Malware

Generic.MSIL.Bladabindi.72282E4C (file analysis)

Malware Removal

The Generic.MSIL.Bladabindi.72282E4C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.72282E4C virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • CAPE detected the njRat malware family
  • Creates a copy of itself

How to determine Generic.MSIL.Bladabindi.72282E4C?


File Info:

name: 543C098C16A65D05C9E2.mlw
path: /opt/CAPEv2/storage/binaries/9ac77fbacf5d8a49842d2dc802394c7d41ed53b450558a699468fd3af7a37a5c
crc32: 4D86D38A
md5: 543c098c16a65d05c9e204417972b965
sha1: 09fce40c5bc00a43348303c0017c79ad654121f5
sha256: 9ac77fbacf5d8a49842d2dc802394c7d41ed53b450558a699468fd3af7a37a5c
sha512: 1bb2c1d4f18201702f1bda5ef600a120711b375c3e9be8fd40cde1901b1bb0f50c37e7e8220132486e172ca5978444580a0dcb0d477f43f519c558543b74dd48
ssdeep: 768:aAYPRaCpS/bqNqEZMWWwoP6ncm6lyVlSsmH8YumW80LOxbnXDt:pYPRa+S/bqNqSWwoP6ncmnrbYqwbnX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15ED2198D7BB50616C5EC677084A693220BF382070523DBDF1DD9A8E69E772F02D48EE5
sha3_384: 0a311d6822eee41d2cae6ebbd4e353fd14ca4e4191bc99aa6b76491fa8328bcc006ab16fcab7455757a681cfcae85424
ep_bytes: ff250020400000000000000000000000
timestamp: 2015-08-29 09:35:40

Version Info:

0: [No Data]

Generic.MSIL.Bladabindi.72282E4C also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Generic.lZFZ
MicroWorld-eScanGeneric.MSIL.Bladabindi.72282E4C
ClamAVWin.Packed.Bladabindi-7086597-0
FireEyeGeneric.mg.543c098c16a65d05
CAT-QuickHealBackdoor.Bladabindi.AL3
ALYacGeneric.MSIL.Bladabindi.72282E4C
CylanceUnsafe
VIPREGeneric.MSIL.Bladabindi.72282E4C
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
Cybereasonmalicious.c16a65
BaiduMSIL.Backdoor.Bladabindi.a
VirITTrojan.Win32.DownLoader10.BDFZ
CyrenW32/MSIL_Troj.QB.gen!Eldorado
SymantecBackdoor.Trojan
ElasticWindows.Trojan.Njrat
ESET-NOD32a variant of MSIL/Bladabindi.AS
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.MSIL.Bladabindi.72282E4C
NANO-AntivirusTrojan.Win32.Dwn.ctopxm
AvastMSIL:Agent-CTT [Trj]
TencentTrojan.Win32.Bladabindi.16000442
Ad-AwareGeneric.MSIL.Bladabindi.72282E4C
EmsisoftGeneric.MSIL.Bladabindi.72282E4C (B)
ComodoTrojWare.MSIL.Bladabindi.KX@52g0y5
DrWebTrojan.DownLoader10.19759
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionTrojan-FIGN
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/Bbindi-C
SentinelOneStatic AI – Malicious PE
GDataMSIL.Trojan-Spy.Bladabindi.BX
JiangminTrojan/Generic.biuyb
AviraTR/Dropper.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.3303
MicrosoftBackdoor:MSIL/Bladabindi.AJ
GoogleDetected
AhnLab-V3Trojan/Win32.RL_Generic.C4292292
Acronissuspicious
McAfeeTrojan-FIGN
MalwarebytesTrojan.Agent.MSIL
RisingBackdoor.njRAT!1.9E49 (CLASSIC)
YandexTrojan.RatJn.Gen.MG
IkarusTrojan.MSIL.Bladabindi
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.PPV!tr
BitDefenderThetaGen:NN.ZemsilF.34592.biX@am9Utmm
AVGMSIL:Agent-CTT [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generic.MSIL.Bladabindi.72282E4C?

Generic.MSIL.Bladabindi.72282E4C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment