malavasso.com
migraviro.com
montenegrorio.com
The payload is the Sinowal trojan. Malicious software is hosted on 95.64.45.43 which is well-known very dark grey hat host Netserv Consult SRL of Romania. Blocking 95.64.0.0/17 (95.64.0.0 - 95.64.127.255) will probably do no harm.
The (possibly fake) registrant for these domains is:
Registrant Contact: Xicheng Co. Zhong Si Zhongguancun@yahoo.com 01066569215 fax: 01066549216 Huixindongjie 15 2 Beijing Chaoyang 101402 cn Administrative Contact: Zhong Si Zhongguancun@yahoo.com 01066569215 fax: 01066549216 Huixindongjie 15 2 Beijing Chaoyang 101402 cn Technical Contact: Zhong Si Zhongguancun@yahoo.com 01066569215 fax: 01066549216 Huixindongjie 15 2 Beijing Chaoyang 101402 cn Billing Contact: Zhong Si Zhongguancun@yahoo.com 01066569215 fax: 01066549216 Huixindongjie 15 2 Beijing Chaoyang 101402 cn