Backdoor

Should I remove “Backdoor.Bladabindi.UPX”?

Malware Removal

The Backdoor.Bladabindi.UPX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Bladabindi.UPX virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Behavioural detection: Injection (inter-process)
  • Installs itself for autorun at Windows startup
  • Attempts to bypass application whitelisting by executing .NET utility in a suspended state, potentially for injection
  • CAPE detected the njRat malware family
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine Backdoor.Bladabindi.UPX?


File Info:

name: C14A7BD21D7D0CB1F3B8.mlw
path: /opt/CAPEv2/storage/binaries/6bb37e7f4001b727f339b028ed4a9e60d6bb3d71adec6b3ca3762bdce2e47b52
crc32: DCB233B8
md5: c14a7bd21d7d0cb1f3b89bbb34ae5d76
sha1: 773c07f1d969c84b9a3514929fa457a65429757f
sha256: 6bb37e7f4001b727f339b028ed4a9e60d6bb3d71adec6b3ca3762bdce2e47b52
sha512: fe2d5b41fa50109206f7074c7978a6689c27bbb6035c20470656f9e2c55db2279f10913db35c37c6ee56aad5119aa846ff7ae6ffac8563074a9fae6c3fc3206d
ssdeep: 12288:Cu/osQMgL96w0SVvV6fcaubLH31O2lxvdJGtKcXVA/DBRSZJi5TuO:Cur9gkEPGcHHX1OSr/clYSZJkl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D0D459F871F1E279C80482716A217C7087F14CA4DDB1A915EDECF9E5D631EF62B2260A
sha3_384: c29a896cf7d4b5156545f72dc289edf3878b296d6b19aa6a4ec3d641070a3fb62430f31b20fe07dfdc3b45e3da0cd58e
ep_bytes: 60be00b04a008dbe0060f5ff57eb0b90
timestamp: 2019-08-20 01:23:48

Version Info:

Translation: 0x0809 0x04b0

Backdoor.Bladabindi.UPX also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Script.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
McAfeeArtemis!C14A7BD21D7D
CylanceUnsafe
ZillyaTrojan.AutoIT.Win32.138595
K7AntiVirusTrojan ( 0054da261 )
AlibabaTrojan:Win32/AutoitInject.7dd774fd
K7GWTrojan ( 0054da261 )
Cybereasonmalicious.21d7d0
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.AutoIt.PE
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Malware.Autoit-7130027-0
KasperskyHEUR:Trojan.Script.Generic
BitDefenderTrojan.GenericKD.32312226
MicroWorld-eScanTrojan.GenericKD.32312226
TencentWin32.Trojan.Generic.Svha
Ad-AwareTrojan.GenericKD.32312226
SophosMal/Generic-S + Mal/AuItInj-A
ComodoMalware@#3o9tqkiuq84r0
DrWebTrojan.DownLoader22.669
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.c14a7bd21d7d0cb1
EmsisoftTrojan.GenericKD.32312226 (B)
IkarusTrojan.Autoit
GDataTrojan.GenericKD.32312226
JiangminTrojanDownloader.Alien.gk
AviraTR/AD.Bladabindi.sdjyn
Antiy-AVLTrojan/Generic.ASMalwS.24825A4
ArcabitTrojan.Generic.D1ED0BA2
MicrosoftTrojan:Win32/AutoitInject.BH!MTB
AhnLab-V3Malware/Win32.RL_Generic.R288607
VBA32Trojan.Fuerboos
ALYacTrojan.MSIL.Bladabindi
MAXmalware (ai score=100)
MalwarebytesBackdoor.Bladabindi.UPX
RisingTrojan.Obfus/Autoit!1.BB81 (CLASSIC)
YandexBackdoor.Bladabindi!7ZRZkbYVkgE
MaxSecureTrojan.Malware.74524711.susgen
FortinetAutoIt/Agent.FC2A!tr
BitDefenderThetaAI:Packer.432E053817
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Backdoor.Bladabindi.UPX?

Backdoor.Bladabindi.UPX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment