With the changing of binaries came a new domain: "superdrugtesting.com". It is the same old fast flux network the Storm worm authors have been using for the last year with great success this time the registrar is TODAYNIC.COM in China. This new domain name has also speed up my storm worm binary harvesting to one an hour once again, due to the fact I can grab active IPs instead of sorting through my archived IPs of 85,000 trying to find a host that is alive and well.
I would strongly encourage you to set your spam filters, DNS backholes, and content filters to dropping this stuff. As you can almost bet on seeing this in your Monday morning network traffic.