Sophos

SB/BadBunny-A

Aliases
  • IRC-Worm.StarOffice.Badbunny.a
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Infected files
  • Chat programs
Included in our products from July 2007 (4.19)
Protection available since 21 May 2007 06:25:40 (GMT)
Last updated 21 May 2007 16:29:33 (GMT)
Detected by All Sophos products

Action

More Information

SB/BadBunny-A is a multi-platform worm written in several scripting languages and distributed as an OpenOffice.org document containing a StarBasic macro. SB/BadBunny-A is a multi-platform worm written in several scripting languages and distributed as an OpenOffice.org document containing a StarBasic macro.

SB/BadBunny-A spreads by dropping malicious script files that affect the behavior of the popular IRC programs mIRC and X-Chat, causing them send SB/BadBunny-A to other users. These malicious script files are named badbunny.py (for XChat) and script.ini (for mIRC, overwriting the existing mIRC file) and are also detected as SB/BadBunny-A.

SB/BadBunny-A drops different additional components depending on the platform on which it is running:
 - On Windows, it drops a file named badbunny.js that is a JavaScript file infector also detected as SB/BadBunny-A.
 - On Linux, it drops a file named badbunny.pl that is a Perl file infector also detected as SB/BadBunny-A.
 - On MacOS, it drops one of two possible files named badbunny.rb and badbunnya.rb that are Ruby file infectors also detected as SB/BadBunny-A.

SB/BadBunny-A will also attempt a ping of death attack against the following anti-virus sites:-
 www.ikarus.at
 www.aladdin.com
 www.norman.no
 www.norman.com
 www.kaspersky.com
 www.kaspersky.ru
 www.kaspersky.pl
 www.grisoft.cz
 www.symantec.com
 www.proantivirus.com
 www.f-secure.com
 www.sophos.com
 www.arcabit.pl
 www.arcabit.com
 www.avira.com
 www.avira.de
 www.avira.ro
 www.avast.com
 www.virusbuster.hu
 www.trendmicro.com
 www.bitdefender.com
 www.pandasoftware.comm [sic]
 www.drweb.com
 www.drweb.ru
 www.viruslist.com

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer