Malware

Should I remove “Generic.MSIL.Bladabindi.8352CD9C”?

Malware Removal

The Generic.MSIL.Bladabindi.8352CD9C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.8352CD9C virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • CAPE detected the njRat malware family
  • Creates a copy of itself

How to determine Generic.MSIL.Bladabindi.8352CD9C?


File Info:

name: D0B9CFDB719877A0A515.mlw
path: /opt/CAPEv2/storage/binaries/3f8c7bbc56817d8a90e585cdf6202022259b6a7ca144d8419f23286ecc876e56
crc32: 3B112F86
md5: d0b9cfdb719877a0a5155e246b1c9ae8
sha1: 4e94855abc9ed3a3fceaeccd8dc023f82e22ff70
sha256: 3f8c7bbc56817d8a90e585cdf6202022259b6a7ca144d8419f23286ecc876e56
sha512: a39450d77e24817929c50421cf34949836024aaadee6c5231a554d1409bd0b22d1a30ca4bab20e53d1c550eb8e02ed5d50094a4fc5d4ad1b3b1068c8f281fe99
ssdeep: 1536:dcwC+xhUa9urgOBPmNvM4jEwzGi1dDtD/gS:dcmUa9urgOkdGi1dRY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17293D74977E53524E4BF56F79472F2004E34B44B1602E39E49F259EA0A33AC44F89EEB
sha3_384: cb9bfeb29638564ec2e8cc8db5a52c4a69f5499c5762cfe57ecebcb00c7e2562a88eca633399dcc3feb197b097f35473
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-10-01 19:37:10

Version Info:

0: [No Data]

Generic.MSIL.Bladabindi.8352CD9C also known as:

BkavW32.PrimeaClefAF.Trojan
MicroWorld-eScanGeneric.MSIL.Bladabindi.8352CD9C
FireEyeGeneric.mg.d0b9cfdb719877a0
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
McAfeeTrojan-FIDH!D0B9CFDB7198
MalwarebytesGeneric.Worm.Autorun.DDS
ZillyaWorm.AutoRun.Win32.282893
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 00555f371 )
K7GWEmailWorm ( 00555f371 )
Cybereasonmalicious.b71987
ArcabitGeneric.MSIL.Bladabindi.8352CD9C
VirITTrojan.Win32.MulDrop7.DOQR
CyrenW32/Trojan.BVX.gen!Eldorado
ElasticWindows.Trojan.Njrat
ESET-NOD32a variant of MSIL/Autorun.Spy.Agent.R
APEXMalicious
ClamAVWin.Packed.Generic-9795615-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.MSIL.Bladabindi.8352CD9C
NANO-AntivirusTrojan.Win32.TrjGen.dkmeat
AvastWin32:KeyloggerX-gen [Trj]
TencentWorm.Msil.Agent.zo
Ad-AwareGeneric.MSIL.Bladabindi.8352CD9C
SophosML/PE-A + Mal/MsilPKill-C
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.MulDrop7.62625
VIPREGeneric.MSIL.Bladabindi.8352CD9C
TrendMicroBackdoor.MSIL.BLADABINDI.SMJJ
McAfee-GW-EditionTrojan-FIDH!D0B9CFDB7198
Trapminemalicious.high.ml.score
EmsisoftGeneric.MSIL.Bladabindi.8352CD9C (B)
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Backdoor]/MSIL.Bladabindi
MicrosoftBackdoor:MSIL/Bladabindi.BN
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataMSIL.Backdoor.Agent.AXJ
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Bladabindi.R295982
Acronissuspicious
BitDefenderThetaGen:NN.ZemsilF.34698.fiW@aKu2gHf
ALYacGeneric.MSIL.Bladabindi.8352CD9C
MAXmalware (ai score=89)
VBA32Trojan.MSIL.Bladabindi.Heur
TrendMicro-HouseCallBackdoor.MSIL.BLADABINDI.SMJJ
RisingBackdoor.njRAT!1.A096 (CLASSIC)
YandexTrojan.Agent!9cWTKx22Lpk
IkarusTrojan.MSIL.Bladabindi
FortinetMSIL/Bladabindi.LX!tr
AVGWin32:KeyloggerX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Generic.MSIL.Bladabindi.8352CD9C?

Generic.MSIL.Bladabindi.8352CD9C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment