Backdoor:W32/Finbodos.A is a simple Visual Basic compiled backdoor that listens for remote commands from an attacker.
Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.
Detailed instructions for F-Secure security products are available in the documentation found in the Downloads section of our Home - Global site.
You may also refer to the Knowledge Base on the F-Secure Community site for further assistance.
Backdoor:W32/Finbodos.A is a simple Visual Basic compiled backdoor that listens for remote commands from an attacker.Upon execution, it connects to the following address and tcp port:
The infected machine as a server then will listen for commands issued via a client program. Backdoor:W32/Finbodos.A commands include the following:
- Start DDOS
- Display messages
- Send flood packets
- Start / Stop server
It also downloads the following files which it uses as control variables for the server: