Backdoor

About “Backdoor:Win32/Padodor.SK!MTB” infection

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: A37BE88786BFFBEC82D7.mlw
path: /opt/CAPEv2/storage/binaries/7ad42fe182a8f3273e05f4518bfdd5d37f8655d5b7a9937f90347fe3bce6ab20
crc32: BF4E9BAB
md5: a37be88786bffbec82d7da83de23e2ab
sha1: 08faa969a0f0fe8a769cd443cb5d0c4b977b6f6f
sha256: 7ad42fe182a8f3273e05f4518bfdd5d37f8655d5b7a9937f90347fe3bce6ab20
sha512: 0fec3d23b61d550bc99b87d3355741bea2a1a20fb57de5396fb934107eee8a0e7ba535647063fefe8226292fe2243db48c77512279361e87212d7df8caa495d2
ssdeep: 1536:Zl9/Vk1t5cKCZDUnwppWZfQOfVn/0YtaDfrDA4sRQqRkRLJzeLD9N0iQGRNQR8RW:ZzV0tbCJUnwpIZ4OfV/JtaDKeqSJdENa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T164A38DCF2DC81FB1F999077F2827987A5265D379D7E98990302C81EE220BA5CB1776C1
sha3_384: 6e241f7078054558cef8f9bee0ea0ac1feee8b7164b097a3a8c9d1e10cb80e45c21cf29262d1fab8d17a14297b5174d6
ep_bytes: 90b800104000909090906a0490909090
timestamp: 2017-10-15 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ShellObject.g8X@ait5o7p
SkyhighBehavesLike.Win32.Generic.nc
ALYacGen:Trojan.ShellObject.g8X@ait5o7p
Cylanceunsafe
VIPREGen:Trojan.ShellObject.g8X@ait5o7p
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaBackdoor:Win32/Padodor.7106f116
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.ShellObject.ED118AC
VirITWin32.Padodor.V
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.NAM
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.g8X@ait5o7p
NANO-AntivirusTrojan.Win32.Padodor.foufls
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
TACHYONBackdoor/W32.Padodor
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebBackDoor.HangUp.5
ZillyaTrojan.QukartGen.Win32.2
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.a37be88786bffbec
EmsisoftGen:Trojan.ShellObject.g8X@ait5o7p (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.eybl
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.1G33IXO
VaristW32/Pahador.QLFO-8537
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeArtemis!A37BE88786BF
MAXmalware (ai score=89)
DeepInstinctMALICIOUS
VBA32Backdoor.Padodor
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TencentBackdoor.Win32.Padodor.kg
YandexBackdoor.Padodor.AF
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FBNK!tr
BitDefenderThetaAI:Packer.09E7810F21
AVGWin32:BackdoorX-gen [Trj]
Cybereasonmalicious.786bff
AvastWin32:BackdoorX-gen [Trj]
alibabacloudVirTool:Win/Obfuscate.FakeEp.DYN(dyn)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment