Antivirus and Security Software from Sophos

Sophos blogs

SB/BadBunny-A

Aliases
  • IRC-Worm.StarOffice.Badbunny.a
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Infected files
  • Chat programs
Affected operating systems Windows
Protection available since 21 May 2007 06:25:40 (GMT)
Last updated 16 May 2008 15:00:26 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

SB/BadBunny-A is a multi-platform worm written in several scripting languages and distributed as an OpenOffice.org document containing a StarBasic macro.

SB/BadBunny-A spreads by dropping malicious script files that affect the behavior of the popular IRC programs mIRC and X-Chat, causing them send SB/BadBunny-A to other users. These malicious script files are named badbunny.py (for XChat) and script.ini (for mIRC, overwriting the existing mIRC file) and are also detected as SB/BadBunny-A.

SB/BadBunny-A drops different additional components depending on the platform on which it is running:
 - On Windows, it drops a file named badbunny.js that is a JavaScript file infector also detected as SB/BadBunny-A.
 - On Linux, it drops a file named badbunny.pl that is a Perl file infector also detected as SB/BadBunny-A.
 - On MacOS, it drops one of two possible files named badbunny.rb and badbunnya.rb that are Ruby file infectors also detected as SB/BadBunny-A.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer