Backdoor

Backdoor:Win32/Padodor.SK!MTB (file analysis)

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • Uses Windows utilities for basic functionality
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: AA65E60EB15E5E06BD6B.mlw
path: /opt/CAPEv2/storage/binaries/74e2a782b32d0d4e4142c85b15e97dc09d00c4b4a5d1e5493b4b056184339eff
crc32: A0806510
md5: aa65e60eb15e5e06bd6bdb056208033b
sha1: 09941c77113ee1c9bc82f695f87b9818601e4387
sha256: 74e2a782b32d0d4e4142c85b15e97dc09d00c4b4a5d1e5493b4b056184339eff
sha512: 14dc48984036c1526d11f9fb34beaa91ddc28bde5b3d06296072fc3fc81559b7ec166aca4cf68defec6fb8b744e7e76ab02349b00fd19d1a551f1c781f64edd8
ssdeep: 1536:W9go1xyxvPNWmUdcjRpXe15Dv8NGfubwYQwh55hsRQWDRkRLJzeLD9N0iQGRNQR5:W9TyxvFWmUdc/Xe1uNGfGQ6jeeQSJdEs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T159938C7BF5844FE7C8AD04F129260C8E9717E13423165B936454C20E2797CEEE2BA5EB
sha3_384: cebee9728d0c8b776ea57c7aba92d43ee18f4542067f9753f432b912982fdad7532acbc2b895188dafc70f5a308d3dfe
ep_bytes: 60909067e80000000090909090905890
timestamp: 2017-10-15 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Trojan.ShellObject.f8W@aeOesjp
FireEyeGeneric.mg.aa65e60eb15e5e06
SkyhighBehavesLike.Win32.Generic.nc
McAfeeTrojan-FVOK!AA65E60EB15E
Cylanceunsafe
ZillyaTrojan.PadodorGen.Win32.7
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.7113ee
ArcabitTrojan.ShellObject.E8EEEC
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.NAM
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Qukart-10012701-0
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.f8W@aeOesjp
NANO-AntivirusTrojan.Win32.Padodor.flldmv
AvastWin32:BackdoorX-gen [Trj]
TencentBackdoor.Win32.Padodor.kg
TACHYONBackdoor/W32.Padodor
EmsisoftGen:Trojan.ShellObject.f8W@aeOesjp (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebBackDoor.HangUp.5
VIPREGen:Trojan.ShellObject.f8W@aeOesjp
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Crypt
JiangminBackdoor.Padodor.ewpp
VaristW32/Pahador.QLFO-8537
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataGen:Trojan.ShellObject.f8W@aeOesjp
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
BitDefenderThetaAI:Packer.2ABBEDA021
ALYacGen:Trojan.ShellObject.f8W@aeOesjp
MAXmalware (ai score=80)
VBA32Backdoor.Padodor
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.BJQV!tr
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment