Malware

Generic.MSIL.Bladabindi.3478D649 removal

Malware Removal

The Generic.MSIL.Bladabindi.3478D649 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.3478D649 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • CAPE detected the njRat malware family
  • Creates a copy of itself
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine Generic.MSIL.Bladabindi.3478D649?


File Info:

name: 1206BA30F0B4682A3CA4.mlw
path: /opt/CAPEv2/storage/binaries/8bbc3a08e090f5c71dd1ccf4f748a55ff44f939d887b377441dfb0db73fa7c99
crc32: 4BE1245B
md5: 1206ba30f0b4682a3ca447655990c2d6
sha1: cca66e64a6c9f36a02e3ef6b6e3735208610d9cc
sha256: 8bbc3a08e090f5c71dd1ccf4f748a55ff44f939d887b377441dfb0db73fa7c99
sha512: 18fd7cc2ecf1565967a3c5e999e5445276da4002f0488316cc0a61f540db585cc5d5377c2567e2b3e33979b17bf68e42fb4de2966763060a3239f9d37ee0a391
ssdeep: 384:G3gexUw/L+JrgUon5b9uSDMwT9Pfg6NgrWoBYi51mRvR6JZlbw8hqIusZzZIj1:wIAKG91DP1hPRpcnuh1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11AB22B4E3FA98866C5BC1B748AA5965003B491470423EE2FCDC554CBAFB3BD91D4CAF8
sha3_384: 7022622b2ab26886a79cb4efac0a44ee40ef0d124fc84c7b7800c340dd22542ddbdc260582f29db9f481e8ebbd793297
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-06-29 05:33:43

Version Info:

0: [No Data]

Generic.MSIL.Bladabindi.3478D649 also known as:

BkavW32.FamVT.binANHb.Worm
ElasticWindows.Trojan.Njrat
MicroWorld-eScanGeneric.MSIL.Bladabindi.3478D649
FireEyeGeneric.mg.1206ba30f0b4682a
CAT-QuickHealTrojan.Generic.TRFH5
ALYacGeneric.MSIL.Bladabindi.3478D649
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
Cybereasonmalicious.0f0b46
BitDefenderThetaGen:NN.ZemsilF.34742.bmX@aqyLIko
VirITBackdoor.Win32.Generic.AWM
CyrenW32/MSIL_Bladabindi.AU.gen!Eldorado
SymantecBackdoor.Ratenjay
tehtrisGeneric.Malware
ESET-NOD32MSIL/Bladabindi.BH
BaiduMSIL.Backdoor.Bladabindi.a
TrendMicro-HouseCallBKDR_BLADABI.SMI
ClamAVWin.Packed.Generic-9795615-0
KasperskyTrojan.MSIL.Disfa.bqg
BitDefenderGeneric.MSIL.Bladabindi.3478D649
NANO-AntivirusTrojan.Win32.Disfa.dtznyx
AvastMSIL:Agent-DRD [Trj]
TencentTrojan.Msil.Bladabindi.za
Ad-AwareGeneric.MSIL.Bladabindi.3478D649
EmsisoftTrojan.Bladabindi (A)
ComodoBackdoor.MSIL.Bladabindi.A@566ygc
DrWebBackDoor.Bladabindi.13678
VIPREGeneric.MSIL.Bladabindi.3478D649
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.Trojan.mm
Trapminemalicious.moderate.ml.score
SophosML/PE-A + Troj/Bbindi-W
APEXMalicious
GDataMSIL.Backdoor.Bladabindi.AV
JiangminTrojan.MSIL.erzq
WebrootW32.Trojan.Gen
AviraBDS/Bladabindi.bhh
MAXmalware (ai score=80)
ViRobotBackdoor.Win32.Bladabindi.Gen.A
MicrosoftBackdoor:MSIL/Bladabindi
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Bladabindi.R91438
Acronissuspicious
McAfeeTrojan-FIGN
VBA32Trojan.MSIL.Disfa
MalwarebytesBackdoor.NJRat
IkarusTrojan.MSIL.Bladabindi
RisingBackdoor.njRAT!1.9E49 (CLASSIC)
YandexTrojan.AvsMofer.dd6520
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.LI!tr
AVGMSIL:Agent-DRD [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generic.MSIL.Bladabindi.3478D649?

Generic.MSIL.Bladabindi.3478D649 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment