this Teslacrypt attack, sharing infrastructure with some of the malicious domains in question. In addition to Teslacrypt, some of these are connected with PoSeidon, Pony and Gozi malware.
The analysis [csv] includes SURBL and Google ratings, ISP information and a recommended blocklist.
Partly or wholly malicious IPs:
220.127.116.11/26 (Duomenu Centras, UA)
18.104.22.168/24 (JSC Server, RU)
22.214.171.124/27 (New Wave NetConnect, US)
126.96.36.199/27 (Net3 Inc, US)
188.8.131.52/30 (OVH / Dmitry Shestakov, BZ)
184.108.40.206/20 (PE Ivanov Vitaliy Sergeevich, UA)
220.127.116.11 (Fornex Hosting, NL)
18.104.22.168/28 (CloudSol LLC, Russia)
I've blocked traffic to 22.214.171.124/20 for two years with no ill-effects, it seems to be a particularly bad network. There may be a few legitimate sites hosted in these ranges, they would mostly be Russian.. so if you don't usually visit Russian websites then the collateral damage might be acceptable.