Malware Must Die has published a report warning of Mayhem Shellshock attack. Experts detected numerous attack worldwide exploiting the Bash Bug flaw to spread the Mayhem botnet. The report includes the list of IP addresses belonging to the botnet scanning for vulnerable machines, as well as the IP address of the machine used to serve the Mayhem installer, and the majority of these IP addresses are in the United States. The attack came from various IP of their botnet into many NIX services, utilizing the shellshock web vulnerability scan method to download the remote installer written in Perl.”]
Source: https://securityaffairs.co/wordpress/29070/malware/mayhem-shellshock-attacks-worldwide.html