Malware

Generic.MSIL.Bladabindi.78800CD8 malicious file

Malware Removal

The Generic.MSIL.Bladabindi.78800CD8 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.78800CD8 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • CAPE detected the njRat malware family
  • Creates a copy of itself
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine Generic.MSIL.Bladabindi.78800CD8?


File Info:

name: 27CA48874A5790A56D3E.mlw
path: /opt/CAPEv2/storage/binaries/0d746d68f8a735d54e4062fecb2842501cfb3038ccf06a2a89485bd47216d15a
crc32: 8AE343F0
md5: 27ca48874a5790a56d3e7e1d51b71411
sha1: be28c1820d0c8a9a6d876d060824b5073996eb81
sha256: 0d746d68f8a735d54e4062fecb2842501cfb3038ccf06a2a89485bd47216d15a
sha512: 97ca9d1ad493f5e591df6216f8c587ac71c363082c085fe6a8594691d14968ccf15e32d923aa283f124bfea57f7d821d459718dea64228bcab7ddcd51abccaef
ssdeep: 384:b8aZYC9twBNdcvFaly2H0dbJo6HghcASEJqc/ZmRvR6JZlbw8hqIusZzZG3:fY+sNKqNHnSdRpcnu7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T192B2194E3FA98856C5BD17708AA5965003B091870423EE2FCDC550DBAFB3AD92D4CAF9
sha3_384: 42e95225faae7c905c38f89188572a098d770167e17223f66295d97d6c3c6643651de57f99f1e2931b802cb19053d45e
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-02-03 04:47:27

Version Info:

0: [No Data]

Generic.MSIL.Bladabindi.78800CD8 also known as:

BkavW32.FamVT.binANHb.Worm
Elasticmalicious (high confidence)
ClamAVWin.Dropper.njRAT-7436651-0
CAT-QuickHealTrojan.Generic.TRFH5
ALYacGeneric.MSIL.Bladabindi.78800CD8
CylanceUnsafe
ZillyaBackdoor.Agent.Win32.55242
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
BitDefenderGeneric.MSIL.Bladabindi.78800CD8
K7GWTrojan ( 700000121 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduMSIL.Backdoor.Bladabindi.a
VirITBackdoor.Win32.Generic.AWM
CyrenW32/MSIL_Bladabindi.AU.gen!Eldorado
SymantecBackdoor.Ratenjay
ESET-NOD32MSIL/Bladabindi.BH
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.MSIL.Agent.jdt
NANO-AntivirusTrojan.Win32.Disfa.dtznyx
MicroWorld-eScanGeneric.MSIL.Bladabindi.78800CD8
RisingBackdoor.Njrat!1.9E49 (CLASSIC)
Ad-AwareGeneric.MSIL.Bladabindi.78800CD8
EmsisoftTrojan.Bladabindi (A)
ComodoBackdoor.MSIL.Bladabindi.A@566ygc
DrWebBackDoor.Bladabindi.13678
VIPREBackdoor.MSIL.Bladabindi.a (v)
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.Trojan.mm
FireEyeGeneric.mg.27ca48874a5790a5
SophosML/PE-A + Troj/DotNet-P
SentinelOneStatic AI – Malicious PE
GDataMSIL.Backdoor.Bladabindi.AV
JiangminTrojanDropper.Autoit.dce
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen7
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASBOL.A8F4
KingsoftHeur.SSC.1608662.1216.(kcloud)
ArcabitGeneric.MSIL.Bladabindi.78800CD8
ViRobotBackdoor.Win32.Bladabindi.Gen.A
MicrosoftBackdoor:MSIL/Bladabindi
AhnLab-V3Backdoor/Win32.Bladabindi.R91438
Acronissuspicious
McAfeeTrojan-FIGN
TACHYONTrojan-Dropper/W32.DN-FrauDrop.24064.C
VBA32Trojan.MSIL.Disfa
MalwarebytesBackdoor.NJRat
PandaGeneric Malware
TrendMicro-HouseCallBKDR_BLADABI.SMC
YandexTrojan.Agent!L4uy5JhITR0
IkarusTrojan.MSIL.Bladabindi
eGambitUnsafe.AI_Score_100%
FortinetMSIL/Agent.LI!tr
BitDefenderThetaGen:NN.ZemsilF.34182.bmW@a0Hkkkj
AVGMSIL:Agent-DRD [Trj]
Cybereasonmalicious.74a579
AvastMSIL:Agent-DRD [Trj]
MaxSecureTrojan.Malware.300983.susgen

How to remove Generic.MSIL.Bladabindi.78800CD8?

Generic.MSIL.Bladabindi.78800CD8 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment