Malware

Generic.MSIL.Bladabindi.134BC148 information

Malware Removal

The Generic.MSIL.Bladabindi.134BC148 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.134BC148 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • CAPE detected the njRat malware family
  • Creates a copy of itself
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine Generic.MSIL.Bladabindi.134BC148?


File Info:

name: E607E4F0F449946EA534.mlw
path: /opt/CAPEv2/storage/binaries/cdfd8ea2e3b8193edf4148c6ada4bbf6860d8c321c461f404196e4459e834034
crc32: 9B58C65C
md5: e607e4f0f449946ea53433cb1075026c
sha1: 677a2502ce5d3df95ef8d55c58f4cc2624ebf0ae
sha256: cdfd8ea2e3b8193edf4148c6ada4bbf6860d8c321c461f404196e4459e834034
sha512: 14535a0f10eca49c8ed907fbdcb915f0cea3eb3884bba04f59f03b0f7b96eb7e66c504bd38bbfdbd66b75adf18cf571cc918bd703fb527ba6b5a8bd69f603770
ssdeep: 384:eYmdk8XvCJrQLdRGSiEYF7Y65gPyx6BDXNRmRvR6JZlbw8hqIusZzZ+lw:BwWkti/aeRpcnuW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T110B21A0E3FA98866D46C17B48AA59A5003B091470423EF2FCDD554CBAFB36D92D4CAF9
sha3_384: 1df513dac9f7886266c2dac467ba488dce6a9b7f06daaf669f5e7f46b0f62c784fe8146a1285677889c5bfd610b2afed
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-07-16 17:27:55

Version Info:

0: [No Data]

Generic.MSIL.Bladabindi.134BC148 also known as:

BkavW32.FamVT.binANHb.Worm
DrWebTrojan.DownLoader22.55152
MicroWorld-eScanGeneric.MSIL.Bladabindi.134BC148
FireEyeGeneric.mg.e607e4f0f449946e
CAT-QuickHealTrojan.Generic.TRFH5
McAfeeTrojan-FIGN
CylanceUnsafe
VIPREGeneric.MSIL.Bladabindi.134BC148
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
Cybereasonmalicious.0f4499
BitDefenderThetaGen:NN.ZemsilF.34786.bmW@a8qC9@n
VirITBackdoor.Win32.Generic.AWM
CyrenW32/MSIL_Bladabindi.AU.gen!Eldorado
SymantecBackdoor.Ratenjay
ElasticWindows.Trojan.Njrat
ESET-NOD32MSIL/Bladabindi.BC
APEXMalicious
ClamAVWin.Packed.Generic-9795615-0
KasperskyTrojan.MSIL.Disfa.bqd
BitDefenderGeneric.MSIL.Bladabindi.134BC148
NANO-AntivirusTrojan.Win32.Disfa.dtznyx
AvastMSIL:Agent-DRD [Trj]
TencentTrojan.Msil.Bladabindi.za
Ad-AwareGeneric.MSIL.Bladabindi.134BC148
ComodoBackdoor.MSIL.Bladabindi.A@566ygc
BaiduMSIL.Backdoor.Bladabindi.a
ZillyaBackdoor.Agent.Win32.55233
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.BackdoorNJRat.mm
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.Bladabindi (A)
SentinelOneStatic AI – Malicious PE
GDataMSIL.Backdoor.Bladabindi.AV
JiangminTrojanDropper.Autoit.dce
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen7
Antiy-AVLTrojan/Generic.ASBOL.A8F4
ArcabitGeneric.MSIL.Bladabindi.134BC148
ViRobotBackdoor.Win32.Bladabindi.Gen.A
MicrosoftBackdoor:MSIL/Bladabindi
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Bladabindi.R91438
Acronissuspicious
VBA32Trojan.MSIL.Disfa
ALYacGeneric.MSIL.Bladabindi.134BC148
MAXmalware (ai score=85)
MalwarebytesBladabindi.Backdoor.Njrat.DDS
TrendMicro-HouseCallBKDR_BLBINDI.SMN
RisingBackdoor.njRAT!1.9E49 (CLASSIC)
YandexTrojan.Bladabindi!1GApeSwcQ1s
IkarusTrojan.MSIL.Bladabindi
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.LI!tr
AVGMSIL:Agent-DRD [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Generic.MSIL.Bladabindi.134BC148?

Generic.MSIL.Bladabindi.134BC148 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment