Backdoor

Backdoor:MSIL/Bladabindi.AP (file analysis)

Malware Removal

The Backdoor:MSIL/Bladabindi.AP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:MSIL/Bladabindi.AP virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor:MSIL/Bladabindi.AP?


File Info:

crc32: 02FB4E5B
md5: 541dce93da456fd7830cda46a9d07941
name: fontdrvhost.exe
sha1: b08b3bfd5556f18b8c696925146985a86ee72fdd
sha256: 3b8c6f0033980eed8f86a029be14ff32c32f535c4bdaeb5c5f857236722ac9c8
sha512: 6d2164e340691b2ba8cba81979d7fe403739290a583fdeaee7ead5c9b94bc5e0d025d1943df559e1a01ea2e700aa2513c7ad8bd742524d2370c54d644769a3e2
ssdeep: 768:6qJsK/jerpoJwbkhRc++Y1lzWTjX/2KzyzN6cYRw1g9JX4h7f5LYZ/SJkpvLIq0:6gwrpoyqRcmWTj+KzyzQRw1gvXo6ZfL
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Backdoor:MSIL/Bladabindi.AP also known as:

MicroWorld-eScanGen:Variant.Razy.53678
FireEyeGeneric.mg.541dce93da456fd7
McAfeeBackDoor-FDNN!541DCE93DA45
ALYacGen:Variant.Razy.53678
CylanceUnsafe
ZillyaTrojan.Bladabindi.Win32.108762
SangforMalware
K7AntiVirusTrojan ( 700000121 )
BitDefenderGen:Variant.Razy.53678
K7GWTrojan ( 700000121 )
CrowdStrikewin/malicious_confidence_100% (W)
Invinceaheuristic
BaiduMSIL.Backdoor.Bladabindi.a
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Malware.Genkryptik-6860402-0
GDataGen:Variant.Razy.53678
KasperskyHEUR:Trojan.MSIL.Crypt.gen
AlibabaBackdoor:MSIL/Bladabindi.8b7f9447
NANO-AntivirusTrojan.Win32.Crypt.gfvnzu
AegisLabTrojan.MSIL.Crypt.4!c
RisingBackdoor.MSIL.Bladabindi!1.9E49 (CLOUD)
Endgamemalicious (high confidence)
SophosTroj/Bbindi-W
F-SecureTrojan.TR/Spy.Gen8
DrWebBackDoor.BladabindiNET.1
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DK419
McAfee-GW-EditionBehavesLike.Win32.Generic.ph
MaxSecureTrojan.Malware.300983.susgen
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Razy.53678 (B)
IkarusTrojan.MSIL.Bladabindi
CyrenW32/Trojan.TELI-2661
JiangminTrojan.MSIL.niba
AviraTR/Spy.Gen8
MAXmalware (ai score=88)
ArcabitTrojan.Razy.DD1AE
ZoneAlarmHEUR:Trojan.MSIL.Crypt.gen
MicrosoftBackdoor:MSIL/Bladabindi.AP
AhnLab-V3Trojan/Win32.RL_Generic.C3550050
Acronissuspicious
Ad-AwareGen:Variant.Razy.53678
MalwarebytesBackdoor.Bladabindi
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Bladabindi.AS
TrendMicro-HouseCallTROJ_GEN.R002C0DK419
TencentWin32.Trojan.Spy.Ssqv
YandexTrojan.Crypt!/3Y9vcIQ2zk
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetMSIL/Bbindi.AS!tr
BitDefenderThetaGen:NN.ZemsilF.34090.cmW@aCYrq7d
AVGWin32:Trojan-gen
Cybereasonmalicious.3da456
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.21a

How to remove Backdoor:MSIL/Bladabindi.AP?

Backdoor:MSIL/Bladabindi.AP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment