So, inside the user agent it is starting a PHP script that tries to download the file http://websalesusa.com/ken, which is the r57shell.php.
My guess is that it is trying to exploit a web stats or log analysis tool (like webalizer, google analytics, ossec, etc), but I couldn't find which one is vulnerable to that. Any ideas?
**this is what the r57shell looks like: http://sucuri.net/?page=tools&title=blacklist&seeall=1&detail=eadbf8dc38276dba3df4d6db9608db74