Backdoor

Backdoor:Win32/Padodor.SK!MTB (file analysis)

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: 53FEE7FDD7EFC3CAC119.mlw
path: /opt/CAPEv2/storage/binaries/be605587005d4a83274846d96ac1df5a0f316fe2c9d6e06a49cb07e8c978cd31
crc32: 0D9D0683
md5: 53fee7fdd7efc3cac1195f8fe164c3a4
sha1: abb4c32a1990db0796008f260157973ac5fd5ad0
sha256: be605587005d4a83274846d96ac1df5a0f316fe2c9d6e06a49cb07e8c978cd31
sha512: f9f755bc5903e969256b977eb3a352737713dae52697f2037712bdeb2dc0bd4c9af11f2bd39eb02cd74098fc49e02972b817595791cb6fd98b6a842d190413f6
ssdeep: 1536:9jfRBbBkitySsoduUlNu7tbjIFGN/bRK14yB2xhkf05xzBduV9jojTIvjrH:3pydoddSbjUk/bRYChy05xVd69jc0vf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13CA38E2F96A02FBECEB401F27B065587370A8E734F6EFD67C920504E3A4BA505676D42
sha3_384: fbaa18c34a2b555d0576bf225a0a1fe6d649900bb541d61b2c502b09e66861d70fef1fe19478d847262256c75efe4565
ep_bytes: 90909067e80000000090909058909005
timestamp: 1986-03-19 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ShellObject.g8W@aaajMem
SkyhighBehavesLike.Win32.Generic.nc
McAfeeGenericRXPE-AP!0E259F4CCC65
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.PadodorGen.Win32.15
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.AB
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Convagent-10013360-0
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.g8W@aaajMem
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kp
EmsisoftGen:Trojan.ShellObject.g8W@aaajMem (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.Wdozer
VIPREGen:Trojan.ShellObject.g8W@aaajMem
SophosML/PE-A
IkarusBackdoor.Win32.Padodor
GDataGen:Trojan.ShellObject.g8W@aaajMem
JiangminTrojanSpy.Convagent.fp
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
ArcabitTrojan.ShellObject.E87CBE
ZoneAlarmBackdoor.Win32.Padodor.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
ALYacGen:Trojan.ShellObject.g8W@aaajMem
TACHYONBackdoor/W32.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Padodor!8.118 (TFE:5:ostuCj5goYJ)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.B077!tr
BitDefenderThetaAI:Packer.6CB2E9D01E
AVGWin32:Padodor-V [Trj]
Cybereasonmalicious.a1990d
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment