Backdoor:W32/Finbodos.A is a simple Visual Basic compiled backdoor that listens for remote commands from an attacker.
Upon execution, it connects to the following address and tcp port:
The infected machine as a server then will listen for commands issued via a client program.
Backdoor:W32/Finbodos.A commands include the following:
- Start DDOS
- Display messages
- Send flood packets
- Start / Stop server
It also downloads the following files which it uses as control variables for the server: