Backdoor

What is “Backdoor:Win32/Padodor.SK!MTB”?

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: BD45E2D6B8258B24702B.mlw
path: /opt/CAPEv2/storage/binaries/61a66a2ae33522d4eec20cae261d9e4057350b94e9f10ba752b6128724627588
crc32: 1C0A76AA
md5: bd45e2d6b8258b24702b64c288e7abb9
sha1: cf40c9ba388b9c7be6e5112229b22d02297f1a15
sha256: 61a66a2ae33522d4eec20cae261d9e4057350b94e9f10ba752b6128724627588
sha512: 918b43241f2405b5c8332792cbcef39daaff2d6a5524e4f6d8e8e539a3a9aba7638824b383b9118becb21c8c537101579ded6a7312fd8217baba855be2ec0ef4
ssdeep: 6144:Mm3fjzvElNxunXe8yhrtMsQBvli+RQFdq:Mm3f4vAO8qRMsrOQF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T123646D17B5980F71CA831273263B0CD2EB2A446C1B7499E36778921E19E6CF2D1B7F46
sha3_384: 659b75de851f6c6df4caad122b007d5606d6f5e113b3a38b7e10c851f6eeb362bf9d36bd6cf178348666fbba508827ed
ep_bytes: 90909090906067e80000000090909090
timestamp: 2021-11-23 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ShellObject.t8Z@aWlu0Qk
FireEyeGeneric.mg.bd45e2d6b8258b24
CAT-QuickHealBackdoor.Padodor.S31773937
SkyhighBehavesLike.Win32.Generic.fh
McAfeeGenericRXHD-SL!060163D3D1BF
Cylanceunsafe
ZillyaTrojan.Padodor.Win32.963849
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaBackdoor:Win32/Padodor.da9553c8
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.a388b9
BitDefenderThetaAI:Packer.2715D70421
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.NAM
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Crypted-31
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.t8Z@aWlu0Qk
NANO-AntivirusTrojan.Win32.Padodor.fmsfjf
AvastWin32:BackdoorX-gen [Trj]
TencentBackdoor.Win32.Padodor.kp
TACHYONBackdoor/W32.Padodor
EmsisoftGen:Trojan.ShellObject.t8Z@aWlu0Qk (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebBackDoor.HangUp.5
VIPREGen:Trojan.ShellObject.t8Z@aWlu0Qk
TrendMicroTROJ_GEN.R002C0DKU23
Trapminemalicious.high.ml.score
SophosTroj/Padodor-M
IkarusBackdoor.Win32.Padodor
JiangminBackdoor.Padodor.svm
VaristW32/Pahador.QLFO-8537
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ArcabitTrojan.ShellObject.E668B8
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.15MS2TX
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
ALYacGen:Trojan.ShellObject.t8Z@aWlu0Qk
MAXmalware (ai score=81)
VBA32Backdoor.Padodor
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DKU23
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
YandexBackdoor.Padodor.AF
SentinelOneStatic AI – Malicious PE
FortinetW32/Qukart.A!tr
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment