1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




Backdoor:W32/Finbodos.A

Name : Backdoor:W32/Finbodos.A
Category:Malware
Type:Backdoor
Platform:W32

Summary

Backdoor:W32/Finbodos.A is a simple Visual Basic compiled backdoor that listens for remote commands from an attacker.

Additional Details

Backdoor:W32/Finbodos.A is a simple Visual Basic compiled backdoor that listens for remote commands from an attacker.
Upon execution, it connects to the following address and tcp port:
  •  botnet.dy.fi:7668/TCP

The infected machine as a server then will listen for commands issued via a client program.
Backdoor:W32/Finbodos.A commands include the following:
  •  Start DDOS
  • Display messages
  • Send flood packets
  • Start / Stop server

It also downloads the following files which it uses as control variables for the server:
  •  http://hotelliretro.org/[REMOVED]/teksti.dat
  • http://hotelliretro.org/[REMOVED]/interval.dat
  • http://hotelliretro.org/[REMOVED]/mainostila.dat