Malware

Generic.MSIL.Bladabindi.76FC4474 information

Malware Removal

The Generic.MSIL.Bladabindi.76FC4474 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.76FC4474 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • CAPE detected the njRat malware family
  • Creates a copy of itself
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine Generic.MSIL.Bladabindi.76FC4474?


File Info:

name: 7B38522BA5CE4A7EF06F.mlw
path: /opt/CAPEv2/storage/binaries/52e3b299382528388973f9e9ab6cd70a0f58fab7ee899c07c0792bd7c0c6d59f
crc32: 4F16E2FA
md5: 7b38522ba5ce4a7ef06f3b641bef2c60
sha1: 0dc4c6deccf8a84e18e2815be883a5f6eb398cfb
sha256: 52e3b299382528388973f9e9ab6cd70a0f58fab7ee899c07c0792bd7c0c6d59f
sha512: 6feada94873c1334f82c73ede05a956aff9fc6315586591efa8accd4dc3fa824f20ea9284c68441c946588bf7adf5da91b70d09697efd92cad753b5e510b0de5
ssdeep: 384:j8aLWS0dABLYVq6RxP8MDFF09vK563gRMmJKUv0mRvR6JZlbw8hqIusZzZ+3:oXcwt3tRpcnuD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10BB21A4E3FA98856C5AC1B748AB5965003B4D1470423EE2FCCC454DBAFB36D92D4CAF8
sha3_384: a0b7d196a34da5b6ac97199b6cdcc723bd851ac8389858fe75368dc0f378e607cf1fc1c3a4ef0284f1e27058668d1470
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-02-03 13:10:58

Version Info:

0: [No Data]

Generic.MSIL.Bladabindi.76FC4474 also known as:

BkavW32.FamVT.binANHb.Worm
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Generic.TRFH5
ALYacGeneric.MSIL.Bladabindi.76FC4474
MalwarebytesBackdoor.NJRat
VIPREBackdoor.MSIL.Bladabindi.a (v)
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
Cybereasonmalicious.ba5ce4
BaiduMSIL.Backdoor.Bladabindi.a
VirITBackdoor.Win32.Generic.AWM
CyrenW32/MSIL_Bladabindi.AU.gen!Eldorado
SymantecBackdoor.Ratenjay
ESET-NOD32MSIL/Bladabindi.BC
APEXMalicious
ClamAVWin.Dropper.njRAT-7436651-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.MSIL.Bladabindi.76FC4474
NANO-AntivirusTrojan.Win32.Disfa.dtznyx
MicroWorld-eScanGeneric.MSIL.Bladabindi.76FC4474
RisingBackdoor.Njrat!1.9E49 (CLASSIC)
SophosML/PE-A + Troj/DotNet-P
ComodoBackdoor.MSIL.Bladabindi.A@566ygc
F-SecureTrojan.TR/Dropper.Gen7
DrWebTrojan.DownLoader17.52584
ZillyaTrojan.Disfa.Win32.27264
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.Trojan.mm
FireEyeGeneric.mg.7b38522ba5ce4a7e
EmsisoftTrojan.Bladabindi (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Autoit.dce
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen7
Antiy-AVLTrojan/Generic.ASBOL.A8F4
KingsoftHeur.SSC.1614947.1216.(kcloud)
MicrosoftBackdoor:MSIL/Bladabindi
ViRobotBackdoor.Win32.Bladabindi.Gen.A
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataMSIL.Backdoor.Bladabindi.AV
AhnLab-V3Win-Trojan/Zbot.24064
McAfeeTrojan-FIGN
MAXmalware (ai score=85)
VBA32Trojan.MSIL.Disfa
CylanceUnsafe
TrendMicro-HouseCallBKDR_BLADABI.SMC
YandexTrojan.Agent!B7PRUu47T9c
IkarusTrojan.MSIL.Bladabindi
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.LI!tr
BitDefenderThetaGen:NN.ZemsilF.34182.bmW@aGYW70f
AVGMSIL:Agent-DRD [Trj]
AvastMSIL:Agent-DRD [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Generic.MSIL.Bladabindi.76FC4474?

Generic.MSIL.Bladabindi.76FC4474 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment