Earlier today, Cyveillance issued this report of a nearly identical attack with over 260,000 dangerous URLs prompting the Threat Prevention Team to revisit this threat.
Between the newly reported Cyveillance URLs and additional URLs discovered by the eSoft there are now well over 800,000 active URLs matching this pattern. Surprisingly, Google only detects a small portion of these sites as malicious.
Using this technique allows the attackers to quickly and easily change distribution points and payloads. The current payloads have low detection rates among AV scanners.
In addition to the URL strings reported by Cyveillance be on the lookout for these additional URL types.
eSoft will continue to flag associated domains into their appropriate security categories, protecting SiteFilter users from falling victim to this attack.