Once executed, the worm drops the following files:
The worm then downloads a file from the following URL:
[http://]www.gratisweb.com/badbunny/badbun[REMOVED]
It then displays the following message:
Title: ///BadBunny\\\
Body: Hey '[USERNAME]' you like my BadBunny?
The worm attempts a denial of service attack by pinging the following URLs with ICMP packets of size 5000 bytes:
- www.ikarus.at
- www.aladdin.com
- www.norman.no
- www.norman.com
- www.kaspersky.com
- www.kaspersky.ru
- www.kaspersky.pl
- www.grisoft.cz
- www.symantec.com
- www.proantivirus.com
- www.f-secure.com
- www.sophos.com
- www.arcabit.pl
- www.arcabit.com
- www.avira.com
- www.avira.de
- www.avira.ro
- www.avast.com
- www.virusbuster.hu
- www.trendmicro.com
- www.bitdefender.com
- www.pandasoftware.comm
- www.drweb.com
- www.drweb.ru
- www.viruslist.com
Note: Reportedly, these packets should not cause a restart on any remote computer.
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":