Backdoor

Backdoor:Win32/Padodor.SK!MTB malicious file

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: C5F5C6BD6ED0844EBDFC.mlw
path: /opt/CAPEv2/storage/binaries/87fd5403fc70c9b9d9d843cef05664a46e7c3220a58ba244c654ab487fb0b1d2
crc32: 6EAA9E4F
md5: c5f5c6bd6ed0844ebdfce877275658c3
sha1: 3093d830a3b9863c00856ef959f1169de5966e2a
sha256: 87fd5403fc70c9b9d9d843cef05664a46e7c3220a58ba244c654ab487fb0b1d2
sha512: e03390e076815adfd1b6ca094a6abda319125117dec9531848e2875c47d15c481a52764ba87b928e17fe653ee4cc7ccb854ea7598f4d30bd8863029c039d0e7e
ssdeep: 3072:TyiA0qk+eJ38YVdknZZvcIPel203H/6TC+qF1SsB1bw4AVRrd9:OiA523KZZUIml9C81NBy9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T100C38C6F164B0F93CA45007031AE618AE525C6380B6F8DF6A86DC15C23DBFDB667D3A4
sha3_384: 7767438cdac2bf23a50625a68e97ea3d21b99d716cd4100f1b6b28c8284470b7ace6c23ee734fe412809597a478c6ef9
ep_bytes: 609090b800104000bbd0c740009090b9
timestamp: 2023-04-07 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.DQQO
ClamAVWin.Trojan.Berbew-10013977-0
FireEyeGeneric.mg.c5f5c6bd6ed0844e
SkyhighBehavesLike.Win32.Generic.cc
McAfeeTrojan-FVOJ!C5F5C6BD6ED0
MalwarebytesPadodor.Backdoor.Bot.DDS
ZillyaTrojan.PadodorGen.Win32.21
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaBackdoor:Win32/Padodor.a6b234ad
K7GWTrojan ( 005780dd1 )
K7AntiVirusTrojan ( 005780dd1 )
SymantecBackdoor.Berbew
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.NAM
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderTrojan.Agent.DQQO
NANO-AntivirusTrojan.Win32.Padodor.foufls
AvastWin32:BackdoorX-gen [Trj]
TencentBackdoor.Win32.Padodor.kp
TACHYONBackdoor/W32.Padodor
EmsisoftTrojan.Agent.DQQO (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebBackDoor.HangUp.5
VIPRETrojan.Agent.DQQO
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Crypt
JiangminBackdoor.Padodor.exyu
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ArcabitTrojan.Agent.DQQO
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.9FITS9
VaristW32/Pahador.QLFO-8537
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
ALYacTrojan.Agent.DQQO
MAXmalware (ai score=86)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
YandexBackdoor.Padodor.AF
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.BJQV!tr
BitDefenderThetaAI:Packer.0C3353A21D
AVGWin32:BackdoorX-gen [Trj]
Cybereasonmalicious.0a3b98
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment