Backdoor

Backdoor:Win32/Padodor.SK!MTB (file analysis)

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: ED626D3112C034253DDE.mlw
path: /opt/CAPEv2/storage/binaries/4db3202869623c1e491083deaa82317b814ed7ab2b22bfd5a18204f85d39bf63
crc32: 1B7133E2
md5: ed626d3112c034253ddea05d5ec3f0ab
sha1: b46e9a381ce9368d78f0d4497a95652f5d2da31c
sha256: 4db3202869623c1e491083deaa82317b814ed7ab2b22bfd5a18204f85d39bf63
sha512: bf78af9930acf0f1b874cea65758fed020dc7d719208afff67c9fa44ac4773eac50113c454c36bd4be2006bbb8a0c72328a70a2a23978c2e08ed431c518afd3d
ssdeep: 1536:fcGNET3Q1UUNv5Mu+sMTJoFrrnfGBU7j/zRQy8RvwtycORTRQ6mRQQRRQjGmZrhB:EGOQTO9oFaijbey8pwoTRBmDRGGurhUI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T157A38C9FB1C60F56F98136F0A803D8A3E739D53E73158BE1405C502F639BE1AD2BA598
sha3_384: 329b1ac4cfb87f272c5f09af7016907b3f4553c9a088f21e6487b55701bb4244841e3fbdc69c3fe265654f754a5e8ea5
ep_bytes: 9090b80010400090906a049090909090
timestamp: 2016-06-02 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ShellObject.g8W@aWD2a0g
FireEyeGeneric.mg.ed626d3112c03425
SkyhighBehavesLike.Win32.Backdoor.nc
McAfeeGeneric Malware.bj
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.ShellObject.g8W@aWD2a0g
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.112c03
BitDefenderThetaAI:Packer.AF4775D21E
VirITWin32.Padodor.V
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.NAM
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.g8W@aWD2a0g
NANO-AntivirusTrojan.Win32.GenKryptik.kcaixj
AvastWin32:BackdoorX-gen [Trj]
TACHYONBackdoor/W32.Padodor
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
DrWebBackDoor.HangUp.5
ZillyaTrojan.PadodorGen.Win32.8
Trapminemalicious.high.ml.score
EmsisoftGen:Trojan.ShellObject.g8W@aWD2a0g (B)
IkarusBackdoor.Win32.Padodor
JiangminBackdoor.Padodor.eyaa
VaristW32/Pahador.QLFO-8537
AviraTR/Crypt.ZPACK.Gen2
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ArcabitTrojan.ShellObject.E3B4B2
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataGen:Trojan.ShellObject.g8W@aWD2a0g
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
ALYacGen:Trojan.ShellObject.g8W@aWD2a0g
MAXmalware (ai score=89)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
YandexBackdoor.Padodor.AF
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FBNK!tr
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment