Backdoor

Backdoor:Win32/Padodor.SK!MTB (file analysis)

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • Uses Windows utilities for basic functionality
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: ACC2A91936520694886B.mlw
path: /opt/CAPEv2/storage/binaries/6e6bedd88b72824c246314efc6cdccbded0ef5f09d11a8885f35bda25ddc1775
crc32: DE07DB3E
md5: acc2a91936520694886b069b18b5e3e4
sha1: f9da567ae040d733122654e25e382518f212de5a
sha256: 6e6bedd88b72824c246314efc6cdccbded0ef5f09d11a8885f35bda25ddc1775
sha512: 9af0e1f0db1f176ce4485f7a11912e82c2170c6a2d6faf25137b8fbbe003932faef9e1d6f0dacb8d65add882961251d16b9d5e58306a6cab64d2deed373452d1
ssdeep: 12288:MXhRsYnz4uYGCzXjOYpV6yYPI3cpV6yYPeHCXwpnsKvNA+XTvZHWuEo3oWL5g:MEYz4wCzXjOYWHWIpsKv2EvZHp3oWNg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11B658031F9C39222C8C261F5695D1E60E46EC53E0FB196C356AC83A875563E20BF73DA
sha3_384: cf032fa67653f4172615f7fb5a32edf96a96b8f09683d122ee31643f2128bec6275b278e26a85bf30ae62696b6da7a14
ep_bytes: 90909090906067e80000000090905890
timestamp: 2021-11-23 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Trojan.ShellObject.AXZ@aCIJdog
FireEyeGeneric.mg.acc2a91936520694
CAT-QuickHealWorm.Dorkbot.A
SkyhighBehavesLike.Win32.Generic.tt
McAfeeGenericRXHD-SL!508501B11AA8
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Padodor.Win32.2211655
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.ae040d
ArcabitTrojan.ShellObject.E3B339
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.NAM
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Crypted-31
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.AXZ@aCIJdog
NANO-AntivirusTrojan.Win32.Padodor.foufls
AvastWin32:BackdoorX-gen [Trj]
TencentBackdoor.Win32.Padodor.kp
TACHYONBackdoor/W32.Padodor
SophosTroj/Padodor-M
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.HangUp.5
VIPREGen:Trojan.ShellObject.AXZ@aCIJdog
Trapminemalicious.high.ml.score
EmsisoftGen:Trojan.ShellObject.AXZ@aCIJdog (B)
IkarusBackdoor.Win32.Padodor
JiangminTrojanProxy.Qukart.cfa
VaristW32/Pahador.QLFO-8537
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.1D7CWH4
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
BitDefenderThetaAI:Packer.5134665F21
ALYacGen:Trojan.ShellObject.AXZ@aCIJdog
MAXmalware (ai score=81)
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
YandexBackdoor.Padodor.AF
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Qukart.A!tr
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment