Malware

Generic.MSIL.Bladabindi.4466C739 malicious file

Malware Removal

The Generic.MSIL.Bladabindi.4466C739 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.4466C739 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • CAPE detected the njRat malware family
  • Creates a copy of itself

How to determine Generic.MSIL.Bladabindi.4466C739?


File Info:

name: 899C1EE980F8935298C4.mlw
path: /opt/CAPEv2/storage/binaries/61de38669aef512c039d19ce8fe90f08be5b75d15f1e4be5f591dc4a53773ad4
crc32: 2A05931E
md5: 899c1ee980f8935298c4e452710eb571
sha1: dde3e5db63eb46c8c6e2517b542cea4b369db986
sha256: 61de38669aef512c039d19ce8fe90f08be5b75d15f1e4be5f591dc4a53773ad4
sha512: dae88590ebbd58dd3be8516289d33492439bb9384e4b983f8d1f8c76e9c3f870a243588a00d947ef820aa76fc19a3bea971541c4998301872357c86474b8110b
ssdeep: 1536:Kmdkv2wMaZ1rdiXimiW1M1QzsCP1aed/y4mov:KmNaZ1RSJogAed/nm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15AB3084DB7D83450D0BE21B68AA2B1104E75B45B2607D34D4AE358BE2E376F08E94DFB
sha3_384: a93368bc8e5c140fb5b264a174206a7527cc02348be3b5aedb94a05e46d9fc4a0c3d7e10e0de811ffb8dec182fdadd6f
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-08-15 23:30:08

Version Info:

0: [No Data]

Generic.MSIL.Bladabindi.4466C739 also known as:

BkavW32.AIDetectNet.01
LionicHeuristic.File.Generic.00×1!p
MicroWorld-eScanGeneric.MSIL.Bladabindi.4466C739
FireEyeGeneric.mg.899c1ee980f89352
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacGeneric.MSIL.Bladabindi.4466C739
CylanceUnsafe
ZillyaWorm.AutoRun.Win32.272847
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 00555f371 )
AlibabaBackdoor:MSIL/Bladabindi.31f15292
K7GWEmailWorm ( 00555f371 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZemsilF.34646.giW@aCKhOyo
VirITTrojan.Win32.MulDrop7.DJFC
CyrenW32/Trojan.BVX.gen!Eldorado
SymantecML.Attribute.HighConfidence
ElasticWindows.Trojan.Njrat
ESET-NOD32a variant of MSIL/Autorun.Spy.Agent.R
TrendMicro-HouseCallTROJ_GEN.R002C0DHG22
Paloaltogeneric.ml
ClamAVWin.Packed.Generic-9795615-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.MSIL.Bladabindi.4466C739
NANO-AntivirusTrojan.Win32.TrjGen.dkmeat
CynetMalicious (score: 100)
AvastWin32:RATX-gen [Trj]
TencentTrojan.Win32.Bladabindi.16000442
Ad-AwareGeneric.MSIL.Bladabindi.4466C739
SophosML/PE-A + Mal/MsilPKill-C
DrWebTrojan.MulDrop7.58944
VIPREGeneric.MSIL.Bladabindi.4466C739
TrendMicroTROJ_GEN.R002C0DHG22
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
SentinelOneStatic AI – Malicious PE
Trapminemalicious.moderate.ml.score
EmsisoftGeneric.MSIL.Bladabindi.4466C739 (B)
APEXMalicious
GDataMSIL.Backdoor.Agent.AXJ
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3DAC
ViRobotTrojan.Win32.Z.Bladabindi.109056.UV
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
MicrosoftBackdoor:MSIL/Bladabindi.BN
GoogleDetected
AhnLab-V3Trojan/Win32.RL_Generic.C3455351
Acronissuspicious
McAfeeTrojan-FIDH!899C1EE980F8
MAXmalware (ai score=83)
VBA32Trojan.MSIL.Bladabindi.Heur
MalwarebytesBladabindi.Backdoor.Njrat.DDS
RisingBackdoor.njRAT!1.A096 (CLASSIC)
YandexTrojan.Agent!f5BTsW4iZY8
IkarusTrojan.MSIL.Filecoder
MaxSecureTrojan.Malware.7164915.susgen
FortinetMSIL/Bladabindi.LX!tr
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.980f89
PandaTrj/CI.A

How to remove Generic.MSIL.Bladabindi.4466C739?

Generic.MSIL.Bladabindi.4466C739 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment