Backdoor

Backdoor:Win32/Padodor.SK!MTB (file analysis)

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • Uses Windows utilities for basic functionality
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: 0697C50645F24469812C.mlw
path: /opt/CAPEv2/storage/binaries/b819f135c787b927e63c331f5e3b5114ec2ebbf226e519914ae3e20f361347d3
crc32: B329F85F
md5: 0697c50645f24469812c2dd726f4e3a1
sha1: faadd4c8166454f23daf7928a6a724fb977d0490
sha256: b819f135c787b927e63c331f5e3b5114ec2ebbf226e519914ae3e20f361347d3
sha512: ef049e837bf9aed8e41b18362dd50abb5a658c6d9492a6260a2c3b07a76ac002cb316412095fb373e09a0c770bee3e21d0b2a791dd69451ee84033609facb846
ssdeep: 3072:vg/oqCieC2mR/0e3o3/zrB3g3k8p4qI4/HQCC:waa/PUPBZs/HNC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F7A36B5FA7423FA2C19132B1395B68CAF715953F535E86A9E8BC8018325BE7703FB601
sha3_384: d45dc9b59882d432b8d6d96c2431948023c1793bb196b4c08daf34d3fdcf0e56ed362e039d73f4437944e4e771bdb644
ep_bytes: 909067e8000000009090909090589005
timestamp: 2019-02-27 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebBackDoor.HangUp.5
MicroWorld-eScanGen:Trojan.ShellObject.g8X@a4IOpRm
FireEyeGeneric.mg.0697c50645f24469
SkyhighBehavesLike.Win32.Generic.ch
McAfeeGeneric Malware.bj
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.PadodorGen.Win32.18
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.816645
BitDefenderThetaAI:Packer.5E7FBA6C21
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.NAM
APEXMalicious
ClamAVWin.Trojan.Obfus-38
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.g8X@a4IOpRm
NANO-AntivirusTrojan.Win32.Padodor.foufls
AvastWin32:BackdoorX-gen [Trj]
TencentBackdoor.Win32.Padodor.kp
EmsisoftGen:Trojan.ShellObject.g8X@a4IOpRm (B)
F-SecureTrojan.TR/Dropper.Gen
VIPREGen:Trojan.ShellObject.g8X@a4IOpRm
Trapminemalicious.high.ml.score
SophosML/PE-A
IkarusBackdoor.Win32.Padodor
MAXmalware (ai score=83)
GDataWin32.Trojan.PSE.1A8ERTK
JiangminBackdoor.Padodor.eytg
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/Pahador.QLFO-8537
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
ArcabitTrojan.ShellObject.E3FEDE
ZoneAlarmBackdoor.Win32.Padodor.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
ALYacGen:Trojan.ShellObject.g8X@a4IOpRm
TACHYONBackdoor/W32.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
YandexBackdoor.Padodor.AF
SentinelOneStatic AI – Malicious PE
FortinetW32/GenKryptik.FBNK!tr
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment