Backdoor

Backdoor:Win32/Padodor.SK!MTB information

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: E96A8ECF46D0E38A73CF.mlw
path: /opt/CAPEv2/storage/binaries/3de46547b62b813c1c195024ada3ee4bbb13a04a6c44ddd1af6baeffbfce673b
crc32: CBA09094
md5: e96a8ecf46d0e38a73cf54f5ffdad605
sha1: 23063553b520541cc08b58a1475866619f9d3202
sha256: 3de46547b62b813c1c195024ada3ee4bbb13a04a6c44ddd1af6baeffbfce673b
sha512: e488f311a4a880090a5df24a6c24d3ae464e85953e4d6c772b9cee6276778f9b91e5d20e98fc9814bc68d8031d989ce9e296c060286426a3f7fc23840ba74884
ssdeep: 24576:q5KPh2kkkkK4kXkkkkkkkka0+YNpsKv2EvZHp3oWbvrec:QmLXZ5Tec
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17C456B53FEC3A133C0AB51B5267F8B25A13ACD34AFA184C35D8C9A743DA62D416B83D5
sha3_384: 0321cb770e0141cb6a2a505f98f5c94164f64d2e4a02e535ffb5b8e48f153ce6d1be0e155aa1c91384e541e9b88ac5cc
ep_bytes: 909090909060b80010400090bbd0c740
timestamp: 2021-11-23 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.m!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Agent.DQQO
FireEyeGeneric.mg.e96a8ecf46d0e38a
SkyhighBehavesLike.Win32.Generic.tm
McAfeeTrojan-FVOJ!E96A8ECF46D0
Cylanceunsafe
ZillyaTrojan.QukartGen.Win32.2
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaBackdoor:Win32/Padodor.03bfd9be
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.3b5205
BitDefenderThetaAI:Packer.1DE844F721
SymantecBackdoor.Berbew
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.NAM
APEXMalicious
ClamAVWin.Trojan.Crypted-31
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderTrojan.Agent.DQQO
NANO-AntivirusTrojan.Win32.Padodor.foufls
AvastWin32:BackdoorX-gen [Trj]
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
TACHYONBackdoor/W32.Padodor
EmsisoftTrojan.Agent.DQQO (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebBackDoor.HangUp.5
VIPRETrojan.Agent.DQQO
TrendMicroTROJ_GEN.R002C0DAJ24
Trapminemalicious.high.ml.score
SophosTroj/Padodor-M
IkarusBackdoor.Win32.Padodor
GDataWin32.Trojan.PSE.15977NU
JiangminBackdoor.Padodor.esac
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/Pahador.QLFO-8537
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
ArcabitTrojan.Agent.DQQO
ZoneAlarmBackdoor.Win32.Padodor.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
ALYacTrojan.Agent.DQQO
MAXmalware (ai score=86)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DAJ24
TencentBackdoor.Win32.Padodor.kp
YandexBackdoor.Padodor.AF
SentinelOneStatic AI – Malicious PE
FortinetW32/GenKryptik.EZNP!tr
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment