First posted on 01 June 2007.
Source: SecurityHome
Backdoor:W32/Finbodos.A is also known as  Finbodos.A.
Backdoor:W32/Finbodos.A is a simple Visual Basic compiled backdoor that listens for remote commands from an attacker.
 Backdoor:W32/Finbodos.A is a simple Visual Basic compiled backdoor that listens for remote commands from an attacker.
Upon execution, it connects to the following address and tcp port:
 
 
The infected machine as a server then will listen for commands issued via a client program. 
Backdoor:W32/Finbodos.A commands include the following:
 
 - Start DDOS
  - Display messages
  - Send flood packets
  - Start / Stop server
  
 
It also downloads the following files which it uses as control variables for the server:
 
 - http://hotelliretro.org/[REMOVED]/teksti.dat
  - http://hotelliretro.org/[REMOVED]/interval.dat
  - http://hotelliretro.org/[REMOVED]/mainostila.dat
  
Last update 01 June 2007
 
TOP