OpenOffice macro worm exposes bad bunny

By Brett Winterford, ZDNet Australia
Wednesday, May 23, 2007 10:34 AM

Sophos has warned users of the multi-platform OpenOffice productivity tool not to open any files named "badbunny.odg", which releases a worm exposing users to an image of a man in a bunny suit and a scantily clad woman performing a sexual act in woodland.

The macro-based worm, named SB/Badbunny-A, does not appear to pose any threat to infected systems aside from downloading and displaying the pornographic JPEG image.

But the virus does expose some holes in the productivity tool.

Users that open badbunny.odg launch a macro that behaves in several different ways depending on the user’s operating system.

On Windows systems, it drops a file called drop.bad which is moved to the system.ini in the user’s mIRC folder, while executing the Javascript virus badbunny.js that replicates to other files in the folder.

On Apple Mac systems, the worm drops one of two Ruby script viruses in files called badbunny.rb and badbunnya.rb.

On Linux systems, the worm drops both badbunny.py as an XChat script and badbunny.pl as a Perl virus.

"This is old-school malware--seemingly written to show off a proof of concept rather than a serious attempt to spy on and steal from computer users," says Graham Cluley, senior technology consultant for antivirus vendor Sophos.

"A financially motivated hacker would have targeted more widely used software and not incorporated such a bizarre image. This is not a piece of malware which we expect to see spreading in the wild, despite its use of a photograph of unusual wildlife."

Sophos has posted an edited version of the image on its Web site.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Use shades of gray to enhance scale in Excel

Microsoft Office Suite

Excel's palette is generous, but don't throw buckets of pigment all over your spreadsheets just because you can.


Read more »



Ultimate 2012 recovery site: the moon

Blog thumbnail

Have you seen the disaster movie "2012"? A friend from Control Risks and I did, and we reluctantly concluded we wouldn't be able to write off the cost of our..... by Nathaniel Forbes

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web