Backdoor

Backdoor:MSIL/Bladabindi.OP information

Malware Removal

The Backdoor:MSIL/Bladabindi.OP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:MSIL/Bladabindi.OP virus can do?

  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • ‘Google Drive’ in HTML Title but connection is not HTTPS. Possibly indicative of phishing.
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Turkish
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

xred.mooo.com
freedns.afraid.org
ocsp.pki.goog

How to determine Backdoor:MSIL/Bladabindi.OP?


File Info:

crc32: ADC389AB
md5: 3e1d6ff8af7bfaa074aef28d195f0a57
name: krnl_bootstrapper.exe
sha1: 45cb16be316cc3f805197e851f205465eb023128
sha256: 0e6ae4a6931e69708c66765e6862585da75b345cc13d1239720fe8dc9f75fe22
sha512: 4a8d4612a60e0d34affc37517e6f58542928a0e7b32fca81c0b62c63b69e5302c1f7cde3a07a2d418d76b8eb86ed2cdc17da53f11218c1fd2624ef311490ad6d
ssdeep: 12288:gMSApJVYG5lDLyjsb0eOzkv4R7QnvUUilQ35+6G75V9Gdqvj:gnsJ39LyjbJkQFMhmC+6GD9mq7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.0.0.4
CompanyName: Synaptics
LegalTrademarks:
Comments:
ProductName: Synaptics Pointing Device Driver
ProductVersion: 1.0.0.0
FileDescription: Synaptics Pointing Device Driver
OriginalFilename:
Translation: 0x041f 0x04e6

Backdoor:MSIL/Bladabindi.OP also known as:

BkavW32.AIDetectVM.malware
DrWebTrojan.DownLoader22.9658
MicroWorld-eScanDropped:Trojan.GenericKD.33822205
CAT-QuickHealSus.Nocivo.E0011
McAfeeGenericRXCB-VC!3E1D6FF8AF7B
CylanceUnsafe
VIPREBehavesLike.Win32.Malware.eah (mx-v)
AegisLabTrojan.Win32.DarkKomet.tp6k
SangforMalware
BitDefenderDropped:Trojan.GenericKD.33822205
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
ArcabitHEUR.VBA.Trojan.d
Invinceaheuristic
BitDefenderThetaAI:Packer.F5AF03D517
CyrenW32/Backdoor.OAZM-5661
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Delf.NBX
ZonerTrojan.Win32.88102
TrendMicro-HouseCallVirus.Win32.NAPWHICH.B
Paloaltogeneric.ml
ClamAVWin.Malware.Delf-6899401-0
KasperskyBackdoor.Win32.DarkKomet.hqxy
AlibabaBackdoor:Win32/DarkKomet.131
NANO-AntivirusTrojan.Win32.DarkKomet.fazbwq
RisingBackdoor.Agent!1.BF3D (CLOUD)
Ad-AwareDropped:Trojan.GenericKD.33822205
EmsisoftDropped:Trojan.GenericKD.33822205 (B)
ComodoVirus.Win32.Agent.DE@74b38h
F-SecureTrojan:W97M/MaliciousMacro.GEN
ZillyaTrojan.Delf.Win32.76144
TrendMicroVirus.Win32.NAPWHICH.B
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.3e1d6ff8af7bfaa0
SophosMal/Generic-S
IkarusTrojan-PWS.Win32.QQPass
F-ProtW32/Zorex.A
JiangminTrojan.Generic.bhoqf
WebrootW32.Malware.gen
AviraWORM/Dldr.Agent.gqrxn
FortinetW32/Delf.NBX!tr
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (high confidence)
MicrosoftBackdoor:MSIL/Bladabindi.OP
SUPERAntiSpywareAdware.FileTour/Variant
ZoneAlarmBackdoor.Win32.DarkKomet.hqxy
AhnLab-V3Win32/Zorex.X1799
Acronissuspicious
VBA32TScope.Trojan.Delf
ALYacDropped:Trojan.GenericKD.33822205
MAXmalware (ai score=81)
MalwarebytesTrojan.Agent
PandaTrj/Genetic.gen
APEXMalicious
TencentVirus.Win32.DarkKomet.a
YandexRiskware.GameHack!
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
GDataDropped:Trojan.GenericKD.33822205
MaxSecureTrojan.Malware.121218.susgen
AVGOther:Malware-gen [Trj]
AvastOther:Malware-gen [Trj]
Qihoo-360Win32/Virus.Synaptics.A

How to remove Backdoor:MSIL/Bladabindi.OP?

Backdoor:MSIL/Bladabindi.OP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment