Malware

About “Generic.MSIL.Bladabindi.19240F09” infection

Malware Removal

The Generic.MSIL.Bladabindi.19240F09 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.19240F09 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • CAPE detected the njRat malware family
  • Creates a copy of itself
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine Generic.MSIL.Bladabindi.19240F09?


File Info:

name: 5E419CD5546C73F43269.mlw
path: /opt/CAPEv2/storage/binaries/73a37471271390700aae01ecb8c0c25990bd073d1a580bd103df26e3a4a568b3
crc32: EAE44B69
md5: 5e419cd5546c73f43269ffef578aacd4
sha1: bdb5f7c9d0d988a963fd4366b66036c43869e97d
sha256: 73a37471271390700aae01ecb8c0c25990bd073d1a580bd103df26e3a4a568b3
sha512: 42eafb5faba120800300e46f94100d8af58e0876b2b296e4a6f5200573d2902c1a9603414990ded114b952f5750c402a4a2f114abf3873c50204cdb27d61ca1c
ssdeep: 384:XLfAGjjMicNPkOMrJHbKIStzJWOse0+IyaKur3HyHvHki2VzDyHvHhMkLDOHYCF6:bfAGjjMzkOwIaN6vkpVv6vNmF7Q71h
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T119E2E60537AA4703C67D03B90826471647F1CE83453BEB6F5CD9B4E91E7B7808E816AB
sha3_384: 79ea3e387438c3fd6bebfee138d3d75a6ad9434b41b6201a91d946d628d0337a4bd34cb90f499c7bab01e1fb1a15aefb
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-08-21 13:51:57

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: k.exe
LegalCopyright:
OriginalFilename: k.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Generic.MSIL.Bladabindi.19240F09 also known as:

BkavW32.AIDetectNet.01
ElasticWindows.Trojan.Njrat
MicroWorld-eScanGeneric.MSIL.Bladabindi.19240F09
FireEyeGeneric.mg.5e419cd5546c73f4
CAT-QuickHealTrojan.GenericFC.S6059376
McAfeeTrojan-FIGN
CylanceUnsafe
ZillyaWorm.Bladabindi.Win32.7859
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004b99501 )
BitDefenderGeneric.MSIL.Bladabindi.19240F09
K7GWTrojan ( 004b99501 )
Cybereasonmalicious.5546c7
BaiduMSIL.Backdoor.Bladabindi.a
VirITTrojan.Win32.Dnldr25.PBI
CyrenW32/MSIL_Agent.CP.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Autorun.Agent.LW
CynetMalicious (score: 100)
APEXMalicious
AvastMSIL:Agent-CIB [Trj]
ClamAVWin.Trojan.Generic-6417450-0
KasperskyHEUR:Trojan.Win32.Generic
RisingBackdoor.njRAT!1.D4D6 (CLASSIC)
Ad-AwareGeneric.MSIL.Bladabindi.19240F09
SophosML/PE-A + Mal/Bladabi-T
ComodoBackdoor.MSIL.Bladabindi.BSS@7pzdvl
DrWebTrojan.DownLoader25.46117
VIPREGeneric.MSIL.Bladabindi.19240F09
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionTrojan-FIGN
EmsisoftGeneric.MSIL.Bladabindi.19240F09 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Agent.aaxh
AviraTR/ATRAPS.Gen
MicrosoftBackdoor:MSIL/Bladabindi.BO
ArcabitGeneric.MSIL.Bladabindi.19240F09
SUPERAntiSpywareBackdoor.NJRat/Variant
GDataMSIL.Backdoor.Bladabindi.AV
GoogleDetected
AhnLab-V3Win-Trojan/NjRAT01.Exp
Acronissuspicious
BitDefenderThetaGen:NN.ZemsilF.34606.cm0@aaIWItp
ALYacGeneric.MSIL.Bladabindi.19240F09
MalwarebytesBladabindi.Backdoor.Njrat.DDS
TencentTrojan.Win32.Bladabindi.16000442
MAXmalware (ai score=87)
MaxSecureTrojan.Malware.121218.susgen
FortinetMSIL/Agent.LI!tr
AVGMSIL:Agent-CIB [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Generic.MSIL.Bladabindi.19240F09?

Generic.MSIL.Bladabindi.19240F09 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment