Backdoor

Backdoor:Win32/Padodor.SK!MTB (file analysis)

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: 16C4FAA50F24D1F0D49F.mlw
path: /opt/CAPEv2/storage/binaries/c3e9fc2db2a663c6004631e4b19260308832c05319b15c1cefe73b9aace6bf90
crc32: EE5A8B3F
md5: 16c4faa50f24d1f0d49fb051c764faf8
sha1: f9832630bcaff98b6bedf37a4ce127171ae24cec
sha256: c3e9fc2db2a663c6004631e4b19260308832c05319b15c1cefe73b9aace6bf90
sha512: c49d99e51308e3940e899bb6f3b0aab5396083ab14e0353e26d1efdc2dbcddb05b9031fac15f28f3b255dcd9d83efb13eba7ca3ce8bc984a6e1acf332df00b1b
ssdeep: 1536:O/GXmhnQD46pMGXK0VlalvxG7fxDzgiPT8sRQTRkRLJzeLD9N0iQGRNQR8RyV+3K:Ozn2m6lalvxG7f9zgiPT7eTSJdEN0s4X
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F8939EBB22D45FE7EA6005F16257D4C67227DC76013B8680406BC11EE3FBE6C8D7AA49
sha3_384: 211d0c72ff935e7bb303b8791e50139a17b421220638126d27bc999c3ac8c0cd876ce095fb2c8e8099d775caacbef3fd
ep_bytes: 90909090b800104000bbd0c7400090b9
timestamp: 2017-10-15 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGenPack:Trojan.Agent.DQQO
CAT-QuickHealBackdoor.Padodor
SkyhighBehavesLike.Win32.Generic.nc
McAfeeGenericRXHD-SL!684A55CC9557
Cylanceunsafe
VIPREGenPack:Trojan.Agent.DQQO
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderGenPack:Trojan.Agent.DQQO
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.0bcaff
BitDefenderThetaAI:Packer.2ABBEDA021
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.NAM
APEXMalicious
ClamAVWin.Trojan.Qukart-10012701-0
KasperskyBackdoor.Win32.Padodor.gen
NANO-AntivirusTrojan.Win32.Padodor.foufls
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebBackDoor.HangUp.5
ZillyaTrojan.Padodor.Win32.1675578
TrendMicroTROJ_GEN.R03BC0DJQ23
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.16c4faa50f24d1f0
EmsisoftGenPack:Trojan.Agent.DQQO (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=82)
JiangminBackdoor.Padodor.ewpp
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
VaristW32/Pahador.QLFO-8537
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ArcabitGenPack:Trojan.Agent.DQQO
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataGenPack:Trojan.Agent.DQQO
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
ALYacGenPack:Trojan.Agent.DQQO
TACHYONBackdoor/W32.Padodor
DeepInstinctMALICIOUS
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DJQ23
TencentBackdoor.Win32.Padodor.kg
YandexBackdoor.Padodor.AF
IkarusBackdoor.Win32.Padodor
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FBNK!tr
AVGWin32:BackdoorX-gen [Trj]
AvastWin32:BackdoorX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment