Malware

Should I remove “Generic.MSIL.Bladabindi.48B8EC52”?

Malware Removal

The Generic.MSIL.Bladabindi.48B8EC52 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.48B8EC52 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • CAPE detected the njRat malware family
  • Creates a copy of itself
  • Creates known Njrat/Bladabindi RAT registry keys
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.MSIL.Bladabindi.48B8EC52?


File Info:

name: A95FAC6D27A3D26D9D9A.mlw
path: /opt/CAPEv2/storage/binaries/24035b223beb439f94e2bd4d93dac520c11875676a48ffed6c30e7f03df095cd
crc32: 484C5481
md5: a95fac6d27a3d26d9d9adbb0db1fc499
sha1: 46f92894212e9d3cc1e622629d83d55ff36ec203
sha256: 24035b223beb439f94e2bd4d93dac520c11875676a48ffed6c30e7f03df095cd
sha512: 7cedde30737ad9274fb15b0a75de2b6b02dcbcad34546333627298d7b4be59dfab8a1d6801a247c1dc1dc3188c5f2ea0c23d33255a34b2734d80f43756b56911
ssdeep: 384:nqTMUiDHblmJEpRGyEfBffXuKCYyEWnrAF+rMRTyN/0L+EcoinblneHQM3epzX1T:qTqHpR9EfBfWKClEMrM+rMRa8NuLRt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14E03294D7FE18168C4FD167B05B2D41207BBE04B6E23D90E8EF164AA37636C18B50AF2
sha3_384: a888a4faeb4a203f857fd8c068205c398c972564af08a74853505ac9480271bcb7592142da32d255a45762ed8d4922e2
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-07-25 19:35:38

Version Info:

0: [No Data]

Generic.MSIL.Bladabindi.48B8EC52 also known as:

BkavW32.AIDetectNet.01
MicroWorld-eScanGeneric.MSIL.Bladabindi.48B8EC52
CAT-QuickHealBackdoor.Bladabindi.B3
McAfeeTrojan-FIGN
CylanceUnsafe
VIPREIL:Trojan.MSILZilla.4691
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
Cybereasonmalicious.d27a3d
BaiduMSIL.Backdoor.Bladabindi.a
VirITTrojan.Win32.DownLoader21.BPQW
CyrenW32/MSIL_Troj.AP.gen!Eldorado
SymantecBackdoor.Ratenjay!gen3
ElasticWindows.Trojan.Njrat
ESET-NOD32a variant of MSIL/Bladabindi.AR
APEXMalicious
ClamAVWin.Packed.Bladabindi-7994427-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.MSIL.Bladabindi.48B8EC52
NANO-AntivirusTrojan.Win32.Autoruner2.ebrjyu
ViRobotBackdoor.Win32.Agent.37888.AL
AvastMSIL:Bladabindi-JK [Trj]
TencentTrojan.Msil.Bladabindi.fa
Ad-AwareGeneric.MSIL.Bladabindi.48B8EC52
TACHYONBackdoor/W32.DN-Bladabindi.37888.B
EmsisoftWorm.Bladabindi (A)
ComodoTrojWare.MSIL.Spy.Agent.CP@4pqytu
DrWebTrojan.DownLoader20.55401
ZillyaTrojan.Bladabindi.Win32.72266
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.Backdoor.nm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.a95fac6d27a3d26d
SophosML/PE-A + Troj/Bbindi-W
IkarusTrojan.MSIL.Bladabindi
GDataMSIL.Trojan-Spy.Bladabindi.BQ
JiangminTrojanDropper.Autoit.dce
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan/Generic.ASBOL.A8F4
ArcabitIL:Trojan.MSILZilla.D1253
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:MSIL/Bladabindi.B
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Korat.R207428
Acronissuspicious
VBA32Trojan.Downloader
ALYacIL:Trojan.MSILZilla.4691
MAXmalware (ai score=82)
MalwarebytesBackdoor.NJRat.MSIL
RisingBackdoor.njRAT!1.9E49 (CLASSIC)
YandexTrojan.AvsMofer.dd6520
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Bladabindi.AS!tr
BitDefenderThetaGen:NN.ZemsilF.34806.cmW@aGQXq1i
AVGMSIL:Bladabindi-JK [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Generic.MSIL.Bladabindi.48B8EC52?

Generic.MSIL.Bladabindi.48B8EC52 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment