Backdoor

Backdoor.Bladabindi.Enigma (file analysis)

Malware Removal

The Backdoor.Bladabindi.Enigma is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Bladabindi.Enigma virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Checks for the presence of known windows from debuggers and forensic tools
  • A process was set to shut the system down when terminated
  • Installs itself for autorun at Windows startup
  • Checks for the presence of known devices from debuggers and forensic tools
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Backdoor.Bladabindi.Enigma?


File Info:

crc32: FA94D05C
md5: 45b373ced7450861037af028411f1d8a
name: 45B373CED7450861037AF028411F1D8A.mlw
sha1: 28ec29af913ff03ca829abc0ffdafbfa6fa74b72
sha256: 919022b4d48980a56a1805f80646201ae7312cdf64891c3ac591e7eb33a96973
sha512: fd18c97d3216928a077aca31b2ca1a80ee78cf674b4b2adedc6073fcb2199f6f79b64f2f981c9f4fff0bf31a6d7fdb388a78487629d175980dabbb29d8bdb05b
ssdeep: 24576:7iAJkN5ELePHAzK7hsuVDHEODvO37yWsRssinZ864:77LePHAzKr79Dvk7yWsRssinZ8Z
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.Bladabindi.Enigma also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop16.12221
MicroWorld-eScanTrojan.GenericKD.36417999
FireEyeGeneric.mg.45b373ced7450861
ALYacTrojan.GenericKD.36417999
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.36417999
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.f913ff
BitDefenderThetaGen:NN.ZexaF.34590.ezW@au2dFbo
CyrenW32/Trojan.FFG.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packed.Disfa-9774865-0
KasperskyBackdoor.Win32.Bladabindi.kj
AlibabaPacked:Win32/Enigma.efac2f0a
RisingPUF.Pack-Enigma!1.BA33 (CLOUD)
Ad-AwareTrojan.GenericKD.36417999
EmsisoftTrojan.GenericKD.36417999 (B)
F-SecureHeuristic.HEUR/AGEN.1138849
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKD.36417999
MaxSecureTrojan.Malware.300983.susgen
AviraHEUR/AGEN.1138849
KingsoftWin32.Heur.KVMH008.a.(kcloud)
GridinsoftTrojan.Heur!.030120A1
ArcabitTrojan.Generic.D22BB1CF
ZoneAlarmBackdoor.Win32.Bladabindi.kj
MicrosoftBackdoor:MSIL/Bladabindi.AP
CynetMalicious (score: 100)
McAfeeArtemis!45B373CED745
MAXmalware (ai score=89)
VBA32Trojan.Zpevdo
MalwarebytesBackdoor.Bladabindi.Enigma
ESET-NOD32a variant of Win32/Packed.Enigma.AK
TrendMicro-HouseCallTROJ_GEN.R002H01BQ21
TencentWin32.Backdoor.Bladabindi.Pdwd
IkarusTrojan-Dropper.MSIL.Agent
eGambitUnsafe.AI_Score_99%
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Generic.HxIBjJoA

How to remove Backdoor.Bladabindi.Enigma?

Backdoor.Bladabindi.Enigma removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment