Backdoor.Win32.ShadowPad.a was injected as Encrypted Payload by Cyber Criminals. Attacker origin might be China which is Predicted by same attack were used in another malware like PlugX and Winnti. Backdoor will be Activated only when it received a special packet from Command & Control Server. It has an ability to Transfer only basic information such as computer, domain and user names and every 8 hours it uses to send this information. The C&C DNS server in return sends back the decryption key.”]
Source: https://gbhackers.com/server-management-software-infected-by-backdoor/

