MalwareMustDie, NPO, during its research activities, is following the process of suspension malware bad domains as important milestones in malware fighting steps. The Kelihos Trojan were distributed in (mainly) East European (Ukrainian, Latvia, Belarus, Russia) and Asia servers (Japan, Korea, Taiwan and Hongkong) as the secondary layers, with also using the scattered world wide hacked machines. The usage of the DGA-like randomisation for the domain used for the payload is the MO of this distribution.”]
Source: https://blog.malwaremustdie.org/2013/07/suspension-announcement-of-97-ru.html

