Malware

Generic.MSIL.Bladabindi.78F3B3CF (file analysis)

Malware Removal

The Generic.MSIL.Bladabindi.78F3B3CF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.78F3B3CF virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • CAPE detected the njRat malware family
  • Creates a copy of itself
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine Generic.MSIL.Bladabindi.78F3B3CF?


File Info:

name: 964EAA8F39116D2AB536.mlw
path: /opt/CAPEv2/storage/binaries/a05a4c069339863e95bb6e6106ef5602bb5b00ec2830cf90133ddd6dcbc139f2
crc32: A7BA7C6D
md5: 964eaa8f39116d2ab536bc9cfb0a3b8d
sha1: bdebe89afc5d9df7371a58685b1f152337995dc4
sha256: a05a4c069339863e95bb6e6106ef5602bb5b00ec2830cf90133ddd6dcbc139f2
sha512: 08c55b43c71ebbf94a379715f98d423658a76c4f0a84e4a6dc1d38a52a6ffbf8dd650e3a4db0316182fac8e7b54e26b90edfc55621bd7e3698816482702adbe8
ssdeep: 384:wslUlEvOEJ8xWwYJOMiOBZEdj1567gtwi5HhbQmRvR6JZlbw8hqIusZzZ6E:peEvwIlLMRpcnuk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B0B22A0E3FB9C856C5AC177486A5965003B091470423EE2FCDC964DBAFB3BD92D48AF9
sha3_384: 1774473705a6e81eb77f5488b0c52bf65c05d8d040c2fb250eb182ea98f6a7e0848c0d044f91c65b13c953dd7347fe3d
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-06-08 23:10:12

Version Info:

0: [No Data]

Generic.MSIL.Bladabindi.78F3B3CF also known as:

BkavW32.FamVT.binANHb.Worm
ClamAVWin.Packed.Generic-9795615-0
CAT-QuickHealTrojan.Generic.TRFH5
McAfeeTrojan-FIGN
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
Cybereasonmalicious.f39116
BaiduMSIL.Backdoor.Bladabindi.a
VirITBackdoor.Win32.Generic.AWM
CyrenW32/MSIL_Bladabindi.AU.gen!Eldorado
ElasticWindows.Trojan.Njrat
ESET-NOD32MSIL/Bladabindi.BH
APEXMalicious
AvastMSIL:Agent-DRD [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.MSIL.Bladabindi.78F3B3CF
NANO-AntivirusTrojan.Win32.Disfa.dtznyx
ViRobotBackdoor.Win32.Bladabindi.Gen.A
MicroWorld-eScanGeneric.MSIL.Bladabindi.78F3B3CF
RisingBackdoor.njRAT!1.9E49 (CLASSIC)
Ad-AwareGeneric.MSIL.Bladabindi.78F3B3CF
EmsisoftTrojan.Bladabindi (A)
ComodoBackdoor.MSIL.Bladabindi.A@566ygc
DrWebTrojan.DownLoader23.25967
ZillyaTrojan.Disfa.Win32.27264
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.Trojan.mm
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.964eaa8f39116d2a
SophosML/PE-A + Troj/DotNet-P
SentinelOneStatic AI – Malicious PE
GDataMSIL.Backdoor.Bladabindi.AV
JiangminTrojanDropper.Autoit.dce
AviraTR/Dropper.Gen7
ArcabitGeneric.MSIL.Bladabindi.78F3B3CF
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:MSIL/Bladabindi
TACHYONBackdoor/W32.DN-NjRat.24064.Y
AhnLab-V3Win-Trojan/Zbot.24064
Acronissuspicious
VBA32Trojan.MSIL.Disfa
ALYacGeneric.MSIL.Bladabindi.78F3B3CF
MAXmalware (ai score=82)
MalwarebytesBladabindi.Backdoor.Njrat.DDS
TrendMicro-HouseCallBKDR_BLADABI.SMC
TencentTrojan.Msil.Bladabindi.za
YandexTrojan.Agent!28GjWDalpXI
IkarusTrojan.MSIL.Bladabindi
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.LI!tr
BitDefenderThetaGen:NN.ZemsilF.34712.bmW@a0LMokm
AVGMSIL:Agent-DRD [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Generic.MSIL.Bladabindi.78F3B3CF?

Generic.MSIL.Bladabindi.78F3B3CF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment