Malware

What is “Generic.MSIL.Bladabindi.4553AF52”?

Malware Removal

The Generic.MSIL.Bladabindi.4553AF52 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.4553AF52 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • CAPE detected the njRat malware family
  • Creates a copy of itself

How to determine Generic.MSIL.Bladabindi.4553AF52?


File Info:

name: 46623F451754DF84A4EF.mlw
path: /opt/CAPEv2/storage/binaries/884207e6813a422f0fe468bb46f298963513f236905ea40800a91b400c574fe6
crc32: 929ED0AF
md5: 46623f451754df84a4ef9c37f4afc642
sha1: 0a503cb6f80c6fc579d854deaa0499653395f574
sha256: 884207e6813a422f0fe468bb46f298963513f236905ea40800a91b400c574fe6
sha512: 25becdcf8e1b1a49c013e2c3b9ce55038be9a3d663c855beb4ef0d390c5f2d170fd2599c58209504a513208ddb2182b0b75f8f5e22612ec71b073130867caf3d
ssdeep: 1536:cGSmf5/ZnBRICJ3LmxqE8+nYrhjxiTOV94vzW4Xh85Z6xRP:cGSmf5/ZBRICtmxqE8+nYrhjkfvsSR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15EC3E8556F48CD14E39CB2F8E472A24CC1B4FA5229DBCB19DDE624A94B3EF426C9F101
sha3_384: 03aea29ca544e5bb3bee2b5faf49f6fd9675e433afe0955289bccdd1f7d402e708f199f68062d0c80239f7596ce6611f
ep_bytes: ff250020400000000000000000000000
timestamp: 2012-11-02 15:01:11

Version Info:

0: [No Data]

Generic.MSIL.Bladabindi.4553AF52 also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop13.2717
MicroWorld-eScanGeneric.MSIL.Bladabindi.4553AF52
FireEyeGeneric.mg.46623f451754df84
CAT-QuickHealWorm.Necast.J3
McAfeeTrojan-FIGN
CylanceUnsafe
VIPREGeneric.MSIL.Bladabindi.4553AF52
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZemsilF.34592.hmW@aKvrhZc
VirITTrojan.Win32.Packed2_c.AWBD
CyrenW32/MSIL_Troj.AP.gen!Eldorado
SymantecBackdoor.Ratenjay!gen1
ESET-NOD32a variant of MSIL/Bladabindi.AZ
APEXMalicious
TrendMicro-HouseCallWORM_PCUT.SMA
ClamAVWin.Trojan.B-468
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.MSIL.Bladabindi.4553AF52
NANO-AntivirusTrojan.Win32.Autoruner.ctqpfj
AvastMSIL:Agent-CIB [Trj]
TencentTrojan.Win32.Bladabindi.16000442
Ad-AwareGeneric.MSIL.Bladabindi.4553AF52
EmsisoftGeneric.MSIL.Bladabindi.4553AF52 (B)
ComodoTrojWare.MSIL.Spy.Agent.EF@4r4nna
BaiduMSIL.Backdoor.Bladabindi.a
ZillyaTrojan.Bladabindi.Win32.20283
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
Trapminesuspicious.low.ml.score
SophosML/PE-A + Mal/MSIL-GL
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.apkbt
GoogleDetected
AviraTR/Agent.5587925
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.24D
MicrosoftBackdoor:MSIL/Bladabindi.AJ
GDataGeneric.MSIL.Bladabindi.4553AF52
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Generic.C4013419
Acronissuspicious
ALYacGeneric.MSIL.Bladabindi.4553AF52
MalwarebytesBackdoor.Bladabindi
RisingTrojan.Agent!1.9DB7 (CLASSIC)
YandexTrojan.Agent!n5LDe0OVp34
IkarusTrojan-Spy.HawkEye
MaxSecureTrojan.MSIL.Bladabindi.b
FortinetMSIL/Agent.PPV!tr
AVGMSIL:Agent-CIB [Trj]
Cybereasonmalicious.51754d
PandaGeneric Malware

How to remove Generic.MSIL.Bladabindi.4553AF52?

Generic.MSIL.Bladabindi.4553AF52 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment