Perl IRC Worm

This one is a IRC Perl Worm, which according to it's header, was written in 2012 for “educational purposes only” by the “w0rmer security team”. It’s funny that something so old can still be seen making it's way around the internet. I saw it a few months after it attacked, and the IRC C2 was already taken down. Taking a quick look at the header and the source, it is mostly for DDoS, but has a few other features (email, portscan, run commands, ...). It is not a direct feature for it to bruteforce SSH credentials, but it is possible that after a host joins on IRC, it is directed to download an additional payload for SSH scanning and bruteforcing.


VirusTotal
Login Attempts (From one IP)
Download logs
../