Backdoor

Backdoor:Win32/Padodor.SK!MTB (file analysis)

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: 07C9884DB05418B9D632.mlw
path: /opt/CAPEv2/storage/binaries/61fb14279b87335cae9bcd1a2bbea56f595f83ecb84f4e5654b8d536138b6494
crc32: 91A8C14A
md5: 07c9884db05418b9d632a4880c0a52ec
sha1: 1a264b2aa9ee2f0d6ab63fdcaa114c96809c359f
sha256: 61fb14279b87335cae9bcd1a2bbea56f595f83ecb84f4e5654b8d536138b6494
sha512: 677e66aa05df9f18c5bb6864fc2a02872cdb4307b451626c7ce0a39e3e59d0ffa0e84cbc9c88f7bb96eefab9aa602e063b5f5ca437aae2902711e5047e8988c7
ssdeep: 1536:C+mpNVD6fsd4e3tm9m3XM93EUL+r4575zbdgKVpRQlR+KRFR3RzR1URJrCiuiNjH:CDpNVWfeP9v2L+r4575dVpeljb5ZXUf5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CB939D06AF7B2FEEE5A632F500F5CD8756AC9834322390A6619C8E8D48FF79443F9151
sha3_384: 3e0f864d531a5d8dc0bb3c89ffb0dab74e5ae824dd417b79ddf03aa15cdfabbb74c46a83283f45a19298aa219e944712
ep_bytes: 609090909090b80010400090906a0490
timestamp: 2020-07-11 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGenPack:Trojan.Agent.DQQO
ALYacGenPack:Trojan.Agent.DQQO
MalwarebytesPadodor.Backdoor.Bot.DDS
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 005780dd1 )
K7AntiVirusTrojan ( 005780dd1 )
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.NAM
APEXMalicious
CynetMalicious (score: 100)
NANO-AntivirusTrojan.Win32.GenKryptik.kcaixj
TencentBackdoor.Win32.Padodor.kp
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
ZillyaTrojan.Padodor.Win32.728437
Trapminemalicious.high.ml.score
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.ZPACK.Gen2
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
TACHYONBackdoor/W32.Padodor
DeepInstinctMALICIOUS
Cylanceunsafe
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
YandexBackdoor.Padodor.AF
IkarusBackdoor.Win32.Padodor
Cybereasonmalicious.aa9ee2
PandaTrj/Genetic.gen

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment