Malware

Generic.MSIL.Bladabindi.274D1999 (file analysis)

Malware Removal

The Generic.MSIL.Bladabindi.274D1999 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.274D1999 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • CAPE detected the njRat malware family
  • Creates a copy of itself
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine Generic.MSIL.Bladabindi.274D1999?


File Info:

name: C0EEFCE25902B4594434.mlw
path: /opt/CAPEv2/storage/binaries/4c4d0cdd322cadc495917f8b32987392ab55f6be43a5fbf38774109920915f0b
crc32: B2242E5B
md5: c0eefce25902b459443449cf58d0e0da
sha1: a3d821969f40e89622b10e9fc080673c5068eeaa
sha256: 4c4d0cdd322cadc495917f8b32987392ab55f6be43a5fbf38774109920915f0b
sha512: 7b267f77385736828b4ccfb7e2325d83cf076997a48a36caf04ed442db27b5ccccf82d66e4f67222c605350294630c8e1d358442a86dc6e8bdaf643f2a6ff981
ssdeep: 384:rdMKFYuEEhERvoBG16Xuy0MHNw6Tg1Y+75JTFmRvR6JZlbw8hqIusZzZpG:rmW4V6+yDRpcnu/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FEB23A0E3FA98856C5BC1B7086A5965003B491870413EE2FCDC564CBAFB3BD92D4CAF9
sha3_384: fc96c311d3f9ba44ce225fd500c8492e4b9fc697b0d96b9f5c201b30a404b962d7eb2187277a8e19786846722adfa4e4
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-06-03 13:16:53

Version Info:

0: [No Data]

Generic.MSIL.Bladabindi.274D1999 also known as:

BkavW32.FamVT.binANHb.Worm
LionicTrojan.Win32.Generic.mAmC
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.MSIL.Bladabindi.274D1999
FireEyeGeneric.mg.c0eefce25902b459
CAT-QuickHealBackdoor.Bladabindi.AL3
McAfeeTrojan-FIGN
CylanceUnsafe
ZillyaBackdoor.Agent.Win32.55242
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
Cybereasonmalicious.25902b
BitDefenderThetaGen:NN.ZemsilF.34084.bmW@aKt09c
CyrenW32/MSIL_Bladabindi.AU.gen!Eldorado
SymantecBackdoor.Ratenjay
ESET-NOD32MSIL/Bladabindi.BC
BaiduMSIL.Backdoor.Bladabindi.a
TrendMicro-HouseCallBKDR_BLADABI.SMC
Paloaltogeneric.ml
ClamAVWin.Dropper.njRAT-7436651-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.MSIL.Bladabindi.274D1999
NANO-AntivirusTrojan.Win32.Disfa.dtznyx
AvastMSIL:Agent-DRD [Trj]
TencentWin32.Trojan.Generic.Syru
Ad-AwareGeneric.MSIL.Bladabindi.274D1999
EmsisoftTrojan.Bladabindi (A)
ComodoBackdoor.MSIL.Bladabindi.A@566ygc
DrWebTrojan.DownLoader23.12367
VIPREBackdoor.MSIL.Bladabindi.a (v)
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.Trojan.mm
SophosML/PE-A + Troj/DotNet-P
IkarusTrojan.MSIL.Bladabindi
GDataMSIL.Backdoor.Bladabindi.AV
JiangminTrojanDropper.Autoit.dce
AviraBDS/Bladabindi.uppj
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASBOL.A8F4
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Bladabindi.sa
ArcabitGeneric.MSIL.Bladabindi.274D1999
ViRobotBackdoor.Win32.Bladabindi.Gen.A
APEXMalicious
MicrosoftBackdoor:MSIL/Bladabindi
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Bladabindi.R91438
Acronissuspicious
VBA32Trojan.MSIL.Disfa
ALYacGeneric.MSIL.Bladabindi.274D1999
MalwarebytesBackdoor.NJRat
RisingBackdoor.Njrat!1.9E49 (CLASSIC)
YandexTrojan.Agent!ALulVOXZjgg
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetMSIL/Agent.LI!tr
AVGMSIL:Agent-DRD [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Generic.MSIL.Bladabindi.274D1999?

Generic.MSIL.Bladabindi.274D1999 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment