FYI…

- http://isc.sans.org/diary.php?date=2005-02-24
Updated February 25th 2005 00:48 UTC
"It is based heavily on the PhpInclude code on K-OTiK's site ( http://www.k-otik.com/exploits/20041225.PhpIncludeWorm.php ). It appears to be a variant of the ASW worm and is being used to drop an IRC bot that is connecting to a server in Brazil. Google has been notified. The worm doesn't appear to be identified by many AV vendors yet however the bot is: (from VirusTotal)

Antivirus Version Update Result

AntiVir 6.29.0.16 02.24.2005 no virus found
AVG 718 02.22.2005 PERL/ShellBot
BitDefender 7.0 02.24.2005 Backdoor.Perl.Shellbot.B
ClamAV devel-20050130 02.24.2005 Trojan.Perl.Shellbot.C
DrWeb 4.32b 02.24.2005 no virus found
eTrust-Iris 7.1.194.0 02.24.2005 no virus found
eTrust-Vet 11.7.0.0 02.24.2005 Perl.Shellbot.A
Fortinet 2.51 02.25.2005 no virus found
F-Prot 3.16a 02.24.2005 Unix/ShellBot.C
Ikarus 2.32 02.24.2005 Backdoor.Perl.Shellbot.A
Kaspersky 4.0.2.24 02.25.2005 Backdoor.Perl.Shellbot.a
NOD32v2 1.1007 02.23.2005 Perl.Shellbot.A
Norman 5.70.10 02.22.2005 no virus found
Panda 8.02.00 02.24.2005 no virus found
Sybari 7.5.1314 02.25.2005 Perl.Shellbot.A
Symantec 8.0 02.24.2005 IRC.Backdoor.Trojan …"

:ph34r: