Malware

What is “Generic.MSIL.Bladabindi.348DD1FA”?

Malware Removal

The Generic.MSIL.Bladabindi.348DD1FA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.348DD1FA virus can do?

  • Uses Windows utilities for basic functionality
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • CAPE detected the Njrat malware family
  • Creates a copy of itself
  • Creates known Njrat/Bladabindi RAT registry keys
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generic.MSIL.Bladabindi.348DD1FA?


File Info:

name: 50D5C2CD7F021C3A958F.mlw
path: /opt/CAPEv2/storage/binaries/f96fcc4a8387079ea3556075b9d58c726007b8d15d46f9975dc70df13a92820f
crc32: AFA615C6
md5: 50d5c2cd7f021c3a958fa272d42342ad
sha1: 063d01a338911b2155624f6f20aed080d6e612b5
sha256: f96fcc4a8387079ea3556075b9d58c726007b8d15d46f9975dc70df13a92820f
sha512: 4b4a394a96f950650d7f8e55fa2291c3289015755755c67d42881d3d929dc832cff52adc125a34372cffa57a27c29feca6d728c6042402b3cace55eff23ec0de
ssdeep: 384:BZLZvjluAczvU8oHvloNFzTWK45ioTHJu3Wi2V9laJSEkLDOHYCFXPzlpmIMxTZ4:BpZvjlu3vU8h+i8pVX1mF71715
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T172E2F70537AA4703C62D03B94926471647F1CE43453BEB5F1CD9F4ED1DBB7848A81AAB
sha3_384: a3d53ebfec5d72d281914dc13e7fbd8ab653c8bfeb82a258542242bb16c29bd9cf931bb54805de289e4b6d5be012cf36
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-08-06 01:43:06

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: k.exe
LegalCopyright:
OriginalFilename: k.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Generic.MSIL.Bladabindi.348DD1FA also known as:

LionicTrojan.Win32.Generic.lWjm
MicroWorld-eScanGeneric.MSIL.Bladabindi.348DD1FA
FireEyeGeneric.mg.50d5c2cd7f021c3a
CAT-QuickHealTrojan.GenericFC.S6059376
ALYacGeneric.MSIL.Bladabindi.348DD1FA
Cylanceunsafe
ZillyaWorm.Bladabindi.Win32.7859
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004b99501 )
AlibabaBackdoor:MSIL/Bladabindi.237da37f
K7GWTrojan ( 004b99501 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZemsilF.36662.cm0@amMoOSe
VirITTrojan.Win32.Dnldr25.PBI
CyrenW32/MSIL_Agent.CP.gen!Eldorado
SymantecML.Attribute.HighConfidence
ElasticWindows.Trojan.Njrat
ESET-NOD32a variant of MSIL/Autorun.Agent.LW
APEXMalicious
ClamAVWin.Trojan.Generic-6417450-0
BitDefenderGeneric.MSIL.Bladabindi.348DD1FA
SUPERAntiSpywareBackdoor.NJRat/Variant
AvastMSIL:Agent-CIB [Trj]
TencentTrojan.Win32.Bladabindi.16000442
SophosMal/Bladabi-T
BaiduMSIL.Backdoor.Bladabindi.a
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.DownLoader25.15762
VIPREGeneric.MSIL.Bladabindi.348DD1FA
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionTrojan-FIGN
EmsisoftGeneric.MSIL.Bladabindi.348DD1FA (B)
SentinelOneStatic AI – Malicious PE
GDataMSIL.Backdoor.Bladabindi.AV
JiangminTrojanSpy.Agent.aaxh
AviraTR/ATRAPS.Gen
XcitiumBackdoor.MSIL.Bladabindi.BSS@7pzdvl
ArcabitGeneric.MSIL.Bladabindi.348DD1FA
ViRobotTrojan.Win.Z.Bladabindi.32768.HX
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:MSIL/Bladabindi.BO
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/NjRAT01.Exp
Acronissuspicious
McAfeeTrojan-FIGN
MAXmalware (ai score=85)
VBA32Trojan.MSIL.Bladabindi.Heur
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/GdSda.A
RisingBackdoor.njRAT!1.D4D6 (CLASSIC)
IkarusWorm.MSIL.Autorun
MaxSecureTrojan.Malware.121218.susgen
FortinetMSIL/Agent.LI!tr
AVGMSIL:Agent-CIB [Trj]
Cybereasonmalicious.338911
DeepInstinctMALICIOUS

How to remove Generic.MSIL.Bladabindi.348DD1FA?

Generic.MSIL.Bladabindi.348DD1FA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment