Malware

What is “Generic.Dacic.D6DFC400.A.FBD39F62”?

Malware Removal

The Generic.Dacic.D6DFC400.A.FBD39F62 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Dacic.D6DFC400.A.FBD39F62 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • CAPE detected the NjRATGolden malware family
  • Creates a copy of itself
  • Creates known Njrat/Bladabindi RAT registry keys
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generic.Dacic.D6DFC400.A.FBD39F62?


File Info:

name: 355221891CBBF1FF5BC4.mlw
path: /opt/CAPEv2/storage/binaries/4790377c96e047c3a4af143e569784bef07ed4368b076f65870669e58697e247
crc32: E112BCA1
md5: 355221891cbbf1ff5bc4b9e02effc954
sha1: 9f8dfa101b1ff664194098bd9619d8998cbf05ff
sha256: 4790377c96e047c3a4af143e569784bef07ed4368b076f65870669e58697e247
sha512: 60fa45e3bcea4a8d5cc69bad255481f973306b4e4f62f2e7b28e97693d474e7c88e79d1f59e0a6871042c529e228e7082ec40f4f8883a1bed98479bc5aea96ab
ssdeep: 384:vIhqBkiyrnDNGRn5IyUv6IzfDhW/6wFbbrAF+rMRTyN/0L+EcoinblneHQM3epzM:gf5M5jUvPzQCw1rM+rMRa8NuDyt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D2032A4D7FE181A8C5FD197B05B2D41207BAE04F6E23D90E8EE564AA37636C18F50AF1
sha3_384: 218902f681ba98c6ffcb1075e4ef71a06c345e4c71a089611c547ac49eaef225e7c4e2e7c91f6db8b05bd8fff3f552ed
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-10-02 18:11:23

Version Info:

0: [No Data]

Generic.Dacic.D6DFC400.A.FBD39F62 also known as:

ElasticWindows.Trojan.Njrat
MicroWorld-eScanGeneric.Dacic.D6DFC400.A.FBD39F62
FireEyeGeneric.mg.355221891cbbf1ff
CAT-QuickHealBackdoor.Bladabindi.B3
McAfeeTrojan-FIGN
MalwarebytesGeneric.Malware.AI.DDS
VIPREGeneric.Dacic.D6DFC400.A.FBD39F62
SangforWorm.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
Cybereasonmalicious.91cbbf
BitDefenderThetaGen:NN.ZemsilF.36348.cmW@aqG@Gtl
VirITTrojan.Win32.DownLoader21.BPQW
CyrenW32/MSIL_Bladabindi.A.gen!Eldorado
SymantecBackdoor.Ratenjay!gen3
ESET-NOD32a variant of MSIL/Bladabindi.AR
APEXMalicious
ClamAVWin.Packed.Bladabindi-7994427-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.Dacic.D6DFC400.A.FBD39F62
NANO-AntivirusTrojan.Win32.Autoruner2.ebrjyu
AvastMSIL:Bladabindi-JK [Trj]
TencentTrojan.Msil.Bladabindi.fa
EmsisoftWorm.Bladabindi (A)
BaiduMSIL.Backdoor.Bladabindi.a
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.MulDrop6.40595
ZillyaTrojan.Bladabindi.Win32.72266
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.BackdoorNJRat.nm
Trapminemalicious.high.ml.score
SophosTroj/Bbindi-W
IkarusTrojan.MSIL.Bladabindi
GDataMSIL.Trojan-Spy.Bladabindi.BQ
JiangminTrojanDropper.Autoit.dce
GoogleDetected
AviraTR/ATRAPS.Gen
MAXmalware (ai score=88)
Antiy-AVLTrojan[Backdoor]/MSIL.Bladabindi.as
XcitiumTrojWare.MSIL.Spy.Agent.CP@4pqytu
ArcabitGeneric.Dacic.D6DFC400.A.FBD39F62
ViRobotBackdoor.Win32.Agent.37888.AL
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:MSIL/njRAT.RDSA!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Korat.R207428
Acronissuspicious
VBA32Trojan.MSIL.Bladabindi.Heur
ALYacGeneric.Dacic.D6DFC400.A.FBD39F62
TACHYONBackdoor/W32.DN-NjRAT.37888.B
Cylanceunsafe
PandaTrj/GdSda.A
ZonerTrojan.Win32.84773
RisingBackdoor.njRAT!1.9E49 (CLASSIC)
YandexTrojan.AvsMofer.dd6520
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Bladabindi.AS!tr
AVGMSIL:Bladabindi-JK [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Generic.Dacic.D6DFC400.A.FBD39F62?

Generic.Dacic.D6DFC400.A.FBD39F62 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment