Thanks to an Independant researcher from Russia who shared some referer driving to an Exploit Kit on tcp 27005, I was able to meet again the "Unknow EK" that was first spotted by EKWatcher in September 2013.
more here.............http://malware.dontneedcoffee.com/2014/06/cottoncastle.html
more here.............http://malware.dontneedcoffee.com/2014/06/cottoncastle.html