The IRVL group seems to think that they will go undetected longer by creating a bunch of new domains over the weekend. Pft! They should know by now that we don’t sleep over here.

The files currently being distributed have been passed around quite a bit and I expect for the binaries to be changed within the next few days. One of the new domains (hxxp://antivirused.com) already has an updated file (DEFB61DF4D6A187038FC3725EB431FAB) with only a 5/36 detection ratio at VirusTotal.
None of these new domains have the exploit code we talked about here. (at the time of this post)
Site: hxxp://antivirus5.com
File: scan.exe (ACA8B3BF12AF0B652AF5997DB629BDC5)
Info: File size: 203776 bytes [VirusTotal18/36]
MDB Path: /lithium-malware/scan.zip
Site: hxxp://antivirus6.com
File: scan.exe (ACA8B3BF12AF0B652AF5997DB629BDC5)
Info: File size: 203776 bytes [VirusTotal18/36]
MDB Path: /lithium-malware/scan.zip
Site: hxxp://antivirused.com
File: scan.exe (DEFB61DF4D6A187038FC3725EB431FAB)
Info: File size: 203776 bytes [VirusTotal 5/36] [ThreatExpert] *new*
MDB Path: /lithium-malware/scan(4).zip
Site: hxxp://antivirusik.com
File: scan.exe (ACA8B3BF12AF0B652AF5997DB629BDC5)
Info: File size: 203776 bytes [VirusTotal18/36]
MDB Path: /lithium-malware/scan.zip
Site: hxxp://antivirusol.com
File: scan.exe (ACA8B3BF12AF0B652AF5997DB629BDC5)
Info: File size: 203776 bytes [VirusTotal18/36]
MDB Path: /lithium-malware/scan.zip
Site: hxxp://antivirusrf.com
File: scan.exe (ACA8B3BF12AF0B652AF5997DB629BDC5)
Info: File size: 203776 bytes [VirusTotal18/36]
MDB Path: /lithium-malware/scan.zip
Site: hxxp://antivirustg.com
File: scan.exe (ACA8B3BF12AF0B652AF5997DB629BDC5)
Info: File size: 203776 bytes [VirusTotal18/36]
MDB Path: /lithium-malware/scan.zip
Site: hxxp://antivirusuj.com
File: scan.exe (ACA8B3BF12AF0B652AF5997DB629BDC5)
Info: File size: 203776 bytes [VirusTotal18/36]
MDB Path: /lithium-malware/scan.zip
Site: hxxp://antivirusyh.com
File: scan.exe (ACA8B3BF12AF0B652AF5997DB629BDC5)
Info: File size: 203776 bytes [VirusTotal18/36]
MDB Path: /lithium-malware/scan.zip
Site: hxxp://antivirusik.com
File: scan.exe (ACA8B3BF12AF0B652AF5997DB629BDC5)
Info: File size: 203776 bytes [VirusTotal18/36]
MDB Path: /lithium-malware/scan.zip
Removal: