Backdoor

What is “Backdoor:Win32/Mdmbot.D”?

Malware Removal

The Backdoor:Win32/Mdmbot.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Mdmbot.D virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Mdmbot.D?


File Info:

name: 4D1F6C8957F7A960C350.mlw
path: /opt/CAPEv2/storage/binaries/d8898c09dcc248cd460e213da5ba906de954355bf7f03b756764119a1d7d1dfe
crc32: CAB19F52
md5: 4d1f6c8957f7a960c3501a150d292cc0
sha1: bdc1a89f7922c085713e192362fcaa7be66a2caa
sha256: d8898c09dcc248cd460e213da5ba906de954355bf7f03b756764119a1d7d1dfe
sha512: 84db480377038a78bb486345606d738f19a22274dd4f6b43ae1252e2f5e15c41cfa2980fc3a283684247069ce4350f5f1a78b9df5ff00e1567e7dff69dae5e2f
ssdeep: 768:lLo8eMGZCuEv9I72UByaBDm80K+mZIL/QvwPD5K78JoNgH6rK:h3Wnh7Tm8nOjUwPs76hmK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B0038E41A3E837BAF3F70AB12876467A5A397D315B79C0BE0E33C5D518BA644E434362
sha3_384: 560ee59610a79b8f9815c2594551af9ea7d53c218e0f8ffafd7c05581d66fb55ef092b68972dfbe5b2392f4e5cab0c07
ep_bytes: b8fc120000e83605000056578d8424ec
timestamp: 2011-08-04 09:53:27

Version Info:

Comments:
CompanyName: Microsoft Corporation
FileDescription: Protected Storage COM interfaces
FileVersion: 6, 0, 0, 0
InternalName: Microsoft(R) Windows(R) Operating System
LegalCopyright: Copyright (C) 2008
LegalTrademarks:
OriginalFilename: Loader.exe
PrivateBuild:
ProductName: Microsoft(R) Windows(R) Operating System
ProductVersion: 6, 0, 0, 0
SpecialBuild:
Translation: 0x0409 0x04b0

Backdoor:Win32/Mdmbot.D also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.b!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
McAfeeArtemis!4D1F6C8957F7
ZillyaDropper.Dorifel.Win32.16444
SangforSuspicious.Win32.Save.ins
K7AntiVirusRiskware ( 0040eff71 )
AlibabaBackdoor:Win32/Dorifel.1fb9b0ae
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.f7922c
BitDefenderThetaAI:Packer.722F35791F
VirITBackdoor.Win32.Generic14.ACLN
CyrenW32/Mdmbot.A!Eldorado
SymantecPacked.Generic.374
ESET-NOD32a variant of Win32/McRat.B
APEXMalicious
KasperskyTrojan-Dropper.Win32.Dorifel.amin
BitDefenderGen:Variant.Graftor.79175
NANO-AntivirusTrojan.Win32.TrjGen.cxsevg
MicroWorld-eScanGen:Variant.Graftor.79175
AvastWin32:Malware-gen
TencentWin32.Trojan-Dropper.Dorifel.Yimw
EmsisoftGen:Variant.Graftor.79175 (B)
F-SecureBackdoor.BDS/Mdmbot.D.3
DrWebTrojan.DownLoader9.55951
VIPREGen:Variant.Graftor.79175
McAfee-GW-EditionBehavesLike.Win32.Dropper.ph
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.4d1f6c8957f7a960
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDropper.Agent.biro
AviraBDS/Mdmbot.D.3
Antiy-AVLTrojan[Dropper]/Win32.Agent
MicrosoftBackdoor:Win32/Mdmbot.D
XcitiumMalware@#394dljh7dm1g5
ArcabitTrojan.Graftor.D13547
ZoneAlarmTrojan-Dropper.Win32.Dorifel.amin
GDataGen:Variant.Graftor.79175
GoogleDetected
AhnLab-V3Dropper/Win32.Agent.R30440
Acronissuspicious
VBA32BScope.Backdoor.ZZSlash
ALYacGen:Variant.Graftor.79175
MAXmalware (ai score=100)
Cylanceunsafe
ZonerTrojan.Win32.33591
RisingBackdoor.Mdmbot!8.2049 (TFE:2:TZd3BeRLA6J)
IkarusTrojan-Dropper.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.FXYT!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Mdmbot.D?

Backdoor:Win32/Mdmbot.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment