Malware

What is “Generic.MSIL.Bladabindi.04FC379E”?

Malware Removal

The Generic.MSIL.Bladabindi.04FC379E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.04FC379E virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • CAPE detected the njRat malware family
  • Creates a copy of itself
  • Creates known Njrat/Bladabindi RAT registry keys
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.MSIL.Bladabindi.04FC379E?


File Info:

name: 42123E56F14A3C35C070.mlw
path: /opt/CAPEv2/storage/binaries/52ec28bb1ceabd132afa04f7d3af4f70f29dff31fb4ce49bbaa2afef0b6cb6df
crc32: BD7CE8E5
md5: 42123e56f14a3c35c07046c43e623d26
sha1: 73fd0c633f40a038458a93aff21cf271a2988a90
sha256: 52ec28bb1ceabd132afa04f7d3af4f70f29dff31fb4ce49bbaa2afef0b6cb6df
sha512: a3669676425b922bfd53fff6561701b01a488e89df7f65767bac35728ac9688f962e666bf95cffd2af3fd9f78689fcf4f03d9878dde7249f1ef5ad93e381b62b
ssdeep: 384:CvmK3hUidksXR21cGMy8PIU5fHkFlacpMrAF+rMRTyN/0L+EcoinblneHQM3epz6:omK3bLGv8PIU58KcarM+rMRa8NuL8t
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T191033A4D7FE18168D5FD067B05B2D41307BAE04B6E23D90E8EE164AA37636C18B50EF2
sha3_384: beb28c888435a00b6efd307fc3e9ea099ebb4e8898056b21bfad9c2694b77dbd8f59ed97261cdddbae8a6f95f607d1d5
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-08-06 14:57:22

Version Info:

0: [No Data]

Generic.MSIL.Bladabindi.04FC379E also known as:

BkavW32.AIDetectNet.01
MicroWorld-eScanGeneric.MSIL.Bladabindi.04FC379E
CAT-QuickHealBackdoor.Bladabindi.B3
ALYacGeneric.MSIL.Bladabindi.04FC379E
MalwarebytesBackdoor.NJRat
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
BitDefenderGeneric.MSIL.Bladabindi.04FC379E
K7GWTrojan ( 700000121 )
Cybereasonmalicious.6f14a3
BitDefenderThetaGen:NN.ZemsilF.34582.cmW@aG2ey7f
VirITTrojan.Win32.DownLoader21.BPQW
SymantecBackdoor.Ratenjay!gen3
ElasticWindows.Trojan.Njrat
ESET-NOD32a variant of MSIL/Bladabindi.AR
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Autoruner2.ebrjyu
AvastMSIL:Bladabindi-JK [Trj]
Ad-AwareGeneric.MSIL.Bladabindi.04FC379E
ComodoTrojWare.MSIL.Spy.Agent.CP@4pqytu
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.MulDrop6.47155
VIPREGeneric.MSIL.Bladabindi.04FC379E
TrendMicroBKDR_BLADABI.SMC
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.42123e56f14a3c35
SophosML/PE-A + Troj/Bbindi-W
JiangminTrojanDropper.Autoit.dce
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan/Generic.ASBOL.A8F4
ViRobotBackdoor.Win32.Agent.37888.AL
ZoneAlarmHEUR:Trojan-Spy.MSIL.KeyLogger.gen
GDataMSIL.Trojan-Spy.Bladabindi.BQ
TACHYONTrojan/W32.DN-Agent.37888.BN
AhnLab-V3Trojan/Win32.Korat.R207428
Acronissuspicious
VBA32Trojan.Downloader
MAXmalware (ai score=81)
TencentTrojan.Msil.Bladabindi.fa
YandexTrojan.AvsMofer.dd6520
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Bladabindi.AS!tr
AVGMSIL:Bladabindi-JK [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Generic.MSIL.Bladabindi.04FC379E?

Generic.MSIL.Bladabindi.04FC379E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment