Malware

Generic.MSIL.Bladabindi.51FD66FF malicious file

Malware Removal

The Generic.MSIL.Bladabindi.51FD66FF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.51FD66FF virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • CAPE detected the njRat malware family
  • Creates a copy of itself
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine Generic.MSIL.Bladabindi.51FD66FF?


File Info:

name: E46F10636A45DB38151C.mlw
path: /opt/CAPEv2/storage/binaries/944062c427a9b7c315b5ec338e370e7078a960bc8436f0665a3596802eeb0592
crc32: 2C9443A5
md5: e46f10636a45db38151ce0aa51a511b5
sha1: 66c0f1f4726d66ffa846d65d177a633f739b63f1
sha256: 944062c427a9b7c315b5ec338e370e7078a960bc8436f0665a3596802eeb0592
sha512: 9dd36154926483177fefd67cd620ec2be2fe4a88f4a774cee1c0ede6826d617f75c3497d1095883764f7e21924ea2d1cec586db264ef5b8ca3d0b64e1deb8768
ssdeep: 384:GslUlEvOEJ8xWwYJOMiOBZEdj1567gtwi5HhbQmRvR6JZlbw8hqIusZzZ64:PeEvwIlLMRpcnuY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T130B2290E3FB9C856C5AC177486A5965003B491470423EE2FCDC560DBAFB3BD92D48AF9
sha3_384: 4fb7908af043f4677ae34ef58d9ac6a9c8483b9f3110f199fbee1535dab9a6295c486d054485adba146d5ac10040ebbe
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-06-28 22:47:51

Version Info:

0: [No Data]

Generic.MSIL.Bladabindi.51FD66FF also known as:

BkavW32.FamVT.binANHb.Worm
CynetMalicious (score: 100)
FireEyeGeneric.mg.e46f10636a45db38
CAT-QuickHealTrojan.Generic.TRFH5
McAfeeTrojan-FIGN
MalwarebytesBladabindi.Backdoor.Njrat.DDS
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
BitDefenderGeneric.MSIL.Bladabindi.51FD66FF
K7GWTrojan ( 700000121 )
Cybereasonmalicious.36a45d
ArcabitGeneric.MSIL.Bladabindi.51FD66FF
BaiduMSIL.Backdoor.Bladabindi.a
VirITBackdoor.Win32.Generic.AWM
CyrenW32/MSIL_Bladabindi.AU.gen!Eldorado
SymantecBackdoor.Ratenjay
ElasticWindows.Trojan.Njrat
ESET-NOD32MSIL/Bladabindi.BH
APEXMalicious
ClamAVWin.Packed.Generic-9795615-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Disfa.dtznyx
MicroWorld-eScanGeneric.MSIL.Bladabindi.51FD66FF
RisingBackdoor.njRAT!1.9E49 (CLASSIC)
Ad-AwareGeneric.MSIL.Bladabindi.51FD66FF
SophosML/PE-A + Troj/DotNet-P
ComodoBackdoor.MSIL.Bladabindi.A@566ygc
F-SecureTrojan.TR/Dropper.Gen7
DrWebTrojan.DownLoader23.25967
ZillyaTrojan.Disfa.Win32.27264
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.Trojan.mm
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.Bladabindi (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Autoit.dce
AviraTR/Dropper.Gen7
MicrosoftBackdoor:MSIL/Bladabindi
ViRobotBackdoor.Win32.Bladabindi.Gen.A
GDataMSIL.Backdoor.Bladabindi.AV
TACHYONBackdoor/W32.DN-NjRat.24064.Y
AhnLab-V3Win-Trojan/Zbot.24064
Acronissuspicious
VBA32Trojan.MSIL.Disfa
ALYacGeneric.MSIL.Bladabindi.51FD66FF
MAXmalware (ai score=86)
CylanceUnsafe
PandaGeneric Malware
TrendMicro-HouseCallBKDR_BLADABI.SMI
TencentTrojan.Msil.Bladabindi.za
YandexTrojan.Agent!28GjWDalpXI
IkarusTrojan.MSIL.Bladabindi
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.LI!tr
BitDefenderThetaGen:NN.ZemsilF.34742.bmW@aWQLlGb
AVGMSIL:Agent-DRD [Trj]
AvastMSIL:Agent-DRD [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Generic.MSIL.Bladabindi.51FD66FF?

Generic.MSIL.Bladabindi.51FD66FF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment