Botnet using Plesk vulnerability and takedown

Parallels Plesk
Today while investigating the Plesk/Apache Remote Code Execution vulnerability disclosed by Kingcope, we uncovered what appeared to be a sizeable botnet leveraging this vulnerability to infect webservers with a malicious IRC bot written in Perl; a loosely modified version of a publicly known tool.

A large list of hosts believed to be infected was generated from the data gathered, and probed in an automated fashion for vulnerable Plesk installations. Over 900 hosts attempting to connect were running vulnerable Plesk installations, confirming our suspicion that the Plesk exploit was how this malware was spreading; based on our estimates, about 40 hosts were being infected an hour, which we found intolerable.

Source