Backdoor

Backdoor.MSIL.Bladabindi.brgs (file analysis)

Malware Removal

The Backdoor.MSIL.Bladabindi.brgs is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.MSIL.Bladabindi.brgs virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Possible date expiration check, exits too soon after checking local time
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • CAPE detected the EnigmaStub malware family
  • Creates a copy of itself
  • Creates known Njrat/Bladabindi RAT registry keys
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Backdoor.MSIL.Bladabindi.brgs?


File Info:

name: 42ECD3BC15F554A5A820.mlw
path: /opt/CAPEv2/storage/binaries/3246f932f66741263b3cdd54b9e0e2c98bfbcda92a9b17dbb4740f031b138740
crc32: F585FD01
md5: 42ecd3bc15f554a5a820da3ec485b3a5
sha1: df4ac3620ed9d8bd36c667f90068c79d9d2d0d83
sha256: 3246f932f66741263b3cdd54b9e0e2c98bfbcda92a9b17dbb4740f031b138740
sha512: f2412a7aca9cade4b11bed50f77d44c5db50c0625284777cb01d67a7b00dce073184ecf27b20a1e3628609059d1e237b9c763e5fd9cc01d3c453b311c9a5ad98
ssdeep: 24576:BwtlMt4QlOYagLazet2TXnQCul5daMwJVk91IQ8ISQer4:cStvYg1t2znm5oMwJVk9T8F4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T150353388E3C7A4C8FAF906B61C2B5E3F2FB6260F15D48F5523809C617891C77E45768A
sha3_384: d308a0e21e8d6c1dc1403fb10a9d19d06512da8caec9f846acfe7014fb8fcacaf8777af748a3b28eb3f21a8cb010a568
ep_bytes: 558bec83c4f0b800104000e801000000
timestamp: 2021-11-27 14:10:21

Version Info:

0: [No Data]

Backdoor.MSIL.Bladabindi.brgs also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38131960
FireEyeGeneric.mg.42ecd3bc15f554a5
ALYacTrojan.GenericKD.38131960
MalwarebytesBackdoor.Bladabindi
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaBackdoor:MSIL/Bladabindi.5afeb73b
K7GWTrojan ( 005835da1 )
K7AntiVirusTrojan ( 005835da1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.EnigmaProtector.J suspicious
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Enigmaprotector-9837396-0
KasperskyBackdoor.MSIL.Bladabindi.brgs
BitDefenderTrojan.GenericKD.38131960
Ad-AwareTrojan.GenericKD.38131960
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0DKR21
EmsisoftTrojan.GenericKD.38131960 (B)
IkarusPUA.EnigmaProtector
AviraHEUR/AGEN.1128047
Antiy-AVLTrojan/Generic.ASBOL.C669
GridinsoftRansom.Win32.Bladabindi.sa
MicrosoftBackdoor:MSIL/Bladabindi.AJ
GDataTrojan.GenericKD.38131960
CynetMalicious (score: 100)
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34062.arW@aG@H0ff
MAXmalware (ai score=86)
VBA32BScope.Trojan.Inject
TrendMicro-HouseCallTROJ_GEN.R002C0DKR21
RisingPUF.Pack-Enigma!1.BA33 (CLASSIC)
YandexBackdoor.Bladabindi!5wXpj0AkRuc
SentinelOneStatic AI – Malicious PE
FortinetRiskware/Application
Cybereasonmalicious.20ed9d
PandaTrj/Genetic.gen

How to remove Backdoor.MSIL.Bladabindi.brgs?

Backdoor.MSIL.Bladabindi.brgs removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment