OpenOffice macro worm exposes bad bunny

By Brett Winterford, ZDNet Australia
Wednesday, May 23, 2007 10:34 AM

Sophos has warned users of the multi-platform OpenOffice productivity tool not to open any files named "badbunny.odg", which releases a worm exposing users to an image of a man in a bunny suit and a scantily clad woman performing a sexual act in woodland.

The macro-based worm, named SB/Badbunny-A, does not appear to pose any threat to infected systems aside from downloading and displaying the pornographic JPEG image.

But the virus does expose some holes in the productivity tool.

Users that open badbunny.odg launch a macro that behaves in several different ways depending on the user’s operating system.

On Windows systems, it drops a file called drop.bad which is moved to the system.ini in the user’s mIRC folder, while executing the Javascript virus badbunny.js that replicates to other files in the folder.

On Apple Mac systems, the worm drops one of two Ruby script viruses in files called badbunny.rb and badbunnya.rb.

On Linux systems, the worm drops both badbunny.py as an XChat script and badbunny.pl as a Perl virus.

"This is old-school malware--seemingly written to show off a proof of concept rather than a serious attempt to spy on and steal from computer users," says Graham Cluley, senior technology consultant for antivirus vendor Sophos.

"A financially motivated hacker would have targeted more widely used software and not incorporated such a bizarre image. This is not a piece of malware which we expect to see spreading in the wild, despite its use of a photograph of unusual wildlife."

Sophos has posted an edited version of the image on its Web site.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Windows Server 2008 iSCSI multiple connected session modes

Enterprise Servers & Storage

For administrators using Windows Server 2008's iSCSI initiator, selecting the right connection policy is critical. Rick Vanover explains the options for the ease-of-entry storage protocol.


Read more »


 
Virtualize your way to cost savings
Build an infrastructure that is flexible, scalable, and economical, as you strive to become a truly agile business.

Red Hat Outlines Its Virtualization Strategy and Roadmap for 2009
» Watch the video




NUS Enterprise: An 'incubator without walls'

Blog thumbnail

Almost everyone has had dreams of owning their own shop, but most of us know also that it takes a fair amount of resources to open a new business, and..... by Eileen Yu

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web