First posted on 01 June 2007.
Source: SecurityHome
Backdoor:W32/Finbodos.A is also known as Finbodos.A.
Backdoor:W32/Finbodos.A is a simple Visual Basic compiled backdoor that listens for remote commands from an attacker.
Backdoor:W32/Finbodos.A is a simple Visual Basic compiled backdoor that listens for remote commands from an attacker.
Upon execution, it connects to the following address and tcp port:
The infected machine as a server then will listen for commands issued via a client program.
Backdoor:W32/Finbodos.A commands include the following:
- Start DDOS
- Display messages
- Send flood packets
- Start / Stop server
It also downloads the following files which it uses as control variables for the server:
- http://hotelliretro.org/[REMOVED]/teksti.dat
- http://hotelliretro.org/[REMOVED]/interval.dat
- http://hotelliretro.org/[REMOVED]/mainostila.dat
Last update 01 June 2007
TOP