Actually, Lizamoon is just one of the latest mal-domains involved in a series of SQL injection attacks that started seven months ago, to be exact. The first encounter Cisco ScanSafe recorded was September 20th @10 21:58:08 GMT.
During the course of this long run, we've observed a total of 42 malware domains (list below). However, despite the lengthy run and large number of malware domains, only 0.15 percent of encounters have thus far involved a functional/active malware domain. In other words, 99.85 percent of encounters have involved no content/dead domains.
Lizamoon did shake things up substantially, though. She got 55 percent of all encounters just on March 25th alone. But her success was also her undoing. That round of SQL injection netted a very big fish -- the website was so popular that 92 percent of all encounters on the heavy-hitting March 25th was a result of visits to that one website. And because of that, it was removed. Immediately. Even before other security firms noticed there was a SQL injection attack under way and began reporting on it.
Here's the current list of domains we've observed as of yesterday: