If you've not already done so, you'll want to block 126.96.36.199 asap. It's currently housing a plethora of domains that are serving malware via exploit.
Payloads are coming from paths such as;
You'll no doubt notice the usual suspects as far as the ccTLD branches (redirection services serving off of ccTLDs such as .cc) are concerned. Reports are being fired off to the host and various service providers as I write this, and should hopefully be down soon.
http://hphosts.blogspot.com/2011/06/ale ... 51100.html