Backdoor

Dropped:Backdoor.Padodor.BJ (file analysis)

Malware Removal

The Dropped:Backdoor.Padodor.BJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Backdoor.Padodor.BJ virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Dropped:Backdoor.Padodor.BJ?


File Info:

name: 283BB6917BAD7CB86731.mlw
path: /opt/CAPEv2/storage/binaries/6e795e6809a1f217a85e2d008298254edb0b1c0e20b0b3c8667d3d64f1fd856f
crc32: 5F1D52EF
md5: 283bb6917bad7cb867319cef90558e96
sha1: e60136016f4d8f6a11d9d2982100eb905c4aec36
sha256: 6e795e6809a1f217a85e2d008298254edb0b1c0e20b0b3c8667d3d64f1fd856f
sha512: d120c2b9a20eca866a260c00d1c78923aa63118813be3ea2ed359c12a48682e1104112459c178d12818cfb1adc2db4e3079860be1f41d6d67b5b7b0119b86a5c
ssdeep: 768:hOnMQ/YubOGUVlmBvv47ywOJ9g9ZtUxVNdgX6/s1Vdwb/1H5URXdnhgdwQU3bIEW:EMlmO7H9ZtUJd/sipUZrI1jHJZrR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17083494B6E614F62F9490FF6711B5E92A11E837F3176C2CC686CF18C0327A684EAD784
sha3_384: 9d7fcbb839196da2ad077810ee55de4780dc8599832fdb37be00e8af6f93f6937bd69d8b31fe3452ed06b9292b3f6053
ep_bytes: 6067e8000000009090909058909005aa
timestamp: 2014-05-31 22:06:51

Version Info:

0: [No Data]

Dropped:Backdoor.Padodor.BJ also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanDropped:Backdoor.Padodor.BJ
ClamAVWin.Malware.Convagent-10013337-0
FireEyeGeneric.mg.283bb6917bad7cb8
CAT-QuickHealBackdoor.Berbew.A6.MUE
SkyhighBehavesLike.Win32.Generic.lh
McAfeeGenericRXVP-YB!283BB6917BAD
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.PadodorGen.Win32.1
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.16f4d8
BitDefenderThetaAI:Packer.FFE9BACD21
VirITWorm.Win32.Berbew.G
SymantecBackdoor.Berbew.F
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Padodor.NAX
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Proxy.Win32.Qukart.gen
BitDefenderDropped:Backdoor.Padodor.BJ
NANO-AntivirusTrojan.Win32.Qukart.fokxzm
AvastWin32:TrojanX-gen [Trj]
TACHYONBackdoor/W32.Padodor
EmsisoftDropped:Backdoor.Padodor.BJ (B)
BaiduWin32.Trojan-Spy.Quart.a
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.HangUp.43791
VIPREDropped:Backdoor.Padodor.BJ
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.11RRK8R
JiangminTrojanProxy.Qukart.hveo
GoogleDetected
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
ArcabitBackdoor.Padodor.BJ
ZoneAlarmTrojan-Proxy.Win32.Qukart.gen
MicrosoftBackdoor:Win32/Berbew.AA!MTB
VaristW32/Kryptik.JEE.gen!Eldorado
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32BScope.Backdoor.Berbew
ALYacDropped:Backdoor.Padodor.BJ
MAXmalware (ai score=89)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
IkarusTrojan-Spy.Win32.Qukart
FortinetW32/Qukart.A!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Dropped:Backdoor.Padodor.BJ?

Dropped:Backdoor.Padodor.BJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment