The attack wave of “ELF.so malware library”, an installer of a known botnet called as “Mayhem” just hit all of us. The attack came from various IP of their botnet into many NIX services, utilizing the shellshock web vulnerability scan method to download the remote installer written in Perl (replacing the previous PHP base infection). It is obviously a new different vector for Mayhem infection, we start calling it Mayhem Shellshock version of attack. The 404.cgi file is the Perl installer of the malware library, the neutralized code can be viewed below.”]
Source: https://blog.malwaremustdie.org/2014/10/mmd-0029-2015-warning-of-mayhem.html

