1avnikoyun.com 1avortekstil.com 1avrotours.com 1avukatportal.org 1aybeymakina.com 1aycanmakina.com 1

Page 32: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

32S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

aydinbentonit.com 1aydinhidrolik.com 1aydinlarcam.com 1aydogduyapi.com 1ayembilisim.com 1ayfirsat.com 1ayhanyildiz.net 1ayisigimedya.com 1aykorelektrik.com 1aykutbalci.net 1aykuttekin.com 1ayrenparts.com 1aysanelektrik.net 1aysantarim.com.tr 1aysegulozgur.com 1aytacbranda.com 1aytacengin.com 1aytam.com.tr 1aytaslar.com 1aytcarrental.com 1ayvansaray.com 1azizceylan.com 1b2bkaucuk.com 1badeks.com 1bademlergida.com 1bahcesehirbotanik.com 1BAHTIYARHALIYIKAMA.com 1balansmatik.com 1baltat.com 1barikagida.com 1bariskirtasiye.net 1barkanmuhendislik.com 1basaksistem.com 1basaktemizlik.com 1basaraniselbiseleri.com 1baseyapi.com.tr 1baskentltd.com.tr 1batupatent.com.tr 1bay-kon.com 1baydo.com.tr 1bayrakas.com 1bayrammuhendislik.com 1bebekbakimi.org 1bebekkuaforu.com 1believeacademy.com 1bell-blis.com 1benda.com.tr 1berkaygrup.com 1berktrade.com 1bernaoruc.com 1besatas.com 1besiadturkey.com 1

besok.com.tr 1bestartikel.de 1betafuar.com 1betonmaksan.com 1betultekstil.com 1beyazgrp.com 1beyondenergy.com.tr 1bgaarchitects.com 1bgmtrading.com 1biceris.com.tr 1bigbiz.com.tr 1bigdel.com 1bilalkuyumculuk.com.tr 1bilgibilisim.com.tr 1bilgili.org 1bilgipro.com 1biltekcopy.com 1bimarinsaat.com.tr 1binbirgecehome.com 1bintuinsaat.com 1bionicinc.com 1birhekimoglu.com 1birlikenerji.com 1birtik.net 1biyotip.com.tr 1bkymuhendislik.com 1blackseashipsupply.com 1blumekanik.com 1bogazliyan.bel.tr 1boskartustoner.com 1bostanoglukomur.com 1boyut-mimarlik.com.tr 1brandaci.net 1brief.com.tr 1buffnme.com 1bugratour.com 1buhlersortex.co.uk 1bulentacir.com 1bulentcalimlioglu.com 1bulutinsaatyapi.com 1burayadabak.com 1burcinkaya.av.tr 1burcsu.com.tr 1burkesmakina.com 1bursayetkinhukuk.com 1burunishoes.com 1buse-metal.com 1bykleber.com.tr 1bynnakliyat.com 1bytechboya.com.tr 1cabacilar.com 1cadirci.com 1

Page 33: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

33S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

cagmanken.com 1cakirtorna.com 1calisantur.com 1caliskansosyalhizmetler.com 1camolukhaber.com 1canak.org 1caninusdental.com 1cankaya.av.tr 1cankayaofset.com 1canlitvizle.tv 1canofset.net 1canteknoloji.com 1cantokman.com 1canyapi.net 1capoon.com 1cappafe.com 1carepark.com.tr 1carmetravel.com 1carredartistesturkey.com 1casawebtasarim.com 1casinoliman.com 1cates.gov.tr 1cayelitrans.com 1cccmturkiye.com 1cctvtamiri.com 1cebecibaca.com.tr 1celeste.com.tr 1celikev.net 1celikkardesler.com.tr 1cemgrup.net 1cemozturk.com.tr 1cemrecerceve.com 1cemresupply.com 1cemreyapiinsaat.com.tr 1cengizticaret.com.tr 1cenkalyans.com 1centralhospital.com.tr 1cerciller.com 1cesanmakina.com 1cetinelmuhendislik.com 1cetinharita.com 1cetinpansiyon.com 1cetinplastic.com 1cevrecikalem.com 1chdotomasyon.com 1chelebi.com.tr 1chellfleet.com 1chinalinetravel.com 1choccom.com 1cicekbilgisayar.com 1cigdemcinar.com 1cilingiri.com 1

cimtohumculuk.com 1ciraksan.com.tr 1circleconsultancy.com 1cityparkgrand.com.au 1cizgice.com 1cizgiyapi.com.tr 1clovamarble.com 1coco.com.tr 1cohoelectric.com 1coldgaz.com.tr 1comcity.com.tr 1copmatik.com 1cotanak.net 1craftyapi.com 1cromx.com 1crsbina.com 1cruise-club.com 1csdizayn.com 1csgurses.com 1csl.com.tr 1ct.com.tr 1cumorsan.com 1czmteknik.com 1dalinsaat.com 1damlasigorta.net 1darulerkam.org 1datanetweb.net 1datapc.net 1datcasepeti.com 1date.com.tr 1dayancsigorta.com 1debba.com.tr 1decktropic.com 1decoformmobilya.com 1degirmencioglugrup.com 1degirmeninsaat.com 1dekadanismanlik.com 1delamar.com.tr 1deltayilmaznakliyat.com 1demirbeyinsaat.com 1denizdekor.com 1denizegzost.com 1denizevim.com 1denizticaretenstitusu.com 1denkkiralama.com 1denpaglobal.com 1dentarium.com 1depetente.com.tr 1designadver.com 1designkara.com 1detaypen.com 1detayreklamcilik.com 1

Page 34: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

34S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

devran.k12.tr 1dfm.com.tr 1didas.com.tr 1didimseyahat.com 1digikon.com.tr 1dijifotolab.com 1dilaegitim.com 1dilatasyonprofilleri.com 1dilercan.com 1disten.com.tr 1dizayndecor.com 1dizivfilm.com 1dnmsigorta.com 1dogahospital.com 1dogrubilgi.com 1dogusmuhasebe.net 1dokmeoglu.com 1doktorvip.com 1donetrade.com 1dortlerlojistik.com 1doruk-makina.com.tr 1dorukhaberlesme.com 1dostboya.com 1drsdijital.com 1dumakgroup.com 1duyguvida.com 1duyuticaret.com 1ea-gs.com 1ebastir.com 1ecepak.com.tr 1ecmyland.com 1edebiyatdunyasi.com 1efeisi.com 1efeshaliyikama.com 1eforevdeneve.com 1egestore.com 1egopsikiyatri.com 1ekbicvinc.com 1ekbirholding.com 1ekgelektronik.com 1ekizlojistik.com 1ektayapi.com 1elas.com.tr 1electropark.ch 1elifinsaat.com.tr 1elitereklam.com.tr 1elsekurumsal.com 1elsis-elektrik.com.tr 1embigida.com 1emg-as.com 1emirotomotiv.org 1emiryapiinsaat.com 1

empatiinsaat.com 1emreguney.com 1emsaguvenlik.com 1enaparoto.com 1eneraconsulting.com 1eneselektrik.com 1eniskurtayyilmaz.com 1enkasigorta.com 1enkasigorta.com.tr 1eno7.org 1enopan.net 1enternetbilisim.com 1environinteriors.com 1eosharita.com 1er-kayapi.com 1er-ko.com 1erapalet.com 1eratsport.com 1erciyesambalaj.com 1erdal.com.tr 1erdalyolcu.com 1erdemhali.com 1erdogmuslar.com.tr 1erenmakine.com 1eresan.com.tr 1erkermakina.com 1eroglumetal.com 1erpaoyuncak.com.tr 1ersateknik.com.tr 1ertarman.com 1erteknikcivata.com 1erteshavalandirma.com.tr 1ervemetal.com 1ervin.com.tr 1es-kar.com 1esas-sco.com.tr 1esassco.com.tr 1eselektronik.com 1esineldiven.com 1esuaritma.com.tr 1esustrade.com 1etaservis.com 1etckalip.com 1etcyapi.com 1etkenosgb.com 1etum.com.tr 1evariyorum.com 1evizaperde.com 1expo.com.tr 1eylulkalip.com 1eynel.com 1eyupoglusmmm.com 1

Page 35: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

35S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

fabekskimya.com 1fabioricci.eu 1fagokece.com 1faktoring.com.tr 1famtouralanya.com 1farinelunion.com 1farmax.com.tr 1fatihkollektif.com 1fbsdanismanlik.com 1fctasarim.com 1femay.com.tr 1fermetal.com.tr 1ferro-steel.com 1fetihboya.com 1fibar.com.tr 1fiberkablolama.net 1fikirart.com 1fikridizayn.com 1firatelektrik.com.tr 1floratekstil.com 1forkliftsatis.com 1forshotel.com 1fosforix.com 1fox-body.com 1fps.ee 1fullcirclefeedback.com.au 1furkanpen.com.tr 1gaiamimarlik.com 1gaiayapi.com 1gamayapim.com 1garfi.net 1gayaltd.com 1gayaltd.com.tr 1gaziantepdekor27.com 1gecermobilya.com 1gediz.com.tr 1gelatomagazin.com 1gencayakkabi.com 1gencbilgisayar.com.tr 1genclermuhendislik.net 1gencraf.com.tr 1genesisbiomedical.com 1genpasan.com 1gerkap.com.tr 1gfsturkiye.com 1girtasinsaat.com 1gitex.com.tr 1globaldanismanlik.net 1gmail.com 1gmateam.com 1gmgdisticaret.com 1gokhanege.com 1

goktepebilisim.com 1goktugreklam.com 1gokturkler.net 1goldeyestheme.com 1golyazinakliyat.com 1google.com 1gorkempoli.com 1gozeymakina.com 1grafikkent.com 1grandoriatours.com 1granitinsaat.com 1granitsitesi.com 1grenstudio.com 1groosy.com 1guclumatbaa.com 1guldemkimya.com 1gulkurusu.net 1gulnayin.com 1gulsigorta.net 1gultasinsaat.com 1gultekinturizm.com 1gumdas.com 1gumusemlakinsaat.com 1gumusforklift.com 1gumushanevi.com 1gunay.info 1gunaygumrukleme.com 1gundogdular.com.tr 1gundoviz.com 1gunduzofset.com 1gunesfidancilik.com.tr 1guneysu.net 1guneytip.com 1gurayturizm.com 1gurermatbaa.com 1gurparoto.com 1gurtug.com.tr 1guvenagac.com 1guvenishidrolik.com.tr 1guvercinevi.net 1guvercinlerimiz.com 1halkpen.com 1hammaksan.com 1hamret.net 1haratpen.com 1hasankaradeniz.av.tr 1hasesanticaret.com 1hasimoglunakliyat.com 1haticeunal.com 1hatirkahvesi.org 1hattatselim.com 1hazelgida.com 1

Page 36: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

36S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

hazyapi.com 1hg-grup.com.tr 1HILALYEMEK.com 1hititmedya.com.tr 1hizaaksesuar.com 1host-ota.com 1houdiard.com 1humraltan.com 1hunkar1950.com 1hursankalip.com 1huseyinsahin.com.tr 1ibcg-turkey.com 1iconyapi.com 1icywave.com 1idealsan.com.tr 1idilmuhendislik.com 1idsnet.com.au 1ifc.com.tr 1ifturkmen.com 1ijmgroup.com.au 1ilayderi.com 1iler.com.tr 1ilkumut.biz 1iloglu.com 1imecoglobal.com 1imesgroup.nl 1inanceyuboglu.com 1inanoglu.com 1inanotomasyon.com 1inceeleyen.com 1incias.com 1indaproje.com 1info-protech.com 1inmola.com 1innoactive.com.tr 1innsbrucktaxi.com 1insabilgisayar.com 1interyat.com 1invitek.com.tr 1ipekmatbaa.com 1ira.com.tr 1iremkimya.com.tr 1irmak.org 1iseltekstil.com 1isikcarsi.com 1isiksaglik.com 1isimtescil.com 1isimtescil.net 1isininsaat.com 1isinneon.com 1isportfoy.com 1istanbulagro.com 1

istanbuldinamik.com 1istanbulruhsagligi.com 1istanbulsporenvanteri.com 1istanbulteknikmakina.com 1istanbulucuzlukpazari.com.tr 1istanbulutinsaat.com.tr 1istanbulwebajans.com 1istifyapi.com.tr 1istmall.com.tr 1itcoglobal.com 1iteksan.com.tr 1itfaiyeokulu.com 1ivedi.com.tr 1iveditranslation.com 1ivmebilisim.com 1iyibirorganizasyon.com 1iyidenkgeldi.com 1izciler.com.tr 1izkoninsaat.com 1izmirpsikolog.net 1izolbant.com 1jammer.gen.tr 1joylife.com.tr 1kaan-mobilya.com 1kabataslilar.org.tr 1kackaripastanesi.com 1kadilarplastik.com 1kadner.net 1kalafat.com.tr 1kaleelektronik.org 1kalelilojistik.com 1kaliteraosgb.com 1kalkan-kalkan.com 1kalkavangrup.com 1kaltem.com.tr 1kanalg.tv 1kandemirkopyalama.com 1karacabobinaj.com 1karadagyapi.com 1karakaspetrol.com.tr 1karakasturizm.com 1karaot.com 1karbir.com.tr 1kardeslertelorme.com 1karebigbag.com 1karinaenerji.com 1karmamakina.com 1karostur.com 1kassajans.com 1kavrayis.com 1kayatarim.com 1kayhanipek.com 1

Page 37: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

37S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

kaymazlar.com.tr 1kaysticaret.com 1kayzennkayis.com 1kazancimining.com 1kebankasap.com 1kemerenduro.com 1kencolor.com 1kentbis.com 1kentyapidenetim.com 1kevsermodaevi.com 1khazirgroup.com 1kibristransfer.com 1kidabilgisayar.com.tr 1kimteks.org 1kirgaz.com.tr 1kls.com.tr 1kmkotomotiv.com 1kobidanisma.com 1kocflota.com 1koksallarhidrolik.com 1koksallarmobilya.net 1kolektivplan.com 1kolikoli.com 1komesanplastik.com 1komurcuoglugroup.com 1kopitoebruk.com 1korkutlaryatmobilya.com 1koseogullari.com.tr 1kreateks.com 1kremgrup.com 1kromer-tr.com 1kromtes.com 1kucukdahiler.com 1kucuklaw.com 1kulvaryapi.com.tr 1kureselanahaber.com 1kursathoca.com 1kusinsaat.com 1kutluyapi.biz 1kuyrukcuoglu.com 1kuzeybalik.com 1kyp.com.tr 1kytekstil.com 1laperryhome.com 1laser-t.com 1laserbilgisayar.com 1lazca.org 1lbdmuhendislik.com 1legobebe.com 1letoonhospital.com.tr 1lettime.com 1libergraphic.com 1

libracem.com 1liderotobus.com 1linsisotomasyon.com 1livahali.com 1livamedikal.com 1lochlaggan.com 1logogrup.com 1logosdanismanlik.com 1longabilisim.com 1longlineus.com 1lotus7.club 1lotussea.com 1lous-stuff.com 1lsmimarlik.com.tr 1lundqvistpehrsson.com 1luvisaglik.com 1lynecotedesigner.com 1m-arslan.com 1magnamech.com 1magnesiaweb.com 1mahirates.com 1mail.cliltd.co.uk 1maksimize.net 1malatyasafakofset.com 1malimusaviriniz.net 1marasanahtarci.com 1marble.com.tr 1marka-reklam.net 1MARKAGARANTI.com 1markakids.com 1markizethotel.com 1marmarameslekkursu.com 1marmiad.org 1martasnakliyat.com 1martsigorta.com 1masalkonagianaokulu.com 1masdisticaret.com 1masisan.com 1masterbt.com 1matbaamarket.net 1mateks-tr.com 1matelektronik.com 1matesmekanik.com.tr 1matexgiyim.com 1mattdean.net 1maviaybodrum.com 1mavidussanat.com 1mavitextile.com 1maxtekno.com 1maysu.com.tr 1mckurt.com 1medhan.com 1

Page 38: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

38S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

medikalstore.com 1medine.net 1mediporortopedi.com 1medlabor.com.tr 1medpolco.com.au 1medyayesilmavi.com 1megaas.com.tr 1megafuarhizmetleri.com 1megakalip.com 1megamarine.com.tr 1megasulama.com 1meggsbodrum.com 1mehmetgumus.com 1mehmetvolkanaksoy.com 1mellisheye.com 1menzara.com 1meraksitesi.com 1meraninsaat.net 1merkezegitimkurumlari.com 1merkezseramik.com 1mertartarim.com 1mertkavi.com 1metrapol.com 1mevcert.com.tr 1mevsimtekstil.com 1mikbal.com 1mikronommaster.com 1mikrosan.com 1mikroticaret.com 1mimagenerji.com 1missronn.com 1mj-support.com 1mobiltreyler.com 1mobosel.com 1modasahra.com 1modernist.com.tr 1molarestaurant.com 1mondialcrepis.com 1morcilek.net 1motiftekstil.com 1mseyapi.com 1mskinsaat.com.tr 1mtechbilisim.com 1mujdatozkan.com 1mukatek.com 1multimed.com.tr 1multimedyateknoloji.com 1murtazaoglu.com 1musaoglu.com 1mutluotomasyon.net 1mwvaudit.com.au 1mymoonkaraokebar.com 1

myseaturkey.com 1nadirinsaat.com.tr 1nak-kargo.com 1naqui.co.uk 1narcicegikosku.com 1nbsbilisim.com.tr 1ndh.gov.tr 1nedretdemir.com 1nesilbilgisayar.com 1netcraft.co.za 1netmakina.com.tr 1netserv.net 1nettalya.com.tr 1nettrade.biz 1nevzatraf.com 1newgoldkuy.com 1newstour.com.tr 1ngnturk.com 1nichegenerics.co.uk 1nickservice.com 1nikahsekeri.org 1niramakine.com 1nls.hu 1nordic.com.tr 1nostaljiburada.com 1noteks.com.tr 1novacasa.com.tr 1ntakip.com 1ntgroup.org 1nurcollection.net 1objekta-immobilien.de 1odakkirtasiye.com 1office-inn.com 1ofissanmobilya.com.tr 1oguncelik.com 1okeanos.com.tr 1olcummarket.com 1omoistanbul.org.tr 1onedautoparts.com 1onlinedergi.net 1onlinedestek.com 1onureltelekom.com 1onurexpress.com 1oreo.com.tr 1orgamed.web.tr 1organikdizayn.com 1organiktasarim.com 1organizedergi.com 1orhanmarble.com 1osd.com.tr 1osem.com.tr 1otantikbutik.com 1

Page 39: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

39S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

otelekipmanlari.com 1otovinn.com 1oturoyna.com 1outdooracademy.org 1ovo.com.tr 1oyacetinkaya.com 1oz-kaetiket.com 1ozalpgroup.net 1ozanil.com 1ozbek.com.tr 1ozdemirorme.com 1ozdemirtasimacilik.com 1ozdikmen.com 1ozelatolye.com 1ozelipekyoluhastanesi.com 1ozelithalat.com 1ozgugumruk.com 1ozgunpano.com 1ozgurkayaa.com 1ozkannakliyat.org 1ozman.biz 1ozmenkids.com 1ozsahinambalaj.com 1ozsimseklertasimacilik.com 1ozsis.com.tr 1oztanelektrik.com 1oztaslar.com.tr 1ozturkahsapsandik.com 1ozturkparke.com 1ozturkpc.com 1panelvankiralama.net 1panoto.com 1parkaden.com.tr 1parkwestgc.com 1pasalikilit.com 1paslanmazelek.com 1patentmuhendisi.com 1patrad.com 1pbahukuk.com 1pecadosweb.com 1pehlivanltd.com 1pekinyumurta.com.tr 1pencereburada.com 1perga.com.tr 1petrolgazetesi.com 1petrolguney.com 1phibio.de 1pimsam.com 1pinarbasimatbaacilik.com 1pinarkaya.com.tr 1pinartuncer.com 1piramitajans.com 1

piramitgrup.com.tr 1plastpark.com 1pointproduction.org 1postofficeistanbul.com 1poyrazdisticaret.com 1poyri.com 1pozitifmuhasebe.com 1pratikutu.com 1premiershipping.ru 1prizmabilgisayar.net 1proborsa.com 1prodactr.com 1prodijidizayn.com 1protekpompa.com 1prusasanat.com 1publicasid.com 1purbeckpeloton.co.uk 1pymtur.com 1queensgarden.net 1quieto.org 1racingedge.biz 1rahmiyilmaz.com.tr 1ramoy.com 1rcquality.com 1referansyonetim.com.tr 1regagroup.com 1rejuviturkiye.com 1reklamexpres.com 1remax-extra.com 1remax-win-ist.com 1remax-yenicem-ist.com 1remzitekeli.com.tr 1renkgroup.co 1renkgroupltd.com 1renkneon.com 1renlazer.com 1resatguner.com 1restorandestek.com 1rezonehotel.com 1rifatturgut.com.tr 1rigostone.com 1riskisosgb.com 1riteks.com.tr 1rixu.fi 1rmenetworks.com 1robincook.com.tr 1rokmakina.com 1rollermakine.com 1rosemfm.net 1roxy-world.ro 1royaltowersresort.com 1sabunbazlari.com 1

Page 40: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

40S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

safirmakina.com 1sahibindendorse.com 1sahinguvenlik.com.tr 1sahinturk.net 1sahrasoft.com 1sahseramik.com.tr 1salihbebe.com 1salihlimedikal.net 1salihmobilya.info 1salsanaluminyum.com 1saltaselektrik.com 1samcom.com.tr 1samsunelektronik.com 1samsungundem.com 1sanalpsikolog.net 1sanatpasta.com 1sandalyebursa.com 1sanliurfaotokurtarma.com 1sapkasapka.com 1saricammakina.com 1sarikayaboya.com 1sarpistanbulosgb.com 1sarpmar.com 1sartour.com 1savanatur.com 1savantconsulting.co.za 1savatek.com 1savra.com.tr 1say-med.com 1schlussel-pvc.com 1schreiner-rabe.de 1sdfmobilya.com 1sdnet.se 1seastarotel.com 1seckinbalikcilik.com 1seckinutu.com 1sedareklam.com 1sehaenerji.com.tr 1selbim.com 1selcukluekk.com 1selgrup.com 1selimoglunakliyat.com 1selpaltd.com 1semasemazen.com 1semiramis2.com.tr 1semyacht.com 1senolnakliyat.com 1seramarket.com 1serda.com.tr 1serdardegerli.com 1serefsanlioglu.com 1serinsogutma.com 1

seriotek.com 1serkanacar.org 1serkantunali.com 1sertcivata.com 1serva.com.tr 1servoapp.com 1severoglugrup.com 1sevgiliyehediye1.com 1sevvalinsaat.com.tr 1seyhantip.com 1sezgold.com 1sezigayrimenkul.com 1sgiunderwear.com 1sgldizayn.net 1siberplastik.com 1siglanlar.com.tr 1sigmatmtr.com 1sigortaniyaptir.com 1SIGORTAPOL.com 1silivriosgb.com 1simesgrup.com 1simsekotomotiv.com.tr 1sindoma.com.tr 1sinerjigida.com 1sinuselektronik.net 1sirinakbulut.com 1sistembir.com 1sivriogluinsaat.com 1sixbynine.no 1SIZCEREKLAM.com 1smarkbil.com 1smdtek.com.tr 1sonexson.com 1sonsuzdtm.com 1sonsuzyapi.com 1sorurobotu.com 1SOSYALMATIK.com 1soylu-makina.com 1standsal.com 1starbaca.com 1starkturizm.com 1station31.org 1stepinsaat.com 1stigmaent.com 1stkimya.com.tr 1studyin-uk.com.tr 1suatkirlic.com.tr 1suffamimarlik.com 1sukruuguz.com 1sumermatbaasi.com 1sunpointhotel.com 1systemscpa.com 1

Page 41: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

41S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

taisad.org.tr 1taksibul.com.tr 1taksicenter.com 1taksiduraklari.net 1talentrich.org 1talyamed.com 1talyapak.com 1tanmusavirlik.com 1taotekstil.com 1TAPAMARKET.com 1tapasan.com 1tasdemirlerun.com.tr 1tashavlu.com 1taskinlaryikama.com 1tassigorta.com 1tataroglu.com 1tavalabs.com 1taymarble.com 1tcs.com.tr 1teamsrl.net 1tebim.com.tr 1tekinalpgroup.com 1tekisogluhurda.com 1teklas.com.tr 1teknik-bilgisayar.com 1teknikaaluminyum.com 1teknikbilisim.net 1teknikgranit.com 1teknikhaberler.com 1teknikyapiboya.com 1teknikyatirim.com 1teknolociks.com.tr 1teknopoll.net 1tektas.biz 1tekurunsatissitesi.net 1telciugur.com 1temelinsaat.com 1temoteks.com 1tenkametal.com 1teperaf.com 1tepetemizlik.com 1terakkiyapi.com 1tesisatkontrolu.com 1teslamuhendislik.net 1tessantestere.com 1tetraboya.com 1theiselaw.com 1thelingfamily.us 1timvanderveenlaw.com 1tinkdavet.com 1tirser.com 1tmoda.com.tr 1

tmpromosyon.com 1tmsvinc.com 1topdemir.com.tr 1topraktrading.com 1tpne.nl 1tr-kardelen.com 1transmarin.com.tr 1trikomaks.com.tr 1tsmmadencilik.com 1tspik.com 1ttvinc.com 1tugceinsaat.net 1turkcan.info 1TURKIYEICINHIZMET.com 1turksal.com 1turksoil.com 1turkuazmarine.com 1turkuazorganizasyon.com 1tursanseramik.com 1ucarsoy.com 1ucelcopy.com 1uclerltd.com.tr 1ucuzlook.com 1ufcotomotive.com 1ulkugulu.com 1ulusalfair.com 1ulusallojistik.com 1ulusalsavunma.com 1umurkaya.com 1umutmobilya.com.tr 1umutmurare.com.tr 1unallarisi.com 1unallojistik.com 1uncuogluyapi.com 1unfatesisat.com 1uniquesourcing.com 1upgradetourism.com 1urgenler.com.tr 1usakarttv.com 1usertrust.com 1uskudardoviz.com 1ustamteknik.com 1uyaryapi.com 1uygunofset.com 1uykumedikal.com 1uykutan.com 1uysalambalaj.com 1uzay.web.tr 1uzaypc.com 1vangolumotorluaraclar.com 1vanwebtasarim.com 1vatannakliyat.com 1

Page 42: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

42S P E C I A L R E P O R T

THREAT RESEARCH LABS

Domain Sum - Count Of Emails Domain Sum - Count

Of Emails

vbs-trading.com 1velinda.com.tr 1velinda.net 1venusreklamcilik.com 1versanboya.net 1VESTELSERVISIGEBZE.com 1viagreen.com.tr 1villadanlin.com 1vinola.com.tr 1visco.com.tr 1vk2001.com 1vmarine.net 1volber.com.tr 1volkanozkoc.com 1vuralelektrik.com 1waaland.com 1walkstage.com 1wareklam.com 1webledim.com 1weldergrup.com 1wentual.com 1witsendcc.com 1wovenhistory.com 1x5.tC 1xyajans.com 1yaglidere.bel.tr 1yagmurorman.com 1

yakutray.com 1yamanlarotel.com 1yanginguvenligi.com 1yapimmimarlik.com.tr 1yaprakpsikoloji.com 1yasarsark.com 1yazmiyor.com 1yetersizbellek.com 1yigitgida.com.tr 1yildizelektrikguvenlik.com 1yildizkovan.com.tr 1yildizlarprefabrik.com 1yilmazpetrol.net 1yoltay.com 1yortan.com.tr 1yorukfm.com 1yucedanismanlik.com 1yukselgumrukleme.com 1yukseluzhan.com 1zakgrup.com 1zegangrup.com 1zemakcelik.com 1zerteks.com 1zeybeklaw.com 1zlmproduction.com 1znskimya.com 1zulalelektrik.com 1

Total Result 54,205

Page 43: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

43S P E C I A L R E P O R T

THREAT RESEARCH LABS

Appendix B: “FACTURE” Attack

Country Sum - Count Of Emails

IN 2,101 VN 1,523 TR 214 ID 205 KE 170 PK 149 MX 118 BD 105 TH 70 BR 69 ZW 58 CI 54 IR 52 PH 51 KH 48 IT 45 RO 40 TZ 36 IL 34 ZA 29 VE 28 RS 27 EC 26 LA 24 N/L* 24 MM 23 MK 22 NG 21 PL 20 ES 15 SA 15 JO 14 CO 13 MA 13 BO 12 AL 11 AO 9

Country Sum - Count Of Emails

BG 9 CY 9 MG 9 CM 8 DZ 8 US 8 EG 7 MN 7 AM 6 BA 6 DO 6 BT 5 GR 5 MD 5 MH 5 NA 5 AR 4 FR 4 GH 4 MV 4 UA 4 DE 3 GM 3 IE 3 LY 3 MY 3 MZ 3 NP 3 RW 3 UG 3 AU 2 CL 2 MU 2 CD 1 PS 1 PY 1 SG 1

Total Result 5,653

Page 44: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

44S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

Vietnam Posts and Telecommunications(VNPT) 1,027Airtel Broadband 691VDC 260Bharti Airtel 191Asianet 153TATA Communications 116Syscon Infoway Pvt. 112CMC Telecom Infrastructure Company 86No Range Owner 86Tellcom Iletisim Hizmetleri A.s. 80Mahanagar Telephone Nigam Ltd. 71In2cable.com (India) 63Tata Teleservices ISP 63Viettel Corporation 57FPT Telecom Company 55Turk Telekom 54Cote d’Ivoire Telecom 53ACCESSKENYA GROUP LTD is an ISP serving 50Bharti Broadband 43D-Vois Broadband Pvt 43ONECOM 42True Internet 41Tata Teleservices Maharashtra Ltd 37Kenyan Post & Telecommunications Company / Telkom 36FASTNET 34Southern Online Bio Technologies Ltd 33D-VoiS Broadband Private Limited 30Wan & Lan Internet Pvt 30Telone 29Meghbela Broadband 27MPLS ADSL Broadband 27Philippine Long Distance Telephone 27CANTV 26Broadband ISP, FTTH and Cable Service Provider 25Serviciul de Telecomunicatii Speciale 25SINET, Cambodia’s specialist Internet and Telecom 24Unitel 24National Telecommunication Corporation HQ 23Telecom Italia 23Safaricom 22Wateen Telecom 22Airtel 20Reliance Communications 19Sify Limited 19Vasai Cable Pvt. Ltd. 19Iusacell 18Mega Cable, S.A. de C.V. 18PERN AS Content Servie Provider, Islamabad, Pakist 18KNK Telekomunikasyon Iletisim Elektrik Sanayi Tica 17Neda Gostar Saba Data Transfer Company Private Joi 17Dishnet Wireless Limited 16PT Indosat Tbk. 16Axtel 15

PT Telkom Indonesia 15RailTel Corporation of India Ltd. 153BB Broadband 14Blizoo DOOEL Skopje 14Eastern Telecoms Phils., Inc. 14Hireach Broadband Private Ltd 14Intech Online Private Limited 14Alestra, S. de R.L. de C.V. 13Bezeq International 13BSNL 13Cogetel Online 13Aria Shatel Company Ltd 12Cablemas Telecomunicaciones SA de CV 12Mexico Red de Telecomunicaciones, S. de R.L. de C. 12PT Tele Globe Global 12SOL-Customer-MIX 12Tanzania Telecommunications 12Telmex 12012 Smile Communications 11Aamra Networks Limited 11AUGERE-Pakistan 11BDCOM Online Limited 11Bharti Telesonic 11Delta Infocom Limited 11Ebone Network (PVT.) Limited 11Internet Service Provider 11Kappa Internet Services Private Limited 11Pt. Matrixnet Global Indonesia 11RCS & RDS 11TurkNet Iletisim Hizmetleri A.S 11UNE 11Bharti Airtel Ltd., Telemedia Services 10Broadband Pacenet Pvt. 10ETAPA EP 10Fastweb 10LINKdotNET Telecom Limited 10MTN Nigeria 10Orion Telekom Tim Ip Network In Pancevo 10Pt Bina Informatika Solusi 10Spice-net-tz 10Afrihost 9Angel Drops Ltd 9Bittel Telecom Pvt Ltd 9Blizoo Media and Broadband 9Chi nhanh MienBac-Cong ty CP Ha Tang Vien Thong CM 9Comilla Online 9CONECEL 9Cyprus Telecommuncations Authority 9Dai IP tinh cho khach hang xDSL 9LINKNET 9MNC Playmedia 9Neuviz Net 9SAGLAYICI Teknoloji Bilisim Yayincilik Hiz. Ticare 9

Page 45: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

45S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

SONIC-Wireless 9Telecomunicacoes Ltda 9X-Link Limited 9Bayanat NOC IP range 8Delhi Gsm Ip Pool 8Primesoftex 8PT. Arsen Kusuma Indonesia 8Smart Link Communication 8Tata Mobile 8Teknotel Telekomunikasyon Sanayi Ve Ticaret A.s. 8Thirumala Tripleplay Network 8TVCabo Angola 8United States Air Force 8Vivo 8Digital Network Associates Private Limited 7Dishnet Wireless Limited. Broadband Wireless 7Fixed IP for cable modem customers 7Honesty Net Solution (I) Pvt 7Hosting Internet Hizmetleri Sanayi ve Ticaret Anon 7INEA Network 7Jazz Telecom S.A. 7Maroc Telecom 7Meghbela Skywave Cablenet Private Limited 7Mizanur Rahman t/a SAM ONLINE 7Mobily 7Multinet Pakistan Pvt. Ltd. 7Mundivox LTDA 7Pars Online PJS 7PT Media Sarana Data 7S.I Group 7salt Lake,Sector-V,Electronic Complex 7Simbanet-as 7TE Data 7Three Indonesia 7VietNam Telecom National 7Allocated to Broad band internet in the following 6Cotas Ltda. 6CS LoxInfo 6europroNET Bosnia d.o.o. 6Inwi Mobile 6KSC Commercial Internet Co. Ltd. 6Linkdotnet-Jordan 6Orange Madagascar 6PT. Eka Mas Republik 6Rasana Pishtaz Network 6Serbia BroadBand-Srpske Kablovske mreze d.o.o. 6SHATEL DSL Network 6Siticable Network Limited 6Telefonica Celular de Bolivia S.A. 6TRD ROBI DOOEL 6TRIPLEPLAY INTERACTIVE NETWORK PVT LTD 6Ucom LLC 6ABCom Internet Services Network 5

Apollo Online Services Pvt ltd 5Arieluniversity 5Augere Wireless Broadband Bangladesh Limited 5Axtel - Recursos WiMAX 5bmc do brasil comercio de eletronicos ltda 5candor infosolution Pvt Ltd 5Chanakya BNR Hotel-TATANAGAR 5Claro Dominican Republic 5DrukNet ISP 5Globalwave Telecom 5Hathway 5Horyzont Technologie Internetowe sp.z.o.o. 5HOTnet 5HTT Telecom S.A 5Mobilink Mobile Internet 5Pacenet Meghbela Broadband Pvt. 5Perfect Internet Pvt Ltd 5Pt Indonesia Comnets Plus 5PT. Cyberindo Aditama 5PT. Dutakom Wibawa Putra 5Sampark Estates Pvt. Ltd. 5Sikka Broadband Pvt. 5SingNet Pte Ltd 5Starnet S.r.l 5Telecom Namibia 5Tiscalinet 5Transtelco S.A. 5Transworld Associates (Pvt.) Ltd. 5YOU Broadband & Cable India Ltd. 5Autonomous System Number for Nexlinx 4BT Italia S.p.A. 4Comcast Business Communications 4delDSL Internet Pvt. Ltd. 4Dhivehi Raajjeyge Gulhun (Dhiraagu) 4Ensync Business Solutions PTY(LTD) 4Global Village Telecom 4Golden Telecom LLC 4Gurunanak Institute for technology, Panihati, Kolk 4Interdomain Routing 4Invest-Inzenjering DOO 4Jawa Pos National Network Medialink, Pt 4Jordan Tv Cable & Internet Services Co 4Kuresel Beta Teknoloji Telekomunikasyon Sanayi Tic 4Media Antar Nusa PT. 4Milleni.com 4Neamul Haque Khan t/a Mazeda Networks Limited 4Netnam Company 4Norfolk Hotel 4Operbes, S.A. de C.V. 4OVH Telecom 4Puntonet S.A. 4Radore Veri Merkezi Hizmetleri A.S. 4Railtelibwcustomers 4

Page 46: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

46S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

River City Internet Group (Primary Networks) 4Sikka Cable 4STLGHANA 4TeleCable 4Tellas S.A. 4Umniah Mobile Company 4University Pop 4Univision 4VDT Communications Limited 4Vodacom 4Wsp Servicos de Telecomunicacoes Ltda 44ALB shpk 3A Multihomed ISP Company 3ADA Holding - ADA AIR sh.p.k. 3ADN Telecom Ltd 3Axiom Networks Ltd 3Bangladesh Online Ltd 3Bharti Airtel Ltd., TELEMEDIA Services, for SMB cu 3Cablemas Telecomunicaciones (merida) 3Citinet LLC 3CMPak Limited 3Cyfrowy Polsat MVNO mobile broadband services 3Deutsche Telekom AG 3EARTH TELECOMMUNICATION (Pvt) 3Infogenie-as 3IP Core MPLS 3JPR Digital 3Konya Organize Sanayi 3Libyan Telecom and Technology 3moztel-as 3Nepal Telecom 3NETLIFE 3Oi Internet 3Oi Velox 3Orange Polska 3PT Comtronics Systems 3PT Graha Sarana Data 3PT Solnet Indonesia 3PT. Net2Cyber Indonesia 3Pulse Telesystems Pvt Ltd 3Quadrant Televentures Limited 3Quantum Net Co Ltd 3RCS & RDS Business 3TGN 3TM Net 3Tripleplay Broadband Pvt Ltd 3UPC Ireland 3Vietnam Posts and Telecommunications (VNPT) 3Vodafone India 3Vodafone Ono 3Vung dia chi IP cap cho dich vu IPTV tai Ha Noi 3Welcome Italia S.p.A 3xDSL Services of HaNoi 3

Aamra technologies limited 2Africell Uganda Ltd 2Bayan Telecommunications Inc. 2Bol-co-tz-as 2BRAC BDMail Network 2Cablevision 2Centennial Cayman Corp Chile S.A 2Corporacion Digitel C.A. 2Corporacion Politecnica Nacional De Colombia 2DCTV Cable Network Broadband Services 2Home Systems Pvt.ltd 2IDS Bangladesh. IP Transit provider. Dhaka, Bangla 2Indusind Media and Communications Ltd. 2Infocom-ug 2Informatica E Servicos Ltda 2Internet Solutions 2IPNXng 2Ixsforall, Inc. 2L E M Telecomunicacpes Ltda -me 2Mahbub Alam T/A CIRCLE NETWORK 2MAINONE 2Maximum Business Information Technology 2NTT Communication (Thailand) Co.,LTD. 2Pardis Ettela Resaan Sepehr 2Tecnowireless Telecom Ltda 2Tehran Kar Ara 2Telecentro S.A. - Clientes Residenciales 2TM International Bangladesh 2TPG Internet 2Triple Play Broadband Private Limited 2TTCLDATA 2Vivacom 221 st Century Technologies Limited 1Bcl South 1Beam Telecom 1Bharti Cellular Ltd. Mumbai 1Brasileira De Telecomunicacoes Sa-embratel 1Cablevision, S.A. de C.V. 1Call U Communications Ltd. 1Co.pa.co. 1Comunicacao Virtual Ltda 1CTBC 1F.H.U. COMP-SERWIS Radoslaw Bilski 1Five network Broadband Solution Pvt Ltd 1hellas online Electronic Communications S.A. 1Hostlocation Ltda 1HYPERIA Ltd 1Internet Access & Telecom Carrier Service Provider 1ipNX NIGERIA LIMITED 1Massachusetts Institute of Technology 1Ministry of Finance 1MyRepublic Ltd (Singapore) 1National Information Technology Authority Uganda 1

Page 47: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

47S P E C I A L R E P O R T

THREAT RESEARCH LABS

Range Owner Sum - Count Of Emails Range Owner Sum - Count

Of Emails

Neostrada Plus 1Netdirekt A.S. 1Nettlinx Limited 1Oasis-sprl 1Operateur Mobile en Cote d’Ivoire Telecom 1Orange Espana 1PADINET - Padi Internet 1Paratus-Telecom 1Pipol Broadband and 1Provedor De Acesso A Internet Ltda 1PT Naraya Telematika 1PT. First Media, Tbk 1PT. First Media, Tbk. 1Rajesh Patel Net Services Pvt. 1Satellite Connection 1

Servicos De Telecomunicacoes Ltda 1SevenStar Broadband 1SRMS College 1Sspnet Com De Equip. De Tele Informatica 1Tata Indicom 1Telecable Central, S.A. 1Telkom Internet 1Tim Celular S.A. 1UPC Romania SRL 1Varnion Technology Semesta, PT 1Via Cast Solucoes em Telecomunicacoes Ltda 1Wananchi-ke 1ZOL GPON Home Users 1ZOL Zimbabwe Assignments 1

Total Result 5,653

Domain Sum - Count Of Emails

laposte.net 5,653

Total Result 5,653

Page 48: Comodo Threat Intelligence Lab · The Comodo Threat Intelligence Lab team was able to quickly verify the two new ... (VNPT) 11,551 Airtel Broadband 33,02 VDC 2,946 Turk Telekom 2,795

Comodo_LockyRansomwareReport_PartII_082917

About Comodo The Comodo organization is a global innovator of cybersecurity solutions, protecting critical information across the digital landscape. Building on its unique position as the world’s largest certificate authority, Comodo authenticates, validates and secures networks and infrastructures from individuals to mid-sized companies to the world’s largest enterprises. Comodo provides complete end-to-end security solutions across the boundary, internal network and endpoint with innovative technologies solving the most advanced malware threats, both known and unknown. With global headquarters in Clifton, New Jersey, and branch offices in Silicon Valley, Comodo has international offices in China, India, the Philippines, Romania, Turkey, Ukraine and the United Kingdom. For more information, visit comodo.com.

Comodo and the Comodo brand are trademarks of the Comodo Group Inc. or its affiliates in the U.S. and other countries. Other names may be trademarks of their respective owners. The current list of Comodo trademarks and patents is available at comodo.com/repository.

Keep up to date with the Latest Comodo News: Blog: https://blog.comodo.com/ Twitter: @ComodoNews LinkedIn: https://www.linkedin.com/company/comodo

About The Comodo Threat Intelligence Lab The Comodo Threat Intelligence Lab (the Lab) monitors, filters and contains, and analyzes malware, ransomware, viruses and other “unknown” potentially dangerous files 24x7x365 in over 190 countries around the world. With 5 offices spread across the Americas, Asia and Europe (and staff covering over 190 countries), the Lab is made up of more than 120 IT security professionals, ethical hackers, computer scientists and engineers (all full-time Comodo Lab employees) analyzing millions of potential pieces of malware, phishing, spam or other malicious/unwanted files and emails every day. The Lab also works with trusted partners in academia, government and industry to gain additional insights into known and potential threats.

The Lab is a key part of the Comodo Threat Research Labs (CTRL), whose mission is to use the best combination of cybersecurity technology and innovations, machine learning-powered analytics, artificial intelligence and human experts and insights to secure and protect Comodo customers, business and public sector partners and the public community.

Comodo Group, Inc. | 1255 Broad Street, Clifton, NJ 07013 US Tel: +1 (888) 266-6361 | Tel: +1 (703) 581-6361 | Fax: +1 (973) 777-4394

48

THREAT RESEARCH LABS

S P E C I A L R E P O R T